Privacy

Privacy policy

ira is deployed inside your walls, so most of what people expect a privacy policy to cover simply does not apply. Here is exactly what we do and do not receive.

GDPRDPDP Act 2023UK GDPR

Last updated 13 August 2026 · Version 3.1

The short version

ira is deployed inside your infrastructure. In a standard deployment we never receive your customers' calls, transcripts, documents or CRM records — those stay on your hardware, on your network. This policy therefore covers mostly the data we collect when you visit our website, talk to our sales team, or ask us for support.

1. Who we are

ira.ai ("ira", "we", "us") builds real-time conversation intelligence software that is deployed on customer-controlled infrastructure. This policy explains what personal data we collect as a company, why, and what you can do about it.

For questions, or to exercise any right described below, write to privacy@ira.ai. Our Data Protection Officer can be reached at the same address, marked for their attention.

2. Two very different roles

It matters which hat we are wearing, because the rules differ:

ContextOur roleWhat it means
Our website, marketing, sales conversations, support tickets, recruitment Controller We decide why and how the data is used. This policy governs it.
Conversations processed by the ira software inside your environment Processor — where we process at all You decide. Our Data Processing Agreement governs it, not this policy. In an air-gapped or standard on-prem deployment, no such data ever reaches us.

3. What we collect

When you visit the website

  • Page requests, referring page, approximate region derived from IP, browser and device type.
  • We do not run advertising trackers, cross-site pixels, or sell traffic data.

When you request a demo or contact us

  • Name, work email, company, role, and anything you choose to write in the message field.
  • Your stated deployment interest and channel requirements, so the demo is relevant.
  • A record of our correspondence with you.

When you become a customer

  • Contact details for named administrators, billing contacts and technical contacts.
  • Contract, invoicing and payment records.
  • Support correspondence, and — only if you deliberately send it — diagnostic logs.

When you apply for a job

  • CV, contact details, work history, interview notes and assessment outcomes.

4. What the product does not send us

In a standard deployment, the following never leave your perimeter and are never received by ira:

  • Call audio, video, or any recording.
  • Transcripts, translations, or hint text.
  • Documents indexed into the Knowledge Bank.
  • CRM records, customer identifiers, or policy data.
  • Agent performance data and AutoCoach scorecards.

Model weights run on your hardware. There is no inference call to an ira-operated server, and nothing is used to train models for other customers. If you ask us to help diagnose a problem and choose to share a log or sample, that is a deliberate act by you, covered by the DPA, and the material is deleted on the timeline agreed with you.

5. Why we process it, and on what basis

PurposeLawful basis (GDPR)
Responding to a demo request or enquirySteps prior to entering a contract; legitimate interests
Providing and supporting the softwarePerformance of a contract
Security, fraud prevention, service integrityLegitimate interests; legal obligation
Invoicing, tax and statutory recordsLegal obligation
Product and marketing emails to business contactsConsent, or legitimate interests where permitted
RecruitmentSteps prior to entering a contract; consent for talent-pool retention

Under India's Digital Personal Data Protection Act, 2023, we rely on your consent or on legitimate uses as defined in that Act, and we honour the equivalent rights described in section 8.

6. Who we share it with

We do not sell personal data. We share it only with:

  • Service providers who host our website, send our email, run our CRM and process payments — each under contract and permitted to act only on our instructions.
  • Professional advisers — lawyers, auditors, accountants — where necessary.
  • Authorities, where we are legally compelled. We will tell you unless prohibited.
  • An acquirer, if the business is sold, subject to this policy continuing to apply.

A current list of our corporate sub-processors is available on request from privacy@ira.ai. Note that these are sub-processors for our business systems. The deployed product has none.

7. How long we keep it

DataRetention
Website analytics14 months, aggregated thereafter
Demo and enquiry records24 months from last contact, unless you become a customer
Customer contract and billing recordsAs required by tax and company law, typically 8 years
Support correspondence3 years from resolution
Unsuccessful job applications12 months, or longer with your consent
Diagnostic material you send usDeleted on the agreed timeline, by default within 30 days

8. Your rights

Depending on where you are, you may ask us to: confirm what we hold about you; give you a copy; correct it; delete it; restrict or object to how we use it; port it elsewhere; or withdraw consent. Indian residents may also nominate another person to exercise these rights in the event of death or incapacity, as provided by the DPDP Act.

Write to privacy@ira.ai. We respond within 30 days. There is no charge unless a request is manifestly excessive.

If you are unhappy with our response you may complain to your supervisory authority — the Data Protection Board of India, or your EU/UK supervisory authority. We would rather you came to us first.

9. International transfers

Our own business systems may involve transfers outside your country. Where they do, we use Standard Contractual Clauses or the UK International Data Transfer Addendum, together with a transfer risk assessment. The deployed product transfers nothing — that is the point of it.

10. Cookies

We use strictly necessary cookies to make the site work, and a first-party analytics cookie to count visits. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser without losing access to anything on this site.

11. Children

This is a business product. Our website and services are not directed at children, and we do not knowingly collect data from anyone under 18.

12. Changes and contact

If we change this policy materially we will update the date at the top and, for customers, give notice through the usual channel. Contact us at privacy@ira.ai or through our contact page.

Next step

Questions we have not answered?

Our DPO reads privacy@ira.ai directly. For contractual questions, the DPA is the document you want.