GalSol Privacy Policy
Welcome to GalSol. This Privacy Policy explains how we collect, use, process, and protect your information when you use our website, tools, and services.
1 Our Role
GalSol is based in Chennai, Tamil Nadu, India. We process digital personal data to provide the GalSol platform for event organisers, educators, businesses, teams, and their invited collaborators.
For creator accounts and GalSol workspace data, GalSol decides how the platform operates. For event forms, mini-sites, passes, emails, committees, budgets, and other event content, the organiser decides what to collect, publish, share, and delete. GalSol provides the technical infrastructure.
2 Account & Platform Data
When you create or use a GalSol account, we may store your name, email address, profile image, account type, authentication method, Google account identifier if you sign in with Google, granted Google scopes, OAuth tokens needed to perform actions you request, plan/quota information, payment records, feature access, and platform activity such as last active time.
3 Product Data We Store
To run your workspace, GalSol stores the content and settings you create in the platform. This can include Mini Site pages, blocks, drafts, published site settings, connected Google Analytics IDs, GS Forms structure and settings, pass settings, Auto Mail designs and rules, dashboard layouts, GAL Studio prompts, generated artifacts, Event Planner events, committees, members, tasks, comments, calendar notes, event flow, budget and fund records, collaboration invites, access permissions, notifications, and activity records.
4 GS Forms & Pass Data
For standard GS Forms responses, GalSol receives the response on its server and may place it in a temporary processing queue so it can be written to the organiser's connected Google Sheet. After a successful Google Sheets write, GalSol deletes the queued response row. GalSol does not maintain a separate long-term response database for standard GS Forms answers. Three narrow exceptions are described below in this section — a duplicate-prevention record, per-option response counts, and Digital Entry Pass records — each of which exists to deliver a specific feature the organiser switched on.
If Google Sheets or the organiser's Google account is temporarily unavailable, a queued response may remain in the processing queue while GalSol retries delivery or records the failure. This queue exists for safe transfer to the organiser's Google Sheet, not for analytics, resale, or unrelated use.
Duplicate-Prevention Record
If an organiser turns off “Allow multiple submissions” for a form, GalSol must be able to recognise an email address that has already responded. For those forms only — and only where the form contains an email question — GalSol stores a duplicate-prevention record containing the respondent’s email address, a reference to the form, a system-generated submission reference, and the time the record was created. It does not contain the respondent’s answers.
This record is checked when a new response is submitted and is used solely to enforce the organiser’s one-response-per-person rule. It is not used for marketing, profiling, advertising, analytics, resale, or any unrelated purpose, and GalSol does not send email to these addresses on its own behalf. The record is deleted automatically when the organiser deletes the form, and a respondent may request earlier deletion as described in Section 8 and Section 15.
Response Limits per Option
If an organiser sets a maximum number of selections for a multiple-choice option — for example, a limited number of seats on a workshop track — GalSol keeps a running count for each option so the limit can be applied at the moment of submission. These are numeric totals only: they contain no respondent identity, no email address, and no answers. They are deleted when the organiser deletes the form.
Storage on the Respondent’s Device
While a respondent is filling in a form, GalSol saves information in their browser’s session storage so that answers are not lost if the page reloads, so a multi-page form can resume where it left off, and so the page can recognise a form that has already been submitted from that browser. This storage stays on the respondent’s own device, is limited to what is strictly necessary to deliver the form they chose to open, and is cleared by the browser when the tab is closed. It is not used for advertising or cross-site tracking.
If an organiser enables Digital Entry Passes, GalSol stores pass records so QR scanning works quickly at the venue. A pass record can include the pass token, form or mini-site reference, submission or row reference, attendee name and email if mapped by the organiser, pass configuration, pass status, scan count, check-in time, check-in staff identifier, attendance log, and participant fields needed for the pass and pass email workflow.
If you are a respondent, the organiser remains responsible for telling you why your information is collected and for handling your access, correction, and deletion requests. GalSol will assist the organiser where our platform controls the relevant technical record.
5 Google Services
GalSol uses Google OAuth and the following Google Workspace APIs when you connect your Google account: Gmail Send, Google Drive, Google Sheets, Google Analytics data, and basic Google profile scopes.
Data Access
Google Drive: GalSol creates folders and files in your Drive (certificate PDFs, campaign backup folders, form/mini-site response Sheets, uploaded attachment files) and looks up folders it previously created so it can reuse them. Gmail: GalSol sends messages through your Gmail account (form confirmation emails, bulk mailer messages, certificate delivery, collaboration and invite emails); GalSol does not read your inbox. Google Sheets: GalSol creates spreadsheets to store form/mini-site responses and campaign data, and reads/writes rows in Sheets you connect or that GalSol created (registration data, certificate-link columns, attendance check-ins, judging results).
Data Use
Google data is used only to operate the specific feature you triggered: generating and filing certificates, storing and displaying form/mini-site responses, sending the emails a feature requires, and syncing attendance or judging data back to your Sheet. Sample rows from a connected Google Sheet may be sent to GalSol's AI-assisted analytics features (see Section 7) to generate chart and dashboard suggestions for that same Sheet.
Data Transfer
GalSol does not sell Google user data and does not share it with data brokers or advertisers. Data generated through these features (certificates, response Sheets, sent emails) is written back into your own Google Drive/Gmail/Sheets account, not to a separate third party. Sample Sheet rows may be sent to GalSol's AI provider strictly to generate the output you requested, as described in Section 7.
Data Protection
OAuth access and refresh tokens are stored server-side and used only to make the authorised API calls described above; they are never exposed to the browser or to other users. All calls to Google APIs use HTTPS/TLS. Access to stored tokens is restricted by the same database access controls described in Section 8.
Data Retention & Deletion
Most form-response data pulled from Google Sheets is not separately stored by GalSol — it is read live from your Sheet on each request, or briefly queued and then deleted once written to your Sheet (see Section 4). GalSol retains only pointers/IDs needed to keep working with your Drive files and Sheets (folder IDs, spreadsheet IDs, sheet names), not the underlying file or row content. OAuth tokens are retained while your Google connection remains active and are deleted if you disconnect Google or delete your account; contact us using Section 15 to request earlier deletion.
Google API Limited Use:
- We use Google data only to provide and improve the user-facing features you request.
- We do not use Google user data for targeted or retargeted advertising.
- We do not allow humans to read your Google data unless required for security, support with your consent, troubleshooting, abuse prevention, or legal compliance.
- The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
6 Analytics
GalSol uses Google Analytics on GalSol pages only after a visitor allows analytics cookies in the cookie banner. Analytics helps us understand aggregated traffic, page usage, and product performance.
Organisers may also connect their own Google Analytics Measurement ID to a published Mini Site. In that case, visitor analytics for that Mini Site are sent to the organiser's own Google Analytics property. GalSol stores the Measurement ID so the organiser's tracking can run on their site, but the organiser controls that analytics property and should provide any required notice to their visitors.
7 AI Features
GalSol includes AI-assisted tools for creating event assets, forms, dashboards, emails, and mini-sites. Prompts, generated content, and workspace context may be processed by the AI provider to generate the requested output. Do not include sensitive personal data in prompts unless it is necessary for the feature you are using.
For the AI dashboard/chart-suggestion features in Google Sheets-connected analytics, a small sample of rows (and, for multi-tab sources, sample rows from each tab) from your connected Google Sheet is sent to our AI provider so it can suggest a relevant chart layout for that data. This data is used only to generate the requested suggestion for you; it is not used to train or improve any general-purpose AI/ML model, and it is not shared with any party other than the AI provider processing that specific request. A separate free-text AI chat feature in the same dashboard is configured to exclude row data entirely.
Limited Use Compliance Statement:
The use of raw or derived user data received from Google Workspace APIs (Drive, Gmail, Sheets) will adhere to the Google User Data Policy, including the Limited Use requirements. This data is not used to develop, improve, or train generalized AI/ML models, and is not transferred to third-party services for the purpose of training their AI/ML models.
8 Security & Retention
We use HTTPS/TLS for data in transit, database access controls, role-based platform permissions, and internal safeguards to reduce unauthorised access. No online service can guarantee absolute security, but we design GalSol to reduce data exposure and keep form responses primarily with the organiser's connected Google account where applicable.
We retain account, workspace, pass, collaboration, and event-planning records while your account or event workspace is active, unless deletion is requested or a longer retention period is required for security, legal, abuse-prevention, billing, or operational reasons.
Records tied to a single form — the duplicate-prevention record and per-option response counts described in Section 4 — are kept only while that form exists, because they are meaningless once the form is gone. Deleting a form removes them automatically. A respondent who wants their duplicate-prevention record removed sooner should contact the organiser who published the form; where GalSol controls the technical record, we will act on the organiser’s instruction, and respondents may also reach us directly using Section 15. Removing that record means the same email address will be able to submit to that form again.
Personal Data Breach
If a personal data breach occurs, GalSol will intimate the Data Protection Board of India and each affected data principal, in the form and manner required under Section 8(5) of the DPDP Act. Our notification will describe what happened, the categories of data involved so far as known, the likely consequences, the measures we have taken or propose to take to mitigate the risk, and the steps you can take to protect yourself.
Where an incident is reportable under the directions issued by the Indian Computer Emergency Response Team (CERT-In) under Section 70B(6) of the Information Technology Act, 2000, GalSol will report it to CERT-In within the prescribed timeline of six hours of noticing the incident, and maintains system logs for the period those directions require. Suspected security issues can be reported to us using Section 15.
9 Embedded Forms & Mini Sites
An organiser can embed a GS Form or Mini Site into their own website using an inline frame (iframe), so the form appears as part of that site. When a form is used this way:
- The form is still served by GalSol. To deliver it, GalSol receives the technical request information a web server necessarily receives, such as IP address, browser and device user-agent, and the address of the form requested.
- Browsers keep framed content separated from the surrounding page. The host website cannot read what a respondent types into the form, and the embedded form cannot read the host page.
- So the frame can be sized to fit the form, the embedded form sends the host page a small technical message containing only the form’s display height, its layout style, and the form’s public address. This message carries no respondent details and no answers.
- The surrounding website is operated by the organiser or a third party, not by GalSol. That website’s own privacy policy, cookie banner, and analytics apply to the page as a whole, and the organiser remains responsible for giving respondents the notice their law requires.
Everything described in Section 4 — including how answers are passed to the organiser’s Google Sheet, the duplicate-prevention record, and storage on the respondent’s device — applies in the same way to an embedded form as it does to a form opened directly on a GalSol address.
10 Your Rights & Responsibilities
If you are in India, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it give you the following rights over your personal data. You can exercise any of them using the details in Section 15, free of charge.
- Right to access information. You may ask us for a summary of the personal data we process about you, the processing activities we carry out, and the identities of any other data fiduciaries or data processors with whom we have shared that data.
- Right to correction, completion and updating. You may ask us to correct inaccurate or misleading data, complete incomplete data, and update data that has changed.
- Right to erasure. You may ask us to erase your personal data where you withdraw consent or the purpose for collecting it is no longer being served, unless we are required to keep it to comply with a law in force.
- Right to withdraw consent. Where we rely on your consent, you may withdraw it at any time and as easily as you gave it — by deleting your account, disconnecting your Google account from GalSol, or writing to us. Withdrawal does not affect processing already carried out lawfully before the withdrawal. Some features cannot function without the underlying data, and you may bear the consequences of that loss of functionality.
- Right to nominate. You may nominate another individual to exercise these rights on your behalf if you die or become unable to act for yourself due to unsoundness of mind or infirmity of body. Write to us with the nominee’s details to record a nomination.
- Right to grievance redressal. You may raise a grievance with us about how we handle your personal data or about our response to any of the above. Section 15 explains how, and how long we take.
We may need to verify your identity before acting on a request, so that we do not disclose or delete one person’s data at another person’s request.
Where you are a respondent to an organiser’s form, mini-site, pass or mailing, that organiser decides what is collected and why. Please direct access, correction and deletion requests to the organiser first. Where GalSol holds the technical record, we will assist the organiser, and you may also contact us directly using Section 15.
Your Responsibilities
The DPDP Act also places duties on you as a data principal. You must comply with applicable law when using GalSol, must not impersonate another person while providing your personal data, must not suppress material information when providing data for any document or identifier, must not register a false or frivolous grievance or complaint, and must furnish only verifiably authentic information when exercising your right to correction or erasure.
11 Children’s Data
GalSol accounts are intended for adults. We do not knowingly create creator accounts for individuals under 18, and the platform is not directed at children.
GalSol does not carry out tracking or behavioural monitoring of children, and does not serve targeted advertising to children, on any part of the platform.
Organisers may run forms, registrations or events involving school or college participants who are under 18. In that case the organiser is the one deciding to collect that data, and the organiser is responsible for obtaining verifiable consent from the child’s parent or lawful guardian before collecting it, as required by Section 9 of the DPDP Act, and for not collecting data likely to have a detrimental effect on a child’s well-being. GalSol provides the technical infrastructure and does not obtain that consent on the organiser’s behalf.
If you believe a child’s personal data has been provided to GalSol without the required parental or guardian consent, contact us using Section 15 and we will remove it promptly, subject to any legal retention obligation.
12 Payments
Paid plans are processed through Razorpay, a third-party payment gateway. Card, UPI, net-banking and similar payment credentials are entered directly with the gateway and are not collected, seen or stored on GalSol’s servers. GalSol receives and stores only the payment and order references, plan, amount, status and timestamp needed to activate your plan, support you, and meet accounting and tax obligations.
Razorpay processes your payment information as an independent service provider under its own privacy policy and applicable Reserve Bank of India requirements. Records required for accounting, taxation or audit are retained for the period required by law even after account deletion.
13 Where Your Data Is Processed
GalSol operates from India. Some of the infrastructure and service providers we rely on — including our database and hosting provider, Google Workspace APIs, our email delivery path, and our AI provider — may store or process data on servers located outside India.
Where personal data is transferred outside India, we do so in accordance with Section 16 of the DPDP Act, and we do not transfer personal data to any country or territory that the Central Government has restricted by notification. Where another Indian law prescribes a higher standard of protection or localisation for a particular category of data, that higher standard applies.
These transfers are limited to what is needed to run the features you use, and our providers are engaged under contractual terms requiring them to protect the data and process it only on our instructions.
14 Changes to This Policy
We may update this Privacy Policy as GalSol changes or as the law requires. The revised version will be posted on this page with a new “Last updated” date, and the updated policy applies from the date it is posted.
Where a change materially affects how we handle your personal data, or where the law requires fresh notice or consent, we will take reasonable steps to inform account holders directly — for example by email or an in-product notice — before the change takes effect. Please review this page periodically.
15 Grievance Redressal & Contact
For privacy questions, to exercise any right in Section 10, or to raise a grievance about how GalSol has handled your personal data, contact our Grievance Officer. This is also the point of contact able to answer questions about our processing of personal data for the purposes of the DPDP Act, and the Grievance Officer for the purposes of the Information Technology Act, 2000 and the rules made under it.
Grievance Officer — GalSol
Name:ALEX SIMON S
Designation:Founder & CEO - GalSol
Email: galsol.co@gmail.com
Subject Line: “Privacy Grievance”
Address: 3/54,Veteran Lane, C.Pallavaram, Chennai-43, Tamil Nadu, India
Phone: [CONTACT NUMBER]
We will acknowledge your complaint within 24 hours of receipt and resolve it within 15 days, unless a shorter period is prescribed by law for the particular request. Please include enough detail to identify your account or the form concerned, so we can locate the record.
If you are not satisfied with our response, or we do not respond within the period above, you may escalate your complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act. Under that Act you are expected to exhaust the grievance process above before approaching the Board.
This notice is published in English. If you would prefer to receive it in Hindi or in any other language listed in the Eighth Schedule to the Constitution of India, write to us at the address above and we will provide it.