Knowledge Base · Compliance & data
Is my-iris GDPR-compliant?
my-iris is built around GDPR requirements, not retrofitted afterward. Alert data lives on the EU edge by architecture (Cloudflare Durable Objects pinned to EU jurisdiction). A push to the my-iris app goes through Apple’s or Google’s push service, so it carries no alert text: the app fetches the text from my-iris. Data subjects can request an Article 15 export or Article 17 erasure, and both cover the my-iris app’s data; erasure pseudonymises historical records, so the audit trail survives without identifying detail. Opting out is a separate process: recipients can stop voice calls and SMS end reports with the STOP keyword, and restart them with START, in 7 languages. A DPA is available on request.
See the full compliance and EU residency picture.
Compliance & EU residencyGDPR-ready from day one
Ask for our DPA, or tell us what your data protection officer needs to see.