Skip to content

Legal

Privacy Policy

How Ironfang Ltd collects, uses and protects personal data.

Last updated: 26 September 2026Privacy settings

Who we are

Ironfang Ltd (registered in England & Wales No. 12764014) is the data controller for personal data processed through this website and our products. We are registered with the Information Commissioner's Office under reference ZB444797.

What we collect

Contact enquiries

Contact form: your name, email address, optional company name and your message. We use this information solely to respond to your enquiry.

Accounts and billing

  • Product accounts (including Ironfang Render): your email address, API usage metrics (render counts, request metadata) and billing status. Card details are handled by Stripe and never touch our servers.
  • Signup details: when you create an account we record the IP address the request came from and the country it was made from, once, at signup. We use this for abuse prevention and to understand where our customers are; it is never shared or used for advertising.

Render inputs and delivery

Render inputs: URLs and HTML you submit are processed to produce your render and cached briefly for performance, then deleted on a rolling schedule. We do not read, mine or share them.

If you configure delivery, we store the destination you chose and what is needed to reach it: a webhook URL and its signing secret, or an S3-compatible bucket address and its access credentials. Secrets and credentials are encrypted at rest and are decrypted only to make a delivery you asked for. Your rendered output is sent to that destination on your instruction, and we do not send it anywhere else.

Invoice validation and generation

  • Anonymous invoice validation: an XML document you submit to the free Peppol validator is sent by your browser directly to our API, validated, and answered. The document and its result are processed transiently and are not stored. Content-free request and security metadata for that request, including the IP address, is kept with the server logs below. Anonymous requests are rate limited and limited to 5 MiB.
  • Synchronous signed-in invoice validation: we do not store your raw XML. Result JSON and findings are kept for 30 days and may be deleted sooner in Ironfang Finance or through the API. Existing results receive a 30-day grace period when this retention policy is introduced. Expired results become unavailable immediately and are removed by a background worker. We retain a small operation record (identity hashes, ruleset, outcome, timestamps and usage) until organisation erasure so a retry cannot repeat the work or charge. Copies you download remain under your control.
  • Async invoice jobs and batches: we temporarily store an encrypted copy of the XML or JSON input so an accepted job can finish after a service restart. The input is removed when the job completes or is cancelled, or by expiry cleanup after its 24-hour deadline. Saved results and findings follow the same 30-day retention and earlier-deletion controls as signed-in validation.
  • Generated invoice documents: a saved generation result includes the generated XML, which can contain names, addresses, tax identifiers, bank details and invoice values. It is kept for 30 days and may be deleted sooner. Readable PDFs and signed reports are produced from the retained result; copies you download remain under your control. Anonymous generation does not save the input or result.

Operational information

Server logs: IP addresses and request data, kept for security and abuse prevention.

Why we process it (lawful bases)

We process contact enquiries and account data to perform a contract with you or take steps you request before one (UK GDPR Art. 6(1)(b)); logs and abuse prevention under legitimate interests (Art. 6(1)(f)); and billing records to meet legal obligations (Art. 6(1)(c)). Google Ads measurement runs only with your consent (Art. 6(1)(a)), which you can withdraw at any time. We do not sell personal data, and we use advertising measurement only to learn whether our own adverts led to a subscription.

Who we share it with

  • Cloudflare: network security and content delivery.
  • SMTP2GO: account emails, product notifications and contact-form delivery.
  • Stripe: payment processing for product accounts.
  • Google: Google Ads advertising measurement, only if you agree to it (see Cookies and analytics). Google then receives your IP address, browser details, the pages you visit on our sites and whether an advert click led to a subscription, and handles them under its own terms and privacy policy.

Each processes data under its own contractual safeguards. Where data leaves the UK, transfers rely on adequacy decisions or standard contractual clauses.

How long we keep it

Retention periods
DataHow long we keep it
Contact enquiriesup to 12 months after resolution
Account datafor the life of the account plus what tax law requires for billing records (typically 6 years)
Render inputs and cached outputsdeleted on short rolling windows measured in days, not months
Logsup to 90 days

Ironfang Audit evidence

Ironfang Audit evidence is hosted for the retention period your plan includes, and then deleted. Deletion removes the captured bytes: screenshots, HTML, extracted text, the manifest, the signature and the timestamp token. A record of the audit remains, holding its identifier, the site, when it completed, the compliance summary and page counts, the root and manifest hashes, the signing key identifier, the retention period and the date of deletion. That record still says what was observed and how it was signed, but the content itself can no longer be verified from our copy. If you need to keep verifiable evidence beyond your retention period, download the bundle or export it to your own storage before it expires.

Your rights

Exporting or closing Ironfang Finance

An authorised organisation administrator can export Ironfang Finance data or close the organisation's Ironfang Finance account in the portal. Closure removes its live Ironfang Finance records and cancels its Ironfang Finance subscriptions. We retain the Ironfang Finance and Ironfang organisation identifiers and the closure time to prevent delayed account or key updates from recreating the closed account. Closing Ironfang Finance does not delete your Ironfang sign-in or data in other Ironfang products. Live deletion does not immediately erase database backups, Stripe's payment records, or copies you downloaded or delivered to a destination you chose.

Your data protection rights

You can ask for access to, correction of, or deletion of your personal data, object to or restrict processing, and request portability. Use the contact form and we will respond within one month. You can also complain to the ICO at ico.org.uk.

Cookies and analytics

Cookies

Our own analytics is cookieless. Product dashboards use strictly necessary cookies for login sessions only.

Google Ads measurement

Google Ads advertising measurement is the one exception, and it only runs if you agree to it. It tells us whether an advert led to someone subscribing, and to do that Google sets cookies that are readable across ironfang.com and our identity and portal sites. We record your choice in a cookie of our own so the three sites honour the same answer, and it lasts a year before we ask again. Nothing is sent to Google until you agree, we never send your name, email address, payment details or any Ironfang account identifier, and you can withdraw your agreement below at any time.

Free-tool statistics

Our free tools report daily totals of views, attempts, outcomes, waiting time, selected options, downloads and next-step clicks. These statistics are grouped by tool and broad browser size (mobile, tablet or desktop) and kept in the live statistics database for 90 days. They contain no visitor identifier, submitted URLs, documents, images or generated output. We do not record tool sessions or reconstruct individual visitor journeys from these counters.

Website analytics

Other website pages use self-hosted analytics on our own UK infrastructure to measure page views and interactions. This does not use analytics cookies. Records include page paths, referrers, browser and approximate location information, and session identifiers. Older analytics records, including earlier tool events, remain separate from the new daily counters and currently have no automatic expiry.

Session recording

Those same pages may also record the session itself, so that we can see where a journey breaks rather than only that it did: the page as it was displayed to you, and the scrolling, pointer movement and clicks on it. That includes what you type into a form, such as the contact form, as you type it and whether or not you send it. Password, one-time code and payment card fields are never recorded, and card numbers are replaced with placeholders in your browser wherever they appear, before anything is sent. The free tools are excluded from recording altogether, so nothing you paste into one of them is captured. Each recording also keeps your IP address, your browser's user agent, its window and screen size, language and time zone, and the page you arrived from without its query, so that a recording can be checked if something looks wrong. All of it is deleted with the recording after 28 days. Once a recording starts, your browser also keeps a random identifier in its local storage, so that recordings made in the same browser can be seen together; it contains nothing about you, and turning analytics off deletes it. Recording follows the same off switch as the rest of analytics.

Your choices

Analytics runs by default to help us understand and improve the service. You can turn it off with Reject optional or Preferences in the notice, or at any time with Privacy choices at the foot of every page or the button below; we also honour Do Not Track. We remember your analytics choice in this browser's local storage on ironfang.com, so it does not carry over to another browser. If you do not answer the notice, analytics carries on, Google Ads measurement stays off, and the notice stays until you choose. Operational logs and account records needed to provide and secure the service are separate from these optional usage statistics.

Privacy settings in this browser

AI assistant connections (MCP)

When you connect an AI assistant to Ironfang through our Model Context Protocol server, you authorise it to act for one of your organisations with the scopes you approve. For each request the assistant makes we record the connection identifier, the organisation, the tool or method name, the outcome, the response time, the size of the request and a request identifier. We do not record the assistant's prompts, the arguments it sends to a tool, the results it receives or the model's output.

Content you ask the assistant to render (for example a screenshot of a web page) is processed and stored exactly as it would be if you used the product directly: as an Ironfang Render job belonging to your organisation, kept for the retention period shown in the documentation, and visible to your organisation in the portal. Consent decisions, client registrations and disconnections are recorded as security events on your account so that you can see who connected what.

Disconnecting an assistant revokes its tokens immediately; it does not delete jobs the organisation has already run. Requests are proxied through Cloudflare like the rest of our services.