BLINE SOLUTION PRIVACY POLICY
Introduction
BLine Solution Private Limited (“BLine”, “we”, “us”, or “our”) respects your privacy. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit www.blinesolution.com or use our platform, or engage our BLine Platform services. Our services include enterprise BLine Pharma Suite, BLine automation suite, OmniMind AI suite, marketing planner suite or services for mid and large manufacturing enterprises, factory automation, AI, IoT and SCADA integrations, GMP consultancy, quality management, and related analytics. This Policy is intended to align with privacy laws across the EU, UK, India, United States (California), Singapore, Australia, UAE, Canada, and Vietnam.
By using our website or services, you agree to this Policy. If you do not agree, please do not use our website or services.
Who We Are
BLine Solution Private Limited is the entity responsible for personal data processed through this website and our business operations. We also operate under the brand name BLine Robotics, which provides automation and robotics solutions. BLine Robotics (www.blinerobotics.com) is currently a division and brand of BLine Solution Private Limited. Any personal data processed in connection with BLine Robotics is processed by BLine Solution Private Limited and is covered by this Policy.
Where we process data on behalf of a client under a contract, the client is the “data controller” (or equivalent term under applicable law) and BLine is the “data processor.”
Personal Data We Collect
Information you provide
- Name, email address, phone number, job title, and organisation name
- Billing and contract information (organisation address, tax identification number)
- Support requests, chat messages, and email communications
- Information submitted through forms on our website
- Details shared during GMP consultancy, training, or audit readiness engagements
Information collected automatically
- IP address, browser type, device information
- Pages visited, session duration, and general usage information
- Cookies and similar technologies (see Section 10)
Information processed on behalf of clients
When clients use our platform, we may process business and operational data as a service provider. This may include user accounts, operational records, and system logs. In such cases, the client controls the data and BLine processes it only as per the client’s instructions and contract.
Sensitive personal data
We may process sensitive personal data only where required and with appropriate safeguards. Categories may include:
- Health information (in the context of GMP consultancy and audit readiness)
- Biometric data (where used for access control)
- Financial information (for billing purposes)
Under Vietnam’s PDPD, sensitive personal data also includes religious and political opinions, sexual orientation, and location data. We obtain explicit consent for processing sensitive personal data and implement enhanced security measures.
Under the UAE PDPL, sensitive data may include racial or ethnic origin, political opinions, religious beliefs, and health data. We process such data only with explicit consent or as otherwise permitted by law.
Payment information
Payment details are processed by third-party payment providers. We do not store full payment card details on our systems.
Information from third parties
We may receive personal data from business partners, resellers, publicly available sources, and service providers. Where we receive personal data indirectly, we will inform you within a reasonable period (and no later than one month under GDPR) of the categories of data obtained, the source, and the purposes of processing.
What we do not do
We do not sell personal data. We do not knowingly collect personal data from children under 18. Our services are not directed to children.
How We Use Personal Data
We use personal data to:
- Provide, operate, and maintain our website and services
- Create and manage user accounts
- Respond to enquiries and provide customer support
- Process billing and payments
- Deliver GMP consultancy, training, and audit readiness services
- Improve our website, services, and security
- Send service-related communications
- Comply with legal and regulatory obligations
- Prevent fraud, misuse, and security incidents
We do not use personal data for automated decision-making that produces legal or similarly significant effects without appropriate safeguards. If we use automated decision-making, we will provide meaningful information about the logic involved, as well as the significance and envisaged consequences, as required by GDPR Article 13 and Australia’s new APPs 1.7–1.9 (effective 10 December 2026).
Legal Basis for Processing
EU / UK (GDPR / UK GDPR)
- Contract — to provide services you or your organisation have requested
- Legitimate interests — to operate, secure, and improve our services
- Legal obligation — to comply with applicable laws
- Consent — where required, such as for certain cookies or marketing
India (DPDP Act)
We process personal data based on consent or other lawful grounds permitted under the Act. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.
UAE (PDPL)
We rely on consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests.
Vietnam (PDPD)
Consent is the primary lawful basis. Consent must be freely given, specific to each processing purpose, and expressed through an affirmative action. For sensitive personal data, we obtain explicit consent and inform you that the data collected is sensitive.
Singapore (PDPA), Australia, Canada (PIPEDA)
We rely on consent or other permitted lawful bases under the applicable legislation in each jurisdiction.
Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by law or contract. When data is no longer needed, we delete it. Under GDPR, we provide the period for which personal data will be stored or the criteria used to determine that period. For data processed on behalf of clients, retention is governed by the client’s instructions and contract.
Sharing of Personal Data
We may share personal data with:
- Our teams and functions involved in delivering automation and robotics services (operating under the BLine Robotics brand), under appropriate confidentiality terms
- Service providers who support our operations (such as hosting, communication, and payment providers), under appropriate data protection terms
- Professional advisers, auditors, and insurers where necessary
- Authorities, regulators, or courts where required by law
- A successor entity in the event of a merger, acquisition, or restructuring
Categories of third parties
- Cloud hosting providers
- Payment processors
- Communication and collaboration platforms
- Analytics providers
- Marketing automation platforms
We do not sell personal data. A current list of key service providers is available on request.
International Transfers
We may transfer personal data to countries outside your own. Where we do so, we take steps to ensure appropriate safeguards are in place, such as standard contractual clauses or other lawful mechanisms.
By jurisdiction
- EU/UK: We rely on adequacy decisions, standard contractual clauses (SCCs), or other lawful transfer mechanisms under GDPR Chapter V.
- UAE PDPL: Transfers outside the UAE require that the destination jurisdiction provides an adequate level of protection, or we implement appropriate safeguards.
- Vietnam PDPD: Cross-border transfers require consent and a transfer impact assessment. Data localisation options may be available for certain clients.
- India DPDP Act: Cross-border transfers are permitted unless restricted by the Central Government. Data localisation options may be available for certain clients under contract.
- Singapore PDPA: Transfers are permitted where the recipient is bound by legally enforceable obligations providing a comparable standard of protection.
- Australia: Transfers are permitted where the recipient is subject to a law or binding scheme providing comparable protection, or with consent.
- Canada PIPEDA: Transfers are permitted where the recipient is subject to comparable privacy protections.
- California: We honour “Do Not Sell or Share My Personal Information” signals, including Global Privacy Control (GPC) browser signals.
Cookies & Your Rights
We use cookies and similar technologies on our website:
Request to know & deletion of your data, where applicable
Children's Privacy
Our website and services are not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
Under the DPDP Act (India), we do not process personal data of children without verifiable parental consent. Under GDPR, we do not process personal data of children under 16 without parental consent where consent is the lawful basis.
Notice at Collection (US State Laws)
Under US state privacy laws, including the CCPA/CPRA, we provide a notice at or before the point of collection that includes:
- The categories of personal information to be collected
- The purposes for which the personal information is collected
- Whether the personal information is sold or shared
- The retention period for each category
This Privacy Policy serves as our Notice at Collection. We may also provide a separate notice at the point of collection.
Do Not Sell or Share My Personal Information: We do not sell personal information. We do not share personal information for cross-context behavioural advertising. California residents may exercise their right to opt out by contacting us at support@blinesolution.com.
GOVERNING LAW AND DISPUTE RESOLUTION
This Policy/Agreement and any dispute or claim arising out of or in connection with it, its subject matter, or its formation (including non-contractual disputes or claims) shall be governed by and construed in accordance with the laws of India. Any dispute, controversy, or claim arising out of or relating to this Policy/Agreement, or the breach, termination, or invalidity thereof, shall be finally settled by arbitration in accordance with the Arbitration and Conciliation Act, 1996, as amended from time to time. The seat and venue of arbitration shall be Indore, Madhya Pradesh, India. The arbitration shall be conducted in English by a sole arbitrator appointed by mutual agreement of the parties. If the parties fail to agree within 30 days, the arbitrator shall be appointed by the Madhya Pradesh High Court, Indore Bench, or its designate. The award rendered by the arbitrator shall be final and binding on both parties. Judgment upon the award may be entered in any court having jurisdiction thereof.
Subject to the arbitration clause above, and to the extent permitted by applicable law, the parties irrevocably agree that the courts at Indore, Madhya Pradesh, India shall have exclusive jurisdiction to settle any dispute or claim that arises out of or in connection with this Policy/Agreement, including for interim measures, enforcement of arbitral awards, and any matter not subject to arbitration. The parties acknowledge and agree that a material part of the cause of action arises in Indore, where BLine Solution Private Limited has its registered office and principal place of business.
Nothing in this section shall prevent or restrict: (a) any data protection or privacy supervisory authority (such as the ICO in the UK, a supervisory authority in the EU, the Data Protection Board of India, the PDPC in Singapore, the OAIC in Australia, the UAE Data Bureau, the Office of the Privacy Commissioner in Canada, or the competent authority in Vietnam) from exercising its regulatory or enforcement powers; (b) any court or tribunal of competent jurisdiction in a country where mandatory local law applies (including consumer protection, data protection, or employment law) from hearing a claim where such law expressly provides for a mandatory local forum; or (c) any individual from exercising their rights under applicable data protection laws, including the right to lodge a complaint with a supervisory authority in their country of residence, place of work, or place of alleged infringement. Notwithstanding the existence of any dispute, the parties shall continue to perform their respective obligations under this Policy/Agreement unless and until the dispute is finally resolved, unless the dispute directly concerns the obligation in question.
All proceedings, documents, and communications related to any dispute shall be in English. If any document is required to be translated, the English version shall prevail.
This Governing Law and Dispute Resolution section applies to all BLine legal documents, BLine all Products & Services, including the Privacy Policy, Service Level Agreement (SLA), Information Security Policy (ISP), and all contractual or policy documents.
Changes to This Policy
We may update this Policy from time to time. The updated version will be posted on this page with a revised “Last Updated” date. Material changes will be communicated where required.
BLine Solution Private Limited
111, B.C. Chamber, Jaora Compound, Indore, Madhya Pradesh – 452001, India
Email: support@blinesolution.com