Privacy Policy
Intero is built on trust, accountability, and respect for the people behind safety data.
Last updated: July 2026
Intero is operated by CloudFinch (“CloudFinch,” “Intero,” “we,” “us,” or “our”), a company incorporated in India, and provides an AI-powered safety intelligence platform for Environmental, Health, and Safety (EHS) teams. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website or use our products and subscriptions (collectively, the “Services”).
This Policy is written with reference to India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), and, for visitors and customers outside India, in a manner consistent with the principles of the EU/UK General Data Protection Regulation (“GDPR”). Where a specific right or obligation applies only under one framework, this Policy says so.
1. Roles under data protection law
- When you use Intero through an employer or organization (a “Customer”), that Customer is the data fiduciary (DPDP Act) or data controller (GDPR) for personal data submitted to the platform, and Intero acts as a data processor on the Customer's behalf and instructions.
- For website visitors and prospective customers, Intero acts as the data fiduciary/controller.
If you use Intero through your employer, questions about your data are usually best directed to your organization first, since they control what is submitted and who can see it.
2. What we collect
2.1 Account data
Name, work email, job title, organization, role/permissions, and authentication details when you or your organization creates an account or subscribes.
2.2 Incident content
The substance of what gets reported and investigated through the platform, which may include:
- Text, voice recordings and transcriptions, photos, and video submitted as incident or hazard reports
- Names, roles, and descriptions of people involved in or witnessing an incident
- Root cause analyses, classifications, and corrective action records
- Location information tied to a reported incident
Incident content is submitted by Customer's Authorized Users at Customer's direction and is subject to Customer's own internal policies.
2.3 Usage telemetry
When you use our website or platform, we automatically collect IP address, device and browser information, pages viewed, features used, log data, and approximate location, via cookies and similar technologies. See Section 6 on cookies and analytics.
3. Why we process it
We process personal data to:
- Provide the Services — receive, analyze, and investigate safety incidents, generate root-cause analyses and corrective action recommendations, and track verification
- Operate accounts — subscriptions, billing, and seat management
- Maintain platform security, auditability, and reliability
- Provide customer support and respond to inquiries
- Improve the Services, including through aggregated or anonymized usage analysis
Incident content and other Customer Data are never used to train general-purpose AI models — ours or any third-party provider's.
Under GDPR/UK GDPR, our legal bases are performance of a contract (providing the Services), legitimate interests (securing and improving the Services), compliance with legal obligations, and consent (for non-essential cookies). Under the DPDP Act, we process personal data on the basis of consent obtained at signup or, where applicable, for legitimate uses permitted by law.
4. Automated processing & AI use
Intero uses AI-assisted processing to support safety investigations, including classification, root-cause drafting, and recommendations. Safeguards include human review before any finding, classification, or corrective action is finalized; customer-controlled workflows and approvals; and no automated decision with legal or similarly significant effect made without human involvement.
5. Who we share data with
We do not sell personal information. We share personal data only with the following categories of recipients:
5.1 Processors / sub-processors
Service providers we use to operate the Services, each bound by a written agreement requiring confidentiality, security, and use limited to providing their service to us:
- AWS — cloud hosting, storage, and database infrastructure
- Anthropic and OpenAI — AI model providers used to generate investigation drafts and recommendations. These providers do not use data sent through our integrations to train their models. They may retain API data briefly for abuse monitoring in accordance with their published API data usage policies
- Stripe — payment processing for subscriptions (Stripe receives billing/payment details directly; we do not store full card numbers)
- Vercel — website and application hosting
- Resend — transactional email delivery (e.g., account, billing, and product notifications)
- Google Analytics — website usage analytics, only if you consent to analytics cookies (see Section 6)
5.2 Customer-directed recipients
Individuals or teams designated by the Customer within their own organization.
5.3 Legal & regulatory authorities
Where required to comply with applicable laws, regulations, or lawful requests.
5.4 Corporate transactions
In connection with a merger, acquisition, corporate reorganization (including a transfer to an affiliated or successor entity, such as our planned US entity), or sale of assets, subject to continued protection of personal data.
6. Cookies & analytics
We use essential cookies to run the website securely. Analytics, marketing, and functional cookies — including Google Analytics — are only set if you consent via our cookie banner or cookie settings, which you can revisit at any time to change your preferences.
7. International data transfers
Our primary infrastructure is hosted on AWS. Some processors listed in Section 5 operate outside India, meaning personal data may be transferred internationally to provide the Services (for example, to AI model providers for processing a request). Where we transfer personal data of EEA/UK individuals outside those regions, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent lawful transfer mechanisms.
8. Data retention
We retain personal data for as long as needed to provide the Services, meet contractual obligations, and comply with legal and regulatory requirements. If a subscription ends, Customer Data remains available for export for 30 days after termination, after which we delete it from active systems except where retention is required by law. Website visitor data (e.g., analytics) is retained only as long as necessary for the purpose collected, consistent with your cookie preferences.
9. Security measures
We implement technical and organizational measures including encryption in transit and at rest, tenant isolation, role-based access controls, and audit logging. Full detail is on our Security page.
10. Your rights
10.1 Deletion & export, for everyone
Regardless of jurisdiction, you can request a copy of your personal data or ask us to delete it by contacting privacy@intero.ai. If you use Intero through an employer, we will generally route deletion or access requests to that organization as the party in control of the account, unless law requires otherwise.
10.2 Rights under the DPDP Act (India)
As a Data Principal, you have the right to obtain a summary of your personal data and processing activities, request correction and completion of your personal data, request erasure of personal data that is no longer necessary for the purpose it was collected, nominate another individual to exercise your rights in the event of death or incapacity, and file a complaint with us and, if unresolved, with the Data Protection Board of India.
10.3 Rights under GDPR / UK GDPR
If you are in the EEA or UK, you may have the right to access your personal data, rectify inaccurate data, request erasure, restrict or object to processing, request data portability, and lodge a complaint with your local supervisory authority.
11. Children's information
The Services are intended for business use by adults and are not directed to individuals under 18. We do not knowingly collect personal information from children.
12. Updates to this policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated “Last updated” date, and where practical, notified to account holders by email.
13. Contact information
CloudFinch (operating Intero)
Privacy inquiries, access, export, and deletion requests: privacy@intero.ai
Questions about your data?
We're committed to transparency. If you have questions about how Intero handles personal data, our team is here to help.
