Legal

Privacy Policy

Last updated: 2026

This Privacy Policy explains how ConferenceOS (“ConferenceOS”, “we”, “us” or “our”) handles personal data when you use our conference management platform — including abstract submission, peer review, registration and payments — and when you visit this website. We have written it to be clear and readable rather than dense with legalese. It is a template policy intended to illustrate our approach; the binding terms for any given event are those agreed with the conference organiser and ConferenceOS.

1. Who we are

ConferenceOS is operated by BdREN — Bangladesh Research and Education Network, a not-for-profit national research and education network. BdREN acts as the data controller for the operation of the platform itself, and as a data processor on behalf of the conference organisers who run their events on ConferenceOS. For any specific conference, the organising committee is the controller of the submissions, reviews and registrations they collect.

2. Data we collect

We collect only what is needed to run a conference well. Depending on your role (author, reviewer, chair, attendee or organiser) this may include:

  • Account information — your name, email address, affiliation, ORCID or similar identifier, password (stored only as a salted hash) and notification preferences.
  • Submissions — abstracts, full papers, supplementary files, co-author details, track and topic selections, and the answers you provide on submission forms.
  • Reviews — scores, written reviews, confidential comments to chairs, bids, conflict-of-interest declarations and meta-reviews.
  • Registration and payment metadata — ticket type, invoice details, billing name and address, registration status and a payment reference returned by our payment provider. We do not store full card numbers (see section 6).
  • Usage data — pages visited, features used, approximate device and browser information, and security logs such as IP address and sign-in timestamps used to detect abuse.

3. How we use it

We use personal data to:

  • Operate the core workflow — receive submissions, assign and collect reviews, record decisions and notify the people involved.
  • Manage registration, issue invoices and reconcile payments.
  • Authenticate you, keep your account secure and prevent fraud or abuse.
  • Send service messages such as deadline reminders, status changes and decision letters.
  • Improve reliability and performance through aggregated, de-identified analytics.

4. Legal bases (GDPR)

Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases: performance of a contract to deliver the platform and process your registration; legitimate interests to secure the service, prevent abuse and improve the product; consent for any optional communications, which you may withdraw at any time; and legal obligation where we must retain records for tax or accounting purposes.

5. Payment processing

Registration payments are handled by PCI-DSS compliant payment providers — Stripe, Razorpay and SSLCommerz, depending on your region. Card details are entered directly with the provider and are never transmitted to or stored on our servers. We retain only a non-sensitive payment reference, the amount and the status so we can match a payment to a registration and support refunds. Each provider processes data under its own privacy policy.

6. Cookies and local storage

We keep cookie usage minimal. After you sign in we store an authentication token in your browser's local storage to keep you logged in; clearing it or signing out removes it. We also use strictly necessary cookies for security and for remembering your language and interface preferences. We do not use third-party advertising or cross-site tracking cookies.

7. Data sharing

We share data only as needed to run your event:

  • Conference organisers — chairs and committee members can see the submissions, reviews and registrations for their own conference, in line with the review model they configure (for example, double-blind reviewing hides author identities from reviewers).
  • Processors — vetted service providers acting on our instructions, such as cloud hosting, email delivery and the payment providers named above. They may process data only for the purposes we specify.

We do not sell personal data. We may disclose information where required by law or to protect the rights and safety of our users.

8. International transfers

Conferences on ConferenceOS are run by organisers around the world, so data may be processed in countries other than your own. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, and we apply the same protections described in this policy regardless of where processing takes place.

9. Retention

We keep personal data only for as long as it is needed. Submissions, reviews and decisions are retained for the duration of the conference and, where the organiser publishes proceedings, for the scholarly record. Account data is kept while your account is active. Financial records are retained for the period required by applicable tax law. When data is no longer needed we delete or anonymise it.

10. Your rights

Subject to applicable law, you have the right to request access to your personal data, to have inaccurate data corrected (rectification), to ask for erasure where there is no overriding reason to keep it, and to receive a copy of the data you provided in a portable, machine-readable format (portability). You may also object to or restrict certain processing. To exercise these rights, contact us using the details in section 14; where the conference organiser is the controller, we will help route your request to them.

11. Security

We protect data with encryption in transit (HTTPS), hashed passwords, role-based access controls, audit logging and regular backups. No system is perfectly secure, but we work to limit risk and to respond quickly to any incident, including notifying affected users and authorities where the law requires.

12. Children

ConferenceOS is intended for academic and professional use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will remove it.

13. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you through the platform.

14. Contact

Questions about this policy or your data? Email us at hello@conferenceos.io or reach out through our contact page. We aim to respond to privacy requests promptly.