GDPR & Data Protection Notice

LAST REVISED: JANUARY 2026

This notice explains how Seminara complies with the General Data Protection Regulation (GDPR) and outlines your rights as a data subject under European and international data privacy frameworks.

SECTION 01

Data Controller

Omni AI Club Private Limited

Registered Office: Bokajan, Karbi Anglong, Assam, India, 782480
Product: Seminara (seminara.online)
Privacy & Data Protection Contact: shivamselam@seminara.online

SECTION 02

Personal Data We Process

We process only the minimum necessary data required to operate the service:

  • Account Information: Full name, email address, profile avatar.
  • Authentication Data: Scoped OAuth tokens (Google Sign-In) or cryptographic magic links. We never collect or store passwords.
  • Presentation Content: Slide PDFs, speaker notes, and proprietary knowledge base documents uploaded to your private tenant.
  • Session Interaction Logs: Session IDs, connection timestamps, and attendee Q&A transcripts logged for your dashboard review.

Key Technical Safeguards:

  • Zero model training: Customer content is never used to train or fine-tune external foundation models.
  • Real-time voice synthesis: Voice audio streams are synthesized in real time and dispatched under zero-retention API policies.
  • Tenant isolation: All data is guarded by PostgreSQL Row-Level Security (auth.uid() = host_id).
SECTION 03

Purpose & Legal Basis for Processing

We process personal data under the following GDPR legal bases (Article 6):

Contractual Necessity

To host interactive presentation sessions, render slides, field live questions, and manage user accounts.

Legitimate Interests

To monitor infrastructure health, prevent abuse, enforce quota boundaries, and maintain platform security.

Explicit Consent

Where you explicitly opt into transactional email notifications, beta features, or developer updates.

SECTION 04

Infrastructure Sub-Processors

We work with industry-standard infrastructure providers operating under strict Data Processing Agreements (DPAs):

Supabase (PostgreSQL & Auth)

Encrypted database storage, user authentication, and row-level partitioning.

Dodo Payments (Merchant of Record)

PCI-DSS Level 1 compliant subscription and billing processor.

LiveKit & WebRTC Edge

Low-latency real-time audio rooms and bidirectional presentation signaling.

Deepgram & Voice Synthesis

Zero-retention neural speech recognition and voice synthesis pipelines.

SECTION 05

Your GDPR Data Subject Rights

Under Articles 15 through 22 of the GDPR, you have the following enforceable rights:

  • Right to Access (Article 15): Request a copy of all personal data held about you in portable, machine-readable format.
  • Right to Rectification (Article 16): Correct inaccurate or incomplete account details directly through the dashboard.
  • Right to Erasure (Article 17): Request permanent deletion of your account, presentations, slides, and all associated embeddings.
  • Right to Restrict Processing (Article 18): Request temporary or permanent restriction of data processing activities.
  • Right to Data Portability (Article 20): Export your raw presentation assets and structured transcript logs via REST API.

To exercise any of these rights, email us at shivamselam@seminara.online. We process all verified requests within 30 days without charge.

SECTION 06

International Data Transfers

Where data is transferred across international jurisdictions, we ensure adequate protection standards through Standard Contractual Clauses (SCCs), certified enterprise hosting providers, and strict end-to-end TLS 1.3 cryptographic transport.