Privacy policy
How Infrared collects, uses, and protects data — for both customers (our users) and end-recipients (your users).
Last updated:
1. Controller & processor roles
For customer account data, Infrared Labs SAS acts as controller. For end-recipient data (phone numbers, message content), Infrared acts as processor on behalf of the customer, under the DPA available on request.
2. Data we collect
Customer account: email, company details, billing address. Operational: API logs, delivery receipts, sender ID review materials. End-recipient: phone number and message payload provided by the customer at send time.
3. Retention
Message payloads: 30 days by default (configurable). Delivery logs: 13 months for carrier dispute windows. Account data: for the duration of the contract plus legal retention periods.
4. Data residency
Primary storage in Paris (France), backup in Frankfurt (Germany). Cross-border transfers, where strictly necessary (e.g. non-EU carriers), are covered by Standard Contractual Clauses.
5. Your rights
Data subjects can request access, rectification, deletion, or export of their personal data via @infraredsms. Customer admins can self-serve end-recipient deletion requests through the console.
6. Contact
Data protection officer: @infraredsms. Postal address: Infrared Labs SAS, 128 Rue La Boétie, 75008 Paris, France.