Legal information
Privacy policy
What personal data IRON ID Group processes, why, for how long, who else sees it, and the rights that come with it.
Last updated [DATE]
DraftThese documents are drafted and complete, but the contracting entity is being incorporated and counsel has not signed them off yet. Three points remain explicitly open and are marked in the text: the entity and the governing law, the liability cap in the terms of service, and the identity of the data protection officer.
1.Who is responsible
The data controller is IRON ID Group, [LEGAL ENTITY NAME], [REGISTRATION NUMBER], with its registered office at [REGISTERED ADDRESS].
When you use the platform on behalf of an organization, it is your organization that decides the purposes and means of processing its members' data and its documents; IRON ID then acts as processor, on the terms of the data processing agreement.
For any question about your data: privacy@iron-id.io. The appointment of a data protection officer, and their contact details, will be published here once the contracting entity is incorporated. [TO BE COMPLETED BY LEGAL COUNSEL]
2.What we collect
We collect what the services and the commercial relationship strictly require. The categories are:
- Account data: name, work email address, password hashed with Argon2, multi-factor authentication factors, API keys.
- Organization data: name, country, teams, roles, memberships, invitations.
- Usage and technical data: sign-in timestamps, IP address, device and browser type, the audit log of actions taken.
- Document metadata: name, size, type, versions, fingerprints, timestamps, provenance manifests, audit entries. Document content is covered by clause 4.
- Contact data: what you enter in the request form — name, work address, company, job title, size, industry, country, intent, products of interest, description of your use case.
- Support exchanges: the messages you send us and our replies.
3.Why, and on what basis
Each category has one purpose and one legal basis, and serves nothing else.
Performance of the contract covers account, organization and document data: without them there is no service. Legitimate interest covers platform security, fraud prevention and product improvement, on usage data reduced to what is necessary. Consent covers the contact form and launch-related messages, revocable in one click. Legal obligation covers accounting, invoicing and requests from competent authorities.
We sell no data, we rent none, and we use neither your documents nor your metadata to train a model.
4.The content of your documents
The content you deposit is encrypted at rest with AES-256-GCM, with a distinct data key per version. Those keys are wrapped by a key management service that never sees the content itself.
Our teams do not access the content of your documents. Isolation between organizations is enforced by the database itself, at row level, in addition to the application filter: a coding mistake is not enough to let a document leave its organization.
Public verification is served by a read-only role that sees only what may be shown: a fingerprint, a date, a verdict. Never the document.
5.How long we keep it
Account and organization data is kept for as long as the organization exists, then for thirty days after termination so you can export, then deleted.
Technical logs are kept for twelve months. Billing data is kept for ten years, the period accounting obligations impose. Requests received through the contact form are kept for three years from the last exchange.
Erasing a document removes its content irreversibly. Its fingerprint, its timestamp and its audit entries remain: they are proof data, and losing them would lose the demonstration that the document existed at a given date. They allow neither reconstruction of the document nor any guess at its nature.
6.Who else sees it
We use a deliberately small number of sub-processors. None of them receives the content of your documents in clear.
- Scaleway (France) — application hosting, database, object storage, key and secret management. Region fr-par. It is the only sub-processor that holds the encrypted data.
- Cloudflare — web application firewall, DDoS mitigation and rate limiting at the edge. Handles requests, never documents in clear.
- Resend — transactional email delivery: welcome, notifications, unsubscribe. Receives the recipient's address and the content of the message sent.
7.Where your data is hosted
The hosted edition runs in France today, in region fr-par, outside the reach of the Cloud Act. The data region is an attribute of your organization, which lets it change without a schema migration.
Deployment on your own infrastructure, with a hosting partner in your country, or inside an isolated network, is rolling out with early access. We do not claim those options already exist: their status is stated on the security page.
No transfer takes place to a third country beyond the sub-processors listed in clause 6 and the contractual safeguards that govern them.
8.Your rights
You have the following rights over your personal data, exercised at privacy@iron-id.io. We answer within one month.
- Access: confirmation that we process your data, and a copy of it.
- Rectification: correction of inaccurate or incomplete data.
- Erasure: deletion of your data, subject to the proof data and the legal retention obligations described in clause 5.
- Portability: receipt of your data in an open, machine-readable format. The platform offers this directly through export.
- Objection: objection to processing based on our legitimate interest.
- Restriction: a freeze on processing while its accuracy or lawfulness is checked.
- Complaint: referral to the national data protection authority if our answer does not satisfy you.
9.Cookies
This site sets one cookie, which remembers the language you chose. There is no analytics, no advertising tracker and no third-party cookie today. The detail is in the cookie policy.
10.Security
The technical and organisational measures are described control by control on the security page: encryption, identity, authentication, authorization, isolation, audit, key management, infrastructure and data residency.
In the event of a data breach likely to create a risk for the people concerned, we notify the competent authority without undue delay and within the deadline the applicable law imposes, according to the deployment model in place. We inform the people concerned where the risk is high.
11.Minors
The services are addressed to organizations and their members in a professional setting. They are not intended for people under eighteen, and we do not knowingly collect their data.
12.Changes
Any substantial change to this policy is announced by email and on this site at least thirty days before it takes effect, and the update date at the top of the page is refreshed.
Get started
See IRON ID for your organization.
Request a demo of the Platform, join early access to be onboarded in the first cohorts, or request a quote for a KYC or Sign SDK integration.
Reply within two business days · contact@iron-id.io