Skip to content
my-iris

Legal

Privacy summary

How my-iris, operated by MeshWorks Wireless Oy (Finland), handles personal data — in plain language.

Last updated: 1 October 2026

This is a plain-language summary, not the binding legal text. The full Privacy Notice is available on request.

What data we process

  • Account data — the email, name, and workspace details of the people who administer a my-iris workspace.
  • Alert metadata — the content, severity, routing, and acknowledgement history of alerts you send, used to drive escalation and to produce the audit trail.
  • Recipient phone numbers — the contact details of the people you alert. For this data we act as a processor on behalf of you, the tenant; you remain the controller.
  • my-iris app data — for the people you alert through the my-iris app: each phone’s app installation (a device label and platform, whether notifications are allowed, and the push address that lets Apple’s or Google’s push service reach it), the invitations and codes used to join, the alerts it was notified of, and the messages people write in an alert. Push notifications carry only an encrypted reference, never the alert text. We act as your processor for this data.
  • Confirmation records — for each number in a receiver group: whether its owner has confirmed it, when and how, and a keyed hash of the six-digit code we sent (never the code). We act as your processor for this data.

Controller, processor & legal bases

For the recipient phone numbers and alert content you push into the platform, you are the controller and MeshWorks Wireless Oy is your processor under a Data Processing Addendum — we process that data only on your documented instructions. Establishing the lawful basis is yours as controller; controllers typically rely on Art. 6(1)(b) (performance of a contract) or Art. 6(1)(f) (legitimate interest in operating safety-critical alerting). See the DPA summary.

For your own operator-account data, the controller is MeshWorks Wireless Oy (Finnish business ID 2119271-8), Hatanpään valtatie 48, 33900 Tampere, Finland. When you sign in to the my-iris dashboard we process your email, a hashed password, and login timestamps to authenticate you, secure the service, and administer billing. Our lawful bases are Art. 6(1)(b) (performance of the Service Agreement), Art. 6(1)(c) (the six-year retention obligation under the Finnish Accounting Act 1336/1997), and Art. 6(1)(f) (detecting login abuse). Recipients of this data are Cloudflare (hosting) and, when paid billing is enabled, Stripe (payment processing, acting as our processor).

Abuse prevention & recipient confirmation

To keep my-iris from being used for phishing, fraud or other abuse, MeshWorks Wireless Oy processes some data for its own purpose, as a controller, under Art. 6(1)(f) — our legitimate interest in protecting recipients, our customers, carriers and providers. We screen text for web addresses before it is saved or sent and keep a log of what was refused or removed — the path, the rule and the address’s domain, never the message — for 90 days. We check who is signing up (a keyed hash of the verified mobile number, so that one number cannot open several workspaces, and a bot check), look a company up in public registers when we verify it, and keep a record of the steps our operators take to pause or suspend a workspace.

Before a phone number receives an alert, its owner has to confirm it: by replying to a request with a six-digit code, or by signing in to the my-iris app with that number. A number that has not confirmed is left out; the alert still goes to everyone who has. The record of each request — the number, whether it was confirmed, when and how, and a keyed hash of the code, never the code — is kept for you, as your processor. Our platform logs mask phone numbers and are kept for at most seven days.

When you contact us

If you submit the contact form, MeshWorks Wireless Oy is the controller of the details you provide (name, work email, company, phone, and any message), together with technical data your browser sends — your IP address, user-agent, and referring page — which we keep to detect and prevent spam and abuse. Our lawful bases are Art. 6(1)(b) (taking steps at your request before entering a contract) and Art. 6(1)(f) (our legitimate interest in responding to business enquiries); the box you tick simply confirms you have read this notice. These details are stored within Cloudflare (our processor) and are not shared with any third-party CRM — core records sit in Cloudflare’s EU region, while some globally-distributed edge components hold the minimum needed, covered by our DPA and the EU–US Data Privacy Framework / SCCs. We retain them for up to two years, then delete them; you can ask us to erase them sooner at the privacy address below.

EU data residency

my-iris runs on Cloudflare’s EU infrastructure. Our core database and alerting state — Cloudflare D1 and Durable Objects — are pinned to the EU region. Some edge components (KV and Queues) are distributed across Cloudflare’s global network; the data they hold is minimised and protected under our DPA and the EU–US Data Privacy Framework / Standard Contractual Clauses. Our current subprocessors are listed on the subprocessors page.

International transfers

Where a subprocessor processes personal data outside the European Economic Area, the transfer is protected by an adequacy decision (e.g. the EU–US Data Privacy Framework, where the recipient is certified), the European Commission’s Standard Contractual Clauses (Decision 2021/914), or another lawful mechanism under Chapter V GDPR. The applicable safeguard for each provider is noted on the subprocessors page.

Your GDPR rights

Subject to the conditions in the GDPR, individuals can exercise rights including:

Access (Art. 15)
A copy of the personal data we hold.
Erasure (Art. 17)
Deletion of personal data, where applicable.
Rectification
Correction of inaccurate data.
Opt-out
STOP/START keyword handling on SMS, in 7 languages.

Where my-iris acts as a processor, requests from individuals are routed to you (the controller); we assist as required under the DPA.

Beyond those shown above, you also have the rights to restriction of processing, data portability, and to object to processing carried out on legitimate-interest grounds. You have the right to lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), or the authority in your own country.

my-iris does not carry out automated decision-making or profiling that produces legal or similarly significant effects (GDPR Art. 22).

Retention

We keep personal data only as long as needed to deliver the service and meet legal obligations:

  • Recipient numbers & group memberships — for the life of your Service Agreement, then deleted within 30 days of termination unless you instruct otherwise.
  • Alert & reply records — 90 days by default; self-select 30, 90 or 365 days from your dashboard, or arrange up to 5 years with us for audit purposes.
  • Billing / usage records — six years (Finnish Accounting Act); phone identifiers kept beyond an erasure request are pseudonymised within 30 days.
  • Operator-account data — account lifetime plus 12 months.
  • my-iris app data — alert messages, push-notification records and end reports follow your alert-record retention; a phone signed out of my-iris is deleted after the same period; join codes are deleted after a day. An erasure request deletes a person’s app installations and pseudonymises what they wrote.
  • Confirmation records — a request that was never answered is deleted once it has expired and your retention period has passed; a confirmed record is kept while your workspace exists and is deleted on an erasure request for the number, or when your data is deleted after termination.
  • Contact-form data — up to two years, then deleted; erasable sooner on request.
  • Opt-out (STOP) state — kept indefinitely so we can keep honouring your opt-out, until you send START.

Analytics & cookies

This website uses privacy-friendly, cookieless analytics (Cloudflare Web Analytics) and only essential cookies. See the cookie policy.

Making a privacy request

Email MWW-Security-Team@mww.fi with your request. The full, binding Privacy Notice is available on request.

MeshWorks Wireless Oy has not designated a Data Protection Officer: our processing does not meet the Article 37(1) GDPR thresholds, and data-protection enquiries are handled at the address above. We will give Customers at least 30 days’ notice of any material change to this notice; the “Last updated” date always reflects the current version.