Privacy Policy
Medvento ("Medvento", "we", "us") is an event management platform for medical societies, associations and healthcare providers, operated by AMS Technologies (Udyam Registration No. UDYAM-UP-28-0047501), based in Noida, Uttar Pradesh, India. This policy explains what personal data we collect, why, how it's used, and the rights you have over it under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and its Rules.
This policy covers data collected through medvento.com, the org-level subdomains societies use to run their events (e.g. cardiacon.medvento.com), and admin.medvento.com.
1. Who this applies to
Two kinds of people interact with Medvento, and we collect different data for each:
- Organizers — society/association staff who sign up, configure events, and manage faculty, abstracts and registrations.
- Delegates & faculty — individuals who register for, present at, or attend an event run on Medvento by an organizing society. For this group, the organizing society is generally the data controller and Medvento acts as data processor on their behalf; we process this data to operate the platform they've chosen to use.
2. What we collect
| Category | Examples | Collected from |
|---|---|---|
| Account data | Name, email, phone, organization, login method (social/OTP) | Organizer sign-up |
| Event & registration data | Delegate name, contact details, registration form responses, ticket type | Delegate registration forms |
| Faculty data | Name, credentials, session assignments, confirmation status | Faculty invite & confirmation flow |
| Abstract submissions | Author details, submitted files, reviewer scores/comments | Abstract submission portal |
| CME & certificates | Session attendance, credit hours, generated certificates | Check-in and session tracking |
| Payment data | Transaction ID, amount, payment status — we never see or store full card/UPI details, these are handled directly by Razorpay | Razorpay checkout |
| Usage data | Login activity, device/browser info, pages visited | Automatically, via the platform |
3. Why we collect it
- To create and operate organizer, faculty and delegate accounts and event workflows
- To process registration payments and issue GST-compliant invoices
- To generate and deliver CME certificates and credit records
- To send transactional communications (confirmations, reminders, certificates) via email and WhatsApp
- To detect fraud, abuse and spam on registration and payment flows
- To comply with tax, accounting and legal obligations
We do not sell personal data, and we do not use delegate or faculty data for advertising.
4. Legal basis and consent
Where the DPDP Act requires consent, we collect it explicitly — for example, via a consent checkbox at organizer registration, and through each event's registration form for delegates. Where processing is necessary to perform a contract (e.g. delivering a certificate you registered for) or to comply with law (e.g. GST invoicing), we rely on that basis instead of, or in addition to, consent.
5. Who we share data with
We share data only with service providers who help us run the platform, under contractual confidentiality obligations:
- Razorpay — payment processing (India)
- Resend — transactional email delivery
- WhatsApp Business API provider (Meta) — message delivery, where an organizer enables WhatsApp notifications
- Supabase / hosting infrastructure — database, authentication and file storage
If you registered for a specific event, your registration and abstract data is also visible to the organizing society running that event, since they are the ones running the conference.
6. Data retention
We retain account and event data for as long as the organizing society's account is active, plus a reasonable period afterward for legal, accounting and dispute-resolution purposes. You can request deletion at any time (see Section 8) — we'll retain only what we're legally required to keep, such as payment records for tax purposes.
7. Security
We use industry-standard safeguards — encrypted connections (TLS), role-scoped database access (RLS), and access controls limiting who can see organizer, faculty and delegate data. No system is 100% secure, and we'll notify affected users and the Data Protection Board where required if a breach materially affects your data.
8. Your rights as a Data Principal
Under the DPDP Act, you can:
- Ask what personal data we hold about you and why
- Correct inaccurate or incomplete data
- Withdraw consent (this may limit or end your access to certain features)
- Request erasure of your data, subject to legal retention requirements
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
- Raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India if unresolved
To exercise any of these — including a data deletion request — contact our Grievance Officer below, or use the self-serve data request tool in your account settings, where available.
9. Grievance Officer
Grievance Officer, AMS Technologies
Email: support@medvento.com
Address: C-1203, Sethi Max Royal, Sector 76, Noida, Uttar Pradesh 201301
We aim to acknowledge grievances within 5 business days.
10. Cookies
We use a small number of cookies to run the platform:
- Essential cookies — login sessions, security tokens. Required for the platform to function; these can't be disabled.
- Analytics cookies — help us understand usage patterns so we can improve the product using GA4 as analytics provider.
You can control or clear cookies through your browser settings. Disabling essential cookies will prevent you from logging in.
11. Cross-border data
Our infrastructure providers may process or back up data outside India as part of standard cloud hosting operations. Most of our infrastructure is located within the United States. Where this happens, we rely on providers with appropriate contractual and security safeguards.
12. Children's data
Medvento is intended for use by adult healthcare professionals and society staff. We do not knowingly collect personal data from individuals under 18.
13. Changes to this policy
We'll update this page when our practices change and update the "Last updated" date above. Material changes affecting how we use previously collected data will be communicated directly where required.
14. Contact
Questions about this policy: support@medvento.com. For account or event support, see our Contact Us page.