/ Legal

Privacy Policy

Last updated: September 2026

Ideolon ("Ideolon," "we," "us," "our") respects your privacy and is committed to protecting personal data processed through our website and the Iritam Audit Management Platform ("Iritam" or the "Platform").

This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal data when you visit our website, submit inquiries, or access the Iritam platform.

01Introduction

Ideolon ("Ideolon," "we," "us," "our") respects your privacy and is committed to protecting personal data processed through our website and the Iritam Audit Management Platform ("Iritam" or the "Platform").

This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal data when you:

  • visit the Ideolon website;
  • submit information through a Request a Demo or Careers form on our website;
  • use or access Iritam as a member of Ideolon's own team (staff, auditors, project managers, administrators, business developers, etc), or as personnel of a client organization we audit;
  • communicate with us regarding our products or services; or
  • receive service-related or marketing communications from us.

Ideolon is based in India and provides services to organizations and individuals internationally, including in the European Economic Area ("EEA"), UK, and elsewhere. This Policy is intended to address applicable requirements including India's Digital Personal Data Protection Act, 2023, the EU GDPR, the UK GDPR, and other applicable laws.

02Who we are

Legal Entity Name: Ideolon

Registered Address: A-1006 & B-1006, Sankalp Iconic Tower, Iskon-Ambli Road, Ahmedabad 380058, Gujarat, India

Website: www.ideolon.com

Privacy Contact: [email protected]

03The two surfaces this policy covers

3.1 Ideolon Website - Our corporate/informational website, including Request a Demo and Careers forms.

3.2 Iritam Platform - Iritam is an audit management platform that Ideolon uses to manage and deliver audit services.

04Our role: Data controller

Ideolon is the data controller (or equivalent) for personal data processed through the website and through Iritam, because Ideolon determines the purposes and means of the audits it conducts and the platform it operates - including who is assigned to an audit, what stages an audit goes through, and what records are generated.

A client organization does not independently determine how its personnel's or auditors' data is processed within Iritam; it participates in the audit as the audited party. Where a specific written agreement with a client separately allocates controller/processor responsibilities for a defined scope of data, that agreement will govern for that scope, and this Policy should be read alongside it.

05Personal data we collect

5.1 Through the Website

  • Request a Demo: name, business email, phone number (if given), company name, and the content of your enquiry.
  • Careers: name, email, phone number, resume/CV, years of experience, cover note and any cover letter or application information you submit. Used only for recruitment purposes, not for unrelated marketing.
  • Technical/usage data: IP address, browser and device information, and log data collected automatically.

5.2 Through Iritam

  • Account and user data: name, business email, username, organization, job title, assigned role and permissions, account status.
  • Audit and business data: audit schedules and assignments, findings and observations, Notices of Compliance, Final Audit Reports, CAPA plans, supporting evidence, closeout records, comments, approvals, and related business-contact information - as entered or uploaded during the audit.
  • E-signature data: via our signature provider (currently Zoho Sign) - name, email, IP address, device/browser information, and a timestamped signing record, retained as part of the document's evidentiary trail.
  • Technical/security data: IP address, device information, login and access records, and security/error logs.

We do not intend to use personal data collected through Iritam for sale of personal data, or unrelated profiling or advertising except as described in Section 9.

06Cookies

The website and Iritam use cookies for core functionality, authentication, and security; the website may also use analytics or preference cookies. Where applicable law requires consent for non-essential cookies, we will request it before use, and you can manage cookies through your browser or our cookie-consent mechanism where provided.

07How we collect personal data

  • Directly from you - form submissions, account creation, uploads, audit participation, or signing documents.
  • From Ideolon's own team - as part of assigning auditors, project managers, and other participants to an audit.
  • From customer/supplier organizations - where a customer/supplier identifies its own personnel as points of contact, reviewers, or signatories for an audit.
  • Automatically - technical and security data collected as you use either surface.
  • Through service providers - e.g., delivery/engagement data from our email or e-signature providers.

09Marketing and campaign emails

We send campaign or newsletter emails only to registered Iritam customers with whom we have an existing business relationship - not to website visitors, demo requesters, or careers applicants who haven't gone on to register. This is a "soft opt-in" grounded in that existing relationship, not a separately obtained affirmative opt-in. Every campaign email includes an unsubscribe link, and you can opt out at any time via that link or by contacting [email protected]. Opting out of marketing emails will not affect transactional or service emails needed to operate your account.

10Who we share data with

  • Sub-processors/service providers: Zoho Sign (e-signature), Zepto Mail/Zoho Campaigns (email delivery and campaigns), and our hosting/infrastructure provider - engaged under contractual terms restricting them to our instructions.
  • Client organizations, where you are their personnel and participate in an audit conducted through Iritam.
  • Regulators or authorities, where required by law, audit standard, or legal process.
  • A successor entity, in the event of a merger, acquisition, or asset sale, subject to equivalent protections.

We do not sell personal data, and we do not permit third parties to use Iritam data for their own unrelated purposes.

11International data transfers

Iritam's infrastructure is currently hosted in the United States. If you access the website or Iritam from the EEA, UK, or elsewhere outside the US, your data will be transferred to and processed in the United States.

Where required, we rely on appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission and/or confirmation that a given sub-processor is certified under the EU-US Data Privacy Framework. You may request details of the applicable safeguard at [email protected].

12Data retention

  • Website enquiries (demo/careers): retained only as long as needed to respond to the enquiry or process the application, then deleted.
  • Iritam account data: for the duration of the account plus permanently after deactivation.
  • Audit records and e-signed documents: retained permanently, reflecting applicable regulatory/audit-standard recordkeeping and evidentiary requirements.
  • Marketing data: until you unsubscribe or after 3 years of inactivity.
  • Technical/security logs: permanently.

13Your rights

Depending on your location, you may have the right to: access your personal data; request correction; request erasure (subject to our legal retention obligations for audit/signature records); request restriction of processing; object to processing, including marketing; request data portability; withdraw consent where applicable; and lodge a complaint with the applicable authority - e.g., the ICO (UK), your EEA supervisory authority, or the Data Protection Board of India.

If you are in India, you additionally have the right to grievance redressal directly with us, and the right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

We encourage you to contact us first with any concern so we can investigate and try to resolve it directly.

If your data is processed through Iritam in connection with an audit of your employer, you may need to route your request through your organization first; we will assist as required.

To exercise these rights, or to raise a grievance, contact us at [email protected]. We will respond within the timeframe required by applicable law.

14Security

We apply technical and organizational measures including role-based access control, encrypted transmission, restricted access to signed documents and evidence files, logging/monitoring, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.

15Data breach notification

If we become aware of a personal data breach posing a risk to individuals, we will investigate, mitigate, and notify affected individuals and relevant authorities as required by applicable law, generally without undue delay and, where feasible, within 72 hours of becoming aware.

16Children's privacy

Neither the website nor Iritam is directed at children. Under Indian law, a "child" is anyone under 18; under GDPR/UK GDPR, the threshold is 13–16 depending on jurisdiction. We do not knowingly collect personal data from children, and if we become aware that we have, we will take reasonable steps to delete it, consistent with applicable law.

17Automated decision-making

Iritam does not use personal data to make solely automated decisions with legal or similarly significant effects on individuals. If this changes, we will implement the safeguards required by applicable law.

18Third-party links and services

The website or Iritam may link to or integrate with third-party services that have their own privacy practices. We are not responsible for those practices beyond what applicable law or our contracts require.

19Changes to this policy

We may update this Policy to reflect changes in our services, processing activities, service providers, or applicable law. The "Last Updated" date reflects the most recent revision. Where required, we will provide additional notice or obtain consent for material changes.

20Contact us

Ideolon

A-1006 & B-1006, Sankalp Iconic Tower, Iskon-Ambli Road, Ahmedabad 380058, Gujarat, India

[email protected]

Questions about this privacy policy?

Contact us at [email protected] or write to A-1006 & B-1006, Sankalp Iconic Tower, Iskon-Ambli Road, Ahmedabad 380058, Gujarat, India.