Skip to content
IronMemo

Your meetings. Your data. Your control.

Security-first architecture from day one. No compromises, no fine print.

How we protect your data

Encryption in transit and at rest

Data is encrypted in transit using TLS 1.2 or later. TLS 1.3 is used where supported by the relevant client, endpoint, and service provider. Stored data is encrypted on our hosting infrastructure in Austria.

Zero Training Policy

Your data is never used to train IronMemo's own AI models, and the third-party providers in our pipeline are contractually barred from training on it. Source audio follows your workspace retention setting.

Every sub-processor published

The full list of third parties that touch your data - what each one does, where it runs, how long it keeps data - is public, not available on request. We give 30 days' notice before adding one.

GDPR Compliant

GDPR-aligned processing with a DPA and Standard Contractual Clauses. Data is stored in the EU, in Austria.

Infrastructure

Cloud Provider

Hosted on netcup GmbH infrastructure in a data centre in Austria (European Economic Area). One location: no additional regions and no customer-hosted deployment today.

Data residency

EU (Austria) for every customer and every plan. Data does not leave the European Economic Area, there is no region setting, and Annex III of the DPA names the same location.

Backup Policy

Daily encrypted backups with 30-day retention, held in the same data centre. Deleted data does not return to active use if a backup is restored.

Uptime SLA

99.9% uptime target. Real-time status page at status.ironmemo.com. Security incidents go to security@ironmemo.com.

Data Handling

What We Collect

Audio/video recordings, transcripts, AI-generated summaries, and account information. We collect only what is needed to deliver the service.

Retention Policy

You control retention periods. Set auto-delete policies by team or project. Default retention follows your plan settings.

Deletion Process

Delete individual recordings or all data at any time. Permanent deletion within 30 days of request, including backups.

Access Control

Only you and your team members access your data. Our engineering team accesses data only for support requests with your explicit permission.

Compliance

GDPR

Full compliance with EU General Data Protection Regulation. Data Processing Agreement (DPA) available for all customers.

CCPA / CPRA

Disclosures and request handling for California and other US state privacy laws. Requests go to dsar@ironmemo.com.

Data Processing Agreement

Standard DPA ready for enterprise customers. Custom DPA available on request for organizations with specific requirements.

Subprocessors

The full sub-processor list is published on our Sub-processors page, with 30 days' notice before we add one.

How We Protect Your Data

Encryption at Rest

Stored data - recordings, transcripts and summaries - is encrypted at rest on our hosting infrastructure. Backups are encrypted and expire on a 30-day cycle.

Encryption in Transit

Data is encrypted in transit using TLS 1.2 or later. TLS 1.3 is used where supported by the relevant client, endpoint, and service provider.

Access Control

Role-based access control, SSO via SAML, and SCIM provisioning. Your IT team stays in control.

Our AI Commitment

  • IronMemo does not use Customer Content to train, fine-tune or improve its own AI models or any third-party AI models - on every plan, with no opt-out to find
  • AI providers are contractually barred from training on your data, and each provider's retention is published on our Sub-processors page
  • Best AI model selected automatically per language - a primary plus a verified fallback, chosen from 95 benchmarked speech models
  • You own your data. Export or delete anytime. We provide data portability tools.
  • Anti-hallucination bar: models that invent text during silence are banned, and every transcript passes automated quality checks before delivery

Security FAQ

IronMemo offers multiple recording methods including browser extension and file upload. You choose what works best for your organization.

On netcup GmbH infrastructure in a data centre in Austria (European Economic Area), encrypted at rest and in transit (TLS 1.2 or later). There is one storage location and no US region. IronMemo is provided as a cloud-hosted SaaS service: self-hosted, on-premises, private-cloud, customer-managed storage, and customer-managed encryption key deployments are not currently available unless expressly stated in an executed Enterprise Order Form.

No. We never use your meeting data to train AI models. Your conversations remain private and are processed only to deliver your transcripts and summaries.

All your data is permanently deleted within 30 days of account deletion. Enterprise customers can request immediate deletion.

Create a free account at app.ironmemo.com and start getting transcripts, summaries, and action items right away. The free plan needs no credit card.Get started free

We are GDPR-aligned: a DPA with Standard Contractual Clauses, a published sub-processor list and a documented deletion process. We are not certified under SOC 2, ISO 27001 or HIPAA, and we do not sign BAAs.

Ready to stop losing what matters in your meetings?

Start for free. No credit card required.

Free plan · No credit card · Setup in 60 seconds