PRIVACY
This policy explains what personal data Golain collects, why we hold it, who we share it with and what you can ask us to do about it. It applies to our website, our platform and every part of the company.
Golain Systems Private Limited (“Golain”, “we”, “us”) builds operational intelligence software for manufacturers. We are registered in India with our office in Pune, Maharashtra.
This policy applies across the company. It covers personal data we handle when you:
It does not cover third-party sites we link to, or a customer’s own privacy practices in the systems they connect to Golain.
The obligations we owe you depend on which of two roles we are in, so it is worth separating them before anything else.
For our website, our marketing and sales activity, our business relationships and our recruitment, we decide why and how personal data is handled. This policy governs that data.
When a customer deploys Golain in their plant, the operational data and the user accounts inside that deployment belong to the customer. We process them on the customer’s documented instructions under the agreement and the data processing terms we sign with them. If you are an operator, technician or engineer using Golain at your employer’s site, your employer is the controller. Send rights requests to them first; we will support them in responding.
We may receive your business contact details from a colleague at your organisation, from a partner or integrator who introduces us, or from a public professional profile or company website.
Most of what the Golain platform reads is machine data rather than personal data: controller tags, PLC programs and backups, electrical schematics, machine manuals, fault logs, work orders and process readings. Some of it carries personal data incidentally, usually the name or identifier of the operator, technician or engineer recorded against a shift, an intervention or a work order.
We treat that data as the customer’s. In practice this means:
We do not sell operational data, and we do not use one customer’s data to serve another customer.
Where Indian law applies, we rely on your consent, or on the legitimate uses recognised by the Digital Personal Data Protection Act, 2023, including data you voluntarily give us for a stated purpose and processing required to comply with law.
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for platform and customer relationships; legitimate interests, for running and securing the business, responding to enquiries and marketing to business contacts, balanced against your rights; legal obligation, for tax and accounting; and consent, where we ask for it, which you may withdraw at any time.
We do not use personal data for automated decisions that produce a legal or similarly significant effect on you.
We use PostHog for product and website analytics, on their European Union hosting. It sets a cookie or equivalent identifier so that repeated visits from the same browser can be recognised, records the page activity described above, and powers the short surveys that occasionally appear on the site. Profiles are only created for people who identify themselves, for example by submitting a survey.
We store your light or dark theme choice in your browser’s local storage. It stays on your device and is never sent to us.
We do not run advertising or cross-site tracking cookies on this website. Our web fonts are served from our own domain, so loading a page does not send a request to a font provider.
You can clear or block cookies in your browser settings, and enable Do Not Track or Global Privacy Control, which our analytics respects. Blocking them does not stop the site working.
We do not sell personal data. We share it only in these situations:
Our website is hosted on Cloudflare’s network, and our website analytics is provided by PostHog in the European Union. We will name the current list of platform subprocessors to any customer on request.
We are based in India and our customers and service providers are in several countries, so personal data may be processed outside the country where you are located.
Where personal data protected by the GDPR or UK GDPR leaves the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum where relevant, or an adequacy decision. Where a customer requires operating data to stay inside a country or inside the plant, we deploy so that it does.
Golain is ISO/IEC 27001 certified. We operate an information security management system with access control on a need-to-know basis, encryption in transit, segregation between customer environments, logging and review of administrative access, vetting of the providers we use, and a defined process for handling a security incident.
No system is completely secure. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required time.
Depending on where you live, you may have the right to:
Write to privacy@golain.io and we will respond within the period the applicable law allows, and in any case within thirty days. We may need to verify who you are before acting. If the data sits inside a customer deployment, we will pass the request to that customer and support their response.
If you write to us about a role, we use what you send to assess your application and to talk to you about it. We keep applications for up to a year in case something suitable opens, and you can ask us to delete yours at any time.
Our website and our product are made for people at work. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
Our site links to services we do not run, including our scheduling provider and the sites of customers and partners. Once you follow such a link, that provider’s own privacy policy applies to what you do there.
We update this policy when our practices or the law change. The effective date at the top of the page always reflects the current version. If a change materially affects how we use your personal data, we will tell affected customers and contacts directly.
Our grievance officer under the Digital Personal Data Protection Act, 2023 handles privacy questions, complaints and rights requests, and is the point of contact for data protection matters generally.
If you are not satisfied with our response, you may complain to the Data Protection Board of India or to the supervisory authority where you live or work.
Questions about how we handle data in a specific deployment are usually easier to answer on a call. See how we work or email privacy@golain.io.