Privacy policy
ira is deployed inside your walls, so most of what people expect a privacy policy to cover simply does not apply. Here is exactly what we do and do not receive.
Last updated 13 August 2026 · Version 3.1
ira is deployed inside your infrastructure. In a standard deployment we never receive your customers' calls, transcripts, documents or CRM records — those stay on your hardware, on your network. This policy therefore covers mostly the data we collect when you visit our website, talk to our sales team, or ask us for support.
1. Who we are
ira.ai ("ira", "we", "us") builds real-time conversation intelligence software that is deployed on customer-controlled infrastructure. This policy explains what personal data we collect as a company, why, and what you can do about it.
For questions, or to exercise any right described below, write to privacy@ira.ai. Our Data Protection Officer can be reached at the same address, marked for their attention.
2. Two very different roles
It matters which hat we are wearing, because the rules differ:
| Context | Our role | What it means |
|---|---|---|
| Our website, marketing, sales conversations, support tickets, recruitment | Controller | We decide why and how the data is used. This policy governs it. |
| Conversations processed by the ira software inside your environment | Processor — where we process at all | You decide. Our Data Processing Agreement governs it, not this policy. In an air-gapped or standard on-prem deployment, no such data ever reaches us. |
3. What we collect
When you visit the website
- Page requests, referring page, approximate region derived from IP, browser and device type.
- We do not run advertising trackers, cross-site pixels, or sell traffic data.
When you request a demo or contact us
- Name, work email, company, role, and anything you choose to write in the message field.
- Your stated deployment interest and channel requirements, so the demo is relevant.
- A record of our correspondence with you.
When you become a customer
- Contact details for named administrators, billing contacts and technical contacts.
- Contract, invoicing and payment records.
- Support correspondence, and — only if you deliberately send it — diagnostic logs.
When you apply for a job
- CV, contact details, work history, interview notes and assessment outcomes.
4. What the product does not send us
In a standard deployment, the following never leave your perimeter and are never received by ira:
- Call audio, video, or any recording.
- Transcripts, translations, or hint text.
- Documents indexed into the Knowledge Bank.
- CRM records, customer identifiers, or policy data.
- Agent performance data and AutoCoach scorecards.
Model weights run on your hardware. There is no inference call to an ira-operated server, and nothing is used to train models for other customers. If you ask us to help diagnose a problem and choose to share a log or sample, that is a deliberate act by you, covered by the DPA, and the material is deleted on the timeline agreed with you.
5. Why we process it, and on what basis
| Purpose | Lawful basis (GDPR) |
|---|---|
| Responding to a demo request or enquiry | Steps prior to entering a contract; legitimate interests |
| Providing and supporting the software | Performance of a contract |
| Security, fraud prevention, service integrity | Legitimate interests; legal obligation |
| Invoicing, tax and statutory records | Legal obligation |
| Product and marketing emails to business contacts | Consent, or legitimate interests where permitted |
| Recruitment | Steps prior to entering a contract; consent for talent-pool retention |
Under India's Digital Personal Data Protection Act, 2023, we rely on your consent or on legitimate uses as defined in that Act, and we honour the equivalent rights described in section 8.
6. Who we share it with
We do not sell personal data. We share it only with:
- Service providers who host our website, send our email, run our CRM and process payments — each under contract and permitted to act only on our instructions.
- Professional advisers — lawyers, auditors, accountants — where necessary.
- Authorities, where we are legally compelled. We will tell you unless prohibited.
- An acquirer, if the business is sold, subject to this policy continuing to apply.
A current list of our corporate sub-processors is available on request from privacy@ira.ai. Note that these are sub-processors for our business systems. The deployed product has none.
7. How long we keep it
| Data | Retention |
|---|---|
| Website analytics | 14 months, aggregated thereafter |
| Demo and enquiry records | 24 months from last contact, unless you become a customer |
| Customer contract and billing records | As required by tax and company law, typically 8 years |
| Support correspondence | 3 years from resolution |
| Unsuccessful job applications | 12 months, or longer with your consent |
| Diagnostic material you send us | Deleted on the agreed timeline, by default within 30 days |
8. Your rights
Depending on where you are, you may ask us to: confirm what we hold about you; give you a copy; correct it; delete it; restrict or object to how we use it; port it elsewhere; or withdraw consent. Indian residents may also nominate another person to exercise these rights in the event of death or incapacity, as provided by the DPDP Act.
Write to privacy@ira.ai. We respond within 30 days. There is no charge unless a request is manifestly excessive.
If you are unhappy with our response you may complain to your supervisory authority — the Data Protection Board of India, or your EU/UK supervisory authority. We would rather you came to us first.
9. International transfers
Our own business systems may involve transfers outside your country. Where they do, we use Standard Contractual Clauses or the UK International Data Transfer Addendum, together with a transfer risk assessment. The deployed product transfers nothing — that is the point of it.
10. Cookies
We use strictly necessary cookies to make the site work, and a first-party analytics cookie to count visits. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser without losing access to anything on this site.
11. Children
This is a business product. Our website and services are not directed at children, and we do not knowingly collect data from anyone under 18.
12. Changes and contact
If we change this policy materially we will update the date at the top and, for customers, give notice through the usual channel. Contact us at privacy@ira.ai or through our contact page.
Questions we have not answered?
Our DPO reads privacy@ira.ai directly. For contractual questions, the DPA is the document you want.