Privacy & Security

Built for trust. Not bolt-on compliance.

Your employee data is sensitive. InnerLoop is designed for the Australian Privacy Act from day one — not retrofitted after the fact.

Australian Privacy Act Compliant
ACSC Essential 8 Aligned
Data Stored in Australia
OAIC-Ready Privacy Policy Included
Australian Privacy Act 2025/2026

Australian Privacy Act 2025/2026 Compliance

The Office of the Australian Information Commissioner (OAIC) has begun active compliance sweeps under the updated Privacy Act. Civil penalties now reach $66,000 per breach for organisations that can\u2019t demonstrate they\u2019ve met their obligations. InnerLoop handles the compliance layer so you don\u2019t have to.

Every applicable Australian Privacy Principle (APP) that touches email communication, tracking, and employee data is addressed below.

APP 1.4 Privacy Policy

A plain-language privacy policy is auto-served to every organisation’s recipients at the point of first email contact. No legal jargon. No buried links.

Consent Records

Every consent event is timestamped and stored. Records are exportable on demand to satisfy any OAIC audit request within minutes.

Right to Deletion

Deletion requests trigger a soft-delete immediately, then permanent hard-delete after a 30-day retention window. Fully auditable trail.

Tracking Disclosure

Every email includes a privacy footer informing recipients of tracking. One-click opt-out is always available and honoured immediately.

Data Breach Notification

A documented 72-hour OAIC notification workflow is in place. Severity tiers, escalation paths, and notification templates are prepared and tested.

Data Retention

Engagement events are auto-purged after 2 years. Personal data is hard-deleted 90 days after an account or recipient is removed.

Cross-Border Transfer

Third-party processors are disclosed explicitly: Anthropic (AI, US), Resend (email delivery, US), Supabase (database, ap-southeast-2), Stripe (billing, US).

Access Rights

Recipients can request an export of all personal data held about them. Requests are fulfilled within 30 days in a portable, readable format.

ACSC Essential 8

ACSC Essential 8 Alignment

The Australian Cyber Security Centre\u2019s Essential 8 is the baseline security framework for Australian organisations. We\u2019ve mapped our controls to these eight mitigation strategies and document them here.

Multi-Factor Authentication

MFA is mandatory for all organisation admins. It cannot be disabled. We enforce this at the authentication layer, not just encouraged in settings.

Restrict Admin Privileges

Row-Level Security (RLS) enforces four distinct roles: super_admin, org_admin, editor, and viewer. No privilege escalation is possible across boundaries.

Patch Applications

Vercel auto-deploys on every merged pull request. Dependabot monitors all dependencies and opens PRs for security patches within 24 hours of disclosure.

Regular Backups

Supabase performs daily automated backups with 30-day point-in-time recovery. Backups are tested quarterly. Recovery procedures are documented.

Application Hardening

CSP headers enforced on all responses. HTTPS-only with HSTS preloading. No inline scripts. Third-party resources locked to explicit allow-lists.

Audit Logging

Every admin action is logged with actor identity, timestamp, IP address, and action type. Logs are immutable and retained for 12 months.

Incident Response

A security events panel in the super-admin dashboard surfaces anomalous activity in real time. Documented runbooks cover the most likely incident types.

Data Handling

How we handle your data

No ambiguity. No buried clauses. Here is exactly what we collect, where it lives, who sees it, and how long we keep it.

What we collect

Email addresses, names, departments, and engagement data: opens, clicks, and read time per block.

Where it’s stored

Supabase PostgreSQL hosted in ap-southeast-2 (Sydney, Australia). Your data never leaves Australian infrastructure.

Who can access it

Only your organisation’s admins and editors, scoped via Row-Level Security. InnerLoop staff cannot read your data without explicit permission.

How long we keep it

Engagement events: 2 years. Personal data: deleted 90 days after a recipient or account is removed.

Third parties

Anthropic (AI content features), Resend (email delivery), Supabase (database), Stripe (billing). All listed in our privacy policy.

We will never sell your data. We will never use your employees' data to train AI models. Third-party processors are contractually bound to use data only for the service they provide. All agreements are available on request.

Our commitments at a glance

Australian Privacy Act Compliant

ACSC Essential 8 Aligned

Data Stored in Australia

OAIC-Ready Privacy Policy Included

Questions about privacy?

We're happy to go deeper.

If you\u2019re evaluating InnerLoop for your organisation and need a Data Processing Agreement, security questionnaire responses, or a conversation with our team, reach out.