Privacy Policy
How Nutrapi Ltd collects, uses and protects personal data, in line with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Last updated: 3 June 2026
1. Who we are
Nutrapi Ltd (“Pharmin”, “we”, “us” or “our”) is the data controller responsible for the personal data described in this policy. We provide software development, communications automation and consultancy services to businesses. We do not sell, supply, prescribe or dispense medications, and we do not provide healthcare or medical services directly.
Our data controller and contact details are:
Nutrapi LtdData Controller: Kieran Walkin
Glasshouse GH2, Dun Laoghaire, Co. Dublin, Ireland
Email: kieran@pharmin.io
Phone: +353 86 782 7399
Company Registration Number (CRO): 721111
2. Scope of this policy
This policy explains how we handle personal data when you visit our website, contact us, or engage our services. It covers data for which Pharmin is the controller — primarily our own website and business contacts.
When we deliver projects for clients (for example operating Pharmin, WhatsApp automations or integrations on their behalf), we typically act as a data processor, processing end-customer data only on the documented instructions of our client, who remains the controller. That processing is governed by a separate Data Processing Agreement with the relevant client, and the client’s own privacy notice applies to their customers.
3. The information we collect
Information you give us
When you complete our contact form or email us, we collect the information you provide — typically your name, email address and the contents of your message. Our contact form is processed on our behalf by Web3Forms, which delivers your submission to us by email.
Information collected automatically
Our hosting provider keeps standard server logs that may include your IP address, browser type, the pages you request and the date and time of access. These are used for security and to keep the website running reliably. Our website uses strictly necessary cookies to function, and analytics cookies only where you consent to them through our cookie banner.
Where you consent through our cookie banner, we use two analytics providers. PostHog (PostHog, Inc., with data hosted in the European Union) provides website analytics — the pages you view and how you navigate — and, where enabled, a session replay in which any text you type into forms is masked and not captured. HubSpot (HubSpot, Inc., United States) provides our customer-relationship platform. Neither sets a cookie nor collects any data until you have given analytics consent, and you can withdraw that consent at any time from the cookie banner.
Email tracking. Where we send you an individual business email, it may contain a small tracking image and links that record whether the message was opened and whether you followed a link. If you follow such a link, we may associate your later activity on this website with your contact record. We rely on our legitimate interests in business-to-business communication for this, and you may object at any time using the contact details below; blocking remote images in your email client will also prevent open tracking.
Information processed for clients
In the course of delivering services we may process personal data belonging to our clients’ customers (for example contact details and message content flowing through WhatsApp, SMS, voice or email channels). We process this data only as a processor, under our client’s instructions, and do not use it for our own purposes.
4. How we use your data and our legal bases
We use personal data for the following purposes, relying on the lawful bases set out in Article 6 GDPR:
- To respond to enquiries you send us — on the basis of our legitimate interest in answering and following up with people who contact us, or to take steps at your request before entering a contract.
- To provide and manage our services to clients — on the basis of performance of a contract.
- To operate and secure our website — on the basis of our legitimate interest in maintaining a safe, functional website.
- To comply with legal obligations — for example accounting, tax and record-keeping requirements.
5. Who we share data with
We do not sell your personal data. We share it only with trusted service providers who help us run our business, and only as far as necessary:
- Hosting — our website is hosted by Hostinger, which stores the website and server logs.
- Contact form processing — Web3Forms processes contact-form submissions and forwards them to us.
- Communications platforms — where we operate messaging services, data may pass through platforms such as Meta Platforms Ireland Ltd (WhatsApp Business) and other messaging, telephony or email providers, in line with the relevant client engagement.
- Professional advisers and authorities — where required by law or to establish, exercise or defend legal claims.
Each provider is bound to protect personal data and to use it only for the agreed purposes.
6. International transfers
Some of our service providers may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, so that your data continues to receive an equivalent level of protection.
7. How long we keep data
We keep personal data only for as long as necessary for the purposes described above. Enquiry and contact data is kept for as long as needed to deal with your request and for a reasonable period afterwards; client project data is retained for the duration of the engagement and any period required by our contract or by law, after which it is deleted or returned.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to our processing of your data;
- data portability; and
- withdraw consent at any time, where we rely on consent.
To exercise any of these rights, or to request deletion of your data, contact us at kieran@pharmin.io. We will respond within one month. If your data is processed by us on behalf of a client, we will direct your request to that client as the controller.
9. Complaints
If you have a concern about how we handle your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
10. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure. No method of transmission or storage is completely secure, but we work to keep our systems and our providers’ systems protected.
11. Children
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time. The current version is always available on this page, with the “last updated” date shown above.
13. Contact us
For any question about this policy or your personal data, contact kieran@pharmin.io or write to us at Glasshouse GH2, Dun Laoghaire, Co. Dublin, Ireland.