CarAlert

Legal

Privacy Policy

How we collect, use, share and protect your personal data — and the rights you have over it.

Last updated: 6 September 2026 · Version 2026-09-06 · Applies to the Republic of Ireland.

Draft — pending Irish legal review

This notice is a product/engineering draft prepared to be substantively correct under the GDPR and the Irish Data Protection Act 2018. It must be reviewed by a qualified Irish solicitor, and a Data Protection Impact Assessment (DPIA) completed, before the service accepts live users. It is not legal advice.

1. Introduction

CarAlert (“we”, “us”, “our”, the “Service”) is an independent, community-based vehicle-safety and vehicle-utility service for the Republic of Ireland. We are committed to protecting your privacy and handling your personal data responsibly, lawfully, transparently and securely, in accordance with Regulation (EU) 2016/679 (the “GDPR”), the Irish Data Protection Act 2018, the ePrivacy Regulations (S.I. No. 336 of 2011) and other applicable law.

This Privacy Policy explains what personal data we collect, why we collect it, the legal bases on which we rely, who we share it with — including how information is shared within the community so that members can look out for one another — how long we keep it, how we protect it, and the rights you can exercise. Please read it carefully. By creating an account you confirm that you have read and accepted this Policy.

We are independent and are not affiliated with, endorsed by, or acting on behalf of the National Car Testing Service (NCTS), the Road Safety Authority (RSA), the Department of Transport, Motor Tax Online, An Garda Síochána, the National Vehicle and Driver File, or any vehicle-owner register.

2. Who is the data controller?

The data controller responsible for your personal data is Huftek Software Limited, a company established in the Republic of Ireland, of [registered office address — to be confirmed]. You can contact us about privacy at privacy@caralert.ie (address to be confirmed). Where required, our Data Protection Officer / privacy contact can be reached at the same address.

3. Scope and your acceptance

This Policy applies to the CarAlert website and web application, and to all personal data we process about visitors, registered members, vehicle watchers, reporters, people invited to share a vehicle, and those who contact our support team. Because a core purpose of the Service is enabling members of the community to alert one another about issues affecting vehicles, you acknowledge and consent that, when you create an account and use the Service, certain information you provide or generate will be shared with other members of the community as described in Section 7, so that the community can function and members can help each other.

4. The personal data we collect

We collect and process the following categories of personal data:

Where a registration number you enter belongs to a vehicle associated with another person, you are providing us with information that may relate to that person. You must only use the Service for genuine safety and vehicle-utility purposes and not to track, harass, identify or contact any individual.

5. How we use your personal data (purposes)

6. Our legal bases for processing

We rely on the following legal bases under Article 6 of the GDPR:

7. Community sharing — how members help each other

The purpose of CarAlert is to let people look out for each other's vehicles. To make that possible, some information is shared between members — but always in a limited, purpose-bound way, and never as a public directory. Specifically:

By accepting this Policy you consent to this community sharing taking place for the purposes described. We do not sell your personal data, and we do not use your safety or compliance data for behavioural advertising.

8. Who else we share data with (processors and recipients)

9. International transfers

We aim to store and process personal data within the European Union / European Economic Area. Where any processor processes data outside the EEA, we ensure an adequate level of protection through an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate supplementary safeguards.

10. How long we keep your data (retention)

11. How we protect your data (security)

We apply appropriate technical and organisational measures, including encryption in transit, hashed passwords, keyed hashing of registration numbers for lookup so raw plates are not exposed in logs or URLs, strict access controls and row-level security, private and time-limited storage of any evidence, rate limiting and abuse detection, redacted logging, and regular review. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident, including notifying the Data Protection Commission and affected individuals where legally required.

12. Automated processing and moderation

We use automated rules to moderate report notes (for example to remove contact details, links, threats or personal data) and to assess risk and trust in order to prevent abuse. These do not produce legal or similarly significant effects on you without the opportunity for human review; account restrictions and claim decisions support human review and appeal.

13. Your rights

Subject to the conditions and exemptions in the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing, including processing based on legitimate interests; data portability; and withdraw consent at any time where processing is based on consent. You can exercise most of these from your account settings, or by contacting us. We will respond within the timeframes required by law, and we will protect the rights and data of other people when we respond.

You also have the right to lodge a complaint with the Irish supervisory authority, the Data Protection Commission (www.dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28), although we would welcome the chance to address your concern first.

14. Emergency boundary

The Service is not an emergency service and cannot dispatch help. If life or safety is at risk, contact the emergency services on 112 or 999 first.

15. Children

The Service is intended for adults. You must be at least 18 years old to create an account, and you confirm this when you register. We do not knowingly collect data from people under 18.

16. Cookies

We use strictly necessary cookies to keep you signed in and to protect the Service, and — only with your consent — optional analytics cookies. For details and choices, see our Cookie Notice.

17. Changes to this Policy

We may update this Policy from time to time. When we make material changes we will update the version and date at the top and, where appropriate, notify you or ask you to re-accept. Your continued use after an update means you accept the revised Policy.

18. Contact us

If you have any questions about this Policy or how we handle your personal data, contact us at privacy@caralert.ie or write to us at the registered office above (details to be confirmed before launch).