Privacy
Two separate questions live under this heading: what this website does with your data, and what the IREX platform does with a customer’s. They have different answers, so they are answered separately.
Privacy Policy
This Website, and the Platform
Part One: This Website
What We Collect
This site collects personal data in exactly one place: the contact and demo-request form. The fields are your name, email address, telephone number, the nature of your interest in IREX, and your message. The form also records the page you submitted from, and the request’s approximate region as reported by our content delivery network.
We use analytics to understand which pages are read. Analytics identifiers are set by Google Analytics and Google Ads.
Why We Collect It, and What We Do with It
To reply to you, and to route your inquiry to the right person. A form submission is delivered to the relevant IREX team through an internal secure channel. We do not sell personal data, and we do not share form submissions with third parties other than the processors that operate the site and its delivery infrastructure.
Cookies and Similar Technologies
The site uses cookies for analytics, and the contact form uses an anti-abuse challenge that sets its own cookie in order to distinguish a person from a bot. Blocking analytics cookies does not prevent you from using the site. Where consent is required in your jurisdiction, the consent choice you make is the one we act on.
Your Rights
Depending on where you are, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent. To exercise any of these, use the contact form and we will respond within the period your law requires.
Part Two: The IREX Platform
If you are a member of the public wondering what an IREX deployment in your city does with your image, this is the part that matters, and the honest summary is that IREX does not hold that data at all.
- The customer owns it, entirely. Customers retain 100% ownership and control of their data. IREX neither owns nor accesses customer video, events, logs, alarms, watchlists or floor plans, and there is no IREX-side data plane for customer media. In a customer-hosted deployment the data never leaves the customer’s own infrastructure.
- The platform recognizes only pre-registered people. Alert-based monitoring targets a watchlist of specific individuals, such as wanted suspects, missing children and adults, and trafficking victims. It cannot recognize or track random individuals in public spaces. This is enforced architecturally, not by policy.
- Every privacy-sensitive action requires a recorded lawful reason. Before a facial-recognition search or comparable action, the operator records the grounds: a case file, a court order, a missing-person report. That Case ID is mandatory at platform level.
- The record cannot be erased. Actions are written to an append-only, tamper-evident log, exported daily, with read access designed for supervisors, ethics committees and independent oversight bodies.
- Nothing acts autonomously. Detections are signals for a person to verify.
Because IREX is not the controller of that data, a request about footage held by a city, a police force or a transport operator has to go to that organization. If you are unsure who operates a deployment, write to us and we will tell you where to direct it.
Where Platform Data Is Processed
For customer-hosted deployments, entirely on the customer’s own infrastructure in their chosen jurisdiction. For IREX-managed instances, in the IREX private cloud on colocation in Dallas and Plano, Texas, United States. EU and EEA data subjects are served from a local, in-region instance rather than the US instance, and cross-border transfers from IREX-managed instances rely on Standard Contractual Clauses plus supplementary measures.
Lawful Basis, Where IREX Is a Processor
Service operation rests on contractual necessity. Biometric processing requires a valid GDPR Article 9 condition, enforced operationally through the Case ID lawful-authorization gate. Security monitoring rests on legitimate interest.
Contact
IrexAI Inc., 29970 Technology Drive, Suite 210A, Murrieta, California 92563, United States. Contact form · +1 (301) 392-7621.
Document Status
This page describes IREX’s privacy practices and the platform’s data-protection architecture. The formal, counsel-approved privacy notice, the data-processing agreement, and the data-protection policy are issued on request. If you need the executable document for a procurement file, ask through the contact form rather than relying on this summary.
FAQ
Does IREX hold footage of me?
No. IREX neither owns nor accesses customer video, and in a customer-hosted deployment the data never leaves the customer’s own infrastructure. A request about footage has to go to the organization operating the cameras, whether that is a city, a police force or a transport operator.
Can an IREX deployment recognize me if I am not on a watchlist?
No. Alert-based monitoring targets only pre-identified people, and the platform cannot recognize or track random individuals in public spaces. That constraint is enforced in the architecture rather than by policy.
How do I make a data-subject request?
For this website, use the contact form. For a deployment, the request goes to the organization operating it, because IREX is not the controller of that data. If you do not know who operates it, ask us and we will point you.
Is this the formal legal notice?
It is an accurate description of practice, and it is the page we maintain. The formal, counsel-approved privacy notice and the data-processing agreement are issued on request, and those are the documents to put in a procurement file.
Ask a Privacy Question
Including the awkward ones. We would rather answer them than have them asked about us.