Legal
Last updated 25 August 2026.
This policy explains what personal data Ironimo collects, why we collect it, how long we keep it, and what you can require us to do with it. It is written to be read, not to be survived.
Ironimo ("we", "us") is a company established in the Netherlands and is the data controller for the personal data described in this policy. For privacy matters, contact privacy@ironimo.online.
Where you use Ironimo to scan your own systems, you are the controller of any personal data that happens to appear in your scan results, and we act as your processor. We will sign a data processing agreement on request.
| Data | Why | Legal basis |
|---|---|---|
| Account data — name, email address, password hash, organisation | To create and secure your account and let you use the service | Performance of a contract |
| Scan configuration — target URLs, scan settings, and any credentials you supply for authenticated scanning | To run the scans you ask for | Performance of a contract |
| Scan results — findings, raw tool output, reports | To deliver the product you are paying for | Performance of a contract |
| Billing data — plan, invoices, payment reference | To charge you and meet tax and accounting obligations | Contract and legal obligation |
| Security and audit logs — authentication events, administrative actions, IP address | To detect abuse and investigate incidents | Legitimate interest in securing the service |
| Website analytics — pages viewed, referrer, approximate location, device type | To understand which content is useful and improve the site | Legitimate interest for cookieless page counts; consent (via the cookie banner) for persistent, cross-page analytics |
| Waitlist and marketing email addresses, where you gave one | To send you product updates you asked for | Consent — withdrawable at any time |
We do not collect special categories of personal data, and we ask that you do not put any into scan configurations.
This website uses PostHog for product analytics, served from PostHog's EU endpoint (eu.i.posthog.com). Before you make a choice on the cookie banner we count pages viewed and links clicked in a cookieless mode: nothing is stored on your device — no cookies, no browser storage, no cross-page profile, no session recording. Each page load is an unlinked, anonymous record. We do this on the basis of our legitimate interest in knowing whether our own website works. If you press Accept, analytics upgrade to persistent, cross-page measurement. If you press Decline, PostHog is not loaded at all and nothing further is sent.
You can change your mind by clearing this site's data in your browser, which removes the stored consent choice and makes the banner reappear.
Cookies strictly necessary to keep you logged into the application are set regardless of analytics consent, because the service cannot function without them.
We use a small number of subprocessors to run the service, including hosting, analytics, email delivery, and payment processing. Where a subprocessor is located outside the European Economic Area, transfers are covered by Standard Contractual Clauses or an adequacy decision.
The current subprocessor list is available on request from privacy@ironimo.online. We do not sell personal data, and we do not share it with advertisers or data brokers.
Passwords are hashed. Scanning credentials are encrypted at rest with Fernet symmetric encryption and decrypted only at scan time inside the scan worker; they are never included in a report or returned by the API. Access to production data is limited to the people who need it to operate the service. Details are on the Security page, including an honest account of the certifications we do not yet hold.
Under the GDPR you can require us to:
Email privacy@ironimo.online. We respond within one month. If you think we have handled your data badly, you can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens — though we would rather you told us first so we can fix it.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and tell affected customers without undue delay. We will tell you what happened, what data was involved, and what we are doing about it.
Ironimo is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16.
If we change this policy in a way that materially affects you, we will email account holders before it takes effect. The date at the top always reflects the current version.
Privacy questions and rights requests: privacy@ironimo.online
Security reports: security@ironimo.online
Everything else: contact@ironimo.online