Third Party Index

Snapshot 49232

Document
Data processing addendum
URL
https://ironyard.io/DataProcessing
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
53844 bytes
SHA-256 (raw)
d491781346c751a7ec6a83748905dad55258488af14be83fde4b8cdc3d59228e
SHA-256 (normalized text)
1603fddef72c8ab1dee4f9be536f7fcbfd01f428a049178aa4ed7992f80867a6

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Legal
Data Processing Agreement
Effective 3 September 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the agreement between Iron Yard Limited ("IronYard", "we", "us") and the customer organisation that has agreed to IronYard's Terms of Service or an equivalent order form (the "Customer", "you") governing Customer's use of the IronYard application (the "Service"). This DPA applies whenever IronYard processes Personal Data on Customer's behalf as a processor.
Capitalised terms not defined in this DPA have the meaning given in the Terms of Service or the GDPR, as applicable.
1. Definitions
"Data Protection Laws" means the GDPR, the UK GDPR and the UK Data Protection Act 2018, and any other data protection or privacy law applicable to the processing of Personal Data under this DPA.
"Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in the GDPR.
"Customer Data" means Personal Data that Customer or its authorised users submit to, or make available to, the Service — including data accessed through a connected CRM, Google Calendar, Gmail, or Slack integration — and that IronYard Processes on Customer's behalf.
"Sub-processor" means any third party engaged by IronYard to Process Customer Data in providing the Service, as listed in Annex B.
2. Roles of the Parties
2.1 Customer is the Controller of Customer Data. IronYard is the Processor of Customer Data and will Process it only on behalf of, and in accordance with, Customer's documented instructions, except where required to do otherwise by applicable law.
2.2 This DPA does not apply to Personal Data that IronYard Processes as a Controller in its own right — for example, account administration, billing, security, and IronYard's own business communications with Customer's administrators. That processing is described in IronYard's Privacy Policy.
2.3 Customer is solely responsible for ensuring it has a lawful basis to provide Customer Data to IronYard and to authorise IronYard's Processing of it as described in this DPA and the Terms of Service, including where Customer connects a third-party CRM, Google Calendar, Gmail, or Slack to the Service.
3. Scope and Nature of Processing
3.1 Subject matter: IronYard's provision of the Service to Customer.
3.2 Duration: for the term of the agreement between the parties, and thereafter as set out in Section 8 (Deletion and Return of Data).
3.3 Nature and purpose of processing: storage, organisation, retrieval, analysis and display of Customer Data to provide CRM-integrated sales coaching, pipeline intelligence, deal health scoring, forecasting, meeting preparation, and related features of the Service, as described in IronYard's Privacy Policy.
3.4 Categories of Data Subjects: Customer's employees and authorised users; and the individuals whose data appears in Customer's connected CRM, calendar, or email accounts (e.g. prospects, contacts, and other business contacts).
3.5 Categories of Personal Data: as described in Section 4 of IronYard's Privacy Policy — account and user information; CRM data (deals, contacts, companies, pipeline and activity data); Google Calendar event data (where connected); Gmail message data (where connected); and automatically collected technical/usage data.
3.6 Special category data: the Service is not designed to collect or require special category data (as defined in Article 9 GDPR). Customer must not submit special category data to the Service unless the parties have agreed additional terms to address it.
4. IronYard's Obligations
IronYard shall:
4.1 Process Customer Data only on Customer's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by law applicable to IronYard, in which case IronYard shall inform Customer of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest;
4.2 ensure that persons authorised to Process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
4.3 implement appropriate technical and organisational measures as described in Annex A;
4.4 taking into account the nature of the Processing, assist Customer, by appropriate technical and organisational measures, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR;
4.5 assist Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of Processing and the information available to IronYard;
4.6 at Customer's choice, delete or return all Customer Data after the end of the provision of Service-related Processing, and delete existing copies unless applicable law requires storage, as further described in Section 8; and
4.7 make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to Section 6 (Audits).
5. Sub-processors
5.1 Customer authorises IronYard to engage the Sub-processors listed in Annex B to Process Customer Data in connection with the Service.
5.2 IronYard will impose data protection obligations on each Sub-processor that are no less protective of Customer Data than those set out in this DPA, and remains liable to Customer for each Sub-processor's performance of its data protection obligations.
5.3 IronYard will maintain an up-to-date list of Sub-processors (Annex B) and will provide reasonable advance notice to Customer of the addition or replacement of a Sub-processor. Customer may object to a new Sub-processor on reasonable data protection grounds by notifying IronYard within 14 days; the parties will work in good faith to resolve the objection, which may include IronYard not appointing the new Sub-processor for Customer, or Customer terminating the affected part of the Service.
6. Audits
6.1 IronYard will, on reasonable prior written request and no more than once per year (unless required following a Personal Data Breach or by a supervisory authority), make available information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a written response to a reasonable questionnaire, a summary of a recent third-party security assessment, or, where those are insufficient, a mutually agreed on-site or remote audit conducted at Customer's expense during normal business hours, subject to reasonable confidentiality restrictions.
7. Personal Data Breach
7.1 IronYard will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, and will provide information reasonably available to it to assist Customer in meeting any obligations to notify a supervisory authority or affected Data Subjects under Articles 33 and 34 of the GDPR.
7.2 IronYard will take reasonable steps to contain, investigate and remediate a Personal Data Breach, and will keep Customer reasonably informed of material developments.
8. Deletion and Return of Data
8.1 On termination or expiry of the agreement, or on Customer's request, IronYard will delete Customer Data from its active production systems in accordance with the process described in Section 11 of IronYard's Privacy Policy, except to the extent applicable law requires IronYard to retain some or all of the Customer Data, in which case IronYard will isolate and protect that data from further Processing.
8.2 Deletion from active systems does not necessarily mean immediate deletion from encrypted backups; backup copies are retained only for the duration of the applicable backup cycle before being securely overwritten or deleted, and are not restored except for disaster recovery or security purposes.
9. International Transfers
9.1 IronYard's principal infrastructure Sub-processors process Customer Data within the European Economic Area, as set out in Annex B. Where IronYard or a Sub-processor transfers Customer Data outside the EEA or UK, IronYard will ensure an appropriate transfer mechanism is in place, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, an adequacy decision, or another legally recognised transfer mechanism, together with any additional safeguards reasonably necessary in the circumstances.
10. Liability
10.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, applied in aggregate across the Terms of Service and this DPA and any other document referencing them, unless otherwise required by applicable Data Protection Laws.
11. Term
This DPA takes effect on the date Customer first agrees to the Terms of Service (or, if later, the effective date above) and remains in effect for as long as IronYard Processes Customer Data on Customer's behalf.
12. Governing Law
This DPA is governed by the same governing law and jurisdiction provisions as the Terms of Service.
Annex A — Technical and Organisational Security Measures
Encryption of data in transit using TLS.
AES-256-GCM encryption of stored CRM/OAuth access tokens and API keys.
Passwords stored using bcrypt cryptographic hashing, never in plain text.
JWT-based session authentication with distinct signing secrets for customer/representative sessions and IronYard staff sessions, so neither can be used to access the other's routes.
Role-based access controls within the Service (administrator vs. team member permissions).
Least-privilege access to production systems and data, limited to personnel who reasonably require it to operate, maintain or support the Service.
Security and audit logging.
Encrypted backups and disaster-recovery measures.
Employee confidentiality obligations.
A defined incident-response process for security events (see Section 7 of this DPA and Section 13 of the Privacy Policy).
Automated data retention/pruning for defined categories of operational data (see Section 10 of the Privacy Policy), run nightly.
Annex B — Sub-processors
Sub-processor	Purpose	Processing location
Supabase	Database hosting and management	EU — AWS eu-central-1, Frankfurt
Google Cloud Platform	Application hosting	EU — europe-west3, Frankfurt
Vercel	Frontend hosting and product analytics	EU — fra1, Frankfurt
Stripe	Payment processing and billing	International, subject to Stripe's own safeguards
Anthropic	AI processing, where selected by Customer as its AI provider	Subject to Anthropic's own safeguards
OpenAI	AI processing, where selected by Customer as its AI provider	Subject to OpenAI's own safeguards
Google	AI processing, where selected by Customer as its AI provider	Subject to Google's own safeguards
Slack Technologies (Salesforce)	Delivery of authorised IronYard notifications via Slack, where Customer connects Slack	International, subject to Slack's own safeguards
Apify	Company/prospect/competitor research, where enabled	International, subject to Apify's own safeguards
Hosting Ireland (mail.ironyard.io)	Transactional email delivery (verification, password reset, team invitations)	Ireland
Only one of Anthropic, OpenAI, or Google is active as Customer's AI provider at any given time, per Customer's own configuration choice.