Skip to main content

Privacy Policy

Last updated: September 2026

iPify is committed to an ongoing process of compliance with applicable French and European data protection laws, in particular the French Data Protection Act of 6 January 1978, as amended, and Regulation (EU) 2016/679 of 27 April 2016, the General Data Protection Regulation (“GDPR”).

This Privacy Policy describes how iPify collects and processes personal data when you:

  • browse the iPify website
  • use the iPify Platform
  • access or integrate with the iPify REST API
  • use the iPify Model Context Protocol (“MCP”) Server
  • contact iPify
  • receive support or commercial communications
  • apply for a position at iPify

It also explains how you can exercise your rights in relation to your personal data.

For the purposes of this Privacy Policy, personal data means any information relating to an identified or identifiable natural person. A person may be identifiable directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.

1. Who is responsible for your personal data?

The services covered by this Privacy Policy are operated by:

iPify SAS
Société par actions simplifiée
SIRET: 904 924 925 00012
12-15 Quai du Commerce
69009 Lyon
France

For any question regarding this Privacy Policy, our processing of personal data or the exercise of your data protection rights, you may contact us at:

[email protected]

iPify has not appointed a Data Protection Officer (“DPO”).

2. In what capacity does iPify process personal data?

Our role under data protection law depends on the processing concerned.

2.1 When iPify acts as a data controller

iPify acts as a data controller where we determine the purposes and means of processing personal data.

This includes, in particular, processing relating to:

  • user and access management
  • authentication and security
  • operation and monitoring of our services
  • product analytics
  • customer support
  • customer relationship management
  • commercial communications
  • enquiries submitted to iPify
  • recruitment
  • compliance with our own legal obligations

2.2 When iPify processes personal data on behalf of a customer

Customers may use the iPify Platform, REST API, integrations or MCP Server to process information relating to intellectual property cases, portfolios, applicants, inventors, representatives, clients or other individuals.

Where a customer determines the purposes for which such information is processed, that customer acts as the data controller and iPify processes the relevant personal data on the customer’s instructions.

In those circumstances, the customer’s own privacy information and contractual arrangements may also apply.

3. What personal data do we collect through our public website?

The public website does not currently set analytics cookies or write analytics information to browser local storage or session storage.

When you contact iPify by email, telephone or through a contact form, we may collect:

  • your first name
  • your last name
  • your company name
  • your email address
  • the content of your enquiry

We use this information to respond to your enquiry and manage our relationship with you.

Our website contact form submits information to HubSpot.

Our hosting and infrastructure providers may also process technical connection, server-log and security information necessary to deliver, maintain and protect the website.

Unless you become an iPify customer or user, remain subscribed to our communications, or another legitimate reason requires us to retain the information for longer, we may keep contact information relating to an enquiry for up to one year.

4. What personal data do we process through the iPify Platform?

When you use the iPify Platform, we may process information including:

  • your first and last name
  • your email address
  • your organisation
  • your user account and technical identifiers
  • authentication information
  • your IP address
  • browser and device information
  • information about your activity and interactions with the Platform
  • support requests and conversations
  • information contained in cases, portfolios, documents, files and other content submitted through the Platform

Customer case and portfolio information may contain personal data relating to third parties, including applicants, inventors, representatives and other persons connected with intellectual property matters.

Where this information is processed on behalf of an iPify customer, iPify processes it in accordance with that customer’s instructions.

5. What personal data do we process through the iPify REST API and integrations?

Customers and authorised systems may interact programmatically with the iPify Platform through the iPify REST API and related integrations.

Depending on the endpoint and the customer’s use of the API, iPify may receive, retrieve, transmit, validate, update or otherwise process information relating to:

  • intellectual property cases
  • works, estimates and instructions
  • portfolio information
  • documents and associated files
  • purchase invoices
  • portfolio synchronisations
  • validation information
  • operational or support information exposed through the API

Information submitted or retrieved through the API may include personal data contained in intellectual property records, documents, files or customer systems.

Documents and files may also contain confidential business or intellectual property information.

5.1 Data validation and normalisation

Information submitted to iPify may pass through processing steps that sanitise, validate and normalise incoming data.

The API may expose the state or outcome of those processing and verification steps, including fields that:

  • are pending verification
  • contain detected errors
  • have been amended as part of a verification process

5.2 API authentication and technical data

Access to documented REST API endpoints uses bearer authentication.

In connection with the operation and security of the API, we may process:

  • authentication credentials or tokens
  • technical client identifiers
  • request metadata
  • endpoint information
  • timestamps
  • security and diagnostic information
  • other technical information necessary to authenticate, process and protect API requests

5.3 Actions available through the API

Depending on the endpoint and permissions available, the REST API may allow authorised customers or connected systems to:

  • retrieve case information
  • access works and pricing information
  • place instructions for services provided through iPify
  • retrieve documents and associated files
  • retrieve purchase invoice information and invoice documents
  • submit, validate or manage portfolio-related information
  • access operational information exposed through the API

Certain API operations may therefore create or update operational records or trigger services requested by the customer.

Where iPify processes personal data through the API on behalf of a customer, the customer acts as the data controller and iPify processes the relevant personal data on that customer’s instructions.

6. What personal data do we process through the MCP Server?

The iPify MCP Server may be used independently from the iPify Platform.

6.1 Authentication

Authentication to the MCP Server is provided through Auth0 using a tenant separate from the tenant used for the iPify Platform.

For existing iPify users, federation may allow an MCP identity to be associated with an existing iPify account.

A verified email address is required for authentication. If the identity provider does not return a verified email address, the MCP connection is refused.

For authentication and access management, we may process:

  • your verified email address
  • the display name provided by your identity provider
  • an OAuth subject identifier
  • an OAuth client identifier
  • permissions and scopes
  • authentication tokens and grants
  • technical session information

The MCP Server does not store your organisation as a separate MCP account attribute.

Where relevant, an organisation may be resolved when a request is made by matching your verified email address with an existing iPify account, for example to determine the applicable service or pricing context.

6.2 MCP requests

The MCP Server processes information supplied by your MCP client in order to perform the requested operation.

Depending on the tool and request, this may include:

  • case or portfolio information
  • simulation parameters
  • case names
  • free-text information
  • structured information
  • CSV data
  • uploaded files
  • other information included in the arguments of an MCP tool call

The information sent to iPify is determined partly by the MCP client or assistant you use.

MCP requests may therefore include free text or other information derived from your interaction with that service.

You should avoid providing personal or confidential information that is not necessary for the requested operation.

7. What does the MCP Server do?

The MCP tools currently provided by iPify are limited to information retrieval, analysis and simulation.

7.1 Use of AI models

iPify does not call an external large language model or other AI model in order to execute an MCP tool request.

In particular, iPify does not send MCP requests to OpenAI, Anthropic, Mistral or another AI model provider for processing on iPify’s behalf.

The result of an MCP tool call is, however, returned to the MCP client that initiated the request.

Depending on the MCP client or assistant you use, that result may subsequently be included in your conversation or otherwise processed by the provider of that client or assistant.

Such processing is controlled independently by the relevant third party and is subject to its own privacy policy, contractual terms and, where applicable, your organisation’s settings.

7.2 No use of MCP content for AI model training

iPify does not use files, prompts, MCP calls or MCP results to:

  • train AI models
  • fine-tune AI models
  • build AI training datasets
  • build internal AI evaluation datasets
  • conduct internal AI model evaluations involving human review

8. For what purposes do we process personal data?

Depending on the relevant service and context, we process personal data in order to:

  • provide and operate our website, Platform, REST API, integrations and MCP Server
  • authenticate users, API clients and connected systems
  • manage user access and permissions
  • receive, validate, normalise and process information submitted through our services
  • perform requested calculations, simulations and analyses
  • process instructions submitted through authorised API endpoints
  • administer customer accounts and services
  • maintain the security, availability and reliability of our systems
  • investigate and diagnose technical problems
  • measure and understand the use of our products
  • improve our products and services
  • provide customer support
  • manage customer and commercial relationships
  • respond to enquiries
  • manage recruitment
  • comply with legal and regulatory requirements
  • establish, exercise or defend legal claims

Where iPify acts as a controller, the lawful basis for processing depends on the relevant activity and may include:

  • taking steps at your request before entering into a contract
  • performance of a contract
  • compliance with a legal obligation
  • our legitimate interests in operating, securing, supporting and improving our services and managing our business
  • consent, where applicable

Where iPify processes personal data solely on behalf of an iPify customer, the customer is responsible for determining the lawful basis applicable to its processing.

9. Product analytics and technical monitoring

We use certain third-party services to understand how our products are used, maintain their performance and diagnose technical problems.

9.1 PostHog

We use PostHog Cloud for product analytics.

iPify Platform

On the iPify Platform, PostHog may process information relating to authenticated users and their interactions with the Platform.

This may include technical information, user identifiers and information about Platform usage.

The PostHog configuration used by the Platform may differ from the configuration used by the MCP Server.

MCP Server

For the MCP Server, PostHog is configured to use PostHog’s EU region.

Analytics events relating to MCP tool calls may include:

  • the MCP tool used
  • the date and time of the request
  • whether the request succeeded or failed
  • request duration
  • the OAuth subject used as a technical user identifier
  • the user’s email address
  • the MCP client name and version
  • technical session information
  • arguments supplied with the MCP request

MCP request arguments may themselves contain:

  • simulation or request parameters
  • free-text information
  • case names
  • structured information supplied directly as an argument

PostHog’s SDK applies sanitisation and payload-size limits before analytics events are transmitted.

Certain secrets and large encoded binary values may be redacted and long values may be truncated.

However, these controls do not prevent portions of free-text or structured information from being included in analytics where that information forms part of an MCP request argument.

For example, where CSV content is pasted directly into an MCP request, part of that CSV may be included in an analytics event in truncated form.

Files transferred through the MCP Server’s separate file-upload mechanism are not included in MCP request parameters merely because they were uploaded through that mechanism.

9.2 Sentry

We use Sentry on the iPify Platform for:

  • technical error monitoring
  • diagnostics
  • session replay

Session Replay is currently active in production and may record a sample of user sessions, including sessions in which no technical error occurs.

Sentry applies masking to displayed text, form fields and media in session recordings.

URLs are not currently masked and may contain technical identifiers relating to accounts, cases or other Platform resources.

Technical error data and session recordings stored in Sentry are currently retained for up to 30 days.

The MCP Server does send information to Sentry.

9.3 HubSpot

We use HubSpot for:

  • customer relationship management
  • customer and prospect communications
  • customer support and chat
  • certain analytics and tracking activities on the Platform
  • website contact forms

Information processed through HubSpot may include:

  • your title
  • your first and last name
  • your company
  • your telephone number
  • your email address
  • support conversations
  • information submitted through support
  • customer relationship information
  • information relating to your interactions with applicable iPify services

Using the MCP Server alone does not automatically:

  • create a HubSpot marketing contact
  • add you to a commercial marketing list
  • subscribe you to a newsletter

10. Service providers and recipients

In order to support our operations, we rely on service providers that assist us with authentication, infrastructure, analytics, technical monitoring, customer relationship management and other functions.

Our current service providers and infrastructure include, depending on the relevant service:

Auth0

Purpose: Authentication and identity management.

Data concerned may include: email address, identity information, technical identifiers, authentication information, OAuth information and permissions.

PostHog

Purpose: Product analytics.

Data concerned may include: technical identifiers, email address, usage information, analytics events and, for the MCP Server, certain request arguments as described above.

For the MCP Server, PostHog is configured to use its EU region.

Sentry

Purpose: Technical error monitoring, diagnostics and session replay on the iPify Platform.

Data concerned may include: technical error information, browser and device information, URLs, technical identifiers and session recordings.

Sentry’s current data storage region for iPify is the United States.

HubSpot

Purpose: Customer relationship management, support, website forms and certain analytics or marketing activities.

Data concerned may include: title, name, company, telephone number, email address, support communications and information relating to customer or prospect interactions.

Hetzner

Purpose: Infrastructure used for the MCP environment.

The MCP infrastructure is hosted in Europe.

AWS

Purpose: Production infrastructure and related technical services.

Relevant production infrastructure is hosted in Europe.

Other infrastructure

Our services also rely on database, storage, caching, backup and security infrastructure.

These components are used for purposes including data storage, OAuth token management, uploaded files and generated artefacts.

Access to personal data is limited to iPify personnel and service providers who require access for the relevant purpose.

We may also disclose personal data:

  • where necessary to provide, maintain or secure our services
  • where required by applicable law, court order or a competent authority
  • where necessary to establish, exercise or defend legal claims

iPify never sells or rents personal data to third parties for their own marketing purposes.

11. Cookies and similar technologies

Cookies and similar technologies may store or access information on your device in order to provide functionality, remember information, measure service usage or support other purposes.

11.1 Public website

It does not currently set analytics cookies or write analytics information to browser local storage or session storage.

11.2 iPify Platform

The iPify Platform currently uses technologies provided by PostHog, Sentry and HubSpot.

These technologies may begin operating when an authenticated user accesses the Platform.

The Platform does not currently provide an in-product consent management interface allowing users to enable or disable each of these technologies before they are activated.

If you wish to object to or request the deactivation of applicable analytics or tracking activities associated with your use of the Platform, please contact:

[email protected]

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

12. How long do we retain personal data?

We retain personal data only for as long as necessary for the purposes for which it is processed.

When determining the appropriate retention period, we take into account:

  • the nature of the relevant service
  • the nature and sensitivity of the information
  • our contractual relationship
  • operational and security requirements
  • legal and regulatory obligations
  • the need to establish, exercise or defend legal claims

Different categories of information may therefore be retained for different periods.

12.1 MCP simulation data

MCP simulation data is retained for no longer than 180 days.

This may include:

  • imported information
  • simulation executions
  • source files
  • generated reports or report artefacts

During the MCP beta phase, the MCP environment may periodically be reset and recreated.

When this occurs, MCP-specific simulations and imports stored in that environment may be deleted earlier than the maximum 180-day retention period.

Following the beta phase, the configured MCP retention window applies, with MCP simulation data retained for no longer than 180 days.

12.2 MCP authentication data

Authentication credentials and authorisations have technical expiry periods.

Under the current configuration:

  • an authorisation code expires after approximately 5 minutes
  • an access token expires after approximately 8 hours
  • a refresh token expires after approximately 30 days
  • a single-use upload link expires after approximately 5 minutes
  • an OAuth client registration generally expires after approximately 180 days

Revoking authentication credentials removes the relevant token pair from the token store.

Revocation does not automatically erase simulation data previously created under the corresponding OAuth identity. Such data remains subject to the MCP retention rules described above.

12.3 Sentry

Technical error data and session recordings stored in Sentry are currently retained for up to 30 days.

12.4 REST API and integration data

Information processed through the REST API or related integrations generally follows the retention rules applicable to the corresponding information in the iPify Platform or underlying customer service.

Technical authentication, security and API request information may be retained for as long as reasonably necessary to operate and secure the API and comply with applicable contractual or legal requirements.

12.5 Website enquiries

Where you contact iPify but do not subsequently become an iPify customer or user, we may retain your contact information for up to one year, unless you remain subscribed to our communications or another legitimate reason requires a longer retention period.

12.6 Recruitment

When you apply for a position at iPify through our website, by email or through a recruitment agency, we may collect:

  • your first and last name
  • your email address
  • your telephone number
  • information contained in your CV or résumé
  • information contained in your cover letter
  • other information you choose to provide as part of your application

iPify does not ask candidates to provide information that is not necessary for the recruitment process.

In particular, we do not request information concerning matters such as racial or ethnic origin, political opinions, religious beliefs, trade union membership or sexual orientation unless processing such information is specifically required or permitted by applicable law.

If iPify enters into an employment contract with you, relevant information will be retained and processed for the management of the employment relationship in accordance with applicable legal requirements.

If no employment contract is concluded, iPify may retain information submitted in connection with your application for up to three years in order to contact you regarding future opportunities, unless you ask us not to do so.

12.7 Other information

Where no specific period is stated above, we retain information for no longer than reasonably necessary for the relevant purpose, contractual relationship, legal obligation, security requirement or legitimate business need.

13. International transfers of personal data

We use service providers located within the European Economic Area (“EEA”) as well as providers that may process or permit access to personal data from other countries.

Our current infrastructure includes:

  • MCP infrastructure hosted in Europe through Hetzner
  • production infrastructure hosted in Europe through AWS
  • PostHog Cloud in its EU region for MCP product analytics
  • Sentry with its data storage region located in the United States

Personal data processed through Sentry, including technical error information and session recordings, may therefore be stored in the United States.

Some service providers may also provide support, administration or other services involving access to personal data from outside the EEA, even where the primary hosting region is located within the EEA.

Where personal data is transferred outside the EEA and applicable law requires safeguards, we use an appropriate legal transfer mechanism.

Depending on the circumstances, these safeguards may include:

  • an adequacy decision adopted by the European Commission
  • the European Commission’s Standard Contractual Clauses
  • another legally recognised transfer mechanism

Where your personal data is transferred to a third country or international organisation, you may request information about the safeguards applicable to that transfer.

14. How do we protect personal data?

iPify recognises the sensitivity of the information entrusted to us.

We take technical, administrative and organisational measures designed to protect personal data against:

  • unauthorised access
  • accidental or unlawful disclosure
  • alteration
  • loss
  • destruction
  • misuse

Depending on the relevant service, these measures may include:

  • authentication and access controls
  • restricted access to production systems
  • technical logging and monitoring
  • API authentication and request validation
  • security controls implemented by our infrastructure providers
  • confidentiality obligations for personnel with access to personal data
  • measures intended to maintain the availability and integrity of our systems

For the REST API, security measures may include bearer-token authentication, access controls and request-validation measures designed to prevent unauthorised access to API endpoints and customer information.

Additional information about our technical, administrative and organisational security measures is available in our Security Policy.

No information system can be guaranteed to be completely secure.

Where we become aware of a personal data breach, we handle it in accordance with applicable legal requirements.

15. Marketing communications

iPify does not sell or rent personal data to third parties for their own marketing purposes.

Where you receive marketing or commercial communications from iPify, you may object to those communications or unsubscribe using the mechanism provided in the relevant communication.

You may also contact us at:

[email protected]

Using the MCP Server alone does not automatically:

  • create a marketing contact in HubSpot
  • add you to a commercial marketing list
  • subscribe you to a newsletter

16. What are your rights?

Subject to the conditions and limitations set out in applicable law, you have the following rights in relation to your personal data.

16.1 Right of confirmation

You have the right to obtain confirmation as to whether or not personal data concerning you is being processed.

16.2 Right of access

You have the right to obtain access to personal data concerning you and, subject to applicable law, a copy of that information.

You may also obtain information concerning:

  • the purposes of the processing
  • the categories of personal data concerned
  • the recipients or categories of recipients to whom the personal data has been or will be disclosed, including recipients in third countries or international organisations
  • where possible, the envisaged retention period or the criteria used to determine that period
  • the existence of your rights to rectification, erasure, restriction and objection
  • your right to lodge a complaint with a supervisory authority
  • where the personal data was not collected directly from you, any available information as to its source
  • the existence of automated decision-making, including profiling, where applicable
  • where personal data is transferred outside the EEA, information concerning the applicable safeguards

16.3 Right to rectification

You have the right to request the rectification of inaccurate personal data concerning you without undue delay.

Taking into account the purposes of the processing, you may also have incomplete personal data completed, including by providing a supplementary statement.

16.4 Right to erasure

You may have the right to request the erasure of personal data concerning you where, for example:

  • the data is no longer necessary for the purposes for which it was collected or processed
  • you withdraw consent and there is no other legal basis for the processing
  • you validly object to the processing and there are no overriding legitimate grounds for continuing it
  • the data has been unlawfully processed
  • erasure is required to comply with a legal obligation

The right to erasure does not apply where processing remains necessary, for example, for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

16.5 Right to restriction of processing

You may have the right to request restriction of processing where:

  • you contest the accuracy of the personal data while we verify it
  • the processing is unlawful and you request restriction instead of erasure
  • iPify no longer needs the information for its processing purposes, but you require it for the establishment, exercise or defence of legal claims
  • you have objected to processing and verification of the relevant legitimate grounds is pending

16.6 Right to data portability

Where the conditions provided by the GDPR are met, you have the right to receive personal data you have provided to iPify in a structured, commonly used and machine-readable format.

You may also have the right to transmit that information to another controller without hindrance from iPify and, where technically feasible, to request direct transmission between controllers.

16.7 Right to object

Where processing is based on legitimate interests, you may have the right to object, on grounds relating to your particular situation, to the processing of your personal data.

If you validly object, we will stop the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for the establishment, exercise or defence of legal claims.

16.8 Right to object to direct marketing

Where personal data is processed for direct marketing purposes, you have the right to object at any time.

If you object to direct marketing, we will no longer process your personal data for those purposes.

16.9 Automated individual decision-making, including profiling

Subject to the conditions provided by applicable law, you have the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning you or similarly significantly affects you.

Where an exception provided by law applies, appropriate safeguards will be implemented where required.

These may include the right to obtain human intervention, express your point of view and contest the decision.

Where processing is based on your consent, you have the right to withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

16.11 Rights after death

Under French law, you may issue instructions concerning the retention, erasure and communication of your personal data after your death.

These instructions may be general or specific, subject to the conditions provided by applicable law.

17. How can you exercise your rights?

You may exercise your rights or ask us any question about our use of your personal data by contacting:

[email protected]

Please describe your request with sufficient detail to allow us to identify the relevant information.

Where we have reasonable doubts concerning the identity of the person making a request, we may ask for additional information necessary to confirm that person’s identity.

We will respond within the time periods required by applicable data protection law.

Where iPify processes personal data solely on behalf of one of our customers, we may refer or forward your request to that customer as the relevant data controller and assist the customer in handling the request where appropriate.

18. Right to lodge a complaint

You have the right to lodge a complaint with a competent supervisory authority, in particular in the Member State of your habitual residence, place of work or place of an alleged infringement.

In France, the competent supervisory authority is:

Commission Nationale de l’Informatique et des Libertés (CNIL)
3 Place de Fontenoy
TSA 80715
75334 Paris Cedex 07
France

19. Third-party MCP clients and assistants

When you connect the iPify MCP Server to a third-party assistant, AI service or other MCP client, that third party may independently process:

  • information you provide directly to it
  • information it sends to iPify through MCP tool calls
  • information returned to it by iPify through MCP tool results

iPify does not control processing independently carried out by those third-party providers.

Before using the MCP Server with a third-party service, you should review:

  • the provider’s privacy policy
  • its data-retention settings
  • its contractual terms
  • any organisational or enterprise privacy settings applicable to your account

20. Contacting us

If you wish to know more about how iPify uses personal data, exercise your rights, raise an objection, submit a complaint, ask a question or make a recommendation concerning this Privacy Policy, you may contact us at any time at:

[email protected]

or by writing to:

iPify SAS
12-15 Quai du Commerce
69009 Lyon
France

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, including in order to:

  • clarify its contents
  • reflect changes to our website or services
  • reflect new products or features
  • reflect changes to our service providers or processing activities
  • comply with legal or regulatory requirements

The “Last updated” date at the top of this Privacy Policy indicates the date of the latest revision.

Where appropriate, we may provide additional notice of material changes through the relevant service or another suitable communication channel.

We may make previous versions of this Privacy Policy available so that you can review changes over time.