Privacy Notice
Last updated: 08.01.2026 · Effective date: 08.01.2026
1. Introduction
Inertia Systems Inc. (“Inertia,” “we,” “us,” or “our”) takes the protection of your personal information seriously. This Privacy Notice explains what personal information we collect, how we use and disclose it, how we protect it, how long we retain it, and what privacy rights may be available to you under applicable privacy and data protection laws.
This Notice applies to our websites, applications, software-as-a-service solution, APIs, support services, sales and marketing activities, events, integrations, and related services, including products and features marketed under our trademarks Blade™, Nexus™, and Live Drawings™, and related Inertia offerings (collectively, the “Services”).
This Notice is intended to supplement, not replace, written agreements between Inertia and its customers as respects personal information.
2. What This Notice Does Not Cover
Customer Solution Data
Customers and authorized project participants may upload, submit, connect, generate, or store information in the Services, including drawings, models, specifications, RFIs, submittals, forms, inspections, checklists, photos, videos, comments, markups, schedules, locations, closeout records, project metadata, and related construction project information (“Customer Content”). Customer Content may contain personal information and, to the extent that it does contain personal information, our use of that personal information is subject to this Notice.
In those cases, the customer is deemed the controller for purposes of applicable data privacy laws, and Inertia acts as a processor under the customer’s instructions. If you have a direct relationship with one of our customers, you should contact that customer if you have questions regarding your privacy rights relating to personal information contained in any Customer Content.
Human Resources Data
This Notice does not apply to personal information processed in the employment, recruiting, contractor, officer, or director context.
Deidentified or Aggregated Data
This Notice does not apply to information that does not identify, relate to, describe, or reasonably link to a particular individual or household. We may use deidentified or aggregated information for lawful business purposes, including analytics, security, benchmarking, service improvement, and product development, subject to customer agreements and applicable law.
3. Our Role With Respect to Personal Information
Inertia may act in different roles depending on our relationship with you. For website visitors, business contacts, prospects, event attendees, account administrators, and direct communications with Inertia, we may act as a controller with respect to your personal information. For personal information included in Customer Content processed through the Services, we generally act as a processor on behalf of the customer.
When we act as a processor, we process personal information only as instructed by the customer, as necessary to provide the Services, as permitted by the applicable agreement, or as required by law.
4. Personal Information We Process
The personal information we process depends on how you interact with Inertia and the Services. The information we collect is sorted by the categories below; to the extent that this information contains personal information, its processing is subject to the terms of this Notice.
| Category | Examples |
|---|---|
| Identity and contact information | Name, business email, company, title or role, phone number, mailing address, username, account name, and similar identifiers. |
| Account and authentication information | Account status, login credentials or authentication method, user role, permissions, session information, and access history. |
| Device and technical information | IP address, browser type, device type, operating system, device identifiers, referring pages, timestamps, error logs, security logs, and rough location derived from IP address. |
| Usage and product information | Pages or screens viewed, features used, workflow activity, form activity, clicks, preferences, performance data, telemetry, adoption metrics, and troubleshooting information. |
| Customer Content | Drawings, models, specifications, RFIs, submittals, forms, inspections, photos, videos, logs, comments, markups, schedules, locations, closeout records, metadata, and other project information. |
| Support and communications information | Support tickets, emails, chat messages, implementation notes, training records, meeting notes, feedback, survey responses, and customer success records. |
| Sales and marketing information | Demo requests, event attendance, CRM records, communication preferences, marketing engagement, lead source, and business development notes. |
| Integration information | Data imported from or exported to connected systems authorized by a customer or user, such as Procore, Autodesk Construction Cloud, Oracle Aconex, Primavera P6, Dropbox, Egnyte, Tekla, Revit, IFC tools, Revizto, or similar solutions. |
| AI-derived or system-generated information | Document classifications, extracted fields, linked records, confidence scores, recommendations, summaries, structured metadata, review queues, and approval or correction feedback. |
5. Sources of Personal Information
- Directly from you when you create an account, use the Services, submit a form, request support, request a demo, attend an event, or communicate with us.
- From customers, customer administrators, project sponsors, general contractors, owners, trade partners, consultants, or other organizations that invite you to use the Services.
- From Customer Content uploaded, connected, or generated by customers and authorized users.
- From third-party integrations authorized by customers or users.
- From service providers, advertising partners, analytics tools, CRM systems, event organizers, and professional or publicly available business sources.
6. Cookies and Similar Technologies
We may use cookies, pixels, local storage, device identifiers, and similar technologies to operate our websites and Services, authenticate users, maintain sessions, remember settings, measure performance, analyze usage, improve our Services, and support marketing or advertising where enabled.
| Technology Type | Purpose |
|---|---|
| Session cookies | Temporary cookies used during a browser session, such as for authentication, navigation, and security. |
| Persistent cookies | Cookies that remain after a browser session for a defined period, such as to remember preferences or measure returning website activity. |
| First-party cookies | Cookies placed directly by Inertia to operate, secure, analyze, and improve our websites and Services. |
| Third-party cookies and pixels | Technologies placed by providers such as analytics, advertising, or social media partners, where enabled, to measure campaigns or support relevant advertising. |
Users can manage cookies through browser settings and, where available, our cookie preference tool. If you reject certain cookies, some website or Service features may not function properly.
7. Purposes for Processing Personal Information
We may process personal information for the following purposes:
- To provide, operate, maintain, host, secure, and improve the Services.
- To create and manage accounts, authenticate users, administer permissions, and support project workflows.
- To process Customer Content, run workflows, generate project records, support collaboration, and enable product features.
- To provide customer support, troubleshoot issues, respond to requests, conduct training, and communicate about account or service matters.
- To monitor Services performance, debug errors, maintain Services availability, detect fraud, prevent abuse, and protect against unauthorized access or security threats.
- To analyze usage, improve usability, develop features, measure adoption, and understand how our customers use the Services.
- To conduct sales, marketing, demos, events, customer relationship management, and business communications.
- To comply with legal obligations, enforce agreements, manage disputes, support audits, and protect the rights, safety, property, and integrity of our Services and of Inertia, users, customers, and the public.
- To facilitate mergers, acquisitions, financing, restructuring, due diligence, asset sales, bankruptcy proceedings, or similar corporate transactions involving Inertia.
8. Lawful Bases for Processing
Additional Information for Individuals in the EEA and United Kingdom
If you are located in the European Economic Area (“EEA”) or the United Kingdom, our processing of your personal information may be governed by the General Data Protection Regulation (“GDPR”) or the UK General Data Protection Regulation (“UK GDPR”), as applicable. When Inertia acts as a controller, we process personal information only when we have a valid legal basis, as described below. When Inertia acts as a processor on behalf of a customer, that customer determines the purposes and legal bases for processing, and Inertia processes the information according to the customer’s instructions and the applicable agreement.
Where applicable data privacy laws require a lawful basis for processing, we may process personal information based on one or more of the following grounds:
| Lawful Basis | Examples |
|---|---|
| Contract | To provide the Services, administer accounts, support users, and perform customer agreements. |
| Legitimate interests | To secure and improve the Services, prevent fraud, conduct business communications, develop products, and manage customer relationships, after considering individual rights and interests. |
| Consent | To use certain cookies, send certain marketing communications, process certain sensitive data, or conduct other activities where consent is required. |
| Legal obligation | To comply with applicable laws, legal process, regulatory obligations, audits, and recordkeeping requirements. |
| Customer instructions | When Inertia acts as processor or service provider for Customer Content under a written agreement. |
Where we rely on consent, you may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal or processing based on another lawful basis.
9. Artificial Intelligence and Automated Processing
Inertia may use artificial intelligence, machine learning, optical recognition, classification, extraction, recommendation, summarization, and related technologies to help customers manage construction project information. These technologies may assist with drawings, models, specifications, RFIs, submittals, forms, inspections, checklists, schedules, photos, logs, locations, closeout records, and other project documents.
AI-assisted features are intended to help humans review, organize, classify, extract, link, and summarize information. No final project, legal, safety, payment, compliance, or employment decision should be made solely by Inertia AI output. Users and customers are responsible for reviewing AI-assisted output before relying on it.
Any personal information processed by AI features is generally incidental to the project records being processed. The primary purpose is to understand construction project information, project relationships, workflow status, document requirements, and related metadata.
Unless otherwise stated in a written agreement or authorized by the customer, Inertia does not use Customer Content to train generalized third-party AI models. Inertia may use deidentified, aggregated, or system telemetry data to maintain, secure, evaluate, and improve the Services, where permitted by applicable law and customer agreements.
10. How Long We Retain Personal Information
We retain personal information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, support audits, and operate our business. Retention periods vary based on data type, customer agreement, product configuration, account status, legal requirements, and backup or disaster recovery processes.
Customer Content is generally retained according to the applicable customer agreement, project settings, deletion instructions, and backup schedules.
Deleted information may remain in backups or archived systems for a limited period until overwritten or deleted according to backup retention procedures. If restored from backup, deleted information will remain subject to the original deletion or restriction instruction where technically feasible and legally required.
11. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients:
- Inertia personnel, contractors, and affiliates who need access to operate, secure, support, improve, sell, or administer the Services.
- Service providers and subprocessors that provide hosting, storage, analytics, monitoring, security, authentication, email, CRM, support, AI, professional services, and other business or technical services.
- Customers, customer administrators, project owners, and authorized users according to project permissions, account settings, workflows, and customer agreements.
- Third-party integrations when a customer or authorized user enables an integration or directs data transfer.
- Professional advisors, auditors, insurers, lawyers, accountants, and compliance reviewers.
- Government authorities, regulators, courts, law enforcement, or other parties where required by applicable law or where reasonably necessary to protect rights, safety, property, users, customers, the Services, Inertia, or the public.
- Transaction participants in connection with a merger, acquisition, financing, restructuring, bankruptcy, due diligence process, asset sale, or similar business transaction involving Inertia.
We do not rent, share or sell your personal information.
12. International Transfers
Inertia is based in the United States. Personal information may be processed in the United States and other countries where Inertia, its affiliates, service providers, subprocessors, or integration partners operate. These countries may have data protection laws different from those in your location.
Where EU, UK, Swiss, Canadian, or other international data protection laws apply, Inertia uses a legally recognized transfer mechanism where required. These mechanisms may include an applicable adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another approved safeguard. Where we rely on a specific certification framework, we will do so only while our certification remains valid and applicable to the relevant transfer.
13. Your Privacy Rights
Depending on where you live and how you interact with Inertia, you may have some or all of the following rights. Some rights may apply only when Inertia acts as a controller. If your request relates to personal information contained in Customer Content controlled by an Inertia customer, we may direct you to that customer or assist the customer in responding.
You may have the right to receive information about how we collect, use, disclose, retain, and protect your personal information. This Notice is intended to provide that information.
You may have the right to confirm whether we process personal information about you and to receive a copy of certain personal information and related processing details.
You may have the right to ask us to correct inaccurate personal information, taking into account the nature of the information and the purposes of processing.
You may have the right to ask us to delete personal information, subject to exceptions for security, legal compliance, contract performance, dispute resolution, backup retention, and other permitted purposes.
You may have the right to ask us to restrict certain processing or object to processing based on legitimate interests or direct marketing.
You may have the right to receive certain personal information in a structured, commonly used, and machine-readable format.
You may have the right to opt out of targeted advertising, sale or sharing of personal information, or certain profiling, where applicable.
Where applicable, you may have rights related to decisions based solely on automated processing that produce legal or similarly significant effects. Inertia’s AI features are intended to support human review and users should not make final decisions without human evaluation.
Where we rely on consent, you may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal.
We will not discriminate against you for exercising privacy rights, except where permitted by law or where a request limits our ability to provide a requested service.
14. How to Exercise Your Privacy Rights
To submit a privacy request, you may contact us using one of the following methods:
- Email: privacy@inertiasystems.com
- Website: www.inertiablade.ai
- Mail: Inertia Systems Inc, 11000 Equity Drive, Houston, Texas 77041
We may need to verify your identity or authority before responding. For requests submitted through a password-protected account, we may treat account authentication as verification. For other requests, we may verify through reasonable and proportionate measures such as email confirmation, account details, phone confirmation, signed authorization, or other information appropriate to the request.
If you submit a request on behalf of another person, we may require proof of your authority, such as signed permission, a valid power of attorney, or direct confirmation from the person whose information is involved.
We will respond to privacy requests within the time period required by applicable law. If we deny a request, we will explain the basis for denial where required and provide appeal instructions where applicable.
We generally do not charge a fee for privacy requests. We may charge a reasonable fee or decline to act where permitted by law if a request is excessive, repetitive, unfounded, or manifestly abusive.
15. State-Specific Rights
Texas Residents
Texas residents may have rights under the Texas Data Privacy and Security Act, including rights to confirm processing, access personal data, correct inaccuracies, delete personal data, obtain a portable copy, opt out of targeted advertising, sale of personal data, or certain profiling, and appeal denied requests. Texas law also requires clear privacy notice disclosures, request methods, appeal rights, reasonable security practices, and data processing contracts where the law applies.
California Residents
California residents may have rights under the California Consumer Privacy Act, as amended, including rights to know/access, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and not be discriminated against for exercising rights.
Other U.S. State Residents
Residents of other U.S. states may have additional privacy rights under applicable state privacy laws. Inertia will respond to requests as required by applicable law and may provide supplemental notices as legal requirements evolve.
16. Privacy of Children
The Services are intended for business and construction project use and are not directed to children under 13. We do not knowingly collect personal information from children under 13 through the Services. If we learn that we have collected personal information from a child under 13 without required consent, we will take appropriate steps to delete it or handle it as required by law.
17. Data Integrity and Security
We use administrative, technical, physical, and organizational safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, exfiltration, theft, or destruction. These safeguards may include role-based access controls, encryption in transit, encryption at rest where applicable, logging, monitoring, vulnerability management, vendor review, confidentiality obligations, and incident response processes.
No method of transmission or storage is completely secure. Customers and users are responsible for maintaining appropriate credentials, access controls, project permissions, device security, and internal procedures.
18. Complaints and Supervisory Authorities
If the GDPR, UK GDPR, or another applicable international data protection law applies to our processing of your personal information, you may have the right to lodge a complaint with the data protection authority in the country where you live, where you work, or where you believe a violation occurred.
Individuals in the EEA can locate their applicable supervisory authority through the European Data Protection Board. Individuals in the United Kingdom may contact the UK Information Commissioner’s Office.
We encourage you to contact us first at privacy@inertiasystems.com so that we have an opportunity to address your concern directly.
19. Changes to This Notice
We may update this Notice from time to time. The updated version will be posted with a revised “Last updated” date. If we make material changes, we will provide notice as required by law, which may include notice through the Services, email, or another reasonable method.
20. Contact Us
For privacy questions or requests, contact:
21. Relationship to Customer Agreements
Other written agreements may supplement this Notice. To the extent there is a conflict between the terms of this Notice and the terms of a written agreement with a customer regarding Customer Content or customer-controlled data, the terms of the written agreement will govern to the extent permitted by law. Nothing in this Notice limits rights that cannot be waived under applicable privacy laws.
