1. Scope and controller
Volterra Advisors LLC (“Volterra,” “we,” “us,” or “our”) operates Volterra IRIS (“IRIS”), a digital-infrastructure event intelligence and collaboration service. This policy applies to the IRIS public website, accounts, workspaces, support interactions, and related service operations. It does not govern third-party sites linked from IRIS or separate Volterra services that publish their own policies.
2. Information we collect
Information you provide
- Account and identity information, such as name, email address, authentication identifiers, organization, and role.
- Workspace information, including workspace name, members, invitations, seat selections, shared planning, saved items, and private notes you choose to create.
- Billing and subscription information, such as plan, seat count, billing cadence, Stripe customer and subscription references, invoice status, and transaction status.
- Communications and support information that you send by email, telephone, or another support channel.
Information collected through the Service
- Technical and security records, such as IP address, device/browser information, request time, authentication and audit events, and limited diagnostic records needed to operate and secure IRIS.
- Service activity, such as authorized workspace changes, content saves, attendance state, and feature use needed to provide the requested functionality.
Payment information is entered through Stripe-hosted Checkout and processed by Stripe. IRIS does not receive or store full payment-card numbers or card security codes. The public product and legal site has no account or payment form.
3. How we use information
We use personal information to:
- provide, administer, personalize, and support IRIS;
- authenticate users, enforce workspace access, manage seats, and maintain private and shared records;
- process subscriptions, reconcile payments, provide billing support, and prevent duplicate or unauthorized transactions;
- secure the Service, detect abuse, investigate incidents, maintain audit records, and enforce our Terms;
- communicate service, account, security, policy, and support updates; and
- comply with law, respond to lawful requests, and establish or defend legal claims.
4. How we disclose information
We may disclose information:
- to workspace owners, administrators, and members according to the workspace permissions and collaboration choices you use;
- to service providers that support IRIS, including Amazon Web Services for infrastructure, Clerk for identity services, Stripe for payment processing, and other vendors used for documented operational purposes;
- to professional advisers subject to appropriate duties of confidentiality;
- when required by law or reasonably necessary to protect rights, safety, the Service, or users; or
- in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards and notice where required.
We do not sell personal information. We do not use personal information for cross-context behavioral advertising. The public product and legal site runs no advertising tracker, analytics script, account form, or payment form.
5. Cookies and similar technologies
The public product and legal site does not set cookies. The IRIS application may use strictly necessary cookies and browser storage to maintain secure sessions, protect requests, and remember essential account state. Optional analytics, if introduced after review, will be described here and configured to avoid private workspace content.
6. Retention
We retain information for as long as reasonably necessary to provide the Service, maintain account and subscription history, meet contractual and legal obligations, resolve disputes, prevent abuse, and protect security. Retention varies by record type. We may retain limited audit, transaction, backup, and legal records after account closure where necessary, then delete or de-identify them under our retention process.
7. Security
We use administrative, technical, and physical safeguards designed to protect information, including access controls, encryption in transit and at rest where appropriate, environment separation, audit logging, and least-privilege service roles. No system is completely secure, so we cannot guarantee absolute security. Please report suspected account or data-security issues promptly.
8. Choices and privacy requests
Depending on where you live, you may have rights to request access to, correction of, or deletion of certain personal information, or to object to or restrict some processing. We will verify your authority before acting and may retain information where law or legitimate security, billing, or recordkeeping needs require it.
To make a privacy request, email j@volterraadvisors.com with “IRIS privacy request” in the subject line.
9. U.S. processing and international users
IRIS is operated from the United States and its primary infrastructure is in the United States. If you access the Service from another country, your information may be transferred to and processed in the United States, subject to applicable legal safeguards.
10. Children
IRIS is a business-oriented service for adults and is not directed to children under 18. We do not knowingly collect personal information from children. Email our privacy contact if you believe a child has provided personal information to IRIS.
11. Changes to this policy
We may update this policy to reflect Service, vendor, legal, or operational changes. We will post the revised effective date and give additional notice when required by law.
12. Contact
Privacy questions may be sent to j@volterraadvisors.com, 410-600-9000, or Volterra Advisors LLC, 428 Halsey Road, Annapolis, MD 21401.