IronProve

Privacy Policy

Last updated: 15 August 2026

This is a draft policy, not a finished legal document. It is pending review by a qualified solicitor before it should be treated as complete or final. Bracketed placeholders below mark details still to be confirmed.

1. Who we are

IronProve ("we," "us," "our") provides a compliance inspection logging platform for organizations such as care homes. This policy explains how we collect, use, and protect personal data when you use our service at taphin.vercel.app.

Data controller contact: [COMPANY LEGAL NAME], [REGISTERED ADDRESS], [CONTACT EMAIL].

If your organization is a customer, you (the organization) act as the data controller for the personal data of your own staff and the records you create using our platform. We act as the data processor on your behalf for that data. See Section 7 (Our role: processor vs controller).

2. What data we collect

Account and admin data:

  • Name and email address of admin users (collected via Google OAuth or email sign-in)
  • Organization name and details you provide

Technician and inspection data, entered by your organization's staff:

  • Names typed by technicians when logging an inspection
  • Inspection responses, timestamps, and comments
  • Item and category details you configure, such as locations and custom fields

Technical data:

  • IP address, used for rate limiting and security, for example preventing brute-force attempts on access codes
  • Session cookies (see our Cookie Policy)
  • Basic usage and error logs for maintaining service reliability

We do not collect patient or resident personal data. Our platform is built for equipment and compliance record-keeping, not care or medical records.

3. Why we process this data (lawful basis)

  • Providing the service. Performance of a contract with your organization.
  • Security (rate limiting, fraud prevention). Legitimate interest.
  • Sending OTP sign-in codes and due/overdue reminder emails. Performance of a contract, or legitimate interest.
  • Improving the service, using aggregated, non-identifying usage data only, if applicable. Legitimate interest.

4. Who we share data with (subprocessors)

We use the following third-party services to operate IronProve. Each processes data only as needed to provide their specific function.

SubprocessorPurposeData involved
VercelApplication hostingAll data in transit or at rest during use
MongoDB AtlasDatabase hostingAll stored account, organization, and inspection data
ResendSending OTP and reminder emailsEmail address, email content
Google (OAuth)Sign-in authenticationName, email address, only if you choose Google sign-in

We do not sell personal data to any third party, ever.

5. Where data is stored

Data is stored with MongoDB Atlas in [DATA CENTER REGION, to be confirmed]. If any subprocessor stores data outside the UK or EEA, the safeguard used will be stated here, for example Standard Contractual Clauses.

6. How long we keep data

We do not currently operate an automated data-retention or deletion schedule. Inspection records are retained to support your organization's ongoing compliance history, since that is the purpose they exist for, and account data is retained while your organization's account is active. A specific, published retention and deletion policy is planned as the product matures, not yet finalized. If you would like data removed sooner, contact us at [CONTACT EMAIL].

7. Our role: processor vs controller

For inspection and technician data your organization enters into the platform, your organization is the data controller and we are the data processor, acting only on your instructions. A separate Data Processing Agreement governs this relationship and is available on request.

For admin account data, meaning the person who signs up and manages the account, we are the data controller.

8. Your rights

Depending on your role, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion, subject to our compliance record-keeping obligations to your organization
  • Object to or restrict certain processing
  • Data portability, meaning exporting your data

To exercise these rights, contact [CONTACT EMAIL]. If you are a technician or staff member whose name appears in inspection records, please contact your organization's administrator first, since they control that data.

9. Security

We take reasonable technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS) and at rest, hashed storage of access codes and passwords, never plaintext, rate limiting on authentication endpoints, and role-based access controls.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated to account admins by email.

11. Contact

Questions about this policy: [CONTACT EMAIL]

We use only strictly necessary cookies to keep you signed in. No tracking or analytics cookies are used. Cookie Policy