Iriska.AI
Prices for
Language
Create account

Are you buying for business, or for home?

Legal

Privacy

What Iriska knows about you, why, for how long, and how to make it stop. Written to be read rather than to be complied with.

Who is responsible

Iriska B.V. (KvK 42071022, Amsterdam, the Netherlands) is the controller for the personal data described here.

Privacy contact: [TO BE CONFIRMED — DATA_CONTACT]

Sellers are separate controllers for what they do with your data after an order — an invoice they issue, a delivery they arrange. Their obligations are their own.

What is collected, and why

Grouped by what it is for, because a list of field names tells you nothing about what is happening to you.

  • To let you in: email address, and a phone number if you give one. Lawful basis: performance of a contract.
  • To run an order: delivery address, order contents, the price paid, VAT treatment, and the invoice. Lawful basis: contract, and legal obligation for the tax record.
  • To verify a business: company number, VAT number, the names of the people who represent it, and the documents uploaded to support a capability claim. Lawful basis: legal obligation and legitimate interest in a marketplace that is not full of fictional companies.
  • To keep the platform honest: an append-only log of significant actions — an order placed, a price changed, a listing published — with the account that did it and when. Lawful basis: legitimate interest in being able to reconstruct what happened.
  • To tell you things: notifications inside the platform, and email where you have chosen it. Lawful basis: contract for transactional messages, consent for anything else.
  • To fix faults: error reports. These carry no cookie and no tracking identifier. Session replay, which records how a page behaved for you, is separate and off unless you turn it on — see the cookies page.

What is not collected

No advertising or profiling cookies. No third-party analytics. No data sold or shared for anyone else’s marketing. No card numbers: those go to Mollie and never reach Iriska.

The catalogue is browsable without an account, and browsing it does not require you to accept anything.

Automated decisions and AI

Iriska uses AI to match products to requests, to draft text a human then edits, and to flag risk signals during verification for a human to look at.

No decision that affects you legally or significantly is made by a machine alone. Verification outcomes, account suspensions and refunds all pass a human. Where a risk engine flags something, it flags it to a person; it does not decide.

Who else processes it

Iriska uses processors to run the platform. Each one is contracted to process data only on Iriska’s instructions.

  • Supabase — database, authentication and file storage
  • Vercel — application hosting
  • Mollie — payment processing (a licensed Dutch payment institution, and a separate controller for what it must keep by law)
  • Sendcloud — carrier aggregation and shipping labels
  • Sentry — error reporting, and session replay only with your consent
  • Resend — transactional email
  • Anthropic — the AI layer
  • Signed data-processing agreements and, where any processing happens outside the EEA, the transfer mechanism relied on: [TO BE CONFIRMED — PROCESSOR_TERMS]

How long it is kept

Order and invoice records are kept for seven years. That is the Dutch statutory retention period for accounting records and Iriska has no discretion about it.

Everything else is kept while your account is open and removed when it is closed, except where a specific obligation says otherwise.

Deleting your account

Deletion anonymises; it does not erase everything, and it is important to understand which is which.

Your personal data goes: name, email, phone, saved addresses, preferences. Your identity becomes a tombstone. Orders survive, with every figure intact and the buyer reference redacted — because an order and its invoice are statutory records the Netherlands requires to be kept for seven years, and destroying them on request would be unlawful in the other direction from a privacy breach.

The redacted reference is stable, so two orders from the same deleted person still read as the same person to an auditor, without the name.

It is refused in one case: if you are the owner of an organisation that has other members. Transfer ownership first — you can do that yourself — and then delete.

You can also export everything held about you, from the same screen, before you decide.

Your rights

Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time, and withdrawing it does not make what happened before unlawful.

Most of this is self-service in your account under Privacy and data. For anything else, write to [TO BE CONFIRMED — DATA_CONTACT]

If you think Iriska has got it wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the authority in the EU country where you live.

Draft — not yet reviewed

The other documents: terms of service, cookies, imprint, returns and cancellation.