Privacy Policy
Last updated: 15 August 2026
1. Who we are
IronProve ("we," "us," "our") provides a compliance inspection logging platform for organizations such as care homes. This policy explains how we collect, use, and protect personal data when you use our service at taphin.vercel.app.
Data controller contact: [COMPANY LEGAL NAME], [REGISTERED ADDRESS], [CONTACT EMAIL].
If your organization is a customer, you (the organization) act as the data controller for the personal data of your own staff and the records you create using our platform. We act as the data processor on your behalf for that data. See Section 7 (Our role: processor vs controller).
2. What data we collect
Account and admin data:
- Name and email address of admin users (collected via Google OAuth or email sign-in)
- Organization name and details you provide
Technician and inspection data, entered by your organization's staff:
- Names typed by technicians when logging an inspection
- Inspection responses, timestamps, and comments
- Item and category details you configure, such as locations and custom fields
Technical data:
- IP address, used for rate limiting and security, for example preventing brute-force attempts on access codes
- Session cookies (see our Cookie Policy)
- Basic usage and error logs for maintaining service reliability
We do not collect patient or resident personal data. Our platform is built for equipment and compliance record-keeping, not care or medical records.
3. Why we process this data (lawful basis)
- Providing the service. Performance of a contract with your organization.
- Security (rate limiting, fraud prevention). Legitimate interest.
- Sending OTP sign-in codes and due/overdue reminder emails. Performance of a contract, or legitimate interest.
- Improving the service, using aggregated, non-identifying usage data only, if applicable. Legitimate interest.
4. Who we share data with (subprocessors)
We use the following third-party services to operate IronProve. Each processes data only as needed to provide their specific function.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting | All data in transit or at rest during use |
| MongoDB Atlas | Database hosting | All stored account, organization, and inspection data |
| Resend | Sending OTP and reminder emails | Email address, email content |
| Google (OAuth) | Sign-in authentication | Name, email address, only if you choose Google sign-in |
We do not sell personal data to any third party, ever.
5. Where data is stored
Data is stored with MongoDB Atlas in [DATA CENTER REGION, to be confirmed]. If any subprocessor stores data outside the UK or EEA, the safeguard used will be stated here, for example Standard Contractual Clauses.
6. How long we keep data
We do not currently operate an automated data-retention or deletion schedule. Inspection records are retained to support your organization's ongoing compliance history, since that is the purpose they exist for, and account data is retained while your organization's account is active. A specific, published retention and deletion policy is planned as the product matures, not yet finalized. If you would like data removed sooner, contact us at [CONTACT EMAIL].
7. Our role: processor vs controller
For inspection and technician data your organization enters into the platform, your organization is the data controller and we are the data processor, acting only on your instructions. A separate Data Processing Agreement governs this relationship and is available on request.
For admin account data, meaning the person who signs up and manages the account, we are the data controller.
8. Your rights
Depending on your role, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion, subject to our compliance record-keeping obligations to your organization
- Object to or restrict certain processing
- Data portability, meaning exporting your data
To exercise these rights, contact [CONTACT EMAIL]. If you are a technician or staff member whose name appears in inspection records, please contact your organization's administrator first, since they control that data.
9. Security
We take reasonable technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS) and at rest, hashed storage of access codes and passwords, never plaintext, rate limiting on authentication endpoints, and role-based access controls.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to account admins by email.
11. Contact
Questions about this policy: [CONTACT EMAIL]