The Galway Group, LLC
Last updated 9 September 2026
Draft pending legal review. This policy describes our actual practices in plain language, but it has not yet been reviewed by an attorney. If you need a signed data processing agreement or have a specific compliance requirement, email hello@galway.group and we will work from your paperwork.
The Galway Group, LLC (“we”, “us”) is a Florida limited liability company providing virtual CTO, managed IT, and software development services. This policy explains what information we collect through galway.group and in the course of delivering those services, why we collect it, and what we do with it.
Two different kinds of information are covered here, and it is worth keeping them separate: information about visitors to this website, and information we access inside a client’s own systems when we are engaged to run them. The second category is far more sensitive, and we treat it accordingly.
On this page
When you load a page on galway.group, we record a server-side log entry containing:
We use this to understand which pages are worth keeping and roughly where our visitors are. To derive the location we send your IP address to ipify, a third-party geolocation service. If that lookup fails, the location is stored as “Unknown” and nothing else changes.
We do not run Google Analytics, advertising pixels, session recording, or cross-site trackers on this website, and we do not sell or rent any of this data. We do not use cookies to profile you across other websites.
Our contact form asks for your name, email address, mobile number, company size, the plan you are interested in, and a description of what you need. It is used for one purpose: to reply to you and to size an engagement correctly.
Submitting the form sends the details to our own mailbox and sends you an acknowledgement. If we do not end up working together, we keep the enquiry only as long as it is commercially useful and delete it on request.
If you run our free assessment, you sign in with your own Microsoft account and consent to a set of read-only Microsoft Graph permissions. This is worth reading carefully, because it is the most sensitive thing this website does.
With your consent we read: device management configuration and applications, managed device inventory, license assignments, directory role assignments, user directory information, and group information. We use these to generate your assessment report.
We do not write to, change, or delete anything in your tenant during an assessment, and we do not read the contents of your email, files, chats, or calendars. Consent is granted by you and can be withdrawn by you at any time from your Microsoft 365 admin centre, which revokes our access immediately.
When you engage us, we typically hold administrative access to your Microsoft 365 or Azure environment in order to do the work. Some principles that apply for the whole engagement:
Where an engagement requires a formal data processing agreement, a business associate agreement, or specific contractual security commitments, we will sign yours or negotiate terms. Please ask.
We share information only with service providers that make the business run, and only what they need:
We may also disclose information where we are legally required to, or where it is necessary to protect our rights, our clients, or someone’s safety.
Website traffic logs are retained for operational analysis. Contact enquiries are kept while a sales conversation is live and for a reasonable period afterwards. Client engagement records, documentation, and correspondence are retained for the life of the engagement and afterwards as required for legal, tax, and professional obligations. Assessment data is retained only as long as needed to produce and discuss your report.
If you want something deleted, ask us, and we will delete whatever we are not legally required to keep.
You can ask us what information we hold about you, ask us to correct it, or ask us to delete it. You can withdraw assessment consent yourself at any time from your Microsoft admin centre. You can opt out of any commercial email by replying and telling us to stop, and we will.
Depending on where you live, you may have additional statutory rights over your personal data. We will honour a valid request under applicable law regardless of whether we are strictly required to.
We use multi-factor authentication on our own accounts, keep administrative credentials separate from day-to-day accounts, and apply the same security baseline to our own environment that we deploy for clients. No system is perfect. If we ever became aware of a breach affecting your information, we would tell you promptly and directly rather than by quietly updating this page.
Questions about this policy, or a request about your information, can go to hello@galway.group. We are a Florida LLC serving clients across the United States, and we reply within a business day.
If we make a material change to this policy, we will update the date at the top of this page.
Tell us what’s on your plate. We’ll come back within one business day, and tell you straight up if we’re not the right fit.