Privacy Policy
1. About this policy and who we are
This policy explains how we collect, use, disclose, and protect personal information in connection with the Inerture website at inerture.com (the Site). Inerture (ABN 35 110 646 360) (“we”, “us”, “our”) is a partnership and is the data controller for the personal information described in this policy. You can reach us at contact@inerture.com.
We are based in Australia and handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). If you are in the European Union or the United Kingdom, we act as the data controller for the information described below, and the GDPR / UK GDPR applies to that processing.
This policy covers the public Site only. The Inerture applications (the “App Portal” and design apps) are a separate, invite-only alpha; their data handling is covered by the terms and privacy notice provided when you are invited. See also our Cookie Policy and Terms of Use.
2. What we collect
2.1 Information you give us
- Waitlist details: your email address (required), and optionally your name, company, and role, when you join the waitlist.
- Correspondence: the contents of any message you send us (for example by email).
2.2 Information collected automatically
- Technical data: IP address, browser and device type, operating system, screen size, referrer, language, and time zone.
- Essential function: a single
consentcookie that records your cookie choice.
2.3 Analytics and session recording — only with your consent
If you accept non-essential cookies, we also collect:
- Usage analytics: pages viewed, interactions, and whether you are a returning visitor (via a first-party identifier).
- Session recording (replay): a recording of your interactions with the page (clicks, scrolls, navigation) so we can see how the Site is used and fix problems. Form inputs are masked — we do not capture what you type into fields such as your email or name.
These are off by default and only start if you select “Accept” in the cookie banner. You can change your choice at any time via Cookie settings in the footer.
2.4 Cookieless analytics — always on, cannot identify you
Separately, we measure aggregate traffic using self-hosted Umami: pages viewed, referrer, and an approximate location (country/region derived from your IP address, which is not stored). Umami sets no cookies, stores no identifier, and does not track you across sites — so it runs without requiring consent, on the basis of our legitimate interest in understanding how the Site is used. It cannot identify you.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Contact you about access to the Inerture alpha when places open | Your consent |
| Respond to enquiries you send us | Consent / our legitimate interest in replying |
| Operate, secure, and protect the Site (including spam prevention) | Our legitimate interests |
| Analytics and session recording to understand and improve the Site | Your consent |
| Aggregate, cookieless web analytics (visitor counts, approximate geography) | Our legitimate interests |
| Marketing emails (only if you separately opt in) | Your consent |
| Comply with the law | Legal obligation |
We do not sell personal information, and we do not share it with third parties for their own marketing. Providing your email is required to join the waitlist; the other fields are optional.
4. Who we share it with
We use a small number of service providers (subprocessors), each bound to handle information only on our instructions and to keep it secure:
| Provider | Purpose | Location |
|---|---|---|
| Inerture's own infrastructure | Hosting and storage | Australia |
| Listmonk (self-hosted) | Waitlist and list management | Australia |
| Amazon Web Services (SES) | Email delivery (sending, bounce and complaint handling) | Australia (AWS Sydney region) |
| HyperDX (self-hosted) | Analytics and session recording (consent-gated) | Australia |
| Umami (self-hosted) | Cookieless, aggregate web analytics (no cookies, no profile) | Australia |
| Cloudflare | DNS, content delivery, and security | Global (may process technical data such as IP addresses) |
We may also disclose personal information where required by law, or to a successor entity if Inerture is later incorporated or its business is transferred (the successor will be bound to protections equivalent to this policy).
5. Where it's stored and international transfers
Personal information is held on Australian infrastructure wherever practical. Some providers (for example, a global CDN) may process limited technical data outside Australia. Where information is processed overseas, we take reasonable steps (APP 8) — and, for EU/UK data, rely on an appropriate transfer mechanism such as Standard Contractual Clauses or an adequacy decision — so it receives equivalent protection.
6. How long we keep it
- Waitlist details: until we launch and you have had the chance to take up (or decline) access, or until you ask to be removed — whichever is first.
- Session recordings: a short period for debugging and analysis (no more than 30 days), after which they are deleted or aggregated.
- Server and analytics logs: retained only as long as needed for security and analysis.
7. How we keep it secure
We use HTTPS/TLS for all connections, access controls, and reputable hosting. No system is perfectly secure; if we become aware of a data breach likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme.
8. Your rights
You can ask us to:
- access the personal information we hold about you;
- correct it if it is wrong or out of date;
- delete it (subject to any legal obligation to keep it);
- restrict or object to certain processing;
- receive a copy (portability) of information you gave us; and
- withdraw consent at any time — for analytics/recording via Cookie settings, and for marketing via the unsubscribe link in any marketing email. Withdrawing is as easy as giving consent and does not affect processing already carried out.
To make a request, email contact@inerture.com. We may need to verify your identity first, and we aim to respond within 30 days. If you are unhappy with our response you can complain to the OAIC (oaic.gov.au); if you are in the EU/UK, you may also complain to your local data protection supervisory authority.
9. Children
The Site is not intended for anyone under 18, and we do not knowingly collect their personal information.
10. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows the current version, and material changes will be highlighted on the Site.
11. Contact
Questions about this policy or your personal information: contact@inerture.com.