Privacy Policy
Last updated: July 2026
1. Who We Are
IRIX ("IRIX," "we," "us," "our") is the data controller for personal data collected through irix.bio. We process data in accordance with the EU General Data Protection Regulation (GDPR).
Contact for privacy matters: hello@irix.bio
2. What Data We Collect
When you join our newsletter or use the Protocol Matcher: Email address.
When you place an order: Name, shipping address, email address, order history, and payment confirmation. Card details are processed directly by Stripe — we do not store or have access to full card numbers.
We do not collect: health data, biometric data, or any other sensitive personal data.
3. How We Use Your Data
- Send you research updates and protocol content you signed up for
- Process and fulfill orders, including shipping and customer service
- Respond to inquiries you send us
- Comply with legal obligations (e.g. tax and accounting records)
We do not sell your personal data to third parties. We do not use analytics tools or tracking pixels.
4. Legal Basis for Processing (GDPR Article 6)
| Purpose | Legal Basis |
|---|---|
| Sending newsletter / protocol emails | Consent (you opted in) |
| Processing and fulfilling orders | Performance of a contract |
| Responding to inquiries | Legitimate interest |
| Legal/tax recordkeeping | Legal obligation |
5. Third Parties We Share Data With
We share data only with the service providers needed to operate IRIX:
- Stripe — payment processing. Card data is handled directly by Stripe and never stored by IRIX.
- Zoho — email hosting for hello@irix.bio.
- Systeme.io — email marketing. Only applies if you subscribe to research updates.
- Vercel — website hosting and infrastructure.
- CloudCart — order and shipping data processing (coming soon).
We do not sell, rent, or trade your data with any third party for marketing purposes.
6. International Data Transfers
Our service providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) as required under GDPR.
7. Your Rights Under GDPR
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — request that we limit processing of your data
- Data portability — request your data in a portable format
- Object — object to processing based on legitimate interest or for direct marketing
- Withdraw consent — unsubscribe from emails at any time via the link in any email, or by contacting us directly
To exercise any of these rights, contact us at hello@irix.bio. We will respond within 30 days as required by GDPR.
This site operates under EU law. For data protection enquiries, contact hello@irix.bio.
8. Data Retention
- Newsletter / protocol email addresses: until you unsubscribe or request deletion
- Order data: 3 years for legal and accounting purposes
- Inquiry / support communications: up to 2 years from last contact
9. Data Security
We take reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security of data transmitted to us.
10. Children's Privacy
Our products and services are not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.
12. Contact
Questions about this Privacy Policy or your data: hello@irix.bio