How we handle government and law-enforcement requests
Version 1.0 · Last updated 6 September 2026
1. Why this page exists
If you run your business on someone else's software, the data your customers gave you sits somewhere you do not control. The question you are entitled to ask is what happens when a public authority asks us for it. This page answers that, in the same words as clause 8.6 of our Data Processing Agreement, which is the contractual version of the same commitment.
2. Two kinds of data, two different answers
Data inside your account — your customers, jobs, quotes, invoices, messages and files. You are the controller of it and we are only the processor. It is not ours to hand over. Our starting position with any authority is that the request should be directed to you.
Data we hold as controller — your account and billing records, your support tickets, and enquiries sent through our website. We answer for that ourselves, under the same rules below.
3. What we require before we disclose anything
We disclose personal data to a public authority only where we are compelled to by a valid legal instrument that is binding on us — a court order, a warrant, a production order, a statutory notice, or an equivalent instrument under Irish, EU or, where it applies to us, UK law.
- A request must be in writing, must identify the authority and the officer making it, and must state the legal power relied on.
- An informal request is refused. "As part of an investigation", a phone call, or an email without an instrument is not a basis on which we disclose anything.
- A foreign order is not automatically binding on us. Where an authority outside Ireland, the EU or the UK seeks data, we require the request to come through mutual legal assistance or another international agreement that makes it enforceable against us. Article 48 of the GDPR does not permit us to treat a foreign judgment or decision as a basis for transfer on its own.
- We disclose only the minimum the instrument actually requires, and we do not volunteer anything beyond it.
- We challenge a request that appears to us to be unlawful, overbroad or excessive, and we will seek to narrow it.
We do not voluntarily disclose Customer Personal Data to any government or law-enforcement body, and we never have. We do not operate any standing arrangement, direct access facility or bulk feed for any authority.
4. We tell you before we disclose
If we receive a request for data in your account, we notify you before disclosing anything, so that you can seek to challenge it yourself, unless we are legally prohibited from telling you.
Where we are prohibited:
- we use reasonable efforts to obtain a waiver of the prohibition, or to have it narrowed or time-limited; and
- we tell you as soon as we lawfully can, including where a non-disclosure order expires or is lifted.
5. Emergencies
Where an authority states that there is an imminent risk of death or serious physical harm, we may disclose the minimum information needed to address that risk without waiting, and we will tell you afterwards as soon as we are able. We record every such disclosure and the grounds for it.
6. Records
We keep a record of every request we receive, what was asked for, what we disclosed or refused, the instrument relied on, and whether and when the affected customer was told. That record is available to a supervisory authority on request, and it is what we would produce if a customer asked us to account for a disclosure.
7. Address for service
Legal process must be served in writing on:
Go Gadgets LtdCupidstown, Kilteel, Co. Kildare, Ireland Company registration number: 565656 Email: hello@field2service.com — subject line "Legal process"
We accept service by email at that address for the purpose of acknowledging receipt; that is not an agreement that email service is valid where the instrument requires another method.
8. If you are not an authority
If you are a customer with a question about this page, or you believe a disclosure has been made about you, write to hello@field2service.com. If your data is inside a business's Field 2 Service account, that business is the controller — see section 3 of our Privacy Policy.