IRONKEEP Privacy Policy
Effective Date: July 21, 2026 | Last Updated: July 23, 2026
1. Introduction & Scope
This Privacy Policy (“Policy”) explains how DatumWard Technologies, LLC (“IRONKEEP,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the IRONKEEP platform and its products, including IRONKEEP MAIL, IRONKEEP DRIVE, IRONKEEP CHAT, and IRONKEEP MEETINGS (collectively, the “Services”), and our marketing website at https://www.ironkeep.us/.
IRONKEEP is a business-to-business (B2B) secure productivity platform. Most individuals who use the Services do so as Authorized Users provisioned by an Organization (an enterprise or government agency customer). Because of this structure, our role under data protection law differs depending on the category of data:
-
Customer Data (IRONKEEP acts as a processor). “Customer Data” means data submitted to or processed through the Services by or on behalf of the Customer or its Authorized Users — including emails, files, documents, chat messages, calendar events, contacts, and meeting metadata. For Customer Data, the Customer (the Organization) is the controller and IRONKEEP acts as a processor (or service provider) acting on the Customer’s documented instructions. Our processing of Customer Data is governed by the Data Processing Addendum (see IRONKEEP Data Processing Addendum), not this Policy. Where this Policy and the DPA conflict with respect to Customer Data, the DPA controls.
-
Account Data and marketing-website data (IRONKEEP acts as a controller). “Account Data” means the registration, administrative-contact, and billing information we collect to establish, manage, and bill the Customer’s account. For Account Data, marketing-website data, and other information we collect for our own operational purposes, IRONKEEP is the controller and this Policy governs.
A note for Authorized Users. If you use the Services because your employer, agency, or another organization gave you access, that Organization controls your Customer Data and determines how it is used within the Services. Your use is also subject to that Organization’s own policies and privacy notices, which you should consult. Requests relating to Customer Data are generally directed to and handled by your Organization (see Sections 6 and 10).
Free tier. An individual may self-sign-up for the free tier and is placed under a shared, platform-operated Organization. The free tier is provided “as is” and may be changed or discontinued. The DPA contractual framework primarily applies to paid and Organization Customers, and a free-tier individual using the Services in a personal capacity will typically not have an executed DPA. Where a free-tier individual is functionally both the account holder and the user, this Policy governs the Account Data we collect to operate that account, and IRONKEEP acts as the controller for the content that individual stores in the Services and applies DPA-equivalent processing and security safeguards to that content by reference.
Defined terms used in this Policy (“Services,” “Customer,” “Organization,” “Authorized User,” “Customer Data,” “Account Data,” “Personal Data,” “Subprocessor,” “DPA,” “AUP”) have the meanings given in the IRONKEEP Terms of Service and the IRONKEEP Data Processing Addendum.
2. Information We Collect
2.1 Account and Registration Data
When a Customer establishes or administers an account, we collect information such as organization name, custom domain(s) submitted for verification, administrative-contact names, business email addresses, role assignments, and authentication-related metadata. For Authorized Users, we process identifiers and profile attributes provisioned by the Organization directly or through its identity-management services.
2.2 Billing Data
For paid tiers, we collect billing and subscription information necessary to charge for the Services. Self-service payments are handled by a third-party payment processor identified in the IRONKEEP Subprocessors list; IRONKEEP does not store full payment card numbers. ENTERPRISE billing may be handled through separate invoicing arrangements. We retain billing and usage records needed to administer subscriptions, calculate charges, and meet legal and accounting obligations.
2.3 Usage, Device, and Log Data
To operate, secure, and troubleshoot the Services, we collect operational and security data, including audit logs, security events, request metadata, IP addresses, and derived geolocation. We use this information to provide customer-configured location-based access controls, monitor reliability, and detect and prevent abuse. Our infrastructure providers process this information only as needed to provide their services.
2.4 Support Communications
When you contact us for support or other inquiries, we collect the information you provide (such as your contact details and the contents of your message) to respond and to maintain support records.
2.5 Marketing-Website Cookies
Our marketing website at https://www.ironkeep.us/ may use ordinary cookies and similar technologies. See Section 12.
2.6 Customer Data Processed on Behalf of Customers
We process Customer Data — emails, files, documents, chat messages, calendar events, contacts, meeting metadata, and similar content — to provide the Services. This processing is performed on behalf of and under the instructions of the Customer and is governed by the IRONKEEP Data Processing Addendum.
2.7 No In-Application Advertising or Analytics
IRONKEEP does not use third-party advertising, analytics, or telemetry inside the application. We do not embed third-party ad networks, behavioral-tracking pixels, or third-party product-analytics SDKs within IRONKEEP MAIL, IRONKEEP DRIVE, IRONKEEP CHAT, or IRONKEEP MEETINGS. The only cookies/tokens used inside the application are strictly necessary for authentication and operation (see Section 12). Our separate marketing website may use ordinary cookies.
3. How We Use Information
We use the information described above for the following limited operational purposes:
- Provide the Services — deliver, maintain, and operate IRONKEEP MAIL, IRONKEEP DRIVE, IRONKEEP CHAT, IRONKEEP MEETINGS, and their shared identity, data-protection, retention, audit, and access controls.
- Secure the Services — authenticate users; enforce access controls; detect, investigate, and prevent fraud, abuse, and security incidents; operate logging and monitoring.
- Bill and administer accounts — process subscriptions and usage metering and manage account lifecycle.
- Support — respond to inquiries and provide technical assistance.
- Maintain and improve the Services — diagnose problems, ensure reliability, and improve functionality using operational and security data (not in-application advertising or third-party analytics).
- Comply with law — meet legal, regulatory, and compliance obligations, and respond to lawful requests.
We do not use Customer Data for our own purposes except as necessary to provide and secure the Services or as instructed by the Customer under the DPA.
4. Legal Bases (Where GDPR / UK GDPR Applies)
Where the EU General Data Protection Regulation or the UK GDPR applies to our processing as a controller, we rely on the following legal bases:
- Performance of a contract — to provide and administer the Services and accounts under our agreement with the Customer.
- Legitimate interests — to secure the Services, prevent abuse and fraud, maintain reliability, and operate our business, balanced against individuals’ rights.
- Legal obligation — to comply with applicable laws and lawful requests.
- Consent — where required, for example for certain marketing-website cookies; consent may be withdrawn at any time.
For Customer Data processed as a processor, the Customer is responsible for establishing the legal basis for processing.
5. How We Share Information
We do not sell personal information, and we do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. We disclose information only as follows:
- Subprocessors. We engage a limited set of Subprocessors to provide the Services. The authoritative, current list — including each Subprocessor’s purpose and processing location — is maintained in the IRONKEEP Subprocessors list. Subprocessors are bound by contractual obligations consistent with the DPA.
- Customer-configured services (not IRONKEEP Subprocessors). Customer-controlled identity, authentication, and user-provisioning services may participate in the data flow. These services are configured and controlled by the Customer, not by IRONKEEP, and the Customer is responsible for them.
- Legal and compliance. We may disclose information where required to comply with applicable law, regulation, legal process, or enforceable governmental request, or to protect the rights, safety, and security of IRONKEEP, our customers, or others.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy and applicable law.
6. Customer Data & Our Role as Processor
For Customer Data, IRONKEEP acts as a processor on behalf of the Customer, which is the controller. Our handling of Customer Data is governed by the IRONKEEP Data Processing Addendum, including instructions, confidentiality, security, subprocessing, assistance, and deletion/return obligations.
If an Authorized User wishes to access, correct, delete, or otherwise exercise rights over Customer Data, that request should be directed to the relevant Organization, which controls the data. IRONKEEP will assist the Customer in responding to such requests as set out in the DPA, but we generally cannot act on Customer Data directly without the Customer’s instruction.
Customer Data is encrypted at rest and in transit. IRONKEEP restricts administrative access to Customer content through technical and organizational controls designed to prevent routine access to plaintext content.
7. Data Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention behaviors include:
- Temporary email processing copies. Temporary copies created while processing inbound and outbound email ordinarily expire after approximately 7 days.
- Trashed files. Files placed in trash are purged after 30 days unless subject to a legal hold.
- Legal holds. When a compliance officer applies a legal hold, affected data is preserved until the hold is released.
- Data export on cancellation. Following cancellation, the Customer has 30 days to export data using the export functionality available through the Services.
- Organization offboarding/deletion. Upon organization offboarding or deletion, IRONKEEP initiates a secure deletion process. Customer Data generally becomes unrecoverable within approximately 30 days, subject to legal holds and applicable law.
- Account Data and security/audit logs. Account Data is retained for the life of the account and, after account closure, for a limited period as required to meet our legal, accounting, tax, and audit obligations and to resolve disputes and enforce agreements, after which it is deleted or anonymized. Audit logs and security-event records are retained for as long as needed to operate and secure the Services, support incident investigation, and satisfy applicable legal and regulatory retention requirements.
8. Security
We maintain technical and organizational measures designed to protect personal information, including encryption at rest and in transit, separation of Customer Data between Organizations, restricted administrative access to Customer content, identity and access controls, security monitoring, rate limiting, and secure software-development and deployment practices.
Incident response and breach notification. We maintain an incident-response process to detect, investigate, and respond to security incidents. In the event of a personal data breach affecting personal information for which we are the controller (such as Account Data), we will notify affected account holders and/or the Customer’s administrative contact, and applicable regulators, as and to the extent required by applicable law and without undue delay. Breach notification and handling with respect to Customer Data are governed by the IRONKEEP Data Processing Addendum.
Compliance posture. The Services are architected and designed to align with the FedRAMP Moderate baseline and NIST SP 800-53 controls and to support FedRAMP-oriented and government workloads. IRONKEEP is not currently FedRAMP authorized or certified, does not hold an Authorization to Operate (ATO), and is not listed on the FedRAMP Marketplace. Nothing in this Policy should be read as a claim of certification, authorization, or audited compliance. Customers requiring a specific certification or attestation should address that under a separate written agreement (e.g., ENTERPRISE).
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International Data Transfers
The Services are hosted in the United States through the infrastructure providers identified in the IRONKEEP Subprocessors list. Specialized U.S. government cloud environments may be available for supported workloads. If you access the Services from outside the United States, your information may be transferred to, stored in, and processed in the United States.
Where transfers of personal data are subject to the GDPR, UK GDPR, or similar laws, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum or equivalent), as applicable. Transfer terms for Customer Data are addressed in the IRONKEEP Data Processing Addendum.
EU/UK representative. Where required under Article 27 of the GDPR or UK GDPR, our designated representative in the European Union and/or the United Kingdom may be contacted at support@ironkeep.us. Where IRONKEEP is not established in, and is not required to designate a representative for, the EEA or the UK, no Article 27 representative is appointed; in that case data subjects may contact us using the details in Section 15.
10. Your Privacy Rights
Depending on your jurisdiction, you may have rights regarding your personal information.
10.1 GDPR / UK GDPR
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority.
10.2 CCPA / CPRA and Other U.S. State Laws
Subject to applicable law, you may have the right to: know/access the personal information we hold about you; delete it; correct it; opt out of the “sale” or “sharing” of personal information and certain profiling; and limit the use and disclosure of sensitive personal information. As stated elsewhere in this Policy, IRONKEEP does not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that would trigger the right to limit beyond providing and securing the Services. You have the right not to receive discriminatory treatment for exercising your privacy rights.
Categories of personal information. The following summarizes, for the preceding 12 months, the categories we collect as a controller (Account Data, billing data, usage/device/log data, and support communications described in Section 2); Customer Data is processed on behalf of the Customer and is addressed by the DPA. For full detail, see Section 2.
| Category collected | Sources | Business / commercial purposes | Categories of recipients |
|---|---|---|---|
| Identifiers and account/registration data (e.g., names, business email, organization, domain, role) | The Customer/Organization; the Authorized User; Customer-controlled identity services | Provide, secure, and administer the Services; authentication | Subprocessors (see IRONKEEP Subprocessors); legal/compliance recipients; parties to a business transfer |
| Commercial / billing information (subscription and metering records) | The Customer; payment processor | Billing, subscription management, usage metering | Payment processor; Subprocessors; legal/compliance recipients |
| Internet/network and device activity (IP address, request metadata, audit and security logs) | Automatically from use of the Services | Operate, secure, and troubleshoot the Services; geo-fencing; abuse and fraud prevention | Subprocessors; legal/compliance recipients |
| Geolocation data (derived from IP address) | Automatically from use of the Services | Geo-fencing access control; abuse prevention | Subprocessors; legal/compliance recipients |
| Other information you provide (support communications) | The individual | Provide support; maintain support records | Subprocessors; legal/compliance recipients |
We do not sell or share any of these categories for cross-context behavioral advertising.
10.3 How to Exercise Rights
- Authorized Users. If your access is provided by an Organization, that Organization controls your Customer Data. Please direct requests concerning Customer Data to your Organization, which will instruct us as needed under the DPA.
- Account holders. If you are an account holder (including a free-tier individual) and wish to exercise rights over Account Data we control, contact us at security@ironkeep.us. We will verify your request and respond as required by applicable law.
We do not discriminate against individuals for exercising their privacy rights. Where permitted, an authorized agent may submit a request on your behalf with appropriate verification.
11. Children’s Privacy
The Services are intended for organizations and their Authorized Users in a business or government context. The Services are not directed to children and are not intended for individuals under 18 years of age. We do not knowingly collect personal information from anyone under the applicable minimum age. If we learn that we have collected personal information from a child without appropriate authorization, we will take steps to delete it.
12. Cookies & Similar Technologies
- Inside the application. IRONKEEP MAIL, IRONKEEP DRIVE, IRONKEEP CHAT, and IRONKEEP MEETINGS use only strictly necessary cookies and session tokens required for authentication, security, and core functionality. The application does not use third-party advertising, analytics, or telemetry cookies.
- Marketing website. Our marketing website at https://www.ironkeep.us/ may use additional ordinary cookies (for example, to remember preferences or measure site performance).
- Your choices. You can control cookies through your browser settings; disabling strictly necessary cookies or session tokens may prevent the Services from functioning. Where required by law, we will obtain consent for non-essential marketing-website cookies and provide a means to manage your choices.
13. Government & Public-Sector Users
For government and public-sector customers, the Services may be deployed in specialized U.S. government cloud environments where supported. As described in Section 8, the Services are architected and designed to align with the FedRAMP Moderate baseline and NIST SP 800-53 controls, but are not currently FedRAMP authorized or certified and do not hold an ATO. Government data is handled subject to this Policy, the IRONKEEP Data Processing Addendum, and any applicable Order Form or separate written agreement. Specific compliance commitments, if any, are addressed in such separate agreements.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last Updated” date above and, where appropriate, provide additional notice (for example, by notifying the Customer’s administrative contact or posting a notice on the marketing website). Your continued use of the Services after an update becomes effective constitutes acceptance of the revised Policy, to the extent permitted by law.
15. Contact / Data Protection Officer
If you have questions about this Policy or our privacy practices, or wish to exercise your rights, please contact us:
- Privacy inquiries: security@ironkeep.us
- Data Protection Officer: security@ironkeep.us
- EU/UK representative (where applicable): support@ironkeep.us
- Mailing address: 2221 Yellowstone Ranch Court, Waxahachie, TX 75165, United States
- Phone: +1 703-338-6561
For other matters, you may also reach us at support@ironkeep.us (support), security@ironkeep.us (security and abuse), or legal@ironkeep.us (legal notices).