Privacy Policy

gammaNext Privacy Policy

Effective Date: (To be determined)

gammaNext (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information in connection with the gammaNext website (the “Site”) and our GammaAgent product (together with the Site, the “Services”). It also explains how GammaAgent operates securely within your Salesforce and Microsoft Azure environments. This policy is intended for enterprise customers and complies with applicable privacy laws such as the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). By using our Site or Services, you agree to the practices described in this Privacy Policy.

Information We Collect
We collect various types of information to provide and improve our Services. The categories of information we collect include:

  • Personal Information You Provide: When you contact us, sign up for a demo or free trial, register for an account, or otherwise communicate with us, you may provide personal information. This includes identifiers and contact details such as your name, business email address, phone number, job title, company/organization name, postal address, or any other information you choose to give us. We use this information to respond to inquiries, set up your account or trial, provide support, and communicate about our Services.
  • Usage Data and Device Information: When you visit our Site, we automatically collect certain information about your device and how you interact with our Site. This may include your IP address, browser type, device identifiers, pages visited, date/time of visits, and referring website. We collect this usage data to understand how our Site is used, to diagnose technical issues, ensure security, and to improve the user experience. We may also infer general location (e.g., city or country) from your IP address.
  • Cookies and Tracking Technologies: We use cookies, web beacons, and similar tracking technologies on our Site to collect information automatically. For details, see “Use of Cookies and Tracking Technologies” below. These technologies help us recognize you, customize your experience, and analyze web traffic.
  • GammaAgent Product Data: Importantly, gammaNext does not collect or access the content that you or your users process through the GammaAgent product. GammaAgent is designed to run entirely within your Salesforce organization and your Microsoft Azure cloud infrastructure[1]. This means that any data GammaAgent uses – such as Salesforce records, files stored in your Azure Blob Storage, knowledge base articles, user prompts, and AI-generated responses – remains in your controlled environment. The GammaAgent managed package communicates directly between Salesforce and your Azure services (e.g. Azure OpenAI, Azure Cognitive Search) using secure connections and does not transmit your business data back to gammaNext or to any other external servers[2]. We do not have access to your Salesforce CRM data or any sensitive information processed by GammaAgent during its operations. The only information related to GammaAgent that we may collect is limited metadata necessary for licensing and support, such as your Salesforce organization ID, license key activation status, and diagnostic logs or configuration details that you choose to share with us for troubleshooting purposes. We use such information solely to activate your GammaAgent license and assist you in resolving issues, not to monitor your content.
  • Information from Third Parties: We may receive your information from third-party sources in certain situations. For example, if your company purchases GammaAgent through a Salesforce AppExchange listing or a channel partner, we might receive contact information and organizational details from that third party. We treat such information in accordance with this Privacy Policy and any additional obligations imposed by the source.
  • We do not knowingly collect sensitive personal information (such as government ID numbers, financial account details, or health information) through our Site. We ask that you avoid submitting sensitive data to us via the Site. (If your use of GammaAgent involves processing sensitive data within Salesforce/Azure, that data remains under your control as described above.)

How We Use Your Information
We use the collected information for the following purposes, in accordance with applicable legal bases:

  • Providing and Improving the Services: We use personal information to deliver our Services and ensure their proper functioning. For example, we use your information to set up and administer your GammaAgent account or trial, to integrate GammaAgent with your systems, and to enable the AI features within your Salesforce environment. We also use data (excluding any customer content from GammaAgent) to maintain and improve our Site and products – for instance, analyzing Site usage patterns to enhance navigation or fixing bugs in GammaAgent.
  • Communication and Support: We use contact information (such as email and phone number) to communicate with you about your use of the Services. This includes sending you service-related announcements, responding to your inquiries or support requests, and providing customer support. If you reach out for technical assistance, we may request diagnostic or log information from GammaAgent; any such information will be used strictly to help resolve your issue and will remain confidential.
  • Analytics and Product Development: We may use usage data and aggregated information to understand how our Services are used and to develop new features or improvements. For example, we might analyze website traffic trends or error logs to improve performance and usability. Any analytics concerning GammaAgent usage would be done on de-identified data or high-level usage metrics (e.g., number of agents deployed, frequency of interactions) and not on any personal or record-specific content. This helps us enhance features while respecting the privacy of your business data.
  • Marketing and Updates: With your consent or as otherwise permitted by law, we may use your contact information to send you newsletters, product updates, marketing communications, or event invitations that may be of interest. For instance, if you sign up for our mailing list or if you are an existing customer, we might send emails about new GammaAgent features, industry insights, or gammaNext services. You can opt out of marketing communications at any time (see “Your Rights and Choices” below). We do not use sensitive GammaAgent data for marketing purposes.
  • Security and Compliance: We use information to protect the security of our Services, our company, and other users. This includes using data to detect, prevent, and respond to potential fraud, intellectual property infringement, or other misuse of our Site or product. We may use personal information as necessary to comply with applicable legal obligations, such as verifying user identity for data requests or complying with government requests and regulatory requirements. We also use and retain personal data as needed to enforce our agreements (e.g., license terms, Terms of Use) and to resolve disputes.

We always ensure that we have a lawful basis for processing personal information. For individuals in the European Economic Area (EEA) or United Kingdom, our legal bases include: contract performance (providing you with Services or support you requested), legitimate interests (such as improving our Services, securing our systems, or communicating with business contacts, balanced against your privacy rights), and consent (for optional uses like marketing cookies or newsletters, where consent is required). We will seek your consent where required by law, and you have the right to withdraw consent at any time.

Use of Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our Site to collect information automatically. Cookies are small text files placed on your device that enable core site functionality and help us analyze usage. For example, we use necessary cookies to enable login sessions or remember your preferences. We may also use analytics cookies (such as those provided by Google Analytics or similar services) to collect information about how visitors use our Site – for instance, which pages are visited and in what order – so we can improve performance and content. These analytics cookies may collect your IP address and generate statistical usage reports for us. We do not use cookies for advertising purposes, and we do not share cookie data with third-party advertisers.

Managing Cookies: When you first visit our Site, you may be presented with a cookie notice or preferences tool (where required by law). You can choose to accept or reject non-essential cookies. Additionally, most web browsers allow you to control and delete cookies through their settings. You can set your browser to refuse cookies or to alert you when cookies are being sent. However, please note that if you disable certain cookies, some features of our Site may not function properly (for example, session login or interface preferences might not be saved).

For more information on how to adjust your browser settings or opt out of Google Analytics, you can visit resources provided by your browser or Google’s opt-out page. By using our Site without disabling cookies, you consent to our use of cookies as described in this policy.

Information Sharing with Third Parties

We do not sell your personal information to third parties. We only share your information in the following circumstances and with appropriate safeguards:

  • Service Providers and Partners: We share information with trusted third-party service providers who perform services on our behalf to operate and support our business. These include:
  • Hosting and Infrastructure: We host our website and related data on cloud platforms such as Microsoft Azure. Personal data (like contact form submissions or account information) may be stored on Azure cloud servers or databases. Microsoft Azure is a secure, enterprise-grade cloud provider that maintains high standards of data protection and security.
  • Customer Relationship Management (CRM): We may use Salesforce or similar CRM platforms to manage customer relationships, sales pipelines, and support tickets. This means that if you provide us your contact and account details, they may be stored in our Salesforce CRM system. Salesforce acts as a processor of this data on our behalf, and we have agreements in place to protect your information.
  • Analytics Providers: As mentioned, we may use third-party analytics tools (e.g., Google Analytics or Azure Application Insights) to collect site usage data. These providers may receive your truncated IP address or cookie identifiers to provide analytic services to us. They are prohibited from using personal data for any purpose other than providing us insights and are bound by privacy obligations.
  • Communication and Support Tools: We might use third-party platforms for sending emails (e.g., an email service provider), scheduling demos, or providing customer support (e.g., a ticketing system or live chat service). If so, your contact information and any message content will be processed through those tools solely for the purpose of facilitating our communications.
    We ensure that our service providers are bound by contracts requiring them to protect your information and use it only for the purposes we specify. They are not permitted to use your data for their own unrelated purposes.
  • Within Your Salesforce/Azure Environment: As described, the GammaAgent product operates using integrations within your own infrastructure. When GammaAgent connects Salesforce to Azure services via secure Named Credentials, data is exchanged between those systems under your control[3][4]. For example, if GammaAgent calls Azure OpenAI to process a query, the query and relevant data are sent to Microsoft Azure (within your subscription) and the response is returned to Salesforce – all over encrypted channels. This sharing of data happens between Salesforce and Azure as part of the service you configure, and does not involve any third-party beyond your chosen enterprise platforms. gammaNext itself does not receive these data transmissions. The only exception would be if you explicitly share certain results or logs with us for troubleshooting or improvements, in which case we handle that data confidentially as a service provider to you.
  • Corporate Transactions: If gammaNext is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be disclosed or transferred as part of that transaction. We would ensure the new owner or successor honors the commitments we have made in this Privacy Policy with respect to your personal information.
  • Legal Compliance and Protection: We may disclose information to third parties (such as courts, law enforcement agencies, regulators, or attorneys) if required to do so by law or legal process or if we have a good-faith belief that such disclosure is necessary to (i) comply with a legal obligation, subpoena, or request from governmental authorities, (ii) enforce our Terms of Use, license agreements, or other contracts, (iii) prevent or investigate suspected wrongdoing in connection with the Services, (iv) protect the rights, property, or safety of gammaNext, our customers, or the public, or (v) defend against legal claims or allegations. In all such cases, we will only disclose the minimum information necessary and will do so in accordance with applicable laws.
  • With Your Consent: We will share your personal information with other third parties for purposes outside of those described in this policy only if you direct us to or explicitly consent to such sharing. For example, if you request that we integrate a gammaNext service with a third-party application or if you opt-in to an offering in collaboration with a partner, we will share data as needed with your consent. You may also authorize us to share a testimonial or case study that includes your personal information on our Site; in such cases, we will seek your approval before publishing.

We want to reiterate that your enterprise data processed by GammaAgent is not sent to gammaNext or any external party during normal operations[1]. All AI processing occurs within your Salesforce and Azure environment, which is a key privacy and security feature of our product. gammaNext’s role as a service provider primarily involves supporting you and ensuring the software license is valid – not handling your internal data. This helps achieve “100% data residency compliance”[2] for GammaAgent usage, meaning your data stays within the geographic and virtual boundaries you set for Salesforce and Azure.

Data Storage and Security
We understand the importance of securely storing and processing your information. gammaNext implements a variety of technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure, or destruction:

  • Secure Infrastructure: We use reputable cloud infrastructure (such as Microsoft Azure and Salesforce’s platform) to host our applications and store data. These providers maintain robust physical and network security and hold certifications for compliance with industry standards. All data we hold in our databases or file storage is protected by access controls, and we limit access to employees or contractors who have a business need to handle that information.
  • Encryption: We protect data in transit between your browser and our Site using encryption protocols like HTTPS/TLS. Similarly, GammaAgent’s communications between Salesforce and Azure services occur over encrypted channels (HTTPS API calls), ensuring that data is not exposed in transit[5]. Our databases and storage utilize encryption at rest as provided by our cloud providers. This means that your personal information is encrypted when stored on disk and when transmitted over networks, adding layers of security against interception.
  • Access Controls and Policies: gammaNext restricts internal access to personal data on a need-to-know basis. Employees are trained on data privacy and security practices, and we have in place authentication controls and monitoring to prevent unauthorized access. Admin access to production systems is limited and logged. We also maintain policies and incident response plans to handle any security breaches responsibly.
  • GammaAgent Data Stays in Your Environment: A core security aspect of GammaAgent is that it operates within your own Azure and Salesforce environment. There is no replication or extraction of your Salesforce records or Azure data to external systems[3]. By using Named Credentials and direct integration, GammaAgent avoids data duplication and minimizes exposure surface. In practical terms, this means the data used by GammaAgent (your CRM data, documents, chats, etc.) remains stored in Salesforce and Azure as per your configurations, inheriting those platforms’ security controls. gammaNext does not store this data on our systems, which drastically reduces the risk of unauthorized access on our side – we simply never take possession of your sensitive content.
  • Data Retention: We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and contractual obligations. For example, if you are a customer, we will keep your account information for the duration of the business relationship and for a reasonable period thereafter (to manage renewals, provide support, or maintain records of the contract). If you contact us with a question, we may retain the correspondence to follow up or improve our services. We periodically review the data we hold and erase or anonymize personal information that is no longer needed. In cases where we process data on your behalf (e.g., if you provide us log files for support), we will retain that data only for as long as needed to resolve the issue or as instructed by you, and then securely delete it.
  • International Storage: The personal information we collect may be stored and processed on servers in the United States or other countries. We recognize that different jurisdictions have different data protection laws, so we take steps to ensure that your data is protected according to the standards of your home country’s law (see “International Data Transfers & Compliance” below for more details on cross-border data protections).

Despite our efforts, no security measure or method of data transmission over the Internet can be guaranteed 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot warrant absolute security. In the unlikely event of a data breach that affects your personal information, we will notify you and the appropriate authorities as required by law.

Your Rights and Choices
You have certain rights and choices regarding your personal information. gammaNext is committed to honoring your rights under applicable data protection laws, which include:

    • Access and Correction: You have the right to request access to the personal information we hold about you and to receive information about how it is used and shared. You may also request that we correct or update any inaccurate or incomplete personal information. For example, if you are a contact person for your company’s account and your email address changes, you can ask us to update our records.
    • Deletion (Right to Erasure): You have the right to request that we delete your personal information. Upon verified request, we will delete or anonymize personal data we have about you, except to the extent we are permitted or required to retain the data (for example, to complete transactions, comply with legal obligations, or exercise our rights). If you are an end user of GammaAgent through one of our customers (e.g., an employee using GammaAgent at your company), you should direct any deletion request to your company as they control the data within Salesforce/Azure; however, if any of your personal data is held by gammaNext (such as your email in a support ticket), we will process a deletion request for that information.
    • Objection and Restriction: You have the right to object to or request restriction of processing of your personal information in certain circumstances. For instance, if we process your information based on our legitimate interests, you can object to that processing if you feel it impacts your fundamental rights and freedoms. You can also ask us to restrict processing while a dispute is being resolved (such as verifying the accuracy of your data or our grounds for processing it). We will honor valid objections unless we have compelling legitimate grounds or legal reasons to continue processing.
    • Data Portability: Where applicable (e.g., under GDPR), you have the right to receive a copy of certain personal information in a structured, commonly used, machine-readable format, and to request that we transfer that information to another controller, when technically feasible. This typically applies to information you provided directly and that we process by automated means based on your consent or a contract with you.
    • Opt-Out of Marketing: If you have subscribed to our marketing communications, you have the right to opt out at any time. You can do so by clicking the “unsubscribe” link in any promotional emails, or by contacting us as described in the Contact section below. Once you opt out, we will stop sending you non-essential communications. Please note that even if you opt out of marketing messages, we may still send you transactional or service-related communications (such as account notices or responses to your inquiries) as these are not promotional.
    • California Privacy Rights: If you are a California resident, you have specific rights under the CCPA/CPRA, including the right to know what personal information we collect, use, disclose, and not sell. You also have the right to request correction or deletion of your personal information, and the right to opt out of the “sale” or “sharing” of your personal information. As of the effective date of this Policy, gammaNext does not sell personal information as “sell” is defined under CCPA. If that changes in the future, we will update this policy and provide a means for you to opt out. California residents may exercise their rights by contacting us with your request (see Contact Information below). We may need to verify your identity before fulfilling certain requests, as required by law. If you exercise any of these rights, we will not discriminate against you for doing so (e.g., we will not deny services or provide a different level of service just because you exercised your privacy rights).
    • Other State Privacy Rights: Residents of certain other states (such as Virginia, Colorado, Connecticut, Utah, etc. under their respective privacy laws) may also have similar rights to access, correct, delete personal data, and opt out of certain data processing. gammaNext will honor those rights in accordance with applicable state laws. You may contact us to exercise those rights, and we will respond as required by law.
    • EEA/UK Privacy Rights: If you are in the European Economic Area or United Kingdom, in addition to the rights above, you have the right not to be subject to a decision based solely on automated processing (in our case, we do not make legally significant decisions purely by algorithms without human involvement). You also have the right to lodge a complaint with a supervisory authority (such as the Data Protection Authority in your country or the UK Information Commissioner’s Office) if you believe our processing of your personal data violates the law. We encourage you to contact us first so we can address your concerns directly.

To exercise your rights or make any requests regarding your personal information, please contact us using the information in the Contact Information section. We will respond to your request within the timeframe required by law (for example, within 30 days for GDPR requests, and 45 days for CCPA requests, with the possibility of a reasonable extension). Please note that for certain requests, we will need to verify your identity to ensure we are providing access or making changes to the correct individual’s data. Verification may involve confirming information we already have on file or asking for additional information as necessary.

International Data Transfers & Compliance

gammaNext is headquartered in [the United States]* and operates internationally. Whenever we transfer personal information across national borders, we take steps to ensure that appropriate safeguards are in place to protect your data, as required by applicable data protection laws.

  • Data Transfers from the EEA/UK: If you are located in the European Economic Area or the United Kingdom, your personal information may be accessed or processed in a country outside of the EEA/UK (for example, on servers in the United States or by our personnel in India or other locations). Such countries may have data protection laws that are different from (and potentially less protective than) the laws of your jurisdiction. In these cases, we will ensure that an appropriate transfer mechanism is in place. This may include relying on the European Commission’s Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement/Addendum, which are contracts approved by regulators to safeguard personal data transferred internationally. We may also rely on an adequacy decision from the European Commission (if applicable) or other legal bases for transfer. Our goal is to ensure that your personal information enjoys a high level of protection wherever it is processed.
  • Azure and Salesforce Regional Controls: For GammaAgent customers concerned about data residency, note that you can choose regional Azure resources and configure data storage locations within Salesforce to meet local compliance needs. All GammaAgent-related processing will occur in the regions and accounts that you control. All AI activity stays within the customer’s Azure and Salesforce environments – with zero external data movement[2], which helps address international data transfer concerns by keeping data local to the region you select. Microsoft Azure and Salesforce each publish commitments to GDPR and international data protection which apply when you use their platforms to host data. We encourage customers to review those commitments for details on how those providers handle cross-border data flows.
  • Compliance with GDPR/CCPA and other Laws: We adhere to applicable privacy laws in the jurisdictions where we operate or where we offer Services. This includes the GDPR for individuals in the EU, the UK GDPR for the United Kingdom, the CCPA (as amended by CPRA) for California residents, and similar laws. gammaNext has implemented measures such as data protection impact assessments, contractual data protection agreements, and processes to respond to data subject rights to maintain compliance. We also design our products with privacy in mind – as noted, GammaAgent’s architecture supports compliance by keeping personal data under the customer’s control and providing features like audit logs and role-based access controls to facilitate our customers’ regulatory compliance needs[6].
  • Privacy Shield or Successor Frameworks: (If applicable) gammaNext complies with the EU-U.S. Data Privacy Framework and Swiss-U.S. Data Privacy Framework (or any successor mechanism) for the transfer of personal data from the EEA, UK, and Switzerland to the United States. We commit to subject such personal information to the Frameworks’ principles. If there is any conflict between those principles and this Privacy Policy, the Framework principles will govern. (Note: gammaNext will update this section as global data transfer mechanisms evolve, and will enter into any required agreements with customers upon request to facilitate compliant data transfers.)

If you have questions about our international data handling or need more information about the safeguards in place, please contact us. We are happy to provide additional details relevant to your jurisdiction upon request.

Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or how your information is handled, please contact us. We take privacy inquiries seriously and will respond promptly.

  • Email: You can reach our privacy team at privacy@gammaNext.com (or support@gammaNext.com for general support queries). Please include “Privacy Inquiry” in the subject line and detail your request or concern in the email.
  • Contact Form: You may also contact us through the form on our Contact Us page on our website. Provide your name, contact information, and a description of your inquiry, and we will get back to you.
  • Postal Mail: [gammaNext, Attn: Privacy Officer, 66 Brooklyn Street, New York, NY 10001, USA]*. (Please note this mailing address is provided for written correspondence; for the fastest response we recommend email.)

The above contact information is subject to updates. Refer to our Site for the latest contact details.

If you contact us to exercise your privacy rights, we may need to request additional information to verify your identity for security purposes, as mentioned in “Your Rights and Choices.” We will use the information you provide in a request solely to process and document the request.

Changes to This Privacy Policy
We may update or revise this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make changes, we will update the “Effective Date” at the top of this Policy. If changes are significant, we may also notify you by additional means, such as by prominently posting a notice on our website or by sending an email notification to account owners.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our Site or Services after any update to this Policy will constitute your acknowledgment of the changes and agreement to be bound by the updated Policy.

Thank you for trusting gammaNext. We are dedicated to safeguarding your data and enabling secure, AI-powered innovation within your enterprise. If you have any questions about this Privacy Policy or our data handling practices, please do not hesitate to contact us.

Address:
101 Morgan Ln, Suite 356
Plainsboro, NJ 08536

Website:
www.gammaNext.com

Scroll to Top