Legal
Your data stays yours.
What we collect, why we collect it, how long we keep it, and how to get it back or get rid of it. Written to be read, not to be survived.
Last updated 2 September 2026
Who we are
Olivasal is a video meeting platform operated by Megam Technologies, India. This policy covers the Olivasal website at olivasal.com, the Olivasal web application, and the Olivasal API.
Olivasal is also distributed as self-hosted software. When you run Olivasal on your own servers, your organisation is the data controller and this policy does not govern that deployment — we never receive your meetings, recordings, or transcripts. The one exception is licence validation, described in Self-hosted deployments.
For questions about this policy, email support@megamtech.com.
What we collect
We collect only what the product needs to work. We do not sell personal data, and we do not use meeting content to train AI models.
| Data | Why we hold it | Retention |
|---|---|---|
| Account details Name, email, password hash, company, profile photo |
Create your account, sign you in, show you to other participants | Until you delete the account |
| Meeting metadata Room name, participants, join and leave times, host actions |
Run the meeting, build your meeting history, produce the host audit log | Until you delete the meeting |
| Recordings and transcripts Video, audio, chat transcript, AI summary |
Only created when a host starts a recording or enables AI recaps | Until deleted by the host or an administrator |
| Chat and files In-meeting messages and any attachments |
Deliver messages during the meeting and in the meeting record | Until the meeting is deleted |
| Connected accounts OAuth tokens for Google, Microsoft, Zoho |
Sync your calendar and send invitations from your own mailbox | Until you disconnect the integration |
| Billing Plan, seat count, invoices |
Charge for paid plans and meet tax obligations | As long as tax law requires |
| Technical logs IP address, browser, error traces |
Keep the service up, investigate abuse and outages | Typically 30 days |
We do not collect special-category data, and we ask you not to send it through the contact form.
Google user data
Connecting a Google account is optional. Olivasal works fully without it. If you do connect one, here is every scope we request and exactly what we do with it.
| Scope | What Olivasal does with it |
|---|---|
calendar.events |
Creates a calendar event when you schedule an Olivasal meeting, and updates or removes that event when the meeting changes or is cancelled. |
calendar.readonly |
Reads your existing events in a limited window — 14 days back, 90 days ahead — so the scheduler can show your availability and warn you about conflicts. |
gmail.send |
Sends meeting invitations from your own address so recipients see a sender they recognise. We only send. We never read, list, or modify your mail. |
userinfo.email, openid |
Identifies which Google account is linked, so you can see it in settings and we can refresh the connection. |
How Google data is stored
- Access and refresh tokens are encrypted at rest and are never exposed to the browser or to other users.
- Calendar events are cached only for the 14-day-back / 90-day-ahead window, and only to render your availability.
- Google data is never used for advertising, never sold, never shared with third parties, and never used to train AI models.
- Only automated systems process this data. No human at Megam Technologies reads your calendar or your mail.
Disconnecting
Go to Settings → Integrations and choose Disconnect. We delete the stored tokens and the cached calendar events immediately. You can also revoke access at myaccount.google.com/permissions.
Olivasal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Recordings, transcripts, and AI
Recording is off unless a host turns it on, or unless the company administrator has enabled automatic recording for scheduled meetings.
- Every participant sees a recording indicator while a recording is running. Joining a meeting that is being recorded is your consent to that recording.
- Hosts and participants may also save a local copy to their own device. That file never reaches our servers.
- AI recaps — transcript, summary, action items — are generated only from meetings that were recorded, and only when AI recaps are enabled.
- On our managed cloud, transcription and summarisation run on infrastructure we operate. Meeting audio is not sent to a third-party AI provider.
- Meeting content is never used to train models, ours or anyone else's.
Recording laws differ by country and by state. You are responsible for obtaining any consent your jurisdiction requires before recording a meeting.
How we protect data
- All traffic is encrypted in transit with TLS.
- Passwords are stored as salted hashes. We can never read them.
- OAuth tokens and other integration secrets are encrypted at rest with a per-deployment key.
- Media flows through servers we operate ourselves, not a third-party conferencing vendor.
- End-to-end encryption is available on paid plans for meetings that need it.
- Access to production systems is limited to the engineers who need it and is logged.
No system is perfectly secure. If you find a vulnerability, report it to security@megamtech.com and we will respond.
Your rights
Wherever you live, you can ask us to:
- Access the personal data we hold about you
- Correct anything that is wrong — most of it is editable in Settings
- Delete your account and its data
- Export your data in a portable format
- Withdraw consent for any integration you have connected
- Object to or restrict processing
Email support@megamtech.com and we will respond within 30 days. These rights are granted under the EU and UK GDPR and India's Digital Personal Data Protection Act, and we extend them to everyone regardless of where you are.
If your account belongs to a company workspace, your administrator may also hold data about you. Contact them for requests we cannot fulfil directly.
Deletion and retention
Delete a meeting and its recordings, transcripts, and chat go with it. Delete your account and we remove your profile, your connected integrations, and the meetings you own.
Backups roll off within 30 days, so deleted data can survive that long in backup storage before it is gone for good. We keep billing records longer where tax law requires it.
Self-hosted deployments
If you run Olivasal on your own infrastructure, your meetings, recordings, transcripts, and user accounts stay on your servers. We cannot see them.
A licensed self-hosted instance sends a periodic validation check to our licence server containing the instance identifier and licence key — no personal data, no meeting content. If the check cannot reach us, your instance keeps running.
Children's data
Olivasal is built for organisations and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has created an account, email support@megamtech.com and we will remove it.
Changes to this policy
We update this policy when the product changes. The date at the top always reflects the current version. For changes that materially affect how we handle your data, we will notify account holders by email before the change takes effect.
Contact us
Megam Technologies, India — the company behind Olivasal.
- Privacy and data requests — support@megamtech.com
- Security disclosures — security@megamtech.com
- Everything else — the contact page