This Privacy Policy explains how Iron Yard Limited ("IronYard", "we", "us", or "our") collects, uses, stores and protects personal data when you use the IronYard application, our CRM-integrated sales productivity, pipeline intelligence and sales coaching platform (the "Service").
The Service is intended for use by businesses and their authorised users. It may process personal data relating to employees, customers, prospects, contacts and other individuals whose information is contained in a connected CRM, email, calendar or other business system.
This Privacy Policy applies to:
This Privacy Policy should be read together with any applicable Terms of Service, Data Processing Agreement ("DPA") and other contractual terms between IronYard and your organisation, where such agreements are in place.
The role IronYard plays under data protection law depends on how personal data is processed.
When an organisation connects its CRM, email, calendar or other business systems to IronYard, IronYard generally processes the personal data contained in those systems on behalf of that organisation.
In these circumstances, the organisation is generally the data controller and IronYard acts as its data processor. The organisation determines the purposes for which the personal data is processed and is responsible for ensuring that it has an appropriate legal basis for providing the data to IronYard.
Where a Data Processing Agreement has been entered into between IronYard and the organisation, IronYard processes such data in accordance with the organisation's instructions and that agreement.
IronYard acts as a data controller for information that it determines how and why to process itself. This includes information relating to account administration, billing, security, service administration, product analytics, customer support and business communications.
IronYard is based in Ireland and complies with applicable data protection legislation, including:
Where IronYard acts as a controller, our legal bases for processing may include:
Where IronYard acts as a processor, the relevant customer organisation is responsible for determining the appropriate legal basis for processing the personal data concerned.
When an IronYard account is created or administered, we may collect:
Passwords are protected using bcrypt cryptographic hashing and are not stored in plain text.
When an organisation connects a supported CRM, IronYard may access and process information made available through the authorised integration.
Supported CRM systems include:
Depending on the integration and permissions granted, this may include:
IronYard accesses information required to provide the relevant Service features and uses the permissions granted through the CRM's authorisation process. Access to connected CRM data is read-only — IronYard does not create, edit or delete records in a connected CRM unless a particular integration or feature expressly provides otherwise and the customer has authorised that functionality.
If you choose to connect Google Calendar, IronYard may access your primary calendar on a read-only basis.
This may include:
IronYard uses this information to identify relevant upcoming sales meetings and provide meeting preparation and coaching features.
IronYard does not use Google Calendar data for advertising.
If you choose to connect Gmail, IronYard may access Gmail information using the permissions you grant.
This may include:
IronYard uses relevant Gmail information to provide sales coaching, deal analysis, summaries and related Service features.
Gmail data is not sold or used for advertising.
Where email content is transmitted to the AI provider selected by the customer's organisation to generate a requested coaching output or summary, it is transmitted only for that purpose and is subject to the restrictions and safeguards described in this Privacy Policy and any applicable contractual arrangements.
IronYard's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect Google Calendar or Gmail from IronYard at any time through your account settings or revoke IronYard's access through your Google account permissions.
When an integration is disconnected, IronYard stops accessing new information through that integration and deletes synchronised data from its active systems in accordance with the deletion provisions in this Privacy Policy.
If you connect Slack, IronYard uses the authorised Slack integration to deliver coaching alerts, notifications and daily briefings.
IronYard does not read Slack channel history or private Slack messages for this purpose.
The Slack integration operates through Slack OAuth and is limited to the permissions required to deliver the relevant IronYard notifications.
Where enabled, IronYard may use Apify to perform company, prospect or competitor research and retrieve publicly available information.
Information retrieved through these research functions may be processed by IronYard to provide research, sales intelligence and related Service features.
IronYard does not use this functionality to access private accounts, bypass access controls or obtain information that is not made available through the applicable research service.
When you use the Service, we may automatically collect:
IronYard uses this information to operate and secure the Service, diagnose technical problems, prevent abuse and understand how the Service is used.
Vercel Web Analytics is used within the customer-facing Sales Hub application to understand product usage. IronYard does not use Google Analytics, Meta Pixel or third-party advertising or targeting analytics within the Service or on the IronYard marketing website.
Data processed through the Service is used to:
We do not sell personal data.
We do not use customer CRM, email or calendar data for third-party advertising.
Some IronYard features, including coaching, briefings, deal summaries and related sales intelligence, are powered by large language models.
Each organisation selects which AI provider processes its data when setting up IronYard. The available providers are:
Only one AI provider is active for an organisation at any given time.
Only the relevant deal, sales, communication and coaching context reasonably necessary to generate the requested output is sent to the selected provider. Data belonging to different customer organisations is logically separated and is not mixed for processing.
Depending on the customer's configuration, IronYard may use the customer's own encrypted AI provider API key or an IronYard platform API key.
IronYard does not use customer data to train its own AI models — IronYard does not build or train any general-purpose AI model. Each of Anthropic, OpenAI and Google publishes its own policy on whether data submitted through its commercial API is used to train its models; as of the effective date of this policy, all three state that they do not use API-submitted data for that purpose by default. IronYard relies on the selected provider's own published terms in this respect and does not itself configure or override that behaviour.
AI processing is performed solely to provide the requested IronYard functionality and is subject to the applicable contractual, security and data protection safeguards.
Limited Use compliance statement. IronYard's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Information accessed through Google Calendar and Gmail is used only to provide and improve the user-facing IronYard features described in this Privacy Policy — meeting preparation, deal-relevant email summaries and related coaching output — and is not used to train general-purpose AI or machine-learning models beyond generating the individual user's own requested output.
IronYard uses automated analysis, statistical techniques and AI-assisted processing to analyse sales and business information.
This may produce:
These outputs are intended to assist sales professionals in making business decisions.
IronYard does not make solely automated decisions that produce legal or similarly significant effects on individuals.
Organisations using IronYard remain responsible for how they use IronYard's outputs when making decisions about their employees, customers or other individuals.
IronYard shares personal data with service providers where necessary to operate the Service.
IronYard employees and authorised contractors may access personal data where reasonably necessary to operate, maintain, secure or support the Service. Access is subject to appropriate confidentiality obligations and access controls.
IronYard uses the following principal sub-processors and service providers:
| Provider | Purpose | Processing location / scope |
|---|---|---|
| Supabase | Database hosting and management | EU — AWS eu-central-1, Frankfurt |
| Google Cloud Platform | Application hosting | EU — europe-west3, Frankfurt |
| Vercel | Frontend hosting and Web Analytics | EU — fra1, Frankfurt |
| Stripe | Payment processing and billing | International, subject to applicable safeguards |
| Anthropic | AI processing where selected by the organisation | Subject to applicable provider configuration and safeguards |
| OpenAI | AI processing where selected by the organisation | Subject to applicable provider configuration and safeguards |
| AI processing where selected by the organisation | Subject to applicable provider configuration and safeguards | |
| Slack Technologies / Salesforce | Delivery of authorised IronYard notifications through Slack | International, subject to applicable safeguards |
| Apify | Company, prospect and competitor research | International, subject to applicable safeguards |
| Hosting Ireland / mail.ironyard.io | Transactional email delivery, including verification, password reset and team invitations | Ireland |
Each processor or subprocessor is required to process personal data only for the purposes for which it has been engaged and subject to appropriate contractual and data protection obligations.
Some IronYard service providers may process personal data outside the European Economic Area ("EEA") or the United Kingdom.
Where personal data is transferred outside the EEA or UK, IronYard will use an appropriate lawful transfer mechanism where required by applicable data protection law.
Depending on the destination and circumstances, this may include:
Where appropriate, IronYard will implement additional contractual, technical or organisational safeguards for international transfers.
Information about the processing locations of our principal subprocessors is provided in the Subprocessor section above.
Account, CRM, and calendar/email data is retained for as long as your organisation's account remains active.
If your organisation closes its account, all associated data — including deals, contacts, activity history, synchronised emails and calendar events, and account records — is permanently deleted from IronYard's active systems at the time of closure.
A small number of operational records may be retained for up to 90 days where reasonably necessary for security and billing purposes. These may include token usage records, AI research history and deal-health computation history. After this period, they are automatically deleted or stripped of identifying detail on a nightly basis.
Encrypted backup copies, where applicable, may remain for the duration of the relevant backup cycle before being securely overwritten or deleted.
Certain information may also be retained where required by applicable law or where reasonably necessary to establish, exercise or defend legal claims.
Customers may request deletion of their data by contacting IronYard.
Where IronYard acts as a processor under a Data Processing Agreement, we will delete or return personal data in accordance with the customer's instructions and that agreement, subject to legal retention requirements.
When an integration is disconnected, IronYard stops obtaining new information through that integration and deletes the previously synchronised data from its active systems in accordance with the applicable deletion process.
Deletion from active systems does not necessarily mean immediate deletion from encrypted disaster-recovery backups. Backup copies are subject to controlled retention and are not ordinarily restored except where necessary for disaster recovery or security purposes.
IronYard uses technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures include:
Access to production data is limited to authorised personnel who reasonably require access to operate, maintain or support the Service.
No method of transmitting or storing information is completely secure. While IronYard takes reasonable measures to protect personal data, we cannot guarantee absolute security.
If IronYard becomes aware of a security incident involving personal data, we will assess and respond to the incident in accordance with applicable law and any applicable contractual obligations.
Where IronYard acts as a processor under a Data Processing Agreement, we will notify the affected customer without undue delay where required by applicable law or that agreement and provide information reasonably necessary for the customer to assess and meet its own regulatory obligations.
Depending on the circumstances and applicable law, individuals may have rights including:
Where IronYard acts as a data processor on behalf of an organisation, requests relating to that data should normally be directed to the relevant organisation, which is the data controller.
IronYard will provide reasonable assistance to its customers in responding to valid data subject requests in accordance with applicable law and any applicable Data Processing Agreement.
Where IronYard acts as a data controller, you may exercise applicable rights by contacting us using the details below.
If you have concerns about how IronYard processes your personal data, we encourage you to contact us first so that we can investigate and attempt to resolve the issue.
You also have the right to lodge a complaint with the relevant data protection supervisory authority.
For Ireland, the supervisory authority is the Data Protection Commission (DPC).
Individuals in other EEA countries or the United Kingdom may also have the right to contact the supervisory authority in the country where they live, work or believe an infringement has occurred.
IronYard uses cookies and similar technologies within the Service where necessary to:
IronYard does not use third-party advertising or targeting cookies.
Vercel Web Analytics is used within the customer-facing Sales Hub application for product usage analytics. It is not used on the IronYard internal staff application or marketing website.
IronYard does not use Google Analytics, Meta Pixel or similar third-party advertising or targeting technologies.
Where additional non-essential cookies or analytics technologies are introduced, IronYard will provide appropriate information and obtain consent where required by applicable law.
IronYard is a business application intended for use by sales professionals and organisations. It is not directed at children.
We do not knowingly seek to collect personal data from children. If we become aware that we have inadvertently collected personal data from a child in circumstances where collection was not permitted, we will take reasonable steps to delete it.
We may update this Privacy Policy from time to time to reflect changes to the Service, our processing activities, technology or applicable law.
We will update the effective date when changes are made.
Where we consider a change to be material, we will provide reasonable notice to affected customers, which may include notifying account administrators by email or through the Service.
For questions about this Privacy Policy or IronYard's handling of personal data:
Iron Yard Limited Unit 6E, Nutgrove Office Park Rathfarnham Dublin 14 D14 A0X2 Ireland
Last updated: 3 September 2026