Legal

Privacy Policy

Last updated: July 2026

1. Who We Are

IRIX ("IRIX," "we," "us," "our") is the data controller for personal data collected through irix.bio. We process data in accordance with the EU General Data Protection Regulation (GDPR).

Contact for privacy matters: hello@irix.bio

2. What Data We Collect

When you join our newsletter or use the Protocol Matcher: Email address.

When you place an order: Name, shipping address, email address, order history, and payment confirmation. Card details are processed directly by Stripe — we do not store or have access to full card numbers.

We do not collect: health data, biometric data, or any other sensitive personal data.

3. How We Use Your Data

  • Send you research updates and protocol content you signed up for
  • Process and fulfill orders, including shipping and customer service
  • Respond to inquiries you send us
  • Comply with legal obligations (e.g. tax and accounting records)

We do not sell your personal data to third parties. We do not use analytics tools or tracking pixels.

4. Legal Basis for Processing (GDPR Article 6)

PurposeLegal Basis
Sending newsletter / protocol emailsConsent (you opted in)
Processing and fulfilling ordersPerformance of a contract
Responding to inquiriesLegitimate interest
Legal/tax recordkeepingLegal obligation

5. Third Parties We Share Data With

We share data only with the service providers needed to operate IRIX:

  • Stripe — payment processing. Card data is handled directly by Stripe and never stored by IRIX.
  • Zoho — email hosting for hello@irix.bio.
  • Systeme.io — email marketing. Only applies if you subscribe to research updates.
  • Vercel — website hosting and infrastructure.
  • CloudCart — order and shipping data processing (coming soon).

We do not sell, rent, or trade your data with any third party for marketing purposes.

6. International Data Transfers

Our service providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) as required under GDPR.

7. Your Rights Under GDPR

  • Accessrequest a copy of the personal data we hold about you
  • Rectificationrequest correction of inaccurate data
  • Erasurerequest deletion of your data ("right to be forgotten")
  • Restrictionrequest that we limit processing of your data
  • Data portabilityrequest your data in a portable format
  • Objectobject to processing based on legitimate interest or for direct marketing
  • Withdraw consentunsubscribe from emails at any time via the link in any email, or by contacting us directly

To exercise any of these rights, contact us at hello@irix.bio. We will respond within 30 days as required by GDPR.

This site operates under EU law. For data protection enquiries, contact hello@irix.bio.

8. Data Retention

  • Newsletter / protocol email addresses: until you unsubscribe or request deletion
  • Order data: 3 years for legal and accounting purposes
  • Inquiry / support communications: up to 2 years from last contact

9. Data Security

We take reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security of data transmitted to us.

10. Children's Privacy

Our products and services are not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.

12. Contact

Questions about this Privacy Policy or your data: hello@irix.bio

See also our Cookie Policy.