Privacy Policy
About this Privacy Policy
This Privacy Policy explains how rest easy handles personal data when you use our website, demo and web application. Our Cookie Policy explains the use of cookies, local storage and optional analytics in more detail.
Who is responsible for your data
rest easy
Operated under the registered business name RestEasy
Registration no. 782525
Athlone, Co. Westmeath, Ireland
Email: talk@resteasy.ie
rest easy is responsible for personal data used to operate its public website, handle enquiries, administer its own customer relationships, provide support, maintain service security and operate optional website analytics.
Where a customer organisation uses the application to manage its own staff and restroom operations, that organisation may determine the purpose of the related workplace and operational records. In that context, rest easy provides the service to the customer organisation and processes the records on its behalf. Staff should normally contact their employer or the relevant customer organisation about those records.
Information we collect
Public website and enquiries
Website contact forms collect name, email address, subject, message and form context. Newsletter update requests collect an email address. Public forms also use technical anti-abuse measures, including submission timing, a honeypot field, rate limiting and Cloudflare Turnstile.
Customer and account administration
The application stores business and site details, including business contact details and site address information. User accounts contain name, email address, optional phone number, role, account status, password credentials stored as a hash, and login-related timestamps. Invitation and password-setup processes use account email addresses and time-limited setup records.
Operational records
Customer organisations can create accounts for managers, staff and other authorised users. Checks can record the user account, control point, associated sign, timestamp, optional notes, IP address, user agent and whether the configured NFC route was used. Issue records can include their linked location, acknowledgement and resolution activity, timestamps and response metrics.
Issue management and reports
Issue records can include issue type, title and description, priority, status, response deadline, acknowledgement and resolution timestamps, resolution notes, response time and the authorised users associated with acknowledgement or resolution. Authorised users can view scoped operational reports and export check records in CSV format; these reports may include staff names and operational activity where the user has permission to access them.
Customer feedback
Public restroom feedback is designed to be anonymous. Feedback records contain the rating or predefined issue selection, associated control point and sign, timestamp, IP address and user agent; they do not intentionally require a member of the public to provide their name or contact details. Technical server logs and anti-abuse measures are separate from the feedback record itself.
Notifications and devices
Where enabled, notifications may process recipient user details, notification content and delivery status. Web push subscriptions store the subscription endpoint, keys, user agent and their association with the relevant account and business context. Session, trusted-device and service-worker technologies support authentication and requested application features.
Support communications
Support and service correspondence may contain the contact details, account information and operational context needed to respond to the request. Technical support is handled through tech@resteasy.ie. Authorised rest easy support personnel may access relevant customer records when needed to diagnose a reported problem or provide support.
How we use information and our legal bases
We use account, business and service data where necessary to provide the service and administer the customer relationship. This processing is necessary for the relevant contract or steps taken at a customer’s request before entering a contract.
We use information for service security, authentication, abuse prevention, troubleshooting, audit trails and service administration where this is necessary for our legitimate interests in operating a secure and reliable service. We consider these interests against the rights and interests of individuals.
We use optional Google Analytics 4 only with your consent. You can withdraw that consent through Cookie settings. Where rest easy processes operational records for a customer organisation, that organisation is responsible for identifying the lawful basis for its underlying workplace and operational processing.
Operational data processed for customers
Operational records help customer organisations maintain check records, evidence completed checks, manage reported issues and produce operational and compliance reporting. NFC use records the use of a configured checkpoint route; it is not presented by the service as precise GPS location tracking. These records may be associated with an authorised user account where applicable and are not intended to support covert employee surveillance.
Reporting and automated decision-making
The application produces operational reports, health scores, check-frequency information and issue-response metrics. These are operational reporting tools. rest easy does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Analytics and cookies
Google Analytics 4 is optional and loads only after a valid analytics preference has been granted. The preference is stored using resteasy_cookie_consent in browser local storage and can be changed through Cookie settings without affecting necessary service processing. See our Cookie Policy for details.
Security and fraud prevention
Cloudflare Turnstile is used on certain public forms for spam, bot and abuse prevention. It is a security measure, not advertising. We also use access controls, authentication, role-based permissions, session protections and security logging appropriate to operating the service.
Notifications and communications
We use contact details to respond to public enquiries and provide account, invitation, password-setup, support and operational service communications. Operational email and push notifications may be sent to authorised recipients about issues and other service activity. The public newsletter form submits an update request; separate marketing preference-management and unsubscribe functionality are future work.
Who we share information with
We share information with service providers only as needed to operate the service, including HostGator / Newfold for website, database and email hosting infrastructure, Cloudflare Turnstile for protected forms, Google Analytics when permission is granted, and browser push services when a user enables push notifications. We may also disclose information where required to protect the service or comply with applicable law. We do not currently operate a live payment-gateway integration; billing and subscription database structures are preparatory only.
International transfers
Some of the service providers used by rest easy process personal data outside the European Economic Area. In particular, our website, database and email infrastructure is currently hosted in the United States. Where required, appropriate safeguards are used for international transfers, including the European Commission's Standard Contractual Clauses.
How long we keep information
rest easy keeps personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the service, maintaining appropriate operational records, resolving support matters, protecting the security of the service and meeting applicable legal obligations.
Operational records associated with an active customer account are generally retained while that account remains active. Account information required to provide and administer an active customer account may be retained while the account remains active and for as long afterwards as reasonably necessary for account closure, legitimate business purposes and applicable legal obligations.
Technical support correspondence handled through tech@resteasy.ie is normally retained for up to six months after the support matter has been closed, unless it needs to be retained for longer for an ongoing dispute, security investigation, legal obligation, or the establishment, exercise or defence of legal claims. Other business correspondence, including correspondence sent to talk@resteasy.ie, is retained for as long as reasonably necessary for the purpose for which it was received and any related legitimate business or legal requirements.
Different retention periods may apply where information must be retained for legal, accounting, security or dispute-resolution purposes. Information removed from active systems may remain temporarily in protected backup copies until those backups are overwritten or expire in accordance with applicable backup procedures. The current implementation defines a 24-hour retention period for expired or completed guided-demo run records after their expiry.
Billing, cancellation, account-closure and deletion workflows are not implemented in the current public service. The 90-day cancellation grace lifecycle is not stated as a live retention commitment here.
Security
We use technical and organisational measures designed to protect information, including authentication, role-based access controls, secure session and trusted-device protections, and access restrictions. No method of transmission or storage is completely secure, but we work to protect data appropriate to the service.
Your data-protection rights
Depending on the circumstances and applicable law, you may have rights to request access, correction, erasure, restriction, objection and portability, and to withdraw consent where processing is based on consent. To make a request, contact talk@resteasy.ie. Where records are processed for a customer organisation, requests may need to be made to that organisation as controller; rest easy can assist it as appropriate.
Complaints
You may complain to the Irish Data Protection Commission if you are unhappy with how your personal data is handled. You do not need to contact rest easy before making a complaint.
Children
rest easy is intended for business users and restroom visitors, not for children creating consumer accounts. We do not knowingly offer account services directly to children. Anonymous public feedback may be submitted by a restroom visitor, so we do not make a blanket claim that children’s data can never be processed.
Special-category and criminal-offence data
rest easy does not intentionally request special-category personal data or criminal-offence data through ordinary use of the service. Free-text fields, such as enquiries, notes or issue descriptions, could contain information provided by a user; please avoid including unnecessary sensitive personal information.
Changes to this Privacy Policy
We may update this Privacy Policy when the service or its use of personal data changes. The date at the top of this page shows when it was last updated.
Contact
For privacy questions, contact rest easy at talk@resteasy.ie.