Product
Case StudiesHow We WorkCareers
DocsSign inSpeak to an Engineer

PRIVACY

Privacy Policy.

This policy explains what personal data Golain collects, why we hold it, who we share it with and what you can ask us to do about it. It applies to our website, our platform and every part of the company.

EFFECTIVE 26 AUGUST 2026GOLAIN SYSTEMS PRIVATE LIMITEDPUNE · INDIA
01Who we are and what this policy covers02The two roles we play03Personal data we collect04Industrial and operational data05How we use personal data06Cookies, analytics and local storage07Who we share personal data with08International transfers09How long we keep personal data10How we protect personal data11Your rights12Recruitment13Children14Third-party sites15Changes to this policy16Contact us

01Who we are and what this policy covers

Golain Systems Private Limited (“Golain”, “we”, “us”) builds operational intelligence software for manufacturers. We are registered in India with our office in Pune, Maharashtra.

This policy applies across the company. It covers personal data we handle when you:

  • visit golain.io or any Golain subdomain, including our documentation site;
  • contact us, book a call, respond to a survey on our site or ask for a demonstration;
  • use the Golain platform as a named user at a customer or partner organisation;
  • work with us as a customer, supplier, integrator or other business contact;
  • apply to join the team.

It does not cover third-party sites we link to, or a customer’s own privacy practices in the systems they connect to Golain.

02The two roles we play

The obligations we owe you depend on which of two roles we are in, so it is worth separating them before anything else.

As a controller

For our website, our marketing and sales activity, our business relationships and our recruitment, we decide why and how personal data is handled. This policy governs that data.

As a processor

When a customer deploys Golain in their plant, the operational data and the user accounts inside that deployment belong to the customer. We process them on the customer’s documented instructions under the agreement and the data processing terms we sign with them. If you are an operator, technician or engineer using Golain at your employer’s site, your employer is the controller. Send rights requests to them first; we will support them in responding.

03Personal data we collect

Information you give us

  • Name, work email address, phone number, job title and employer, when you contact us, book a call, or submit a survey on our site.
  • What you write to us in an enquiry, a support request or a scheduling note.
  • Account details for named users of the Golain platform, which are typically created or approved by the customer.
  • Applications, CVs and interview notes if you apply for a role.
  • Billing and statutory details for customers and suppliers, including the details we are required to keep for tax and accounting.

Information collected automatically on our website

  • Pages viewed, referring page, approximate location derived from IP address, browser and device type, and interactions such as clicks and scroll depth.
  • A device or session identifier used by our analytics, described in the cookies section below.
  • Standard server and edge logs, including IP address, generated when a page is served or when our security controls act on a request.

Information from other sources

We may receive your business contact details from a colleague at your organisation, from a partner or integrator who introduces us, or from a public professional profile or company website.

04Industrial and operational data

Most of what the Golain platform reads is machine data rather than personal data: controller tags, PLC programs and backups, electrical schematics, machine manuals, fault logs, work orders and process readings. Some of it carries personal data incidentally, usually the name or identifier of the operator, technician or engineer recorded against a shift, an intervention or a work order.

We treat that data as the customer’s. In practice this means:

  • the customer decides what is connected, what is retained and who may see it;
  • we access a customer environment only to deliver, support or secure the service, or where the customer asks us to;
  • deployment options include an isolated environment or an on-premises gateway where operating data must not leave the site;
  • pipeline formats and templates we build may be reused across deployments. Customer knowledge, process data and intellectual property never travel between customers.

We do not sell operational data, and we do not use one customer’s data to serve another customer.

05How we use personal data

  • To respond to you. Answering enquiries, scheduling calls and preparing a scoped proposal.
  • To provide the platform. Creating and administering accounts, supporting users, investigating faults and keeping the service available.
  • To improve the website and the product. Understanding which pages and features are used, and where people get stuck.
  • To run the business. Contracts, invoicing, accounting and statutory records.
  • To keep things secure. Detecting and preventing abuse, fraud and unauthorised access.
  • To hire. Assessing applications and communicating with candidates.
  • To send relevant updates. Occasional email to business contacts about our work, which you can stop at any time.

Our legal basis

Where Indian law applies, we rely on your consent, or on the legitimate uses recognised by the Digital Personal Data Protection Act, 2023, including data you voluntarily give us for a stated purpose and processing required to comply with law.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract, for platform and customer relationships; legitimate interests, for running and securing the business, responding to enquiries and marketing to business contacts, balanced against your rights; legal obligation, for tax and accounting; and consent, where we ask for it, which you may withdraw at any time.

We do not use personal data for automated decisions that produce a legal or similarly significant effect on you.

06Cookies, analytics and local storage

We use PostHog for product and website analytics, on their European Union hosting. It sets a cookie or equivalent identifier so that repeated visits from the same browser can be recognised, records the page activity described above, and powers the short surveys that occasionally appear on the site. Profiles are only created for people who identify themselves, for example by submitting a survey.

We store your light or dark theme choice in your browser’s local storage. It stays on your device and is never sent to us.

We do not run advertising or cross-site tracking cookies on this website. Our web fonts are served from our own domain, so loading a page does not send a request to a font provider.

You can clear or block cookies in your browser settings, and enable Do Not Track or Global Privacy Control, which our analytics respects. Blocking them does not stop the site working.

07Who we share personal data with

We do not sell personal data. We share it only in these situations:

  • Service providers who work for us. Cloud hosting and content delivery, analytics, email and productivity tools, scheduling, accounting and payment processing. They act on our instructions under contract.
  • Your organisation. If you use the platform through your employer or a partner, your account and usage records are visible to their administrators.
  • Professional advisers. Lawyers, auditors and insurers where needed.
  • Authorities. Where we are required to disclose by law, or to establish, exercise or defend legal claims.
  • A successor. If the business or part of it is reorganised, merged or acquired, subject to this policy continuing to apply.

Our website is hosted on Cloudflare’s network, and our website analytics is provided by PostHog in the European Union. We will name the current list of platform subprocessors to any customer on request.

08International transfers

We are based in India and our customers and service providers are in several countries, so personal data may be processed outside the country where you are located.

Where personal data protected by the GDPR or UK GDPR leaves the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses, the UK Addendum where relevant, or an adequacy decision. Where a customer requires operating data to stay inside a country or inside the plant, we deploy so that it does.

09How long we keep personal data

  • Enquiries and sales conversations: up to three years after our last contact, unless you ask us to erase them sooner.
  • Customer and supplier records: for the life of the agreement, then as long as tax and company law requires.
  • Platform data processed for a customer: for the period agreed with that customer, and deleted or returned on termination in line with the agreement.
  • Website analytics: retained by our analytics provider on a rolling basis and not kept indefinitely in identifiable form.
  • Applications: up to one year, unless you ask us to keep them on file for longer.
  • Security and audit logs: up to twelve months.

10How we protect personal data

Golain is ISO/IEC 27001 certified. We operate an information security management system with access control on a need-to-know basis, encryption in transit, segregation between customer environments, logging and review of administrative access, vetting of the providers we use, and a defined process for handling a security incident.

No system is completely secure. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required time.

11Your rights

Depending on where you live, you may have the right to:

  • ask what personal data we hold about you and get a copy;
  • have inaccurate or incomplete data corrected, updated or completed;
  • have your data erased, subject to what we must keep by law;
  • withdraw a consent you gave, without affecting what we did before you withdrew it;
  • object to or restrict processing we base on legitimate interests, including direct marketing;
  • receive your data in a portable format;
  • nominate another person to exercise these rights on your behalf if you die or become incapacitated, under the Indian Act;
  • complain to a supervisory authority, and in India to the Data Protection Board.

Write to privacy@golain.io and we will respond within the period the applicable law allows, and in any case within thirty days. We may need to verify who you are before acting. If the data sits inside a customer deployment, we will pass the request to that customer and support their response.

12Recruitment

If you write to us about a role, we use what you send to assess your application and to talk to you about it. We keep applications for up to a year in case something suitable opens, and you can ask us to delete yours at any time.

13Children

Our website and our product are made for people at work. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

14Third-party sites

Our site links to services we do not run, including our scheduling provider and the sites of customers and partners. Once you follow such a link, that provider’s own privacy policy applies to what you do there.

15Changes to this policy

We update this policy when our practices or the law change. The effective date at the top of the page always reflects the current version. If a change materially affects how we use your personal data, we will tell affected customers and contacts directly.

16Contact us

Our grievance officer under the Digital Personal Data Protection Act, 2023 handles privacy questions, complaints and rights requests, and is the point of contact for data protection matters generally.

  • Email: privacy@golain.io
  • Phone: +91 986 001 9933
  • Post: Golain Systems Private Limited, Pune, Maharashtra, India

If you are not satisfied with our response, you may complain to the Data Protection Board of India or to the supervisory authority where you live or work.

Questions about how we handle data in a specific deployment are usually easier to answer on a call. See how we work or email privacy@golain.io.

GOLAIN

From machine evidence to a verified next step.
Built for manufacturing operations.

EXPLORE

ProductSolutionsIndustriesUse cases

COMPANY

Case studiesHow we workCareersContactPrivacy

ACCESS

DocumentationSign in
© 2026 Golain (Golain Systems Private Limited). All rights reserved.