
Designed with reference to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025
This notice explains how IAMMTAPC 2026 collects, uses, stores, shares, protects, and retains personal data. It also describes the mechanisms available to Data Principals for exercising applicable privacy rights.
Submit a request relating to access, correction, erasure, consent withdrawal, or grievance.
This Privacy Policy applies to the processing of digital personal data in connection with the XXIX IAMM TAPC Chapter Annual Conference 2026 ("IAMMTAPC 2026"), including its registration, abstract submission, communication, payment, badge, certificate, and related conference services.
The conference organising body acts as the entity responsible for determining the purposes and means of processing personal data for the conference services described in this notice.
We aim to follow the principle of data minimisation and collect personal data that is reasonably necessary for the specific conference services and purposes described in this notice.
Full name, title/designation, institution/organisation, email address, mobile number, city, and state, where required for registration or communication.
Professional registration information, IAMM TAPC membership status, delegate category, and related eligibility information where required.
Abstract title, author/co-author names, affiliations, scientific content, HOD endorsement letters, presentation files, and related submission information.
Order ID, transaction reference, payment timestamp, amount, payment status, and invoice references. We do not intentionally store card numbers, CVV, UPI PINs, or banking credentials.
Registration ID, QR/badge identifier, check-in information, attendance records, certificate information, and accompanying-person information where applicable.
IP address, browser/device information, session information, consent records, notice/policy version, timestamps, and security/audit information where required.
Personal data is processed only for specified conference, operational, legal, security, and communication purposes. Depending on the processing activity, the applicable legal basis may include consent or processing permitted/required by applicable law.
Where processing is based on consent, we aim to obtain consent through clear, specific, informed, and affirmative actions. The privacy notice provided at the point of collection is intended to explain the personal data being collected and the specific purpose for which it is processed.
We use selected third-party service providers to support payment processing, document storage, email/SMS/WhatsApp communications, hosting, and other conference operations. Personal data is shared only where necessary for the relevant purpose. Appropriate contractual, confidentiality, security, and data-protection safeguards are sought where applicable.
| Service Provider | Purpose | Personal Data Shared | Security / Safeguards |
|---|---|---|---|
Razorpay Software Pvt. Ltd. | Payment processing and payment-status verification | Name, email, mobile number, registration/order reference, amount, and transaction-related information | Encrypted transmission and payment-security controls provided by the payment service |
Cloudinary Inc. | Storage and delivery of abstracts, documents, and presentation materials | Uploaded abstract files, HOD letters, presentation files, and related file metadata | HTTPS transmission and access-controlled/private delivery mechanisms where configured |
Email / SMTP Service Provider | Transactional emails, invoices, receipts, registration and conference communications | Recipient name, email address, registration information, and relevant communication/document information | Encrypted transmission and provider-level email security controls |
SMS / WhatsApp Messaging Provider | Transactional alerts, notifications, reminders, and event communications | Name, mobile number, registration ID, and message-related information | Encrypted transmission and applicable messaging-provider security controls |
Vercel / Railway Infrastructure | Website hosting, application execution, networking, and infrastructure services | IP address, request metadata, technical headers, session/technical information, and other data processed through the hosted application | Infrastructure access controls, encryption in transit, monitoring, and provider security controls |
Conference Eligibility: IAMMTAPC 2026 is intended for medical professionals, faculty, postgraduates, researchers, delegates, and other eligible conference participants.
The conference website is not intended to knowingly collect or process personal data of children for ordinary conference participation. We do not use children's personal data for behavioural tracking or targeted advertising.
If we become aware that personal data relating to a child has been collected where the applicable requirements have not been satisfied, we will take appropriate steps consistent with applicable law.
Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, to provide requested services, to maintain required records, or to comply with applicable legal, accounting, security, or dispute-resolution requirements.
| Data Category | Retention Approach | Disposal Approach |
|---|---|---|
| Registration & Badge Data | For the conference lifecycle and the period reasonably required for post-event administration, certificate verification, dispute handling, or other legitimate operational needs. | Deletion or anonymisation when no longer required, subject to applicable retention obligations. |
| Financial & Invoice Records | For the period required by applicable tax, accounting, financial, or other legal obligations. | Deletion or anonymisation when the applicable retention requirement expires, subject to legitimate archival requirements. |
| Scientific Abstracts & Proceedings | For conference proceedings, scientific/academic archival, publication, or other purposes communicated to participants, as applicable. | Deletion, archival, or anonymisation depending on the publication/archival purpose and applicable requirements. |
| Transactional Delivery Logs | For the period reasonably required for delivery verification, troubleshooting, security, and operational purposes. | Periodic deletion or anonymisation according to the platform's operational retention schedule. |
| Consent & Privacy Request Records | For as long as reasonably necessary to demonstrate consent status, process requests, resolve disputes, and meet applicable legal requirements. | Secure deletion or anonymisation when no longer required. |
Subject to the applicable provisions of the DPDP framework, you may have rights including the following:
We implement reasonable technical and organisational measures appropriate to the nature of the personal data and the risks associated with its processing.
HTTPS/TLS is used for protected communication between users, the application, and applicable service providers.
Role-based and authenticated access controls are used for administrative and operational systems.
Authentication credentials are protected using appropriate password hashing and security practices.
Personal information should be minimised and masked in logs and operational diagnostics where practical.
Uploaded documents are subject to access controls and secure delivery mechanisms where configured.
Security incidents are investigated, contained, documented, and escalated in accordance with applicable requirements.
You can submit a privacy request through the available online mechanism or by contacting the conference privacy/grievance contact.
Submit your request with sufficient information for us to identify and process it.
We may take reasonable steps to verify the identity of the requester.
We assess the request against applicable legal, operational, security, and retention requirements.
We communicate the outcome and any applicable next steps.
The website may use cookies or similar technologies for essential functionality, security, session management, preferences, analytics, or other purposes depending on the services enabled on the website.
Required for core website functionality, security, authentication, and session management.
Used to remember choices and improve the user experience where applicable.
Optional measurement or analytics technologies may be controlled through the available privacy settings.
Some technology and infrastructure providers used by the conference platform may operate infrastructure or process data in locations outside India. The applicable location and processing arrangements depend on the services actually configured for the production platform.
Where applicable, we will implement contractual, technical, and organisational safeguards and comply with any requirements imposed under applicable Indian law concerning processing or making personal data available outside India.
Abstract submissions may contain personal information relating to authors, co-authors, institutions, and scientific work. Access to submissions is restricted according to the conference workflow.
Author email addresses, mobile numbers, login credentials, payment information, and other non-public personal information should not be displayed on public abstract, speaker, or conference pages unless there is a valid and appropriately communicated basis for doing so.
If you have a question, concern, or grievance relating to the processing of your personal data, please contact the conference secretariat using the details below.
We may update this Privacy Policy from time to time to reflect changes in the conference services, technology, applicable law, third-party services, or data-processing practices.
When material changes are made, we will update the version and last-updated date shown at the top of this page and, where appropriate, provide an additional notice or obtain consent where required.
The conference platform is being designed and operated with privacy-by-design principles and with reference to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
This notice describes the platform's current privacy practices and should not be interpreted as a legal certification or guarantee of statutory compliance. Organisational policies, contractual arrangements, retention schedules, processor agreements, and other compliance matters should be reviewed by the appropriate legal/privacy authority before making a formal compliance representation.