Privacy Policy
Version 1.0 · Last updated 28 June 2026
Privacy Policy
Last updated: 28 June 2026
Version: 1.0
This Privacy Policy explains how Inferno Analytics LLP, trading as Inferno FMEA (“Inferno”, “Inferno FMEA”, “we”, “us” or “our”), collects, uses, stores, discloses and protects personal information when you access or use our website, application, software platform, AI-assisted FMEA/FMECA tools, reports, exports, documentation, support services, sales channels and related services (together, the “Services”).
Inferno FMEA is a business-to-business software platform that helps reliability, engineering, maintenance, asset management and operational readiness teams prepare, review and export FMEA, FMECA, maintenance strategy and related engineering decision-support outputs.
This Privacy Policy applies to personal information about individuals. It also explains how we handle customer engineering data and customer content that may not be personal information, but may be confidential, commercially sensitive or operationally significant.
This Privacy Policy should be read together with our Terms of Service, Disclaimer, Cookie Policy and any order form, subscription agreement, pilot agreement, data processing agreement or security schedule that applies to your organisation.
1. Who we are
Inferno Analytics LLP
Email: admin@infernofmea.com
Website: https://www.infernofmea.com
Postal address: No. 29, 1st Cross, RRMR Extension, Double Road, Bangalore- 560027 INDIA.
For privacy questions, access or correction requests, deletion requests, security questions, grievances or complaints, contact us at:
Email: admin@infernofmea.com
Subject line: Privacy Request
If required under applicable law, we may appoint and publish details for a Grievance Officer, Data Protection Officer or other privacy contact.
2. Key points
Inferno FMEA is designed for professional and enterprise use.
We collect limited personal information needed to provide, secure, support, improve and administer the Services.
We process customer engineering data, including asset data, FMEA inputs, uploaded files, prompts, draft outputs, review comments and exports, to provide the Services.
Customer engineering data is not always personal information. However, we treat it as confidential customer content.
We do not intentionally collect sensitive personal information, such as health information, biometric information, religious beliefs, political opinions, criminal records or government identifiers.
We do not ask users to upload personal information into FMEA studies unless it is genuinely required for the customer’s lawful business purpose.
We do not sell personal information.
We do not use customer FMEA content, uploaded files, prompts or outputs to train public AI models.
AI-generated outputs are decision-support materials only. Customers and users remain responsible for reviewing, validating and approving all engineering, safety, operational, asset management and maintenance decisions before use.
3. Scope of this Privacy Policy
This Privacy Policy applies when you:
- visit our website;
- create an account;
- log in to the Services;
- use the Inferno FMEA application;
- submit prompts, files, asset data or FMEA content;
- generate, edit, review or export outputs;
- request a demo;
- participate in a pilot or trial;
- contact us for support;
- receive marketing or service communications from us;
- interact with us in relation to the Services.
This Privacy Policy does not apply to third-party websites, tools, platforms or services that we do not control, even if they are linked from the Services.
4. Our role
Inferno FMEA is a business-to-business platform.
Depending on the context, we may act as:
- a data fiduciary, controller or equivalent when we decide why and how personal information is processed, such as for account management, billing, support, security and marketing; or
- a processor, data processor or service provider when we process personal information on behalf of a customer organisation under that customer’s instructions.
If your account is provided by your employer, client, contractor, consultant or another organisation, that organisation may also be responsible for how your personal information and customer content are handled.
5. Types of information we collect
We collect the following categories of information.
5.1 Account and user information
We may collect:
- name;
- work email address;
- phone number, if provided;
- job title;
- organisation name;
- department or business unit;
- user role;
- workspace permissions;
- account status;
- login details;
- authentication information;
- user preferences;
- support history;
- communication history.
We do not intend to store raw passwords. Where password-based authentication is used, credentials are handled using authentication systems and security controls designed to protect them.
5.2 Organisation and subscription information
We may collect:
- organisation name;
- business address;
- billing contact details;
- procurement contact details;
- contract contact details;
- subscription plan;
- licence allocation;
- number of authorised users;
- workspace details;
- pilot or trial details;
- order form details;
- invoice and payment status;
- tax and billing information;
- transaction metadata.
Where payments are processed through third-party payment providers, those providers handle payment card details. We do not intend to store full payment card numbers or card security codes.
5.3 Customer engineering data and customer content
When you use Inferno FMEA, you or your organisation may submit, generate, upload, edit, review, approve or export content such as:
- asset names;
- asset hierarchies;
- asset registers;
- equipment descriptions;
- component lists;
- operating context;
- failure modes;
- failure causes;
- failure effects;
- existing controls;
- recommended controls;
- maintenance strategies;
- inspection and testing tasks;
- risk ratings;
- severity, occurrence and detection ratings;
- likelihood and consequence ratings;
- risk matrices;
- assumptions;
- engineering standards references;
- customer templates;
- SME comments;
- review notes;
- uploaded documents;
- generated FMEA/FMECA tables;
- reports, exports and load sheets;
- prompts, instructions and feedback.
This information is usually business, technical or engineering information. It may not be personal information unless it identifies, or can reasonably identify, an individual.
Even where customer engineering data is not personal information, we treat it as confidential customer content.
5.4 AI inputs and outputs
When you use AI-assisted features, we may process:
- prompts;
- instructions;
- uploaded files;
- selected customer content;
- asset and component context;
- draft FMEA rows;
- study content;
- risk scoring inputs;
- generated outputs;
- user edits;
- review comments;
- approvals;
- feedback on generated outputs.
AI outputs may contain errors, omissions, assumptions, duplications or incomplete reasoning. Inferno FMEA is a decision-support tool. It does not replace professional judgement, site-specific review, statutory obligations, safety obligations, engineering approval or competent person review.
5.5 Usage, device and technical information
We may automatically collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- approximate location derived from IP address;
- pages or features used;
- date and time of access;
- session information;
- audit logs;
- error logs;
- diagnostic logs;
- performance data;
- security logs;
- cookie and analytics data;
- referral source;
- actions taken inside the Services.
We use this information to operate, secure, monitor, troubleshoot, support and improve the Services.
5.6 Sales, marketing and support information
If you contact us, request a demo, join a pilot, submit feedback or communicate with us, we may collect:
- name;
- work contact details;
- organisation details;
- role;
- enquiry details;
- demo request details;
- meeting notes;
- support tickets;
- emails and messages;
- feedback;
- survey responses;
- marketing preferences.
5.7 Cookies and similar technologies
We may use cookies, local storage, pixels, analytics tools and similar technologies to:
- keep users signed in;
- remember preferences;
- secure sessions;
- prevent fraud;
- understand website and product usage;
- measure performance;
- improve the Services;
- support marketing and demo requests.
For more information, see our Cookie Policy.
6. Sensitive personal information
We do not intentionally collect sensitive personal information.
Sensitive personal information may include information about a person’s health, biometric data, genetic information, racial or ethnic origin, religious beliefs, political opinions, union membership, sexual orientation, criminal record, government identifiers or similar information protected by applicable law.
Inferno FMEA is intended for engineering, reliability, maintenance, asset management and operational readiness work. Users should not upload sensitive personal information into the Services unless:
- it is strictly necessary;
- the customer organisation has a lawful basis to provide it;
- the individual has been given any required notice;
- any required consent has been obtained;
- doing so complies with applicable laws and the customer’s internal policies.
If sensitive personal information is uploaded accidentally, contact us so we can assist with deletion or containment where reasonably practicable.
7. How we collect information
We collect information:
- directly from you when you create an account, use the Services, upload content, submit prompts, contact support, request a demo or communicate with us;
- from your organisation when it sets up users, licences, workspaces, permissions or subscriptions;
- automatically through the Services, cookies, logs, analytics and security tools;
- from third-party service providers that help us operate the Services;
- from payment providers, where needed to confirm payment and billing status;
- from publicly available business sources where used for legitimate business development or customer relationship purposes;
- from referrals, events, meetings or professional networks where you or your organisation interact with us.
8. Why we collect and use information
We collect, use and disclose information for the purposes below.
8.1 To provide the Services
We use information to:
- create and manage accounts;
- authenticate users;
- provide access to workspaces and studies;
- generate, edit, store and export FMEA/FMECA outputs;
- process AI-assisted requests;
- enable collaboration and review;
- maintain roles and permissions;
- provide reports and downloadable materials;
- operate pilots, trials and subscriptions;
- provide customer support.
8.2 To support engineering workflows
We use customer content to:
- structure FMEA studies;
- draft failure modes, causes, effects, controls and recommendations;
- support review workflows;
- generate risk ratings and summaries;
- help users align studies with nominated standards or customer methodologies;
- prepare outputs for review, export and implementation.
Inferno FMEA does not approve engineering decisions. Customers and authorised users are responsible for reviewing, validating and approving all outputs.
8.3 To secure and administer the Services
We use information to:
- detect and prevent unauthorised access;
- monitor suspicious activity;
- maintain audit logs;
- investigate errors or incidents;
- enforce our terms and policies;
- protect customers, users and our systems;
- manage backups and service continuity;
- prevent fraud, misuse and abuse.
8.4 To communicate with users and customers
We use information to:
- respond to enquiries;
- provide support;
- send service notices;
- send product updates;
- manage subscriptions and billing;
- notify users about privacy, security or legal matters;
- invite users to provide feedback;
- manage pilots, trials and demonstrations.
8.5 To improve the Services
We may use limited usage, performance, diagnostic and feedback data to:
- improve reliability;
- improve user experience;
- fix bugs;
- improve prompts, workflows and templates;
- develop new features;
- understand which features are useful;
- improve safety, auditability and review workflows.
We do not use customer FMEA content, uploaded files, prompts or outputs to train public AI models.
Where we use customer content to improve customer-specific workflows, templates or configurations, we do so only as permitted by the customer agreement or with the customer’s permission.
8.6 To comply with legal and contractual obligations
We may use and retain information to:
- comply with applicable laws;
- meet tax, accounting, audit and regulatory obligations;
- respond to lawful requests;
- resolve disputes;
- enforce contracts;
- protect legal rights;
- investigate misuse or security incidents.
9. Legal bases and lawful grounds
Depending on the jurisdiction and context, we may rely on one or more lawful grounds to process personal information, including:
- your consent;
- performance of a contract;
- taking steps before entering into a contract;
- legitimate business purposes;
- compliance with legal obligations;
- protection of legal rights;
- customer instructions where we process information on behalf of a customer;
- any other lawful basis available under applicable privacy or data protection law.
Where consent is required, you may withdraw consent as permitted by law. Withdrawal of consent may affect your ability to use some parts of the Services.
10. Customer roles and responsibilities
Where your organisation provides access to the Services, your organisation is usually responsible for determining:
- which users may access the Services;
- what content is uploaded;
- what studies are created;
- what customer engineering data is processed;
- whether personal information is included in customer content;
- what outputs are reviewed, approved or implemented;
- whether use of the Services complies with the organisation’s legal, safety, privacy, procurement and internal policy obligations.
Customers are responsible for ensuring they have provided any required privacy notices and obtained any required consents before uploading personal information into the Services.
Where we process personal information on behalf of a customer, we do so in accordance with the applicable customer agreement, data processing agreement, security schedule or lawful customer instructions.
11. AI processing
Inferno FMEA uses AI-assisted functionality to support engineering, reliability, maintenance strategy and asset management workflows.
AI-assisted features may be used to:
- draft FMEA content;
- suggest component breakdowns;
- suggest failure modes;
- suggest causes and effects;
- suggest controls and maintenance tactics;
- summarise uploaded or entered information;
- help structure outputs;
- support review and quality checks;
- assist with standards-aligned formatting and study structure.
We may send relevant prompts, selected customer content and contextual information to AI service providers to generate outputs. We only send information reasonably required to provide the requested functionality.
We do not authorise AI service providers to use customer FMEA content, uploaded files, prompts or outputs to train public AI models unless expressly agreed in writing with the customer.
AI outputs are not professional advice, engineering certification, safety approval, legal advice, regulatory approval or compliance certification. Users must review and validate outputs before relying on them.
Inferno FMEA is not intended to make automated decisions about individuals that produce legal or similarly significant effects. The Services are designed to assist professional users with engineering decision-support workflows.
12. Automated decision-making
The Services may use AI and automation to generate draft engineering outputs, classifications, summaries and recommendations.
The Services are not intended to make decisions about individuals that significantly affect their rights, interests, employment, access to services, finances, health, legal status or similar matters.
If we introduce functionality that uses personal information to make or materially assist decisions that could significantly affect an individual, we will update this Privacy Policy and provide any required notices under applicable law.
13. When we disclose information
We may disclose personal information and customer content in the following circumstances.
13.1 To service providers and subprocessors
We may disclose information to trusted third parties that help us operate, host, secure, support, analyse, improve or administer the Services.
These may include providers for:
- cloud hosting;
- database services;
- authentication;
- AI processing;
- file storage;
- payments;
- analytics;
- logging;
- email delivery;
- customer support;
- security monitoring;
- professional advice.
We require service providers to handle information only for authorised purposes and to apply appropriate confidentiality, security and data protection measures.
13.2 To the customer organisation
If your account is provided by your employer, client, contractor, consultant or another organisation, we may disclose account, usage, audit, support and workspace information to authorised administrators of that organisation.
For example, a customer administrator may be able to see:
- users in the workspace;
- study names;
- user roles;
- access permissions;
- usage activity;
- support issues;
- generated or uploaded customer content within that workspace.
13.3 For legal, safety and security reasons
We may disclose information where reasonably necessary to:
- comply with applicable law;
- respond to a lawful request;
- enforce our terms;
- protect rights, property or safety;
- investigate suspected misuse;
- prevent fraud, security incidents or unauthorised access;
- respond to privacy, security or legal complaints.
13.4 Business transfers
If we are involved in a merger, acquisition, financing, restructure, sale of assets, investment, insolvency event or similar transaction, information may be disclosed as part of due diligence or transferred as part of that transaction, subject to appropriate confidentiality arrangements.
13.5 With consent or instructions
We may disclose information where you or your organisation instructs us to do so or gives consent.
14. Subprocessors and service providers
We use third-party providers to operate the Services. Before publishing this Privacy Policy, we will maintain a current list of actual service providers and subprocessors.
The following table describes the categories of providers we may use.
Provider category | Purpose | Information processed |
|---|---|---|
Cloud hosting provider | Hosting the website and application | Technical data, logs, application data |
Database and storage provider | Storing account data, workspace data and customer content | Account data, customer content, logs |
Authentication provider | User login and account security | Identity, login and authentication data |
AI service provider | AI-assisted drafting, summarisation and analysis | Prompts, selected customer content, outputs |
Payment provider | Billing and payment processing | Billing details, transaction metadata |
Email provider | Service emails and support communications | Contact details, email content |
Analytics provider | Usage analytics and product improvement | Usage data, event data, device data |
Security and logging provider | Monitoring, diagnostics and security | Technical data, logs, audit events |
Professional advisers | Legal, accounting, audit and compliance support | Information relevant to the advice |
Current providers may include: [Insert current provider list, for example Vercel, Supabase, OpenAI API, Stripe, XFlow, email provider, analytics provider and security/logging provider, only if actually used].
We will update this Privacy Policy or a linked subprocessor list when our provider list materially changes.
15. Overseas disclosure and international processing
We are located in India and may provide Services to customers in Australia and other countries.
We may disclose or make personal information accessible to recipients located outside your country.
For users in Australia, overseas recipients may be located in:
- India;
- Australia;
- United States;
- Singapore;
- European Union;
- United Kingdom;
- other countries where our service providers, cloud providers, payment providers, AI providers or support providers operate.
Where we disclose personal information overseas, we take reasonable steps to use appropriate contractual, technical and organisational protections, unless an exception applies.
Unless expressly agreed in writing, we do not guarantee that all personal information or customer content will remain in a single country.
16. Data hosting and storage
Customer data may be stored in cloud infrastructure operated by our hosting, database, storage, AI and service providers.
We aim to configure hosting and storage in regions appropriate for our customer base and contractual commitments.
Where a customer requires specific data residency, hosting region, access control, security or subprocessor commitments, those commitments must be documented in the relevant order form, data processing agreement or security schedule.
17. Security
We take reasonable technical, organisational and administrative measures designed to protect personal information and customer content against misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.
These measures may include:
- encryption in transit;
- encryption at rest where supported by our providers;
- role-based access controls;
- authentication controls;
- least privilege access;
- row-level security where applicable;
- audit logging;
- administrative access restrictions;
- secure development practices;
- vulnerability monitoring;
- environment separation;
- backups;
- incident response processes;
- confidentiality obligations for staff and contractors;
- review of service provider security practices.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect information using measures appropriate to the nature of the Services and the information we process.
18. Data breaches and security incidents
If we become aware of a security incident involving personal information or customer content, we will take reasonable steps to investigate, contain, assess and remediate the incident.
Where required by applicable law, customer agreement or data processing agreement, we will notify affected customers, users, regulators or other required parties.
For Australian personal information covered by the Privacy Act 1988, we will assess whether the incident is an eligible data breach and, where required, notify affected individuals and the Office of the Australian Information Commissioner.
For Indian digital personal data covered by the Digital Personal Data Protection Act, 2023 and applicable rules, we will comply with applicable breach notification, reporting and remediation obligations.
19. Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law, contract, tax, audit, accounting, dispute resolution, security or legitimate business requirements.
Typical retention periods are:
Information type | Typical retention approach |
|---|---|
Account information | Retained while the account is active and for a reasonable period afterwards |
Customer content and FMEA studies | Retained during the subscription, pilot or contract term, unless deleted earlier by authorised users or agreed otherwise |
AI prompts and outputs | Retained as part of the relevant workspace, study, logs or support records, unless deleted or agreed otherwise |
Backups | Retained for a limited backup cycle before being overwritten or deleted |
Billing and transaction records | Retained as required for tax, accounting, audit and legal purposes |
Support communications | Retained for support history, quality, dispute resolution and legal purposes |
Security logs | Retained for security, fraud prevention, audit and incident investigation purposes |
Marketing information | Retained until you unsubscribe or request deletion, unless retention is otherwise permitted |
Customers may request deletion or export of customer content in accordance with the applicable agreement and available product functionality.
Deletion from active systems may not immediately remove information from backups, logs or archived systems. Backup deletion occurs through ordinary backup lifecycle processes unless otherwise agreed.
20. Your privacy rights
Depending on where you are located and which laws apply, you may have rights to:
- request access to personal information we hold about you;
- request information about how your personal information has been processed;
- request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading personal information;
- request erasure or deletion of personal information;
- withdraw consent where processing is based on consent;
- object to or restrict certain processing, where applicable;
- opt out of marketing communications;
- nominate another person to exercise certain rights after death or incapacity, where applicable;
- complain about how we handle personal information;
- request information about overseas disclosures or service providers.
To make a request, contact us at infernosolution50@gmail.com.
We may need to verify your identity before responding.
If your account is managed by a customer organisation, we may refer your request to that organisation or work with that organisation to respond.
We will respond within the timeframe required by applicable law. If no specific timeframe applies, we will aim to respond within a reasonable period.
21. Access, correction and deletion
You may request access to personal information we hold about you.
You may also request that we correct personal information if it is inaccurate, out of date, incomplete, irrelevant or misleading.
You may request deletion of personal information where permitted by law and where retention is not required for legal, contractual, security, tax, audit, dispute resolution or legitimate business purposes.
We may refuse access, correction or deletion where permitted by law, such as where providing access would compromise another person’s privacy, reveal confidential commercial information, prejudice security, breach legal privilege, interfere with an investigation or be otherwise unlawful.
If we refuse a request, we will explain the reason where reasonably practicable and legally permitted.
22. Grievances and complaints
If you have a privacy grievance or complaint, contact us first at:
Email: admin@infernofmea.com
Subject line: Privacy Complaint
Please include enough information for us to understand and investigate your complaint.
We will acknowledge and respond to your complaint within a reasonable period and within any timeframe required by applicable law.
If you are in India and are not satisfied with our response, you may have the right to approach the Data Protection Board of India or another competent authority, once applicable procedures are available.
If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
If you are in another jurisdiction, you may have the right to contact your local privacy, data protection or consumer authority.
23. Marketing communications
We may send business, product or marketing communications to users and business contacts where permitted by law.
You can opt out of marketing emails by using the unsubscribe link in the email or contacting us.
Even if you opt out of marketing, we may still send non-marketing communications, such as service notices, security updates, billing notices, legal notices and support communications.
24. Cookies and analytics
We may use cookies and analytics technologies to operate, secure, measure and improve the Services.
Some cookies are necessary for the Services to function. Others help us understand how users interact with the website or application.
You can control some cookies through your browser settings. Blocking cookies may affect how the Services function.
For more details, see our Cookie Policy.
25. Children and minors
The Services are intended for professional and business users.
We do not knowingly provide the Services directly to children or minors. Users must be at least 18 years old or otherwise authorised by their organisation and applicable law to use the Services.
If we become aware that we have collected personal information from a child without appropriate authority, we will take reasonable steps to delete it.
26. Customer content and confidentiality
Customer content remains the responsibility of the customer organisation.
As between Inferno and the customer, ownership of customer content is addressed in the applicable customer agreement. Unless otherwise agreed, customers retain ownership of their customer content.
We use customer content to provide, secure, support and improve the Services as described in this Privacy Policy and the applicable customer agreement.
We do not sell customer content.
We do not publish customer content without permission.
We do not use customer content to build a competing customer-facing dataset for another customer.
We do not use one customer’s identifiable confidential engineering content to provide another customer with that content.
27. De-identified and aggregated information
We may create de-identified or aggregated information from usage data, diagnostic data, support data or customer interactions.
Where information has been properly de-identified so that individuals are not reasonably identifiable, it may no longer be personal information.
We may use de-identified or aggregated information to:
- understand product usage;
- improve performance;
- develop features;
- prepare internal analytics;
- improve reliability;
- improve security;
- communicate general product insights.
We will not intentionally use de-identified or aggregated information to re-identify individuals.
28. Third-party websites and services
The Services may contain links to third-party websites, services, documentation or resources.
We are not responsible for the privacy practices, security or content of third-party websites or services. You should review the privacy policies of any third-party services you use.
29. Professional and engineering responsibility
Inferno FMEA processes information to support engineering, reliability, maintenance strategy and asset management workflows.
The Services may generate draft outputs, suggestions, classifications, risk ratings, maintenance tactics or recommendations. These outputs are not final engineering advice, legal advice, safety advice, compliance certification or asset-owner approval.
Users and customer organisations are responsible for:
- checking the accuracy and completeness of inputs;
- reviewing AI-generated outputs;
- validating outputs against site conditions;
- applying competent engineering judgement;
- complying with applicable laws, standards and internal procedures;
- obtaining required approvals before implementation;
- maintaining final records and audit trails.
This section is included because some customer content may relate to high-risk, safety-critical or operationally significant assets. It does not reduce our privacy commitments, but it clarifies the role of the Services.
30. Cross-border customers
If you access the Services from outside India, you acknowledge that your information may be processed in India and other countries where we or our service providers operate.
Privacy laws may differ between countries. We take reasonable steps to protect information in accordance with this Privacy Policy, applicable customer agreements and applicable law.
If your organisation requires specific cross-border transfer terms, these should be documented in a data processing agreement, order form or security schedule.
31. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we make changes, we will update the “Last updated” date at the top of this Privacy Policy.
If changes are material, we may provide additional notice, such as by email, in-app notice or website notice.
Your continued use of the Services after the updated Privacy Policy takes effect means you acknowledge the updated Privacy Policy.
32. Contact us
For privacy questions, requests, grievances or complaints, contact:
Inferno Analytics LLP
Email: admin@infernofmea.com
Website: https://www.infernofmea.com
Postal address: No. 29, 1st Cross, RRMR Extension, Double Road, Bangalore- 560027 INDIA.
Please use the subject line Privacy Request or Privacy Complaint so we can route your message appropriately.