Skip to content

Privacy Policy

Last updated: June 17, 2026

Download PDF

1. Introduction and Scope

FactoryNerve (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our Software-as-a-Service (SaaS) platform.

This policy applies to all users of the FactoryNerve platform, including company administrators, factory supervisors, shift in-charges, and any employees whose data may be processed through our systems. By accessing or using FactoryNerve, you acknowledge that you have read and understood this policy.

FactoryNerve provides operational data management for manufacturing facilities, including attendance tracking, production reporting, inventory management, OCR document processing, invoicing, and employee records. This policy covers all data processed in connection with these services.

2. Data Controller Information

Data Controller: FactoryNerve Technologies Pvt. Ltd.

Registered Address: 4th Floor, Tech Tower, Industrial District, Shillong, Meghalaya 793001, India

Contact Email: legal.factorynerve.online@redvortexorg.me

Data Protection Officer (DPO): dpo@factorynerve.online

For customers established in the European Union, our representative can be reached at dpo@factorynerve.online for all GDPR-related inquiries.

3. Information We Collect

We collect and process the following categories of data to provide and improve our services. The specific data collected depends on how you use the platform and which features you enable.

3.1 Account Information

When a company registers for FactoryNerve, we collect company name, administrator name, work email address, phone number, billing address, and payment information. This data is necessary to create and maintain your account, process subscriptions, and provide customer support.

3.2 Employee Data

For workforce management features, we process employee names, employee identification numbers, attendance records (check-in/check-out times), shift assignments, department or line assignments, leave records, and supervisory notes. This data is provided to us by the employer (who acts as the data controller for this information) and processed solely on their behalf.

3.3 Operational Data

This includes production metrics (daily production reports, shift-wise output, machine-wise production), inventory records (stock levels, material receipts, dispatches), OCR-scanned documents (handwritten register pages, delivery challans, weighbridge tickets, invoices), quality control data, and dispatch logs. This data constitutes the core operational records managed through the platform.

3.4 Usage Data

We automatically collect login times, feature usage patterns, page interactions, time spent on different sections, search queries within the platform, and IP addresses. This data helps us understand how the platform is used and identify areas for improvement.

3.5 Technical Data

We collect browser type and version, device type and operating system, session tokens for authentication, cookies and similar tracking technologies (as described in our Cookie Policy), and log data including access times and error reports.

5. How We Use Your Information

5.1 Service Delivery

We use your data to provide, maintain, and operate the FactoryNerve platform. This includes processing daily production reports, managing attendance records, generating invoices, processing OCR-scanned documents, tracking inventory movements, and enabling approvals workflows. All operational data is processed in real time to support factory operations.

5.2 Analytics and Improvement

Aggregated and anonymized usage data helps us understand platform performance, identify bottlenecks, and develop new features. We analyze feature adoption patterns to improve user experience. Individual operational records are never used for analytics in identifiable form.

5.3 Customer Support

Account and technical data are used to respond to support tickets, troubleshoot issues, provide onboarding assistance, and communicate service updates or changes to terms.

5.4 Security Monitoring

We monitor login patterns, access logs, and API usage to detect unauthorized access attempts, potential breaches, and anomalous activity. This is essential for protecting both our platform and your data.

6. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes described in this policy, or as required by applicable law. The retention periods vary by data category:

Data CategoryRetention PeriodRationale
Account InformationDuration of account + 6 yearsContractual and legal (tax) obligations
Employee RecordsDuration of employment relationship + 3 yearsEmployer compliance and dispute resolution
Attendance Data3 years from date of recordWage calculation and labor law compliance
Production / Operational Data5 years from date of recordBusiness record keeping and audit trail
OCR-Scanned Documents5 years from date of scanAudit trail and quality verification
Invoices & Billing Records7 years (or as required by local tax law)Statutory tax and accounting requirements
Usage Data (logs, telemetry)12 monthsPlatform improvement and security analysis
Session Tokens / CookiesSession duration or 6 months (persistent)Authentication and user experience

Upon expiration of the applicable retention period, data is securely deleted or anonymized. You may request earlier deletion of your data subject to our legal obligations to retain certain records.

7. Sharing and Third Parties

We do not sell your personal data to third parties. We share data only with trusted service providers who help us deliver the platform, and only under strict data processing agreements.

Third PartyServiceData SharedLocation
AWS (Amazon Web Services)Cloud hosting and infrastructureAll platform data (encrypted)India (ap-south-1)
ResendEmail delivery (notifications, invoices)Email addresses, recipient namesUS / EU
PostHogProduct analytics and feature usageAnonymized usage data, page viewsUS / EU
SentryError monitoring and crash reportingError logs, browser/device infoUS / EU
Stripe / RazorpayPayment processing (subscriptions)Billing info, payment amountUS / India

We require all third-party service providers to implement appropriate technical and organizational measures to protect your data. We may also disclose data when required by law, court order, or governmental regulation.

8. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. We respond to all requests in accordance with applicable data protection laws.

8.1 Right of Access

You have the right to obtain confirmation of whether we process your personal data and, if so, to request a copy of that data along with information about how it is processed.

8.2 Right to Rectification

You may request correction of inaccurate or incomplete personal data. Account administrators can update most information directly through the platform settings.

8.3 Right to Deletion (“Right to be Forgotten”)

You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent on which processing is based. This is subject to our legal retention obligations.

8.4 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.

8.5 Right to Restrict Processing

You may request restriction of processing where you contest the accuracy of the data, where processing is unlawful, or where you have objected to processing pending verification of our legitimate grounds.

8.6 Right to Object

You have the right to object to processing based on legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests or where processing is necessary for legal claims.

How to Exercise Your Rights: To exercise any of these rights, please submit a request to legal.factorynerve.online@redvortexorg.me or write to our DPO at dpo@factorynerve.online. We will respond within 30 days of receiving a verifiable request. Where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act.

9. International Data Transfers

Your personal data may be transferred to and processed in countries other than your own. When we transfer personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been deemed adequate by the European Commission, we rely on appropriate safeguards.

Safeguards we use include:

  • Standard Contractual Clauses (SCCs): We execute SCCs approved by the European Commission with all third-party service providers that process data outside the EEA.
  • Data Processing Agreements (DPAs): We maintain DPAs with all sub-processors that include the required transfer safeguards.
  • AWS India Region: Primary data hosting is in Mumbai, India (ap-south-1), which provides a data residency option for Indian and Asian customers.

By using FactoryNerve, you consent to the transfer of your data to our servers in India and to the third parties listed in Section 7, subject to the safeguards described above.

10. Security Measures

We implement robust technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

10.1 Technical Measures

  • Data encryption at rest using AES-256 and in transit using TLS 1.3
  • Multi-factor authentication (MFA) for all admin accounts
  • Role-based access control (RBAC) that restricts data access by user role
  • Automated session timeouts and IP-based access restrictions
  • Regular vulnerability scanning and penetration testing
  • 24/7 automated security monitoring and anomaly detection

10.2 Organizational Measures

  • Strict access controls on a need-to-know basis for all employees
  • Regular data protection training for all team members
  • Annual third-party security audits (SOC 2 Type II)
  • Incident response plan with 24-hour breach notification commitment
  • Data processing agreements with all sub-processors

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify affected parties and relevant supervisory authorities within 72 hours as required by applicable law.

11. Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will notify you through the platform and, where appropriate, via email.

We encourage you to review this policy periodically. The “Last updated” date at the top of this page indicates when the policy was last revised. Continued use of FactoryNerve after changes take effect constitutes your acceptance of the updated policy.

Significant changes include, but are not limited to: new data collection practices, changes in how we use data, new third-party processors, or changes to your rights under this policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email (Privacy Inquiries): legal.factorynerve.online@redvortexorg.me

Data Protection Officer: dpo@factorynerve.online

Postal Address: FactoryNerve Technologies Pvt. Ltd., 4th Floor, Tech Tower, Industrial District, Shillong, Meghalaya 793001, India

Response Time: We aim to respond to all inquiries within 10 business days.

For EU residents: You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.

© 2026 FactoryNerve Technologies Pvt. Ltd. All rights reserved.

Return to FactoryNerve