Legal · v2.0

Privacy Policy

Last updated: 1 July 2026

This Privacy Policy explains how Nara Virtual ("Nara Virtual", "we", "us", "our") collects, uses, discloses, retains, and protects personal data when you use Conference — including our website at https://conference.naravirtual.in, workspace applications, APIs, and our Android/iOS native client applications (collectively, the "Service"). It also describes your choices and rights. This Policy is incorporated into our Terms of Service.

1. Who we are

Nara Virtual operates Conference and is the primary data controller for the processing described in this Policy, except where a workspace host independently determines purposes and means for their participants' data (see Section 3).

Operator website: https://naravirtual.in. Product: https://conference.naravirtual.in. Support: [email protected]. Privacy: [email protected].

We design the Service for a global audience. Our infrastructure and support operations are primarily based in India; we apply protections described below when data is processed in or transferred to other countries.

2. Controller, processor, and host roles

Understanding who is responsible for your data depends on context:

  • Nara Virtual (controller): account registration, authentication, platform security, billing, subscription entitlements, platform-wide audit logs, first-party traffic analytics, abuse prevention, legal compliance, and operation of shared infrastructure (databases, media servers, storage).
  • Workspace owner / administrator (often an independent controller or business operator): choices about who may join, registration forms, webinar attendee lists, meeting titles and settings, recording start/stop, member invites, workspace branding, and how long they retain exports or recordings within plan limits. Hosts must provide their own notices to participants where required by law.
  • Nara Virtual (processor, on host instructions): storing and delivering meeting/webinar metadata, chat, Q&A, polls, recordings, and registration responses on behalf of a workspace, subject to this Policy and the host's use of the Service.
  • Participants and guests: you choose what to share (name, camera, microphone, chat, registration answers). You may leave a session at any time.

3. Scope and audience

This Policy applies to visitors of our marketing site, registered users, workspace members, guests joining via link or code, webinar registrants, billing contacts, and platform administrators.

It does not apply to third-party websites, apps, or services you access through links (including payment pages operated by our payment processor, or Google sign-in flows governed by Google's policies).

The Service is a business communications platform. It is not intended for consumer social networking, emergency calling, or healthcare-specific regulated use without appropriate agreements and safeguards.

4. Categories of personal data we process

We collect only what we need to operate the Service. Categories include:

  • Identity and account: display name, email address, password (stored as a one-way hash), profile photo (upload or URL), job title, locale, time zone, date/time format preferences, default mic/camera join preferences, email notification category preferences, account creation and last-update timestamps, legal acceptance timestamp.
  • Authentication and security: Google account identifiers and tokens when you choose Google sign-in (web or native); email verification and password-reset one-time codes; session tokens (JWT/cookies); guest session identifiers for link-based joins; rate-limit and abuse-prevention counters keyed by IP and/or account.
  • Workspace and membership: workspace name and slug, your role (owner, admin, host, co-host, member, guest), invite tokens, membership history, workspace billing profile (legal name, address, phone, GSTIN or tax identifiers when provided).
  • Meetings and webinars (metadata): titles, descriptions, codes, schedules, passcodes, lobby/waiting-room settings, host options (guest access, join-before-host, auto-end, recurrence), registration form field definitions and responses, attendance logs, participant join/leave events, active-speaker and roster state during sessions.
  • Realtime communications content: audio and video streams, screen-share content, and in-meeting reactions are transmitted through our self-hosted media infrastructure (LiveKit SFU) for the duration of the session. We do not sell session content or use it to build advertising profiles. Chat messages in meetings may be buffered in Redis with a short retention window and paginated history while the room is active.
  • Webinar engagement: Q&A questions and votes, poll questions and votes (deduplicated per voter where configured), and related timestamps.
  • Recordings (when enabled on eligible plans): composite audio/video (and related egress outputs) stored in object storage, plus metadata (duration, size, status, storage key, expiry, consent notice version shown). Recordings may include anything visible or audible in the session, including screen share and chat read aloud.
  • Billing and transactions: plan tier, subscription status, billing interval, Razorpay customer/subscription/payment identifiers, invoice numbers, amounts, currency, tax lines, and webhook event references. We do not store full payment card numbers — card data is handled by Razorpay.
  • Communications we send: transactional email content and delivery metadata (verification, password reset, invites, billing, recording-ready, webinar confirmation) via configured email providers; in-app notifications stored until read or account deletion.
  • Support, audit, and administration: privileged-action audit logs (actor user ID, action type, target, timestamp, IP address, reason where supplied), platform-admin support actions including time-limited impersonation tokens (audit-logged, single-use, short TTL), suspension and deletion scheduling.
  • Technical and usage data: IP address, user agent, request paths, HTTP referrer, UTM campaign parameters, coarse country/region/city derived from IP (including occasional lookups via ipwho.is for operational analytics), device/browser characteristics, connection quality signals reported by the client, first-party traffic visit logs for admin dashboards.
  • Android/iOS native client: OS-granted permissions for camera, microphone, notifications, screen capture (screen share), and foreground meeting services; app loads the same web application inside a secure WebView with an appended user-agent token for support and layout. Offline shell assets may cache static fallback pages locally; session data remains online.

5. Sources of personal data

We obtain personal data from: (a) you directly (forms, settings, chat, registration, profile uploads); (b) your device and browser automatically (logs, cookies, beacons); (c) workspace administrators who invite or register you; (d) payment processors (e.g., Razorpay webhooks confirming payment status); (e) media infrastructure webhooks (session and egress lifecycle); (f) identity providers (Google) when you opt into social sign-in; and (g) optional IP geolocation services for coarse analytics.

6. Purposes of processing

We use personal data to:

  • Provide, maintain, and improve meetings, webinars, scheduling, recordings, chat, Q&A, polls, and workspace collaboration.
  • Authenticate users, enforce roles and entitlements, operate waiting rooms, and mint short-lived media access tokens.
  • Process subscriptions, invoices, taxes, refunds, and fraud prevention.
  • Send transactional and service messages and display in-app notifications.
  • Measure first-party product usage, diagnose errors, and protect against abuse (rate limits, audit trails).
  • Comply with law, enforce our Terms, and respond to lawful requests.
  • With your consent where required: optional marketing email categories, and your decision to remain in a session after a recording notice.

8. Real-time media, recordings, and host duties

Audio, video, and screen share are routed through our self-hosted Selective Forwarding Unit (SFU) infrastructure. Media is encrypted in transit (TLS/DTLS/SRTP as applicable). We do not intentionally route meeting media through unrelated third-party ad or analytics networks.

When a host starts cloud recording, participants see an in-product recording indicator and consent notice (customizable by platform administrators). By remaining in the session after notice, you acknowledge the recording. Hosts are responsible for obtaining any additional consent required by their jurisdiction, industry, or workplace policies.

Hosts control recording retention within plan limits, download access, and deletion. We auto-expire recordings per plan entitlements. Hosts must not record where prohibited by law or without required notices.

We do not use meeting audio, video, chat, or recordings to train third-party artificial intelligence or machine-learning models.

9. Mobile applications (Android / iOS)

Our native apps are thin clients that load the Service from our servers (production: the deployed web origin configured at build time). Functionality, data processing, and retention are the same as the browser experience unless noted below.

  • Permissions: the OS may prompt for camera, microphone, notifications, and screen capture. You can deny permissions; core features may not work without them.
  • Google sign-in (Android/iOS): if you choose it, Google's native sign-in SDK may process device identifiers according to Google's policy; we receive an ID token to authenticate your account.
  • Deep links and App Links: meeting, join, and auth URLs on our domain may open directly in the app when installed.
  • Foreground services (Android): ongoing meeting and screen-share capture may display a persistent notification as required by the OS.
  • Picture-in-picture: may be available during meetings per OS support.
  • Offline mode: a static offline page may display when the network is unavailable; authenticated session data is not stored for offline meeting access.

10. Cookies, local storage, and similar technologies

We use strictly necessary technologies for authentication (Auth.js session cookies), workspace selection, guest identifiers, CSRF/session integrity, and security.

We use first-party analytics beacons (sendBeacon/fetch to our own API) to record page path, referrer, and UTM parameters tied to a coarse IP-derived country for operational dashboards — not for third-party advertising.

Progressive Web App (browser): a service worker may cache static offline assets and icons. It does not cache your meeting media.

You can control cookies via browser settings. Blocking essential cookies will prevent sign-in. We do not respond to Do Not Track signals with a different experience because we do not engage in cross-site tracking for ads.

11. How we disclose personal data

We do not sell personal data. We disclose personal data only as follows:

  • Infrastructure subprocessors we operate or contract (see Section 12).
  • Payment processing: Razorpay (subscriptions, invoices, payment status).
  • Identity: Google (OAuth / native sign-in) when you choose it.
  • Email delivery: configured SMTP or providers such as Brevo, Postmark, or Amazon SES for transactional email only.
  • Coarse IP geolocation: ipwho.is (or similar) for admin traffic analytics — IP submitted, country/region returned.
  • Workspace members and hosts: rosters, registrant data, recordings, and analytics visible per role.
  • Participants in the same session: display names, presence, chat, and media as designed by the product.
  • Legal and safety: regulators, law enforcement, or courts when we believe disclosure is required by law or necessary to protect rights, safety, and platform integrity.
  • Corporate transaction: merger, acquisition, or asset sale, with notice where required by law.

12. Subprocessors and infrastructure

We use the following categories of subprocessors to operate the Service. Exact entities and regions may evolve; material changes will be reflected in this Policy.

  • Application hosting and CDN: VPS/cloud servers and reverse proxy (e.g., Dokploy, Traefik, Cloudflare) — application traffic, logs.
  • PostgreSQL database: account, workspace, meeting, billing, audit, and analytics records.
  • Redis: caching, rate limits, ephemeral meeting chat buffers, session-scoped tokens.
  • LiveKit (self-hosted): realtime audio/video/screen-share SFU; short-lived participant tokens.
  • TURN/STUN (self-hosted): NAT traversal for media where direct connectivity fails.
  • Egress/recording workers (self-hosted): composite recording to object storage when hosts start recording.
  • Object storage (S3-compatible / Cloudflare R2 / MinIO): recordings and uploaded assets (profile photos, webinar banners).
  • Razorpay: payment processing (India and international cards per configuration).
  • Email provider (environment-specific): transactional email delivery.
  • Google Cloud: OAuth client services when you sign in with Google.

13. International transfers

We serve users globally from infrastructure that may be located in India and other regions. Where personal data is transferred across borders, we implement appropriate safeguards — including encryption in transit, access controls, vendor review, and contractual protections — consistent with applicable law.

If you are in the EEA/UK and require information about transfer mechanisms (e.g., Standard Contractual Clauses), contact us at the addresses below.

14. Retention

We retain personal data only as long as necessary for the purposes in this Policy:

  • Account profile: until you delete your account, plus up to 30 days' grace before permanent erasure, unless a longer period is required by law or active dispute.
  • Workspace data: until the workspace owner deletes the workspace (same grace period) or account purge cascades apply.
  • Meeting chat (Redis): short TTL while rooms are active; not kept as a long-term archive after room teardown.
  • Webinar Q&A/polls/registrations: until deleted with the webinar/workspace or purged on account/workspace erasure.
  • Recordings: per plan retention window and storage caps; deleted on expiry, host deletion, or workspace purge.
  • Billing and invoices: typically 7–8 years for tax and accounting in India unless a shorter lawful period applies.
  • Audit and security logs: generally up to 24 months unless needed for an investigation or legal hold.
  • Traffic visit logs: operational retention for admin dashboards; not used for ad targeting.
  • Impersonation tokens: seconds (single use); impersonation events retained in audit logs.
  • Backups: encrypted backups may persist for a limited cycle after deletion before overwrite.

15. Your privacy rights and choices

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent.

In the Service (Settings → Privacy & data): export your account data (JSON), export workspace data (workspace admins), request account deletion, or request workspace deletion (owner). Deletion schedules erasure after the grace period described above. Exports and deletion requests are audit-logged.

Email: manage non-security email categories in profile settings. Security messages (verification, password reset) cannot be disabled.

Meetings: you may mute camera/microphone, leave a session, or decline to join. If you do not wish to be recorded, leave the session after the recording notice.

To exercise rights not available in-product, email [email protected]. We may verify your identity. Authorized agents may submit requests where permitted by law.

16. Region-specific notices

India (DPDPA): see Section 17 for Grievance Officer contact. You may also have rights to access, correction, erasure, and grievance redressal as prescribed by applicable rules.

EEA/UK (GDPR): you may lodge a complaint with your local supervisory authority. Our lawful bases are in Section 7. You may object to processing based on legitimate interests where applicable.

California (CPRA): we do not sell or share personal information for cross-context behavioral advertising. Categories collected in the last 12 months mirror Section 4. Retention periods mirror Section 14. Submit requests via [email protected].

Other US states: where comprehensive privacy laws apply, we provide analogous access and deletion rights subject to verification and exceptions.

17. Grievance officer (India)

Under the Digital Personal Data Protection Act, 2023 (India), you may contact our Grievance Officer:

Email: [email protected] (also reachable via [email protected]).

We will acknowledge complaints and endeavour to resolve them within timelines prescribed by applicable law.

18. Security

We implement administrative, technical, and organizational measures including: TLS for data in transit; role-based access control; workspace scoping; hashed passwords; short-lived LiveKit tokens; secrets in environment configuration; rate limiting; audit logging for privileged actions; encrypted object storage for recordings in production; and network isolation for datastores in production deployments.

No system is perfectly secure. You are responsible for strong passwords, safeguarding invite links, and configuring workspace access appropriately.

19. Data breach notification

If we become aware of a personal data breach likely to affect your rights, we will investigate promptly, mitigate harm, and notify affected users and regulators as required by applicable law (including India's DPDPA and GDPR where relevant).

20. Children

The Service is not directed to children under 18, and we do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.

21. Automated processing

We use automated systems for rate limiting, entitlement enforcement, fraud signals, plan-limit warnings, and abuse detection. We do not make solely automated decisions with legal or similarly significant effects on you without human review where required by law.

22. Changes to this Policy

We may update this Policy. The "Last updated" date and version number will change. Material changes may be notified in-product or by email. Continued use after the effective date constitutes notice of the update. Prior versions may be available on request.