Skip to content

Legal

Privacy Policy

How Embeint Inc. and Embeint Pty Ltd handle personal information. This policy replaces the Data & Privacy Policy dated 8 April 2024.

Last updated: 18 September 2026

This policy explains how Embeint Inc., a Delaware corporation, 1111B S Governors Ave STE 2039, Dover, Delaware 19904, United States, and Embeint Pty Ltd (ACN 676 233 060), 19 Denali Circuit, Warner QLD 4500, Australia (together “Embeint,” “we,” “us”) collect, use, and share personal information.

Embeint Inc. typically operates embeint.com and related websites and forms (the “Site”). Embeint Pty Ltd may handle personal information in Australia for sales, research programmes, support, and operations. Where the Australian Privacy Act 1988 (Cth) applies, Embeint Pty Ltd is an APP entity for that handling.

Infuse products (including Infuse-IoT, Infuse-DB, Infuse-Analytics, Infuse-SDK, and related hardware or research toolkits) also process customer and device data. That processing is governed by the Master Infuse Services Agreement or other written product terms (the “Infuse Agreement”) as well as this policy. If the Infuse Agreement and this policy conflict on product data, the Infuse Agreement controls for that product.

1. Information we collect

You give us

  • Name, work email, company, role, country, address, and phone, if you choose
  • Account details when you register, including identifiers if you continue with Google or Microsoft, or an email login
  • Messages, quote and estimate requests (including study country and toolkit configuration), accelerator applications, and careers submissions (LinkedIn, GitHub, a short written summary; we do not require a CV file)
  • Optional files where a form allows them
  • Payment details when you buy a paid service. Card and bank numbers are processed by our payment provider. We do not store full primary account numbers on the Site

From devices and Infuse products

  • Data you or your organisation upload or stream: sensor and telemetry data, logs, GPS time and location associated with a device, configuration, and similar operational data
  • Device and fleet metadata needed to operate Infuse (identity, connectivity, software version, update state)

Device and fleet data is typically customer data under the Infuse Agreement. It may include personal information if it relates to an identifiable person (for example an operator identifier). We treat it as personal information where the law requires.

We collect automatically

  • IP address, device and browser type
  • Pages viewed, referring URL, and approximate location derived from IP
  • Cookies and similar identifiers (section 9)
  • Form and checkout progress needed to complete a request

From others

  • Public professional profiles you point us to (LinkedIn, GitHub)
  • Meeting metadata if you book via a scheduling tool
  • Payment-processor confirmation of payment state, not your full card number

Please do not send sensitive information (health, government ID numbers, precise personal geolocation of a person, passwords for other services, or children’s data) through general Site forms unless a form expressly asks for a specific field.

2. How we use information

  • Operate, secure, and improve the Site and Infuse products
  • Create and administer accounts and subscriptions you request
  • Provide support, diagnose faults, and respond to enquiries, quotes, and calls
  • Evaluate accelerator, partnership, and careers applications
  • Send service messages (quotes, receipts, security, product notices)
  • Send product or event updates where you have asked or applicable law allows. You can opt out of marketing
  • Measure Site performance, fix errors, detect abuse, and meet legal obligations
  • Produce aggregated or de-identified insights that do not identify you

We do not sell personal information for money. We do not use Site form vendors to market their own products using your enquiry.

3. United States (including California)

Embeint Inc. handles personal information in the United States. If you are a California resident, you may request access, deletion, and correction, and you may not be discriminated against for exercising CPRA rights.

We do not “sell” or “share” personal information as those terms are used in California law for cross-context behavioural advertising. We use analytics to understand Site use (section 8). We do not use advertising cookies to build profiles for third-party ads.

4. Australia

Where the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles apply, Embeint Pty Ltd handles personal information in line with those Principles: collect only what we need for the functions in this policy, use and disclose it for those purposes or as permitted by law, take reasonable steps to keep it secure, and give access and correction rights (section 10).

If we cannot collect information we need to provide a service, we may be unable to fulfil that request. Complaints may be made to us first, then to the Office of the Australian Information Commissioner (oaic.gov.au).

5. Legal bases (EEA/UK)

Where GDPR or UK GDPR applies, we rely on:

  • Contract — to provide what you asked for
  • Legitimate interests — securing and improving the Site and products, B2B sales to corporate contacts, answering partnership requests
  • Consent — non-essential cookies, some marketing
  • Legal obligation

6. Who we share with

  • Embeint Inc. and Embeint Pty Ltd, so the right team can answer you
  • Service providers on our instructions: hosting and CDN (including Vercel), email (including SendGrid), CRM (including Attio for completed lead actions), scheduling, payments, analytics (including Google Analytics), and error logging
  • Professional advisers and insurers under confidentiality
  • Authorities if required by law or to protect rights, safety, or the Site
  • A buyer or successor in a genuine corporate transaction

Infuse platform hosting may use third-party cloud hosting described in the Infuse Agreement. That is product infrastructure.

7. International transfers

We operate in the United States and Australia. Information may be stored or accessed in those countries and in other countries where our processors run infrastructure. Those laws may differ from yours. Where required, we use appropriate transfer mechanisms (for example contractual clauses). Courts and law-enforcement agencies in those places may be able to access information as local law allows.

8. Retention

  • Enquiries, estimates, and quotes: as long as needed to handle the request and for a reasonable business record period
  • Accounts and billing: for the life of the account and as tax and accounting law require
  • Product and device data: as set in the Infuse Agreement or your configuration, then deleted or de-identified when no longer required
  • Accelerator and careers: for the cycle, then a short archive unless you ask us to delete sooner and we have no legal need to keep a record
  • Server logs: typically a short operational window unless needed for security

We do not keep personal information indefinitely pending an email from you asking us to destroy it. You may still ask us to delete information (section 10). We may keep a record where law requires.

9. Cookies

  • Necessary — load the Site, keep a session, remember dark/light preference
  • Analytics — understand which pages work. We use Google Analytics. We will only set non-essential analytics cookies in the EEA/UK where required consent is obtained

You can control cookies in your browser. Blocking some cookies may break account or checkout flows.

10. Security

We use commercially reasonable organisational, technical, and administrative measures appropriate to the Site and products, including encryption in transit (TLS) for the Site. No method of transmission or storage is completely secure. We cannot guarantee that unauthorised access will never occur.

11. Children

The Site and Infuse products are for business and research users. We do not knowingly collect personal information from children under 16 (or a higher age if local law requires).

12. Your rights

Depending on where you are, you may have rights to access, correct, delete, or restrict personal information, to object to certain processing, to withdraw consent, to portability, and to complain to a regulator.

  • Australia: OAIC — oaic.gov.au. Access and correction are handled under APP 12 and APP 13
  • United States / California: CPRA requests as in section 3
  • EEA: your local supervisory authority
  • UK: Information Commissioner’s Office

Exercise rights via contact or privacy@embeint.com. We will need to verify your request. We may refuse requests that are unfounded, excessive, or that we must keep for law. Where law allows a fee for unfounded or excessive requests, it will be a reasonable amount reflecting our costs.

13. Do not track

The Site does not respond to browser Do Not Track signals.

14. Changes

We will post updates on this page and change the “last updated” date. If we make a material change to how we use personal information we already have, we will take additional steps where law requires (for example a notice or new consent).

15. Contact

Privacy requests: embeint.com/contact or privacy@embeint.com.

Embeint Inc.
1111B S Governors Ave STE 2039
Dover, Delaware 19904, United States

Embeint Pty Ltd (ACN 676 233 060)
19 Denali Circuit
Warner QLD 4500, Australia