Privacy Policy
1. Overview
This Privacy Policy describes how IrmaWP, Inc. ("IrmaWP," "we," "our") collects, uses, and shares information when you use our website and platform (the "Services").
We've tried to write this in plain English. If you have questions, email privacy@irmawp.com — a human will read it.
2. Data we collect
We collect three categories of information:
- Account information: name, email, company, billing details. Provided by you when you sign up.
- Workspace data: the WordPress sites you connect, their operational metadata (plugin versions, uptime checks, change history). Created as a result of using the platform.
- Usage information: pages viewed, actions taken inside IrmaWP, error logs. Collected automatically to operate and improve the service.
We do not sell personal data. We do not use workspace data to train third-party models.
3. How we use information
We use the information we collect to provide, maintain, and improve the Services; to communicate with you about your account; and to comply with legal obligations.
We also use operational and usage data to detect abuse, investigate incidents, enforce limits, and improve the product.
4. AI providers and subprocessors
If you use IrmaWP-managed AI features, prompts, instructions, metadata, and related context may be sent to the third-party AI providers used by the product to complete the request. AI features process workspace data only to respond to your requests. We do not retain prompts or responses for model training.
If your workspace uses BYOK (bring your own key), requests may be sent through the OpenRouter account configured by your workspace instead of IrmaWP-managed credentials. In that case, prompts are routed through your provider under their terms.
5. When we share information
We share information with service providers (hosting, payment processing, email delivery) under standard data processing agreements.
We share information when required by law — such as a valid subpoena. When permitted, we will notify you before disclosure.
If IrmaWP is acquired or merges, your data transfers under the same terms. You'll be notified at least 30 days in advance.
6. Cookies and analytics
We may use cookies or similar technologies for authentication, session management, preferences, security, and basic analytics.
Where required by law, consent and cookie controls should be handled before non-essential tracking is enabled.
7. Retention
Workspace data is retained while your account is active. You can export and delete data at any time from the workspace settings.
After account deletion, we retain billing records for seven years (legal requirement) and otherwise purge data within 30 days. Backups, logs, monitoring data, and AI-related records may be retained for different periods depending on product configuration, legal requirements, or incident investigation needs.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to certain processing. To exercise these rights, email privacy@irmawp.com.
California residents: see our CCPA notice. EU/UK residents: see our GDPR notice.
You can update account information, manage billing, disconnect BYOK credentials, and request deletion of an account subject to legal, billing, security, and operational retention requirements.
9. Security
We use industry-standard safeguards: encrypted data in transit and at rest, role-based access controls, audited backups, and SOC 2 Type II controls.
No system is perfectly secure. If we discover a security incident affecting your data, we will notify you within 72 hours of confirmation.
10. Contact
Questions, requests, or complaints: privacy@irmawp.com. Postal mail: IrmaWP, Inc., 548 Market St #93182, San Francisco, CA 94104.