Privacy Policy
Gammatica
Privacy Policy
Gammatica AI-Powered Management Platform
What changed in version 2.1
- Section 5.1 now lists the exact Google OAuth scopes we request. We no longer request Google Drive access, and calendar access is limited to reading your events plus creating and deleting the bookings made on your own booking page.
- New Section 5.2 describes the AI Meeting Notetaker: what it records, where the data goes, and how to turn it off.
- New sub-processors added to Sections 3 and 4: Recall.ai, ActiveCampaign (Postmark), Bird (MessageBird) and Zapier.
- Our contact address is now help@gammatica.com throughout.
This document provides information about the processing of personal data related to the Gammatica software (“Gammatica” or “Software”) owned and operated by Gammatica Korlátolt Felelősségű Társaság as the data controller (“Gammatica Kft.” or “Controller”).
The personal data of customers using the Software (“Data Subject” or “User”) is processed by the Controller in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Hungarian data protection legislation (Act CXII of 2011).
The Controller reserves the right to unilaterally amend this document at any time. The amended Privacy Policy shall be effective as of the date of its publication.
1Data Controller
- Company
- Gammatica Kft.
- Registered office
- 1123 Budapest, Nagyenyed utca 5., basement level, Hungary
- Postal address
- 1123 Budapest, Nagyenyed utca 5., basement level, Hungary
- Company reg. no.
- 01-09-434270
- Court of registration
- Budapest-Capital Regional Court
- Tax number
- 32628186-2-43
- EU VAT number
- HU32628186
- Represented by
- Viktor Dániel Várhegyi, Managing Director
- help@gammatica.com updated 2.1
2Data Processing During the Use of the Software
2.1Contact by Email
- Purpose
- To communicate with the User and reply to information sent by email.
- Legal basis
- The User’s prior, informed and voluntary consent (Article 6(1)(a) GDPR).
- Data processed
- Email address, other personal data provided by the User (typically name).
- Retention
- 3 months from the date of the last communication.
- Access
- Employees or agents responsible for contact and enquiries.
2.2Registration and User Account Management
By clicking “Registration”, the User declares that they have read the Terms of Service and this Privacy Policy, understand their contents, and accept the terms of data processing.
- Purpose
- Registration, granting access, and sending reports.
- Legal basis
- Performance of a contract (Article 6(1)(b) GDPR).
- Registration data
- First name, last name, email address.
- Account data
- First name, last name, password, email, language. Optionally: position, profile picture.
- Retention
- 5 years after the termination of the contract.
After registration, Users can log in via email/password or Google Account. Organisation heads can invite team members by email.
Users may upload various content (client data, comments, ratings, calendar links). Gammatica provides the platform and data security but excludes responsibility for user-uploaded content.
2.3Billing
- Purpose
- Billing for services used.
- Legal basis
- Legal obligation (Article 6(1)(c) GDPR; Act C of 2000 on Accounting; Act CL of 2017 on Taxation).
- Data processed
- Name/company name, billing address, tax number, bank account number (if applicable).
- Retention
- 8 years after the relevant financial year.
2.4Artificial Intelligence (AI) Features
Gammatica uses AI features to enhance the user experience:
- AI-powered chatbot (lead qualification, customer support)
- Automated text generation and content suggestions
- AI-assisted CRM features (lead scoring, notifications, workflow automation)
- Summary and report generation
- AI-powered email reply (analysing incoming emails and generating reply suggestions)
- AI Meeting Notetaker — transcription and summary of video meetings, described in detail in Section 5.2 new in 2.1
- Purpose
- Operating AI features to provide intelligent responses, suggestions, and automations based on User-provided data.
- Legal basis
- Performance of a contract (Article 6(1)(b) GDPR) — AI features are integral to the Software; and legitimate interest (Article 6(1)(f) GDPR) for service quality improvement.
- Data processed
- Text data entered into chat, CRM, and other fields; client data (name, email, phone, company); incoming and outgoing email content (when using AI email reply); behavioural data (interactions, clicks); uploaded document content insofar as processed by AI.
- Retention
- OpenRouter is configured with prompt/response logging disabled, so it does not retain prompt or response content, and requests are not routed to providers that use the data to train AI models. AI model providers may process the data only to deliver the requested feature and may retain it transiently under their own terms (for example to prevent abuse), but do not use it to train generalised AI/ML models. AI-generated content stored in the CRM is retained until the User’s account is deleted.
2.5Third-Party Integrations
Gammatica integrates with the following third-party services, activated only with the User’s explicit permission:
| Integration | Purpose | Data processed |
|---|---|---|
| Gmail (Google) | Sending, receiving, and managing emails within Gammatica; AI-powered email reply generation | Email address, subject and body, sender/recipient data, attachment metadata |
| Google Calendar | Reading calendar events to display upcoming meetings, prevent double-booking on the public booking page, and schedule the AI Meeting Notetaker; creating and deleting the events generated by your public booking page. No other events are modified or deleted. updated 2.1 | Event name, date/time, attendee emails, location, description |
| Microsoft Outlook (email & calendar) | Email and calendar synchronisation with Gammatica; AI-powered email reply generation | Email address, subject and body, calendar event data, attendees |
| Make.com (Celonis) | Automation workflows: cross-system data synchronisation, trigger-based actions | All data involved in the workflow (CRM data, email data, calendar data — depending on the scenario configured) |
| Zapier | Automation workflows connecting Gammatica to other applications the User chooses new in 2.1 | All data involved in the Zap (CRM data, contact, deal, task and booking data — depending on the Zap configured) |
- Legal basis
- Performance of a contract (Article 6(1)(b) GDPR). Integrations only operate after the User’s activation and OAuth consent.
- Retention
- Until the integration is deactivated or the User’s account is deleted. Third-party providers’ own retention policies also apply.
2.6Automated Decision-Making and Profiling
In accordance with Article 22 of the GDPR, the Controller informs Users that Gammatica performs the following automated processing activities:
| Feature | Description and impact |
|---|---|
| AI-based lead scoring | The system automatically scores clients based on interactions. Advisory only; the final decision is made by the User. |
| Chatbot-based qualification | The AI chatbot pre-screens enquiries. Serves as a suggestion, not a decision with legal effect. |
| Automatic workflow triggers | CRM events may trigger automatic actions (e.g. email sending, status change), including via Make.com and Zapier. |
| AI email reply suggestion | AI analyses incoming emails and generates reply suggestions. Final sending requires the User’s approval. |
| AI meeting notes new in 2.1 | The notetaker generates a summary, main points and action items from a meeting transcript. Advisory only; the User reviews and edits the result. See Section 5.2. |
Data Subject’s right: The User may at any time request human intervention, express their view, and contest an automated decision by contacting help@gammatica.com. updated 2.1
3Recipients, Data Transfers, Data Processors
Users’ personal data may be transferred or made available to:
| Name | Contact | Purpose / task | Location |
|---|---|---|---|
| VAMOSOFT Kft. | 2310 Szigetszentmiklós, Kert u. 6. · info@vamosoft.hu | Software development, support | Hungary |
| Szigeti-Korán | 1132 Budapest, Visegrádi u. 48. · info@szigeti-koran.hu | Accountant | Hungary |
| DigitalOcean LLC | 101 6th Ave, New York · privacy@digitalocean.com | Hosting service | USA |
| Stripe Payments Europe Ltd. | Grand Canal St Lower, Dublin · privacy@stripe.com | Online payment system | Ireland |
| Billingo Technologies Zrt. | 1133 Budapest, Árbóc u. 6. · hello@billingo.hu | Online billing system | Hungary |
| Smartsupp.com, s.r.o. | Šumavská 31, 602 00 Brno · dpo@smartsupp.com | Online chat, customer support | Czech Republic |
| Make.com (Celonis SE) | Thomas-Dehler-Str. 14, Munich · privacy@celonis.com | Automation workflows | Germany |
| Google LLC (Gmail, Calendar, Workspace) | 1600 Amphitheatre Pkwy, Mountain View · privacy@google.com | Email & calendar integration, OAuth | USA |
| Microsoft Corp. (Outlook) | One Microsoft Way, Redmond · privacy@microsoft.com | Email & calendar integration | USA |
| PostHog Inc. (EU Cloud) | EU hosting: Frankfurt (AWS eu-central-1) · privacy@posthog.com | Product analytics, user behaviour analysis | EU (Germany) |
| Recall.ai, Inc. new in 2.1 | address + privacy contact to be filled in | Meeting-bot infrastructure (recording and transcript) for the AI Meeting Notetaker | EU data region (eu-central-1) |
| ActiveCampaign, LLC (Postmark) new in 2.1 | address + privacy contact to be filled in | Transactional email delivery (welcome messages, notifications) | USA |
| Bird B.V. (MessageBird) new in 2.1 | address + privacy contact to be filled in | SMS and campaign email delivery | Netherlands (EU) |
| Zapier, Inc. new in 2.1 | address + privacy contact to be filled in | Automation platform — only if the User connects it | USA |
3.1AI Service Data Processors
Gammatica’s AI features operate through OpenRouter, Inc., which routes requests to AI model providers.
| Provider | Location | Task | Data retention |
|---|---|---|---|
| OpenRouter, Inc. | USA (New York) | Routing AI requests (proxy) | Prompt/response logging disabled; OpenRouter does not retain prompt or response content. AI-training opt-out enabled, so requests are not routed to providers that train on the data. |
| AI model providers (sub-processors) | USA / EU | Running language models, text generation, email reply generation, meeting summaries | Requests are routed only with the AI-training opt-out applied, so providers do not use prompts or responses to train AI/ML models. Any retention is transient and governed by each provider’s own data-processing terms. |
Sub-processors: Anthropic (Claude), OpenAI, Google (Gemini), Meta (Llama). Current list: openrouter.ai/docs/guides/privacy/logging
4Data Transfers to Third Countries (Outside the EEA)
Personal data may be transferred outside the European Economic Area (EEA) with the following safeguards:
| Provider | Destination | Safeguards applied |
|---|---|---|
| DigitalOcean LLC | USA | EU-U.S. Data Privacy Framework (DPF); Standard Contractual Clauses (SCC) |
| OpenRouter, Inc. | USA | Standard Contractual Clauses (SCC); prompt/response logging disabled and AI-training opt-out enabled |
| AI model providers | USA / varies | OpenRouter’s privacy settings ensure transfers only to providers with adequate safeguards |
| Stripe Payments Europe | Ireland / USA | EU-U.S. Data Privacy Framework; Stripe DPA |
| Google LLC | USA | EU-U.S. Data Privacy Framework; Google DPA; Standard Contractual Clauses |
| Microsoft Corp. | USA | EU-U.S. Data Privacy Framework; Microsoft DPA; Standard Contractual Clauses |
| ActiveCampaign, LLC (Postmark) new in 2.1 | USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses |
| Zapier, Inc. new in 2.1 | USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses |
Data Subject’s right: A copy of the safeguards can be requested at help@gammatica.com. updated 2.1
5Cookies and Web Tracking
The gammatica.com website uses the following cookies and tracking technologies:
| Cookie / tool | Purpose | Legal basis | Lifetime |
|---|---|---|---|
| PostHog (EU Cloud) | Product analytics, session recording, feature usage analysis | Consent (Art. 6(1)(a) GDPR) | 24 months |
| Google Analytics | Website traffic analysis, visitor statistics | Consent (Art. 6(1)(a) GDPR) | 26 months |
| Google Tag Manager | Tag management for tracking codes | Consent (Art. 6(1)(a) GDPR) | Session |
| Meta Pixel | Ad campaign measurement, remarketing | Consent (Art. 6(1)(a) GDPR) | 90 days |
| Meta Conversions API | Server-side conversion tracking | Consent (Art. 6(1)(a) GDPR) | 90 days |
| Smartsupp | Online chat, customer support | Legitimate interest (Art. 6(1)(f)) | Until chat ends |
| Essential cookies | Basic website functionality | Legitimate interest (Art. 6(1)(f)) | Session |
PostHog EU Cloud: Analytics data is stored within the EU in Frankfurt (AWS eu-central-1). IP address capture is disabled by default.
Managing cookies: Users can accept or reject non-essential cookies via the cookie banner on first visit. Settings can be changed at any time.
5.1Google Workspace API rewritten in 2.1
Data obtained through Google Workspace APIs is not used to develop, improve, or train generalized, non-personalized artificial intelligence (AI/ML) models. Google user data is used solely to provide the features you have requested, and is never transferred or sold for advertising purposes.
Google user data we access
Gammatica requests the following Google OAuth scopes, and only these:
- Basic profile (
openid,email): your name and email address, used to identify the connected account inside Gammatica. - Gmail — read (
gmail.readonly): we read messages so that your customer conversations appear on the contact timeline and in the Conversations inbox. We never read mailboxes of anyone other than the connecting user. - Gmail — send (
gmail.send): we send emails on your behalf only when you (or an automation you configured) explicitly initiate sending. - Google Calendar (
calendar.events): we read your calendar events to show your upcoming meetings, to prevent double-booking on your public booking page, and to schedule the AI Notetaker for meetings you asked it to join. We write to your calendar in one specific case: when a guest books a time slot on your public Gammatica booking page, we create the corresponding event in your calendar (with the guest as an attendee and, if requested, a Google Meet link), and we delete that event if the booking is cancelled. We never modify or delete any other events.
We request no other Google scopes (no Google Drive, no Contacts).
Google user data is never sold. Data is only shared with third parties with User consent, for legal compliance, or with service providers bound by confidentiality agreements.
5.1.1Data Protection Mechanisms for Google User Data
Gammatica implements the following technical and organizational measures to protect Google user data accessed through Google Workspace APIs. These measures are in addition to the general data security measures described elsewhere in this Privacy Policy:
Encryption: All data transmitted between Gammatica and Google services is encrypted using TLS 1.2 or higher (HTTPS). Google OAuth tokens and refresh tokens are encrypted at rest using AES-256 encryption and are stored separately from other application data.
Access Control: Access to Google user data within the Gammatica platform is governed by role-based access control (RBAC). Only authenticated and authorized users within a workspace can access data obtained through Google integrations. Internal staff access to production systems containing Google user data is restricted to essential personnel only and is logged.
Token Security: Google OAuth access tokens and refresh tokens are never:
- logged in application logs or error reports;
- displayed in user interfaces;
- transmitted to third parties;
- stored in client-side code or browser storage.
Tokens are stored server-side in encrypted form and are automatically revoked when the user disconnects the Google integration from their Gammatica account.
Data Isolation: Each workspace’s Google integration data is logically isolated. Users in one workspace cannot access Google data belonging to another workspace.
Monitoring and Incident Response: Gammatica maintains system monitoring to detect unauthorized access attempts to Google user data. In the event of a data breach involving Google user data, Gammatica will notify affected users and Google within 72 hours in accordance with GDPR Article 33.
Data Minimization: Gammatica requests only the minimum OAuth scopes necessary for functionality — the four scopes listed in Section 5.1 and no others. Gammatica does not request or store full Gmail mailbox access beyond what is necessary for the features activated by the user. Calendar write access is used solely to create and delete the events generated by your own Gammatica booking page; no other events are modified or deleted. updated 2.1
Data Retention and Deletion: Google OAuth tokens are retained only while the user’s Google integration is active. When a user disconnects their Google account or deletes their Gammatica workspace, all associated Google tokens and cached Google data are permanently and immediately deleted from Gammatica’s systems.
Regular Security Reviews: Gammatica conducts periodic security reviews of its integration with Google APIs to ensure continued compliance with the Google API Services User Data Policy and applicable data protection regulations.
5.1.2Google API Services Limited Use Disclosure
Gammatica’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Gammatica will only use access to Google user data to provide and improve user-facing features that are prominent in the application’s user interface.
- Gammatica will not transfer Google user data to third parties unless necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior user notice.
- Gammatica will not use Google user data for serving advertisements.
- Gammatica will not allow humans to read Google user data unless the user has provided affirmative consent, it is necessary for security purposes, to comply with applicable law, or the data is aggregated and anonymized for internal operations.
5.2AI Meeting Notetaker new in 2.1
If you enable the notetaker, a clearly labelled bot participant (“Gammatica AI-jegyzetelő”) joins the video meetings you selected (auto-join can be turned off per user at any time). The bot records the meeting audio/video and produces a transcript; from the transcript we generate a summary, main points, topics and action items.
- Data processed: meeting audio/video stream, transcript, the meeting title and time, and the attendees’ email addresses (used solely to match the meeting to your existing CRM contacts).
- Where it goes: the finished note is stored in your workspace. If the “note to contact timeline” setting is on (default, can be switched off), the summary and transcript excerpt are also posted as a note on the matched contact’s timeline, and action items become tasks.
- Sub-processor: the meeting bot infrastructure is provided by Recall.ai (data region: EU, eu-central-1). Recall processes the recording on our instruction and does not use it for its own purposes.
- AI processing: transcripts are summarized via OpenRouter, Inc. under the same safeguards as our other AI features (logging disabled, no routing to providers that train on the data).
- Your responsibility: you must inform meeting participants that the meeting is being recorded and obtain any consent required by applicable law before inviting the notetaker. The bot always appears as a visible, named participant.
- Retention & deletion: notes and transcripts remain until you delete them or your account; disconnecting the calendar or turning off auto-join stops any future recording immediately.
6Data Subject’s Rights
6.1Right of Access
Data Subjects may request information on whether their data is processed, what data, on what basis, for what purpose, for how long, and whether automated decision-making applies. The first copy is free.
6.2Right to Rectification
The Data Subject may request rectification of inaccurate data. The Controller shall comply within one month.
6.3Right to Restriction of Processing
The Data Subject may request restriction where: accuracy is contested; processing is unlawful; the Controller no longer needs the data; or the Data Subject has objected.
6.4Right to Object
The Data Subject may object to processing if they consider the Controller is handling data inappropriately.
6.5Right to Erasure (“Right to Be Forgotten”)
The Data Subject may request erasure where: consent is withdrawn; the purpose has ceased; processing is unlawful.
6.6Right to Data Portability
The Data Subject may request their data in a structured, machine-readable format where processing is consent-based and automated.
6.7Right to Legal Remedy
If you believe your rights have been infringed, contact us at help@gammatica.com. updated 2.1
If your complaint cannot be resolved, you may lodge a complaint with:
- Authority
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address
- 1363 Budapest, Pf.: 9.
- Phone
- +36 (1) 391-1400
- ugyfelszolgalat@naih.hu
The Data Subject may also seek judicial remedy before the court of their habitual residence or domicile.