Privacy Policy
Last updated: 19th September 2026
Who we are
Obscurity Ltd ("we", "us", "our") is an analytics governance practice registered in Ireland (Company Registration No. 622475). We are the controller for personal data processed through obscurity.ie, and for the business contact details we hold when we approach people at other organisations, as set out under "Business contacts we approach" below. For any privacy query, or to exercise any of the rights below, contact contact@obscurity.ie.
What this website collects
This website loads Google Tag Manager, which manages analytics and advertising tags. Those tags are gated behind a consent banner: if you do not consent, no analytics or advertising tags run and no analytics or advertising cookies are set. If you contact us by email, we process your name, email address, and the content of your message in order to respond.
Cookies and consent
Consent is managed by a consent banner we host ourselves - no third-party consent provider is involved. The banner controls four categories:
- Strictly necessary - required for the site to function, including the first-party cookie (cc_cookie) that stores your consent choice and a random consent identifier. Always active; set without consent as permitted under the ePrivacy Directive.
- Analytics - Google Analytics 4 (GA4), used to understand aggregate site usage. GA4 applies IP anonymisation, so no raw IP addresses are stored.
- Advertising - Google Ads, used to measure and improve our marketing.
- Functional - optional functionality and personalisation preferences.
The analytics, advertising, and functional categories are off by default. Google Tag Manager loads with every Google Consent Mode v2 signal denied, and tags in those categories run only after you grant the matching category through the banner. When you make or change a consent choice, we keep a record of the decision - the categories granted or refused, the time, and the random consent identifier - so that we can demonstrate how consent was collected.
You can change or withdraw consent at any time by reopening the cookie preferences. Withdrawing consent stops the affected tags from running from that point on; it does not retroactively delete data already collected, though you can ask us to arrange that (see your rights below).
Legal bases
We rely on your consent (Article 6(1)(a) GDPR) for the analytics, advertising, and functional cookie categories. We rely on our legitimate interest (Article 6(1)(f) GDPR) in responding to correspondence when handling email enquiries. We rely on the same legitimate interest for business prospecting - approaching named people at other organisations about analytics governance - which is set out in full, with the balancing assessment behind it, under "Business contacts we approach" below.
Recipients and transfers
Data collected through Google Tag Manager, GA4, and Google Ads is processed by Google Ireland Limited for users in the EEA, and may be transferred to Google LLC in the United States. Email enquiries, and the prospecting messages described under "Business contacts we approach" below, are handled through Google Workspace, which is provided by the same Google Ireland Limited and may travel the same way. Google states that Google LLC is certified under the EU-US Data Privacy Framework, and that it relies on the standard contractual clauses where a transfer is not covered by an adequacy decision. That statement is about the Google entity rather than about one product, so it covers GA4 data and email alike. We acknowledge that transfer mechanisms may change and will review this policy accordingly.
Retention
The consent cookie persists for six months. GA4 event data is retained for 2 months and GA4 user data for 14 months. Enquiry emails are kept for as long as needed to handle the enquiry and any follow-up.
Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Request erasure of your personal data
- Restrict or object to processing of your personal data
- Data portability
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, contact contact@obscurity.ie. You also have the right to lodge a complaint with the Data Protection Commission (Ireland).
Business contacts we approach
We approach people in other organisations about analytics governance. If you have received a message from us and never gave us your details, this section says where they came from, what we hold, and how to stop it. It is the information Article 14 GDPR requires where personal data was not collected from the person it describes, and it is the section our messages link to.
Who holds the data
Obscurity Ltd, the controller named under "Who we are" above. Any query about this section, and any right exercised under it, goes to the same place: contact@obscurity.ie.
What we hold
Your name, your role or job title, your employer, and a business email address or a LinkedIn profile. Alongside it we hold the result of a scan of your employer's public website - the tags, cookies and consent behaviour our scanner observed on pages anyone can open. The scan looks at the website, not at you. It is not directed at you, and we do not use it to evaluate or infer anything about you. The scan record is private, describes the scanner's own visit rather than any visitor's, and is kept for thirteen months. If you follow a link to our own site, that site's cookie banner applies as described above.
Where it came from
Public professional profiles, including LinkedIn and LinkedIn Sales Navigator, your employer's own website, and the Companies Registration Office and Companies House. We do not scrape LinkedIn and we do not buy lists. The website scan is an automated visit to the organisation's public website, not to any person. We record the source of each contact detail we hold, so if you ask us where we got yours, we can tell you precisely.
Why we use it
To contact the person whose role covers their organisation's website measurement and consent, about analytics governance services. The message describes what we observed on the employer's public website and links to the result. It makes no finding about you, and we do not use automated decision-making or profiling that produces legal or similarly significant effects.
Our lawful basis
Legitimate interests, Article 6(1)(f) GDPR - our interest in offering a professional service to the organisations it is meant for, and the benefit to the recipient of a dated observation about their organisation's website. We have carried out and written down a balancing assessment weighing that interest against the interests, rights and reasonable expectations of the person contacted, and we will share it on request.
We approach people at work, on LinkedIn or by email to a work address at their organisation. We do not send marketing to personal addresses, to sole traders or to unincorporated partnerships, and we do not make marketing calls. If you think we should not have used a channel to reach you, tell us and we will not use it again.
How long we keep it
Contact details are kept for 12 months from the last contact and then deleted, and a follow-up message counts as contact. If you object, we keep a suppression record - the minimum needed to recognise you and stop - indefinitely. That record exists only to keep us from approaching you again.
Who else sees it
The platform each message travels on: LinkedIn where we message you there, and Google Workspace where we email you. We do not sell contact details, we do not pass them to anyone for their own marketing, and we do not give them to the scanned organisation beyond the message itself.
Where it goes
Email is handled through Google Workspace, as set out under "Recipients and transfers" above. Google Workspace is provided by Google Ireland Limited, which may transfer the message to Google LLC in the United States. Google states that Google LLC is certified under the EU-US Data Privacy Framework, and that it relies on the standard contractual clauses where a transfer is not covered by an adequacy decision. A message you receive on LinkedIn is processed by LinkedIn Ireland Unlimited Company, which may transfer it to LinkedIn Corporation in the United States. LinkedIn states that its companies have adopted the standard contractual clauses for those flows, and that LinkedIn Corporation is certified under the EU-US Data Privacy Framework. Beyond those two platforms, prospecting records stay in our own systems and we transfer them nowhere else.
How to stop this
You can object at any time, and you do not have to give a reason. Reply "no" to the message, or write to contact@obscurity.ie. An objection is permanent and it covers every channel: we stop, we do not approach you again on LinkedIn, by email or otherwise, and we do not approach your employer through you.
The rights listed under "Your rights" above apply to this processing too - access, rectification, erasure, restriction and objection. You can also complain to the Data Protection Commission in Ireland, or to the Information Commissioner's Office in the United Kingdom.
Changes to this policy
We may update this policy as the site's tooling changes. The "Last updated" date at the top of this page reflects the most recent revision.