Legal
This Privacy Policy explains how Iridae ApS ("we", "us") processes personal data in connection with the Intelligence Platform (the "Service"). This policy is written for business customers.
Controller (for most business/contact/admin data): Iridae ApS, Maglebjergvej 6, 2800 Kongens Lyngby, Denmark. Email: privacy@iridae.com
When you upload content or provide links that contain personal data, you typically do so on behalf of your organization. In that case:
The processing is governed by our DPA: /legal/dpa/
We are the Controller for personal data we process to run our business, such as:
This Privacy Policy mainly describes this Controller-side processing, and it also summarizes Processor-side handling at a high level.
We may collect:
Important: You control what you submit into the Service. We strongly discourage submitting unnecessary personal data in uploads/links.
We use personal data to:
We rely on:
Where consent is required (typically cookies/analytics in the EU), we will request it.
When you use the Service, your organization may submit documents, game materials, and links that could include personal data. In most cases we process this as a Processor under the DPA.
AI and subprocessors. We may use our own models and third-party AI providers/subprocessors to generate Outputs as described in our AI Policy and in our Subprocessor list.
Training and improvement. Unless you have a written no-training agreement with us, we may use Customer Content to improve the Service, including training our systems, as described in the AI Policy and DPA. We aim to do this in privacy-preserving ways (for example, learning model updates/weights rather than reusing raw content across accounts), but residual risk cannot be eliminated entirely.
We share personal data with:
We do not sell personal data.
If personal data is processed outside the EU/EEA, we use appropriate safeguards (for example, adequacy decisions or Standard Contractual Clauses), as described in the DPA.
We use appropriate technical and organizational measures to protect personal data (access controls, encryption in transit, and other safeguards described at a high level in the DPA).
No system is perfectly secure. You are responsible for configuring access to any third-party links you provide.
If we are the Controller of your personal data, you may have rights to access, rectify, delete, restrict, object, and data portability, and to lodge a complaint with a supervisory authority.
To exercise rights, contact: privacy@iridae.com.
If the personal data is in Customer Content that we process as a Processor, we will generally refer you to the Customer (the Controller) or assist the Customer under the DPA.
We use analytics/cookies and describe them at /legal/cookies/ and (where required) obtain consent via a cookie banner and preference controls.
The Service is for business use and not directed to children. We do not knowingly collect children's personal data.
We may update this policy from time to time. We will post the updated version with a new effective date.