Gammatica
Gammatica AI-Powered Management Platform
Version 2.4 · Effective 13 September 2026 · Replaces v2.3 of 9 September 2026
What changed in version 2.4
- Section 2.5 gains six rows for services the User can connect: Dropbox, the User's own Stripe account, Számlázz.hu, Billingo, and the Meta Ads and Google Ads ad accounts. Each row states which way the data moves, what we store from it, and what we do not.
- The same section describes how we keep the keys and tokens the User provides, what happens to them on disconnection, and sets out the roles: for data coming from the User's own accounts, the User is the controller and Gammatica is the processor.
- Section 2.3 clarifies what we store from the payment provider (identifiers, card brand and last four digits) and that full card data never reaches us.
- Section 2.6 gains a row on actions the AI performs in connected accounts and the approval rules that apply to them.
- Sections 3 and 4 add rows for Dropbox, Számlázz.hu (KBOSS.hu Kft.) and Meta Platforms; section 3.1 lists the model providers actually reached through OpenRouter.
What changed in version 2.3
- Section 2.5 gains a row for the Meta (Facebook) Lead Ads integration: what data arrives from lead forms on connected Facebook and Instagram Pages, how it arrives, and what we do — and do not do — with it.
- The same section now states the roles explicitly: for leads received through Meta Lead Ads, the customer operating the workspace is the data controller and Gammatica is the data processor. The leads come from the customer’s own advertising, not from Gammatica’s.
- Section 6.5 now describes how to request deletion in practice: where to write, and the deadline we work to.
What changed in version 2.2
- Section 2.6 (Article 22 GDPR) gains a row for Full AI Sales: in that mode the agent can correspond with an enquirer in the User's name without human approval. The previous text promised approval for every AI email, which did not hold in that mode.
- New section 2.7 describes the processing behind portrait avatars, AI advertising images and AI video: what you upload, what happens to it, how long we keep it, and why this is not biometric processing.
- We state that the system does not currently mark generated image, audio and video content, so disclosing its artificial origin on publication is the User’s responsibility (Article 50 of the EU AI Act).
What changed in version 2.1
- Section 5.1 now lists the exact Google OAuth scopes we request. We no longer request Google Drive access, and calendar access is limited to reading your events plus creating and deleting the bookings made on your own booking page.
- New Section 5.2 describes the AI Meeting Notetaker: what it records, where the data goes, and how to turn it off.
- New sub-processors added to Sections 3 and 4: Recall.ai, ActiveCampaign (Postmark), Bird (MessageBird) and Zapier.
- Our contact address is now [email protected] throughout.
This document provides information about the processing of personal data related to the Gammatica software (“Gammatica” or “Software”) owned and operated by Gammatica Korlátolt Felelősségű Társaság as the data controller (“Gammatica Kft.” or “Controller”).
The personal data of customers using the Software (“Data Subject” or “User”) is processed by the Controller in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Hungarian data protection legislation (Act CXII of 2011).
The Controller reserves the right to unilaterally amend this document at any time. The amended Privacy Policy shall be effective as of the date of its publication.
1. Data Controller
| Company | Gammatica Kft. |
|---|---|
| Registered office | 1123 Budapest, Nagyenyed utca 5., basement level, Hungary |
| Postal address | 1123 Budapest, Nagyenyed utca 5., basement level, Hungary |
| Company reg. no. | 01-09-434270 |
| Court of registration | Budapest-Capital Regional Court |
| Tax number | 32628186-2-43 |
| EU VAT number | HU32628186 |
| Represented by | Viktor Dániel Várhegyi, Managing Director |
| [email protected] (updated 2.1) |
2. Data Processing During the Use of the Software
2.1. Contact by Email
| Purpose | To communicate with the User and reply to information sent by email. |
|---|---|
| Legal basis | The User’s prior, informed and voluntary consent (Article 6(1)(a) GDPR). |
| Data processed | Email address, other personal data provided by the User (typically name). |
| Retention | 3 months from the date of the last communication. |
| Access | Employees or agents responsible for contact and enquiries. |
2.2. Registration and User Account Management
By clicking “Registration”, the User declares that they have read the Terms of Service and this Privacy Policy, understand their contents, and accept the terms of data processing.
| Purpose | Registration, granting access, and sending reports. |
|---|---|
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR). |
| Registration data | First name, last name, email address. |
| Account data | First name, last name, password, email, language. Optionally: position, profile picture. |
| Retention | 5 years after the termination of the contract. |
After registration, Users can log in via email/password or Google Account. Organisation heads can invite team members by email.
Users may upload various content (client data, comments, ratings, calendar links). Gammatica provides the platform and data security but excludes responsibility for user-uploaded content.
2.3. Billing
| Purpose | Billing for services used. |
|---|---|
| Legal basis | Legal obligation (Article 6(1)(c) GDPR; Act C of 2000 on Accounting; Act CL of 2017 on Taxation). |
| Data processed | Name/company name, billing address, tax number, bank account number (if applicable). The customer and payment-method identifiers created at the payment provider (Stripe), the card brand and the last four digits of the card number. The full card details are entered by the User directly with Stripe; they never reach us and we do not store them. (updated in 2.4) |
| Retention | 8 years after the relevant financial year. |
2.4. Artificial Intelligence (AI) Features
Gammatica uses AI features to enhance the user experience:
- AI-powered chatbot (lead qualification, customer support)
- Automated text generation and content suggestions
- AI-assisted CRM features (lead scoring, notifications, workflow automation)
- Summary and report generation
- AI-powered email reply (analysing incoming emails and generating reply suggestions)
- AI Meeting Notetaker — transcription and summary of video meetings, described in detail in Section 5.2 (new in 2.1)
| Purpose | Operating AI features to provide intelligent responses, suggestions, and automations based on User-provided data. |
|---|---|
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR) — AI features are integral to the Software; and legitimate interest (Article 6(1)(f) GDPR) for service quality improvement. |
| Data processed | Text data entered into chat, CRM, and other fields; client data (name, email, phone, company); incoming and outgoing email content (when using AI email reply); behavioural data (interactions, clicks); uploaded document content insofar as processed by AI. |
| Retention | OpenRouter is configured with prompt/response logging disabled, so it does not retain prompt or response content, and requests are not routed to providers that use the data to train AI models. AI model providers may process the data only to deliver the requested feature and may retain it transiently under their own terms (for example to prevent abuse), but do not use it to train generalised AI/ML models. AI-generated content stored in the CRM is retained until the User’s account is deleted. |
Important notice: When using AI features, personal data may be transmitted via OpenRouter, Inc. to third-party language model providers (see Sections 3 and 4). When using AI email reply, email content (including sender name, address, and message body) may be transmitted to the AI provider. Please do not enter special categories of personal data (health, racial, political, sexual orientation, etc.) when using AI features.
2.7. Portrait avatars, AI-generated images and video (new in version 2.2)
The Software lets the User upload a photograph and have an AI avatar (a character sheet in several views), an advertising image or a short video generated from it. Content produced this way is synthetic: it was created by artificial intelligence and is not a real recording.
| Purpose of processing | Producing the image, avatar and video content requested by the User. |
|---|---|
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR). Where the uploaded image shows a natural person other than the User, obtaining that person's consent is the User's responsibility (Article 6(1)(a) GDPR). |
| Data processed | The uploaded photograph, the images and videos generated from it, and the text instruction given for the generation. |
| Retention | Uploaded and generated files are kept until deleted by the User, or failing that until the User Account is deleted. |
We do not perform biometric identification. The uploaded portrait is used solely to produce the requested content: we do not derive a biometric template from it, and we do not use it for facial recognition, identification or linking individuals. Processing of the special category of data under Article 9 GDPR therefore does not take place.
Generation follows the route described in section 2.4: the image and the instruction reach the model provider through OpenRouter, Inc.
Transparency (Article 50 of the EU Artificial Intelligence Act). The Service does not currently apply a machine-readable marking or a visible watermark to the image, audio and video content it generates. Where the User publishes such content — in particular where it depicts a real person or event — disclosing its artificial origin is therefore solely the User’s responsibility, and that obligation rests with them. We recommend labelling published content as generated with artificial intelligence.
2.5. Third-Party Integrations
Gammatica integrates with the following third-party services, activated only with the User’s explicit permission:
| Integration | Purpose | Data processed |
|---|---|---|
| Gmail (Google) | Sending, receiving, and managing emails within Gammatica; AI-powered email reply generation | Email address, subject and body, sender/recipient data, attachment metadata |
| Google Calendar | Reading calendar events to display upcoming meetings, prevent double-booking on the public booking page, and schedule the AI Meeting Notetaker; creating and deleting the events generated by your public booking page. No other events are modified or deleted. (updated 2.1) | Event name, date/time, attendee emails, location, description |
| Microsoft Outlook (email & calendar) | Email and calendar synchronisation with Gammatica; AI-powered email reply generation | Email address, subject and body, calendar event data, attendees |
| Make.com (Celonis) | Automation workflows: cross-system data synchronisation, trigger-based actions | All data involved in the workflow (CRM data, email data, calendar data — depending on the scenario configured) |
| Zapier | Automation workflows connecting Gammatica to other applications the User chooses (new in 2.1) | All data involved in the Zap (CRM data, contact, deal, task and booking data — depending on the Zap configured) |
| Meta (Facebook) Lead Ads | Reading lead form submissions from the Facebook and Instagram Pages the User connects. The data is retrieved through the Meta Marketing API using webhooks and written into the User’s workspace as a contact and a pipeline card. We do not use this data for advertising, profiling, or any purpose other than delivering it to the User’s workspace, and we never share it with other customers. (new in 2.3) | The contact details the person entered (name, email address, phone number) and their answers to the lead form questions, together with the form, page and campaign identifiers |
| Dropbox (new in 2.4) | Searching and listing the files stored in the User's Dropbox account and reading the content of smaller text files so that the AI can answer the User's request from them. The connection is read-only: Gammatica does not upload to Dropbox and does not modify, delete or share anything there. We keep no copy of the files on our own storage; the text excerpt read may be passed to the AI provider as part of the given AI request (section 3.1). A separate switch lets the User decide whether the AI may read from the files. | The account's email address; file names, paths, sizes and modification times; a temporary download link valid for a few hours; an excerpt of at most a few thousand characters from the text file read |
| Stripe (the User's own account) (new in 2.4) | Connecting the User's own Stripe account with a restricted API key the User provides: revenue and balance summaries, an overview of open invoices, and the creation of payment links and checkout pages on the User's instruction. This connection is independent of Gammatica billing its own fees through Stripe (section 2.3). We do not store the transaction and customer data retrieved from Stripe: it is processed temporarily to serve the request, and the summary may be passed to the AI provider (section 3.1). We keep only the URLs of the payment links created and the User's settings. | Payment data of the User's customers: amount, currency, status, billing email address, the name and email address entered on the checkout page; the amounts of open invoices; the name and currency of the Stripe account |
| Számlázz.hu (KBOSS.hu Kft.) (new in 2.4) | Issuing invoices and proforma invoices in the User's own Számlázz.hu account with the Számla Agent key the User provides. The invoice is issued in the User's name, in the User's own invoice series and with the User's own tax-authority reporting; Gammatica transmits the invoice data on the User's instruction. An invoice prepared by an automation is issued only after the User's approval. | The buyer's name, address, tax number and email address; line items, quantities, unit prices and VAT rates; the fulfilment date and the payment due date; in return the invoice number and a temporary link to the invoice image, which we store together with the issued invoice's data |
| Billingo (the User's own account) (new in 2.4) | Issuing invoices and proforma invoices in the User's own Billingo account with the API key the User provides, under the same rules as the previous row. The buyer's details are created in Billingo as a partner record; the document's paid status is retrieved afterwards. This connection is independent of Gammatica issuing invoices for its own fees through Billingo (section 3). | The buyer's name, tax number, EU VAT number, email address and address; line items, VAT codes, currency and payment due date; in return the document identifier, its download link and the date of payment |
| Meta Ads (ad account) (new in 2.4) | Connecting the User's Meta ad account through the ads MCP server operated by Meta, with an access token the User provides, for reading only: retrieving campaign performance summaries so that the AI can interpret them at the User's request. Through this connection Gammatica does not create, modify or pause campaigns and does not initiate ad spend. We do not store the retrieved data; the summary may be passed to the AI provider (section 3.1). | Spend, impressions, clicks, results and conversion counts; the identifiers, names and statuses of campaigns, ad sets and ads; links to ad creatives; the identifier and name of the ad account |
| Google Ads (ad account) (new in 2.4) | Connecting the User's Google Ads account through an MCP server, with an access token the User provides, under the same read-only rules as the previous row. | The same performance data and identifiers as in the previous row |
| Legal basis | Performance of a contract (Article 6(1)(b) GDPR). Integrations only operate after the User’s activation and OAuth consent. |
|---|---|
| Retention | Until the integration is deactivated or the User’s account is deleted. Third-party providers’ own retention policies also apply. |
Roles for Meta (Facebook) Lead Ads. For leads received through Meta Lead Ads, the customer operating the workspace is the data controller and Gammatica acts as a data processor on their behalf. The leads arriving through this integration come from the customer’s own advertising and Pages; Gammatica neither collects leads for itself through this integration nor uses them for its own marketing. Lead data is stored in the customer’s workspace until they delete it, and is removed when the workspace is deleted. (new in 2.3)
Keys and tokens provided by the User. Where the connection is made with an API key or access token provided by the User (Stripe, Számlázz.hu, Billingo, Meta Ads, Google Ads) or with an OAuth token (Dropbox, Meta Lead Ads), we store the key or token encrypted, never write it to logs, and use it solely for the requests of the given integration. When the connection is ended we delete the key or token; the User can also revoke the Dropbox-side and Meta-side permission in the provider's own interface. The data of invoices already issued and the contacts, deals and notes that arrived in the User's workspace remain after disconnection until the User deletes them. (new in 2.4)
Roles for the User's own accounts. For personal data coming from, or sent to, the User's own Stripe, Számlázz.hu, Billingo, Dropbox and ad accounts — including the data of the User's customers and buyers — the User is the controller and Gammatica is the processor acting on the User's instructions. The provider concerned processes the data under its own contract with the User and its own privacy policy. Gammatica does not use this data for its own purposes and never shares it with other customers. (new in 2.4)
2.6. Automated Decision-Making and Profiling
In accordance with Article 22 of the GDPR, the Controller informs Users that Gammatica performs the following automated processing activities:
| Feature | Description and impact |
|---|---|
| AI-based lead scoring | The system automatically scores clients based on interactions. Advisory only; the final decision is made by the User. |
| Chatbot-based qualification | The AI chatbot pre-screens enquiries. Serves as a suggestion, not a decision with legal effect. |
| Automatic workflow triggers | CRM events may trigger automatic actions (e.g. email sending, status change), including via Make.com and Zapier. |
| AI email reply suggestion | AI analyses incoming emails and generates reply suggestions. In semi-automatic mode, final sending requires the User’s approval. |
| Automated sales correspondence (Full AI Sales) (new in 2.2) | Where the User selects it, the agent may send email to an enquirer in the User’s name, from their connected mailbox, without human approval, and continue the correspondence. Every such message is logged, and the User can switch back to semi-automatic mode at any time. Any message touching price, discount, contract or a complaint is returned to a human. The mode is switched on inside the User’s workspace and is off by default. |
| AI meeting notes (new in 2.1) | The notetaker generates a summary, main points and action items from a meeting transcript. Advisory only; the User reviews and edits the result. See Section 5.2. |
| AI actions in connected accounts (new in 2.4) | On the User's instruction the AI may perform an action in a service the User has connected, for example create a payment link in the User's Stripe account or retrieve a summary from the ad account. The User sets the AI's autonomy level in the workspace: by default such an action runs only after the User's confirming click; the User may choose to let the AI perform it without confirmation. The system issues invoices only with the User's approval; in ad accounts the AI only reads. These actions are not decisions with legal effect on the natural persons concerned: the User initiates and reviews them. |
Data Subject’s right: The User may at any time request human intervention, express their view, and contest an automated decision by contacting [email protected]. (updated 2.1)
3. Recipients, Data Transfers, Data Processors
Users’ personal data may be transferred or made available to:
| Name | Contact | Purpose / task | Location |
|---|---|---|---|
| VAMOSOFT Kft. | 2310 Szigetszentmiklós, Kert u. 6. · [email protected] | Software development, support | Hungary |
| Szigeti-Korán | 1132 Budapest, Visegrádi u. 48. · [email protected] | Accountant | Hungary |
| DigitalOcean LLC | 101 6th Ave, New York · [email protected] | Hosting service | USA |
| Stripe Payments Europe Ltd. | Grand Canal St Lower, Dublin · [email protected] | Online payment system | Ireland |
| Billingo Technologies Zrt. | 1133 Budapest, Árbóc u. 6. · [email protected] | Online billing system (Gammatica's own invoicing); and the User's own Billingo account, if the User connects it (updated in 2.4) | Hungary |
| Smartsupp.com, s.r.o. | Šumavská 31, 602 00 Brno · [email protected] | Online chat, customer support | Czech Republic |
| Make.com (Celonis SE) | Thomas-Dehler-Str. 14, Munich · [email protected] | Automation workflows | Germany |
| Google LLC (Gmail, Calendar, Workspace) | 1600 Amphitheatre Pkwy, Mountain View · [email protected] | Email & calendar integration, OAuth; reading the Google Ads ad account, if the User connects it (updated in 2.4) | USA |
| Microsoft Corp. (Outlook) | One Microsoft Way, Redmond · [email protected] | Email & calendar integration | USA |
| PostHog Inc. (EU Cloud) | EU hosting: Frankfurt (AWS eu-central-1) · [email protected] | Product analytics, user behaviour analysis | EU (Germany) |
| Hyperdoc Inc. (Recall.ai) (new in 2.1) | 2261 Market Street #4339, San Francisco, CA 94114, USA · [email protected] | Meeting-bot infrastructure (recording and transcript) for the AI Meeting Notetaker | EU data region (eu-central-1) |
| ActiveCampaign, LLC (Postmark) (new in 2.1) | 1 North Dearborn Street, 5th floor, Chicago, IL 60602, USA · [email protected] | Transactional email delivery (welcome messages, notifications) | USA |
| Bird B.V. (MessageBird) (new in 2.1) | Keizersgracht 268, 1016 EV Amsterdam, The Netherlands · [email protected] | SMS and campaign email delivery | Netherlands (EU) |
| Zapier, Inc. (new in 2.1) | 548 Market St. #62411, San Francisco, CA 94104-5401, USA · [email protected] | Automation platform — only if the User connects it | USA |
| Dropbox, Inc. (new in 2.4) | 1800 Owens St, San Francisco, CA 94158, USA · [email protected] | File storage integration — only if the User connects it; read access | USA |
| KBOSS.hu Kft. (Számlázz.hu) (new in 2.4) | 1031 Budapest, Záhony utca 7. · [email protected] | The User's own invoicing account — invoice data transmitted on the User's instruction, only if the User connects it | Hungary |
| Meta Platforms Ireland Ltd. (new in 2.4) | Merrion Road, Dublin 4, D04 X2K5, Ireland · facebook.com/privacy | Lead Ads and ad account integration — only if the User connects it; lead data arrives from Meta, ad data is read | Ireland / USA |
3.1. AI Service Data Processors
Gammatica’s AI features operate through OpenRouter, Inc., which routes requests to AI model providers.
| Provider | Location | Task | Data retention |
|---|---|---|---|
| OpenRouter, Inc. | USA (New York) | Routing AI requests (proxy) | Prompt/response logging disabled; OpenRouter does not retain prompt or response content. AI-training opt-out enabled, so requests are not routed to providers that train on the data. |
| AI model providers (sub-processors) | USA / EU | Running language models, text generation, email reply generation, meeting summaries | Requests are routed only with the AI-training opt-out applied, so providers do not use prompts or responses to train AI/ML models. Any retention is transient and governed by each provider’s own data-processing terms. |
Sub-processors (model providers reached through OpenRouter): Anthropic (Claude — text and agent features), OpenAI (image generation), xAI (speech synthesis), HeyGen (portrait avatars), and the video model provider reached through OpenRouter. Current list: openrouter.ai/docs/guides/privacy/logging (updated in 2.4)
4. Data Transfers to Third Countries (Outside the EEA)
Personal data may be transferred outside the European Economic Area (EEA) with the following safeguards:
| Provider | Destination | Safeguards applied |
|---|---|---|
| DigitalOcean LLC | USA | EU-U.S. Data Privacy Framework (DPF); Standard Contractual Clauses (SCC) |
| OpenRouter, Inc. | USA | Standard Contractual Clauses (SCC); prompt/response logging disabled and AI-training opt-out enabled |
| AI model providers | USA / varies | OpenRouter’s privacy settings ensure transfers only to providers with adequate safeguards |
| Stripe Payments Europe | Ireland / USA | EU-U.S. Data Privacy Framework; Stripe DPA |
| Google LLC | USA | EU-U.S. Data Privacy Framework; Google DPA; Standard Contractual Clauses |
| Microsoft Corp. | USA | EU-U.S. Data Privacy Framework; Microsoft DPA; Standard Contractual Clauses |
| ActiveCampaign, LLC (Postmark) (new in 2.1) | USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses |
| Zapier, Inc. (new in 2.1) | USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses |
| Dropbox, Inc. (new in 2.4) | USA | EU-U.S. Data Privacy Framework; Standard Contractual Clauses |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. (new in 2.4) | Ireland / USA | EU-U.S. Data Privacy Framework; Meta's Standard Contractual Clauses (SCC) |
Make.com (Celonis SE, Germany), PostHog EU Cloud (Frankfurt, Germany), Bird B.V. (Netherlands) and the Recall.ai meeting-bot infrastructure (EU, eu-central-1) store data within the EEA and do not constitute third-country transfers.
Data Subject’s right: A copy of the safeguards can be requested at [email protected]. (updated 2.1)
5. Cookies and Web Tracking
The gammatica.com website uses the following cookies and tracking technologies:
| Cookie / tool | Purpose | Legal basis | Lifetime |
|---|---|---|---|
| PostHog (EU Cloud) | Product analytics, session recording, feature usage analysis | Consent (Art. 6(1)(a) GDPR) | 24 months |
| Google Analytics | Website traffic analysis, visitor statistics | Consent (Art. 6(1)(a) GDPR) | 26 months |
| Google Tag Manager | Tag management for tracking codes | Consent (Art. 6(1)(a) GDPR) | Session |
| Meta Pixel | Ad campaign measurement, remarketing | Consent (Art. 6(1)(a) GDPR) | 90 days |
| Meta Conversions API | Server-side conversion tracking | Consent (Art. 6(1)(a) GDPR) | 90 days |
| Smartsupp | Online chat, customer support | Legitimate interest (Art. 6(1)(f)) | Until chat ends |
| Essential cookies | Basic website functionality | Legitimate interest (Art. 6(1)(f)) | Session |
PostHog EU Cloud: Analytics data is stored within the EU in Frankfurt (AWS eu-central-1). IP address capture is disabled by default.
Managing cookies: Users can accept or reject non-essential cookies via the cookie banner on first visit. Settings can be changed at any time.
5.1. Google Workspace API (rewritten in 2.1)
Data obtained through Google Workspace APIs is not used to develop, improve, or train generalized, non-personalized artificial intelligence (AI/ML) models. Google user data is used solely to provide the features you have requested, and is never transferred or sold for advertising purposes.
Google user data we access
Gammatica requests the following Google OAuth scopes, and only these:
- Basic profile (
openid,email): your name and email address, used to identify the connected account inside Gammatica. - Gmail — read (
gmail.readonly): we read messages so that your customer conversations appear on the contact timeline and in the Conversations inbox. We never read mailboxes of anyone other than the connecting user. - Gmail — send (
gmail.send): we send emails on your behalf only when you (or an automation you configured) explicitly initiate sending. - Google Calendar (
calendar.events): we read your calendar events to show your upcoming meetings, to prevent double-booking on your public booking page, and to schedule the AI Notetaker for meetings you asked it to join. We write to your calendar in one specific case: when a guest books a time slot on your public Gammatica booking page, we create the corresponding event in your calendar (with the guest as an attendee and, if requested, a Google Meet link), and we delete that event if the booking is cancelled. We never modify or delete any other events.
We request no other Google scopes (no Google Drive, no Contacts).
Google user data is never sold. Data is only shared with third parties with User consent, for legal compliance, or with service providers bound by confidentiality agreements.
5.1.1. Data Protection Mechanisms for Google User Data
Gammatica implements the following technical and organizational measures to protect Google user data accessed through Google Workspace APIs. These measures are in addition to the general data security measures described elsewhere in this Privacy Policy:
Encryption: All data transmitted between Gammatica and Google services is encrypted using TLS 1.2 or higher (HTTPS). Google OAuth tokens and refresh tokens are encrypted at rest using AES-256 encryption and are stored separately from other application data.
Access Control: Access to Google user data within the Gammatica platform is governed by role-based access control (RBAC). Only authenticated and authorized users within a workspace can access data obtained through Google integrations. Internal staff access to production systems containing Google user data is restricted to essential personnel only and is logged.
Token Security: Google OAuth access tokens and refresh tokens are never:
- logged in application logs or error reports;
- displayed in user interfaces;
- transmitted to third parties;
- stored in client-side code or browser storage.
Tokens are stored server-side in encrypted form and are automatically revoked when the user disconnects the Google integration from their Gammatica account.
Data Isolation: Each workspace’s Google integration data is logically isolated. Users in one workspace cannot access Google data belonging to another workspace.
Monitoring and Incident Response: Gammatica maintains system monitoring to detect unauthorized access attempts to Google user data. In the event of a data breach involving Google user data, Gammatica will notify affected users and Google within 72 hours in accordance with GDPR Article 33.
Data Minimization: Gammatica requests only the minimum OAuth scopes necessary for functionality — the four scopes listed in Section 5.1 and no others. Gammatica does not request or store full Gmail mailbox access beyond what is necessary for the features activated by the user. Calendar write access is used solely to create and delete the events generated by your own Gammatica booking page; no other events are modified or deleted. (updated 2.1)
Data Retention and Deletion: Google OAuth tokens are retained only while the user’s Google integration is active. When a user disconnects their Google account or deletes their Gammatica workspace, all associated Google tokens and cached Google data are permanently and immediately deleted from Gammatica’s systems.
Regular Security Reviews: Gammatica conducts periodic security reviews of its integration with Google APIs to ensure continued compliance with the Google API Services User Data Policy and applicable data protection regulations.
5.1.2. Google API Services Limited Use Disclosure
Gammatica’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Gammatica will only use access to Google user data to provide and improve user-facing features that are prominent in the application’s user interface.
- Gammatica will not transfer Google user data to third parties unless necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior user notice.
- Gammatica will not use Google user data for serving advertisements.
- Gammatica will not allow humans to read Google user data unless the user has provided affirmative consent, it is necessary for security purposes, to comply with applicable law, or the data is aggregated and anonymized for internal operations.
5.2. AI Meeting Notetaker (new in 2.1)
If you enable the notetaker, a clearly labelled bot participant (“Gammatica AI-jegyzetelő”) joins the video meetings you selected (auto-join can be turned off per user at any time). The bot records the meeting audio/video and produces a transcript; from the transcript we generate a summary, main points, topics and action items.
- Data processed: meeting audio/video stream, transcript, the meeting title and time, and the attendees’ email addresses (used solely to match the meeting to your existing CRM contacts).
- Where it goes: the finished note is stored in your workspace. If the “note to contact timeline” setting is on (default, can be switched off), the summary and transcript excerpt are also posted as a note on the matched contact’s timeline, and action items become tasks.
- Sub-processor: the meeting bot infrastructure is provided by Recall.ai (data region: EU, eu-central-1). Recall processes the recording on our instruction and does not use it for its own purposes.
- AI processing: transcripts are summarized via OpenRouter, Inc. under the same safeguards as our other AI features (logging disabled, no routing to providers that train on the data).
- Your responsibility: you must inform meeting participants that the meeting is being recorded and obtain any consent required by applicable law before inviting the notetaker. The bot always appears as a visible, named participant.
- Retention & deletion: notes and transcripts remain until you delete them or your account; disconnecting the calendar or turning off auto-join stops any future recording immediately.
6. Data Subject’s Rights
6.1. Right of Access
Data Subjects may request information on whether their data is processed, what data, on what basis, for what purpose, for how long, and whether automated decision-making applies. The first copy is free.
6.2. Right to Rectification
The Data Subject may request rectification of inaccurate data. The Controller shall comply within one month.
6.3. Right to Restriction of Processing
The Data Subject may request restriction where: accuracy is contested; processing is unlawful; the Controller no longer needs the data; or the Data Subject has objected.
6.4. Right to Object
The Data Subject may object to processing if they consider the Controller is handling data inappropriately.
6.5. Right to Erasure (“Right to Be Forgotten”)
The Data Subject may request erasure where: consent is withdrawn; the purpose has ceased; processing is unlawful.
How to request deletion. Write to [email protected] from the email address the data concerns, stating what should be deleted. We acknowledge the request and complete the deletion within one month. Data that reached Gammatica through an integration — including leads from Meta (Facebook) Lead Ads — sits in the workspace of the customer who is its data controller: we forward the request to them without delay and carry out the deletion in the workspace within one month of receiving the request; in every case the data is removed when the workspace itself is deleted. (new in 2.3)
6.6. Right to Data Portability
The Data Subject may request their data in a structured, machine-readable format where processing is consent-based and automated.
6.7. Right to Legal Remedy
If you believe your rights have been infringed, contact us at [email protected]. (updated 2.1)
If your complaint cannot be resolved, you may lodge a complaint with:
| Authority | Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
|---|---|
| Address | 1055 Budapest, Falk Miksa utca 9–11, Hungary |
| Postal address | 1363 Budapest, Pf.: 9. |
| Phone | +36 (1) 391-1400 |
| [email protected] |
The Data Subject may also seek judicial remedy before the court of their habitual residence or domicile.
Budapest, 9 September 2026
Gammatica Kft.
Viktor Dániel Várhegyi, Managing Director