Privacy Policy
Last updated: January 2026
This Privacy Policy describes how J.A. Consulting ("I", "me", or "my") collects, uses, and protects personal data in connection with the operation of this website and the provision of my professional services.
For the purposes of the EU General Data Protection Regulation (GDPR), J.A. Consulting operates from Ireland and is subject to the supervision of the Irish Data Protection Commission (DPC).
1. Scope and Purpose
This Privacy Policy applies to personal data collected through this website and through direct interactions with me, including contact requests, professional inquiries, and the provision of advisory services.
I process personal data only to the extent necessary for legitimate, defined purposes and in accordance with applicable data protection laws, including the GDPR and relevant Irish legislation.
2. Data Controller
The data controller responsible for the processing of personal data under this Policy is:
J.A. Consulting
Email: john@jaconsulting.pro
3. Personal Data I Collect
A. Information You Provide Voluntarily
I may collect personal data that you choose to provide, including:
- Full name
- Email address
- Company name and role
- Contact details
- Information included in inquiries or correspondence
Payment and billing details, if and when applicable. At present, I do not process payments through this website. Client payments are handled separately and offline, typically via bank wire transfer or similar arrangements.
B. Information Collected Automatically
I use Google Analytics to collect anonymized data about website usage, including pages visited, time on site, and general location. This is a non-essential cookie and requires your explicit consent before activation.
Any automatically collected information is limited to basic, technical data required for the secure and proper operation of the website by my hosting infrastructure, such as:
- IP address (in truncated or aggregated form where applicable)
- Browser type and operating system
- Technical logs necessary for security and stability
No behavioral analytics, profiling, or marketing tracking is performed without explicit user consent.
C. Sensitive Data
I do not intentionally collect special categories of personal data (such as health data, biometric data, or political opinions). Please do not submit such information through the website.
4. Purposes of Processing and Legal Basis
I process personal data for the following purposes and on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Responding to inquiries and contact requests | Legitimate interests or pre-contractual steps |
| Providing professional advisory services | Performance of a contract |
| Newsletter distribution and marketing communications | Explicit consent |
| Lead magnets (free guides, checklists, informational resources) | Explicit consent |
| Website security and integrity | Legitimate interests |
| Compliance with legal and regulatory obligations | Legal obligation |
Providing a Lead Magnet does not constitute a contractual relationship. Consent for marketing or informational communications may be withdrawn at any time.
5. Lead Magnets and Marketing Content
From time to time, I may offer free resources such as guides, checklists, newsletters, webinars, or other informational materials ("Lead Magnets").
Where personal data (such as an email address) is collected in connection with such Lead Magnets, the legal basis for processing is explicit consent.
Consent may be withdrawn at any time by using the unsubscribe mechanism included in communications or by contacting me directly.
6. Data Sharing and Processors
I do not sell or rent personal data.
Personal data may be shared with trusted service providers acting as processors on my behalf, including:
- Website hosting and infrastructure providers
- Email and communication service providers
- Google Analytics (website analytics)
Where personal data is transferred outside the European Economic Area (EEA), such transfers are subject to appropriate safeguards, including the use of Standard Contractual Clauses approved by the European Commission.
7. WhatsApp Communication
Where you choose to contact me via WhatsApp, your messages and associated personal data will be processed by WhatsApp LLC, a subsidiary of Meta Platforms Inc., which may involve the transfer of personal data outside the European Economic Area. Such transfers are subject to Meta's own privacy policy and terms of service. I use WhatsApp solely to respond to direct inquiries and do not use it for automated messaging or marketing purposes.
8. Data Retention
I retain personal data only for as long as necessary for the purposes for which it was collected:
- Inquiries and contact requests: up to 3 months from the date of last interaction
- Client data: for the duration of the engagement and up to 1 year thereafter
- Accounting and tax records: as required under applicable law and regulatory obligations
9. Cookies and Consent Management
I use Google Analytics as an analytics tool. This non-essential cookie is only activated after explicit user consent is provided through the cookie consent mechanism on this website.
Essential cookies required for the secure and proper operation of the website may be used.
A cookie consent mechanism is implemented to allow users to manage preferences should non-essential cookies or tracking technologies be introduced in the future. No non-essential cookies are deployed unless and until explicit user consent is provided.
10. Data Subject Rights
Under the GDPR, you have the right to:
- Access your personal data
- Request rectification of inaccurate data
- Request erasure of your data
- Restrict or object to processing
- Request data portability
- Withdraw consent at any time (where processing is based on consent)
To exercise these rights, please contact me using the details above.
11. Right to Lodge a Complaint
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC) if you believe that the processing of your personal data infringes applicable data protection law.
12. Security Measures
I implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse. However, no method of transmission over the internet is entirely secure.
13. Children's Privacy
This website is not intended for children under the age of 16, and I do not knowingly collect personal data from children.
14. Changes to This Policy
I may update this Privacy Policy from time to time to reflect legal, regulatory, or operational changes. The updated version will be posted on this page with a revised "Last updated" date.