Skip to content
IRIS

Knowledge Base · Compliance & data

Is IRIS GDPR-compliant?

IRIS is built around GDPR requirements, not retrofitted afterward. Alert state lives on the EU edge by architecture (Cloudflare Durable Objects pinned to EU jurisdiction), so data doesn't leave the EU as a side effect of infrastructure choice. Recipients can opt out with STOP/START keywords in 7 languages, data subjects can request an Article 15 export or Article 17 erasure — the latter pseudonymises historical records so the audit trail survives without retaining identifying detail — and a DPA is available on request.

Related questions

What personal data does IRIS actually process?

Recipient phone numbers, names, language preference, and the timestamped record that someone was notified and how they responded. That's the data an on-call chain inherently needs — IRIS doesn't collect anything beyond what escalation and proof require.

Does erasure destroy my audit trail?

No — Article 17 erasure pseudonymises historical records rather than deleting them outright, so the audit trail (that an alert happened, was escalated, and was acknowledged) survives without retaining data that identifies the person.

See the full compliance and EU residency picture.

Compliance & EU residency

GDPR-ready from day one

Start free with 1,000 credits on EU-resident infrastructure.