Privacy Policy
Effective Date: January 7, 2026
1. Introduction
This Privacy Policy explains how Philip Healy, an individual based in Ireland (“Operator”, “I”, “me”, or “my”), collects, uses, and protects your personal data when you use the decisionpoint.io website, application, and related services (collectively, the “Service”).
By using the Service, you agree to the collection and use of your information as described in this Privacy Policy. If you do not agree, please do not use the Service.
2. Data Controller
Philip Healy
Email: philip.healy@decisionpoint.io
Based in Ireland
I am responsible for how your personal data is processed in connection with the Service.
3. Information We Collect
A. Account Information
Currently, the Service uses Google OAuth for authentication. The only personal information received from Google is:
- Your name
- Your email address
- Your avatar URL
No passwords are collected at this time. If additional authentication methods (such as password login) are added in the future, the Privacy Policy will be updated accordingly.
B. User-Generated Content
- Any inputs, decision models, or collaborative content you provide within the Service
- This content remains your property
C. Analytics and Performance Data
We use the following services to improve and monitor the Service:
- Google Analytics – collects usage patterns and session information via the app code, without relying on browser cookies
- MixPanel – tracks product engagement and feature usage via the app code, without relying on browser cookies
- Sentry – collects error reports and diagnostic information
These tools may collect technical information such as IP addresses, browser type, device, and usage events. This information is used to monitor performance, fix errors, and improve the Service.
D. Email Communications
We may contact you via email to:
- Request feedback about the Service
- Inform you about product updates or changes
All feedback emails will include an option to unsubscribe.
4. Legal Basis for Processing (GDPR)
| Processing Activity | Legal Basis |
|---|---|
| Account registration via Google OAuth | Performance of contract |
| Sending feedback-request emails | Legitimate interest (with opt-out) |
| Analytics (Google Analytics, MixPanel, Sentry) | Legitimate interest |
| Future password login or auth information | Performance of contract |
5. How We Use Your Information
We use personal data for the following purposes:
- To provide and operate the Service
- To communicate with you about your account or the Service
- To improve the Service based on usage patterns and feedback
- To detect, prevent, and respond to technical issues or fraud
6. Cookies and Tracking
The Service uses minimal cookies for functional purposes only, such as remembering whether you have dismissed banners.
No cookies are used for tracking or advertising purposes.
7. Data Sharing
We do not sell or rent your personal information. Your data may be shared with:
- AWS – hosting infrastructure
- Google Analytics, MixPanel, Sentry – analytics and monitoring
We may also disclose information if required by law or to protect our legal rights.
8. Data Retention
- Account information (name, email) is retained until you delete your account or request removal
- User-generated content is retained until deletion or account closure
- Analytics data may be stored in anonymized or aggregated form for ongoing service improvement
9. User Rights (GDPR)
If you are an EU resident, you have the right to:
- Access the personal data we hold about you
- Rectify or update your information
- Delete your account and data
- Request portability of your data
- Withdraw consent where applicable (e.g., marketing/feedback emails)
- Lodge a complaint with the Data Protection Commission in Ireland
10. Security
We take reasonable measures to protect your personal data:
- AWS hosting with secure infrastructure
- HTTPS encryption for data in transit
- Access control policies for sensitive information
- Sentry only collects error and diagnostic information
No system is completely secure. You acknowledge that some risk of unauthorized access remains.
11. International Data Transfers
Your data may be transferred outside the European Economic Area (EEA) to services such as AWS, Google Analytics, MixPanel, and Sentry.
These providers implement safeguards such as Standard Contractual Clauses or other compliance mechanisms to ensure protection of your personal data.
12. Changes to This Privacy Policy
The Privacy Policy may be updated from time to time. Material changes will be communicated via the Service or by email where appropriate.
Your continued use of the Service after such changes constitutes acceptance of the updated Privacy Policy.
13. Contact
If you have questions or concerns about this Privacy Policy or your personal data, you may contact:
Philip Healy
Email: philip.healy@decisionpoint.io
Based in Ireland