top of page

Zest Digital Marketing Agency

PRIVACY POLICY

  • Privacy Policy

  • Effective date: 5 August 2026
    Last updated: 5 August 2026
     

  • 1. Introduction
     

  • Zest Digital respects your privacy and is committed to protecting your personal data.

  • This Privacy Policy explains how Zest Digital (“Zest Digital”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data. It also explains the rights available to individuals under applicable data-protection law.

  • This Privacy Policy applies when you:

  • visit our website;

  • contact or enquire about our services;

  • become or represent one of our clients;

  • subscribe to our marketing communications;

  • interact with us through social media;

  • participate in photography, video, podcast or content-production projects;

  • attend a meeting, consultation or event;

  • apply for employment or freelance work with us;

  • provide services to us as a supplier or contractor; or

  • otherwise interact with Zest Digital.
     

  • 2. Who We Are

  • Zest Digital is an Irish digital marketing agency providing services that may include:

  • digital marketing strategy;

  • social media management;

  • content creation;

  • photography and video production;

  • podcast and audio production;

  • website design and management;

  • search engine optimisation;

  • email marketing;

  • digital advertising;

  • campaign management;

  • branding and creative services;

  • analytics and reporting; and

  • related marketing consultancy services.

  • Contact details

  • Business name: Zest Digital
     

  • For most of the activities described in this Privacy Policy, Zest Digital acts as the data controller. This means we decide why and how personal data is processed.

  • When we process personal data solely on a client’s documented instructions, we normally act as the client’s data processor. Further information about this relationship is provided in Section 10.
     

  • 3. Personal Data We May Collect

  • The information we collect depends on how you interact with us and the services involved.

  • 3.1 Identity and contact information

  • This may include:

  • your name;

  • job title;

  • employer or organisation;

  • business or postal address;

  • email address;

  • telephone number;

  • social media username; and

  • other contact information you provide.
     

  • 3.2 Enquiry and communication information

  • This may include:

  • contact-form submissions;

  • emails and messages;

  • telephone and video-call information;

  • meeting notes;

  • project briefs;

  • quotations and proposals;

  • feedback;

  • reviews;

  • survey responses; and

  • records of support or customer-service requests.
     

  • 3.3 Client and commercial information

  • This may include:

  • contracts and statements of work;

  • project requirements;

  • account information;

  • marketing objectives;

  • brand assets;

  • campaign information;

  • billing details;

  • invoices;

  • transaction and payment records;

  • service history;

  • correspondence;

  • business-development information; and

  • information required to manage our client relationship.

  • We do not normally collect or store complete payment-card details. Where online payment services are used, payment information may be processed directly by an authorised third-party payment provider under its own privacy terms.
     

  • 3.4 Website and technical information

  • When you visit our website or interact with our digital services, we may collect:

  • IP address;

  • browser type and version;

  • operating system;

  • device type;

  • approximate location derived from your IP address;

  • referring website;

  • pages viewed;

  • links selected;

  • date and time of visits;

  • session duration;

  • cookie identifiers;

  • advertising identifiers;

  • conversion information;

  • website interaction information;

  • server logs; and

  • security and diagnostic information.

  • Non-essential analytics and advertising technologies will only be activated where permitted by law and, where required, after valid consent has been provided.
     

  • 3.5 Marketing information

  • This may include:

  • newsletter subscriptions;

  • marketing preferences;

  • consent records;

  • event attendance;

  • campaign engagement;

  • email interactions, where tracking is enabled;

  • responses to marketing communications;

  • professional interests;

  • the source of a business contact; and

  • unsubscribe, objection or suppression records.
     

  • 3.6 Social media and advertising information

  • When you interact with Zest Digital through social media or advertising platforms, we may receive information made available through the relevant platform, including:

  • your public profile information;

  • username;

  • comments;

  • messages;

  • reactions;

  • campaign interactions;

  • advertising audience information; and

  • information submitted through lead-generation forms.

  • Social media and advertising platforms also process personal data for their own purposes under their respective privacy policies and terms.
     

  • 3.7 Photography, video and audio information

  • As part of our services, we may collect and process:

  • photographs;

  • video footage;

  • audio and voice recordings;

  • podcast recordings;

  • interviews;

  • testimonials;

  • event footage;

  • names and job titles;

  • information shared during recordings; and

  • consent forms, releases and usage permissions.

  • Where appropriate, we or our client will explain how the content will be used and obtain the permissions required for recording, editing, publication, advertising or promotional use.
     

  • 3.8 Recruitment information

  • If you apply for employment, freelance work or a contractor role, we may process:

  • your CV;

  • contact information;

  • employment history;

  • qualifications;

  • portfolio or work samples;

  • references;

  • interview notes;

  • availability;

  • remuneration expectations; and

  • information required to assess your suitability.
     

  • 3.9 Special-category personal data

  • We do not normally seek to collect special-category personal data, such as information concerning health, ethnicity, religion, political opinions, trade-union membership, sexual orientation or biometric identification.

  • Where processing such information is necessary, we will only do so when a valid legal basis and an additional condition under applicable data-protection law are available.

  • Please avoid sending sensitive personal information that is not necessary for your interaction with us.
     

  • 4. How We Collect Personal Data

  • We may collect personal data:

  • directly from you;

  • through our website and online forms;

  • through emails, telephone calls, meetings and video calls;

  • through booking, survey or newsletter systems;

  • through social media and advertising platforms;

  • from our clients when we provide services on their behalf;

  • during content-production projects;

  • from suppliers, contractors and business partners;

  • from event organisers and referral partners;

  • from professional networks and business directories;

  • from publicly available company websites and professional profiles;

  • through cookies and similar technologies; and

  • from technology and analytics providers.

  • Where we obtain personal data from a source other than the individual, we will provide the information required by law unless an applicable exception applies.
     

  • 5. Why We Process Personal Data

  • We only process personal data where we have a lawful basis for doing so.

  • 5.1 Responding to enquiries

  • We process contact and enquiry information to:

  • respond to questions;

  • discuss potential projects;

  • arrange consultations;

  • prepare quotations or proposals; and

  • take steps requested before entering into a contract.

  • Our lawful basis is normally taking steps at your request before entering into a contract or our legitimate interest in responding to business enquiries.
     

  • 5.2 Providing our services

  • We process client and project information to:

  • provide agreed services;

  • manage campaigns and accounts;

  • create and deliver content;

  • communicate about projects;

  • meet deadlines;

  • manage revisions and approvals;

  • provide reports;

  • administer client accounts; and

  • maintain service quality.

  • Our lawful basis is normally the performance of a contract or our legitimate interests in delivering and managing services where the contract is with an organisation rather than the individual concerned.
     

  • 5.3 Business administration

  • We process information to:

  • issue quotations and invoices;

  • manage payments;

  • maintain financial records;

  • manage suppliers and contractors;

  • administer our business;

  • maintain insurance records;

  • resolve disputes; and

  • obtain professional advice.

  • Our lawful basis is normally contractual necessity, compliance with a legal obligation or our legitimate interests in operating and protecting our business.
     

  • 5.4 Website operation, security and improvement

  • We process website and technical information to:

  • operate and maintain our website;

  • protect our systems;

  • prevent misuse, fraud and cyber threats;

  • identify technical problems;

  • understand website performance;

  • improve the user experience; and

  • measure the effectiveness of our services and campaigns.

  • Our lawful basis is normally our legitimate interests in maintaining a functional and secure website. Where non-essential cookies or tracking technologies are involved, we rely on consent where required.
     

  • 5.5 Marketing and business development

  • We may process personal data to:

  • provide requested newsletters or updates;

  • promote relevant services;

  • contact existing or prospective business clients;

  • manage marketing preferences;

  • measure campaign engagement; and

  • develop business relationships.

  • Depending on the circumstances, our lawful basis may be consent or our legitimate interests in promoting and developing our business.

  • Electronic marketing communications will only be sent where permitted under applicable law. Where consent is required, we will obtain it before sending the communication.

  • You may unsubscribe or object to direct marketing at any time. We may retain a minimal suppression record to ensure that your preference continues to be respected.
     

  • 5.6 Social media and advertising

  • We may process information to:

  • manage our social media pages;

  • respond to comments and messages;

  • publish content;

  • administer competitions or campaigns;

  • create advertising audiences;

  • measure campaign performance;

  • generate leads; and

  • promote Zest Digital’s services.

  • Our lawful basis may be consent, contractual necessity or our legitimate interests in communicating with audiences and promoting our business.

  • Where a social media or advertising platform determines purposes and methods of processing independently, or jointly with us, its own privacy policy and contractual terms will also apply.
     

  • 5.7 Photography, video, podcast and content production

  • We may process photographs, recordings and related information to:

  • plan and produce content;

  • edit and deliver client projects;

  • publish approved material;

  • advertise products or services;

  • produce social media content;

  • create podcasts, interviews or testimonials; and

  • maintain an authorised portfolio of our work.

  • Depending on the circumstances, our lawful basis may be:

  • consent;

  • the performance of a contract;

  • our legitimate interests;

  • the legitimate interests of our client; or

  • another lawful basis available under applicable law.

  • We will not rely on this Privacy Policy alone as permission to use an identifiable person’s image, voice or testimonial where a separate release, consent or contractual permission is appropriate.
     

  • 5.8 Recruitment

  • We process applicant information to:

  • assess applications;

  • communicate with candidates;

  • arrange interviews;

  • verify information;

  • select employees or contractors; and

  • maintain appropriate recruitment records.

  • Our lawful basis is normally taking steps before entering into a contract, compliance with legal obligations or our legitimate interests in recruiting suitable people.
     

  • 5.9 Legal and regulatory purposes

  • We may process personal data to:

  • comply with applicable law;

  • respond to lawful requests;

  • protect our legal rights;

  • enforce agreements;

  • establish, exercise or defend legal claims;

  • investigate suspected misconduct; and

  • manage security incidents.

  • Our lawful basis is normally compliance with a legal obligation or our legitimate interests in protecting Zest Digital, our clients and other individuals.
     

  • 6. Legitimate Interests

  • Where we rely on legitimate interests, we consider:

  • whether there is a genuine and lawful business purpose;

  • whether the processing is necessary for that purpose;

  • the nature of the personal data;

  • the reasonable expectations of the individual;

  • the potential effect on the individual; and

  • whether appropriate safeguards can reduce any risk.

  • You may object to processing based on legitimate interests by contacting us using the details in Section 2.
     

  • 7. Cookies and Tracking Technologies

  • Our website may use cookies and similar technologies.

  • Cookies may be used for:

  • essential website operation;

  • security;

  • remembering preferences;

  • measuring website performance;

  • analytics;

  • embedded content;

  • advertising;

  • conversion measurement; and

  • remarketing.

  • Strictly necessary technologies may be used without consent where they are required to provide a service requested by the visitor or to operate the website securely.

  • Analytics, advertising and other non-essential technologies will not be activated until valid consent has been provided where consent is legally required.

  • Visitors must be able to:

  • accept or reject non-essential cookies;

  • make choices by cookie category;

  • withdraw or change consent; and

  • access clear information about the cookies and technologies used.

  • Further information should be provided in our separate Cookie Policy and through our cookie preference tool.
     

  • 8. Direct Marketing

  • We may send marketing communications about services that we believe may be relevant to recipients where we are legally permitted to do so.

  • We will:

  • identify Zest Digital as the sender;

  • use contact information fairly and lawfully;

  • obtain consent where required;

  • maintain appropriate consent and preference records;

  • provide a clear method of opting out;

  • respect objections and unsubscribe requests; and

  • avoid disguising or concealing the identity of the sender.

  • You may object to direct marketing at any time by:

  • selecting the unsubscribe option in an email;

  • replying to the communication;

  • changing your available preferences; or

  • contacting us using the details in Section 2.
     

  • Once you object to direct marketing, we will stop using your personal data for that purpose. We may keep limited information on a suppression list to ensure we do not contact you again contrary to your request.
     

  • 9. When We Share Personal Data

  • We may share personal data with carefully selected third parties where this is necessary for the purposes described in this Privacy Policy.

  • These may include:

  • website hosting and domain providers;

  • cloud storage providers;

  • email and communication providers;

  • customer relationship management systems;

  • project-management platforms;

  • analytics providers;

  • social media and advertising platforms;

  • email marketing providers;

  • website developers;

  • photographers, videographers and editors;

  • podcast and audio-production providers;

  • freelance specialists and subcontractors;

  • payment providers;

  • accountants and bookkeepers;

  • legal advisers;

  • insurers;

  • IT and cybersecurity providers;

  • professional consultants;

  • regulators, public authorities and law-enforcement bodies; and

  • prospective purchasers or advisers involved in a legitimate business sale, restructuring or investment.

  • We only share personal data where:

  • it is necessary for a legitimate purpose;

  • an appropriate lawful basis exists;

  • the recipient is subject to suitable confidentiality or data-protection obligations;

  • the disclosure is required by law; or

  • you have authorised the disclosure.

  • We do not sell personal data to third parties.
     

  • 10. Client Data and Our Role as a Data Processor

  • When a client gives Zest Digital access to personal data for the purpose of delivering services, the client will normally remain the data controller and Zest Digital will act as a data processor.

  • This may apply where we:

  • manage a client’s mailing list;

  • access a client’s CRM;

  • administer social media accounts;

  • manage advertising audiences;

  • process website enquiries;

  • operate lead-generation campaigns;

  • access customer information;

  • prepare analytics or reports; or

  • process personal data through a client’s systems.

  • In these circumstances:

  • we process personal data only on the client’s documented instructions;

  • the client is responsible for establishing the appropriate lawful basis;

  • the client is responsible for providing necessary privacy information;

  • the client is responsible for the accuracy and legality of data supplied to us;

  • we apply appropriate confidentiality and security measures;

  • we only appoint sub-processors in accordance with the applicable agreement;

  • we assist the client with relevant data-protection obligations where required; and

  • processing is governed by a written contract or Data Processing Agreement.

  • Zest Digital may refuse an instruction that we reasonably believe would breach applicable data-protection law.

  • Some activities may involve Zest Digital and a client acting as separate or joint controllers. Where required, responsibilities will be addressed in the relevant service agreement.
     

  • 11. International Transfers

  • Some service providers, platforms or subcontractors may process personal data outside Ireland or the European Economic Area.

  • Where personal data is transferred internationally, we will take appropriate steps to ensure that the transfer is lawful. These may include:

  • transferring data to a country recognised as providing an adequate level of protection;

  • using approved Standard Contractual Clauses;

  • relying on another legally recognised transfer mechanism;

  • carrying out an appropriate transfer assessment; and

  • applying supplementary technical or organisational safeguards where necessary.

  • Further information about safeguards relevant to a particular transfer may be requested using the contact details in Section 2.
     

  • 12. Data Retention

  • We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, contractual and reporting requirements.

  • When determining a retention period, we consider:

  • the nature and sensitivity of the information;

  • the purpose for which it was collected;

  • the period during which it remains relevant;

  • contractual requirements;

  • legal and regulatory obligations;

  • applicable limitation periods;

  • the risk associated with continued retention; and

  • whether the information can be securely deleted or anonymised.
     

  • Our general retention approach is as follows:

  • Client, contract and financial records

  • Client agreements, invoices, payment information and relevant accounting records may generally be retained for the duration of the relationship and for at least six years afterwards where required for tax, accounting, contractual or legal purposes.

  • Enquiries and unsuccessful proposals

  • Information relating to an enquiry or proposal that does not become a client engagement may generally be retained for up to 24 months after the last meaningful interaction, unless a shorter or longer period is justified.
     

  • Marketing information

  • Marketing information may be retained while you remain subscribed or while a lawful business-development purpose continues. Unsubscribe and objection information may be retained for as long as necessary to ensure that your preference is respected.

  • Content-production files

  • Raw and completed photography, video and audio files may be retained for the period agreed with the client, for legitimate project archiving, or for authorised portfolio use. Retention arrangements may also be set out in the relevant contract.

  • Recruitment information

  • Information relating to an unsuccessful applicant may generally be retained for up to 12 months after the recruitment process, unless the applicant agrees to a longer period or a legal reason requires further retention.

  • Website and analytics information

  • Retention periods for website logs, analytics data and cookies depend on the technology used and will be described in our Cookie Policy or cookie preference tool.

  • Personal data may be retained for longer where necessary to investigate a complaint, establish or defend legal claims, comply with law or respond to a regulatory investigation.

  • When information is no longer required, it will be securely deleted, destroyed or anonymised.
     

  • 13. Data Security

  • We take reasonable and proportionate technical and organisational measures to protect personal data against:

  • unauthorised access;

  • accidental loss;

  • unlawful use;

  • alteration;

  • disclosure;

  • destruction; and

  • other forms of unauthorised processing.

  • Depending on the nature of the processing, measures may include:

  • access controls;

  • password protection;

  • multi-factor authentication;

  • encryption;

  • secure cloud services;

  • device security;

  • data backups;

  • confidentiality obligations;

  • supplier checks;

  • staff awareness;

  • limited access based on business need; and

  • incident-response procedures.

  • No online service or method of electronic storage is completely secure. Although we take reasonable steps to protect personal data, we cannot guarantee absolute security.

  • Where a personal data breach occurs, we will assess it and make any notifications required under applicable law.
     

  • 14. Your Data-Protection Rights

  • Depending on the circumstances, you may have the right to:

  • receive information about how your personal data is processed;

  • request access to your personal data;

  • request correction of inaccurate or incomplete information;

  • request deletion of your personal data;

  • request restriction of processing;

  • object to processing based on legitimate interests;

  • object at any time to processing for direct marketing;

  • receive certain personal data in a structured, commonly used and machine-readable format;

  • request the transfer of eligible data to another controller;

  • withdraw consent at any time where processing is based on consent; and

  • request safeguards relating to certain international transfers.
     

  • These rights are not absolute and may be subject to legal conditions or exemptions.

  • Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

  • To exercise a right, contact us using the details in Section 2. Please describe your request clearly.

  • We may request information reasonably necessary to confirm your identity and protect personal data from unauthorised disclosure.
     

  • We will respond within the timeframe required by applicable law. Where a request is complex or numerous, the response period may be extended as permitted by law, and we will explain the reason for the extension.

  • We do not normally charge a fee for handling a data-protection request. A reasonable fee may apply, or a request may be refused, where it is manifestly unfounded or excessive and the law permits us to do so.
     

  • 15. Automated Decision-Making

  • Zest Digital does not currently use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

  • If this changes, we will provide the information and safeguards required by applicable law.

  • Advertising platforms may use automated technologies under their own terms and privacy policies to select or deliver advertisements.
     

  • 16. Children’s Personal Data

  • Our website and services are primarily intended for businesses and adults. We do not knowingly use our website to collect personal data directly from children.

  • Where children appear in photography, video, audio, social media or advertising content, appropriate consent, parental or guardian permission, client instructions and safeguarding measures must be obtained where required.

  • Clients must inform Zest Digital where a project involves children so that suitable permissions and controls can be agreed before production or publication.
     

  • 17. Third-Party Websites and Platforms

  • Our website and communications may contain links to third-party websites, embedded content or social media platforms.

  • Those third parties may collect and process personal data independently. Zest Digital is not responsible for the privacy practices, security or content of third-party services that we do not control.

  • You should review the privacy information of the relevant third party before providing personal data or using its services.
     

  • 18. Complaints

  • Please contact Zest Digital first if you have a concern about how we process personal data. We will take the concern seriously and try to resolve it promptly.
     

  • You also have the right to raise a concern or lodge a complaint with the Irish Data Protection Commission or another competent supervisory authority.

  • Contact details for the Irish Data Protection Commission are available through its official website.
     

  • 19. Changes to This Privacy Policy

  • We may update this Privacy Policy where:

  • our services or processing activities change;

  • we introduce new technology or providers;

  • our business structure changes;

  • legal or regulatory requirements change; or

  • clarification is required.

  • The current version will be published on our website with its effective date and latest revision date.

  • Where a change is material, we may provide additional notice where appropriate.
     

  • 20. Contact Zest Digital

  • For questions about this Privacy Policy, to exercise a data-protection right or to make a privacy complaint, contact: Zest Digital

Zest logo_edited.jpg
bottom of page