This policy explains what personal data Ironimo collects, why we collect it, how long we keep it, and what you can require us to do with it. It is written to be read, not to be survived.

1. Who is responsible

Ironimo ("we", "us") is a company established in the Netherlands and is the data controller for the personal data described in this policy. For privacy matters, contact privacy@ironimo.online.

Where you use Ironimo to scan your own systems, you are the controller of any personal data that happens to appear in your scan results, and we act as your processor. We will sign a data processing agreement on request.

2. What we collect and why

DataWhyLegal basis
Account data — name, email address, password hash, organisation To create and secure your account and let you use the service Performance of a contract
Scan configuration — target URLs, scan settings, and any credentials you supply for authenticated scanning To run the scans you ask for Performance of a contract
Scan results — findings, raw tool output, reports To deliver the product you are paying for Performance of a contract
Billing data — plan, invoices, payment reference To charge you and meet tax and accounting obligations Contract and legal obligation
Security and audit logs — authentication events, administrative actions, IP address To detect abuse and investigate incidents Legitimate interest in securing the service
Website analytics — pages viewed, referrer, approximate location, device type To understand which content is useful and improve the site Legitimate interest for cookieless page counts; consent (via the cookie banner) for persistent, cross-page analytics
Waitlist and marketing email addresses, where you gave one To send you product updates you asked for Consent — withdrawable at any time

We do not collect special categories of personal data, and we ask that you do not put any into scan configurations.

3. Cookies and analytics

This website uses PostHog for product analytics, served from PostHog's EU endpoint (eu.i.posthog.com). Before you make a choice on the cookie banner we count pages viewed and links clicked in a cookieless mode: nothing is stored on your device — no cookies, no browser storage, no cross-page profile, no session recording. Each page load is an unlinked, anonymous record. We do this on the basis of our legitimate interest in knowing whether our own website works. If you press Accept, analytics upgrade to persistent, cross-page measurement. If you press Decline, PostHog is not loaded at all and nothing further is sent.

You can change your mind by clearing this site's data in your browser, which removes the stored consent choice and makes the banner reappear.

Cookies strictly necessary to keep you logged into the application are set regardless of analytics consent, because the service cannot function without them.

4. Who else processes your data

We use a small number of subprocessors to run the service, including hosting, analytics, email delivery, and payment processing. Where a subprocessor is located outside the European Economic Area, transfers are covered by Standard Contractual Clauses or an adequacy decision.

The current subprocessor list is available on request from privacy@ironimo.online. We do not sell personal data, and we do not share it with advertisers or data brokers.

5. How long we keep it

  • Account data — for as long as your account is open, then deleted within 90 days of closure
  • Scan results — 30 days on Starter, 90 days on Pro, indefinitely on Enterprise, or until you delete the target
  • Scanning credentials — until you delete the target they belong to
  • Billing records — 7 years, as required by Dutch tax law
  • Security and audit logs — 12 months
  • Analytics — as configured in PostHog, and never linked to an identified person unless you have an account

6. How it is protected

Passwords are hashed. Scanning credentials are encrypted at rest with Fernet symmetric encryption and decrypted only at scan time inside the scan worker; they are never included in a report or returned by the API. Access to production data is limited to the people who need it to operate the service. Details are on the Security page, including an honest account of the certifications we do not yet hold.

7. Your rights

Under the GDPR you can require us to:

  • Access — give you a copy of the personal data we hold about you
  • Rectify — correct anything inaccurate
  • Erase — delete your data, subject to legal retention obligations such as invoices
  • Restrict or object — stop or limit certain processing, including anything based on legitimate interest
  • Port — receive your data in a structured, machine-readable format
  • Withdraw consent — for analytics or marketing, at any time, without affecting processing already carried out

Email privacy@ironimo.online. We respond within one month. If you think we have handled your data badly, you can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens — though we would rather you told us first so we can fix it.

8. Data breaches

If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and tell affected customers without undue delay. We will tell you what happened, what data was involved, and what we are doing about it.

9. Children

Ironimo is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16.

10. Changes

If we change this policy in a way that materially affects you, we will email account holders before it takes effect. The date at the top always reflects the current version.

11. Contact

Privacy questions and rights requests: privacy@ironimo.online
Security reports: security@ironimo.online
Everything else: contact@ironimo.online

We count page views without cookies (PostHog, EU-hosted) — nothing is stored on your device until you choose. Accept for full analytics, Decline to switch it off entirely. No personal data is sold or shared with advertisers.