Back to home
Privacy

Privacy policy

This policy explains two separate things: what we do with the data of people who visit this site or write to us, and what we do with the conversations our customers handle inside the platform. The two cases follow different rules and are best not mixed up.

Data controller

Sumgrey OÜ

Olevi 30-77, Kohtla-Järve, Estonia

privacy@sumgrey.com

Sumgrey OÜ is the controller for data collected through this website and through the commercial relationship. For conversations a customer handles inside the platform, Sumgrey OÜ acts as processor on behalf of that customer, who is the controller.

Data we collect on this website

  • Contact details you give us in the form: first name, last name, work email, company, phone and industry.
  • The content of the message you write to us.
  • Technical browsing data strictly necessary for the site to work, plus whatever you authorise through cookies.

We do not collect special categories of data through this website, and we ask you not to include any in the form's message field.

Purpose and legal basis

  • Responding to your enquiry and continuing the commercial conversation. Legal basis: your consent and pre-contractual measures taken at your request.
  • Providing and invoicing the contracted service. Legal basis: performance of a contract.
  • Meeting legal and accounting obligations. Legal basis: legal obligation.
  • Keeping the platform secure and preventing fraud. Legal basis: legitimate interest.

Conversations inside the platform

When a company uses Sumgrey to serve its customers, that company decides what is processed and why. We process it solely on their documented instructions, under the terms of the data processing agreement we sign with them.

Within that agreement, and depending on what each customer enables, the following may be processed: the content of conversations by phone, WhatsApp Business, email and web chat; call recordings; their transcripts; the summaries and quality scoring generated from them; and the contact details attached to each thread.

If you are a customer of a company that uses Sumgrey and you want to exercise your rights over that data, you should contact that company. We will refer you to them.

Call recording and consent

Call recording is a feature each customer enables and configures, including the announcement played and the legal basis it relies on. The platform stores the consent obtained alongside the recording, so it can be evidenced later.

The customer decides which agents record, how long recordings are kept, and whether they are transcribed or analysed.

Data retention

  • Commercial contact data: for the duration of the relationship and, afterwards, for the applicable statutory limitation periods.
  • Conversations, recordings and transcripts inside the platform: for the retention period each customer configures in their organisation. Once that period is up, deletion runs automatically.
  • Invoicing data: for the periods required by accounting and tax law.

Recipients and processors

We do not sell personal data and we do not share it with third parties for commercial purposes.

To deliver the service we work with infrastructure and ancillary service providers acting as sub-processors, bound by contract and by confidentiality obligations equivalent to our own. An up-to-date list of sub-processors is available to our customers.

When the platform queries a customer's system —their CRM, their helpdesk or their calendar— it does so on demand, with the credentials that customer provides. We keep no copy of their records.

International transfers

Our main infrastructure is located in the European Union. Should a transfer outside the European Economic Area ever be necessary, it would rely on an adequacy decision or on standard contractual clauses, with whatever additional safeguards apply.

Information security

We apply technical and organisational measures proportionate to the risk: isolation of each organisation's data in the database engine, encryption of credentials and secrets, access control by role and scope enforced on the server, a mandatory second factor for platform administration, and an audit log of sensitive actions.

We audit the platform regularly. The report is available to customers under a confidentiality agreement.

Your rights

  • Access your data and obtain a copy.
  • Rectify inaccurate or incomplete data.
  • Request erasure when the data is no longer necessary.
  • Restrict or object to processing in the cases provided for by law.
  • Request portability of the data you have given us.
  • Withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand.

You can exercise these rights by writing to privacy@sumgrey.com. You may also lodge a complaint with the competent supervisory authority.

Changes

We may update this policy when the law or the platform changes. The date of the last revision appears at the foot of this page.

Last updated: September 2026.