Legal
Privacy Policy
Last updated 21 August 2026
This policy explains what personal data Automentic collects through this website, why we collect it, and what rights you have over it. It covers this website only. Personal data processed inside the Automentic platform on behalf of a customer is governed by that customer’s agreement with us and by our Data Processing Agreement.
1. Who we are
The controller of personal data collected through this website is Metroelectric – Electricians & Engineers Pty Ltd, registered at 26 Saint Georges Terrace, International House, Ground Floor, Perth, WA 6000, Australia, company number ABN:14 674 306 668. You can reach us about privacy at privacy@automentic.com.
Mark Whibley privacy@automentic.com
2. What we collect
Information you give us. When you submit the demo request form we collect your name, work email address, company, job title, company size and anything you write in the message field. We collect this only because you chose to send it.
Information collected automatically. Our hosting and security infrastructure records standard server logs, including IP address, browser user agent, requested URL and timestamp. We hash IP addresses before storing them for abuse prevention, so we do not retain your IP address in readable form for that purpose.
Cookies and similar technologies. See our Cookie Policy for the full list. No analytics or marketing cookies are set before you consent.
We do not knowingly collect special category data, and we do not collect data from children.
3. Why we use it, and our lawful basis
- Responding to your enquiry — to contact you about the demo you requested and to prepare for that conversation. Lawful basis: legitimate interests, and steps taken at your request prior to entering a contract.
- Running and securing the site — to keep the service available, prevent abuse and rate-limit automated submissions. Lawful basis: legitimate interests.
- Measuring how the site performs — only where you have given consent. Lawful basis: consent, which you may withdraw at any time.
- Meeting legal obligations — where we are required to retain records. Lawful basis: legal obligation.
We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.
4. Who we share it with
We share personal data only with service providers who process it on our instructions, under contract, and only to the extent needed to deliver the service. Our current sub-processors are listed on the Sub-processors page.
We may also disclose personal data where required by law, or in connection with a merger or acquisition, in which case we will tell you before your data becomes subject to a different privacy policy.
5. International transfers
We are established in Australia. Personal data collected through this site is stored and accessed in Australia. Some of our service providers process that data in other countries, as listed on our Sub-processors page.
Where a transfer is restricted under the EU GDPR or the UK GDPR — including a transfer from the EEA or the United Kingdom to Australia, which is not the subject of an adequacy decision — we use the European Commission Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum to those Clauses, and we complete a transfer risk assessment before the transfer begins.
Where a provider is certified under the EU–US Data Privacy Framework, we may also rely on that certification for transfers to that provider in the United States. Framework certification is an additional safeguard. It does not replace the Clauses for transfers to Australia.
For transfers from Australia, we take the steps required by Australian Privacy Principle 8 before personal information is disclosed overseas, including a contract that requires the recipient to handle the information in a way that is consistent with the Australian Privacy Principles.
Current destinations for website data are:
- Australia — Automentic, website hosting, and business email (primary storage).
- European Union — analytics, and CRM or support hosting where we have selected an EU region.
- United States — only where a named website provider is established there or provides support from there (for example CDN/WAF or CRM support access), under the Clauses and, where applicable, the Data Privacy Framework.
We do not sell personal data, and we do not transfer it to a third country for advertising.
6. How long we keep it
Demo request records are retained for 24 months from your last interaction with us, then deleted or anonymised. Server logs are retained for 90 days. Where a record must be kept longer to meet a legal or accounting obligation, we retain only what that obligation requires.
7. Your rights
Depending on where you are and which law applies, you may have some or all of the following rights:
- Access — to be told whether we hold personal data about you and to receive a copy.
- Correction — to have inaccurate or incomplete data corrected.
- Erasure — to ask that data be deleted, where the applicable law gives you that right.
- Restriction and objection — to ask us to limit certain processing, or to object to processing based on legitimate interests.
- Portability — to receive data you provided to us in a structured, commonly used format, where the applicable law gives you that right.
- Withdraw consent — where we rely on consent (including analytics cookies), you may withdraw it at any time. Withdrawal does not affect processing already carried out.
These rights are not absolute. We may refuse a request where the law allows, including where we cannot verify your identity or where another legal obligation requires us to keep the data.
To exercise any of these rights, email privacy@automentic.com. We will respond within one month of receiving a valid request.
If you are not satisfied, you may complain to the regulator that applies to you:
- Australia — Office of the Australian Information Commissioner (OAIC), oaic.gov.au.
- United Kingdom — Information Commissioner’s Office (ICO).
- EEA — your national data protection authority.
Automentic is established in Australia. We do not have an establishment in the EEA or the United Kingdom, so there is no lead supervisory authority under the GDPR one-stop-shop. The OAIC is the regulator for our Australian establishment.
8. How we protect it
Access to demo request records is restricted to staff who need it. Data is encrypted in transit. IP addresses used for abuse prevention are stored as keyed hashes rather than in the clear. We review access and retention periodically.
9. Changes to this policy
If we make a material change we will update the date at the top of this page and, where the change significantly affects you, tell you directly. Please check back periodically.
10. Contact
Questions about this policy, or about how we handle your data, go to privacy@automentic.com.
Questions about your data?
Write to privacy@automentic.com and we will respond within one month, as the regulation requires.