1. Introduction & Scope
Samgamam is a multilingual community platform designed to help school and college alumni circles, cultural organizations, and local groups organize events, share memories, coordinate RSVPs, and stay connected.
This Privacy Policy applies to all users worldwide who visit our public pages, register an account, organize or attend events, participate in group discussions, or otherwise interact with Samgamam.
2. Data Controller
Samgamam is a product and service operated by LuminosichtAI. The entity responsible for the processing of your personal data ("Data Controller") is: LuminosichtAI JERA-94, Greenpark Villas, Jagathy, Thycaud P.O., Thiruvananthapuram, Kerala 695014, India Privacy Contact: contact@luminosichtai.com Website: https://samgamam.com
3. Personal Data We Collect
We collect only the personal information strictly necessary to provide our platform functionality, maintain account security, and facilitate community event coordination:
- Account & Registration Information (name, email, password hash, language preference, platform roles)
- Social Login Identifiers (external provider account identifier, email address where made available by the provider, and profile name)
- Event & Attendance Records (RSVP registrations, attendance state, check-in timestamps, QR ticket token)
- Legal Acceptance and Notice Records (records showing the versions of our Terms of Service, Privacy Policy notices and, where applicable, event risk acknowledgements that were presented to or acknowledged by users; including a pseudonymous account reference, event and registration references, document version, acknowledgement type, document hash, and timestamp)
- Community & Discussion Content
- Event Feedback
- Technical, Session & Security Data (session tokens, hashed IP addresses and hashed device identifiers, rate-limiting metadata, security audit logs)
- Transactional Communications logs
5. Purposes of Processing & Legal Bases (GDPR)
- Account creation, authentication: Art. 6(1)(b)
- Event creation, RSVP registration, waitlist promotion, QR check-in: Art. 6(1)(b)
- Community discussions: Art. 6(1)(b)
- Transactional emails: Art. 6(1)(b) & Art. 6(1)(f)
- Platform security, abuse prevention, audit logging: Art. 6(1)(f)
- Maintaining legal acknowledgement and notice records: Legal obligation where applicable (Art. 6(1)(c)) and legitimate interest in establishing, exercising or defending legal claims and dispute resolution (Art. 6(1)(f))
- Statutory record-keeping: Art. 6(1)(c) / Art. 6(1)(f)
7. Event Organizers & Attendee Data
Organizers receive access to attendee roster information strictly for event organization, capacity management, venue admission, and logistical coordination.
8. Third-Party Service Providers (Processors)
- Web & Application Hosting: Vercel Inc.
- Database Infrastructure: Neon PostgreSQL
- Authentication Providers: Google LLC, Meta Platforms Ireland Ltd., Okta Inc. (Auth0)
- Email Delivery: Transactional email delivery service
9. International Data Transfers
Where international data-transfer rules apply, LuminosichtAI uses or requires an appropriate transfer mechanism permitted by applicable law.
10. Data Retention
Personal information is retained only for as long as necessary to fulfill the purposes described in this policy:
- Account Data: Retained for the duration of your active account. When you request account deletion, personal data is deleted or anonymized in accordance with our deletion workflow.
- Legal Acknowledgement Records: Certain legal acknowledgement records may be retained after account deletion where reasonably necessary to establish, exercise or defend legal claims, resolve disputes, prevent fraud, or comply with applicable legal obligations. These records are kept only for as long as necessary for those purposes and are subject to data minimization.
- Community & Discussion Content: Kept during active community participation; upon account deletion, comments and posts are disassociated and anonymized so threads remain coherent for others.
- Security Audit Logs: Retained in restricted log storage for a limited period necessary for security monitoring, dispute resolution, and fraud defense.
- Authentication Sessions: Authentication sessions automatically expire according to the platform's configured security settings.
11. Account Deletion & Your Privacy Rights
Users have rights under applicable privacy laws (access, rectification, erasure/deletion, restriction & objection). When you request account deletion, Samgamam deletes or anonymizes account and ordinary personal data in accordance with the applicable deletion workflow. Some deletion operations involving external identity providers may require additional processing time. Certain narrowly scoped legal acknowledgement records and security audit logs may be retained where reasonably necessary to establish, exercise or defend legal claims, resolve disputes, prevent fraud, or comply with applicable legal obligations, subject to data minimization. You can request deletion of your account through Account Settings → Security Settings ("Danger Zone") or by following the Data Deletion instructions.
12. Security Safeguards
Encrypted transport (TLS/HTTPS), cryptographic password derivation, HMAC-SHA256 session signatures, hashed sensitive identifiers in logs, rate limiting, and security audit logging.
13. Children & Age Restrictions
Samgamam is not specifically designed for children. Users must be legally able to create an account under the laws applicable to them. Where parental or guardian authorization is required by applicable law, an account must not be created without the required authorization.
14. Automated Decision-Making & Profiling
No decisions based solely on automated processing or profiling that produce legal or similarly significant effects.
15. Changes to This Privacy Policy
Periodically updated to reflect technical enhancements, service changes, or regulatory requirements.
16. Contact Information & Supervisory Authority
LuminosichtAI JERA-94, Greenpark Villas, Jagathy, Thycaud P.O., Thiruvananthapuram, Kerala 695014, India Email: contact@luminosichtai.com EU residents have the right to lodge a complaint with their competent data protection supervisory authority.
4. Social Login & Third-Party Authentication