Privacy Policy
1. Introduction
This Privacy Policy explains how CRUD INFOSYSTEMS PRIVATE LIMITED, operating under the brand name The cRUD Company (“The cRUD Company”, “cRUD”, “Company”, “we”, “us” or “our”), collects, uses, stores, shares, protects and otherwise processes personal data in connection with our websites, applications, products and services.
Our current products include:
- cRUD Webinar; and
- other services expressly referring to this Privacy Policy.
Our registered office is:
CRUD INFOSYSTEMS PRIVATE LIMITED Unit 101, OXFORD TOWERS 139, HAL Old Airport Road Kodihalli, Bengaluru, Karnataka 560008 India
Privacy enquiries and Data Principal requests
General enquiries
Grievances
Security reports
This Privacy Policy should be read together with our:
- Terms of Service;
- Acceptable Use Policy;
- Cookie Policy;
- Communications & Consent Policy;
- Subprocessor List;
- Data Retention & Deletion Policy; and
- any additional notice presented when particular personal data is collected.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed by cRUD when you:
- visit The cRUD Company website;
- create a cRUD account;
- create or administer an Organization;
- use cRUD Webinar;
- register for a webinar operated using cRUD Webinar;
- attend or participate in a webinar;
- act as a host, speaker, moderator or organizer;
- communicate using webinar chat, Q&A, polls, surveys or other engagement tools;
- view a webinar recording or replay;
- receive communications sent by or through cRUD;
- subscribe to our communications;
- purchase or use a paid cRUD service;
- contact support;
- submit a privacy, legal, copyright, security or grievance request;
- interact with integrations or services connected to cRUD;
- otherwise interact with a service expressly covered by this Privacy Policy.
It applies to digital personal data processed by us and, where applicable, personal data initially collected offline and subsequently digitized.
3. Important distinction: cRUD as Data Fiduciary and service provider
The role cRUD plays depends on the circumstances.
3.1 Where cRUD determines the purpose and means of processing
For certain activities, cRUD determines why and how personal data is processed.
Examples include:
- creating and administering your cRUD Account;
- account authentication;
- security and fraud prevention;
- subscription administration;
- billing administration;
- cRUD's own product communications;
- cRUD marketing, where permitted;
- website analytics;
- support;
- compliance;
- handling privacy requests;
- maintaining cRUD operational records.
For these activities, cRUD generally acts as the organization responsible for determining the relevant processing purposes.
Under Indian data-protection terminology, this may make cRUD the Data Fiduciary for that processing.
3.2 Where a cRUD customer determines the purpose of processing
cRUD Webinar allows customers and webinar organizers to collect and process information about their own:
- registrants;
- attendees;
- prospects;
- customers;
- employees;
- partners;
- speakers;
- communities;
- event participants.
For example, a webinar organizer may decide:
- what registration fields to request;
- why those fields are collected;
- which audience to invite;
- who is admitted;
- what polls are conducted;
- what survey questions are asked;
- whether a webinar is recorded;
- what follow-up communications are sent;
- which CRM or marketing platform receives the information.
In these circumstances, the customer or webinar organizer may be responsible for determining the purpose of processing, while cRUD provides the technology used to process that information.
Where applicable, this relationship may also be governed by a separate Data Processing Agreement provided by cRUD.
If you are a webinar attendee and have a question regarding how a particular organizer uses your personal data, you may need to contact that organizer directly.
cRUD will provide reasonable assistance where legally required and technically possible.
4. Meaning of personal data
For purposes of this Policy, personal data means data about an identifiable individual, including where applicable digital personal data covered by applicable data-protection law.
Personal data does not necessarily need to include someone's name.
Information may become personal data where it can reasonably be connected to an identifiable individual.
5. Categories of personal data we may process
The actual information processed depends upon how you interact with cRUD.
We do not necessarily collect every category below from every person.
5.1 Account and identity information
We may process:
- name;
- email address;
- username;
- account identifier;
- profile photograph;
- avatar;
- pronouns, where voluntarily provided;
- timezone;
- preferred language;
- authentication status;
- account verification status;
- Organization membership;
- account roles;
- account status.
6. Authentication and security information
We may process information associated with authentication and account protection, including:
- password-related authentication records;
- password hashes where applicable;
- verification records;
- authentication tokens;
- session identifiers;
- passkey/WebAuthn information;
- login history;
- session history;
- security events;
- revoked sessions;
- authentication failures;
- device/session information.
We do not intentionally store passwords in readable plaintext.
7. Organization and business information
Where you use cRUD on behalf of an Organization, we may process:
- Organization name;
- company website;
- business domain;
- business email domain;
- Organization logo;
- workspace;
- business contact details;
- role within the Organization;
- Organization membership;
- account permissions;
- billing contact;
- Organization administrator information;
- invitation status;
- Organization activity.
8. Webinar information
When a webinar is created or operated, we may process information such as:
- webinar title;
- description;
- date;
- time;
- timezone;
- duration;
- hosts;
- speakers;
- moderators;
- workspace;
- webinar status;
- webinar visibility;
- registration configuration;
- webinar capacity;
- branding;
- webinar pages;
- media;
- resources;
- recordings;
- replay configuration.
Where this information identifies an individual, it may constitute personal data.
9. Registration information
A webinar organizer may configure registration fields.
Accordingly, information collected from registrants may include:
- name;
- email address;
- company;
- job title;
- industry;
- company size;
- country;
- city;
- language;
- timezone;
- business domain;
- custom responses;
- questions selected by the webinar organizer;
- communication preferences;
- marketing consent;
- terms acknowledgements;
- source/attribution information.
The fields requested for one webinar may be different from those requested for another.
Webinar organizers are responsible for ensuring they collect only information they are lawfully entitled to collect.
cRUD may place limits on registration fields where necessary for privacy, security, safety or compliance.
10. Registration and audience-management signals
cRUD Webinar may process information required for audience qualification, registration management and access control.
Depending on functionality enabled, this may include:
- registration status;
- approval status;
- rejection status;
- waitlist status;
- business-email classification;
- domain classification;
- disposable-email indicators;
- personal-email-domain indicators;
- competitor-domain indicators configured by customers;
- Organization allowlists;
- Organization blocklists;
- registration source;
- invitation status;
- capacity status;
- access eligibility;
- verification status.
Where cRUD provides automated assistance, scoring or classification, those signals may be derived from information provided by users, organizers or relevant technical systems.
11. Webinar attendance information
When you attend a webinar, we may process:
- registration identifier;
- attendee identifier;
- join time;
- leave time;
- waiting-room activity;
- attendance status;
- attendance duration;
- watch time;
- access-link status;
- replay access;
- session state;
- device/browser information;
- webinar access events.
This information may be used to operate the webinar and produce analytics for the organizer.
12. Engagement information
If you interact with webinar functionality, we may process:
- chat messages;
- Q&A questions;
- Q&A votes;
- poll responses;
- survey responses;
- reactions;
- resource downloads;
- CTA interactions;
- request-to-join events;
- participation activity;
- engagement timestamps;
- engagement duration;
- replay engagement.
Webinar organizers may receive reports containing some or all of this information.
You should therefore not assume that your interaction with a webinar is anonymous unless the interface expressly states that it is anonymous.
13. Speaker, host and moderator information
We may process:
- name;
- email;
- biography;
- job title;
- company;
- profile photograph;
- speaker invitation status;
- speaker access information;
- participation status;
- readiness checks;
- media/device information;
- stage activity;
- presentation activity;
- recordings containing the speaker's voice or image.
14. Audio, video and recordings
Where webinar functionality includes live media or recording, we may process:
- audio;
- video;
- screen-sharing content;
- presentation content;
- participant image or voice;
- recording files;
- recording metadata;
- replay content;
- transcription data, if transcription functionality is offered and enabled.
Whether a particular webinar is recorded should be disclosed to participants through appropriate notices or controls.
Webinar organizers are responsible for obtaining any additional permissions required for their particular use of a recording.
15. Uploaded content and files
Users may upload or provide:
- images;
- logos;
- avatars;
- webinar banners;
- presentation files;
- videos;
- downloadable resources;
- documents;
- recordings;
- profile photographs;
- other media.
Such content may contain personal data.
Customers should avoid uploading personal data that is unnecessary for the intended purpose.
16. Communications information
We may process information relating to communications, including:
- email address;
- communication type;
- delivery status;
- sending timestamp;
- bounce status;
- complaint status;
- suppression status;
- unsubscribe status;
- marketing preference;
- delivery provider information;
- communication engagement where supported;
- notification settings.
The cRUD Webinar platform may also process communications sent by webinar organizers to their audiences.
17. Support and correspondence
When you contact us, we may process:
- your name;
- email address;
- Organization;
- support request;
- complaint;
- correspondence;
- attachments;
- screenshots;
- diagnostic information;
- support history;
- resolution information.
Please avoid submitting unnecessary sensitive personal information in support requests.
18. Billing and transaction information
Where paid functionality is used, we may process:
- customer name;
- billing address;
- billing email;
- company name;
- plan;
- subscription status;
- invoice information;
- bank transfer or UPI references;
- payment status;
- taxes;
- credits;
- refunds;
- unpaid or overdue invoice information.
Payments to cRUD are made by bank transfer or UPI against an invoice. We do not use a payment processor and do not collect payment-card details.
We may process the payer name and bank transfer or UPI reference that accompany a payment in order to match it to the correct invoice.
19. Device and technical information
When you access our Services, we may automatically receive certain technical information such as:
- IP address;
- browser;
- operating system;
- device category;
- language;
- timezone;
- referring page;
- requested URL;
- access timestamp;
- session information;
- application version;
- diagnostic information;
- network information;
- error information.
If a visitor accepts analytics, we use Google Analytics 4 through Google Tag Manager to measure website use. The information may include pseudonymous analytics identifiers, page views, a controlled version of the current page address, approved campaign parameters, referrer information, browser and device information, approximate location and supported interaction events.
Google Analytics is not loaded if the visitor rejects analytics or does not make a choice.
Our current-page configuration removes URL fragments and arbitrary query parameters before sending the page address to Google Analytics. Only the approved campaign parameters identified in our Cookie Policy may be retained. These campaign parameters must not contain personal or confidential information.
Google may process an Internet Protocol address to determine approximate location and route the analytics request. Google states that the individual IP address is discarded before the analytics information is logged.
Site-search measurement, automatic form-interaction measurement, Google Signals and advertising personalisation are disabled.
20. Logs, security and anti-abuse information
We may generate or receive:
- access logs;
- system logs;
- security logs;
- authentication logs;
- request identifiers;
- activity history;
- audit logs;
- rate-limit information;
- suspected fraud indicators;
- abuse reports;
- malware/security indicators;
- account-risk signals;
- enforcement history.
Certain ICT logs may need to be retained in accordance with applicable cybersecurity obligations. CERT-In's directions require covered entities to maintain specified ICT-system logs securely for a rolling period of 180 days and include obligations concerning specified cyber incidents. (CERT-IN)
21. Cookies and similar technologies
We may use:
- cookies;
- local storage;
- session storage;
- authentication technologies;
- similar browser technologies.
They may be used for:
- authentication;
- security;
- session management;
- preferences;
- functionality;
- analytics;
- remembering choices;
- fraud prevention;
- performance.
The company website uses a necessary browser-local entry to remember the visitor's analytics choice.
Visitors can accept or reject analytics and can change that decision through the permanent Cookie settings control in the website footer.
Rejecting analytics does not prevent access to the website. Google Tag Manager and Google Analytics remain unloaded, and no Google Analytics session or interaction event is recorded.
Some functional processing may still take place when necessary to provide the website or a function the visitor chooses to use. This includes website hosting, email-domain validation, form delivery and embedded content selected by the visitor.
Current website technology providers:
| Provider or service | Website purpose | Information involved | When activated |
|---|---|---|---|
| Google Firebase Hosting | Website hosting, content delivery and security | Requested address and normal web-request information, which may include IP address, browser information and request headers | When any website page or asset is requested |
| Google Tag Manager | Delivery of the configured analytics tag | Consent state and configured analytics information | Only after analytics consent |
| Google Analytics 4 | Website measurement | Pseudonymous identifiers, controlled page address, approved campaign parameters, referrer, browser and device information, approximate location and supported interaction events | Only after analytics consent |
| Web3Forms | Delivery of website form submissions | Form fields deliberately submitted by the visitor and normal request information | When a visitor submits a supported form |
| GitHub Pages domain-intelligence data | Email-domain validation | A short hash-derived shard request and normal connection information. Not the complete email address, email local part, full domain name or complete domain hash | When email-domain validation runs |
| YouTube and associated Google content services | Video thumbnail and privacy-enhanced video playback | Normal connection information and information associated with requested video playback | When a published thumbnail is displayed or a visitor chooses to play a video |
This inventory should be reviewed whenever a website technology is added, removed or materially reconfigured.
Further information will be provided at:
https://www.thecrudcompany.com/trust-center/cookie-policy
22. Information obtained from customers and other users
Not all information we process is supplied directly by the individual concerned.
For example:
- an Organization administrator may invite you;
- a webinar organizer may import a registrant list;
- another user may identify you as a speaker;
- an employer may provide your professional contact information;
- a customer may synchronize information from its CRM;
- a user may submit information about another person in a complaint.
The customer supplying information is responsible for having appropriate authority to do so.
23. Information from integrations
Where a customer enables an integration, cRUD may exchange information with the selected third-party service.
Potential categories include:
- CRM records;
- marketing-system identifiers;
- contact records;
- account information;
- webinar registration;
- attendance;
- engagement;
- replay activity.
The actual integrations available may change over time.
A provider appearing in product plans or technical architecture should not be interpreted as confirmation that the provider is currently enabled in production. This matches cRUD's existing rule that planned/provider abstractions must not be represented externally as production-verified capabilities.
24. Why we process personal data
We process personal data only for identified purposes and in accordance with applicable law.
The purposes below depend upon the relevant interaction.
24.1 Providing the Service
We may process information to:
- create Accounts;
- authenticate users;
- create Organizations;
- administer workspaces;
- create webinars;
- register attendees;
- approve registrations;
- provide attendee access;
- operate live webinars;
- enable speaker access;
- provide engagement functionality;
- record webinars;
- provide replays;
- generate reports;
- send requested communications;
- provide integrations;
- administer subscriptions;
- provide support.
24.2 Account authentication and security
We may process information to:
- verify email addresses;
- authenticate logins;
- prevent unauthorized access;
- revoke sessions;
- detect compromised accounts;
- prevent credential abuse;
- protect tenants;
- investigate suspicious activity.
24.3 Webinar administration
Information may be processed to:
- identify registrants;
- manage capacity;
- manage waitlists;
- provide invitations;
- approve or reject registration;
- generate access links;
- prevent unauthorized access;
- operate waiting rooms;
- manage attendees.
25. Analytics and reporting
We may process webinar activity to provide customers with analytics such as:
- registrations;
- attendance;
- no-shows;
- watch time;
- engagement;
- polls;
- questions;
- chat activity;
- resource engagement;
- CTA activity;
- replay activity;
- source attribution.
Certain analytics may relate to identifiable attendees.
26. Audience and engagement intelligence
Where enabled, cRUD Webinar may analyze first-party webinar activity to generate audience or engagement signals.
Potential inputs may include:
- attendance;
- watch time;
- repeat attendance;
- poll participation;
- questions;
- CTA interactions;
- resource downloads;
- replay activity;
- registration information.
These signals may help webinar organizers identify:
- engaged attendees;
- interested accounts;
- relevant topics;
- follow-up opportunities.
Where such functionality materially affects individuals, we will design and operate it in accordance with applicable privacy obligations.
The product roadmap contemplates explainable audience and buying-intent intelligence rather than opaque unsupported conclusions.
27. Communications
We process contact information to send communications necessary to operate the Service.
These may include:
- account verification;
- password reset;
- authentication notices;
- security alerts;
- webinar confirmations;
- invitations;
- reminders;
- rescheduling notices;
- cancellations;
- replay notices;
- billing notices;
- support responses;
- policy updates;
- enforcement notices.
These are generally referred to as operational or service communications.
28. Marketing communications
Separately, where permitted and where required with your consent, we may send:
- product announcements;
- newsletters;
- promotional campaigns;
- offers;
- cRUD educational content;
- invitations;
- information about additional cRUD products.
Marketing preferences will be treated separately from essential operational communications.
Declining or withdrawing optional marketing communications will not prevent us from sending communications required to:
- operate your Account;
- deliver a requested Service;
- protect security;
- fulfil a transaction;
- provide legal notices.
Further information will be available in our Communications & Consent Policy.
29. Customer support
We may process information to:
- diagnose problems;
- respond to enquiries;
- resolve support requests;
- investigate product failures;
- provide assistance;
- communicate resolutions.
30. Billing and administration
We may process information to:
- manage subscriptions;
- issue invoices;
- process payments;
- administer refunds;
- detect payment fraud;
- maintain accounting records;
- comply with tax and corporate-record requirements.
31. Security, fraud prevention and abuse prevention
We may process information to:
- identify abuse;
- prevent spam;
- detect fraud;
- investigate suspicious behavior;
- prevent phishing;
- prevent malware;
- enforce the Acceptable Use Policy;
- protect children and vulnerable persons;
- investigate threats;
- prevent circumvention of account restrictions;
- protect cRUD infrastructure.
32. Legal and regulatory compliance
We may process information where necessary to:
- comply with legal obligations;
- respond to valid legal process;
- preserve records;
- address regulatory requests;
- investigate alleged violations;
- protect our rights;
- protect users;
- defend legal claims;
- cooperate with competent authorities where legally required.
33. Improving the Services
We may use information about product usage to:
- diagnose errors;
- understand feature usage;
- improve workflows;
- improve reliability;
- identify usability problems;
- develop new functionality.
Where reasonably practicable, improvement activities should use aggregated, de-identified or minimized information where identifiable personal data is not necessary.
34. Legal grounds and permissible processing
Depending on applicable law and circumstances, processing may occur:
- based upon valid consent;
- for purposes voluntarily requested by the individual;
- to provide a service or transaction requested by the individual;
- for specified legitimate uses permitted by applicable law;
- to comply with legal obligations;
- where processing is otherwise permitted under applicable law.
Under the DPDP Act, consent must meet statutory requirements, and the Act separately recognizes certain legitimate uses of personal data. (India Code)
We will not treat acceptance of this Privacy Policy as unrestricted consent to every possible use of personal data.
35. Consent
Where processing is based on consent, we seek to ensure that consent is:
- freely given where required;
- specific;
- informed;
- unambiguous;
- associated with identified purposes;
- capable of being withdrawn.
A request for consent should be presented in clear language and should not seek broader permission than is reasonably required for the stated purpose.
The DPDP framework requires notice describing the personal data and specified purposes and provides for withdrawal of consent with comparable ease to the manner in which consent was given. (India Code)
36. Consent records
Where appropriate, we may maintain evidence of consent or acknowledgement including:
- user identifier;
- email address at the time;
- Organization identifier;
- purpose;
- consent category;
- wording/version presented;
- Privacy Policy version;
- Terms version;
- timestamp;
- source;
- consent status;
- withdrawal timestamp;
- re-consent timestamp;
- other technical evidence reasonably necessary to demonstrate the transaction.
Such records help establish what a user agreed to and when.
37. Withdrawal of consent
Where processing relies on consent, you may withdraw that consent using:
- communication-preference controls;
- unsubscribe links;
- account settings;
- privacy controls;
- or by contacting
privacy@thecrudcompany.com.
Withdrawal applies prospectively.
It does not invalidate processing lawfully performed before withdrawal.
Withdrawal may affect functionality where the relevant personal data is necessary to provide a service requested by you.
38. Operational communications versus marketing communications
For clarity:
Operational communication
Examples include:
- account verification;
- password reset;
- security alerts;
- invoices;
- billing problems;
- webinar registration confirmation;
- host/speaker invitations;
- requested support;
- important Service changes;
- legal notices.
These communications are necessary or closely connected to operation of the Service.
Marketing communication
Examples include:
- promotions;
- newsletters;
- campaigns;
- optional product announcements;
- marketing invitations.
Marketing preferences will be managed separately.
39. Marketing opt-in
Where we request permission to send optional marketing, the user interface should provide a separate choice.
We do not intend to treat acceptance of the Terms as automatic blanket consent to cRUD promotional marketing.
Marketing consent should not be pre-selected where affirmative consent is required.
Users should be able to unsubscribe or change preferences using available controls.
40. How personal data is shared
We do not treat personal data as a commodity to be sold to advertisers.
We may share personal data only as reasonably necessary for the purposes described in this Policy, including with the parties below.
41. Customers and webinar organizers
Where you register for or attend a customer-operated webinar, information may be disclosed to that customer.
This can include:
- registration details;
- attendance;
- watch time;
- questions;
- poll responses;
- engagement;
- resource activity;
- CTA interactions;
- replay activity.
The organizer may use this information according to its own privacy notice and applicable law.
42. Organization administrators
Organization administrators may access information relating to users within their Organization, including:
- membership;
- activity;
- webinars;
- permissions;
- account status;
- analytics;
- billing;
- content.
43. Service providers and subprocessors
We may engage service providers for functions including:
- hosting;
- databases;
- storage;
- live audio/video;
- email delivery;
- authentication;
- payments;
- monitoring;
- analytics;
- security;
- customer support;
- communications;
- infrastructure.
These providers should receive information only to the extent appropriate for the service they perform and subject to applicable contractual safeguards.
Information about relevant service providers and subprocessors may be provided by cRUD where applicable.
44. Integrations selected by customers
Where a Customer chooses to connect a third-party integration, information may be transferred to or received from that provider.
Examples may include CRM, marketing automation or other workflow systems.
The Customer is responsible for selecting and configuring its integrations appropriately.
45. Corporate transactions
If cRUD undergoes or evaluates:
- merger;
- acquisition;
- restructuring;
- financing;
- sale of assets;
- insolvency;
- transfer of a product or business,
relevant information may be disclosed to professional advisers, counterparties or successors subject to applicable confidentiality, privacy and legal requirements.
46. Professional advisers
Information may be shared where reasonably necessary with:
- lawyers;
- accountants;
- auditors;
- insurers;
- consultants;
subject to appropriate confidentiality obligations.
47. Governmental and legal disclosures
We may disclose personal data where:
- required by applicable law;
- required by valid legal process;
- required by a competent authority;
- reasonably necessary to protect users or others from serious harm;
- necessary to investigate fraud or cybercrime;
- necessary to establish, exercise or defend legal rights.
We do not intend to voluntarily provide unrestricted access to customer information merely because a third party requests it.
Further information may be published in our Government Request Policy.
48. No sale of personal data
cRUD does not sell personal data to advertisers or data brokers in exchange for monetary consideration as part of its ordinary business model.
If our business model materially changes in a manner that affects this statement, this Privacy Policy will be updated before such processing is implemented where required.
49. Advertising
cRUD may promote its own products and services.
If we later introduce third-party behavioural advertising or materially different advertising technology, we will update our privacy and cookie disclosures as necessary.
We will not silently represent an advertising model that does not currently exist.
50. International processing
cRUD may use technology and service providers operating in different jurisdictions.
Accordingly, personal data may potentially be processed outside the country in which the individual resides.
Any such transfers will be handled subject to applicable legal restrictions.
Under India's DPDP framework, the Central Government may restrict transfers of personal data to specified countries or territories. (India Code)
We will not make unsupported claims that all data is stored exclusively in India unless our verified production architecture supports that statement.
51. Data location and residency
The geographical location of data may depend upon:
- infrastructure provider;
- database location;
- storage configuration;
- live-media infrastructure;
- backup systems;
- customer-selected integration.
Where an enterprise customer requires specific data-residency commitments, these must be separately confirmed in writing.
This Policy does not by itself promise a particular data residency.
52. Data security
We use administrative, organizational and technical measures intended to protect personal data.
Depending upon the relevant system, these may include:
- access controls;
- authentication;
- authorization;
- tenant isolation;
- secure sessions;
- encryption;
- secure transmission;
- security logging;
- activity logging;
- rate limiting;
- secure storage;
- secret management;
- access revocation;
- backup/recovery measures;
- monitoring;
- vulnerability remediation;
- secure development practices.
The cRUD Webinar architecture is designed around server-side authorization, organization-based tenant isolation, row-level controls, secure attendee access and other security mechanisms.
However, no system connected to the Internet can guarantee absolute security.
53. Security responsibility of customers
Customers must also take reasonable security measures.
This includes:
- protecting credentials;
- maintaining secure email accounts;
- configuring permissions appropriately;
- removing former users;
- protecting attendee access links;
- avoiding unnecessary sharing;
- reviewing integrations;
- reporting compromised accounts.
54. Security incidents and personal-data breaches
If we become aware of a personal-data breach, we may:
- investigate the incident;
- contain affected systems;
- preserve relevant evidence;
- assess affected information;
- remediate vulnerabilities;
- notify affected customers or individuals where required;
- notify competent authorities where required;
- take additional protective measures.
The DPDP framework contains obligations relating to security safeguards and breach notification. (India Code)
Separate cybersecurity-reporting obligations may also apply under Indian law, including applicable CERT-In directions. (CERT-IN)
55. Data retention
We retain personal data only for as long as reasonably necessary for:
- providing the Services;
- fulfilling the purpose for which the information was collected;
- maintaining Account functionality;
- resolving disputes;
- enforcing agreements;
- security;
- fraud prevention;
- backups;
- accounting;
- taxation;
- legal obligations;
- regulatory requirements.
Different categories of information may have different retention periods.
56. Account data
Account information may ordinarily remain while an Account is active.
Following Account deletion or termination, information may be deleted, anonymized or retained for a limited period where required for:
- legal obligations;
- security;
- fraud prevention;
- billing;
- dispute resolution;
- backups;
- enforcement.
57. Webinar data
Retention of webinar information may depend upon:
- Customer configuration;
- Subscription;
- recording status;
- replay availability;
- Customer deletion;
- account termination;
- applicable contractual requirements.
Customers may be provided tools to delete relevant webinar information where technically supported.
58. Financial and statutory records
Certain financial, corporate, tax or transaction records may need to be retained for periods required under applicable law even after an Account is deleted.
Such records will not be retained merely for marketing use simply because they must remain available for statutory purposes.
59. Security logs
Security and ICT logs may be retained for periods necessary to:
- detect incidents;
- investigate abuse;
- prevent fraud;
- comply with cybersecurity requirements.
Applicable CERT-In directions currently prescribe a rolling minimum retention period of 180 days for specified ICT logs for covered entities. (CERT-IN)
60. Backups
Deletion from an active production system may not immediately remove information from all backup copies.
Information remaining in backups may continue until the relevant backup expires or is securely overwritten according to our technical retention cycle.
We will not intentionally restore deleted personal data for ordinary business use merely because an old backup contains it.
61. Detailed retention policy
Additional information about applicable retention and deletion practices may be provided by cRUD where appropriate.
Where a more specific written customer agreement provides different retention commitments, that agreement may control.
62. Your privacy rights
Depending upon applicable law and circumstances, you may have rights relating to personal data processed about you.
Under India's DPDP framework, Data Principals have statutory rights including access to information about personal data, correction and erasure, grievance redressal and nomination, subject to the Act's requirements and commencement framework. (India Code)
63. Access
Where applicable, you may request information concerning personal data processed about you, including information prescribed by applicable law.
64. Correction
You may request correction of inaccurate or misleading personal data.
You may also be able to update certain information directly through your Account.
65. Completion and updating
Where applicable, you may request that incomplete personal data be completed or updated.
66. Erasure
You may request deletion of personal data where applicable.
We may be unable to immediately erase information that must legitimately be retained because of:
- law;
- accounting;
- security;
- fraud prevention;
- dispute resolution;
- legal claims;
- another lawful retention requirement.
Where deletion cannot immediately be completed, we will handle the information consistently with the applicable retention purpose.
67. Withdrawal of consent
Where processing depends on consent, you may withdraw consent as explained above.
68. Marketing preferences
You may unsubscribe from optional cRUD marketing communications.
An unsubscribe from marketing does not prevent essential operational or legal communication.
69. Grievance redressal
If you have concerns regarding our handling of personal data, contact:
If the matter is not resolved to your satisfaction, you may use our grievance process:
Further details will be provided at:
https://www.thecrudcompany.com/trust-center/grievance-complaint-redressal-policy
Where applicable, you may also have rights to approach the competent authority or Data Protection Board under applicable law.
70. Nomination
Where applicable under Indian data-protection law, a Data Principal may have the right to nominate another individual to exercise specified rights in the event of death or incapacity.
We will implement the applicable mechanism as required by the DPDP framework. (India Code)
71. Exercising privacy rights
Requests may be submitted to:
We may need information reasonably necessary to:
- authenticate you;
- locate relevant records;
- prevent fraudulent requests;
- verify authorization;
- understand the requested action.
We will not intentionally request unnecessary information merely because you exercise a privacy right.
72. Requests concerning customer-controlled webinar data
If your request concerns information collected by a particular webinar organizer, we may direct you to the relevant Customer where that Customer controls the processing.
Where appropriate, cRUD may assist the Customer with fulfilling the request.
73. Identity verification
To protect users, we may verify identity before:
- providing personal data;
- deleting Account information;
- changing sensitive information;
- processing certain privacy requests.
Verification requirements should be proportionate to the sensitivity of the requested action.
74. Authorized representatives
Where applicable law permits someone to make a request on another individual's behalf, we may require evidence of authorization.
75. Children
cRUD Accounts are intended for adults and business/professional users.
Users creating cRUD Accounts must generally be 18 years of age or older.
Because customers may operate webinars for different audiences, there may be circumstances where an attendee is under 18.
76. Personal data of children
Under the DPDP Act, a “child” generally means an individual who has not completed eighteen years of age. The Act imposes additional requirements in relation to processing children's personal data, including verifiable parental consent, subject to applicable statutory exceptions and rules. (India Code)
cRUD customers must not intentionally use the Services to collect children's personal data in violation of applicable law.
77. Webinar organizers and children
If an organizer intends to operate a webinar directed toward children, it is responsible for:
- informing cRUD where required;
- determining whether the use is permitted;
- obtaining legally required parental or guardian authorization;
- providing appropriate notices;
- limiting information collected;
- complying with applicable child-safety laws.
cRUD may restrict or decline use cases involving children where we determine that we cannot responsibly or lawfully support the proposed processing.
78. Discovery of children's information
If we reasonably believe children's personal data has been collected unlawfully, we may:
- restrict processing;
- contact the Customer;
- request evidence of authorization;
- suspend the affected workflow;
- delete information where appropriate;
- take other protective action.
Concerns may be reported to:
79. Sensitive information
cRUD Webinar is not intended to serve as a general repository for highly sensitive information unrelated to operating webinars.
Customers should avoid requesting or uploading unnecessary information such as:
- passwords;
- financial credentials;
- government authentication secrets;
- medical information;
- precise sensitive personal information;
- highly confidential identifiers,
unless the use has been specifically assessed and is permitted by applicable law and cRUD.
We may restrict registration fields or content that create disproportionate privacy or security risk.
80. Biometric information
Ordinary cRUD Webinar functionality is not intended to identify people using biometric recognition.
Video and audio provided for webinar participation may contain a person's image or voice, but cRUD does not thereby claim to perform biometric identification unless a feature expressly states otherwise.
81. Automated decision-making and scoring
Certain cRUD functionality may use automated rules or analytics to assist with:
- audience qualification;
- abuse detection;
- fraud detection;
- account security;
- registration classification;
- engagement scoring;
- buying-intent indicators.
We aim to ensure material product decisions are based on appropriate information and that relevant scoring can be explained where appropriate.
Customers should not treat engagement scores as infallible assessments of an individual.
Where applicable law establishes rights relating to automated processing, we will comply with those requirements.
82. Domain intelligence
cRUD may classify email domains for purposes such as:
- preventing disposable emails;
- identifying personal email providers;
- identifying business domains;
- enforcing customer-configured allowlists/blocklists;
- reducing registration abuse.
Domain classifications are operational signals and may not always accurately characterize every user associated with a domain.
Where appropriate, manual review or override mechanisms may be available.
83. Imported lists
Customers may be permitted to import attendee or contact information.
Customers must ensure imported information has been obtained and is being used lawfully.
cRUD may:
- validate imports;
- reject malformed data;
- reject prohibited data;
- restrict suspicious imports;
- investigate abuse;
- suspend bulk import functionality.
84. Marketing lists and spam
Customers must not use cRUD to send unlawful unsolicited marketing.
The existence of an email address does not automatically mean a Customer has permission to market to that person.
Customers remain responsible for applicable communication and marketing laws.
85. Recordings and privacy
Where a webinar is recorded:
- participants should receive appropriate notice;
- organizers must obtain permissions required by law;
- recordings may contain personal data;
- replay publication may increase the audience able to view that data.
Organizers should carefully review recording and replay settings.
86. Public webinar content
Some customer content may intentionally be made public.
For example:
- speaker biographies;
- webinar titles;
- public landing pages;
- replay pages;
- public resources.
Information intentionally published publicly may be accessible to persons outside cRUD.
Customers should not place private information into public content unless they have authority to do so.
87. Customer responsibility for privacy notices
Customers using cRUD Webinar should provide their own privacy notices where they determine the purposes for which attendee information will be used.
For example, if a Customer intends to add webinar attendees to its marketing database, its privacy notice and consent mechanisms must appropriately address that processing.
cRUD's Privacy Policy does not replace the Customer's own privacy obligations.
88. Customer exports
Customers may be permitted to export information from cRUD.
Once information is exported to a Customer-controlled environment, cRUD may no longer control how that copy is stored or used.
The Customer becomes responsible for its subsequent processing.
89. Customer deletion
Deleting information from cRUD does not automatically delete copies previously exported by a Customer to:
- CRM systems;
- spreadsheets;
- marketing systems;
- internal databases;
- third-party applications.
Requests concerning those copies should be directed to the relevant Customer.
90. Do Not Track
Browser “Do Not Track” mechanisms are not uniformly standardized.
Where legally required consent controls exist, the controls provided by cRUD will govern our use of the relevant technologies.
Our Cookie Policy will provide additional information.
91. External websites and links
Webinars and cRUD pages may contain links to external websites.
cRUD is not responsible for the privacy practices of independent third-party websites.
You should review their policies before providing personal data.
92. Social platforms and simulcasting
If customers choose to distribute webinar content through external streaming or social-media platforms, those platforms may independently process information according to their own privacy policies.
cRUD does not control those independent processing activities.
93. Changes to this Privacy Policy
We may update this Privacy Policy due to:
- changes in law;
- regulatory guidance;
- new Services;
- product changes;
- new data uses;
- new subprocessors;
- security requirements;
- operational changes.
Each published version will contain:
- version number;
- last-updated date;
- effective date.
94. Material privacy changes
Where a change materially affects how we process personal data, we may provide notice through:
- email;
- Account notification;
- product banner;
- website notice;
- another appropriate method.
Where applicable law requires new consent for a materially different processing purpose, updating the Privacy Policy alone will not be treated as sufficient consent.
We will obtain appropriate permission separately where required.
95. Privacy Policy version history
cRUD intends to maintain historical versions of material legal documents so that it is possible to determine which Privacy Policy applied at a particular time.
The canonical version is maintained at:
https://www.thecrudcompany.com/trust-center/privacy-policy
This Privacy Policy is published only at the canonical company-website URL. cRUD applications link to that URL in a new browser tab and do not host a duplicate copy of the Policy.
96. Acceptance and acknowledgement records
Where the Privacy Policy is presented during signup, we may record that the user was provided with and acknowledged the applicable Privacy Policy.
This acknowledgement is distinct from consent to particular optional processing.
A record may contain:
- user ID;
- Organization ID;
- Privacy Policy version;
- canonical URL;
- timestamp;
- flow/source;
- Terms version accepted at the same time.
97. Relationship with Terms of Service
Use of cRUD is also governed by our Terms:
https://www.thecrudcompany.com/trust-center/terms-of-service
Where Terms and this Privacy Policy address different subjects, each applies to its respective subject matter.
Nothing in the Terms is intended to remove privacy rights that cannot lawfully be waived.
98. Relationship with Data Processing Agreement
Where a Customer and cRUD enter into a Data Processing Agreement and there is a conflict concerning processing performed on behalf of that Customer, the DPA may control to the extent expressly provided by that agreement.
99. Relationship with specific notices
We may provide short or contextual privacy notices inside the Service.
Examples include:
- registration notices;
- recording notices;
- marketing consent;
- cookie consent;
- data import warnings;
- sensitive-feature notices.
Such contextual notices supplement this Privacy Policy.
100. Contact details
Privacy and personal-data requests
Grievances
Security
Legal
General enquiries
Company
CRUD INFOSYSTEMS PRIVATE LIMITED Operating under the brand name The cRUD Company
Unit 101, OXFORD TOWERS 139, HAL Old Airport Road Kodihalli, Bengaluru, Karnataka 560008 India
This document is published by CRUD INFOSYSTEMS PRIVATE LIMITED, Unit 101, Oxford Towers, 139 HAL Old Airport Road, Kodihalli, Bengaluru, Karnataka 560008, India.
Return to Trust Center.