Privacy Policy
Last updated: January 2026
Subsolum (“Subsolum”, “we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website subsolum.com (the “Site”) and when you interact with our landing-page features (such as joining our waitlist or submitting feedback).
1. Who is responsible for your personal information?
Data Controller: [Insert legal entity name]
Address: [Insert postal address]
Privacy contact: privacy@subsolum.com
2. What information we collect
2.1 Information you provide
- Waitlist: name, email address, and (optionally) company and role.
- Feedback: name, email address, and your message/comments.
- Contact: if you email us, we will receive the contents of your email and related metadata.
2.2 Information we collect automatically
When you visit or interact with the Site, we (and our service providers) may automatically collect:
- Device and usage data (e.g., browser type, pages viewed, approximate timing, referrer/landing page).
- Network data (e.g., IP address and general location derived from it).
- Security/anti-abuse signals (e.g., user agent, suspected bot activity, and similar indicators).
2.3 Anti-bot and abuse prevention
To protect the Site and our forms from spam and abuse, we use a combination of a hidden “honeypot” field and Google reCAPTCHA v3. When you submit our forms, reCAPTCHA may assess interaction patterns and provide a risk score. We use this for security and fraud prevention.
2.4 Waitlist country + IP hashing (anti-abuse)
When you join our waitlist, we may capture a country code derived from network/edge headers and we create a hashed form of your IP address (with a regularly rotating salt) to help detect and prevent abusive submissions. We do not store the plain IP address in the waitlist record when this hashing is enabled.
3. How we use your information
- Provide and operate the Site (including enabling you to join the waitlist and submit feedback).
- Communicate with you (e.g., confirmations, responses, and product updates where permitted).
- Improve our Site and services (e.g., understand what content is useful, improve UX, and prioritize product development).
- Security and fraud prevention (e.g., detect bots, prevent duplicate/abusive submissions, and protect our infrastructure).
- Compliance (e.g., meet legal obligations and enforce our terms).
4. Cookies, analytics, and similar technologies
We use cookies and similar technologies for site functionality and (with your consent where required) to measure and improve usage of the Site. For details, see our Cookie Policy.
You can manage your analytics preference at any time via Cookie Preferences.
If your browser has Global Privacy Control (GPC) enabled, we treat it as a request to opt out of non-essential tracking on this Site by default (see our Cookie Policy for details).
5. Legal bases (EEA/UK)
If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under applicable data protection law (including the GDPR and UK GDPR), depending on context:
- Contract / steps prior to entering a contract: to process your waitlist request and provide requested communications.
- Consent: for analytics and similar non-essential technologies where your consent is required, and for marketing communications where applicable.
- Legitimate interests: to secure the Site, prevent abuse, and understand how the Site is used (balanced against your rights).
- Legal obligation: where we must comply with applicable laws.
6. How we share information
We may share personal information with service providers that help us run the Site and operate our business, such as:
- Google (e.g., Google Analytics and reCAPTCHA).
- Amazon Web Services (AWS) (e.g., SES for emails and DynamoDB for waitlist/feedback storage).
- Vercel (Site hosting and delivery).
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising (as those terms are defined under some US privacy laws).
7. International data transfers
Subsolum is based in Australia, and our service providers may process information in Australia, the United States, and other jurisdictions. Where required by law, we use appropriate safeguards for international transfers (such as contractual protections) to help protect your personal information.
8. Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. For example:
- Waitlist: retained until we no longer need it for onboarding/communications, or until you request deletion (subject to legal requirements).
- Hashed IP for anti-abuse: retained for a limited period (typically around 7 days) where used.
- Feedback: retained as needed to respond and improve our product and services.
9. Security
We maintain reasonable technical and organizational measures designed to protect personal information. No method of transmission over the Internet is 100% secure, so we cannot guarantee absolute security.
10. Your choices
- Cookies/analytics: you can choose whether to allow analytics via our cookie preference banner. You can also update your selection at any time via Cookie Preferences, or adjust browser settings to control cookies.
- Email communications: you can unsubscribe from non-essential communications by using an unsubscribe link where provided or by contacting us.
11. Your rights (by region)
11.1 EEA/UK
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction, portability, or to object to processing. Where we rely on consent, you may withdraw your consent at any time (without affecting processing already carried out).
You may also lodge a complaint with your local supervisory authority. In the UK, the supervisory authority is the Information Commissioner’s Office (ICO).
11.2 Australia
You may request access to or correction of personal information we hold about you. If you have a complaint about how we handle personal information, please contact us and we will work with you to resolve it. You may also contact the Office of the Australian Information Commissioner (OAIC).
11.3 United States (including California)
Depending on your state of residence, you may have rights to know/access, delete, correct, or obtain information about our collection and disclosures of personal information. You may exercise applicable rights by contacting us at privacy@subsolum.com.
CCPA/CPRA notice: We collect identifiers (such as name and email), internet or other electronic network activity information (such as browsing/usage data), and security-related signals (such as reCAPTCHA results). We use this information to operate the Site, provide waitlist/feedback features, improve our services, and prevent fraud/abuse. We disclose information to service providers for these purposes. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
12. Children
The Site is not intended for children under 18, and we do not knowingly collect personal information from children.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the “Last updated” date above.