Climb
Privacy Policy
Last updated: 2 July 2026
This is a working draft. It has not been reviewed by a solicitor. Before publishing, especially once you are actively collecting client and end-customer data through the Review Engine, have this checked by a qualified professional — the cost is small relative to the risk.
Who this applies to
This policy explains how Samuel Ryan, trading as Climb ("Climb", "we", "us"), collects and uses personal data. Climb is currently operated as a sole trader and has not yet been incorporated as a limited company. If and when Climb is incorporated, this policy will be updated to reflect the new legal entity.
Climb provides website design and build services, a managed Google review growth service ("Review Engine"), and custom software development, to business clients located in Ireland, the United Kingdom, the United States, and elsewhere.
Data controller
For data collected through the Climb website (contact forms, discovery call bookings, general enquiries), Samuel Ryan is the data controller.
For personal data processed on behalf of a client through the Review Engine (see below), Climb generally acts as a data processor, processing that data under the instructions of the business client, who remains the data controller for their own customers' data. The specific arrangement is set out in the agreement with each client.
What we collect
From visitors to this website
- Name, email address, phone number, and business name, when voluntarily submitted through a contact form, audit request, or discovery call booking
- Information discussed during a discovery call, which may include business details, current website or review setup, and contact preferences
- Basic technical data (see Cookie Policy) such as pages visited and general location, where cookies or analytics are enabled
From clients we work with
- Business and billing contact details
- Any information a client shares with us to complete a project (for example, business branding, copy, and account access needed to build a website or software)
Through the Review Engine, on behalf of clients
Climb's Review Engine sends review requests to a client's own customers by SMS, email, or QR code, on the client's instruction. The exact data processed depends on the individual client and how they choose to use the service, but typically includes:
- Names, phone numbers, and/or email addresses of the client's customers
- Basic transaction or job details needed to time a review request appropriately (for example, that a service was recently completed)
We do not collect this data ourselves. It is provided to us by our client, who is responsible for having a lawful basis to share it with us and to have their customers contacted (see "Review Engine and consent" below).
Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Responding to enquiries, discovery calls, providing quotes | Legitimate interest / steps prior to entering a contract |
| Delivering a website, review, or software project | Performance of a contract with the client |
| Sending review requests on a client's behalf | Performance of our contract with the client, who confirms they have a lawful basis to contact their own customer |
| Site analytics, if enabled | Consent, via cookie banner |
| Legal and accounting records | Legal obligation |
Review Engine and consent
If you have received a review request message from a business that uses Climb's Review Engine, that message was sent on the instruction of that business, using contact details they provided to us. Climb requires clients to confirm they have a lawful basis to contact their customers this way (for example, because the customer is an existing customer of theirs and the message relates to a service recently provided). Climb is not the party who obtained that consent, and if you have questions about why you received a message, your request should be directed to the business that sent it. You can also contact us directly using the details below and we will assist in identifying the sending client and honouring your request.
Every review request message includes a clear way to opt out. Opt-out requests are honoured promptly, however they are made, not only by replying to a specific keyword.
Who we share data with
- Service providers who help us operate (for example, website hosting, email or SMS delivery platforms, and analytics tools), under terms that require them to protect the data appropriately
- We do not sell personal data
- We do not share client end-customer data collected through the Review Engine with anyone other than the service providers needed to deliver the messages themselves
International transfers
Because Climb works with clients and their customers in Ireland, the EU, the UK, and the United States, personal data may be transferred and stored outside the country where it was originally provided. Where this involves transferring personal data out of the EU/EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an equivalent lawful transfer mechanism offered by our service providers.
How long we keep data
- Enquiry and contact form data: kept for 12 months from last contact, unless you ask for earlier deletion
- Client project data: kept for the duration of the engagement and for a reasonable period afterward for legal, accounting, and support purposes
- Review Engine end-customer data: retained only for as long as instructed by the relevant client, and deleted or returned at the end of that engagement in line with our agreement with them
Your rights
If you are in the EU, EEA, or UK, under GDPR / UK GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Request deletion of your data, in certain circumstances
- Object to or restrict certain processing
- Request a copy of your data in a portable format
- Withdraw consent at any time, where we rely on consent
- Complain to a supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie)
If you are in the United States, rights available to you may vary depending on your state of residence. Contact us using the details below and we will do our best to accommodate your request regardless of location.
To exercise any of these rights, contact us at hello@climb.services. We aim to respond within 30 days.
Security
We take reasonable technical and organisational measures to protect the personal data we hold, appropriate to the scale of a small business. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Changes to this policy
We review this policy periodically, and will update it as Climb's services and data processing activities change. The "last updated" date at the top will reflect the most recent revision.
Contact
Samuel Ryan, trading as Climb
hello@climb.services
[Business address — to be added once CRO registration is complete]