Privacy Policy · Last updated June 2026

Privacy Policy

This Privacy Policy is issued by Olbrain Labs Private Limited (“Olbrain”, “we”, “us”), a company incorporated in India (CIN U62013HR2024PTC123898) with its registered office at 825-26, Emaar Emerald Plaza, Sector 65, Gurugram, Haryana — 122102. It explains how we handle personal data on this website (olbrain.com) and in connection with the Olbrain Studio platform (studio.olbrain.com and admin.olbrain.com), the platform for building, running, and governing enterprise AI agent fleets.

01

Two roles, two kinds of data

We handle data in two distinct capacities, and the rules differ:

As a data fiduciary (controller)

For data you give us directly — through this website, by email, or when an account is created on Olbrain Studio — Olbrain Labs Private Limited is the data fiduciary under India's Digital Personal Data Protection Act, 2023 (and the data controller under equivalent foreign laws). This policy governs that data.

As a data processor

When an enterprise runs agents on Olbrain Studio, the data flowing through those agents — including the enterprise's own customer data — is processed by Olbrain on the enterprise's behalf and under its instructions. That processing is governed by the customer agreement and Data Processing Agreement signed with the enterprise, not by this website policy. It is protected by tenant isolation, per-tenant key management, and PII tokenization, as described on our Trust & Security page.

02

What we collect

We do not collect more than we need, and we do not buy, sell, or trade personal data.

03

How we use it

We do not use customer or enterprise data to train base models, fine-tunes, or evaluations. This is a contractual and architectural commitment, stated identically on our Trust & Security page. Any platform improvement work uses aggregated, de-identified telemetry only.

04

Where data lives

Olbrain customer data is stored and processed in India — Google Cloud, Mumbai region (asia-south1). Payloads sent to third-party language models pass through our PII tokenizer sidecar first, so detected PII spans are replaced with ciphertext tokens before any model call; the sub-processor inventory documenting these flows is being formalized (status on the Trust page) and will be made available to customers under their agreements. Website analytics and email infrastructure may involve standard international service providers; no enterprise workflow data flows through them.

05

Your rights under the DPDP Act, 2023

If you are a data principal in India, you have the right to:

To exercise any of these rights, write to privacy@olbrain.com. We respond within the timelines prescribed under applicable law.

06

Visitors from other jurisdictions

If you are in the European Economic Area or the United Kingdom, you have equivalent rights under the GDPR/UK GDPR — including access, rectification, erasure, restriction, portability, and objection — and the right to lodge a complaint with your supervisory authority. If you are a California resident, you have the rights provided by the CCPA/CPRA, including the right to know, delete, and correct; we do not sell or share personal information as those terms are defined there. The contact for all such requests is the same: privacy@olbrain.com.

07

Retention

We keep personal data only as long as needed for the purposes above or as required by law. Contact enquiries are retained while the conversation is live and for a reasonable period after. Account data is retained for the life of the customer relationship. Enterprise workflow data is retained and deleted per the customer agreement — including deletion on contract termination, with a certification process being formalized (status on the Trust page).

08

Security

Our security posture — encryption, tenant isolation, key management, access control, PII architecture, and the current status of our SOC 2 and ISO 27001 programs — is documented in detail and kept honestly status-labelled on the Trust & Security page. We err toward stating the true stage of every control.

09

Cookies

This website uses only what is necessary for it to function and for basic, privacy-respecting analytics. We do not run advertising trackers or cross-site profiling.

10

Changes to this policy

When we change this policy, we update the date at the top of this page. Material changes affecting customer data are communicated to customers directly under their agreements.

11

Contact & grievance

Olbrain Labs Private Limited
825-26, Emaar Emerald Plaza, Sector 65,
Gurugram, Haryana — 122102, India
CIN: U62013HR2024PTC123898

Privacy and data-protection requests, including grievances under the DPDP Act: privacy@olbrain.com
General enquiries: hello@olbrain.com

This policy is governed by the laws of India; courts at Gurugram, Haryana have jurisdiction.