Legal / Privacy Policy

Draft — pending legal review. This document has not yet been reviewed by counsel and may change before Irisend is generally available.

Privacy Policy

Effective date: 2026-09-25

This Privacy Policy explains how Irisend ("Irisend", "we", "us"), registered at [to be completed: COMPANY_ADDRESS] (KVK [to be completed: KVK_NUMBER]), collects, uses, and shares personal data.

Two roles. Irisend processes two categories of personal data:

  1. Account data — information about you as our Customer (or your team members) when you sign up for and use the Irisend dashboard and API. For this data, Irisend is the data controller and this Privacy Policy applies directly.
  2. Recipient/message data — information contained in or generated by the emails our Customers send through the Service (e.g., recipient email addresses, message content, open/click events) ("Customer Content"). For this data, Irisend is a data processor (or "service provider" under CCPA/CPRA) acting only on the instructions of our Customer, who is the controller. If you received an email sent via Irisend and have questions about that email, please contact the sender directly — we are not able to act on data-subject requests about Customer Content ourselves except as instructed by, or under the direct arrangement with, our Customer. Our processing of Customer Content is governed by our Data Processing Agreement, not this Privacy Policy.

The rest of this policy addresses our role as controller of account data.

1. What We Collect

  • Account and identity data: name, email address, password hash, company name, billing address, tax ID, phone number (optional).
  • Payment data: processed by our payment processor (Stripe); we store limited metadata (e.g., last 4 card digits, subscription status) but not full card numbers.
  • Usage and log data: API requests, dashboard interactions, IP address, browser/device information, timestamps, sending volumes, and diagnostic logs, collected for security, billing, and service-improvement purposes.
  • Support communications: content of support tickets, emails, and chat messages you send us.
  • Cookies and similar technologies: see our Cookie Policy.

2. How We Use Account Data

We use account data to: provide and operate the Service; authenticate and secure accounts; process payments and prevent fraud; provide customer support; send service, security, and billing communications; monitor and improve the Service (including aggregated, de-identified analytics); comply with legal obligations (e.g., tax, accounting, know-your-customer checks); and, where you have opted in, send product updates and marketing communications.

3. Legal Bases (GDPR / UK GDPR)

Where GDPR or UK GDPR applies, we rely on:

  • Contract (Art. 6(1)(b)) — to create and operate your account and provide the Service.
  • Legitimate interests (Art. 6(1)(f)) — for fraud prevention, service security, product analytics, and direct marketing to existing customers about similar products (with an opt-out in every message).
  • Consent (Art. 6(1)(a)) — for non-essential cookies and marketing emails to non-customers, revocable at any time.
  • Legal obligation (Art. 6(1)(c)) — for tax, accounting, and law-enforcement requests.

4. Sharing and Subprocessors

We do not sell your personal data. We share account data with:

  • Service providers who process data on our behalf under contract (hosting, email delivery, payment processing, analytics, customer support tooling) — see our Subprocessors list, updated as providers change.
  • Professional advisors (lawyers, auditors, accountants) as needed.
  • Successors in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.
  • Authorities, where required to comply with law, court order, or to protect the rights, property, or safety of Irisend, our users, or the public.

5. International Data Transfers

Irisend is based in the Netherlands. Some of our subprocessors (e.g., AWS, Stripe) process data outside the EEA/UK, including in the United States. Where we transfer personal data outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (2021/914, as applicable modules), the UK International Data Transfer Addendum, and/or the recipient's certification under the EU-U.S. Data Privacy Framework (and UK extension), together with supplementary technical and organizational measures, as the applicable safeguard.

6. Data Retention

We retain account data for as long as your account is active and for a reasonable period afterward to comply with legal obligations (e.g., tax records, typically 7 years), resolve disputes, and enforce agreements. Server and access logs are generally retained for up to 12 months. You may request earlier deletion subject to Section 8.

7. Security

We apply technical and organizational measures described in our Security page, including encryption in transit, access controls, and monitoring. No system is 100% secure; we will notify affected individuals and authorities of a qualifying personal data breach as required by applicable law (e.g., within 72 hours of becoming aware, under GDPR Art. 33).

8. Your Rights

Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to processing; receive a portable copy of your data; and withdraw consent at any time (without affecting prior lawful processing).

  • EEA/UK residents (GDPR/UK GDPR): exercise these rights via legal@irisend.dev. You also have the right to lodge a complaint with your local supervisory authority (in the Netherlands: the Autoriteit Persoonsgegevens).
  • California residents (CCPA/CPRA): you have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information (we do not sell or share personal information for cross-context behavioral advertising) and the right to non-discrimination for exercising these rights. Submit requests via legal@irisend.dev.
  • Other jurisdictions: we will honor equivalent rights available under applicable local law (e.g., Canada's PIPEDA, Australia's Privacy Act) on request.

We will respond to verified requests within the time required by applicable law (e.g., one month under GDPR, extendable by two months for complex requests; 45 days under CCPA).

9. Children

The Service is not directed to individuals under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact legal@irisend.dev for deletion.

10. Marketing Emails From Us

If you subscribe to product updates or marketing from Irisend, every message includes a one-click unsubscribe link and, where applicable, RFC 8058 List-Unsubscribe / List-Unsubscribe-Post headers. You can also manage preferences from your account settings.

11. Changes to This Policy

We will post updates here and, for material changes, notify you via email or in-dashboard notice at least 30 days before they take effect.

12. Contact

Data controller: Irisend, [to be completed: COMPANY_ADDRESS], legal@irisend.dev.

If we appoint an EU representative under GDPR Art. 27 or a UK representative under UK GDPR Art. 27 (required if Irisend has no EU/UK establishment but targets EU/UK individuals), their contact details will be listed here: [to be completed: EU_REPRESENTATIVE_CONTACT].


This document is a draft template and does not constitute legal advice. See research/legal.md for review recommendations before publishing.