Privacy Policy

Last updated: 18 July 2026

The Big Data Company builds and runs IRIS, a location-intelligence platform. We are European by design, and we treat data protection as part of the product, not an afterthought bolted on. This policy explains, plainly, what personal data we handle, why, and the rights you have. If anything here is unclear, ask us. Our contact details are at the end.

1. Who is responsible for your data

The controller for the personal data described in this policy is:

The Big Data Company B.V. Princetonlaan 6, 3584 CB Utrecht, The Netherlands Email: info@irisplatform.nl Phone: +31 30 899 9477 Chamber of Commerce (KVK): 71155821

For any privacy question or to exercise your rights, contact us at info@irisplatform.nl.

2. What this policy covers

This policy covers two different situations, and the rules differ, so we keep them separate:

  • Part A - Visiting this website (irisplatform.nl): reading our pages, requesting a demo, or starting a free IRIS Market trial.
  • Part B - Using the IRIS product (app.irisplatform.nl): the platform our clients licence, and the business data they load into it.

Part A - When you visit this website

A1. We built this site to collect as little as possible

We made a deliberate choice: this website makes no third-party browser requests. Fonts are served from our own servers, map tiles are bundled with the site, and there are no third-party trackers, advertising pixels, or social widgets. That means:

  • We do not use analytics cookies, advertising cookies, or tracking pixels.
  • We do not load Google Fonts, Google Analytics, or any external script that would send your IP address or browsing behaviour to a third party.
  • Because we set no non-essential cookies, there is no cookie banner - there is nothing to consent to. See section 9 for the full cookie position.

A2. Information you actively give us

We only receive personal data from this site when you choose to send it to us:

  • Booking a call with us (the "Book a demo" page). That page embeds a booking calendar served by meetergo (Frankfurt, Germany). Because it is embedded, opening that page contacts meetergo, which means meetergo receives your IP address and technical details of the request, and it may set its own cookies or storage inside the calendar. Loading that calendar also contacts meetergo's own service and asset hosts, plus one asset host operated by a different provider that we are still confirming and will name in section 6. This is the only page on the site that loads anything from a third party; every other page loads exclusively from our own domain. No other external host is loaded anywhere else on the site. (It was three: the separate Validation Sprint booking page was retired on 2026-08-08 and its URL redirected here, because both calendars booked the same call, and the "Start free" signup page was retired on 2026-08-25 when the free tier was withdrawn.) Links to other companies do appear in our copy, but a link is not a load: nothing is fetched from them unless you click. When you book, you give the details the calendar asks for, which is your name and email plus the questions we configure, and meetergo processes all of this as our sub-processor (see section 6) to place the meeting in our calendar. If you would rather not use the embedded calendar, email or call us instead, in which case you send us your name, company, email or phone, and the market you care about.
  • Contacting us directly by email or phone, in which case we hold whatever you send us.

We said we would describe any EU-hosted booking or signup tool here, and add it to the sub-processor list in section 6, before it went live. meetergo is described above and listed in section 6, and that now covers the free-access signup form as well as the booking calendars. The same commitment stands for anything we add next.

Why we use it, and on what legal basis:

WhatPurposeLegal basis (GDPR Art. 6)How long we keep it
Demo / trial / contact detailsTo respond to you, set up a demo or trial, and take the steps you asked for before any contractArt. 6(1)(b) steps at your request prior to a contract, and Art. 6(1)(f) our legitimate interest in responding to enquiriesUp to 24 months after last contact, then deleted
Marketing follow-up about IRIS, where you've asked for it or are an existing business contactTo tell you about the product you enquired aboutArt. 6(1)(a) consent, or Art. 6(1)(f) legitimate interest for existing business contactsUntil you object or unsubscribe

You can opt out of any marketing contact at any time - reply "stop", use an unsubscribe link, or email us. We act on it promptly.

A3. Server logs

Our hosting provider records standard technical logs (for example IP address, timestamp, and the page requested) to keep the site secure and available. Legal basis: Art. 6(1)(f), our legitimate interest in security and reliability. Retention: a short period, as retained by our hosting provider.

Part B - When you use the IRIS product

IRIS clients load their own business data (for example store locations and historical sales) so we can calibrate and validate forecasts for them.

B1. Two roles

  • For account and administrative data about the individual users of the platform (name, work email, role, login records), The Big Data Company is the controller. Legal basis: Art. 6(1)(b), performance of the licence contract. Retention: for the life of the account and 12 months after it closes, then deleted or anonymised, subject to any legal retention duty.
  • For the business data a client loads into IRIS, the client is the controller and The Big Data Company acts as processor, handling that data only on the client's documented instructions under a Data Processing Agreement (see section 7). Where that data contains personal data, the client's own privacy notice governs it; we process it solely to provide the service.

B2. How we handle client data (the commitments we make on the site, restated here as policy)

  • Never used to train shared models without your permission. Your data calibrates your model. We do not use it to train a model shared with any other client or third party unless you explicitly opt in to collective learning, in which case it is ringfenced to participating clients. It is never sold. This is a contractual commitment, not just a reassurance - ask us for the clause.
  • Never blended. Your data is not mixed with another client's data.
  • Fully exportable. You can export everything - maps, raw signals, and finished analyses - in open formats, at any time, and take it elsewhere without asking us first.
  • Data minimisation. We ask only for the data a forecast actually needs.
  • Role-based access. Access to client data is restricted by role, on a need-to-use basis.

3. We do not sell your personal data

We do not, and will not, sell your personal data, and we do not share it for anyone else's advertising.

4. Where your data is stored, and international transfers

IRIS is hosted and processed inside the EU. We do not transfer personal data to countries outside the European Economic Area. Our infrastructure runs on Microsoft Azure and Google BigQuery, in EU regions.

If that ever needs to change, we will update this policy first and put appropriate safeguards in place before any transfer, and we will tell affected clients.

5. Security

We protect personal data with technical and organisational measures appropriate to the risk, including EU-only hosting, role-based access control, and data minimisation. No system is ever perfectly secure, but we design to reduce what could be exposed and to whom.

6. Who else processes data for us (sub-processors)

We use a small number of vetted providers to run the service. Where they process personal data, they do so under a written data-processing agreement and, for the product, inside the EU:

  • Microsoft Azure (EU regions) - hosting and infrastructure for the IRIS platform.
  • Google BigQuery (EU regions) - data warehousing and large-scale processing behind the platform.
  • meetergo (Frankfurt, Germany; EU-hosted) - scheduling and forms. It processes the name, email and answers you give when you book a demo. Chosen over US scheduling tools specifically because it has no US parent and so no CLOUD Act exposure.

We add any new sub-processor here before it goes live. IRIS clients can request the current, complete sub-processor list, and we notify clients of material changes as set out in the DPA.

7. The paperwork your procurement team will ask for

For the IRIS product we maintain, and will share with clients under NDA where appropriate:

  • a Data Processing Agreement (DPA) governing our role as processor;
  • a Data Protection Impact Assessment (DPIA) covering the data flows, sub-processors, and retention; and
  • a Legitimate Interest Assessment (LIA) where we rely on legitimate interest.

Ask us and we will walk your data protection team through them.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten"), subject to any legal retention duty;
  • restrict or object to certain processing, including direct marketing;
  • data portability, receiving your data in a structured, common format; and
  • withdraw consent at any time, where we relied on consent, without affecting past processing.

To exercise any of these, email info@irisplatform.nl or write to the address in section 1. We respond within one month. If you are an individual whose data was loaded into IRIS by one of our clients, please contact that client (the controller); we will support them in responding.

9. Cookies and analytics

This website (irisplatform.nl) uses only what is strictly necessary to make the page work. We set no analytics, advertising, or tracking cookies here, and load no third-party analytics script, so there is nothing to consent to and we show no cookie banner.

The IRIS product (app.irisplatform.nl), once you log in, uses analytics to run and improve the service, for example to understand which features get used and to find and fix problems. We use it to operate and improve the product, not to profile you or target advertising. This sits under your licence agreement and the account data described in Part B.

If we ever introduce analytics or a non-essential cookie on this website, we will ask for your consent first (via a proper banner) and update this policy before switching it on.

Our site links to a few external places (for example our login at app.irisplatform.nl and the Microsoft Azure Marketplace). Once you follow a link off this site, that destination's own privacy policy applies. We are not responsible for how other sites handle your data.

11. Changes to this policy

We update this policy when what we do changes, and we date every revision at the top. If a change materially affects how we handle your personal data, we will make that clear.

12. Contact and complaints

Questions, requests, or complaints: info@irisplatform.nl / +31 30 899 9477 / The Big Data Company B.V., Princetonlaan 6, 3584 CB Utrecht, The Netherlands.

You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to resolve it with you first.