Privacy Policy
In short
- We play two different roles. For the data inside our customers' CRMs, mailboxes and calls, we are a processor acting on our customer's instructions — that customer, not us, decides what happens to it. For our own website visitors, account holders and business contacts, we are a controller.
- We do not train AI models on customer content, and our AI providers are contractually barred from doing so.
- We do not sell personal data, and we do not use it for advertising.
- This website sets no cookies and runs no analytics or tracking.
- If your personal data appears in a customer's deal records and you want it removed, we will route you to that customer, because they control it — see section 9.
This summary is for orientation only. The sections below govern.
1. Who we are
Trade licence No. 66961
Registered office: IFZA Properties, Premises DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates
Contact: hello@sumgate.io
1.1 We provide Sumgate Signal, a service that analyses the history of a sales deal — emails, call and meeting transcripts, and CRM records — and returns a structured assessment with supporting quotations.
1.2 This policy explains what we do with personal data. It applies to our website, to the Signal application, and to our dealings with business contacts.
1.3 We are established in the United Arab Emirates and subject to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Where we process personal data of individuals in the European Economic Area or the United Kingdom on behalf of a customer established there, the EU General Data Protection Regulation or the UK GDPR applies to that processing, and we act as processor under it.
2. The two roles we play
2.1 The distinction below determines who is accountable for what, and where you should direct a request.
- We are a processor for Customer Content
- Our customer — the business that subscribes to Signal — decides which systems to connect, which deals to analyse, and what to do with the result. It is the controller. We process that content only on its instructions, under our Data Processing Agreement. This covers the emails, transcripts, meeting records and CRM data described in section 3, including personal data about people who have never heard of us.
- We are a controller for our own data
- For the personal data described in section 4 — website visitors, people who fill in our contact form, account administrators, billing contacts and business contacts we speak to about our product — we decide the purposes and means, and we are accountable directly to you.
2.2 We do not use Customer Content for our own purposes. We do not mine it for leads, market intelligence, benchmarking, or product development.
3. Customer Content: what we process for our customers
3.1 At our customer's instruction, and using the access permissions its administrators grant, we retrieve and analyse:
| Source | What we read |
|---|---|
| CRM (e.g. HubSpot) | Deal records, stages, values, close dates, activity history, contact and company records, notes, owner assignments |
| Message headers, sender and recipient addresses, timestamps and message bodies of threads associated with the deal | |
| Calls and meetings (e.g. Zoom, Google Meet, Aircall) | Transcripts, participant lists, timestamps, duration and call metadata |
| Calendar | Meeting titles, times, attendees, and whether meetings occurred |
3.2 The personal data in that content typically includes: names, business email addresses and phone numbers, job titles, employer, and — importantly — the substance of what people wrote and said, together with our system's characterisations of their behaviour, such as that a person has stopped replying.
3.3 Categories of individuals affected. This includes our customer's own personnel, and also employees and representatives of our customer's prospects and customers. Those individuals have no direct relationship with us. Their information reaches us because our customer instructed us to read records in which it appears.
3.4 Special category data. The Service is not designed to process special category or sensitive personal data, and our customers are contractually prohibited from submitting it. Free-text communications can nevertheless contain incidental sensitive information. We do not seek it out, do not index it, and do not use it to derive any characteristic about an individual.
3.5 Lawful basis and consents are our customer's responsibility. Our customer warrants to us that it has established a lawful basis, given the necessary notices, and obtained any consents its law requires — including consent to record calls where that is required, and any employee-monitoring formalities. We are not in a position to verify that, and we do not.
4. Data we process as controller
| Who | Data | Purpose | Legal basis (GDPR/UK GDPR) |
|---|---|---|---|
| Website visitors | IP address, user agent, request paths and timestamps, in server logs | Serving the site, security, diagnosing faults, preventing abuse | Legitimate interests (operating and securing our website) |
| People who submit our contact form | Name, work email, phone number, and the fact and time of submission | Responding to the enquiry, arranging a demonstration, and follow-up about our product | Legitimate interests in responding to an enquiry you initiated; where required by local law, consent, which you may withdraw |
| Account administrators and Authorised Users | Name, work email, role, authentication events, audit and activity logs | Providing and securing the account, support, audit trail | Performance of a contract; legitimate interests (security) |
| Billing contacts | Name, email, billing address, tax identifiers, invoice and payment records | Invoicing, collection, accounting, tax | Performance of a contract; legal obligation |
| Business contacts | Name, employer, role, business contact details, correspondence | Business communication about our product | Legitimate interests (business-to-business communication); consent where required |
4.1 We do not buy personal data from data brokers, and we do not enrich our records from third-party datasets.
4.2 Where we rely on legitimate interests, we have considered the impact on you and concluded that the processing is proportionate and would be expected in a business context. You can ask us for our assessment, and you can object — see section 10.
4.3 We do not send marketing email to individuals at consumer addresses. If you no longer want to hear from us, reply to any message or write to hello@sumgate.io and we will stop.
5. How we use AI, and what we do not do
5.1 To produce an analysis, we send the relevant records — which contain personal data — to a third-party large language model provider for inference. The provider returns the analysis to us and we present it to our customer.
5.2 We commit that:
- Customer Content is not used to train, fine-tune or improve any generalised, foundational or frontier AI or machine learning model, whether ours or a third party's;
- our AI providers are engaged under terms that prohibit training on the data we send them and require them not to retain it beyond what is needed to return a response;
- Customer Content is not stored in conjunction with any such model; and
- Customer Content is not disclosed to any AI provider for that provider's own purposes.
5.3 What we retain. Source records are processed for the duration of the analysis and are not stored by us as a copy of your systems. The analysis we produce is stored — including the conclusions and the verbatim quotations that evidence them — so that our customer can return to it, and so that scheduled reviews can reference earlier findings. Those quotations are extracts of the underlying communications and therefore contain personal data. Retention is described in section 9.
5.4 We do not use AI to make decisions about individuals. See section 15.
5.5 Output is generated by statistical inference and can be inaccurate. Our customers are contractually required to verify it against the underlying record and are prohibited from using it as the basis for decisions about people.
6. Google user data and Limited Use
6.1 Where our customer connects Google Workspace — for example to read Gmail threads or Google Meet transcripts — we access that data through Google APIs under the authorisation the customer grants.
Sumgate Signal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6.2 Specifically, in respect of data obtained through Google APIs:
- we use it only to provide and improve the user-facing features that the customer has asked for, and for security and abuse prevention;
- we do not retain or use it to develop, improve or train generalised or non-personalised AI or machine learning models, and we do not permit our sub-processors to do so;
- we do not transfer it to third parties except to the sub-processors listed in section 7 as necessary to provide the feature, to comply with law, or in connection with a merger or acquisition where the acquirer is bound by this policy;
- we do not sell it, and we do not use it for advertising, credit assessment or lending purposes;
- we do not allow humans to read it, except with the customer's affirmative agreement for specific records, where necessary for security purposes, to comply with law, or where the data has been aggregated and de-identified; and
- we do not create permanent copies of it or build a database from it beyond the analyses described in section 5.3.
6.3 A customer may revoke our access at any time through its Google account security settings, or by disconnecting the integration in Signal. Revocation stops future retrieval; it does not automatically delete analyses already produced, which the customer can delete in the Service or ask us to delete.
6.4 Equivalent restrictions imposed by other platform providers, including HubSpot, Zoom and Microsoft, apply to data obtained through their interfaces, and we observe them.
7. Sub-processors and recipients
7.1 We use the following sub-processors. Each is engaged under a written contract imposing data protection obligations no less protective than ours.
| Sub-processor | Role | Data | Location |
|---|---|---|---|
| Railway Corporation | Application hosting and infrastructure | All data processed by the Service | United States |
| Anthropic PBC | Large language model inference | Records submitted for analysis, and the analysis returned | United States |
| OpenAI, L.L.C. / OpenAI Ireland Ltd | Large language model inference | Records submitted for analysis, and the analysis returned | United States; Ireland |
7.2 The current list is maintained in Annex III of the Data Processing Agreement. We give customers at least 30 days' notice before adding or replacing a sub-processor, and customers may object as set out in clause 5 of that agreement.
7.3 We may also disclose personal data to: our professional advisers (legal, accounting, audit) under duties of confidentiality; payment providers, for billing; and a purchaser or successor in connection with a merger, acquisition or reorganisation, subject to equivalent protection.
7.4 We may disclose personal data where required by law, by a court, or by a competent authority. Where we are legally permitted to do so, we will notify the affected customer before disclosing Customer Content, and will challenge requests that appear overbroad or unlawful.
7.5 We do not sell personal data, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months.
8. International transfers
8.1 We are established in the United Arab Emirates, and our sub-processors are located primarily in the United States. Providing the Service therefore involves international transfers of personal data.
8.2 Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland, we rely on:
- for transfers to us from a customer in those territories, the European Commission Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), incorporated into our Data Processing Agreement, together with the UK International Data Transfer Addendum issued under section 119A of the UK Data Protection Act 2018 and, for Switzerland, the amendments recognised by the Swiss Federal Data Protection and Information Commissioner;
- for onward transfers to our sub-processors, the Standard Contractual Clauses, Module Three (processor to processor), or another valid transfer mechanism; and
- supplementary measures including encryption in transit and at rest, minimisation of the data sent for inference, contractual no-training and no-retention commitments, and a commitment to challenge unlawful authority access requests.
8.3 We have carried out a transfer impact assessment and will provide it to customers on request.
8.4 Under UAE Federal Decree-Law No. 45 of 2021, cross-border transfers of personal data are permitted to jurisdictions with an adequate level of protection or, otherwise, on the basis of contractual clauses, binding commitments, express consent, or the other grounds that law provides. We rely on contractual clauses for our transfers.
8.5 A copy of the transfer mechanism relevant to you is available on request from hello@sumgate.io.
9. Retention
| Data | Retention |
|---|---|
| Source records retrieved for an analysis (emails, transcripts, CRM records) | Held only for the duration of the analysis; not retained afterwards as a copy of the customer's systems |
| Analyses, including conclusions and evidencing quotations | For the subscription term, and for 30 days after it ends, after which deleted. Customers may delete individual analyses at any time, and may request earlier deletion of all of them |
| Account, configuration and audit records | For the subscription term and 12 months after, for security and dispute-resolution purposes |
| Server and security logs | Up to 12 months |
| Contact-form submissions and business correspondence | Up to 24 months from the last interaction, unless the enquiry becomes a customer relationship |
| Invoices, payment and tax records | As required by applicable accounting and tax law, and in any event not less than 5 years |
9.1 Backups are retained on a rolling basis and are overwritten in the ordinary course. Deletion from live systems may therefore precede deletion from backups by up to 35 days.
9.2 We may retain data for longer where necessary to comply with a legal obligation, or to establish, exercise or defend legal claims, and only for that purpose.
10. Your rights
10.1 Subject to the conditions and exemptions in the law that applies to you, you may have the right to: be informed about the processing; obtain access to your personal data; have inaccurate data corrected; have data erased; restrict processing; object to processing based on legitimate interests, including for direct marketing; receive your data in a portable form; withdraw consent where consent is the basis; and not be subject to a decision based solely on automated processing that has legal or similarly significant effects.
10.2 Under the UAE Personal Data Protection Law you additionally have the right to request that processing be stopped, and to object to automated processing.
10.3 Under the California Consumer Privacy Act, as amended, and comparable United States state laws, you may have the right to know, delete, correct, and opt out of sale or sharing. As stated in section 7.5, we do not sell or share personal data. We will not discriminate against you for exercising a right.
10.4 To exercise a right in respect of data for which we are the controller, write to hello@sumgate.io. We will respond within one month, and will tell you if we need longer, up to two further months, and why. We may ask for information to verify your identity, and will use it only for that purpose.
10.5 Exercising a right is free. We may charge a reasonable fee, or refuse, where a request is manifestly unfounded or excessive, and will explain why.
11. If you are not our customer
11.1 If you are a salesperson, buyer or other participant whose emails or calls were analysed because one of our customers connected its systems to Signal, then that customer is the controller of your personal data, not us.
11.2 We cannot lawfully grant your access, correction or deletion request in respect of that content on our own initiative, because we do not have the authority to decide what happens to it and cannot reliably verify your relationship to records that belong to someone else's account.
11.3 What we will do, if you write to hello@sumgate.io:
- identify the customer whose account is involved, where you give us enough detail to do so;
- pass your request to that customer without undue delay, and tell you that we have;
- give that customer the assistance it needs to respond, as required by our Data Processing Agreement; and
- act on that customer's instruction to correct, restrict or delete.
11.4 If you tell us that content in a customer's account was obtained unlawfully — for example a call recorded without the consent your jurisdiction requires — we will raise it with that customer, and may suspend processing of the affected content while it is resolved.
12. Security
12.1 We maintain technical and organisational measures appropriate to the risk, including: encryption of data in transit using TLS and encryption at rest; OAuth-based authorisation so that we do not receive or store our customers' passwords for connected systems; least-privilege access scoped to what a feature requires; access control and authentication for our personnel; audit logging; segregation of environments; dependency and vulnerability management; and an incident response process.
12.2 The measures in force are set out in Annex II of the Data Processing Agreement, which is the operative description.
12.3 We do not currently hold an ISO 27001 certification or a completed SOC 2 report. Where we describe such work as in progress, that is a statement of intent and not a representation that it has been completed.
12.4 If a personal data breach affects Customer Content, we will notify the affected customer without undue delay, as required by clause 7 of the Data Processing Agreement. Where we are the controller, we will notify you and the competent authority where the law requires.
12.5 No system is perfectly secure. To report a suspected vulnerability, write to hello@sumgate.io. We will not pursue action against good-faith security research that does not access, modify or exfiltrate other people's data.
13. Cookies and tracking
13.1 This website sets no cookies. We run no analytics, no advertising pixels, no session recording, no fingerprinting and no third-party trackers, and we do not build profiles of visitors. That is why you are not asked to accept cookies.
13.2 Our web server writes standard request logs, described in section 4.
13.3 The website loads the Inter typeface from Google's font service (fonts.googleapis.com and fonts.gstatic.com). That request necessarily discloses your IP address and user agent to Google, acting as an independent controller for that transaction. No cookie is set by that request.
13.4 The Signal application itself uses strictly necessary cookies or equivalent local storage to keep you signed in and to protect against request forgery. These are not used for tracking and do not require consent.
14. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data of anyone under 18. If you believe we have, write to hello@sumgate.io and we will delete it.
15. Automated decision-making
15.1 We do not make decisions about individuals by automated means.
15.2 The Service produces scores, risk indicators and characterisations about deals. Those necessarily describe the conduct of the people involved — for example, that a named person has not replied for 19 days. That is profiling in the sense used by data protection law.
15.3 Our customers are contractually prohibited from using the Service, or its output, as the sole or principal basis for employment decisions, performance evaluation of individuals, or any other decision with legal or similarly significant effects concerning a person. See section 8.5 of the Terms of Service.
15.4 That prohibition binds our customer. If you believe a decision about you was made in breach of it, tell us at hello@sumgate.io; we will raise it with the customer and may suspend the affected processing.
16. Changes to this policy
16.1 We may update this policy. The version and dates are shown at the top. Where a change materially affects how we handle personal data, we will give notice by email to account contacts, or by notice on this page, at least 30 days before it takes effect, except where a shorter period is required by law.
16.2 Previous versions are available on request.
17. Contact and complaints
17.1 For any privacy question, request or complaint: hello@sumgate.io, or write to us at the registered office in section 1.
17.2 We would like the chance to put things right. If you are not satisfied with our response, you may complain to a supervisory authority:
- United Arab Emirates: the UAE Data Office, established under Federal Decree-Law No. 45 of 2021.
- European Economic Area: the data protection authority of your country of residence, place of work, or the place of the alleged infringement.
- United Kingdom: the Information Commissioner's Office.
17.3 Where your personal data reached us through a customer's account, your complaint will normally be against that customer as controller. Section 11 explains how we help.