Legal

Privacy Policy

What we collect, why we collect it, who it is shared with and what you can ask us to do about it — written to be read, not skimmed past.

Last updated1 August 2026

01Who we are and what this covers

Gbooks builds and operates a connected business software suite used by organisations across healthcare, hospitality, education, e-commerce, manufacturing, HR, accounting and digital marketing. Our registered place of business is BL-FRONT, 2nd Floor, 96/L S.P. Mukherjee Road, Kolkata, West Bengal, India – 700026.

This policy explains how we handle personal data on gbooks.com, on our demo and trial environments, and in the hosted software we provide to our customers. It applies to visitors to our website, people who contact us or request a demo, and users who access a Gbooks system provided by their employer or service provider.

It does not apply to third-party websites or services we link to, or to how our customers use the data they hold in their own Gbooks systems — for that, their own privacy notice governs.

02When we are the controller, and when we are the processor

We act in two distinct roles, and your rights differ depending on which applies.

  • As a controller: for data we collect directly — website visitors, demo requests, sales and support enquiries, marketing subscribers, job applicants and our own account contacts. We decide why and how that data is used, and this policy governs it.
  • As a processor: for the data our customers put into their Gbooks systems — patient records, guest bookings, student records, employee payroll and similar. We process it only on our customer's documented instructions under our services agreement. If your data is in a system run by a hospital, hotel, school or employer, contact them first; we will support them in responding to you.

03Information we collect

We collect only what we need to run our website, respond to enquiries, deliver our services and keep them secure.

  • Information you give us: your name, work email, phone number, company, industry, the modules or add-ons you are interested in, and anything you write in a message or demo request form.
  • Account and usage data: login identifiers, role and permission assignments, configuration choices, and records of actions taken inside a Gbooks system (audit trails), where we host that system.
  • Technical data: IP address, browser and device type, operating system, referring page, pages viewed and approximate location derived from IP. This is collected automatically when you visit our website.
  • Support and communication records: emails, call notes, chat and WhatsApp messages exchanged with our sales, implementation and support teams, including attachments you send us.
  • Billing data: the contact, tax and payment reference details needed to raise invoices and record payments. Card and bank credentials are handled by our payment providers — we do not store them.
  • Customer data: whatever our customer chooses to record in their system. We do not select the categories, and we do not use this data for our own purposes.

We do not knowingly seek sensitive personal data through our website forms. Please do not include patient, student, employee or financial records in a demo request or support message unless we have specifically asked for them under an agreement.

04How we use information

  • To respond to your enquiry, arrange a demo and prepare a proposal scoped to your operations.
  • To provide, configure, migrate, support and improve the services you or your organisation have subscribed to.
  • To secure our platform — authenticating users, detecting misuse, investigating incidents and maintaining audit trails.
  • To send service messages such as release notes, maintenance windows, incident updates and billing notices. These are part of the service and are not marketing.
  • To send marketing about Gbooks products where you have asked for it or where we are permitted to, always with a way to opt out.
  • To meet our legal, tax, accounting and regulatory obligations, and to establish or defend legal claims.
  • To analyse aggregated, de-identified usage so we can see which features earn their place and where the product needs work.

We do not sell personal data, and we do not share it with third parties for their own advertising.

06Cookies and analytics

Our website uses a small number of cookies and similar technologies: strictly necessary ones that make the site work and keep it secure, and optional analytics that tell us which pages are read and where visitors drop off.

You can block or delete cookies in your browser settings. Blocking strictly necessary cookies may break parts of the site. We do not run third-party advertising trackers on this website.

07When we share information

We disclose personal data only in these circumstances:

  • Service providers and sub-processors who host, deliver, monitor or support our platform — cloud infrastructure, email and messaging delivery, payment gateways, and support tooling. They act on our instructions under written terms and may not use the data for their own purposes.
  • Your organisation, where you use a Gbooks system provided by an employer, hospital, hotel, institution or client of ours — administrators there can see activity within their own system.
  • Professional advisers such as auditors, accountants and lawyers, under duties of confidentiality.
  • Authorities and courts, where we are legally required to disclose. We review every request, disclose no more than required, and notify the affected customer unless the law forbids it.
  • An acquirer, in the event of a merger, acquisition or restructuring — in which case this policy continues to apply to the transferred data until it is replaced by a notice at least as protective.

08International transfers

We are based in India and host primarily in Indian data centres. Some of our service providers operate outside India, so personal data may be transferred and stored elsewhere.

Where we transfer data across borders, we do so under appropriate safeguards — contractual protections with the receiving party, and any transfer restrictions that apply under the DPDP Act or, for EU/UK data, standard contractual clauses. Customers with data residency requirements should raise them before contracting so we can confirm what we can support.

09How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, then delete or anonymise it.

  • Enquiry and demo request records: up to 24 months from our last meaningful contact, unless you become a customer.
  • Customer account and contract records: for the life of the agreement, plus the period required by tax, accounting and limitation laws.
  • Customer data in hosted systems: for the term of the agreement. On termination we make it available for export for the window set out in that agreement, then delete it on the agreed schedule.
  • Security and audit logs: typically 12 months, longer where an investigation or legal hold requires it.
  • Backups: on a rolling cycle, so deleted records may persist in backups for a short period before being overwritten.

10How we protect it

Data is encrypted in transit and at rest, access is role-based and granted on need, administrative access requires multi-factor authentication, and every module writes to a tamper-evident audit trail. Backups are automated and restores are tested.

No system is perfectly secure, and we do not pretend otherwise. Our security practices, and how to report a vulnerability, are set out on our security page.

11Your rights

Subject to the law that applies to you and to verification of your identity, you may:

  • Ask what personal data we hold about you and get a copy of it.
  • Have inaccurate or incomplete data corrected or completed.
  • Ask us to erase data we no longer have a lawful reason to keep.
  • Withdraw consent where our processing relies on it.
  • Object to, or ask us to restrict, processing based on legitimate interests, including direct marketing — which you can stop at any time.
  • Receive certain data in a portable, machine-readable format, where that right applies.
  • Nominate another person to exercise these rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.

Write to hello@gbooks.com to exercise any of these. We respond within the period the applicable law allows, and we will tell you if we need more information to verify who you are. If your data sits in a customer's system, we will pass the request to them and support their response.

12Children's data

Our website and services are intended for businesses and institutions, not for children. We do not knowingly collect personal data directly from children through this website.

Our education customers do hold student records in systems we host, as processors on their instructions. In that arrangement the institution is responsible for the lawful basis, including any parental consent required.

13Third-party links and integrations

Our site and product link to and integrate with third-party services — payment gateways, messaging providers including the WhatsApp Business API, mapping and analytics. Once your data reaches them, their own terms and privacy notices apply.

We choose integration partners carefully and put contracts in place where they process data for us, but we do not control how independent services handle data you supply to them directly.

14Changes to this policy

We update this policy when our practices, our services or the law change. The revision date at the top always reflects the current version.

If a change materially affects how we use your personal data, we will give notice by email or an in-product notice before it takes effect, wherever we reasonably can.

15Contact and grievances

For any question, request or complaint about this policy or our handling of personal data, write to our Grievance Officer at hello@gbooks.com, or post to: Grievance Officer, Gbooks, BL-FRONT, 2nd Floor, 96/L S.P. Mukherjee Road, Kolkata, West Bengal, India – 700026.

We aim to acknowledge every grievance promptly and resolve it within the timeframes set by applicable law. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or, where the GDPR applies to you, to your local supervisory authority.

Questions about this document?

Write to hello@gbooks.com and a member of our team will respond.

Contact us