Privacy Policy
Last updated: March 28, 2026
Your privacy is critically important to us. This Privacy Policy explains how SoftSys Solutions S.A.S collects, uses, discloses, and safeguards your information when you use SoftSysVideo.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address: Used for account authentication, communications, and password recovery
- Organization name: To identify your tenant account
- Password: Stored securely using industry-standard hashing (we never store plain-text passwords)
- Authentication tokens: OAuth tokens if you sign in with Google
1.2 Usage Data
When you use the Service, we automatically collect:
- Meeting data: Meeting IDs, names, start/end times, participant counts
- Participant information: Display names, join/leave timestamps, participant roles (moderator/attendee)
- Recording metadata: Recording IDs, durations, file sizes, creation dates
- Usage metrics: Number of minutes consumed, storage used, API calls made
- Technical logs: IP addresses, browser types, device information, error logs
1.3 Payment Information
Payment card information is collected and processed directly by PayPal, our payment processor. We do not store your credit card numbers or CVV codes. We only receive confirmation of successful transactions and maintain records of purchases for billing purposes.
1.4 Content Data
During video conferences, the following content may pass through our infrastructure:
- Video and audio streams: Transmitted in real-time between participants (not stored unless recording is enabled)
- Chat messages: Text messages sent during meetings
- Shared documents: Files shared during sessions
- Recordings: Video/audio recordings when recording feature is used
Video and audio streams are encrypted during transmission and are not stored on our servers unless the meeting host explicitly enables recording.
1.5 Mobile App Device Permissions
The SoftSysVideo mobile app for Android and iOS asks for the following device permissions. Each one is requested only when you join a meeting, and each can be denied or revoked at any time from your device settings — the app still joins, without the capability you declined:
- Microphone: Captures your voice so other participants can hear you. Audio is transmitted in real time and is not stored unless the meeting host enables recording.
- Camera: Captures your video when you turn it on. The camera stays off until you explicitly enable it, and video is not stored unless the meeting host enables recording.
- Screen recording: Used only for the "Share screen" feature, and only after you confirm the system prompt. Your screen is streamed to the other participants for as long as you keep sharing, and stops the moment you stop.
- Notifications: Displays the ongoing notification Android requires while a call is active, so the meeting keeps running when the app is in the background.
- Nearby devices (Bluetooth): Routes call audio to a connected Bluetooth headset. It is used for audio routing only — the app does not scan for, track, or derive your location from nearby devices.
The mobile app does not collect location data, does not read your contacts, photos, files or messages, and contains no advertising or analytics SDKs. It has no sign-up of its own: you enter a meeting through a link issued by your institution's learning platform, so the app creates no account and stores no credentials.
2. How We Use Your Information
2.1 Service Delivery
We use your information to:
- Provide and maintain the video conferencing service
- Authenticate your identity and authorize access
- Process and deliver recordings
- Calculate and charge for usage-based pricing
- Send transactional emails (meeting invitations, low-balance alerts, receipts)
2.2 Service Improvement
We analyze aggregated usage data to:
- Monitor service performance and reliability
- Identify and fix technical issues
- Optimize infrastructure capacity
- Develop new features and improvements
2.3 Security and Compliance
We use your information to:
- Detect and prevent fraud or abuse
- Enforce our Terms of Service
- Comply with legal obligations
- Respond to law enforcement requests when legally required
3. Data Processors and Third Parties
3.1 Infrastructure Providers
We use trusted third-party infrastructure providers to deliver the Service:
- Cloud infrastructure provider: Delivers our computing platform, database, file storage, and global content delivery network. All data is hosted in enterprise-grade data centers with ISO 27001 and SOC 2 certifications.
These providers act as data processors and are bound by strict data protection agreements. They do not use your data for their own purposes.
3.2 Payment Processor
PayPal: Handles all payment processing, including credit card transactions and invoicing. PayPal is PCI-DSS compliant and maintains strict security standards. View PayPal's privacy policy at paypal.com/legalhub/privacy-full.
3.3 Authentication Providers
If you sign in with Google OAuth, Google may collect information about your use of the Service in accordance with their privacy policy. We only receive basic profile information (email, name) necessary for authentication.
4. Data Security
4.1 Encryption
We implement industry-standard security measures:
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3
- At Rest: Databases and storage are encrypted using AES-256 encryption
- Video Streams: Real-time video/audio uses DTLS-SRTP encryption
4.2 Access Controls
We restrict access to personal data through:
- Multi-factor authentication for administrative access
- Role-based access control (RBAC) for internal systems
- Regular security audits and penetration testing
- Employee background checks and confidentiality agreements
4.3 Multi-Tenant Isolation
Each tenant account is logically isolated. Your data cannot be accessed by other tenants. All database queries and file access enforce strict tenant-based access controls.
5. Data Retention
5.1 Active Accounts
We retain your data for as long as your account remains active and for a reasonable period thereafter to provide continuous service and comply with legal obligations.
5.2 Deleted Accounts
When you delete your account, we retain your data for 30 days to allow account recovery. After 30 days, all personal data, including recordings, is permanently deleted from our systems. Some aggregated, anonymized data may be retained for analytics purposes.
5.3 Legal Requirements
We may retain certain information longer if required by law, regulation, legal process, or to protect our rights, property, or safety.
6. Your Rights (GDPR Compliance)
If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with similar data protection laws, you have the following rights:
6.1 Right to Access
You have the right to request a copy of the personal data we hold about you. You can access most of your data directly through the dashboard.
6.2 Right to Rectification
You can update your account information at any time through the dashboard settings.
6.3 Right to Erasure (Right to be Forgotten)
You can request deletion of your personal data by deleting your account or contacting our support team.
6.4 Right to Data Portability
You can export your meeting data and recordings at any time through the dashboard. Contact us if you need data in a specific machine-readable format.
6.5 Right to Restrict Processing
You can request that we temporarily restrict processing of your data in certain circumstances.
6.6 Right to Object
You can object to processing of your data for direct marketing purposes or based on legitimate interests.
To exercise any of these rights, please contact us at privacy@softsyssolutions.com. We will respond within 30 days.
7. Cookies and Tracking
7.1 Essential Cookies
We use essential cookies required for the Service to function:
- Session cookies: To maintain your login session
- Authentication tokens: To verify your identity
7.2 Analytics
We use privacy-focused analytics to understand how the Service is used. These analytics are aggregated and anonymized. We do not use third-party advertising trackers.
8. Children's Privacy
The Service is not intended for children under 13 years of age (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately so we can delete it.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
10. Data Selling Policy
We Do Not Sell Your Data
We have never sold personal data to third parties and have no plans to do so in the future. Your data is used solely to provide the Service. We do not share your data with advertisers or data brokers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by email or through a prominent notice in the dashboard. The "Last updated" date at the top of this page indicates when the policy was last revised.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Data Controller: SoftSys Solutions S.A.S
Location: Medellín, Colombia
Privacy Email: privacy@softsyssolutions.com
General Email: info@softsyssolutions.com
Support: support@softsyssolutions.com
Your privacy and data security are our top priorities. We are committed to protecting your information and handling it responsibly in accordance with applicable laws.