Iris OS
Security & Consent

Data Usage & Privacy Policy

Last Updated: July 28, 2026 • GDPR & DPDP Compliant • Iris OS

1. Data Controller Identification

Iris OS ("we", "us", or "our") is the Data Controller responsible for the processing of your personal data on the Iris OS Platform under Article 4(7) of the EU General Data Protection Regulation (GDPR) and acts as the Data Fiduciary under Section 3 of the Digital Personal Data Protection (DPDP) Act of India.

2. Categories of Personal Data We Collect

When you use the Platform, we process the following categories of data:

  • Identity & Account Metadata: Corporate name, billing address, currency settings, administrator emails.
  • Financial Data: Internal ledgers, client invoices, amount totals, expenses, merchant names.
  • Integration Telemetry & Access Tokens: OAuth authorization tokens for Canva catalogs, Meta Ads metrics, and Google or Notion workspaces.
  • Google Account & Calendar Data: Google account email and profile information, calendar identifiers, and event information such as titles, descriptions, dates, times, attendees, RSVP status, recurrence, locations, and Google Meet links, when you connect Google Calendar.
  • Human Resources & Contractor Allocation Logs: Contractor name initials and assigned deliverable hours.
  • System Logs & Telemetry: IP address, device headers, authentication timestamps.

3. Purpose and Legal Basis of Processing

Under Article 6 of the GDPR, we process data based on:

  • Contractual Performance (Art. 6.1.b): To deploy settings, calculate invoices, sync project milestones, and authorize client logins.
  • Explicit Consent (Art. 6.1.a): To connect Canva, Google, Notion, and Meta APIs; synchronize and manage Google Calendar events; use Google Gemini models exclusively for AI-assisted call scheduling; and securely analyze financial ledgers and lead pipeline data using Prism AI models. Connected integrations and AI-assisted scheduling are optional and can be declined or revoked in settings at any time.
  • Legitimate Interests (Art. 6.1.f): To execute Prism AI heuristics, identify contractor profit leaks, and detect anomalous security activity.

Under Section 4 and 5 of the Indian DPDP Act, we process personal data only for specified, lawful purposes to which you have given unambiguous, affirmative consent.

4. Google API Data, Google Calendar, and Gemini-Assisted Scheduling

Iris OS accesses Google user data only after you expressly connect your Google account and grant the requested permissions. We use that data to provide the Google Calendar features you request, including calendar synchronization, availability and conflict checks, call scheduling, event creation and updates, attendee invitations, RSVP status, and Google Meet links.

  • Google Account Data: We access the verified email address and basic account information returned by Google to identify the connected account and maintain the integration. Iris OS does not request access to Gmail, Google Drive, documents, or photos as part of the Google Calendar integration.
  • Google Calendar Data: With your permission, Iris OS reads calendar lists and future calendar events and may store event titles, descriptions, start and end times, recurrence details, attendee email addresses, RSVP status, event identifiers, locations, and Google Meet links. Iris OS also sends the meeting title, date, time, attendee email addresses, and conferencing request to Google when you ask it to create or update an event.
  • Gemini-Only AI Scheduling: Google Gemini is the only AI model family used to interpret requests to schedule calls. For this workflow, Gemini may process only the information reasonably necessary to understand the scheduling request, such as the meeting title, attendee names or email addresses, requested date and time, time zone, and current scheduling state. Iris OS does not send Google OAuth access or refresh tokens to Gemini, and it does not use OpenAI, Anthropic, or any other AI provider to process Google Calendar data for call scheduling.
  • Notion Authentication: We retrieve authorized database schema read/write tokens. This scope is strictly confined to workspace databases you explicitly select for project reporting.

Limited AI Use and Google Workspace API Compliance

Iris OS uses Google Workspace data only to provide or improve the visible calendar and call-scheduling features requested by the connected user. Google Workspace data is not sold, used for advertising, used to determine creditworthiness, or used to create, train, or improve a generalized or shared machine-learning or artificial-intelligence model. It is not used to build advertising profiles or retained as a permanent dataset for model training. The use and transfer of information received from Google Workspace APIs by Iris OS adheres to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.

Sharing, Transfer, and Disclosure of Google User Data

Iris OS does not sell Google user data. We share, transfer, or disclose it only to the following recipients and only to the extent necessary for the stated purpose:

  • Google: Google Calendar APIs receive event details and conferencing requests to synchronize calendars, create events, invite attendees, record responses, and provision Google Meet links. Google Gemini receives the limited scheduling inputs described above solely to interpret the user-requested scheduling workflow.
  • Authorized Workspace Users and Meeting Participants: Calendar information is visible to authorized members of the connected Iris OS workspace as permitted by their role. Event titles, times, attendee details, and meeting links may be disclosed to people whom the user chooses to invite.
  • Infrastructure and Delivery Service Providers: Vetted hosting, database, authentication, and transactional-email providers may process the minimum Google user data necessary to operate, secure, store, or deliver the calendar and invitation features on our behalf. They act under contractual confidentiality, security, and purpose-limitation obligations and may not use the data for their own advertising or unrelated purposes.
  • Security and Legal Disclosures: Data may be disclosed when reasonably necessary to investigate abuse or a security incident, or when required to comply with applicable law, regulation, court order, or lawful government request.
  • Corporate Transaction: Google user data may be transferred as part of a merger, acquisition, or sale of assets only after obtaining the user’s explicit prior consent, as required by the Google Workspace Limited Use requirements.

Data Protection Mechanisms for Sensitive Google Data

  • Encryption: Google user data is transmitted over HTTPS/TLS. Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM, and encryption keys are stored separately from encrypted credentials.
  • Least-Privilege Access: Iris OS requests only the Google OAuth scopes needed to read calendars and manage events. Authentication, workspace authorization, and user-specific ownership controls restrict access to connected-account data.
  • AI Data Minimization: Only the minimum scheduling inputs are sent to Gemini. OAuth credentials are never placed in AI prompts, and synchronized calendar contents are not provided to other AI providers for call scheduling.
  • Retention and Deletion Controls: Google data is retained only while needed to provide the connected feature or meet applicable legal obligations. Disconnecting Google Calendar deletes the stored connection credentials and synchronized events associated with that connection; users may also revoke Iris OS access from their Google Account.
  • Operational Safeguards: Iris OS applies access controls, input validation, security monitoring, and restricted administrative access designed to prevent unauthorized access, alteration, loss, or disclosure. Human access to Google user data is prohibited except with specific user consent or when necessary for security or legal compliance.
Google and Notion OAuth credentials are encrypted at rest and stored securely. Google OAuth credentials are used by Iris OS servers to communicate with Google APIs and are not included in prompts sent to Gemini. You can disconnect Google Calendar in Iris OS or revoke access at any time from your Google Account security settings. On disconnection or a valid deletion request, Iris OS removes the stored Google credentials and synchronized Google Calendar data associated with the connection, subject only to legal retention obligations.

5. Data Retention, Erasure, & Anonymization

In accordance with GDPR Article 17 (Right to Erasure) and DPDP Act Section 12 (Right to Erasure of Personal Data):

We retain personal data only for as long as your workspace account is active or as necessary to fulfill the primary purposes of processing. Upon contract termination or a valid erasure request:

  • All API tokens (Google, Notion, Meta) are immediately and permanently purged from active databases.
  • Your identity details are deleted or fully anonymized.
  • Historical operational logs used by Prism AI are fully scrubbed of identifiable references.
  • For Meta (Facebook/Instagram) integrations, you can deauthorize the application or request deletion of all retrieved campaigns, ads, and leads data at any time via the deauthorization endpoint (/api/meta-ads/deauthorize) and data deletion request endpoint (/api/meta-ads/delete-data). Following verification, the data is immediately and permanently wiped from the active database and a unique tracking code is generated to confirm completion.

6. GDPR & DPDP Act Data Subject Rights

You hold the following legal rights regarding your personal data:

  • Right of Access & Portability: Obtain a structured JSON copy of all data held.
  • Right to Rectification: Request correction of inaccurate ledgers or profiles.
  • Right of Consent Withdrawal: Revoke API permissions at any time.
  • Right to Grievance Redressal (DPDP Act): Raise grievances directly with our DPO.
  • Right to Nominate (DPDP Act): Designate an individual to exercise your rights in the event of death or incapacity.

7. International Cross-Border Data Transfers

Personal data collected under these policies is processed in secure servers located within the United States, the EEA, and India. To facilitate cross-border transfers from the EEA, Iris OS relies on Standard Contractual Clauses (SCCs) approved by the European Commission. Transfers under the DPDP Act are executed in full compliance with cross-border guidelines established by the Government of India.

8. Contact Our Data Protection Officer (DPO)

To exercise your legal data rights, withdraw consent, or file a complaint regarding our privacy practices:

Fiduciary: Iris OS
Data Protection Officer: Iris OS Privacy & Compliance
Email: cto.admin@irisos.app
Subject Header: PRIVACY: DATA RIGHTS EXERCISE