Privacy Policy
How GutConference uses your data.
This Privacy Policy explains what personal data GutConference Online collects, why we collect it, how we use it, who we share it with, and what rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. By using gutconference.online (the “Website”), creating an account, or signing in with Google, you acknowledge this policy.
1. Data Fiduciary — Who We Are
The Data Fiduciary (the entity that decides the purpose and means of processing your personal data) is:
GutConference Online
Operated by Dr. Praveen Jacob
Email: gutconference2026@gmail.com
Phone: +91 97314 82585
India
For any privacy question, request, complaint, or grievance, contact us at the email or phone above. Our Grievance Officer (named in section 8 below) responds within the windows described there.
2. Personal Data We Collect
We collect the following categories of personal data, only to the extent necessary to provide the service:
- Account data: name, name for certificate, email address, password (hashed; we never store passwords in plain text), phone (optional), and Google account identifier (if you sign in with Google).
- Booking and registration data: event or course selected, registration status, payment status, certificate status, attendance, and any event-specific responses you provide.
- Payment metadata: Razorpay
order_id,payment_id, paymentsignature, payment method family (card, UPI, netbanking, wallet), and the derivedpayment_status. We do not collect, store, transmit, or have access to your full card number, UPI PIN, netbanking password, or OTP. - Support data: anything you share through the contact form, the support agent chat, the support tickets you raise, and our email or WhatsApp conversations with you.
- Notification preferences: whether you opted in to the newsletter or to calendar reminders.
- Operational logs and audit data: timestamped records of administrative actions and security-relevant events, retained for 1 year.
- Analytics data: if Google Site Tag or Google Tag Manager is enabled (configured in
adminsecrets.json), basic page-view events are sent to Google Analytics. No personally identifying data is sent unless you submit a form on the same page.
3. Purposes of Processing
We process your personal data only for the following purposes:
- To create and maintain your account.
- To register you for events and courses you book, process payment, and deliver joining links, agenda details, and certificates.
- To verify payment status and prevent fraudulent bookings.
- To send transactional communications (payment confirmations, joining links, schedule changes, certificate notifications, support follow-ups).
- To send optional marketing communications (newsletter, upcoming event announcements) only if you have explicitly opted in. You can opt out at any time.
- To provide customer support and respond to your requests.
- To comply with applicable law, including tax, accounting, and audit obligations, and to respond to lawful requests from public authorities.
- To detect and prevent fraud, abuse, and security incidents.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you, except for the limited automated fraud and abuse detection described above.
4. Google API Services — Limited Use Disclosure
Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we request the following Google API scopes:
openid— to obtain your stable Google account identifier (sub) for account creation and deduplication.email— to read the email address associated with your Google account for login, booking receipts, and certificate delivery.profile— to read your display name and (where available) profile photo, so your customer dashboard and certificate can show the right name.
Where a specific event is configured for calendar reminders, we may additionally request https://www.googleapis.com/auth/calendar.events to create a single Google Calendar event reminder for that booking. The reminder is created in your default Google Calendar and is owned by you; we do not read, list, modify, or delete any of your other calendar events.
Limited Use commitment. We use Google user data only as a user-facing feature that is visible to you: signing you in, displaying your name on the dashboard and certificate, and (when enabled) creating a single calendar reminder for the event you booked. We do not transfer Google user data to third parties, advertising platforms, data brokers, or information resellers. We do not use Google user data for serving ads, retargeting, or credit-worthiness decisions. We do not allow humans to read Google user data unless (a) you have explicitly asked for support on a specific record, (b) it is necessary for security or legal compliance, or (c) the data is aggregated and used only for internal operations in accordance with applicable law.
5. Razorpay — Payment Processor
All payments are processed by Razorpay Software Limited, a payment aggregator and gateway licensed by the Reserve Bank of India. Razorpay is a separate Data Fiduciary / Data Processor for the payment data it collects. Razorpay’s privacy policy is available at razorpay.com/privacy-policy.
GutConference Online stores only the Razorpay order_id, payment_id, payment signature, and our derived payment_status for accounting, reconciliation, fraud review, and customer support. We do not store card, UPI, wallet, or banking credentials.
6. Cookies, Local Storage, and Analytics
The Website uses a PHP session cookie (PHPSESSID) for authentication and to remember your login state. This cookie is strictly necessary for the service and is not used for advertising.
If Google Site Tag (gtag.js) or Google Tag Manager is enabled, the Website loads Google Analytics and may set additional cookies described in Google’s cookie policy. You can block these via your browser settings; the core booking and login flows will continue to work.
The support agent widget stores the chat thread in your browser’s localStorage for the duration of the session. The widget does not transmit chat content to a third party without your action.
7. Your Rights as a Data Principal
Under the DPDP Act, 2023, you have the following rights with respect to your personal data:
- Right to access: request a copy of the personal data we hold about you.
- Right to correction: ask us to correct inaccurate or incomplete data.
- Right to erasure: ask us to delete your personal data, subject to the retention described in section 9.
- Right to grievance redressal: raise a grievance and have it addressed within the window described in section 8.
- Right to withdraw consent: if processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to nominate: nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, email us at gutconference2026@gmail.com from the email address on your account (so we can verify the request). We will respond within the window in section 8.
8. Grievance Officer & Response Window
In compliance with the IT Act, 2000, the SPDI Rules, 2011, and the DPDP Act, 2023, the Grievance Officer for the Website is:
Dr. Praveen Jacob
Grievance Officer, GutConference Online
Email: gutconference2026@gmail.com
Phone: +91 97314 82585
We acknowledge receipt of your grievance within 7 business days and aim to resolve grievances within 30 calendar days. If your grievance involves a payment dispute, we will coordinate with Razorpay and provide our position in writing within the same window.
9. Data Retention & Erasure
We retain personal data only for as long as necessary for the purposes described in this policy, subject to the following minimum windows required by Indian law:
- Account and registration data: for the lifetime of your account, plus 7 years after account closure, to satisfy the Indian Limitation Act, 1963 (which prescribes a 3-year limitation period for contract disputes, doubled for acknowledgment) and Indian tax and accounting obligations.
- Payment metadata: 8 years from the date of the transaction, in line with Indian income-tax record-keeping requirements.
- Audit logs and security events: 1 year.
- Support conversations and contact form submissions: 2 years from last interaction, unless you ask us to delete them earlier.
- Marketing opt-in records: until you opt out, plus 1 year for audit.
When retention is no longer required, the data is erased or irreversibly anonymized.
10. Children’s Data
The Website is not directed at children under the age of 18. We do not knowingly collect personal data from children. If a parent or legal guardian books an event for a minor, the parent or guardian is the Data Principal and is responsible for the minor’s data; the minor’s data is processed only for the booked event and is not used for marketing.
11. Cross-Border Data Transfer
Your data is stored on Hostinger shared hosting in India. Razorpay and Google may process some of your data in their own regions, including outside India, in line with their own policies and applicable law. We do not transfer your data to any other third party for their own purposes.
12. Security
We take reasonable and appropriate steps to protect your personal data against unauthorized or unlawful access, use, destruction, loss, alteration, or disclosure. These include: TLS for data in transit, password hashing with bcrypt, role-based access for the admin panel, audit logging for administrative actions, and access controls for the underlying hosting account. No system is perfectly secure; if we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify you and the Data Protection Board of India in line with the timelines required by the DPDP Act.
12.1 User Data Isolation
Your personal data is stored in a dedicated, per-user file on our servers. This architecture provides the following guarantees:
- File-per-user isolation: Each user’s bookings, tickets, appointments, and support conversations are stored in a separate file linked to their account identifier. No two users share a data file.
- Query scoping: When the system retrieves your data, it queries only records matching your authenticated email address. Cross-user data access is not technically possible through the normal application flow.
- Access restriction: Your data is accessible only by you (when signed in) and by authorized GutConference administrators for the purposes described in this policy (support, order management, audit).
- Support agent context: The AI support agent reads only your current session’s context snapshot. It does not have access to other users’ data or to your full account history beyond what is necessary to answer your query.
13. Changes to This Privacy Policy
We may update this Privacy Policy at any time to reflect changes in our practices, applicable law, or the services we offer. The latest version will always be posted at /privacy with an updated “last modified” date. Material changes that affect the data we collect or how we use it will be communicated by email to registered users at least 14 days before the change takes effect, except where the change is required sooner by applicable law. Your continued use of the Website after the effective date constitutes acceptance of the updated policy.
14. Contact
For any privacy question, request, complaint, or grievance, contact us at gutconference2026@gmail.com or call +91 97314 82585.
Last modified: 7 June 2026. Version 1.0.