Helioran Capital

Privacy

Your data, treated with care.

This policy explains how Helioran Capital Limited collects, uses, stores, and protects personal data — in line with the EU General Data Protection Regulation (GDPR) and Irish data protection law.

Last updated · 2026-06-22

01

Who we are

Helioran Capital Limited (“Helioran,” “we,” “our” or “us”) is the data controller for any personal information processed in connection with this website and our advisory services.

Registered office: Ducart Suite, Commercial Campus, Castletroy, Limerick V94 Y6FD, Ireland. You can reach our data contact at niamh@heliorancapital.com.

02

What we collect

We collect the minimum information needed to respond to enquiries and provide advisory services. This may include:

  • Your name, email address, and (optionally) the organisation you represent, when you complete the contact form.
  • The contents of your message, including any commercial information you choose to share.
  • Basic technical data such as IP address, device type, and browser, recorded by our hosting provider for security and abuse prevention.
  • Information you share with us in the course of an engagement — collected and used strictly under the terms of the engagement letter.

We do not sell personal data, and we do not use it for advertising or profiling.

03

Why we use it

We process personal data for the following purposes:

  1. To respond to enquiries made via the website or email — legal basis: your consent and our legitimate interest in engaging with prospective clients.
  2. To deliver advisory services under a signed engagement — legal basis: performance of a contract.
  3. To comply with legal obligations, including anti-money-laundering, tax, and professional record-keeping requirements — legal basis: legal obligation.
  4. To protect our website and systems against abuse — legal basis: legitimate interest.
04

Who we share it with

We do not share personal data except where strictly necessary to deliver our service or comply with the law. Recipients may include:

  • Our infrastructure providers (e.g. Vercel for website hosting), who process data on our instructions under written terms.
  • Professional advisors (legal, accounting, audit) bound by confidentiality.
  • Regulators, courts, or law enforcement, where a valid legal request requires disclosure.

If any processor is located outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

05

How long we keep it

We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law:

  • Enquiry messages — up to 24 months from the most recent contact, unless an engagement begins.
  • Client engagement records — for the duration of the engagement and a further 6 years thereafter, in line with Irish commercial and tax record-keeping standards.
  • Technical logs — up to 90 days, then deleted or anonymised.
06

Your rights under GDPR

If you are in the EU/EEA, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data, subject to legal retention requirements.
  • Restrict processing in certain circumstances.
  • Receive your data in a portable format.
  • Object to processing carried out under our legitimate interests.
  • Withdraw consent at any time, where consent is the legal basis for processing.

To exercise any of these rights, email niamh@heliorancapital.com. We respond within one calendar month.

You may also lodge a complaint with the Irish Data Protection Commission at dataprotection.ie.

07

Cookies and tracking

Our website uses only the cookies and similar technologies that are strictly necessary to make it work. We do not currently use third-party analytics or advertising trackers.

If we add analytics in future, we will update this policy and ask for your consent through our cookie banner before any non-essential tracking is enabled.

08

Security

We protect personal data with technical and organisational measures appropriate to the risk, including encrypted transport (TLS), access controls, and confidentiality obligations on all personnel.

No system is perfectly secure. If you believe your data has been compromised, please contact us immediately at niamh@heliorancapital.com.

09

Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top of the page reflects the most recent revision. Material changes will be communicated by an appropriate means.

Questions about this document? We respond to data and engagement queries personally within two business days.

Get in touch