Legal

Privacy Policy

Effective date: 30 May 2026  ·  Applies to all factol products and services

Plain-English summary

  • Your factory data is yours. We do not sell it, share it, or use it to serve ads.
  • Each role sees only what they need workers see their tasks, supervisors see their section, owners see everything.
  • All data is encrypted in transit and at rest using 256-bit AES encryption, and stored in India.
  • We may use anonymised, aggregated data (never identifiable) for industry benchmarks — only with your consent.
  • We comply with India's Digital Personal Data Protection (DPDP) Act, 2023.

01Who we are

factol is a mobile-first factory management platform built for small and medium manufacturing businesses (MSMEs) in India. We are operated by the factol team, based in Kerala, India.

This policy explains what personal and operational data we collect when you use the factol app, why we collect it, how we protect it, and what rights you have over it.

02What data we collect

We collect only what is needed to run your factory operations effectively.

CategoryExamplesWhy we need it
Account informationOwner name, phone number, email, factory nameTo create and manage your account
Employee recordsWorker name, photo (optional), section, wage rate, employment statusFor task assignment and attendance tracking
Attendance dataCheck-in / check-out times, shift details, overtime hoursTo calculate labour productivity and costs
Production dataOrders, tasks, quantities completed, section-wise progressTo track production flow and identify delays
Material dataRaw material names, quantities used, wastage recordedFor inventory management and wastage detection
Device informationDevice type, OS version, push notification tokenTo send alerts and enable offline sync
Usage dataApp interactions, feature usage frequencyTo improve the product experience

03How we use your data

We use your data to provide the factol platform, which includes: running production dashboards, calculating labour and material costs, generating shift reports, sending real-time alerts, and delivering AI-powered efficiency insights.

We do not use your data to serve advertisements. We do not sell your data to any third party. We do not profile your workers for purposes outside your factory's operations.

We may use anonymised, aggregated data — where no individual or factory can be identified — to compute industry benchmarks (for example, average wastage rates by sector). This is opt-in and clearly disclosed in the app before enabling.

04Who sees what — role-based access

Access to data is strictly role-based. factol enforces the principle of minimum necessary access. Factory owners control who is added to the workspace and what role they are assigned. factol staff do not access your factory's data except when explicitly requested for technical support.

Feature / dataOwner / AdminSupervisorWorker
Full production dashboardYes
All section dataYesOwn section only
Labour cost reportsYes
AI-powered insightsYes
Employee recordsAll recordsOwn team only
Wastage analyticsYesOwn section only
Assign tasks to workersYesYes
View & update task progressYesYesOwn tasks only
Attendance (check-in / out)All recordsOwn team onlyOwn record only

05How we protect your data

Data security is built into factol's architecture, not added as an afterthought.

Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). This applies to data on our servers and to any data temporarily stored on your device for offline use.
Tenant isolation: Each factory's data is completely isolated. No factory can ever access another factory's records — not through the app, not through our APIs.
Data residency: All data is stored on servers located in India, in compliance with India's DPDP Act, 2023.
Offline sync: When your device is offline, data is held in an encrypted local queue and synced securely when connectivity is restored. No unencrypted data is stored locally.

06Third-party services

factol uses a small number of trusted third-party services to operate the platform. These are limited to infrastructure and delivery — they are not data brokers or advertisers.

ServicePurpose
AWS / Firebase (cloud hosting)Secure server infrastructure and real-time database
FCM / APNs (push notifications)Delivering alerts to Android and iOS devices
WhatsApp Business APISending order and production alerts via WhatsApp (opt-in only)

We do not share identifiable personal data with these services beyond what is technically necessary (for example, a device token to send a push notification).

07Your rights under the DPDP Act, 2023

As a data principal under India's Digital Personal Data Protection Act, 2023, you have the following rights. To exercise any of them, contact us at the address at the end of this document. We do not require a reason for access or erasure requests.

RightWhat it means
Right to accessRequest a copy of all personal data we hold about you or your factory.
Right to correctionRequest that inaccurate or incomplete data is corrected promptly.
Right to erasureRequest deletion of your data when it is no longer needed for the purpose it was collected.
Right to withdraw consentWithdraw consent for optional data uses (such as benchmarking) at any time through app settings.
Right to grievance redressalRaise a complaint directly with us. We will acknowledge within 24 hours and resolve within 48 hours.
Right to data portabilityExport your production and operational data in CSV or PDF format at any time from within the app.

08Data retention and deletion

We retain your data for as long as your account is active. If you cancel your subscription, your data is retained for 90 days to allow data export, after which it is permanently deleted from our servers.

Attendance and production records may be retained for up to 3 years for operational continuity unless you request earlier deletion. Worker personal data (name, phone) is deleted within 30 days of account closure.

09Changes to this policy

If we make material changes to this privacy policy, we will notify you via in-app notification and email at least 14 days before the changes take effect. Continued use of factol after the effective date means you accept the updated policy.

Questions about your data?

Reach out any time — we'll acknowledge grievance requests within 24 hours and resolve them within 48.

WhatsApp us

Note: This is a working draft. Have a legal counsel admitted to practice in India review and finalise this document before publishing — particularly for DPDP Act compliance obligations, consent notice requirements, and grievance officer appointment.