Legal
Privacy & Data Policy
Irys legal AI services, a product of Iqidis, Inc.
Iqidis, Inc. · 3 Columbus Circle, Floor 15, New York, NY 10019
Effective: May 15, 2026
Owner: Legal & Security, Iqidis, Inc. · Contact: info@iqidis.ai
1. Introduction
Iqidis, Inc. (“Iqidis,” “we,” “us,” or “our”) is committed to protecting privacy and safeguarding information.
This Privacy & Data Policy explains how we collect, use, disclose, secure, and retain information when you use the Irys legal AI platform, our websites, and related applications and services (collectively, the “Services”).
“Irys” is a product name and brand of Iqidis, Inc. and is not a separate legal entity.
This Policy should be read together with our Terms of Service, Acceptable Use Policy, Cookie Policy, Disclaimer, and Service Providers & Subprocessors Policy.
2. Scope and Roles
This Policy applies to:
- customers and authorized users of the Services;
- visitors to our websites;
- prospective customers who interact with us through demos, events, forms, or other communications; and
- other individuals whose information we process in connection with operating the Services.
Organization Customers
Where an organization uses Irys and determines the purposes and means of processing Customer Content, the organization acts as the controller and Iqidis generally acts as its processor or service provider.
Authorized Users act on behalf of the applicable organization.
Customer Content and Output remain subject to the ownership provisions in the Terms of Service and applicable customer agreements.
Iqidis as Controller
Iqidis may act as a controller for information it processes for its own legitimate business purposes, including account administration, billing, website operations, security, fraud prevention, legal compliance, and marketing communications.
3. Information We Collect
Information You Provide
We may collect:
- Account and Profile Information: such as name, email address, organization, role, and authentication information.
- Billing Information: payment and billing information processed through approved payment providers.
- Customer Content: documents, prompts, files, text, and other information submitted to or generated through the Services.
- Support and Feedback: information provided through support requests, product feedback, or other communications.
Information Collected Automatically
We may collect limited operational information such as:
- IP address;
- browser and device information;
- timestamps;
- authentication and security events;
- general location information derived from IP; and
- interaction and performance metadata used to operate, secure, and improve the Services.
Ordinary operational telemetry is designed not to include the substantive contents of customer prompts, model outputs, or uploaded documents except where processing is reasonably necessary for an authorized support, security, incident-response, or legal-compliance purpose.
Information from Third Parties
We may receive limited information from service providers, security and fraud-prevention partners, event or marketing platforms, and other sources consistent with this Policy.
Publicly Available Information
Iqidis may use publicly available legal and other information to develop, operate, and improve the Services in accordance with applicable law.
4. How We Use Information
We may use information to:
- provide and operate the Services;
- process customer requests and generate Output;
- provide customer support;
- maintain account and billing functions;
- improve reliability, performance, and product functionality;
- detect and prevent fraud, misuse, and security threats;
- comply with legal obligations;
- enforce our agreements and policies;
- communicate service, administrative, and product updates; and
- analyze general usage patterns and performance.
Where Iqidis acts as a processor, Customer Personal Data is processed on the applicable customer’s documented instructions and in accordance with the applicable agreement and Data Processing Addendum, where applicable.
5. AI Processing and Customer Content
Irys uses a combination of Iqidis-controlled systems and approved third-party service providers to deliver the Services.
No Training on Customer Content
Iqidis does not use Customer Content to train Iqidis or third-party foundation models unless expressly agreed otherwise in writing.
Where third-party AI providers process Customer Content as part of the Services, they are subject to applicable contractual, privacy, security, and data-use controls.
Iqidis configures third-party AI services to restrict training and vendor-side retention or caching where supported and applicable to the Services.
Current providers are identified in our Service Providers & Subprocessors Policy.
Data Minimization
Iqidis seeks to limit data sent to third-party providers to information reasonably necessary to perform the applicable function.
Data Isolation
Customer Content is logically segregated by organization and applicable user or workspace controls.
Customer Content is not intentionally pooled with unrelated customers’ Customer Content for model training.
6. Access, Storage, and Retention
Authorized Access
Access to Customer Content by Iqidis personnel is limited to authorized purposes such as:
- providing customer support;
- troubleshooting technical issues;
- maintaining and securing the Services;
- investigating incidents;
- complying with legal obligations; and
- enforcing applicable agreements.
Access is subject to appropriate access controls and confidentiality obligations.
Customer Content Retention
Customer Content may be retained during an active subscription as necessary to provide the Services and according to applicable customer settings and agreements.
Upon termination or expiration, Customer Content is handled in accordance with the Terms of Service and, where applicable, the Data Processing Addendum.
Residual copies may remain temporarily in secure backup systems until overwritten in the ordinary course.
Operational Data
Operational logs and telemetry may be retained for periods reasonably necessary for security, reliability, fraud prevention, compliance, and service operation.
7. Sharing and Disclosure
Iqidis does not sell Customer Personal Data.
We may disclose information to:
- Service Providers and Subprocessors necessary to provide and secure the Services;
- professional advisors such as attorneys, auditors, and insurers;
- government authorities or regulators where legally required;
- business transaction participants in connection with a merger, acquisition, financing, or similar transaction, subject to appropriate protections;
- other Authorized Users where directed through the Services and applicable organization permissions; and
- other parties with your consent or at your direction.
Current service providers and subprocessors are listed in our Service Providers & Subprocessors Policy.
8. Organization Accounts
Where Customer Content is created within an Organization Account, that content is processed within the applicable organization context.
Organization administrators may manage users, roles, and organization-level controls.
Access to individual user workspaces is governed by the product’s applicable permissions and administrative features.
When an Authorized User is removed from an Organization, that user’s access to the applicable Organization Account is terminated. Customer Content associated with the Organization remains subject to the Organization’s rights and applicable agreement.
9. Security
Iqidis maintains technical and organizational measures designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, loss, and misuse.
These measures may include:
- encryption in transit and at rest;
- role-based and least-privilege access controls;
- authentication and identity-management controls;
- security logging and monitoring;
- vulnerability-management and security-testing processes;
- network and infrastructure protections;
- secure software-development practices; and
- incident-response procedures.
Iqidis maintains SOC 2 Type II attestation and ISO/IEC 27001:2022 certification, and its data-protection program complies with HIPAA, GDPR, and CPRA. A Business Associate Agreement (BAA) is available for customers subject to HIPAA. Current reports and certificates are available under NDA on request.
No security system can eliminate all risk, and these measures do not constitute a guarantee that a security incident can never occur.
10. Personal Data Breaches
If Iqidis becomes aware of a Personal Data Breach affecting Customer Personal Data for which Iqidis acts as a processor, Iqidis will notify the applicable Customer without undue delay in accordance with Applicable Data Protection Laws and any applicable Data Processing Addendum.
Where reasonably practicable, the notice will include information then available regarding:
- the nature of the incident;
- affected information or individuals, where known;
- likely consequences;
- mitigation or remediation measures; and
- other information reasonably necessary for the Customer to meet applicable legal obligations.
Information may be provided in phases as the investigation develops.
Notification does not constitute an admission of fault or liability.
Iqidis does not publicly identify customers in connection with security incidents unless authorized by the customer or required by law.
11. Customer Security Responsibilities
Customers are responsible for:
- managing Authorized Users;
- protecting credentials;
- removing access when authorization ends;
- configuring available security controls appropriate to their environment;
- maintaining security of customer-controlled devices and systems; and
- promptly reporting suspected unauthorized access or account compromise.
12. Data Processing Addendum
Where Iqidis acts as a processor and applicable law or the parties’ agreement requires additional processor terms, the Iqidis Data Processing Addendum (“DPA”) may be incorporated into the applicable Order Form, enterprise agreement, or other customer agreement.
The DPA addresses matters including:
- controller and processor obligations;
- subprocessors;
- security;
- Data Subject rights;
- audits;
- deletion and return;
- international data-transfer mechanisms; and
- related privacy obligations.
If there is a conflict between this Policy and an applicable DPA, the DPA controls for the matters it governs.
The DPA is available where applicable by contacting info@iqidis.ai.
13. International Data Transfers
Customer Personal Data may be processed in the United States and other supported locations depending on the Services, customer configuration, and applicable service providers.
Where applicable law requires a transfer mechanism for Personal Data transferred internationally, Iqidis uses appropriate safeguards, which may include:
- European Commission Standard Contractual Clauses;
- the UK International Data Transfer Addendum;
- recognized Swiss transfer safeguards;
- adequacy decisions; or
- other lawful mechanisms available under Applicable Data Protection Laws.
Additional details are contained in the applicable DPA and Service Providers & Subprocessors Policy.
14. Privacy Rights
Depending on applicable law and Iqidis’s role in the Processing, individuals may have rights to:
- request access to Personal Data;
- correct inaccurate Personal Data;
- request deletion;
- restrict or object to certain Processing;
- obtain eligible Personal Data in a portable format;
- withdraw consent where Processing is based on consent; and
- lodge a complaint with a relevant supervisory authority.
Where Customer Personal Data is processed by Iqidis on behalf of an organization, requests relating to that Customer Personal Data should generally be directed to the applicable organization.
Requests relating to Personal Data for which Iqidis acts as controller may be submitted to:
info@iqidis.ai
Iqidis may take reasonable steps to verify identity before fulfilling a request.
15. Automated Decision-Making
Iqidis does not use Personal Data for solely automated decision-making that produces legal or similarly significant effects on individuals unless expressly disclosed and permitted by applicable law.
16. Children’s Privacy
The Services are not intended for individuals under 18 acting as users of the Services.
Iqidis does not knowingly create accounts for children under 18.
Customer Content may contain information about minors where lawfully submitted by customers in connection with legal matters or other professional use.
17. Cookies and Tracking Technologies
Our use of cookies and similar technologies is described in the Cookie Policy.
Where required by applicable law, users may manage non-essential cookies and related preferences through available consent controls.
18. Changes to This Policy
Iqidis may update this Policy to reflect changes in law, technology, the Services, or our business practices.
Material changes will be communicated with reasonable advance notice where appropriate.
The current version will identify its effective date.
19. Contact Us
Iqidis, Inc.
3 Columbus Circle, Floor 15
New York, NY 10019
Email: info@iqidis.ai