PRIVACY NOTICE
Liscaragh Software
Dave Devery Consulting Ltd
Version: 1.1
Effective date: 28 July 2026
This Privacy Notice explains how Dave Devery Consulting Ltd, trading as Liscaragh Software, collects, uses, stores and shares personal data.
Dave Devery Consulting Ltd is an Irish company registered under company number 772249, with its registered address at Liscaragh, Puckane, Co. Tipperary, Ireland.
In this notice, Liscaragh Software, we, us and our refer to Dave Devery Consulting Ltd.
For the purposes of the General Data Protection Regulation and the Data Protection Act 2018, Dave Devery Consulting Ltd is the data controller for the personal data described in this notice.
1. WHO WE ARE
Liscaragh Software is the trading name of Dave Devery Consulting Ltd.
We develop and sell Liscaragh Migrate, a software product used by IT professionals, internal IT teams and managed service providers to migrate data into Microsoft 365.
You can contact us about this notice or your personal data at support@liscaragh.com.
2. WHAT THIS NOTICE COVERS
This notice covers personal data we collect:
a. through our website;
b. when you contact us;
c. when you request an evaluation version or demonstration;
d. when you purchase or activate Liscaragh Migrate;
e. when you request support;
f. when you receive marketing communications from us; and
g. when you otherwise engage with Liscaragh Software in a business or professional capacity.
This notice does not cover data migrated using Liscaragh Migrate.
When you use the Product, you control the source and destination systems and decide what data is migrated. Liscaragh Software does not receive, host or store that data as part of a migration.
We are not a data controller or processor of Customer Data merely because it is migrated using the Product. The Customer remains responsible for its own obligations as controller or processor of that data.
Further information is available in our End User Licence Agreement, including the provisions concerning Customer-controlled operation and data protection.
If you are an individual whose files or personal data were migrated by one of our customers, we do not have visibility of that data and have no direct relationship with you in connection with the migration. Any questions about that data should be directed to the organisation that carried out the migration.
3. PERSONAL DATA WE COLLECT
3.1 Enquiries and evaluation requests
If you contact us with a pre-sales enquiry, request an evaluation version, book a demonstration or complete a form on our website, we may collect:
a. your name;
b. your business email address;
c. your telephone number, where provided;
d. your company or organisation name;
e. your role or job title, where provided;
f. the content of your message or form submission; and
g. details about the type of migration or Product requirement you describe.
We use this information to respond to your enquiry, arrange a demonstration, provide the evaluation version and discuss the Product with you.
Our legal basis is taking steps at your request before entering into a contract and our legitimate interest in responding to enquiries and developing commercial relationships with prospective customers.
3.2 Purchases, invoices and licensing
Purchases are processed securely through Stripe, our payment processor. Stripe collects and holds your card details directly; we do not receive or store full card numbers ourselves.
When you place an order, whether through our website, by email or through another agreed business channel, we may collect:
a. your name;
b. your business email address;
c. your company name;
d. your billing address;
e. your VAT number, where applicable;
f. the number of tenant licences required;
g. purchase order information;
h. invoice and payment details, excluding full card numbers, which Stripe holds directly;
i. the content of any notes or instructions you provide; and
j. correspondence relating to the purchase.
When you activate the Product, we may record:
a. the Microsoft 365 tenant ID for the Licensed Tenant;
b. the licence identifier;
c. the licence issue date;
d. the activation date;
e. the Product version;
f. the version of the End User Licence Agreement accepted;
g. the date and time of acceptance;
h. IP address information associated with activation; and
i. limited device or system information necessary to complete or verify activation.
We use this information to:
a. process and fulfil your order;
b. facilitate invoicing, which Stripe issues directly to you as merchant of record;
c. provide and administer your licence;
d. enforce the per-tenant licensing model;
e. prevent fraud, licence misuse and unauthorised use;
f. maintain evidence of contractual acceptance;
g. provide customer support; and
h. meet our accounting, tax and legal obligations.
Our legal bases are performance of our contract with you, our legitimate interest in preventing fraud and licence misuse, and compliance with our legal obligations, including Irish accounting and tax requirements.
Financial and invoicing information may be shared with our accountant, bookkeeper or other professional adviser where reasonably necessary.
3.3 Support requests
If you contact support@liscaragh.com, we collect:
a. your name and email address;
b. the content of your support request;
c. Product and licence information relevant to the issue;
d. technical information you provide about your environment;
e. logs, screenshots, error messages or diagnostic files you choose to send; and
f. correspondence relating to the investigation and resolution of the issue.
You should remove passwords, authentication tokens, private keys, credentials, secrets and unnecessary personal data before sending support material.
You should also avoid sending special category data, criminal-offence data or sensitive customer content unless it is strictly necessary and has been agreed with us in advance.
We use support information to investigate, diagnose and respond to your request, reproduce reported issues, maintain support records and improve the reliability of the Product.
Our legal bases are performance of our contract with you and our legitimate interest in providing effective support and maintaining the security and reliability of the Product.
Support is currently handled directly through our Microsoft 365 mailbox. We do not currently use a separate outsourced helpdesk or ticketing platform.
Where support material contains personal data relating to another individual, Liscaragh Software may act as a processor in respect of that limited data. The terms governing that processing are set out in our Data Processing Agreement.
3.4 Website analytics
Where you consent through our cookie banner, we use Google Analytics to understand how visitors use our website.
Analytics information may include:
a. pages viewed;
b. navigation through the website;
c. how you arrived at the website;
d. approximate visit duration;
e. browser and device type;
f. operating system;
g. screen size;
h. broad geographic information;
i. technical identifiers; and
j. cookie identifiers.
We use this information to understand website performance, identify useful content, improve navigation and assess how visitors find the website.
Our legal basis is your consent.
Google Analytics is not activated and analytics cookies are not placed unless you actively accept analytics cookies.
You can withdraw or change your consent at any time using Cookie Preferences in the website footer.
Further information is available in our Cookie Policy.
3.5 Marketing communications
We may occasionally send marketing communications concerning Liscaragh Migrate, Product updates, demonstrations, related products or services.
For existing customers, we may rely on our legitimate interest and the limited soft opt-in available under Regulation 13 of the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, as amended, where:
a. we obtained your contact details during a sale or negotiation for a sale;
b. the communication concerns our own similar products or services;
c. you were given a clear opportunity to opt out when your details were collected; and
d. each marketing message includes a clear opportunity to opt out.
For prospective customers or other recipients who do not fall within the soft opt-in, we rely on your consent.
Marketing communications are currently sent manually from our own mailbox rather than through a bulk email or marketing automation platform.
You can opt out at any time by replying to a marketing email or contacting support@liscaragh.com.
Opting out of marketing does not affect transactional or service communications, including licence delivery, invoices, security notices and support replies.
3.6 Local evaluation allowance
The evaluation version may track its free allowance using a one-way cryptographic hash derived from the Microsoft 365 tenant ID.
This value is stored locally on the computer running the Product. It is not transmitted to Liscaragh Software and cannot reasonably be used by us to identify an individual.
We include this information for transparency about how the evaluation version operates.
4. PERSONAL DATA WE DO NOT RECEIVE DURING A MIGRATION
Liscaragh Migrate is designed to operate within the Customer's own environment.
As part of a migration job:
a. Customer Data is transferred directly between systems controlled or authorised by the Customer;
b. Liscaragh Software does not receive a copy of migrated files;
c. Liscaragh Software does not host migrated files;
d. Liscaragh Software does not inspect the contents of migrated files;
e. Liscaragh Software does not determine what data is migrated; and
f. Liscaragh Software does not determine who receives access to the migrated data.
The Product may create local logs, reports and audit records within the Customer's environment. Those records remain under the Customer's control unless the Customer chooses to send some of them to us for support.
5. WHO WE SHARE PERSONAL DATA WITH
We may share personal data with the following recipients where necessary.
5.1 Microsoft
We use Microsoft 365 for business email, correspondence, document storage and support communications.
Microsoft Ireland Operations Limited and other Microsoft group companies may process personal data on our behalf as part of providing those services.
5.2 Stripe
Stripe Payments Europe, Limited provides payment processing, billing and fraud prevention for our purchases, as an independent controller under its own privacy documentation.
Stripe collects and holds your card details directly; we do not receive or store full card numbers ourselves.
5.3 Google
Where you consent to analytics cookies, Google Ireland Limited provides Google Analytics on our behalf.
Google may process analytics information in accordance with its own privacy documentation and the contractual arrangements governing Google Analytics.
5.4 Professional advisers
We may share personal data with professional advisers, including accountants, bookkeepers, tax advisers, auditors, insurers or solicitors, where reasonably necessary to operate our business, meet legal obligations or establish, exercise or defend legal claims.
5.5 Public authorities and regulators
We may disclose personal data to a court, regulator, public authority, tax authority or law enforcement body where:
a. disclosure is required by law;
b. disclosure is necessary to comply with a lawful request;
c. disclosure is necessary to protect our legal rights; or
d. disclosure is necessary to establish, exercise or defend a legal claim.
We do not sell personal data.
We do not share personal data with third parties for their own independent marketing purposes.
6. INTERNATIONAL TRANSFERS
We primarily store and process personal data within the European Economic Area.
Some of our service providers, including Microsoft, Stripe and Google, may transfer personal data outside the European Economic Area or permit access to it from another country as part of providing their services.
Where personal data is transferred outside the European Economic Area, the transfer must be supported by a lawful transfer mechanism under the GDPR.
Depending on the circumstances, this may include:
a. an adequacy decision adopted by the European Commission;
b. the European Commission's Standard Contractual Clauses;
c. the EU-US Data Privacy Framework, where applicable; or
d. another lawful safeguard recognised under applicable data protection law.
We will update this notice if we introduce a service provider or processing arrangement that materially changes the international transfer position described here.
7. HOW LONG WE KEEP PERSONAL DATA
We retain personal data only for as long as reasonably necessary for the purposes described in this notice.
Our normal retention periods are as follows.
7.1 Enquiries and evaluation requests
We normally retain enquiry, demonstration and evaluation correspondence for up to 3 years after our last meaningful interaction with you.
We may delete it earlier where it is no longer required.
7.2 Billing, invoice and tax records
We retain invoices, payment records and related accounting information for at least 7 years, in line with Irish tax and accounting record-keeping requirements.
7.3 Licensing and contract records
We retain licence, activation and End User Licence Agreement acceptance records for the life of the relevant licence and for up to 7 years afterwards.
This allows us to administer the licence and establish, exercise or defend legal claims.
7.4 Support records
We normally retain support correspondence and diagnostic material for 3 years after the support request is resolved.
We may retain information for longer where necessary for an unresolved dispute, security investigation or legal claim.
We may delete diagnostic files earlier where they are no longer required to investigate or document the support issue.
7.5 Marketing information
We retain marketing contact details until you opt out or withdraw consent.
Where there has been no meaningful engagement for 3 years, we may remove your details from our active marketing records.
We may retain limited information on a suppression list to ensure that we respect a previous opt-out request.
7.6 Website analytics
Google Analytics information is normally retained for up to 14 months, subject to the settings and operation of the Google Analytics service.
7.7 Legal claims and disputes
We may retain relevant personal data for longer than the periods above where necessary to establish, exercise or defend a legal claim, comply with a legal obligation or respond to a regulatory investigation.
8. YOUR DATA PROTECTION RIGHTS
Depending on the circumstances, you may have the following rights under the GDPR.
8.1 Right of access
You can ask us whether we process your personal data and request a copy of the personal data we hold about you.
8.2 Right to rectification
You can ask us to correct personal data that is inaccurate or complete data that is incomplete.
8.3 Right to erasure
You can ask us to delete your personal data where there is no longer a lawful reason for us to retain it.
This right is not absolute. We may need to retain information to meet a legal obligation or establish, exercise or defend a legal claim.
8.4 Right to restriction
You can ask us to restrict how we use your personal data in certain circumstances, including while we investigate a concern about accuracy or lawfulness.
8.5 Right to object
You can object to processing based on our legitimate interests.
You have an absolute right to object to direct marketing.
8.6 Right to data portability
Where we process personal data by automated means on the basis of consent or contract, you may have the right to receive that data in a structured, commonly used and machine-readable format and request that it be transmitted to another controller where technically feasible.
8.7 Right to withdraw consent
Where processing is based on consent, you can withdraw your consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
8.8 Right to complain
You have the right to complain to the Irish Data Protection Commission if you are unhappy with how we process your personal data.
To exercise any of your rights, contact support@liscaragh.com.
We may ask you to provide information necessary to verify your identity before responding.
We normally respond within one month, although the GDPR allows this period to be extended in certain circumstances.
9. COOKIES
Our website uses a strictly necessary cookie to remember the cookie preference you select.
Where you actively consent, we also use Google Analytics cookies to understand how visitors use the website.
Analytics cookies are not set unless you accept them.
You can change your choice at any time using Cookie Preferences in the website footer.
Further information about the cookies we use, their purposes and retention periods is available in our Cookie Policy.
10. CHILDREN
Our website and Product are intended for business and professional use.
They are not directed at children, and we do not knowingly collect personal data from children.
11. AUTOMATED DECISION-MAKING
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects concerning individuals.
12. SECURITY
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Depending on the system and the nature of the information, these measures may include:
a. access controls;
b. multi-factor authentication;
c. encryption;
d. software updates and patching;
e. secure backups;
f. restrictions on access to business systems; and
g. measures to protect email and account security.
Access to personal data is limited to those who need it for legitimate business purposes.
No system or method of electronic transmission is completely secure. We cannot guarantee the absolute security of information sent to us or stored electronically.
13. CHANGES TO THIS NOTICE
We may update this Privacy Notice where:
a. our business changes;
b. we introduce new products or services;
c. our suppliers or systems change;
d. our checkout, licensing or support arrangements change;
e. legal or regulatory requirements change; or
f. we identify that the notice should be clarified.
The current version will be published on our website with its version number and effective date.
Where a change is material, we will take reasonable steps to notify affected customers or request fresh consent where required.
14. HOW TO CONTACT US
Questions about this notice, our use of personal data or your data protection rights should be sent to:
Email: support@liscaragh.com
Post: Dave Devery Consulting Ltd, trading as Liscaragh Software, Liscaragh, Puckane, Co. Tipperary, Ireland.
Company number: 772249
15. HOW TO COMPLAIN
If you are unhappy with how we have handled your personal data, you can contact us first so that we have an opportunity to address your concern.
You also have the right to complain to the Irish Data Protection Commission.
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland.
Phone: 01 765 0100 or 1800 437 737.
Website: www.dataprotection.ie
The Data Protection Commission generally handles complaints through its online contact form rather than by telephone.