Your meetings. Your data. Your control.
Security-first architecture from day one. No compromises, no fine print.
How we protect your data
Encryption in transit and at rest
Data is encrypted in transit using TLS 1.2 or later. TLS 1.3 is used where supported by the relevant client, endpoint, and service provider. Stored data is encrypted on our hosting infrastructure in Austria.
Zero Training Policy
Your data is never used to train IronMemo's own AI models, and the third-party providers in our pipeline are contractually barred from training on it. Source audio follows your workspace retention setting.
Every sub-processor published
The full list of third parties that touch your data - what each one does, where it runs, how long it keeps data - is public, not available on request. We give 30 days' notice before adding one.
GDPR Compliant
GDPR-aligned processing with a DPA and Standard Contractual Clauses. Data is stored in the EU, in Austria.
Infrastructure
Cloud Provider
Hosted on netcup GmbH infrastructure in a data centre in Austria (European Economic Area). One location: no additional regions and no customer-hosted deployment today.
Data residency
EU (Austria) for every customer and every plan. Data does not leave the European Economic Area, there is no region setting, and Annex III of the DPA names the same location.
Backup Policy
Daily encrypted backups with 30-day retention, held in the same data centre. Deleted data does not return to active use if a backup is restored.
Uptime SLA
99.9% uptime target. Real-time status page at status.ironmemo.com. Security incidents go to security@ironmemo.com.
Data Handling
What We Collect
Audio/video recordings, transcripts, AI-generated summaries, and account information. We collect only what is needed to deliver the service.
Retention Policy
You control retention periods. Set auto-delete policies by team or project. Default retention follows your plan settings.
Deletion Process
Delete individual recordings or all data at any time. Permanent deletion within 30 days of request, including backups.
Access Control
Only you and your team members access your data. Our engineering team accesses data only for support requests with your explicit permission.
Compliance
GDPR
Full compliance with EU General Data Protection Regulation. Data Processing Agreement (DPA) available for all customers.
CCPA / CPRA
Disclosures and request handling for California and other US state privacy laws. Requests go to dsar@ironmemo.com.
Data Processing Agreement
Standard DPA ready for enterprise customers. Custom DPA available on request for organizations with specific requirements.
Subprocessors
The full sub-processor list is published on our Sub-processors page, with 30 days' notice before we add one.
How We Protect Your Data
Encryption at Rest
Stored data - recordings, transcripts and summaries - is encrypted at rest on our hosting infrastructure. Backups are encrypted and expire on a 30-day cycle.
Encryption in Transit
Data is encrypted in transit using TLS 1.2 or later. TLS 1.3 is used where supported by the relevant client, endpoint, and service provider.
Access Control
Role-based access control, SSO via SAML, and SCIM provisioning. Your IT team stays in control.
Our AI Commitment
- IronMemo does not use Customer Content to train, fine-tune or improve its own AI models or any third-party AI models - on every plan, with no opt-out to find
- AI providers are contractually barred from training on your data, and each provider's retention is published on our Sub-processors page
- Best AI model selected automatically per language - a primary plus a verified fallback, chosen from 95 benchmarked speech models
- You own your data. Export or delete anytime. We provide data portability tools.
- Anti-hallucination bar: models that invent text during silence are banned, and every transcript passes automated quality checks before delivery
Security FAQ
Ready to stop losing what matters in your meetings?
Start for free. No credit card required.
Free plan · No credit card · Setup in 60 seconds