Third Party Index

Snapshot 49234

Document
Privacy policy
URL
https://ironyard.io/Privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
72082 bytes
SHA-256 (raw)
ecc42002f1087b88d6458d6d4c02f2d885811b3e5184d05c959718d174a6ed7b
SHA-256 (normalized text)
d31ec891e215ff9395fcd5560c4e907e7f1626ed267e97a94d3aed2554da7a6c

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Legal
Privacy Policy
Effective 3 September 2026
1. Purpose
This Privacy Policy explains how Iron Yard Limited ("IronYard", "we", "us", or "our") collects, uses, stores and protects personal data when you use the IronYard application, our CRM-integrated sales productivity, pipeline intelligence and sales coaching platform (the "Service").
The Service is intended for use by businesses and their authorised users. It may process personal data relating to employees, customers, prospects, contacts and other individuals whose information is contained in a connected CRM, email, calendar or other business system.
This Privacy Policy applies to:
account holders and administrators;
employees, contractors and other authorised users of customer organisations; and
individuals whose personal data is processed through an organisation's use of the Service.
This Privacy Policy should be read together with any applicable Terms of Service, Data Processing Agreement ("DPA") and other contractual terms between IronYard and your organisation, where such agreements are in place.
2. Controller and Processor Roles
The role IronYard plays under data protection law depends on how personal data is processed.
Where IronYard acts as a processor
When an organisation connects its CRM, email, calendar or other business systems to IronYard, IronYard generally processes the personal data contained in those systems on behalf of that organisation.
In these circumstances, the organisation is generally the data controller and IronYard acts as its data processor. The organisation determines the purposes for which the personal data is processed and is responsible for ensuring that it has an appropriate legal basis for providing the data to IronYard.
Where a Data Processing Agreement has been entered into between IronYard and the organisation, IronYard processes such data in accordance with the organisation's instructions and that agreement.
Where IronYard acts as a controller
IronYard acts as a data controller for information that it determines how and why to process itself. This includes information relating to account administration, billing, security, service administration, product analytics, customer support and business communications.
3. GDPR and UK GDPR
IronYard is based in Ireland and complies with applicable data protection legislation, including:
Regulation (EU) 2016/679 (the "GDPR"); and
the UK GDPR and Data Protection Act 2018, where applicable.
Where IronYard acts as a controller, our legal bases for processing may include:
Performance of a contract — where processing is necessary to provide the Service or manage your account;
Legitimate interests — for purposes such as security, fraud prevention, service improvement, technical support and business administration, where those interests are not overridden by your rights;
Consent — where we rely on consent for a particular processing activity, including certain optional integrations; and
Legal obligation — where processing is necessary to comply with applicable law.
Where IronYard acts as a processor, the relevant customer organisation is responsible for determining the appropriate legal basis for processing the personal data concerned.
4. Information We Collect
4.1 Account and user information
When an IronYard account is created or administered, we may collect:
name;
business email address;
company name;
job title or role;
authentication information;
account preferences;
subscription and billing information; and
information provided when contacting IronYard for support.
Passwords are protected using bcrypt cryptographic hashing and are not stored in plain text.
4.2 CRM data
When an organisation connects a supported CRM, IronYard may access and process information made available through the authorised integration.
Supported CRM systems include:
HubSpot;
Salesforce;
Pipedrive;
Attio; and
Zoho.
Depending on the integration and permissions granted, this may include:
deals and opportunities;
contacts;
companies;
CRM users and sales representatives;
pipeline stages;
deal values;
dates and activity history;
notes and other CRM activity; and
other information made available through the authorised CRM connection.
IronYard accesses information required to provide the relevant Service features and uses the permissions granted through the CRM's authorisation process. Access to connected CRM data is read-only — IronYard does not create, edit or delete records in a connected CRM unless a particular integration or feature expressly provides otherwise and the customer has authorised that functionality.
4.3 Google Calendar
If you choose to connect Google Calendar, IronYard may access your primary calendar on a read-only basis.
This may include:
event title;
start and end time; and
attendee information.
IronYard uses this information to identify relevant upcoming sales meetings and provide meeting preparation and coaching features.
IronYard does not use Google Calendar data for advertising.
4.4 Gmail
If you choose to connect Gmail, IronYard may access Gmail information using the permissions you grant.
This may include:
sender and recipient information;
subject;
message date and time; and
relevant email content.
IronYard uses relevant Gmail information to provide sales coaching, deal analysis, summaries and related Service features.
Gmail data is not sold or used for advertising.
Where email content is transmitted to the AI provider selected by the customer's organisation to generate a requested coaching output or summary, it is transmitted only for that purpose and is subject to the restrictions and safeguards described in this Privacy Policy and any applicable contractual arrangements.
IronYard's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect Google Calendar or Gmail from IronYard at any time through your account settings or revoke IronYard's access through your Google account permissions.
When an integration is disconnected, IronYard stops accessing new information through that integration and deletes synchronised data from its active systems in accordance with the deletion provisions in this Privacy Policy.
4.5 Slack
If you connect Slack, IronYard uses the authorised Slack integration to deliver coaching alerts, notifications and daily briefings.
IronYard does not read Slack channel history or private Slack messages for this purpose.
The Slack integration operates through Slack OAuth and is limited to the permissions required to deliver the relevant IronYard notifications.
4.6 Web research and Apify
Where enabled, IronYard may use Apify to perform company, prospect or competitor research and retrieve publicly available information.
Information retrieved through these research functions may be processed by IronYard to provide research, sales intelligence and related Service features.
IronYard does not use this functionality to access private accounts, bypass access controls or obtain information that is not made available through the applicable research service.
4.7 Automatically collected information
When you use the Service, we may automatically collect:
IP address;
browser and device information;
login information;
timestamps;
application activity and usage information;
error and diagnostic information; and
security and audit logs.
IronYard uses this information to operate and secure the Service, diagnose technical problems, prevent abuse and understand how the Service is used.
Vercel Web Analytics is used within the customer-facing Sales Hub application to understand product usage. IronYard does not use Google Analytics, Meta Pixel or third-party advertising or targeting analytics within the Service or on the IronYard marketing website.
5. How We Use Personal Data
Data processed through the Service is used to:
provide and operate IronYard;
analyse sales pipelines and deals;
calculate deal and pipeline health;
provide sales coaching and recommendations;
generate summaries and briefings;
provide forecasting and pipeline intelligence;
provide meeting preparation;
perform optional company and competitor research;
maintain and improve Service performance;
maintain security and prevent fraud or misuse;
provide technical support;
administer accounts and subscriptions;
process payments; and
communicate with customers about the Service.
We do not sell personal data.
We do not use customer CRM, email or calendar data for third-party advertising.
6. AI Processing
Some IronYard features, including coaching, briefings, deal summaries and related sales intelligence, are powered by large language models.
Each organisation selects which AI provider processes its data when setting up IronYard. The available providers are:
Anthropic;
OpenAI; or
Google.
Only one AI provider is active for an organisation at any given time.
Only the relevant deal, sales, communication and coaching context reasonably necessary to generate the requested output is sent to the selected provider. Data belonging to different customer organisations is logically separated and is not mixed for processing.
Depending on the customer's configuration, IronYard may use the customer's own encrypted AI provider API key or an IronYard platform API key.
IronYard does not use customer data to train its own AI models — IronYard does not build or train any general-purpose AI model. Each of Anthropic, OpenAI and Google publishes its own policy on whether data submitted through its commercial API is used to train its models; as of the effective date of this policy, all three state that they do not use API-submitted data for that purpose by default. IronYard relies on the selected provider's own published terms in this respect and does not itself configure or override that behaviour.
AI processing is performed solely to provide the requested IronYard functionality and is subject to the applicable contractual, security and data protection safeguards.
Limited Use compliance statement. IronYard's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information accessed through Google Calendar and Gmail is used only to provide and improve the user-facing IronYard features described in this Privacy Policy — meeting preparation, deal-relevant email summaries and related coaching output — and is not used to train general-purpose AI or machine-learning models beyond generating the individual user's own requested output.
7. Automated Analysis and Profiling
IronYard uses automated analysis, statistical techniques and AI-assisted processing to analyse sales and business information.
This may produce:
deal health scores;
pipeline assessments;
sales recommendations;
alerts;
forecasts;
summaries;
activity assessments; and
other sales insights.
These outputs are intended to assist sales professionals in making business decisions.
IronYard does not make solely automated decisions that produce legal or similarly significant effects on individuals.
Organisations using IronYard remain responsible for how they use IronYard's outputs when making decisions about their employees, customers or other individuals.
8. Who We Share Data With
IronYard shares personal data with service providers where necessary to operate the Service.
Employees and authorised personnel
IronYard employees and authorised contractors may access personal data where reasonably necessary to operate, maintain, secure or support the Service. Access is subject to appropriate confidentiality obligations and access controls.
Sub-processors
IronYard uses the following principal sub-processors and service providers:
Provider	Purpose	Processing location / scope
Supabase	Database hosting and management	EU — AWS eu-central-1, Frankfurt
Google Cloud Platform	Application hosting	EU — europe-west3, Frankfurt
Vercel	Frontend hosting and Web Analytics	EU — fra1, Frankfurt
Stripe	Payment processing and billing	International, subject to applicable safeguards
Anthropic	AI processing where selected by the organisation	Subject to applicable provider configuration and safeguards
OpenAI	AI processing where selected by the organisation	Subject to applicable provider configuration and safeguards
Google	AI processing where selected by the organisation	Subject to applicable provider configuration and safeguards
Slack Technologies / Salesforce	Delivery of authorised IronYard notifications through Slack	International, subject to applicable safeguards
Apify	Company, prospect and competitor research	International, subject to applicable safeguards
Hosting Ireland / mail.ironyard.io	Transactional email delivery, including verification, password reset and team invitations	Ireland
Each processor or subprocessor is required to process personal data only for the purposes for which it has been engaged and subject to appropriate contractual and data protection obligations.
9. International Data Transfers
Some IronYard service providers may process personal data outside the European Economic Area ("EEA") or the United Kingdom.
Where personal data is transferred outside the EEA or UK, IronYard will use an appropriate lawful transfer mechanism where required by applicable data protection law.
Depending on the destination and circumstances, this may include:
an adequacy decision;
the European Commission's Standard Contractual Clauses;
the UK International Data Transfer Agreement or UK Addendum; or
another legally recognised transfer mechanism.
Where appropriate, IronYard will implement additional contractual, technical or organisational safeguards for international transfers.
Information about the processing locations of our principal subprocessors is provided in the Subprocessor section above.
10. How Long We Store Data
Account, CRM, and calendar/email data is retained for as long as your organisation's account remains active.
If your organisation closes its account, all associated data — including deals, contacts, activity history, synchronised emails and calendar events, and account records — is permanently deleted from IronYard's active systems at the time of closure.
A small number of operational records may be retained for up to 90 days where reasonably necessary for security and billing purposes. These may include token usage records, AI research history and deal-health computation history. After this period, they are automatically deleted or stripped of identifying detail on a nightly basis.
Encrypted backup copies, where applicable, may remain for the duration of the relevant backup cycle before being securely overwritten or deleted.
Certain information may also be retained where required by applicable law or where reasonably necessary to establish, exercise or defend legal claims.
11. Data Deletion
Customers may request deletion of their data by contacting IronYard.
Where IronYard acts as a processor under a Data Processing Agreement, we will delete or return personal data in accordance with the customer's instructions and that agreement, subject to legal retention requirements.
When an integration is disconnected, IronYard stops obtaining new information through that integration and deletes the previously synchronised data from its active systems in accordance with the applicable deletion process.
Deletion from active systems does not necessarily mean immediate deletion from encrypted disaster-recovery backups. Backup copies are subject to controlled retention and are not ordinarily restored except where necessary for disaster recovery or security purposes.
12. Security
IronYard uses technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures include:
encryption of data in transit using TLS;
AES-256-GCM encryption of stored CRM and OAuth access tokens and API keys;
secure password hashing using bcrypt;
JWT-based session authentication;
separate signing secrets for customer/representative and IronYard staff sessions;
role-based access controls;
least-privilege access to production systems;
controlled access to production data;
security and audit logging;
encrypted backups and disaster-recovery measures;
employee confidentiality obligations; and
monitoring and incident-response procedures.
Access to production data is limited to authorised personnel who reasonably require access to operate, maintain or support the Service.
No method of transmitting or storing information is completely secure. While IronYard takes reasonable measures to protect personal data, we cannot guarantee absolute security.
13. Security Incidents and Data Breaches
If IronYard becomes aware of a security incident involving personal data, we will assess and respond to the incident in accordance with applicable law and any applicable contractual obligations.
Where IronYard acts as a processor under a Data Processing Agreement, we will notify the affected customer without undue delay where required by applicable law or that agreement and provide information reasonably necessary for the customer to assess and meet its own regulatory obligations.
14. Your Data Protection Rights
Depending on the circumstances and applicable law, individuals may have rights including:
the right to be informed about how personal data is processed;
the right of access;
the right to rectification;
the right to erasure;
the right to restriction of processing;
the right to data portability;
the right to object to certain processing; and
rights relating to automated decision-making where applicable.
Where IronYard acts as a data processor on behalf of an organisation, requests relating to that data should normally be directed to the relevant organisation, which is the data controller.
IronYard will provide reasonable assistance to its customers in responding to valid data subject requests in accordance with applicable law and any applicable Data Processing Agreement.
Where IronYard acts as a data controller, you may exercise applicable rights by contacting us using the details below.
15. Complaints
If you have concerns about how IronYard processes your personal data, we encourage you to contact us first so that we can investigate and attempt to resolve the issue.
You also have the right to lodge a complaint with the relevant data protection supervisory authority.
For Ireland, the supervisory authority is the Data Protection Commission (DPC).
Individuals in other EEA countries or the United Kingdom may also have the right to contact the supervisory authority in the country where they live, work or believe an infringement has occurred.
16. Cookies and Analytics
IronYard uses cookies and similar technologies within the Service where necessary to:
keep users securely signed in;
maintain sessions;
remember user preferences; and
support the operation and security of the Service.
IronYard does not use third-party advertising or targeting cookies.
Vercel Web Analytics is used within the customer-facing Sales Hub application for product usage analytics. It is not used on the IronYard internal staff application or marketing website.
IronYard does not use Google Analytics, Meta Pixel or similar third-party advertising or targeting technologies.
Where additional non-essential cookies or analytics technologies are introduced, IronYard will provide appropriate information and obtain consent where required by applicable law.
17. Children's Privacy
IronYard is a business application intended for use by sales professionals and organisations. It is not directed at children.
We do not knowingly seek to collect personal data from children. If we become aware that we have inadvertently collected personal data from a child in circumstances where collection was not permitted, we will take reasonable steps to delete it.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our processing activities, technology or applicable law.
We will update the effective date when changes are made.
Where we consider a change to be material, we will provide reasonable notice to affected customers, which may include notifying account administrators by email or through the Service.
19. Contact
For questions about this Privacy Policy or IronYard's handling of personal data:
Iron Yard Limited Unit 6E, Nutgrove Office Park Rathfarnham Dublin 14 D14 A0X2 Ireland
privacy@ironyard.io
Last updated: 3 September 2026