IRIS Privacy Policy — Version 1.0
Effective date: 25 August 2026. This policy explains how personal data is handled when you visit getiris.uk, use IRIS, contact inLIFE or connect an authorised business service to IRIS.
1. Who we are
inLIFE Design Ltd (company number 06400955), whose registered office is Hales Court, Stourbridge Road, Halesowen, England, B63 3TT, provides IRIS — the inLIFE Real-time Intelligence System. For privacy questions or requests, email [email protected].
For account administration, billing, direct enquiries, security and our own service communications, inLIFE is normally the data controller. When we process a client’s website enquiries or connected business data only on that client’s instructions, the client is normally the controller and inLIFE is its processor.
2. Data we handle
- Account and contact data: name, business, role, email address, phone number, authorised users, support messages and service preferences.
- Business Brain and content: approved website pages, business facts, uploaded documents, article ideas, drafts, publishing instructions and selected images.
- Website Chat and leads: visitor conversations, consent choices, enquiry details and delivery status. The IRIS client is responsible for its website privacy information and lawful use of those enquiries.
- Connected service data: authorised identifiers, reporting metrics and content from services such as Google Analytics, Search Console, Google Business Profile, Facebook Pages, Instagram business accounts, LinkedIn, WordPress and WooCommerce. We only request access needed for the features the client chooses.
- AI and voice requests: questions, instructions, responses and resulting transcripts. When a user starts or activates a voice turn, audio may be transmitted securely to a speech provider for transcription. IRIS does not intentionally store ordinary room audio as a business record.
- Billing data: package, subscription, invoice and payment status. Card details are entered into and handled by Stripe rather than stored by IRIS.
- Technical and security data: device and browser information, timestamps, service logs, connection status and privacy-protected evidence derived from IP addresses or user agents.
3. How we obtain data
We receive data from users and website visitors; from an IRIS client or its authorised administrator; from websites and documents a client asks IRIS to use; and from connected services after an authorised user completes that provider’s sign-in and consent process.
4. Why we use data
- to create, secure and administer IRIS accounts and subscriptions;
- to answer business questions, provide reports, operate Website Chat, deliver enquiries and carry out authorised content or publishing actions;
- to connect, maintain and troubleshoot selected third-party services;
- to provide support, service notices, requested alerts and account communications;
- to prevent fraud, misuse and security incidents, keep the service reliable and improve performance; and
- to meet accounting, tax, legal and regulatory duties.
Depending on the activity, our lawful basis under the UK GDPR is performance of a contract, legitimate interests in providing and protecting a business service, consent where it is required, or compliance with a legal obligation. A client using IRIS as controller is responsible for its own lawful basis and notices.
5. Facebook, Instagram and other connected accounts
When a client connects Meta, IRIS may use authorised Facebook Page and Instagram business-account data to list available destinations, show performance information and publish content the client has approved. IRIS does not use this access to publish to personal profiles, sell Platform Data or access unrelated accounts.
Clients can disconnect Meta or another provider from the Business Brain connections area. They may also remove IRIS through the provider’s own account settings. See the IRIS data-deletion instructions for the steps and what happens next.
6. AI providers and automated output
Selected business content and user instructions may be sent to contracted AI or speech providers to produce the requested result. We configure provider access and retention controls appropriate to a business service and do not permit client data to be used to build a competing client profile. AI output may be inaccurate and should be checked before important use or publication.
7. Who receives data
We disclose data only where needed to provide or protect the service, follow an authorised instruction, comply with law or complete a business transaction with appropriate safeguards. Recipients may include:
- authorised users and administrators of the relevant IRIS client;
- hosting, database, encrypted backup, email, monitoring, customer-support, AI and speech providers;
- Stripe for billing and payment administration;
- Google, Meta, LinkedIn, WordPress and other services a client chooses to connect or publish to; and
- professional advisers, regulators or law-enforcement bodies where legally required.
We do not sell personal data.
8. International transfers
Some providers may process data outside the UK. Where UK data-protection law requires it, we use an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard, together with proportionate security measures.
9. Retention and deletion
We keep data only for as long as reasonably needed for the purpose described, the client’s active service, security, dispute handling and legal obligations. Account and connected business data is deleted or anonymised after the service ends in accordance with the agreement and normal protected-backup cycle, unless law requires longer retention. Accounting and transaction records may be kept for the statutory period.
Disconnecting a service stops new collection through that connection and removes or revokes its stored access credentials. A deletion request can also cover previously imported Platform Data, subject to data we must keep for legal, fraud-prevention or dispute purposes.
10. Security
IRIS uses measures including tenant separation, role-based access, encrypted connector credentials, protected transport, restricted administration, rate limiting, operational monitoring, security logging and protected backups. No online service can guarantee absolute security, so users should use unique credentials and promptly report suspected unauthorised access.
11. Cookies and local storage
IRIS uses essential cookies or browser storage to maintain secure sessions, remember necessary interface settings and protect the service. Optional analytics or marketing technologies will only be used where an appropriate notice and consent mechanism is provided.
12. Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict personal data; object to processing; receive portable data; withdraw consent; and complain. Email [email protected] with enough information to identify the relevant account or interaction. We may need to verify your identity. If the data belongs to an IRIS client’s records, we may refer the request to that client as controller.
You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.
13. Changes and contact
We may update this policy when IRIS, the law or connected services change. The current version and effective date will remain available on this page. Questions and requests can be sent to [email protected].