iris

Iris Privacy Policy

Last updated: 14 July 2026

Who we are

Iris (iris.nomad.sc) is a business workspace platform operated by Nomad AI Ltd, a private limited company registered in Ireland. This policy covers the Iris web application, the Iris desktop and mobile apps, and the Iris API. For privacy questions, contact privacy@nomad.sc.

Most information in Iris is business content that belongs to your organisation — the company whose workspace you use. For that content, your organisation is the data controller and Nomad AI Ltd acts as its data processor, handling the data on the organisation's instructions. For your account and the operation of the service itself (your name, email, and sign-in), Nomad AI Ltd is the controller.

Information we process

  • Account and identity — your name and email address, obtained when you sign in. Sign-in uses your organisation's chosen method (email/password, Google, or Microsoft) via our authentication provider. If you sign in with Google or Microsoft, we receive only your basic profile (name, email) at sign-in; the optional workspace integrations that access more are described separately below.
  • Workspace content — the content you and your teammates create in Iris: knowledge-base pages, documents, CRM records, projects and tasks, SOPs, contracts, invoices, comments, and similar. This is scoped to your organisation and isolated from every other customer.
  • Content from connected sources — if a workspace admin connects a document source (see the next section), the text of the documents in the folders they select.
  • Technical data — standard request information (IP address, timestamps, user agent) needed to operate and secure the service, and error diagnostics when something breaks.
  • Billing data — subscription and payment details are handled by our payment provider (Stripe); we do not store card numbers.

We use no advertising trackers and no third-party advertising SDKs, and we do not track you across other apps or websites. Cookies are limited to what the service needs to function — your session, your appearance (theme) preference, and short-lived functional cookies (for example, one that carries an invite through sign-in). We set no advertising or cross-site tracking cookies.

Connected sources (Google Drive, Microsoft 365)

A workspace admin can connect their organisation's Google Drive or Microsoft 365 so the team can search their own documents inside Iris. This is always explicit: the admin grants access through Google's or Microsoft's own consent screen, then selects what Iris may read — specific folders, or the whole connected drive if they choose.

  • Read-only. The document-source connection never creates, modifies, shares, or deletes anything in the connected account. For Google Drive it requests a single scope, drive.readonly.
  • Scoped by the admin. Only what the admin selects is read — the chosen folders or, if they opt for it, the whole drive. Iris stores the extracted text of those documents, their titles, and links back to the original files, to build a private search index for that workspace alone.
  • Disconnect any time. Disconnecting a source immediately stops all syncing and revokes Iris's access. The admin chooses whether to also delete the imported copies and their search index from the workspace, or to keep them. Access can also be revoked at any time from your Google or Microsoft account's security settings, which immediately invalidates Iris's access.
  • Tokens are protected. OAuth tokens are handled by our own connection service and encrypted at rest. The service runs on the hosting subprocessors we list; tokens are never disclosed to anyone else.

Google API Limited Use disclosure: Iris's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used solely to provide the user-facing features described in this policy — document search over the Drive folders a workspace connects, and, where a workspace separately enables them, the optional email and calendar features described in the next section. It is never used for advertising, never sold, never used to train generalised AI or machine-learning models, and never read by humans except with your explicit consent for support, for security purposes, or where required by law.

Optional integrations (email, calendar, e-signature, telephony)

A workspace can separately connect other tools from Settings → Integrations. Each is optional, off by default, and requests its own permissions on the provider's consent screen when connected:

  • Email (Gmail or Outlook), for the CRM — Iris reads message headers and short snippets to match correspondence to your CRM contacts, and sends an email only when a user composes one in Iris.
  • Calendar (Google or Microsoft), for the CRM — Iris syncs events relating to your CRM records, and creates an event only when a user schedules one in Iris.
  • E-signature and telephony — these connect your organisation's own accounts with those providers, used only to send documents for signature or place calls that a user initiates.

Disconnecting an integration in Settings → Integrations stops its access; it can also be revoked from the provider's own account settings. Data received through these integrations is protected under the same commitments as the rest of this policy, including the Limited Use disclosure above for Google data.

How we use information

  • To provide the service and its features — performance of a contract, or on your organisation's instructions.
  • To authenticate you and keep accounts and data secure — legitimate interests and legal obligation.
  • To operate, maintain, and improve the reliability of the service — legitimate interests.

Search indexing uses a text-embedding model (Voyage AI) to make your documents findable, and knowledge search sends the matching excerpts to an AI model (Anthropic) to compose a cited answer; content sent to either provider is processed only for that purpose and is not used to train their models. Beyond that, your content is made available to AI tools only when your organisation explicitly connects one (for example, an AI assistant via Iris's MCP integration) — access is then scoped to your workspace, under your organisation's instruction, with the same permissions the connecting user has. We do not use your information for advertising or for automated decisions with legal effects.

Who we share it with

We share information only with the service providers that help us run Iris, under contract and appropriate safeguards. The current list, with each provider's purpose and region, is maintained on our subprocessors page. We never sell personal data, and we never share it with third parties for advertising.

Your connected content sources (Google Workspace, Microsoft 365) are your organisation's own providers, not our subprocessors — Iris only reads from them as described above.

Security and data protection

Sensitive data — content read from connected sources, OAuth credentials, and personal data generally — is protected with the following mechanisms:

  • All data is encrypted in transit (TLS) and at rest, including backups.
  • Every customer's data is isolated with database-enforced row-level security — one workspace can never read another's data.
  • OAuth tokens and integration credentials are additionally encrypted at the application layer (AES-256) before storage, and are never exposed to clients or logs.
  • Google user data specifically: refresh tokens exist only in encrypted form; Drive content is retained only as extracted text inside the customer's own isolated search index; both are deleted as described under Retention, and access is revocable at any time from the user's Google Account.
  • In the event of a personal-data breach, we notify affected organisations — and, where required, the supervisory authority — without undue delay, in line with GDPR Articles 33–34.
  • Access to production systems is restricted to authorised personnel.

Retention and deletion

Workspace content is retained for as long as your organisation's workspace is active. Content from a connected source is deleted when a workspace admin disconnects the source and chooses to remove the imported copies (admins may instead keep them in the workspace as ordinary workspace content). When a workspace is terminated, its content is deleted from live systems, with residual copies removed from encrypted backups in the ordinary course. Your organisation can also request deletion or export of its data at any time via privacy@nomad.sc.

International transfers

Iris is hosted in the UK and EU. Some subprocessors process data in the United States; where they do, transfers are covered by the EU Standard Contractual Clauses or an equivalent lawful transfer mechanism. See the subprocessors page for regions per provider.

Your rights

Under the GDPR you have the right to access, correct, port, restrict, object to the processing of, or delete the personal data we hold about you. Where your organisation is the controller of workspace content, we will refer your request to them and support them in fulfilling it. Contact privacy@nomad.sc — we respond within 30 days. You may also lodge a complaint with the Irish Data Protection Commission or your local supervisory authority.

Changes

We update this policy when something material changes and will note the date above. Material changes affecting how customer data is processed are communicated to workspace administrators.