
Ironclad
GDPR evidence
AI-powered contract management
Ironclad and GDPR
CertReports found no public GDPR evidence for Ironclad as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 25 Oct 2024
- Expires or valid through
- 1 Oct 2026
- Scope
- Ironclad as a Data Controller Ironclad requires each customer to provide us with personal data to access and use Ironclad products and services. Personal data is captured when a visitor accesses online services, or speaks on the phone with or emails an Ironclad employee, and willingly discloses that information. Personally data includes: (1) contact data (such as name, address, city, state, zip code, phone number, and email address); (2) financial data (such as credit card number, expiration date, and verification code or bank account information); and (3) demographic data (such as zip code and sex). We use information we collect from the online services to: provide customers with the online services; communicate with customers; process customer orders; manage and remember customer preferences and customize the online services; analyze and improve the online services or any other products and online services we provide; improve our advertising and marketing; verify customer identity; facilitate customer transactions with our third-party marketing partners; inform customers of offers and discounts; comply with our legal obligations or as permitted by law; protect the safety and/or integrity of our users, employees, third parties, members of the public, and/or the online services; and prevent fraud and enforce our legal terms. We disclose customer information to the following types of third parties: (1) service providers that help facilitate transactions; and (2) marketers (where we have your explicit consent). Ironclad as a Data Processor Ironclad processes personal data on behalf of Ironclad customers in order to render Ironclad's services to customers pursuant to Ironclad's ESA (legal.ironcladapp.com/#esa). Ironclad services include the provision and use of Ironclad’s contract management SaaS application. Categories of data subjects include (1) prospects, customers, business partners and vendors of customers; (2) employees or contact persons of customers’ prospects, customers, business partners and vendors; and (3) employees, agents, advisors, freelancers of customers. Types of personal data include (1) first and last name; (2) title; (3) position; (4) employer; (5) contact information (company, email, phone, physical business address); (6) identification Data (notably email addresses and phone numbers); and (7) electronic identification data (notably IP addresses and mobile device IDs). Ironclad discloses personal data provided by customers to third parties (specifically, Ironclad's subprocessors, https://ironcladapp.com/subprocessors/) to assist Ironclad in providing the services. For more information, please see Ironclad's DPA (legal.ironcladapp.com/#dpa).
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Ironclad: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 f517bf253e |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Ironclad GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Legal tech category) whose GDPR row is verified or vendor-stated, ranked by similarity.