IRIS by inLIFEPrivacy information

IRIS Privacy Policy — Version 1.0

Effective date: 25 August 2026. This policy explains how personal data is handled when you visit getiris.uk, use IRIS, contact inLIFE or connect an authorised business service to IRIS.

1. Who we are

inLIFE Design Ltd (company number 06400955), whose registered office is Hales Court, Stourbridge Road, Halesowen, England, B63 3TT, provides IRIS — the inLIFE Real-time Intelligence System. For privacy questions or requests, email [email protected].

For account administration, billing, direct enquiries, security and our own service communications, inLIFE is normally the data controller. When we process a client’s website enquiries or connected business data only on that client’s instructions, the client is normally the controller and inLIFE is its processor.

2. Data we handle

3. How we obtain data

We receive data from users and website visitors; from an IRIS client or its authorised administrator; from websites and documents a client asks IRIS to use; and from connected services after an authorised user completes that provider’s sign-in and consent process.

4. Why we use data

Depending on the activity, our lawful basis under the UK GDPR is performance of a contract, legitimate interests in providing and protecting a business service, consent where it is required, or compliance with a legal obligation. A client using IRIS as controller is responsible for its own lawful basis and notices.

5. Facebook, Instagram and other connected accounts

When a client connects Meta, IRIS may use authorised Facebook Page and Instagram business-account data to list available destinations, show performance information and publish content the client has approved. IRIS does not use this access to publish to personal profiles, sell Platform Data or access unrelated accounts.

Clients can disconnect Meta or another provider from the Business Brain connections area. They may also remove IRIS through the provider’s own account settings. See the IRIS data-deletion instructions for the steps and what happens next.

6. AI providers and automated output

Selected business content and user instructions may be sent to contracted AI or speech providers to produce the requested result. We configure provider access and retention controls appropriate to a business service and do not permit client data to be used to build a competing client profile. AI output may be inaccurate and should be checked before important use or publication.

7. Who receives data

We disclose data only where needed to provide or protect the service, follow an authorised instruction, comply with law or complete a business transaction with appropriate safeguards. Recipients may include:

We do not sell personal data.

8. International transfers

Some providers may process data outside the UK. Where UK data-protection law requires it, we use an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard, together with proportionate security measures.

9. Retention and deletion

We keep data only for as long as reasonably needed for the purpose described, the client’s active service, security, dispute handling and legal obligations. Account and connected business data is deleted or anonymised after the service ends in accordance with the agreement and normal protected-backup cycle, unless law requires longer retention. Accounting and transaction records may be kept for the statutory period.

Disconnecting a service stops new collection through that connection and removes or revokes its stored access credentials. A deletion request can also cover previously imported Platform Data, subject to data we must keep for legal, fraud-prevention or dispute purposes.

10. Security

IRIS uses measures including tenant separation, role-based access, encrypted connector credentials, protected transport, restricted administration, rate limiting, operational monitoring, security logging and protected backups. No online service can guarantee absolute security, so users should use unique credentials and promptly report suspected unauthorised access.

11. Cookies and local storage

IRIS uses essential cookies or browser storage to maintain secure sessions, remember necessary interface settings and protect the service. Optional analytics or marketing technologies will only be used where an appropriate notice and consent mechanism is provided.

12. Your rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict personal data; object to processing; receive portable data; withdraw consent; and complain. Email [email protected] with enough information to identify the relevant account or interaction. We may need to verify your identity. If the data belongs to an IRIS client’s records, we may refer the request to that client as controller.

You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.

13. Changes and contact

We may update this policy when IRIS, the law or connected services change. The current version and effective date will remain available on this page. Questions and requests can be sent to [email protected].