Skip to content
Legal

Privacy Policy

How Cloudfinch collects, uses and protects personal data when you visit the Rampart website, contact us or use the Rampart platform.

Last updated · Issued by Cloudfinch Information Technologies Pvt. Ltd.

1. About this policy

This policy explains how Cloudfinch Information Technologies Pvt. Ltd. (“Cloudfinch”, “we”, “us” or “our”), the company behind Rampart, collects, uses, shares and protects personal data. It also explains the rights you have over that data. Personal data means any information about a person who can be identified from it.

This policy applies when you:

  • visit this website, rampart.ai;
  • contact us, book a demo, or otherwise deal with us as a customer, prospective customer or partner;
  • use the Rampart platform as a user at one of our customers.

We have written this policy to meet the requirements of India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it, and of the Information Technology Act, 2000 and its rules. If you are in the European Union or the United Kingdom, please also read People in the EU and UK. Our Terms & Conditions set out the rules for using this website.

2. Our role

Website, enquiries and business contacts. We collect personal data through this website, and from you as a customer contact, prospective customer or partner. For this data, we decide why and how it is used. Under the DPDP Act we are its data fiduciary; under the GDPR, its controller.

Data in the Rampart platform. Our customers use Rampart to record incidents, audits, inspections, training, environmental data and other records. These can include personal data about their employees, contractors and visitors. For that data, the customer is the data fiduciary and decides how it is used. We are their data processor: we process it only on their behalf, on their instructions and under our agreement with them. If an organisation you work with holds your data in Rampart, please contact that organisation about it, and we will help them respond to you.

Platform accounts and usage. When you use the Rampart platform, we collect your account, activity and security data, as described in Personal data we collect. We process it on our customer’s behalf to provide the service. We also use it for our own limited purposes: to keep the platform secure, to send service messages and to understand, in aggregate, how the platform is used. For those purposes we are its data fiduciary, and you can contact us about it directly.

3. Personal data we collect

When you contact us. When you send the contact form on this website, we receive your name, work email, company, the topic you chose and your message, and your mobile number if you give it. An email service provider delivers the form to our inbox. If you email or call us directly, we receive what you send us.

When you book a demo. Demo bookings are made through a scheduling page that HubSpot hosts. We receive the details you enter there, such as your name, email address and company, along with the time you choose.

Partners. If you take part in our partner programme, we collect your contact and business details, and details of the referrals and sales you make.

When you visit this website. Like most websites, the servers that host this website automatically log technical data about each visit. This includes your IP address, your browser and device type, the pages you request, the page you came from, and the date and time. We use this data to run and secure the website.

Visitor statistics. We use Vercel Web Analytics to count visits and page views on this website. It does not set cookies or store your IP address. For each page view it records the page, the page you came from, your approximate location (country, region and city), your browser, operating system and device type, and the date and time. To tell one visit from another, it uses a code made from your request, which it discards after 24 hours. We see these figures only as totals, such as how many people viewed a page, not who you are.

When you use the Rampart platform. Your organisation gives us your account details, or you enter them yourself. These include your name, work email, phone number, job role, and your sites and business units. As you use the platform, we record activity and security data. This includes sign-in times, the actions you take, and your IP address, browser and device. The platform’s audit trail time-stamps every report, edit, approval and attachment. If you contact our support team, we keep a record of the request.

Content in the Rampart platform. This is whatever your organisation records in Rampart, such as incident reports, audit findings, photos and training records. As explained in Our role, we handle it on our customer’s behalf.

Please do not send us sensitive personal data, such as health or financial information, through the contact form or by email unless we ask for it.

4. How we use personal data

We use personal data to:

  • answer your enquiries, and arrange and hold demos;
  • manage our relationships with customers and partners, including contracts and invoicing;
  • provide, maintain and support the Rampart platform, including signing you in, with single sign-on if your organisation uses it;
  • keep the website and the platform secure, and prevent and investigate misuse;
  • send service messages, such as notices about maintenance, security or changes to the platform;
  • understand how the platform is used, in aggregate, so that we can improve it;
  • meet our legal obligations, and establish, exercise or defend legal claims.

We process personal data with your consent, or for a legitimate use that the law allows. Examples are when you give us your data voluntarily for a specific purpose, such as to answer your enquiry, and when we need it to meet a legal obligation. Where we rely on consent, you can withdraw it at any time, as easily as you gave it. Withdrawing consent does not affect processing that took place before you withdrew it.

If you agree, we may send you news about Rampart, such as product updates and events. Every one of these emails includes a way to unsubscribe.

We do not sell personal data. We use the content in your organisation’s Rampart account only to provide the service to your organisation, as our agreement with it allows.

5. Cookies

Cookies are small files that a website stores in your browser.

This website does not use analytics or advertising cookies, and we do not track you across other websites. The visitor statistics described in Personal data we collect work without cookies.

Other websites that this website links to set their own cookies under their own policies. Examples are HubSpot’s demo booking page and social networks.

The Rampart platform uses cookies and similar browser storage to sign you in and keep your session secure. These are essential to the service and cannot be switched off.

If we add non-essential cookies to this website, we will update this policy first, and we will ask for your consent where the law requires it.

6. Who we share personal data with

We share personal data only with:

  • Service providers that work for us, such as website hosting and visitor statistics (Vercel), cloud hosting, email, scheduling (HubSpot) and support tools. They may use the data only to provide their services to us, under contracts that require them to protect it.
  • Your organisation. If you use the Rampart platform, your organisation’s administrators, and others it authorises, can see your account details, your activity and the records you create. What they can see depends on the access your organisation sets up.
  • Professional advisers, such as lawyers, auditors and insurers, where they need it to advise us.
  • Authorities, such as regulators, courts and law enforcement agencies. We share data with them where the law requires us to, or to protect the rights, property or safety of Cloudfinch, our customers or others.
  • A buyer or successor, if all or part of our business is merged, sold or restructured. Your personal data will stay subject to the protections in this policy.

7. Where personal data is stored

Data in the Rampart platform is hosted in the region agreed with each customer, which can be data centres in India.

Our service providers may process data from this website and from enquiries outside India. For example, Vercel, which hosts this website and provides its visitor statistics, and HubSpot, which runs our demo booking page, may process data in the United States. Where we transfer personal data outside India, we do so as the DPDP Act allows, and we take steps to keep it protected.

8. How we protect personal data

We use technical and organisational measures to protect personal data against unauthorised access, loss, misuse and alteration. In the Rampart platform, these include encryption of data, access controls, single sign-on with your identity provider, and an audit trail of every change. We limit our staff’s access to personal data to those who need it for their work.

No method of sending or storing data is completely secure, so we cannot guarantee absolute security. If a personal data breach occurs, we will act promptly to contain it. We will notify the people affected, our customers and the Data Protection Board of India as the law requires.

9. How long we keep personal data

We keep personal data only for as long as we need it for the purposes in this policy, or for longer where the law requires. For example, we keep:

  • enquiries and demo bookings, for as long as we are in touch with you about Rampart and for a reasonable period afterwards;
  • customer and partner records, for the length of the relationship and then for as long as tax, accounting and other laws require;
  • logs, for the period the law requires;
  • data in the Rampart platform, for as long as our customer’s agreement provides. When the agreement ends, the data is returned or deleted as the agreement sets out.

When we no longer need personal data, we delete it or make it anonymous.

10. Your rights

Under the DPDP Act, you have the right to:

  • get a summary of the personal data we hold about you, how we use it, and who we have shared it with;
  • have inaccurate or incomplete data corrected, completed or updated;
  • have your data erased when it is no longer needed, unless the law requires us to keep it;
  • withdraw any consent you have given us, at any time;
  • have your grievances about how we handle your data addressed;
  • nominate someone to exercise these rights for you if you die or become unable to exercise them.

To exercise any of these rights, email our Grievance Officer (see Contact us) with “Privacy request” in the subject line. We may need to confirm your identity before we act on your request. We will respond within the time the law requires.

If an organisation you work with holds your data in the Rampart platform, please send your request to that organisation, because it decides how that data is used. We will help it respond.

If we have not resolved your grievance, you may complain to the Data Protection Board of India.

11. People in the EU and UK

If you are in the European Union or the United Kingdom, the General Data Protection Regulation (GDPR) or the UK GDPR may also apply to how we handle your personal data.

We rely on these legal bases:

  • performing a contract with you or your organisation, or taking steps at your request before entering into one;
  • our legitimate interests in answering enquiries, running and securing our website and platform, and growing our business, where your rights do not override those interests;
  • your consent, for example for marketing emails;
  • complying with our legal obligations.

You have the right to:

  • access, correct or erase your personal data;
  • restrict or object to our processing of it;
  • data portability;
  • withdraw consent at any time.

To exercise these rights, contact us as described in Contact us. You also have the right to complain to the data protection authority in the country where you live or work.

Your personal data may be transferred to and processed in India and other countries. Where the law requires it, we protect those transfers with appropriate safeguards, such as the standard contractual clauses approved by the European Commission.

12. Children

This website and the Rampart platform are intended for businesses and are not directed at children. We do not knowingly collect personal data through this website from anyone under 18. If you believe a child has given us personal data, please contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time, for example when the law or our services change. When we do, we will change the “Last updated” date at the top of this page. If we make significant changes, we will let our customers know and, where the law requires, ask for your consent again.

14. Contact us and Grievance Officer

For questions about this policy, to exercise your rights or to raise a grievance, contact our Grievance Officer:

Grievance Officer
Cloudfinch Information Technologies Pvt. Ltd.
B-4610, Kohinoor Square
N.C. Kelkar Road, Shivaji Park, Dadar West
Mumbai, Maharashtra 400028, India
Email: sales@cloudfinch.com