Communications and Consent Policy
1. Purpose
This Communications & Consent Policy (“Policy”) explains how CRUD INFOSYSTEMS PRIVATE LIMITED, operating under the brand name The cRUD Company (“cRUD”, “The cRUD Company”, “Company”, “we”, “us” or “our”), manages communications sent:
- by cRUD directly;
- through cRUD Webinar;
- by webinar organizers using cRUD;
- to Account holders, attendees, speakers, organizers, and other users.
This Policy also explains:
- the difference between operational and promotional communications;
- when consent may be requested;
- how consent is recorded;
- how consent can be withdrawn;
- how unsubscribe and suppression work;
- how communications preferences are maintained;
- how cRUD handles re-consent and policy changes.
2. Scope
This Policy may apply to communications involving:
- The cRUD Company website;
- cRUD Webinar;
- Account creation;
- login and authentication;
- webinar registration;
- attendee access;
- speaker invitations;
- webinar reminders;
- replay notices;
- billing;
- support;
- legal notices;
- security notices;
- marketing;
- product announcements;
- newsletters;
- promotional campaigns;
- other communications expressly governed by this Policy.
3. Company details
CRUD INFOSYSTEMS PRIVATE LIMITED Operating under the brand name The cRUD Company
Unit 101, OXFORD TOWERS 139, HAL Old Airport Road Kodihalli, Bengaluru, Karnataka 560008 India
General contact
Privacy
Grievances
Legal
4. Relationship with other policies
This Policy should be read together with:
- Terms of Service;
- Privacy Policy;
- Cookie Policy;
- Acceptable Use Policy;
- Data Retention & Deletion Policy;
- Grievance & Complaint Redressal Policy;
- any contextual communication notice shown within the Services.
5. Core principle
cRUD distinguishes between:
- essential operational communications;
- transactional communications;
- legal and security communications;
- webinar lifecycle communications;
- optional promotional or marketing communications.
These categories are not treated as interchangeable.
6. Operational communications
Operational communications are messages reasonably necessary to provide, secure, administer, or support the Services.
Examples include:
- account verification;
- password reset;
- authentication notices;
- suspicious-login notices;
- account recovery;
- account suspension;
- account termination;
- support responses;
- service availability notices;
- major product-operation notices.
7. Transactional communications
Transactional communications are messages associated with a requested transaction or product action.
Examples include:
- subscription confirmation;
- payment receipt;
- invoice;
- refund confirmation;
- cancellation confirmation;
- failed-payment notice;
- renewal notice;
- Event Pass purchase confirmation where applicable.
8. Legal communications
Legal communications may include:
- Terms updates;
- Privacy Policy updates;
- material policy changes;
- legal notices;
- contractual notices;
- compliance notices.
9. Security communications
Security communications may include:
- compromised-account warnings;
- credential-reset requirements;
- security incident notices;
- access revocation;
- suspicious activity alerts.
10. Essential communications are not optional marketing
A user cannot opt out of communications that are reasonably necessary to:
- maintain an Account;
- secure an Account;
- complete a transaction;
- comply with legal obligations;
- provide a requested Service.
11. Marketing communications
Marketing communications are optional promotional messages from The cRUD Company.
Examples may include:
- product announcements;
- newsletters;
- promotional offers;
- educational content;
- launch announcements;
- invitations;
- updates concerning cRUD products.
12. Separate marketing consent
Where applicable or appropriate, cRUD will request separate permission for optional promotional communications.
Acceptance of the Terms of Service does not automatically mean blanket consent to optional cRUD marketing.
13. Recommended marketing consent language
A signup interface may use language such as:
I would like to receive product updates, educational content, offers and other marketing communications from The cRUD Company. I can unsubscribe at any time.
Where affirmative consent is required, this option should not be pre-selected.
14. Signup acceptance
The primary required legal acceptance at signup should remain:
I agree to the Terms of Service and acknowledge the Privacy Policy.
This should be separate from optional marketing consent.
15. Consent principles
Where consent is relied upon, cRUD seeks to ensure it is:
- specific;
- informed;
- clear;
- associated with an identified purpose;
- capable of being withdrawn.
Where India’s statutory consent rules apply to the processing, consent must meet the applicable standards for a free, specific, informed, unconditional and unambiguous indication through clear affirmative action. The substantive Digital Personal Data Protection Act provisions follow the Government’s notified phased commencement schedule. (official Digital Personal Data Protection Act, 2023, official commencement notification)
16. No bundled unrelated consent
Permission to receive one type of communication should not automatically authorize materially unrelated communications.
For example:
- webinar reminder consent does not automatically mean cRUD promotional marketing consent;
- cookie consent does not automatically mean email marketing consent.
17. Consent records
Where appropriate, cRUD may retain evidence of consent or acknowledgement.
A record may include:
- user identifier;
- email address;
- Organization identifier;
- consent category;
- purpose;
- consent wording/version;
- Privacy Policy version;
- Terms version;
- timestamp;
- source;
- withdrawal date;
- re-consent date.
18. Why consent evidence is retained
Consent records may be retained to demonstrate:
- what permission was given;
- when it was given;
- what wording applied;
- whether and when it was later withdrawn.
19. Withdrawal of marketing consent
Users may withdraw permission for optional cRUD marketing through:
- unsubscribe links;
- communication-preference settings;
- Account settings;
privacy@thecrudcompany.com.
Where India’s statutory consent-withdrawal rules apply, withdrawal must be available with ease comparable to giving consent and should stop future processing that depended on the withdrawn consent, subject to applicable lawful grounds. (official Digital Personal Data Protection Act, 2023)
20. Effect of withdrawal
Withdrawal applies prospectively.
It does not make previous lawful communications improper.
21. Unsubscribe
Promotional communications should include a reasonable unsubscribe mechanism where appropriate.
22. Suppression
When a user unsubscribes, cRUD may place the address on a suppression list.
The suppression record may be retained so that the user is not accidentally re-added to optional marketing.
23. Suppression is not Account deletion
Unsubscribing from marketing does not:
- delete the Account;
- cancel a Subscription;
- delete webinar registrations;
- stop essential operational communications.
24. Re-subscription
A user who previously unsubscribed may later choose to opt back into marketing.
This new action should be recorded as a new consent event.
25. Re-consent
Where cRUD introduces a materially new communication purpose requiring consent, cRUD may request new consent.
Existing consent should not automatically be expanded to unrelated uses.
26. Communication preference center
Where available, users should be able to manage communication preferences through product settings.
Potential controls may include:
- cRUD marketing;
- newsletters;
- product announcements;
- communication categories.
27. Mandatory communication categories
Certain categories may not be switchable because they are necessary for:
- security;
- billing;
- account administration;
- requested webinar activity;
- legal notices.
28. Webinar organizer communications
cRUD Webinar allows Customers to communicate with:
- registrants;
- attendees;
- speakers;
- hosts;
- other webinar participants.
29. Organizer responsibility
The webinar organizer is responsible for ensuring that communications it sends through cRUD are lawful.
This includes responsibility for:
- recipient eligibility;
- required consent;
- lawful basis;
- privacy notice;
- unsubscribe requirements;
- suppression requirements.
30. cRUD is not the organizer’s blanket consent source
A person registering through cRUD does not automatically consent to every future promotional communication from the organizer.
The organizer must independently ensure that its use is lawful.
31. Webinar registration confirmation
A registration confirmation is generally an operational/transactional message connected to the attendee’s requested registration.
32. Webinar reminders
Webinar reminders may include:
- event date/time;
- access link;
- schedule changes;
- preparation information.
These are ordinarily related to the registered webinar.
33. Rescheduling notices
Where a webinar is rescheduled, the organizer may send an operational notification to affected registrants.
34. Cancellation notices
Where a webinar is cancelled, registered attendees may receive cancellation information.
35. Replay notices
Where replay access is part of the webinar experience, replay availability notices may be treated as webinar lifecycle communications.
36. Missed-you communications
A webinar organizer may send follow-up to a registrant who did not attend where such communication is reasonably related to the registered event and lawful.
37. Speaker communications
Speakers may receive communications concerning:
- invitation;
- rehearsal;
- backstage access;
- event timing;
- recording;
- event changes.
These are operational event communications.
38. Host and moderator communications
Hosts and moderators may receive operational messages needed to manage the event.
39. Customer marketing through cRUD
Customers may use cRUD communication functionality for marketing where such use is:
- permitted by the product;
- lawful;
- consistent with applicable consent and suppression obligations.
40. Spam prohibited
Customers must not use cRUD to send:
- unlawful spam;
- purchased lists without appropriate authority;
- deceptive communications;
- phishing;
- repeated unwanted communications.
Such activity may violate the Acceptable Use Policy.
41. List provenance
cRUD may ask a Customer to explain how a communication list was obtained.
This may occur where we observe:
- high complaint rates;
- bounce rates;
- suspicious import patterns;
- spam reports.
42. Purchased lists
Use of purchased or third-party contact lists may be restricted where the Customer cannot demonstrate lawful authority to communicate with those recipients.
43. Imported contacts
Customers importing contacts remain responsible for:
- lawful collection;
- permitted use;
- communication authority.
44. Public email addresses
The fact that an email address is publicly visible does not automatically mean the person has consented to marketing.
45. Unsubscribe handling for organizer campaigns
Where cRUD provides unsubscribe functionality for Customer marketing, Customers must not deliberately bypass it.
46. Re-adding unsubscribed recipients
Customers must not deliberately re-add a recipient to optional marketing after that recipient has opted out, unless a new valid consent or lawful basis applies.
47. Suppression enforcement
cRUD may maintain platform-level suppression controls to help prevent repeated sending to addresses that:
- unsubscribed;
- complained;
- bounced permanently.
48. Customer suppression lists
Where applicable, Customers may maintain organization-specific suppression preferences.
49. cRUD marketing and organizer marketing are separate
A user can:
- opt out of cRUD marketing;
- still receive organizer communications where lawful;
and vice versa.
50. Communication sender identities
cRUD Webinar may use product-specific automated sender addresses.
Current automated sender identities include:
communication@crudwebinar.comnotification@crudwebinar.com
These are automated outbound sender identities.
51. Automated sender addresses are not support channels
Users should not rely on automated sender addresses for:
- legal notices;
- privacy requests;
- support complaints.
Relevant contact channels include:
support@thecrudcompany.comprivacy@thecrudcompany.comgrievance@thecrudcompany.com
52. Sender identity
cRUD may send messages using sender identities appropriate to:
- product;
- communication type;
- customer configuration.
53. Customer sender identity
Where Customers can configure sender details, they must not:
- impersonate another brand;
- misrepresent affiliation;
- use unauthorized domains;
- engage in phishing.
54. Sender verification
Where supported, cRUD may require verification of:
- sending domain;
- sender identity;
- business relationship.
55. Email authentication
cRUD may use technologies such as:
- SPF;
- DKIM;
- DMARC
to improve sender authentication and reduce spoofing risk.
56. Deliverability
cRUD does not guarantee that every legitimate email will reach every recipient inbox.
Delivery may depend on:
- recipient provider;
- spam filtering;
- sender reputation;
- domain reputation;
- recipient settings.
57. Bounce handling
cRUD may process:
- hard bounces;
- soft bounces;
- invalid-address signals
to improve deliverability and prevent repeated failed sending.
58. Complaint handling
Email providers or recipients may generate spam-complaint signals.
cRUD may use such information to:
- suppress future sending;
- investigate abuse;
- protect sender reputation.
59. Email open tracking
Where supported, email systems may report open events.
Such information may be technically unreliable because of:
- image blocking;
- privacy relays;
- automated preloading.
We should not represent open data as definitive proof that a human read a message.
60. Link tracking
Where supported, link interaction may be recorded.
Where such tracking involves personal data, it is governed by our Privacy Policy.
61. Operational email analytics
Certain delivery data may be processed even where optional marketing analytics are disabled because it is necessary for:
- bounce management;
- complaint handling;
- security;
- deliverability.
62. SMS or other channels
If cRUD later introduces:
- SMS;
- WhatsApp;
- push notifications;
- other channels,
the same principles apply.
Additional channel-specific consent may be required.
Before enabling commercial SMS or voice communications in India, cRUD and the relevant Organizer must separately assess and implement the then-current Telecom Commercial Communications Customer Preference Regulations framework. This Policy alone does not authorize telecommunications marketing. (official TRAI TCCCPR framework)
63. WhatsApp
Use of WhatsApp or equivalent third-party messaging for Customer communications must comply with:
- applicable law;
- platform rules;
- appropriate consent requirements.
64. Push notifications
If introduced, push notifications may be controlled through:
- device permission;
- product preference settings.
65. In-product notifications
cRUD may provide:
- dashboard alerts;
- in-app banners;
- system notifications.
These may be necessary to communicate product state or security information.
66. Legal notices in product
Material legal notices may be delivered through:
- email;
- Account banner;
- login screen;
- dashboard notification.
67. Material Terms changes
Where Terms materially change, cRUD may require users to re-accept the updated Terms before continuing to use affected functionality.
68. Privacy-policy changes
A Privacy Policy update does not automatically require new consent.
Where a materially new processing purpose requires consent, cRUD will obtain that consent separately where required.
69. Communications-policy changes
Material changes to optional communication practices may require:
- notice;
- new preference;
- re-consent.
70. Notice versioning
Where meaningful, cRUD may store the version of:
- consent wording;
- communication notice;
- relevant policy
shown to a user.
71. Account communications
Account holders may receive:
- signup verification;
- security;
- access;
- product operation;
- legal notices.
72. Account inactivity notices
If cRUD introduces inactive-account deletion or restriction, users may receive advance notice before action is taken.
73. Suspension notices
Where appropriate and legally permissible, users may receive notice concerning:
- suspension;
- reason category;
- appeal route.
74. Immediate enforcement
For serious abuse, cRUD may suspend or terminate first and send notice afterward where prior notice would:
- increase risk;
- compromise security;
- permit continued abuse.
75. Billing communications
Billing communications may include:
- invoices;
- payment failures;
- renewal;
- refund;
- cancellation.
These are not optional marketing.
76. Refund communications
Users may receive communications required to process or confirm:
- refund request;
- refund decision;
- refund completion.
77. Event Pass communications
cRUD does not sell tickets to Attendees. An Organizer buying Event Passes may receive:
- a quotation or invoice;
- payment reminders;
- confirmation of allocation;
- event changes;
- cancellation or refund notices.
78. Privacy communications
cRUD may communicate regarding:
- privacy request;
- identity verification;
- deletion request;
- breach notification;
- consent change.
79. Security incident notifications
Where legally or contractually required, affected users or Customers may receive communications concerning security incidents.
80. Grievance communications
A complainant may receive:
- acknowledgement;
- request for information;
- outcome;
- escalation information.
81. Copyright communications
Rights holders or affected users may receive communications concerning:
- takedown complaint;
- additional evidence;
- content restriction;
- restoration.
82. Government-request related communications
Where legally permitted, cRUD may notify Customers regarding governmental requests affecting their data.
83. No guarantee of notice where prohibited
cRUD may be legally prohibited from informing a user about certain governmental requests or investigations.
84. Preference records
Communication preferences may be stored as:
- enabled;
- disabled;
- consent granted;
- consent withdrawn;
- suppressed.
85. Event-based consent history
Rather than simply overwriting a single Boolean field, cRUD should retain event history such as:
- consent granted;
- consent withdrawn;
- consent granted again.
86. Historical evidence
Historical consent evidence should not be used to continue marketing after the active consent has been withdrawn.
87. Data retention
Communication and consent records are retained as described in this Policy, the Privacy Policy, applicable law and cRUD's applicable retention practices.
88. Consent minimization
cRUD should not retain unnecessary technical evidence merely because consent occurred.
The record should be proportionate to demonstrating what happened.
89. IP addresses
An IP address may be retained where justified as part of technical or security evidence.
However, we do not need to make IP address the primary evidence of consent.
90. Stronger consent evidence
More useful consent evidence includes:
- Account/user;
- exact consent;
- purpose;
- wording version;
- timestamp;
- source.
91. Organizational communications
Organization administrators may receive communications concerning:
- membership;
- security;
- billing;
- organization state;
- webinars.
92. Organization-wide notices
Material Organization-level changes may be sent to:
- owner;
- administrator;
- billing contact.
93. Customer responsibility for internal forwarding
cRUD cannot guarantee that an Organization administrator will internally forward every notice to its employees.
94. Contact accuracy
Users are responsible for maintaining a valid email address associated with their Account.
95. Email change
If a user changes email address, communication preferences and account identity should be updated appropriately.
96. Suppression after email change
A historical suppression record may not automatically apply to an entirely different individual using a recycled address.
Where such edge cases arise, cRUD may review available information.
97. Shared business email addresses
Some Organizations may use shared mailboxes.
The Organization is responsible for determining who can access such communications.
98. Role-based aliases
cRUD may communicate with role addresses such as:
- billing;
- support;
- legal
where provided by a Customer.
99. No guarantee of delivery to role aliases
The recipient Organization remains responsible for monitoring its designated contact addresses.
100. Marketing frequency
cRUD may control marketing frequency to avoid unnecessary excessive communications.
101. Frequency preferences
Where supported, users may be able to choose:
- all announcements;
- occasional updates;
- reduced frequency.
102. Marketing segmentation
Where lawful, cRUD may tailor optional marketing based on:
- product used;
- Organization type;
- prior engagement;
- communication preferences.
103. No sensitive profiling for marketing without appropriate basis
cRUD should not use highly sensitive information for unrelated promotional targeting without appropriate legal basis and safeguards.
104. Webinar engagement and organizer follow-up
A webinar Organizer may use attendee engagement data for follow-up where lawful.
That processing is governed by the Organizer’s own privacy responsibilities.
105. cRUD does not automatically market based on Customer webinar content
Participation in a Customer webinar does not automatically give cRUD permission to use the attendee for unrelated cRUD marketing.
106. Cross-product marketing
If a user consents to The cRUD Company marketing, the applicable consent wording may cover updates regarding:
- cRUD Webinar;
- cRUD Collab;
- other cRUD products
only where this scope is clearly disclosed.
107. Narrow marketing consent
If the wording references only cRUD Webinar, it should not silently be treated as unlimited consent to every future company product.
108. Company-level consent
A broader consent may expressly say:
“The cRUD Company and its products.”
This provides clearer cross-product scope.
109. Recommended company-level wording
If you want one optional consent covering the brand family, use:
I would like to receive product news, educational content, offers and updates from The cRUD Company about cRUD products and services. I can unsubscribe at any time.
110. No third-party marketing sale
cRUD does not intend to sell marketing permission to unrelated third parties.
111. Partner marketing
If joint or partner marketing is introduced, it should be separately disclosed where appropriate.
112. Sponsored content
Participation in a sponsored webinar does not automatically mean a user has consented to every sponsor’s future marketing.
The organizer/sponsor remains responsible for lawful collection and disclosure.
113. Co-hosted webinars
Where multiple Organizations jointly collect attendee information, they should disclose their roles appropriately.
114. Organizer-provided privacy notice
cRUD Webinar should allow organizers to provide:
Organizer Privacy Policy URL
where applicable.
115. Registration consent fields
An Organizer may add its own lawful consent checkbox to a registration form.
Such consent belongs to the Organizer, not automatically to cRUD.
116. cRUD legal acknowledgement
cRUD may separately display:
- cRUD Privacy Policy;
- cRUD platform notices.
117. Distinguishing checkboxes
A registration form should avoid ambiguous text like:
“I agree to everything.”
Where multiple parties seek consent, the purposes should be clear.
118. Required event communications
An attendee may need to provide an email address in order to receive:
- access link;
- registration confirmation.
If the user refuses necessary communication processing, the requested registration functionality may not be possible.
119. Optional organizer marketing
Organizer promotional follow-up should be separately handled where required.
120. Consent withdrawal after webinar
A user may withdraw optional marketing permission after a webinar without losing historical attendance records that remain lawfully retained.
121. Transactional message suppression
Users generally cannot suppress essential transactional messages while continuing to request the transaction requiring those messages.
122. Legal notices
Where law requires notice, cRUD may send it despite ordinary marketing preferences.
123. Abuse investigation messages
cRUD may contact users regarding suspected policy violations.
Such communication is not marketing.
124. Communication security
cRUD may avoid including highly sensitive information directly in email where a secure in-product mechanism is more appropriate.
125. Password reset links
Password reset communications should use appropriately:
- expiring;
- secure;
- single-use or appropriately controlled
mechanisms.
126. Unique webinar links
Unique attendee or speaker access links should be treated as sensitive access information.
Recipients should avoid forwarding them.
127. Sensitive email forwarding
Users remain responsible for controlling access to their own mailboxes.
128. Spoofing awareness
Users should be cautious of messages pretending to be cRUD.
Official legal/support domains should be clearly documented.
129. Official company communication domains
Current company-level contacts use:
@thecrudcompany.com
130. Product automated communication domain
cRUD Webinar automated messages may use:
@crudwebinar.com
131. Official contact distinction
Legal/privacy/support communications should ordinarily be routed through the publicly listed company contact addresses rather than automated sender mailboxes.
132. Communication authenticity
Where available, email-authentication technologies may help recipients identify legitimate messages.
133. Phishing reporting
Suspicious messages claiming to be from cRUD may be reported to:
134. Marketing complaints
Unwanted cRUD marketing may be reported to:
135. Spam or abuse complaints
Abusive messages sent through cRUD Webinar may be reported to:
136. Support
General communication issues may be sent to:
137. Grievance escalation
Unresolved communication complaints may be escalated according to:
https://www.thecrudcompany.com/trust-center/grievance-complaint-redressal-policy
138. Privacy rights
Communication consent and withdrawal requests may also be submitted to privacy@thecrudcompany.com.
139. Privacy Policy
Personal data processing associated with communications is governed by:
https://www.thecrudcompany.com/trust-center/privacy-policy
140. Cookie Policy
Cookie and browser tracking preferences are governed separately by:
https://www.thecrudcompany.com/trust-center/cookie-policy
141. Acceptable Use Policy
Prohibited communication behavior is governed by:
https://www.thecrudcompany.com/trust-center/acceptable-use-policy
142. Changes to this Policy
We may update this Policy due to:
- new communication channels;
- legal changes;
- consent changes;
- product changes;
- sender architecture;
- marketing changes.
143. Material changes
Where a material change expands optional communication purposes, cRUD may:
- notify affected users;
- obtain new consent where appropriate.
144. No retrospective consent expansion
A policy update alone should not be treated as consent to a materially new purpose where new consent is legally required.
145. Versioning
Each material version will identify:
- version number;
- effective date;
- last updated date.
Canonical:
https://www.thecrudcompany.com/trust-center/communications-consent-policy
The cRUD Webinar app must not render or store a duplicate copy. Every in-app reference must open this canonical website URL in a new browser tab; any retired app legal route may redirect here but must not host this Policy.
146. Contact information
Privacy / consent
Grievances / abuse
Support
Legal
General
147. Company details
CRUD INFOSYSTEMS PRIVATE LIMITED Operating under the brand name The cRUD Company
Unit 101, OXFORD TOWERS 139, HAL Old Airport Road Kodihalli, Bengaluru, Karnataka 560008 India
This document is published by CRUD INFOSYSTEMS PRIVATE LIMITED, Unit 101, Oxford Towers, 139 HAL Old Airport Road, Kodihalli, Bengaluru, Karnataka 560008, India.
Return to Trust Center.