IsoBuilder Privacy Notice / Privacy Policy

Effective date: 1 July 2026

This notice explains how IsoBuilder handles personal information when we operate our public website, respond to enquiries, manage Trust Center access requests, and support customer portal or product-related interactions.

It applies when IsoBuilder handles personal information as the business or controller. Customer product data is mainly handled for customers under the relevant service relationship and customer instructions.

IsoBuilder is operated by IsoBuilder Trading Pty Ltd (ABN 47 678 710 355).

Contents

  1. Scope
  2. Personal information we collect
  3. Sources
  4. How we use information
  5. Disclosures
  6. Cookies and telemetry
  7. Security and retention
  8. Children
  9. External links
  10. Australian privacy rights
  11. International users
  12. Contact

1. Scope

This notice covers personal information connected with IsoBuilder's public website, marketing pages, contact and demo enquiries, Trust Center access requests, customer portal sign-in paths, support workflows, and related business communications.

IsoBuilder customers may use the product to manage site, project, drawing, isolation, support, and user-access information. Where that information is handled for a customer, IsoBuilder generally acts as a service provider or processor under the customer relationship.

This notice does not cover employment, contractor, or recruitment information.

2. Personal information we collect

Category Examples Typical context
Contact and enquiry details Name, work email, company, role or team, message content, consent to contact, and any phone number or other details you choose to provide. Contact forms, demo requests, direct business communications, and follow-up conversations.
Demo request details Country, number of employees, referral source, workflow interests, and other context submitted through a Get Started form. Product walkthrough, sales, implementation, and procurement discussions.
Trust Center request details Business email, company, requested Trust Center materials, access reason, terms acceptance, and request status. Security, compliance, procurement, partner, or customer due-diligence review.
Customer portal, support, and account details Microsoft Entra account identifiers, tenant or domain information, roles, access groups, support messages, operational contact details, and audit or access logs. Customer portal sign-in, staff support, product access, support requests, and customer administration.
Product and service content handled for customers User names, email addresses, site or project references, workflow activity, support records, and product records submitted or configured by a customer. IsoBuilder SaaS use under the applicable customer service relationship.
Technical and usage information IP address, browser and device information, page path, referrer or campaign parameters, approximate location, telemetry events, and diagnostic logs. Website operation, marketing analytics, Application Insights telemetry, security monitoring, troubleshooting, and service reliability.

IsoBuilder does not intentionally collect sensitive personal information through public enquiry, demo, partner, or Trust Center forms. Please do not send sensitive personal information through those public forms unless it is necessary for your request. Customer product, support, safety, or incident records may contain sensitive information where a customer or user provides it for an operational workflow.

3. Sources

4. How we use information

Purpose Examples
Responding to enquiries Answering questions, arranging demos, preparing implementation discussions, and following up on product interest.
Managing Trust Center access Reviewing requests, confirming business purpose, providing approved materials, applying access limits, and keeping request records.
Operating customer portal and support workflows Authenticating users, authorising access, resolving support requests, managing customer administration, and maintaining audit trails.
Hosting and securing IsoBuilder Running the service on Microsoft Azure, monitoring availability, investigating errors, protecting accounts, and responding to security events.
Improving website and marketing performance Using Application Insights telemetry to understand page views, campaign engagement, form success events, referrer trends, and public-site performance.
Business, legal, and compliance administration Maintaining records, enforcing agreements, handling disputes, meeting legal obligations, and supporting audits or corporate transactions.

5. Disclosures

IsoBuilder does not sell personal information for money. We may disclose personal information where reasonably necessary for the purposes described in this notice, including to:

6. Cookies and telemetry

IsoBuilder uses cookies, local storage, session storage, and similar browser technologies for necessary website operation. Analytics storage is optional. We do not load the browser Application Insights analytics SDK or set analytics storage unless you opt in.

You can change your analytics choice at any time using the Cookie preferences control in the interactive Privacy Notice or footer. Necessary storage remains active because it supports security, sign-in, Trust Center access, and remembering your preference.

Category Cookie or storage Purpose When used
Necessary ib_cookie_consent_v1 local storage Stores your cookie and analytics preference using version, necessary, analytics, decided, and updated fields. Created when you accept, reject, or save preferences.
Necessary IsoBuilder.TrustAccessSession secure HttpOnly cookie Maintains a short-lived Trust Center access session after verification so controlled documents can be delivered securely. Created only during verified Trust Center access flows.
Necessary ib-hub-service-worker-cleanup-reloaded session storage Prevents reload loops while the site removes old offline service-worker caches. Used only during service-worker cleanup and removed afterwards.
Necessary Microsoft Entra and MSAL browser authentication storage Supports customer portal and staff sign-in, authentication callbacks, access tokens, and protected API requests. Used when you sign in or access protected areas.
Analytics Application Insights cookies and browser storage such as ai_user, ai_session, ai_authUser, and ai_* Sends page views, engagement events, scroll milestones, contact or portal click events, UTM campaign parameters, referrer host, page path, and page title. Used only after analytics opt-in and only when browser telemetry is enabled for the site.
Analytics ib_marketing_internal_traffic local storage Marks browsers that visit staff routes so future marketing analytics can separate internal traffic from public visitor activity. Used only after analytics opt-in when staff-area traffic is detected.

The telemetry script avoids collecting form message content. Browser controls may let you block or clear cookies and local storage, but doing so can affect some site functions.

7. Security and retention

IsoBuilder uses Microsoft Azure hosting, Microsoft Entra authentication, role-based access controls, TLS for data in transit, and Azure-managed platform controls to help protect information. Production access is limited to personnel who need it for support and operations.

We keep personal information for as long as it is reasonably needed for the purpose collected, for customer service delivery, for security and audit records, to meet legal or accounting obligations, or to resolve disputes. Retention periods can differ by record type, customer agreement, operational need, backup schedule, and legal requirement. For example, enquiry, demo, partner, Trust Center, customer account, support, access, audit, diagnostic, and backup records may each have different retention settings. Where personal information is no longer needed and we are not required to keep it, we will take reasonable steps to destroy or de-identify it.

8. Children

IsoBuilder is designed for business and industrial operations. It is not directed to children, and we do not knowingly collect personal information from children through the public website.

IsoBuilder pages may link to external websites, partner resources, customer systems, or third-party services. Those services are controlled by their own operators and privacy notices.

10. Australian privacy rights

If Australian privacy laws apply, you may ask us to access or correct personal information we hold about you, or to make a privacy complaint. Please include enough detail for us to identify the relevant records and respond to your request. We may need information to verify your identity before responding. Some requests may depend on the customer relationship or legal exceptions.

If your request relates to product data controlled by an IsoBuilder customer, we may direct you to that customer or coordinate with them where appropriate.

We will respond to access and correction requests within a reasonable period. If we refuse access or correction where permitted by law, we will explain why unless it would be unreasonable to do so, and explain available complaint mechanisms.

We will acknowledge privacy complaints and investigate them within a reasonable time. We may contact you for more information, confirm the outcome in writing, and explain any steps we will take. If you are not satisfied with our response, or we do not respond within a reasonable time, you may contact the Office of the Australian Information Commissioner.

11. International users

IsoBuilder is operated from Australia and uses Microsoft Azure resources. Product and support data may be hosted in Australia or another supported region selected during customer onboarding. Personal information may be processed in other locations where our service providers, support processes, or customer relationships require it.

IsoBuilder may disclose personal information to overseas recipients where service providers, support providers, customer administrators, implementation partners, or business systems are located outside Australia. Where it is not practicable to specify each country, we identify the relevant service-provider or customer context and can assess specific requests in context.

If you interact with IsoBuilder from outside Australia, your local laws may provide additional rights. Contact us through the path below and we will assess the request in context.

12. Contact

For privacy questions, access or correction requests, and privacy complaints, contact our Privacy Officer at privacy@isobuilder.com.au. Please include enough detail for us to identify the relevant records and respond to your request. You can also contact Jack Dunlop, Principal Software Engineer, at jack@isobuilder.com.au. Existing customers can use their normal customer portal or support path where the request relates to a customer account or product record.

Security vulnerabilities and security incident reports should be sent to security@isobuilder.com.au. Please do not use that address for general privacy or sales enquiries.