Privacy
What we collect, why we have it, and what you can make us do about it. dooco sells AI automation, so this page is unusually specific about where an AI touches your data — that seemed like the least we could do.
Last updated 5 September 2026
Who is responsible for your data
dooco is a business name, not a company — so the person responsible for your data is a person. The data controller is Padraig Dooley, trading as dooco, business name registration number 634832, of Newgardens, Carlow, Ireland, R93YY88. We are based in Ireland, so this site operates under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
For anything on this page — including a request to see or delete your data — write to hello@dooco.com. A person reads it.
What we collect, and why
We collect very little, and only when you hand it to us. There is no account to create and nothing to sign up for.
When you use the contact form
We collect your name, email address, your business nameif you give one (it's optional), and the message you write. That becomes an email to our own inbox — we do not run a database of enquiries or a CRM.
Our lawful basis is Article 6(1)(b) — taking steps at your request before entering into a contract. If your message turns out not to be about working together, we rely instead on our legitimate interests under Article 6(1)(f) in reading and answering correspondence addressed to us.
When you email us or book a call
Email you send to hello@dooco.com reaches the same inbox and is treated the same way. If you book a call, our calendar provider records your name, email address and the time you chose so the meeting can happen.
When you just read the site
This site sets no cookies at all — none for advertising, none for tracking, none for analytics. That is why you have not been shown a cookie banner: there is nothing to consent to.
We do measure traffic, using Vercel Web Analytics, which is designed to work without cookies. It records the page visited, the referring site, approximate location at city level, and device and browser type. Visitors are counted using a hash generated from the request that is discarded within 24 hours; there is no identifier that follows you between sessions or across other websites, and we see aggregate counts rather than people. Our lawful basis is our legitimate interest under Article 6(1)(f) in knowing which pages are worth writing.
Our hosting provider also keeps short-lived technical server logs, which include IP addresses, for security and diagnostics.
How AI is used on your data
dooco runs its own marketing and admin on the automations it sells, so an AI agent genuinely does touch messages you send us. Here is exactly what it does.
A scheduled automation reads our inbox, sorts genuine enquiries from newsletters and receipts, and prepares a draft reply. To do that, it processes the contents of your message and your name and email address. It runs on Claude, provided by Anthropic, which acts as our processor.
It never sends anything. Every reply you receive from dooco was read and sent by a person. The automation cannot email you, delete your message, or make any decision about you — it can only leave a draft for the founder to approve, edit or bin. That is a deliberate rule, not a current limitation.
Because a human makes every decision and every send, there is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22. We do not use your messages to train AI models, and our AI provider does not train its models on data submitted through its business API.
Who else processes your data
We keep the list short on purpose. Each of these acts on our instructions as a processor:
- Google (Google Workspace) — email and calendar. Your message lives in our mailbox.
- Vercel — hosting for this site, server logs, and the cookieless analytics described above.
- Anthropic — the AI that drafts replies, as described above.
We do not sell your data, and we do not share it for anyone else's marketing.
Transfers outside the EEA
These providers are US-based and may process your data outside the European Economic Area. Where that happens, the transfer is made under the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with the additional safeguards in each provider's data processing terms.
How long we keep it
Enquiries that do not become work are deleted within 24 months of our last contact with you — sooner if you ask. Where an enquiry becomes a paid engagement, the related records are kept for six years, which is the period Irish tax and company law requires us to retain business records. Analytics data is aggregate and is not tied to you.
Your rights
Under the GDPR you can ask us to:
- Give you a copy of the personal data we hold about you (access);
- Correct itif it's wrong (rectification);
- Delete it(erasure) — we'll do this unless we are legally required to keep it;
- Restrict or object tohow we're using it, including any use based on our legitimate interests;
- Send it elsewhere in a portable format (portability).
Email hello@dooco.comand we'll respond within one month, free of charge. You do not need to give a reason, and asking will not affect how we deal with you.
If you think we've handled your data badly, you are entitled to complain to the Irish supervisory authority, the Data Protection Commission. We would rather you told us first, but it's your call.
Security
The site is served over HTTPS. Access to the mailbox holding enquiries is protected by two-factor authentication, and the automations that read it are scoped so they can read and draft but not send, delete, or forward.
Changes
If this policy changes materially we will update the date at the top of the page. If you have an open enquiry with us at the time, we'll tell you.