Privacy Policy

Last Updated: September 14, 2026

Applies to: The ioMoVo website at iomovo.io and the ioMoVo platform, including ioCloud, ioHub, ioGallery, ioFlow, ioPilot, ioPortal, and the capture layer.

This policy explains what personal data ioMoVo handles, why we handle it, who we share it with, and what you can ask us to do about it. If anything here is unclear, write to us and we will explain it in plain terms.

1. Who we are

ioMoVo Corp
7918 Jones Branch Drive, Suite 400, McLean, VA 22102, USA
‍Privacy and rights requests: privacy@iomovo.io General contact: support@iomovo.io, +1 202 239 6247
ioMoVo Corp is the data controller for the personal data described in section 2.1. We have not appointed a Data Protection Officer, as we are not required to under Article 37 of the GDPR. Privacy questions go to the address above and reach the people who can answer them.

2. The Two Roles ioMoVo plays

This is the section to read first, because the answer changes depending on which data you mean.

2.1 We are the controller of our own data

When you browse iomovo.io, ask for a demo, create an account, or contact support, ioMoVo decides why and how that data is handled. We are the data controller for it, and the rest of this policy describes what we do with it.

2.2 We are a processor of your content

When a customer stores assets, documents, recordings, or connected system content in the ioMoVo platform, that content belongs to the customer. Where it contains personal data, the customer is the controller and ioMoVo acts as a processor on their instructions. We do not decide what goes into the platform, how long it stays, or what it is used for.

Our handling of customer content is governed by the customer agreement rather than by this policy. As processor, ioMoVo commits to processing content only on the customer’s documented instructions, keeping it confidential, applying the security measures described in section 8, engaging sub processors only under equivalent obligations and with notice to the customer, assisting the customer in responding to data subject requests, notifying them of a personal data breach without undue delay, and deleting or returning content when the contract ends.

Customers who need these commitments set out in a standalone data processing agreement should contact privacy@iomovo.io.

If you are an individual whose personal data sits inside a customer environment and you want it accessed, corrected, or deleted, contact that organization directly. We will support them in responding, but we cannot act on their content without their instruction.

3. Data We Collect

We do not collect more than we need, and we tell you at the point of collection when something is optional.

Category What it includes Where it comes from
Account and contact data Name, business email, phone number, employer, role, and the credentials used to sign in. You, directly.
Usage data IP address, device and browser characteristics, pages visited, time spent, navigation path, request and response details. Collected automatically.
System logs Records of interaction with the platform kept for operation, troubleshooting, and security. Collected automatically.
Support and sales correspondence Messages you send us and our replies. You, directly.
Connected service data Data drawn from services you choose to connect, such as Google Drive or YouTube. See section 10. You, by authorizing the connection.
Customer content Assets and documents customers place in the platform, which may contain personal data about third parties. Our customers. We act as processor.

Where data is genuinely required to deliver the service, we say so and the service will not work without it. Everything else is optional and declining it costs you nothing.

4. Why We Use it, and on What Legal Basis

Purpose Legal basis
Providing the platform and fulfilling our contract with you Performance of a contract, and pre contractual steps taken at your request
Account security, fraud prevention, and abuse detection Legitimate interests in keeping the service safe
Support and correspondence Performance of a contract, or legitimate interests
Service improvement and diagnostics Legitimate interests, using the least identifying data that works
Analytics and marketing cookies Consent, where consent is required in your jurisdiction
Marketing communications Consent, or legitimate interests where an existing business relationship permits it. You can opt out at any time
Meeting legal, regulatory, and accounting obligations Compliance with a legal obligation
Establishing or defending legal claims Legitimate interests, and compliance with a legal obligation where applicable

If you want to know which basis applies to a particular activity, ask and we will tell you. Where we rely on legitimate interests, we can explain the balancing we carried out.

5. Who We Share Data With

We do not sell personal data for money. We share it only in these situations:

  • Our Own People. Staff involved in operating the service, in administration, sales, support, legal, and system administration, limited to what their role requires.
  • Service Providers Acting on our Instructions. Hosting and infrastructure, website hosting, analytics, customer relationship management, support and messaging tooling, and email delivery. Each is bound by contract to process data only as we direct.
  • Professional Advisers. Auditors, lawyers, and accountants, where they need it.
  • Authorities. Where we are legally required to disclose, or where disclosure is necessary to establish or defend a legal claim.
  • An Acquirer. If the business or part of it changes hands, with notice to you.

A current list of the sub processors used to deliver the platform is available from privacy@iomovo.io. Customers are notified before a new sub processor begins processing their content, and may object under the terms of their agreement.

6. Where Data is Processed, and International transfers

ioMoVo Corp is based in the United States. Depending on where you are, using our website or platform can mean your personal data is transferred to a country other than your own, including to the United States.

For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies. We carry out a transfer risk assessment where one is required, and we apply additional technical measures, including encryption in transit and at rest, to protect data in transit between jurisdictions. You can request a copy of the safeguards that apply to your data from privacy@iomovo.io.

Customers running sovereign, in region, or air gapped deployments can restrict where their content is processed as part of their deployment configuration. Those arrangements sit in the customer agreement and take precedence over the general position described here.

7. How long we keep it

We keep personal data only as long as the purpose it was collected for requires. In practice:

Data Retention
Account and contract data For the life of the contract, then up to seven years to meet tax, accounting, and audit obligations
Marketing and prospect contacts Up to twenty four months after your last engagement with us, or until you unsubscribe
System and security logs Up to twelve months, unless a longer period is needed to investigate a specific incident
Support and sales correspondence Up to twenty four months after the matter is closed
Data held on the basis of consent Until you withdraw consent
Data we are legally obliged to retain For the period the relevant law sets

Customer content follows the retention rules the customer sets in their own environment and in their agreement with us, not this section.

8. Security

We take appropriate technical and organizational measures to protect data against unauthorized access, disclosure, alteration, and loss. These include encryption in transit and at rest, role based access control, least privilege administration, logging of access and administrative actions, and regular review of our controls.

ioMoVo maintains a SOC 2 Type II report and an ISO 27001 certified information security management system. Reports and certificates are available to customers and prospective customers under a non disclosure agreement.

No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs, we will notify the relevant supervisory authority without undue delay and within 72 hours where the GDPR requires it, and we will notify affected individuals where the law requires that too. Where ioMoVo acts as a processor, we notify the affected customer without undue delay so they can meet their own obligations.

9. Your rights

9.1 If you are in the European Economic Area, the United Kingdom, or Switzerland

This section applies under the GDPR and the UK GDPR and, for those users, takes precedence over anything inconsistent elsewhere in this policy.

Right What it means
Withdraw consent Withdraw consent you previously gave, at any time. This does not affect processing already carried out.
Object Object to processing based on legitimate interests or public interest, on grounds relating to your situation. For direct marketing you can object at any time, free of charge, with no reason given, and we will stop.
Access Find out whether we process your data, learn the details, and get a copy.
Rectification Have inaccurate data corrected and incomplete data completed.
Restriction Have processing limited to storage only, in the circumstances the GDPR sets out.
Erasure Have your data deleted where the grounds for erasure apply.
Portability Receive your data in a structured, commonly used, machine readable format and have it sent to another controller where technically feasible.
Complain Lodge a complaint with your supervisory authority, or with the Information Commissioner’s Office in the UK. You can do this without contacting us first, though we would rather have the chance to put it right.

You are also entitled to know the legal basis for any international transfer of your data and the safeguards applied to it. Section 6 sets those out.

9.2 If you are in California, Virginia, or another US state with a comprehensive privacy law

Depending on your state, you have the right to:

  • Know what categories of personal information we collect, the purposes we collect them for, and the categories of third parties we disclose them to.
  • Access a copy of the personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of the sale of personal information, of sharing it for cross context behavioral advertising, and of profiling that produces legal or similarly significant effects.
  • Limit the use and disclosure of sensitive personal information.
  • Appeal a decision if we decline your request. We will respond to an appeal within the period your state law sets, and tell you how to contact your attorney general if you are still unsatisfied.
  • Be free from discrimination for exercising any of these rights. We will not deny service, change pricing, or reduce quality because you asked.

ioMoVo does not sell personal information for money. Our website uses the analytics and marketing technologies described in section 11, and under California law some of that activity may amount to sharing personal information for cross context behavioral advertising. To opt out, write to privacy@iomovo.io and we will suppress it for you, or use your browser’s own cookie and tracking controls. Section 11 explains the consent control we are putting in place and what to do in the meantime.

You may use an authorized agent to submit a request on your behalf. We will ask for written proof of their authority and may ask you to confirm it directly.

9.3 How to exercise any of these rights

Write to privacy@iomovo.io. Requests are free. We will respond within one month, and where a request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month. US state law deadlines are shorter in some cases, and we meet whichever applies to you.

We may need to verify your identity before acting, and we will ask only for what verification requires. If we correct, erase, or restrict your data, we will pass that on to everyone we disclosed it to, unless doing so is impossible or would take disproportionate effort. Ask and we will tell you who those recipients are.

10. Google user data

Where you connect a Google account, ioMoVo requests the scopes below. You grant them during the connection flow and you can revoke them at any time.

Scope What it permits Why ioMoVo needs it
drive.file Create and access only the specific Google Drive files you open with, or create through, ioMoVo. File operations you initiate from inside ioMoVo, including upload, copy, rename, and delete.
userinfo.email View your email address. Identifying your account and securing access.
userinfo.profile View basic profile information such as name and picture. Personalizing your experience in the interface.
youtube Manage your YouTube account, including uploading videos and managing playlists. Publishing and managing video directly from ioMoVo, where you choose to connect YouTube.

We request the narrowest Google Drive scope that supports the features you can see in the product. ioMoVo does not request full Google Drive access, which would allow us to see and change files you have never opened in ioMoVo.

10.1 Limited Use

ioMoVo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means:

  • We use Google user data only to provide and improve the features that are visible and prominent in the ioMoVo interface.
  • We do not transfer Google user data to third parties except where necessary to provide or improve those features, where you give consent, for security purposes, or where the law requires it.
  • We do not use Google user data for advertising of any kind.
  • We do not allow humans to read Google user data, unless you give consent for specific items, it is necessary for security or to resolve abuse, it is required by law, or the data has been aggregated and anonymized for internal operations.
  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
  • We do not create permanent copies of Google user data, and we do not retain cached copies longer than permitted.

10.2 How we protect it

  • Encryption. Data moving between ioMoVo and Google services is encrypted using current standard protocols, and access and refresh tokens are encrypted at rest.
  • Access control. Only authorized users and services inside ioMoVo can reach connected Google data, on a least privilege basis.
  • Minimization. We access only the data an operation needs, and we request only the scopes those operations require.
  • Your control. You can revoke ioMoVo’s access at any time from your Google account settings, and we stop.

11. Cookies and similar technologies

Our website uses cookies and similar technologies in three categories.

Category What it does Consent
Strictly necessary Makes the site work: page delivery, security, load balancing, and remembering your cookie choices. No consent required
Analytics Tells us which pages are used and where people get stuck, so we can improve the site. Delivered through Google Tag Manager and the analytics tools it loads. Consent required in the EEA, the UK, and Switzerland
Marketing Measures the performance of our campaigns and may be used to show you ioMoVo content on other platforms. Consent required in the EEA, the UK, and Switzerland, and treated as sharing under California law

We want to be straightforward about where this stands today. Our analytics and marketing tags are delivered through Google Tag Manager and currently load when you visit the site. We are implementing a consent control that will hold non essential cookies until you agree to them and let you change your choice at any time. Until it is live, you can opt out by writing to privacy@iomovo.io, by using your browser’s cookie and tracking controls, or by installing Google’s analytics opt out browser add on.

When the consent control ships we will update this section and the date at the top of this policy, and we will publish a full list of the individual cookies we set, their providers, and their lifetimes alongside it.

12. Artificial intelligence and machine learning

We do not use personal data, and we do not use customer content, to develop, improve, or train ioMoVo’s own general purpose AI or machine learning models. We do not pass it to third party model providers for their training either.

Where a customer asks us to fine tune a model on their own content, that model and its outputs stay inside that customer’s environment. It is not shared with other customers, not folded into a general model, and not used for any purpose outside that customer’s deployment. Fine tuning happens only where the customer has asked for it in writing.

Customers may choose to route AI processing through a commercial model provider such as Azure OpenAI, or to run open source models inside their own infrastructure. Where a commercial provider is used, that provider’s terms apply to the data sent to it, and we configure those connections so that customer data is not retained for training by the provider.

13. Automated decision making

ioMoVo does not make decisions that produce legal effects, or similarly significant effects, about individuals by automated means alone. The platform’s AI features, including tagging, classification, transcription, and search, produce suggestions and results that people review and act on. A person remains in the decision.

14. Children

ioMoVo is a business platform and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact privacy@iomovo.io and we will delete it.

15. Changes to this policy

We may update this policy. When we do, we will change the Last Updated date above and, where the change is significant, tell you in the platform or by direct notice. Where a change affects processing that rests on your consent, we will ask for consent again where the law requires it. Previous versions are archived and available from privacy@iomovo.io.

16. Definitions

Term Meaning
Personal data Any information that identifies a natural person, or could identify one when combined with other information. Personal information under US state laws means the same thing here.
Usage data Information collected automatically when the service is used, such as IP address, request details, device and browser characteristics, and navigation behavior.
Data subject The person the personal data is about.
Controller The party that decides why and how personal data is processed.
Processor A party that processes personal data on a controller’s instructions.
Sub processor A party a processor engages to help carry out processing.
Customer content Material a customer stores in or connects to the ioMoVo platform.
The platform The ioMoVo software and services, including its modules and capture layer.

17. Contact

Privacy questions and rights requests: privacy@iomovo.io

General: support@iomovo.io, +1 202 239 6247

ioMoVo Corp, 7918 Jones Branch Drive, Suite 400, McLean, VA 22102, USA

This policy is the authoritative statement of how ioMoVo handles personal data and replaces all earlier versions, including any copy hosted elsewhere.