Skip to content
IronMemo

Trust Center

Everything you need to evaluate IronMemo's security, compliance, and data practices.

Compliance Status

GDPRAligned
HIPAANot offered
ISO 27001Not certified
CCPAAligned

Data Practices

Data Location

netcup GmbH data centre in Austria (European Economic Area). One location for every customer and every plan - there is no region setting.

Data Retention

Source audio and video are kept 30 days by default; a workspace can set 7, 30 or 90 days, or keep them until deleted manually. On Enterprise an administrator or owner sets a custom period for the whole workspace, from 24 hours. Removal from active systems completes within 48 hours.

Sub-processors

Every sub-processor is published on our Sub-processors page - purpose, legal entity, processing region and retention for each one. It mirrors Annex III of the DPA.

Incident Response

On a confirmed breach of personal data we notify affected customers within 72 hours of discovery and the supervisory authority within the statutory timeframe. Where we act as a processor, the DPA governs the notification.

Security Documents

Privacy PolicyView
Terms of ServiceView
Data Processing AgreementView
Sub-processorsView
Cookie PolicyView

Questions about security?

Contact our security team: security@ironmemo.com

Request Security Review