Legal
Privacy Policy
- Effective date
- August 28, 2026
- Version
- 2.6
- Status
- In force
Applies to: the ironmemo.com website, the cloud SaaS product, the API, enterprise deployments, and support (the "Service").
What this Policy covers
This Privacy Policy describes how Oxford Construction LLC ("IronMemo", "we", "us") collects, uses, stores, protects, and discloses personal data when you use IronMemo, our product (the "Service"). IronMemo is a product name, not a separate legal entity; where this Policy says "IronMemo", it means Oxford Construction LLC.
This Policy does not apply to data we process on behalf of corporate customers under enterprise agreements — such processing is governed by separate customer contracts and a Data Processing Addendum (DPA).
By using our Service, you agree to the practices described in this Policy. If you do not agree, do not use the Service.
How we handle your data: principles
Before we get into the details, we want to give direct answers to the questions people ask most often.
- Do we train our models on your data?
- No. We do not use your meetings, transcripts, summaries, or anything else you put into IronMemo to train or fine-tune IronMemo's own AI models. The same commitment is written into the Terms of Service and, for customers who sign one, into the Data Processing Agreement.This is not a setting you have to find and switch off - it is how the Service works.
- Do we sell your data?
- No. We do not sell, share, or license your personal data or meeting content to third parties for their own commercial purposes, advertising, marketing, or training of third-party AI models. Ever.
- Do we share data to train other companies' models?
- No. Your meeting content is not used to train, fine-tune, or improve any third party's AI models. When we send data to AI providers for processing (transcription, summary generation), it happens exclusively through enterprise API modes with a contractual ban on training and minimal or zero data retention (Zero Data Retention).
- Do we keep data longer than needed?
- No. Meeting data is stored while your workspace is active. After a recording is deleted or a subscription is cancelled, data is deleted within 30 days. Audio files uploaded on the free plan without registration are deleted immediately after processing.
- Do we distribute your data?
- No. We do not make meeting content publicly available, index it in search engines, pass it to ad networks, or use it for targeted or behavioral advertising.
How we improve the product
- Anonymized telemetry. Which features are used, where errors occur, how fast the Service responds, device type and app version, technical request IDs. It never carries audio, video, transcript fragments, summaries, meeting titles, participant names, email addresses, phone numbers, organisation names, or your prompts and outputs.
- Aggregate figures only. Counts and timings that cannot be matched to a specific user, workspace, or meeting.
- Never model training. Whatever we measure, none of it is used to train or fine-tune IronMemo's own AI models.
What data we collect
We collect only the data necessary to operate the Service, ensure security, provide support, and meet contractual and legal obligations.
Data you provide
| Category | Examples | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Account data | Name, email, company, role, hashed password, avatar, workspace settings, SSO/SCIM identifiers. | Contract performance (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)); consent for marketing communications (Art. 6(1)(a)). | While the account is active + 30 days after deletion. |
| Meeting data | Audio recordings, video recordings, transcripts, speaker identification, AI summaries, tasks, follow-up emails, metadata (duration, platform, participant list). | Contract performance; legitimate interest; consent where required by law. | Until deleted by the workspace admin, or 30 days after subscription cancellation. |
| Integration data | OAuth tokens, scopes, workspace IDs, data synced from CRMs, task trackers, messengers. | Contract performance; legitimate interest. | While the integration is connected + 30 days after disconnection. |
| Support requests | Tickets, feedback, correspondence with the support team, attachments. | Contract performance; legitimate interest; consent for marketing. | 3 years after the request is closed. |
Data we receive automatically
| Category | Examples | Legal basis | Retention |
|---|---|---|---|
| Logs and telemetry | IP address, user agent, browser and device type, OS, time zone, country, request date and time, navigation within the Service. | Legitimate interest; contract performance. | 90 days for general logs; 12 months for security and audit logs. |
| Usage data | Which features are used, frequency, errors, performance, response times, product events. | Legitimate interest. | 90 days in identified form; indefinitely in aggregated/anonymized form. |
| Cookies and similar technologies | Session cookies, authentication tokens, analytics cookies, cookie preferences. | Consent for non-essential cookies (Art. 6(1)(a)); legitimate interest for strictly necessary ones (Art. 6(1)(f)). | Session cookies — until the browser is closed; persistent — up to 12 months. |
Data from third-party sources
We may receive data from security partners to prevent fraud and abuse, and from payment systems to process transactions.
How we use data
To provide the Service
Connecting to Zoom, Google Meet, and Microsoft Teams; recording meetings; creating transcripts; detecting language and participants; generating summaries, tasks, and follow-up emails; indexing meetings in the knowledge base; powering AI chat and semantic search; keeping integrations running.
To perform actions in connected systems
If an administrator has connected integrations — creating tasks in trackers, updating CRM records, sending emails, publishing notes to messengers and knowledge bases.
To improve the product
Anonymized telemetry and usage logs: which features are used, where errors occur, performance metrics. This data does not contain your meeting content and is used for UX improvements, bug fixes, and feature planning.
To keep the Service secure
Logs, audit logs, IP addresses, user agent — to detect errors, unauthorized access, abuse, integration failures, and suspicious activity.
To communicate with you
Email, name, company, support history — to answer support requests and send service, billing, and security notifications. Marketing messages — only with your consent. Unsubscribing takes one click in every email.
To meet legal obligations
Storing and disclosing data where required by law, a court order, a regulator's request, tax rules, or to protect the rights of IronMemo, our customers, and users.
AI and your data
What AI processing IronMemo performs
| Processing | Input data | Result |
|---|---|---|
| Transcription | Meeting audio, language, participant metadata. | Text transcript with speaker labels. |
| Summary | Transcript, meeting structure, workspace settings. | Concise summary of the meeting. |
| Tasks | Transcript, context, participants. | Task list with owners and due dates. |
| Follow-up emails | Transcript, summary, participants, customer templates. | Draft follow-up email. |
| AI chat and search | Meeting index, transcripts, summaries, access permissions. | Answers from the workspace knowledge base. |
| Meeting analytics | Metadata, talk time, topics, sentiment. | Metrics and recommendations for administrators. |
Learn more about our AI: ironmemo.com/our-ai.
Third-party AI providers
We use third-party AI providers for processing. The set of providers depends on the meeting language and the type of processing. Each of them operates under enterprise (enterprise / API) modes and contractual terms, including:
- No training — your meeting content is not used to train, fine-tune, or improve third-party providers' models.
- Minimal retention — Zero Data Retention (ZDR) where the provider offers it; otherwise the provider's own limited retention window, published per provider on our Sub-processors page, with a contractual ban on using the data.
- API-only transfer — TLS 1.2 or later, with no data passed to consumer interfaces or open channels.
- Sub-processor role — providers process data strictly under our instructions.
- Processing locations — customer data is stored in Austria (EEA); AI processing takes place in the United States, and in Ireland for certain OpenAI operations.
The current list of sub-processors is published on our Sub-processors page and in Annex III of the DPA. When we add a new sub-processor, we notify account owners and enterprise administrators 30 days in advance.
What is never used to train AI models
IronMemo does not use Customer Content, including recordings, transcripts, summaries, prompts, outputs, uploaded files, or meeting metadata, to train, fine-tune, or improve IronMemo's own AI models or any third-party AI models. This restriction applies to all plans and does not require the user to opt out. The providers listed above process this content only to produce your results, under terms that forbid training on it.
What happens to the feedback you send us
If you rate a result or write to support, we use it to find out what is going wrong. A rating is not a channel for your meeting content:
- a rating on its own tells us that something was wrong, not what was said — meeting content is not attached to it automatically;
- if a fragment of content would help us reproduce a problem, we ask first, and you send it deliberately;
- feedback is never passed to a third-party AI provider for training;
- support correspondence follows the retention period for support requests in section 07.
Sharing data with third parties
We share data with third parties only where necessary to operate the Service.
| Category | Purpose | Region | Key safeguards |
|---|---|---|---|
| Cloud infrastructure | Hosting, storage, compute, networking, databases. | netcup GmbH data centre in Austria (European Economic Area). | DPA, Standard Contractual Clauses (SCC), encryption at rest and in transit. |
| Transcription AI providers | Audio transcription, diarization, language detection. | United States — Eleven Labs Inc., AssemblyAI Inc. | Enterprise API terms, TLS 1.2 or later, no-training clause; retention per provider, published on our Sub-processors page. |
| LLM AI providers | Summaries, tasks, emails, AI chat. | United States — OpenAI OpCo, LLC, Google LLC, X.AI LLC; OpenAI Ireland Ltd for certain non-US processing. | Enterprise / API terms, no-training clause; retention per provider, published on our Sub-processors page. |
| Billing | Payments, invoices, subscription management, fraud prevention. | Per the payment provider's terms. | PCI DSS, DPA, SCC. |
| Product analytics | Anonymized product events, aggregated statistics, errors. | Per the provider's terms. | Anonymized events only, no meeting content. Cookies are activated with consent. |
| Email notifications | Service emails, security alerts, product notices. | Per the provider's terms, SCC for EU data. | DPA, SCC. |
We do not sell your data or share it for advertising
IronMemo does not "sell" and does not "share" personal data or meeting content within the meaning of the CCPA as amended by the CPRA.
We:
- do not pass data to third parties for targeted or cross-context behavioral advertising;
- do not receive monetary or other valuable consideration for it;
- do not use data for advertising profiling.
When we are required to disclose data
We may disclose personal data:
- when required by law, a court order, or a regulator's request;
- to protect the rights, property, or safety of IronMemo, our users, or third parties;
- to prevent fraud, abuse, or violations of our terms;
- as part of corporate transactions (merger, acquisition, reorganization) — with notice to users.
Integrations the customer connects
If a customer connects Zoom, Google Meet, Teams, Slack, Jira, Salesforce, HubSpot, or other services, data may be transferred to those services according to the workspace administrator's settings. Such transfers are performed on the customer's instructions and are governed by the privacy policies of the respective services.
Data storage and deletion
Where data is stored
| Region | Infrastructure | Details |
|---|---|---|
| EU (Austria) | netcup GmbH data centre, Austria (European Economic Area) | All customers, from one storage location. IronMemo is provided as a cloud-hosted SaaS service: self-hosted, on-premises, private-cloud, customer-managed storage, and customer-managed encryption key deployments are not currently available unless expressly stated in an executed Enterprise Order Form. |
Retention periods
| Data category | Base period | After subscription cancellation |
|---|---|---|
| Account data | While the account is active. | 30 days. |
| Meeting audio and video | 30 days by default. Auto-deletion can be set to 7, 30, or 90 days, or the recordings can be kept until you delete them manually. On Enterprise, an administrator or owner can set a custom period for the whole workspace, from 24 hours. | 30 days after cancellation. |
| Uploaded files | The same as meeting audio and video: 30 days by default, or the period set for the workspace. If you delete a file yourself it leaves active access immediately and is removed from storage within 30 days. | 30 days after cancellation. |
| Transcripts and AI summaries | Per workspace settings. | 30 days after cancellation. |
| AI chat prompts and outputs | While the meeting or the workspace exists. Delete a meeting and its prompts, outputs and chat index go with it; removal from active systems completes within 30 days. | 30 days after workspace deletion. |
| Search index, embeddings and derived data | While the source document exists. When you delete the source, the linked embeddings, index entries and caches are queued for deletion and leave active systems within 30 days. | 30 days after workspace deletion. |
| Integration data | While the integration is connected. Refresh and access tokens are revoked or deleted as soon as you disconnect, wherever the provider makes that technically possible. | 30 days after disconnection. |
| Technical logs | 90 days. Request logs, performance data, errors, routing information and technical identifiers. They do not carry full meeting content, except where a specific error investigation requires it. | Kept until the period expires. |
| Security and audit logs | 12 months. On Enterprise, a longer period can be agreed in the Order Form. | Kept until the agreed period expires. |
| Backups | 30 days. Deleted data stays logically isolated, expires with the backup cycle, and is queued for deletion again if a backup is restored. | 30 days. |
| Billing records | 7 years, or another period required by applicable tax and accounting law. | 7 years. |
| Support requests | 3 years after closure. Attachments that contain your content are deleted earlier, once they are no longer needed to resolve the request. | 3 years. |
Enterprise workspaces can set different periods for audio and video and for text materials; the setting is applied by an administrator or owner and covers the whole workspace. When a period set here expires, the automatic deletion job removes the data from active systems within 48 hours. Deletion that you request yourself follows the timeline in “How to request deletion” below. Final deletion always runs in the same order: the data disappears from the interface immediately, leaves the main active systems within 30 days, is removed by the automatic job within 48 hours once a configured period expires, expires from backups by the end of the 30-day backup cycle, and is deleted at each sub-processor within the period published for that provider on our Sub-processors page. The only exception is a documented legal hold or a retention obligation imposed by law.
What happens when a subscription is cancelled
- Workspace access switches to read-and-export-only mode for 30 days.
- The administrator can export all data (transcripts, summaries, tasks) to JSON/CSV.
- After 30 days, workspace data is deleted unless we are legally required to keep it.
How to request deletion
| Method | Details |
|---|---|
| In the app | Settings → Privacy → Delete data / Delete account |
| dsar@ironmemo.com — include your account email and your request | |
| Form on this page | The privacy request form at the end of this Policy — your email and your request |
We confirm receipt of the request within 3 business days and complete deletion within 30 days, unless the law requires otherwise. We may ask you to verify your identity before deletion.
Encryption and security
| Measure | Description |
|---|---|
| Encryption in transit | Data is encrypted in transit using TLS 1.2 or later. TLS 1.3 is used where supported by the relevant client, endpoint, and service provider. |
| Encryption at rest | All stored data is encrypted at rest on our hosting infrastructure. |
| Access control | Role-based model, workspace-level permissions, SSO (SAML 2.0), SCIM provisioning, least-privilege principle for internal access. |
| Audit logs | Logs of user and administrator actions for security review and compliance export. |
| Data segmentation | Logical separation of data at the workspace level with tenant isolation. |
| Monitoring | Centralized logging, security alerts, error tracking, incident review. |
| Backups | Daily encrypted backups, retained for 30 days, in the same data centre. Backup copies stay logically isolated and are not returned to active use; if a backup is restored, data you deleted is queued for deletion again. |
| Employee access | IronMemo engineers access customer data only with the customer's permission and only for support purposes. |
Learn more: ironmemo.com/security.
Security breach notification
In the event of a confirmed security breach affecting personal data:
- we notify affected customers by email within 72 hours of discovery (in accordance with GDPR Art. 33);
- we notify the relevant supervisory authority within the timeframes required by law;
- we provide a description of the incident, the data affected, the measures taken, and recommendations.
Managing your data
We give you control over how your data is used and stored.
| Control | Where to configure |
|---|---|
| Meeting deletion — delete individual recordings, transcripts, summaries. | Dashboard → Meeting → Delete |
| Data export — download transcripts, summaries, tasks in JSON/CSV. | Settings → Privacy → Export data |
| Account deletion — complete deletion of your account and all related data. | Settings → Privacy → Delete account |
| Recording auto-deletion — 30 days by default; automatically delete audio files after 7, 30, or 90 days, or keep them until you delete them manually. On Enterprise, an administrator can set a custom period, from 24 hours. | Settings → Workspace → Retention |
| Cookie preferences — manage analytics and marketing cookies. | Cookie banner on the website |
| Marketing communications — unsubscribe from emails. | The "Unsubscribe" link in every email |
| Integrations — connect and disconnect third-party services. | Settings → Integrations |
We do not use your content to train IronMemo's own AI models, so there is no training setting to switch off. The commitment applies to every workspace by default.
Your rights
Depending on your country, role, and applicable law, you may have the following rights:
| Right | GDPR | CCPA / CPRA | How to exercise it |
|---|---|---|---|
| Access to data | Art. 15 | Right to know / access | Settings → Privacy → Export data; or email dsar@ironmemo.com |
| Correction | Art. 16 | Right to correct | Edit your profile in Settings or send a request to dsar@ironmemo.com |
| Deletion | Art. 17 | Right to delete | Delete in the workspace or request via dsar@ironmemo.com |
| Portability | Art. 20 | Right to data portability | Export data in JSON/CSV via Settings |
| Objection to processing | Art. 21 | Right to opt-out of sale/share | dsar@ironmemo.com |
| Restriction of processing | Art. 18 | Partially applicable | dsar@ironmemo.com |
| Withdrawal of consent | Art. 7 | Consent withdrawal | Cookie preferences; unsubscribe from emails; Settings → Privacy |
| Non-discrimination | — | Right to non-discrimination | We do not discriminate against users for exercising their rights. |
Response times
GDPR: without undue delay, within one month. May be extended by two months for complex requests — with notice.
CCPA / CPRA: within 45 calendar days. May be extended by an additional 45 days — with notice.
Verification
To protect your data, we may ask you to verify your identity before fulfilling a request. If we cannot verify your identity, we will not be able to fulfill the request.
Authorized agents
You may submit a request through an authorized agent. The agent must present written authorization, and we may additionally ask you to verify your identity. Send agent requests to dsar@ironmemo.com.
Appeals
If you disagree with our decision on your request, send an appeal to dsar@ironmemo.com. If the GDPR applies to you, you may also contact the data protection supervisory authority in your country of residence.
Meeting recordings and participant consent
IronMemo records meetings via Zoom, Google Meet, and Microsoft Teams using a bot participant or native APIs.
Responsibility for consent
The workspace administrator and the customer organization are responsible for obtaining meeting participants' consent in accordance with applicable laws, internal policies, and contractual obligations. This includes notifying participants about recording, transcription, AI processing, and storage.
Recording notice
By default, IronMemo enables a visual recording notice (bot name, banner in the meeting platform's interface) where the platform supports it. The administrator can configure notices in workspace settings.
Jurisdictions with stricter requirements
In a number of jurisdictions (California, Germany, Austria, several US states, and others), recording a call requires the consent of all participants. The customer must account for the legal requirements of the countries, regions, and industries where meeting participants are located.
Children
IronMemo is intended for use by organizations and professional teams.
- Minimum age: 16 in the GDPR context, 13 in the COPPA context.
- We do not knowingly collect children's personal data.
- If you believe a child has provided personal data to IronMemo, write to dsar@ironmemo.com. We will review the request and delete the data.
Changes to this Policy
We may update this Policy when the product, technologies, sub-processors, legal requirements, or our data processing practices change.
- Material changes: notice by email and/or in-app notification 30 days before the changes take effect. A change is material when it affects the no-training rule, the categories of data we collect, the purposes of processing, the main retention periods, the rules for transferring data, the list of key sub-processors, your rights, the contracting entity, or the terms for processing enterprise customer data.
- Notification channels: email to the account owner, email to the enterprise administrator, an in-app banner, a notice in the workspace admin panel, and a visible notice on this page.
- Non-material changes (wording clarifications, contact updates): take effect upon publication of the updated version on this page.
- Version 2.1 (July 28, 2026) - a correction, not a change of practice: the description of AI model training on customer data was removed because it did not reflect how the Service works. It takes effect on publication rather than after the 30-day notice period above, because that period is there to protect you before processing expands - and nothing here expands processing.
- Version 2.2 (July 30, 2026) - the contracting entity is named correctly as ALCHEMAX LLC, dba IronMemo; contact addresses moved to the ironmemo.com domain; the hosting description now matches Annex III of the DPA (netcup GmbH, Austria) instead of naming AWS regions and self-hosted deployments that were never offered; the encryption algorithm and the SOC 2 audit statement are removed as unverified. No processing was added, expanded, or started. Dedicated contact channels are published in section 17: privacy@ironmemo.com for privacy questions, dsar@ironmemo.com for data subject requests, security@ironmemo.com for vulnerability reports, dpa@ironmemo.com for the DPA and sub-processors, legal@ironmemo.com for legal notices. Section 07 now states the Enterprise custom retention floor of 24 hours and the 48-hour ceiling on the automatic deletion job, and corrects the billing-records period from 5 to 7 years to match tax and accounting law; section 17 names the Privacy Officer function.
- Version 2.3 (July 31, 2026) - a precision pass, not a change of practice. Section 02 spells out what anonymized telemetry never contains; section 05 explains what happens to a rating or a support message; section 07 adds rows for uploaded files, AI chat prompts and outputs, technical logs and backups, states that access tokens are revoked as soon as an integration is disconnected, corrects the security and audit log period to 12 months with a longer period available to Enterprise by Order Form, and sets out the order in which deletion completes, including the legal-hold exception; section 14 lists what counts as a material change, the channels used to announce one, and the changes that would need your consent rather than a notice. A privacy request form is published at the end of this page. No processing was added, expanded, or started.
- Version 2.4 (July 31, 2026) - the contracting entity is Oxford Construction LLC (California Entity No. 202131210808), 1968 South Coast Highway, Suite 4811, Laguna Beach, CA 92651, United States. IronMemo is the name of the product, not a separate legal entity; where this Policy says "IronMemo", it means Oxford Construction LLC. Nothing else changed: no processing, retention period, sub-processor, transfer mechanism or right was added, expanded or removed by this version.
- Version 2.5 (August 3, 2026) - a governing-language clause is added: this Policy is maintained in English, translations are provided for convenience, and if a translation conflicts with the English version, the English version prevails. A wording clarification, not a change of practice - it takes effect on publication.
- Version 2.6 (August 28, 2026) - a factual correction to the scope line: the Policy applies to the ironmemo.com website, the cloud SaaS product, the API, enterprise deployments, and support. Mobile and desktop apps are removed from the scope because no such apps exist or are offered today; if they ship, this Policy will be updated before release. A wording correction, not a change of practice - it takes effect on publication.
Changes that would need your consent, not just a notice
A notice would not be enough if we ever decided to:
- use meeting content to train AI models, which we do not do today;
- use your data for advertising;
- pass your data to a new independent controller;
- use voiceprints or biometric identification;
- change the purposes of processing to something incompatible with the purpose the data was collected for.
Each of those would require a separate opt-in. None of them is in place today, and none is planned.
Additional disclosures for US states
Certain US state laws (CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and others) require additional disclosures.
| Category of personal data | Use | Disclosure to third parties |
|---|---|---|
| Identifiers (name, email, IP address, device ID) | Providing the Service, security, support, product improvement, communication. | Infrastructure and service vendors, AI providers, government authorities where required by law. |
| Commercial information (transaction history, subscription plan) | Billing, fraud prevention, accounting. | Payment provider, auditors. |
| Internet activity data (logs, feature usage) | Security, product improvement, error diagnostics. | Analytics vendor (anonymized data). |
| User content (meeting recordings, transcripts, summaries) | Providing the Service; improving IronMemo models (when the setting is enabled, in anonymized form). | AI providers (sub-processors) for processing. |
| Geolocation data (country/region by IP) | Security and fraud prevention. | Not disclosed to third parties. |
We do not "sell" personal data. We do not "share" personal data for cross-context behavioral advertising. We do not process sensitive personal information for purposes that trigger the right to limit.
International data transfers
IronMemo's contracting entity, Oxford Construction LLC, is registered in the State of California, USA. Customer data is stored on infrastructure located in Austria (European Economic Area), and personal data may also be processed in the United States by the sub-processors listed on our Sub-processors page.
Transfer mechanisms (EEA/UK → US)
- Standard Contractual Clauses (SCC) — in place with every sub-processor that processes EU/UK residents' data.
- Data Processing Addendum (DPA) — available to enterprise customers on request at dpa@ironmemo.com.
We apply the safeguards described in this Policy regardless of where the data is processed.
Contact
| Field | Value |
|---|---|
| Legal name | Oxford Construction LLC |
| California Entity No. | 202131210808 |
| Registered address | 1968 South Coast Highway, Suite 4811, Laguna Beach, CA 92651, United States |
| Jurisdiction | State of California, USA |
| Responsible function | Privacy Officer — Legal and Compliance |
| Privacy questions | privacy@ironmemo.com |
| Data subject requests (access, deletion, portability, objection, appeals) | dsar@ironmemo.com |
| Security reports and vulnerability disclosure | security@ironmemo.com |
| DPA and sub-processors | dpa@ironmemo.com |
| Legal notices and Terms of Service | legal@ironmemo.com |
| General inquiries | info@ironmemo.com |
Who is responsible inside IronMemo
Privacy is owned by an internal Privacy Officer function within Legal and Compliance. We publish the function rather than a person's name. It is responsible for data subject requests, privacy complaints, privacy reviews of sub-processors, the record of processing activities, updates to this Policy, coordination with Security, and international transfer assessments. IronMemo has not appointed a statutory Data Protection Officer under GDPR Article 37 or an EU representative under Article 27; each appointment would follow a documented assessment before any commercial launch in the European Economic Area. Reach the function at privacy@ironmemo.com.
Right to contact a supervisory authority
If the GDPR applies to you, you may contact the data protection supervisory authority (Data Protection Authority) in the country of your residence, your place of work, or the alleged violation.
Questions? Write to us: privacy@ironmemo.com
Ask a privacy question
Describe your question or the problem, and tell us where to reply. This form opens your mail client with the request already written - nothing reaches us until you send it from there.
No mail client? Write to privacy@ironmemo.com