KONFHUB PRIVATE LIMITED
How KonfHub Collects, Uses, Shares, and Protects Personal Data
EFFECTIVE DATE: JUNE 29, 2026
LAST REVIEWED DATE: JUNE 29, 2026
Jurisdictional Frameworks: Indian DPDP Act, EU/UK GDPR, California CCPA/CPRA
LEGAL DISCLAIMER: This Privacy Policy is provided for transparency regarding our processing activities. It does not modify contractual rights or obligations unless expressly stated.
This Privacy Policy ('Privacy Policy' or 'Policy') explains how KonfHub Private Limited ('KonfHub', 'Company', 'We', 'Us', or 'Our') processes personal data. As an event management platform handling user registrations, ticketing, and live engagement tools, we prioritize transparency regarding how we process personal data. This document is designed to comply with local, national, and international privacy laws by providing clear information about our data processing activities.
This Policy applies across our entire digital platform ecosystem. This includes our primary web domains (including https://konfhub.com), native iOS and Android mobile applications, localized ticketing engines, digital or physical event check-in tools, event photo galleries, all associated Application Programming Interfaces (APIs), and administrative tools (collectively, the 'Services' or 'Platform').
This Statement applies to any natural person whose personal data is collected, stored, or processed within our infrastructure. These individuals include platform visitors, website viewers, registered Event Organizers, Professional Conference Organizers (PCOs), attendees, speakers, panelists, and corporate sponsors. Depending on the applicable legal framework, these individuals are referred to as 'Data Principals' under Indian law, 'Data Subjects' under European rules, or generally as 'Users' or 'You'.
Because events hosted on our Platform attract global participation, our data operations are designed to comply with applicable legal requirements. Depending on your geographical location, citizenship, or where your data is collected, specific localized statutory rules may take precedence.
For personal data collected, stored, or processed within India, or involving residents of India, this Policy serves as the notice required under applicable provisions of the Digital Personal Data Protection (DPDP) Act. Any interpretation of processing boundaries, operational conditions, and rights shall be guided by the provisions of the DPDP Act and the rules, decrees, or guidelines promulgated thereunder by the Central Government or the Data Protection Board of India (DPBI).
For individuals residing within the European Economic Area (EEA) or the United Kingdom (UK), KonfHub aligns its processing with the General Data Protection Regulation (Regulation (EU) 2016/679) ('GDPR') and the UK Data Protection Act 2018. We establish clear lawful bases under Article 6 of the GDPR, facilitate workflows for data subject access requests (DSARs), and implement cross-border transfer mechanisms such as Standard Contractual Clauses (SCCs).
For residents of California, United States, this Policy fulfills the notice requirements mandated under the California Consumer Privacy Act of 2018 ('CCPA') as amended by the California Privacy Rights Act of 2020 ('CPRA'). We maintain records and technical options ensuring California consumers can exercise their rights to know, delete, correct, and opt-out of the 'sale' or 'sharing' of personal information as defined by state law.
To ensure appropriate legal accountability, KonfHub's formal role shifts based on the commercial context through which your information is gathered:
We act as an independent Data Fiduciary or Data Controller when we determine the standalone purposes and technical means of processing your data. This applies when you perform core activities on our platform, such as browsing our website, creating a master KonfHub user profile, subscribing to corporate marketing newsletters, purchasing platform licenses, or acting as an Event Organizer utilizing our SaaS tools to configure an event page. In these scenarios, KonfHub is directly responsible for compliance with applicable data protection obligations.
We operate strictly as a Data Processor when we provide cloud software, ticketing solutions, and check-in tools on behalf of registered external Event Organizers. When a user registers for or purchases a ticket to an event hosted by a third-party organizer on our platform, that Event Organizer functions as the primary, independent Data Fiduciary or Data Controller. In these configurations, KonfHub processes personal data solely upon the documented instructions of the Organizer, governed by a formal Data Processing Agreement (DPA). KonfHub is not directly liable for independent data tracking, profiling, or privacy violations executed by individual Event Organizers outside our platform controls.
When Event Organizers utilize KonfHub's platform to create registration forms, sell tickets, or manage attendees, they assume primary responsibility as the independent Data Controller or Data Fiduciary. This comes with specific compliance mandates that are independent of KonfHub's platform controls.
Organizers are responsible for: (a) obtaining valid, unambiguous, and where necessary, explicit attendee consent for any event-specific data collection; (b) configuring registration forms and custom fields in a minimal, proportionate, and legally valid manner; (c) providing appropriate transparency and responding to attendee privacy questions or rights requests within statutory timelines; and (d) ensuring the lawful collection of sensitive information through custom fields (such as dietary profile tracking or corporate identifications). Organizers acknowledge their primary legal and contractual responsibility for compliance regarding data collections executed via their configured form builders, as detailed in our standard terms of service or separate organizer agreements
We process personal data only when backed by a recognized lawful basis under applicable global regulations. Processing is executed under the following criteria:
| Processing Activity Group | Personal Data Collected | GDPR Lawful Basis | DPDP Act Base | Operational Justification |
|---|---|---|---|---|
| Account Creation | Name, password hashes, email address. | Article 6(1)(b): Performance of a Contract. | Consent / Contract Fulfillment | Necessary to establish identity profile and fulfill core service delivery. |
| Financial Invoicing | Masked tokens, corporate billing addresses, GSTIN numbers. | Article 6(1)(c): Legal Obligation. | Legitimate Uses (Tax Compliance) | Fulfills local fiscal and corporate transparency mandates (e.g., GST, tax accounting). |
| Security Telemetry | Static/dynamic IP addresses, MAC addresses, clickstream logs. | Article 6(1)(f): Legitimate Interests. | Legitimate Uses (Cybersecurity Logs) | Required to isolate malicious actors and comply with regional threat reporting guidelines. |
| Biometric Entry | Encrypted facial maps, biometric templates. | Article 9(2)(a): Explicit Consent. | Granular, Unbundled Consent | Optional feature deployed for automated physical badge routing or checking. |
| Marketing and Tracking | Tracking pixels, session cookie sequences. | Article 6(1)(a): Granular Consent. | Itemized Consent Notices | Used to update users on upcoming platform events and relevant feature developments. |
Core Account Identity: We collect first name, last name, profile picture, professional or corporate title, and password credentials. Passwords are password-hashed via secure cryptographic protocols and are never stored in clear text. This data is processed for user authentication, profile generation, and prevention of identity spoofing.
Communication Logs: We process primary/alternative email addresses, verified mobile phone numbers, and physical corporate or billing addresses. This data is used for dispatching tax invoices, transactional ticket delivery, system notifications, and responding to support tickets.
Telemetry & Technical Logs: We capture hardware specifications, operating system versions, dynamic/static IP addresses, IMEI or MAC address telemetry, clickstream sequences, and latency logs. This data is used for diagnostic routing, load balancing, fraud prevention, and satisfying statutory cybersecurity log-retention rules (such as CERT-In guidelines).
Transactional & Payment Metrics: We store order identification numbers, chronological timestamps, promo code maps, and masked payment tokens (Credit Card/UPI/NetBanking logs) for financial compliance under applicable central banking and PCI-DSS standards. Raw card numbers or CVVs are directly processed by authorized payment gateways and never touch or store on our servers.
Organizer Custom Fields: We process corporate business names, GST registration numbers, t-shirt sizes, food allergies, dietary profiles, or sensitive custom criteria configured by the host event organizer. This information is processed strictly as a Data Processor on behalf of the Organizer to execute event-specific logistics like badge printing, custom seating, and catering maps.
Through our platform's custom form builders, Event Organizers may occasionally collect health-related, accessibility, or highly specific personal categories from attendees. This includes dietary preferences (which may reveal religious or health attributes), accessibility requirements, and health-related accommodation requests.
KonfHub clarifies that any such sensitive personal data is processed strictly where necessary, entirely under individual organizer instructions, and with an appropriate legal basis as established by the Event Organizer. We apply heightened technical protections to custom data entries but do not use or analyze these inputs for any standalone secondary corporate or marketing purposes.
The KonfHub platform provides interactive networking and collaborative features, allowing users to build public or semi-public attendee profiles, participate in live event chat channels, send direct messages to other registrants, join networking tables, and publish media or photographs. Any content, text, or media you publish within these collaborative modules becomes visible to other authorized event participants, speakers, or organizers depending on the settings of that specific event area.
You are solely responsible for the user-generated content you choose to publish, share, or broadcast. KonfHub does not pre-screen all user content but retains the right to remove any text or media that violates our platform terms of service or applicable community guidelines. Users should exercise caution when publishing personal details, business contact information, or private identifiers within shared chat channels or public attendee directories.
KonfHub utilizes automated systems and software automation layers to optimize platform navigation and user engagement. These automated systems parse attendee metadata, professional designations, and historical event registration choices to surface contextual recommendations, technical track suggestions, session tracks, and peer-to-peer networking connections.
All algorithmic recommendations, session pairings, and automated matching functionalities deployed across our platform are strictly assistive and non-deterministic. They do not dictate access rights, generate automated decisions with severe legal impacts, or alter your registration status without human oversight. Users can opt-out of personalized automated matchmaking recommendations by adjusting their notification and visibility preferences inside their primary profile control panel
Where a registered Event Organizer enables KonfHub's AI-driven event photo booth or galleries or facial recognition entry routing, the collection of underlying biometric media is entirely optional. The platform requires a separate, explicit, unbundled opt-in action from the individual before any visual processing or face-matching is executed. Users are never required to provide biometric information as a condition for entering an event venue or downloading standard digital tickets.
When opt-in consent is provided, KonfHub's computer vision software processes the uploaded reference photograph or on-site kiosk video feed to map unique facial nodes and coordinates. This structural metadata is instantly converted into an encrypted biometric template. Event organizers do not receive, download, or access raw biometric templates or the underlying coordinate maps; these elements remain strictly isolated within KonfHub's secure application environments.
Our image indexing workflows leverage cloud computing instances provided by Amazon Web Services (AWS) that utilize appropriate technical and organizational protections. AWS processes these facial templates using encrypted infrastructure vectors where data is protected at rest and in transit. These activities are governed strictly by the data processing safeguards and service terms established in our contractual agreements with the provider.
Users may withdraw their consent to the processing of their biometric data at any time, without affecting the lawfulness of processing carried out before such withdrawal. A withdrawal request may be submitted through the Privacy Request Center, by opting out through the event profile dashboard (where available), or by contacting us at privacy@konfhub.com.
Upon receipt of a valid withdrawal request, KonfHub will promptly cease processing the user's biometric data for facial recognition purposes and securely delete the associated encrypted biometric template from its active systems, except where retention is required or permitted under applicable law.
Following the conclusion of an event, biometric templates associated with that event are securely and permanently deleted from KonfHub's production systems in accordance with our data retention schedule and applicable legal and contractual obligations.
CCPA Sensitive Personal Information Classification Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), biometric information constitutes Sensitive Personal Information. California residents have the right to limit KonfHub's use and disclosure of their biometric data. To exercise this right contact privacy@konfhub.com with the subject line "California Sensitive PI Limit Request".
Upon receipt of a valid limitation request, KonfHub will restrict the use of your biometric data to purposes strictly necessary to perform the services you have requested. We will not use biometric information for inferences about your characteristics, for cross-context behavioral advertising, or for purposes beyond the specific event check-in function for which you provided consent.
KonfHub's core commercial services, software utilities, and platform architectures are designed for professionals, adult conference participants, corporate attendees, and collegiate event organizations. We do not knowingly collect, ingest, or process personal data from children or minors without obtaining appropriate parental or guardian authorization.
For the purpose of this Policy, the applicable age thresholds are as follows by jurisdiction:
Where a user's jurisdiction cannot be determined, KonfHub will apply the most protective threshold of 18 years. If a specific event hosted on our platform is explicitly tailored for youth educational discovery, scholastic coding leagues, or minor competitions, the Event Organizer is required to get verifiable authorization from a parent or legal guardian.
Under expanded CCPA/CPRA provisions effective January 1, 2026, personal information collected from consumers under the age of 16 constitutes Sensitive Personal Information, regardless of the data category involved. KonfHub addresses this as follows:
KonfHub operates a globalized cloud architecture to deliver high-availability event experiences. Consequently, personal data collected in one territory may be transferred out of your country of origin to secure data repositories operated by our core hosting vendors (such as Amazon Web Services) located in India, South East Asia, the United States, or Western Europe.
To support the strict operational and compliance needs of enterprise clients and Event Organizers operating under localized storage laws, KonfHub offers regional data residency configurations. Organizers can contractually arrange that tenant account data, attendee registration records, financial metrics, and transaction logs be stored and processed within preferred regional server hubs, such as our dedicated clusters in India, the European Union, or the United States. When a regional data residency configuration is selected, KonfHub implements structural logical isolation layers ensuring that active primary database nodes remain contained within that designated geographical boundary
For cross-border data movements originating within the EEA or the United Kingdom to countries lacking a formal adequacy ruling, KonfHub implements appropriate data safeguards, including the execution of standard contractual clauses built into our supplier agreements. We maintain compliance with any territorial data flow restrictions, transfer blocklists, or localized storage mandates issued by regulatory authorities under applicable frameworks like the DPDP Act. Furthermore, KonfHub contractually commits to complying with any future structural restrictions, cross-border transfer conditions, or notifications issued by the Central Government of India regarding the movement of personal data outside India as the regulatory landscape evolves
Data protection is managed through appropriate technical and organizational measures to safeguard personal data against unauthorized access, loss, or alteration. Personal data is encrypted in transit across public networks using Transport Layer Security (TLS 1.3) protocols. Data is also protected at rest within cloud environments utilizing strong industry-standard encryption standards, such as Advanced Encryption Standard (AES-256), where technically feasible and operationally supported.
Cryptographic master keys used to encrypt user tables and data at rest are managed through standard cloud Key Management Services (KMS). These keys are subject to operational control policies, fine-grained access limits based on identity and access management (IAM), and comprehensive audit logging. Detailed cryptographic configurations and key orchestration architectures are maintained outside this notice within our separate security whitepapers and corporate Trust Center documentation.
We enforce Role-Based Access Control (RBAC) and multi-factor authentication (MFA) across our systems. Access to production data environments is restricted exclusively to authorized personnel who require access to maintain platform availability, handle technical support, or process transaction refunds. KonfHub conducts at least annual VAPT assessments and regular vulnerability scanning through qualified security professionals. Security researchers can securely submit potential platform bugs via our Responsible Disclosure Program at reachus@konfhub.com.
We maintain an internal Incident Response Protocol to isolate, contain, and mitigate potential data security anomalies. Upon identifying a verified software security incident or unauthorized logic bypass affecting personal data, our technical team executes containment protocols to secure system endpoints, isolate affected cloud instances, and rotate system credentials.
In the event of a verified personal data breach that poses a risk to the rights and freedoms of individuals, KonfHub will, without undue delay and where feasible not later than 72 hours after becoming aware of the breach:
(a) Notify the relevant supervisory authorities, including the Data Protection Board of India (DPBI), the applicable EU Lead Supervisory Authority under Article 33 GDPR, and/or the UK Information Commissioner's Office (ICO), as required by applicable law; and
(b) Notify affected Data Subjects or Data Principals where the breach is likely to result in a high risk to their rights and freedoms, providing the information required under Article 34 GDPR and corresponding DPDP Act provisions.
Breach notifications will include: (i) the nature of the personal data breach, including where possible the categories and approximate number of individuals concerned; (ii) the likely consequences of the breach; (iii) the measures taken or proposed to address the breach; and (iv) contact details for the Data Protection Officer. Where notification cannot be provided within 72 hours, it will be accompanied by reasons for the delay.
Explicit 72-Hour Commitment: KonfHub commits to notifying competent supervisory authorities within 72 hours of becoming aware of a verified personal data breach, in compliance with GDPR Article 33 and the DPDP Rules 2025. This commitment applies across all three jurisdictions covered by this Policy.
KonfHub processes biometric data (a special category under GDPR Article 9) at scale for event check-in purposes. In accordance with GDPR Article 37(1)(c), which requires the appointment of a Data Protection Officer where the core activities of an organization consist of large-scale processing of special categories of data, KonfHub has appointed a Data Protection Officer (DPO).
The DPO is responsible for: (a) informing and advising KonfHub and its staff on data protection obligations; (b) monitoring compliance with the GDPR, DPDP Act, and applicable data protection regulations; (c) providing advice on Data Protection Impact Assessments (DPIAs) for high-risk processing including biometric data operations; and (d) serving as the primary point of contact for supervisory authorities.
DPO Contact Details:
The DPO acts with independence in performing their tasks and may not be penalized or dismissed for performing their duties. Data Subjects and Data Principals may contact the DPO directly regarding any matter relating to the processing of their personal data or the exercise of their rights.
To safeguard core SaaS ticketing pipelines and live visual features during large-scale global conferences, KonfHub maintains operational procedures for platform continuity. We utilize an internal corporate Business Continuity Plan (BCP) designed to manage system availability, transaction processing, and user access during unforeseen cloud outage emergencies or upstream network disruptions.
Our infrastructure teams implement disaster recovery and data backup procedures. System databases, transaction records, and user profiles are captured using automated data replication alongside periodic snapshot copies. Backups are stored in an encrypted state at rest and are distributed across separated geographic availability zones to support resilience against localized failures. Detailed failover workflows, internal replication maps, and operational metrics are housed separately within our corporate security and operational guidelines.
To deliver our global event management services effectively, KonfHub engages specialized infrastructure vendors and third-party data intermediaries. These parties are subject to background security reviews and formal data processing extensions.
When KonfHub intends to onboard a new subprocessor, adjust an existing infrastructure host, or modify a data intermediary highlighted in Appendix D, we enforce a transparent modification notification process. Event Organizers and enterprise corporate clients can subscribe to our subprocessor modification broadcast loop.
30-Day Objection Window: KonfHub will provide a minimum of 30 calendar days' advance written notice before onboarding any new subprocessor or making any material change to an existing subprocessor's role or processing scope. Controller clients who have reasonable, documented objections based on data protection grounds must notify KonfHub in writing within this 30-day objection window. KonfHub will evaluate the objection in good faith. If the parties cannot resolve the objection through reasonable measures, the controller client may terminate the relevant Services without penalty, subject to the applicable DPA terms. This mechanism satisfies the requirements of GDPR Article 28(2) regarding sub-processor authorization.
The advance notification will detail the subprocessor's identity, its localized processing country, and the specific platform features it supports, allowing clients to evaluate compliance parameters or raise valid, contractually backed security objections.
We preserve personal data only for as long as necessary to satisfy the specific purposes for which it was collected, or to fulfill overriding statutory compliance obligations. In compliance with DPDP Rule 8(3), KonfHub retains all personal data, traffic data, and logs generated during processing activities for a minimum of one year, unless a shorter period is otherwise mandated or permitted by applicable law.
| Data Domain | Retention Window | Legal Justification | Destruction Mechanism |
|---|---|---|---|
| Security Logs & Traffic Data (incl. Cookie Telemetry) | Minimum 365 Days (1 Year) — DPDP Rule 8(3) mandated minimum. Server-side logs retained for 1 year minimum regardless of cookie expiry on device. | DPDP Rule 8(3) mandatory 1-year minimum; CERT-In cybersecurity log compliance; system optimization and performance tracking. | Automated background deletion cycles post minimum retention period. |
| Event Attendee Rosters | Duration of active event + 180 Days | Contractual verification, post-event access, and dispute resolution. | Database cascade deletion and secure erasure. |
| Financial Invoices & Ledgers | 7 Years from fiscal close | Taxation compliance, corporate records, and auditing statutes. | Secure archival with restricted legal compliance access. |
| Biometric Vector Templates | 30 Days post-event or immediate on opt-out | Minimization of high-risk operational profiles under explicit consent. | Irreversible programmatic overwriting and deletion. |
Note on DPDP Rule 8(3) Compliance: The minimum 1-year retention period applies to all security incident logs, access and authentication logs, traffic data, and cookie telemetry server-side logs. This supersedes any shorter device-side expiry. Personal data for which purpose has been fulfilled will continue to be purged in accordance with the applicable retention window set forth above; however, the server-side activity logs associated with that processing will be retained for the 1-year minimum. This policy is applied uniformly across all processing activities covered by this Policy.
Cookies are small alphanumeric text files stored on your browser to optimize platform functionality, remember user preferences, and execute analytics. Where required by applicable law, non-essential cookies are placed only after obtaining your consent. Our deployment details are structured below:
| Cookie Name / Identifier | Classification Tier | Operational Purpose | Retention Duration |
|---|---|---|---|
| kh_session_id | Tier A: Strictly Necessary | Maintains user authentication and secure token stability across browser tabs. | Session expiry on browser close |
| _ga / _gid | Tier B: Performance & Analytics | Captures aggregate traffic patterns, page latency metrics, and error sequences via Google Analytics. | 24 Hours to 2 Days |
| kh_pref_lang | Tier C: Functional & Preference | Stores user choices such as default currency selection and display languages. | 1 Year |
| kh_exp_mod | Tier D: Dynamic & Experimental | Temporary script modules running a/b feature testing for system refinement. | Persists for duration of test |
Our platform interfaces, event landing environments, and newsletter updates may contain embedded links to external third-party web domains, social networks, digital tools, or sponsor portals that operate independently of KonfHub. This Privacy Policy applies strictly to data processed within KonfHub's platform controls.
We do not control, review, or assume liability for the data practices, tracking cookies, or privacy frameworks maintained by third-party web operators. Clicking on external hyperlinks or integrating external add-ons is done at your own discretion. We encourage users to inspect the individual privacy policies of external sites before yielding personal information to them.
For users covered by European or North American privacy frameworks, KonfHub supports clear rights workflows. Data subjects can submit a Data Subject Access Request (DSAR) from the Privacy Request Center or by reaching out to privacy@konfhub.com.
To prevent unauthorized data disclosures or identity spoofing, KonfHub requires a multi-factor authentication check or identity verification loop before generating data extracts. Once verified, our tools compile the user's personal data into a machine-readable format (such as JSON or CSV). We complete this within thirty (30) calendar days from receipt, unless the request requires manual verification or extension due to administrative complexity.
Opt-out requests are processed within 15 business days of receipt. After processing, KonfHub will not sell or share your personal information for cross-context behavioral advertising unless you later provide explicit consent through our opt-in process.
20.2 Opt-Out Confirmation Mechanism
In compliance with CCPA/CPRA regulations effective January 1, 2026, KonfHub provides confirmation that opt-out requests have been processed. Upon receipt of a valid opt-out request (whether manual or via GPC signal), KonfHub will:
(a) Acknowledge receipt of the opt-out request within 5 business days;
(b) Complete processing of the opt-out request within 15 business days;
(c) Send written confirmation to the email address associated with the request, specifying: (i) the date the opt-out was processed; (ii) the categories of sharing affected by the opt-out; (iii) any categories exempt from the opt-out (e.g., operational necessity disclosures); and (iv) instructions for re-authorizing sharing if you later choose to do so;
(d) Maintain the opt-out preference for a minimum of 24 months before requesting re-authorization; and
(e) For GPC-triggered opt-outs, display an on-screen notification on your next visit confirming that the GPC signal has been detected and honored.
KonfHub will not deny goods or services, charge a different price, or provide a different level of quality to any consumer who exercises their opt-out right. All opt-out requests are logged with a timestamp and confirmation record maintained in compliance with CPPA regulatory requirements.
Data Principals processing under Indian jurisdiction possess rights regarding their personal data, including the Right to Summarized Information, Right to Correction and Erasure, Right to Withdraw Consent, and the Right of Nomination. To exercise these rights or lodge a complaint, users can contact our designated Privacy Contact at privacy@konfhub.com or our Data Protection Officer at dpo@konfhub.com or submit the request from Privacy Request Center.
Grievance Resolution Timelines: (a) Acknowledgment: Data inquiries or grievances will be acknowledged within 48 hours of receipt. (b) Review and Resolution: We will investigate and respond with a resolution within 30 days from the receipt date. (c) Regulatory Escalation: If you do not receive a response within 30 days, or remain unsatisfied with the final resolution, you can escalate the matter directly to the Data Protection Board of India (DPBI) or your local data protection authority.
KonfHub is actively evaluating integration with registered Consent Managers ahead of the mandatory registration deadline of November 13, 2026 under the DPDP Rules 2025. Upon registration of eligible Consent Managers with the Data Protection Board of India, KonfHub will update its consent flows to enable Data Principals to give, manage, review, and withdraw consent through interoperable Consent Manager interfaces. We will issue advance notification to all users when Consent Manager integration is activated, with at least 30 days' notice before transitioning consent management to the new framework.
In compliance with the DPDP Rules 2025, at the time of collecting personal data, KonfHub provides Data Principals with a notice that is presented separately from the Terms of Use and that includes:
(a) An itemized description of the personal data being collected, including the specific fields and categories;
(b) The specific purpose(s) for which the personal data is being processed and the goods or services enabled by such processing;
(c) A direct, clickable link to withdraw consent and exercise Data Principal rights (accessible via the privacy dashboard at Privacy Request Center);
(d) Contact details for submitting grievances to our Privacy Contact (privacy@konfhub.com) and for escalation to the Data Protection Board of India; and
(e) Where applicable, the names of any significant Subprocessors or Data Fiduciaries who will process the data on behalf of the organizer.
In the event of a merger, acquisition, corporate restructuring, joint venture, reorganization, or asset sale, user data repositories may be transferred as part of the transaction. Any successor entity or acquiring third party must process personal data in accordance with this Privacy Policy, or issue an updated notice detailing any changes to processing activities. Users will be notified of such transitions via prominent platform alerts or direct email updates.
KonfHub will not deliver promotional materials, partner portfolios, or event notifications without obtaining appropriate consent. In certain regions, including India, separate opt-in consent choices are gathered specifically before dispatching promotional alerts via SMS text messages or WhatsApp communication networks.
Transactional updates—such as ticket confirmations, invoice receipts, dynamic security access codes, and critical policy amendments—do not require marketing opt-ins. Users can opt-out of promotional marketing at any point by clicking the 'Unsubscribe' link embedded in the footer of our emails, or by modifying communication choices within their profile dashboard.
To ensure clear, binding compliance protocols between KonfHub and enterprise event hosts, corporate clients, or Event Organizers, we maintain a comprehensive Customer Data Processing Agreement (DPA) framework. This Customer DPA is designed to integrate into our primary Terms of Service and individual software license agreements.
The DPA defines our strict handling limits as a Data Processor or Data Intermediary under applicable laws (including GDPR Article 28 parameters and corresponding DPDP Act processor requirements). It outlines our technical isolation commitments, subprocessor verification workflows, cross-border safeguard configurations, and breach coordination obligations. Event Organizers can execute our standard pre-signed Customer DPA by contacting our corporate support desks or visiting the account legal portals within their organization administration interface.
Data Controller Name: KonfHub Private Limited
Registered Office Address: No. 173, 6th A Cross, Asha Township, Doddagubbi, Bengaluru - 560077, Karnataka, India
Contact Email: privacy@konfhub.com
KonfHub Private Limited acts as the Data Controller for core account setups, website navigation telemetry, and general platform activity logs. For event-specific sign-ups, custom registration parameters, and ticket purchases managed by third parties, the respective external Event Organizer acts as the primary independent Data Controller, and KonfHub serves strictly as the Data Processor acting under their explicit instruction.
We process personal data across various core activities under defined GDPR Article 6 mechanisms:
• Account Provisioning & Contract Performance (Art. 6(1)(b)): Processing core contact fields and profile configurations necessary to deploy platform features and handle registrations.
• Legal Obligations (Art. 6(1)(c)): Retaining billing identifiers, corporate tax profiles, and transaction records to comply with mandatory local fiscal laws.
• Legitimate Interests (Art. 6(1)(f)): Collecting network security metrics, session keys, and diagnostic telemetry to protect our infrastructure against fraudulent usage patterns.
• Granular Consent (Art. 6(1)(a) / Art. 9(2)(a)): Managing promotional marketing scripts, optional tracking cookies, and optional visual biometric features.
Personal data may be shared with or accessed by the following categories of recipients:
• Core Infrastructure Providers: Authorized cloud hosting networks, storage instances, and server platforms (such as Amazon Web Services).
• Transaction Handlers: Integrated PCI-DSS compliant credit card and local billing gateways (such as Stripe and Razorpay).
• Communications Tools: Automated transactional email dispatch services and user support ticketing platforms.
• Authorized Event Hosts: Independent Event Organizers whose managed event registrations a user explicitly opts to complete.
Personal data handled within our environments may be transferred outside the EEA or the United Kingdom to server infrastructure clusters situated in India or the United States. To safeguard these transfers to jurisdictions without formal adequacy rulings, KonfHub implements statutory cross-border safeguards, including the execution of standard contractual clauses (SCCs) embedded within our processing contracts and subprocessor matrices.
We do not store personal data indefinitely. Data items are held only for the minimum durations required to fulfill their processing goals: account identity profiles are preserved for the lifespan of active registration agreements; basic security telemetry logs are cleared within 24 hours to 180 days; financial ledgers are securely archived for up to 7 years per statutory requirements; and opt-in biometric profiles are removed immediately upon withdrawal or within 30 days of event closure. Review Section 17 of this Policy for the formal data retention schedule.
Providing specific foundational personal categories (such as name, active email, and billing elements) is a mandatory requirement necessary to conclude registration agreements, create active account profiles, or purchase event tickets on our platform. Choosing to withhold these mandatory elements means that KonfHub will be unable to establish your profile or process your requested event registration records. Conversely, providing details for optional platform modules, including visual biometric verification, chat entries, marketing updates, or optional preferences, is completely voluntary, and choosing to bypass them does not impact your access to core platform services.
Data subjects maintain the absolute statutory right to lodge a formal complaint with their regional or local Supervisory Authority if they believe that KonfHub's data processing operations infringe upon the provisions or protections established under the GDPR framework.
Please review Section 6 of this Policy for an inventory of collected categories and operational purposes.
Indian Data Principals can exercise their statutory rights of access, correction, erasure, and nomination by submitting request in the Privacy Request Center or by writing to privacy@konfhub.com. Grievances will be reviewed within 30 days, with escalation available to the Data Protection Board of India (DPBI).
KonfHub is actively evaluating integration with registered Consent Managers ahead of the mandatory registration deadline of November 13, 2026, as required under the DPDP Rules 2025. Upon activation of Consent Manager integration, Data Principals will be able to give, manage, review, and withdraw consent through interoperable Consent Manager interfaces approved by the Data Protection Board of India.
In compliance with the DPDP Rules 2025, KonfHub provides a standalone notice at the point of personal data collection that is separate from our Terms of Use. This notice includes:
(a) An itemized description of the personal data being collected and the specific categories involved;
(b) The specific purpose(s) for which the personal data will be processed;
(c) The goods or services that the processing enables;
(d) A direct link to withdraw consent and exercise Data Principal rights;
(e) Contact details for the Grievance Officer (privacy@konfhub.com) and for escalation to the Data Protection Board of India.
In compliance with the DPDP Act and rules, KonfHub designates its Data Protection Officer as the Grievance Officer for purposes of the DPDP Act. Indian Data Principals may submit grievances to:
In compliance with DPDP Rule 8(3), KonfHub retains all personal data, traffic data, and logs generated during processing activities for a minimum of one (1) year. This 1-year minimum retention applies to security logs, access and authentication logs, traffic data, and cookie telemetry server-side records. Personal data for which the processing purpose has been fulfilled will be purged in accordance with the retention schedule in Section 17, subject to this 1-year minimum.
Over the preceding 12 months, KonfHub has processed identifiers (name, email, IP address), commercial financial tracking (transaction records, purchase history), internet activity telemetry (cookie data, clickstream), and professional or employment information (job title, organization). KonfHub does not sell your personal information for monetary consideration.
While KonfHub does not sell personal information, certain disclosures to analytics or event-promotion partners may constitute 'sharing' for cross-context behavioral advertising under CCPA/CPRA. California residents may opt out via:
Global Privacy Control (GPC) Signal: KonfHub recognizes and automatically honors GPC browser signals as valid opt-outs of sale and sharing for cross-context behavioral advertising. No additional action is required when a GPC signal is detected.
In compliance with CCPA/CPRA regulations effective January 1, 2026, KonfHub provides written confirmation that opt-out requests have been processed, specifying the date processed, categories affected, and instructions for re-authorization. Opt-out preferences are maintained for a minimum of 24 months.
The following categories of information KonfHub processes constitute Sensitive Personal Information under CCPA/CPRA:
California residents have the right to limit KonfHub's use and disclosure of Sensitive Personal Information to uses necessary to perform the services requested. To exercise this right, contact privacy@konfhub.com.
California residents have the following rights under CCPA/CPRA
• Right to Know: Request disclosure of personal information collected, used, shared, or sold. The right to know is not limited to a 12-month look-back period; KonfHub will provide access to historical data upon verified request.
• Right to Delete: Request deletion of personal information, subject to applicable exceptions.
• Right to Correct: Request correction of inaccurate personal information.
• Right to Opt-Out of Sale/Sharing: Opt out of sale or sharing for cross-context behavioral advertising (including via GPC signal).
• Right to Limit Use of Sensitive PI: Limit KonfHub's use of Sensitive Personal Information.
• Right to Non-Discrimination: KonfHub will not deny goods or services, charge a different price, or provide a different level of quality for exercising any privacy right.
Inquiries can be initiated by emailing privacy@konfhub.com or using the Privacy Settings in your account dashboard.
Based on a formal legal assessment, KonfHub has determined that it does not qualify as a 'data broker' under California Civil Code § 1798.99.80 (California Delete Act, SB 362). KonfHub's data disclosures are limited to operational subprocessors, event organizers acting as controllers, and other uses described in this Policy. This determination will be reassessed annually and upon any material change to data sharing practices.
Email: privacy@konfhub.com | Subject line: "California Privacy Rights Request"
Response time: Acknowledgment within 5 business days; resolution within 45 calendar days (extendable by 45 days with notice).
We partner with selected subprocessors to deliver platform features. This registry is updated periodically as our infrastructure requirements evolve:
| Corporate Entity | Processing Focus / Function | Headquarters Location | Safeguard Framework Implemented |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure hosting, database clusters, and media storage. | United States / India Regional Clusters | Enterprise DPA incorporating Standard Contractual Clauses (SCCs). |
| Stripe / Razorpay | Secure transactional processing and payment gateway pipelines. | United States / India | Direct PCI-DSS compliance verification protocols. |
| Google Analytics | Anonymized platform traffic metrics and technical error log tracking. | United States | Data anonymization configurations and automatic IP masking. |
Revision 2.0 (July 8, 2026)
This revision incorporates compliance remediation for DPDP Rules 2025, GDPR Articles 28, 33 & 37, and CCPA/CPRA 2026 requirements.
Summary of amendments: