Security & compliance
Your data,
safe by design.
Sell without the legal worry. Everything you need to prove your clients' data is safe is built in, and ready to forward to their legal team.
Security
Secure at
every layer.
The controls that protect data before anyone even asks for a policy.
-
Encryption
Data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256.
-
Access control
Multi-factor authentication on every system, plus role-based permissions, so people only see what they should.
-
Workspace isolation
Each workspace is isolated. One client's conversations are never mixed with another's.
-
Certified infrastructure
Irelia is built on SOC 2 and ISO 27001 certified cloud infrastructure, with automated backups and continuous monitoring.
-
Responsible disclosure
Found a vulnerability? Report it to info@irelia.ai and we'll act on it.
Report an issue
Privacy & GDPR
GDPR,
by design.
You stay in control of personal data, and we give you the paperwork to prove it.
-
Clear roles
You, or your client, are the data controller. Irelia is your processor, and never contacts the end customer directly.
-
Data subject rights
Access, correction, deletion, and portability requests go through info@irelia.ai, answered within 20 days.
-
Defined retention
Conversations for 24 months from the last message. Leads while the workspace is active, plus 6 months. Billing records for 10 years, as tax law requires.
-
Breach notification
If an incident affects your data, we notify you within 24 hours of becoming aware.
-
Where data lives
Irelia is an EU company. Any transfer of data outside the EU is covered by EU Standard Contractual Clauses and, where it applies, the EU-US Data Privacy Framework, with a data processing agreement in place with every provider.
Read the DPA -
Never sold
Your data, and your customers' data, is never sold or shared for anyone else's purposes.
Privacy policy
AI governance
Powerful,
and bounded.
The agent does a lot. Here's how we keep it safe and honest.
-
Transparency
Every agent introduces itself as an AI, and links your privacy policy, at the start of a conversation.
-
Guardrails before go-live
A compliance check runs before an agent can publish, blocking unsafe setups such as medical or therapeutic advice.
-
No training on your data
Your conversations run on best-in-class AI models and are never used to train them.
-
Only what the agent needs
An AI model only receives the part of a conversation that is strictly necessary for the agent to answer correctly. Nothing beyond that is sent.
-
Human in the loop
Hand any conversation to a person at any moment, with the full context attached.
Trust center
The paperwork,
ready to review.
Every claim on this page has a document behind it. Send them straight to a client's legal team.
-
Data Processing Agreement
The contract that governs how we process data on your behalf.
Read the DPA -
Privacy policy
How Irelia collects, uses, and protects personal data.
Privacy policy -
Sub-processor list
Every provider that touches data, and why.
See the full list -
Acceptable Use Policy
What agents can and can't be built to do.
Read the policy
FAQ
Questions, answered.
Who is the data controller, Irelia or me?
You, or your client, are the controller. Irelia acts as your processor: we handle data on your instructions and never contact your customers ourselves.
Do you sign a Data Processing Agreement?
Yes. Every partner gets a DPA that sets out roles, data categories, retention, and security. You can pass it, and this page, straight to a client's legal team.
Where is my data stored?
Irelia is an EU company. Where a provider operates outside the EU, transfers are covered by EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework, with a data processing agreement in place for each one.
Do you use our conversations to train AI models?
No. Your data and your customers' data are never used to train AI models. On top of that, a model only receives the part of a conversation that is strictly necessary for the agent to answer correctly.
How do you handle access and deletion requests?
Send them to info@irelia.ai. We respond within 20 days, well inside the 30 days GDPR allows.
What happens if there is a data breach?
We notify you within 24 hours of becoming aware, so you can meet your own obligations to customers and regulators.
Does the AI tell people they're talking to a bot?
Yes. Every agent introduces itself as an AI at the start of a conversation, as the EU AI Act requires.
Can I share this with my client?
That's exactly what it's for. Send it over, and reach us at info@irelia.ai for anything they need beyond it.