Last revised on
This Privacy Notice (“Notice”) describes how Gorgias Inc. (“Gorgias”, “we” or “us”) handles information we receive or collect about individual representatives of subscribers to our services (collectively, “You” or “Your”) when interacting with us, subscribing to our services, and using our websites and other digital services that link to this Notice (the “Services”).
This Notice only applies to information we receive from the European Economic Area (“EEA”), Switzerland, or the United Kingdom (“U.K.”). If You are from another jurisdiction, please refer to our Privacy Notice for more information on how we handle Your personal information or data. For purposes of this Notice and the processing of Personal Data from these jurisdictions, Gorgias Inc. is the “Controller” (as defined by such jurisdictions’ applicable data protection laws).
This Notice is designed to describe our processing of personal data submitted to or obtained by Gorgias when our clients purchase and utilize the Services. This Notice only applies when Gorgias is the “Controller” of the personal data (such as when we receive contract information from our business clients (“Clients”) that subscribe to our Services and used for billing purposes). Thus, this Notice does not apply to personal data we process as a “data processor” on behalf of our Clients when they or their customers use our Services. If You have questions regarding how our Clients process Your personal data, please contact them directly. We are not responsible for the data protection practices of our Clients. If You are a Client, and have questions regarding how Gorgias processes personal data from You when we act as a data processor please refer to Gorgias Master Subscription Agreement and related data protection terms and policies, and not this Notice.
By subscribing or using our Services, or by otherwise providing us with Your personal data for our business use, You are accepting the practices and policies described in this Notice. If You do not agree with this Notice, do not provide any personal data to us, or register or use the relevant Services where this notice is posted or linked.
As used in this Notice, the terms “personal data” “data subject” and “processing” are as defined in the EU General Data Protection Regulation (GDPR). “You” means the individual who provided personal data to us in connection with a Client’s subscription to our Services or obtained by us in connection with Your use of the Services, and includes personal business contact information of individual Client representatives.
This section describes the categories of personal data we collect and to whom we disclose personal data. It also contains the legal basis we rely on to collect and share this information. Please see Section 4 of this Notice for a more specific description of why we collect Your personal data to support our legal basis.
While You may not be required to provide us with Your personal data to access our general public-facing website Services or review some of our content on the Service, there may be areas on our Service that require us to collect personal data from You, or about You or Your devices used to access the Services. If You do not provide the requested personal data or prevent us from collecting certain information from Your device, we may not be able to provide access or use of our Services, or such Services may not operate as intended.
We collect Your personal data in a variety of ways.
Information Provided Directly from You. This includes instances when You visit our Services, subscribe or interact with our Services and Services by filling out a registration form or contacting us, when You participate in our marketing and outreach activities including surveys, contests, promotions, sweepstakes, conferences, webinars or when You otherwise use our Services.
Information Collected from Third Parties. We receive information about You from other third parties, such as service providers that help us to build and maintain our Services and that integrate their Services with ours, content providers, entities with whom we partner to sell or promote products and services, telephone and fax companies, authentication service providers, data brokers, and social media networks (including widgets related to such networks). Your interactions with third-party integrated or framed third-party services (including social media networks) are governed by the privacy statements of the companies that provide them, not this Notice.
Information Collected Passively. Our Services use tracking technologies to collect information about Your experience when accessing and using our Services. For more information on how we use tracking technologies and the type of information we collect using these technologies, see our Cookies Notice in Section 5. When you access or use our Services, you consent to the use of these tracking technologies and the data they collect as described in Section 5.
Information Collected from Your Employer. We collect and process personal data concerning representatives (e.g., employees or contractors) of our Clients (or their representatives) and business partners (suppliers, investors and other business partners). We may also receive Your name, address, phone number, and company name from a friend as part of our Referral Program.
We collect and use the information we receive or collect from You or about You for the following purposes:
Tracking Technologies We Use: We collect information over time through the Services by using several common types of tracking technologies (including cookies, log files, pixels, tags, web bugs, web beacons, clear GIFs, Local Storage Objects (LSOs) or other similar technologies) to collect information about the ways You interact with and use the Services and our Services, to support and enhance features and functionality, to monitor performance, to personalize content and experiences, for marketing and analytics, and for other lawful purposes. We may also permit third parties that collect information in this way on Our behalf and for their own business purposes. Tracking technologies are small files that download when You access certain Services. For more information visit: http://www.allaboutcookies.org/.
To assist us with analyzing our Services traffic through tracking technologies, we use analytics services such as Google Analytics. For more information on Google Analytics’ processing of Your personal data, please see “How Google uses information from Services or apps that use our services.” You can opt out of Google Analytics by installing Google’s opt-out browser add-on.
We may use cookies that are session-based or persistent. Session cookies expire when You close Your browser or turn off Your device. Persistent cookies remain on Your device after You close Your browser or turn off Your device.
The following chart describes the type of tracking technologies we use:
Your Choices: Most internet browsers accept cookies by default. You can accept, or block cookies by activating the setting on Your browser that allows You to reject all or some cookies, or by changing Your cookie preferences via the Services. The help and support area on Your internet browser should have instructions on how to block or delete cookies. Some web browsers (including some mobile web browsers) provide settings that allow You to control or reject cookies or to alert You to when a cookie is placed on Your computer, tablet or mobile device. On a mobile device, You may also be able to adjust Your settings to permit or limit ad tracking. Although You are not required to accept cookies, if You block or reject them, You may not have access to all of the features available through the Services. To find out more on how to manage and delete cookies, visit aboutcookies.org. For more details on Your choices regarding use of Your web browsing activity for interest-based advertising You may visit the following Services:
If You would like to be removed from our marketing mailing list or database, please contact us at support@gorgias.com or follow the unsubscribe directions located in the footer of our electronic marketing messages.
Our Services are meant for business Clients, and we will not knowingly collect personal data from any data subject under the age of 18. If You are a parent or legal guardian and think Your child has given us information You can email us at support@gorgias.com. You can also write to us at the address listed in Section 14, “Contacting Gorgias”, of this Privacy Notice. Please mark Your inquiries “Children Privacy Inquiry.”
We will use reasonable administrative, technical, and operational measures to protect the security and integrity of Your personal data in accordance with this Notice and applicable law. Unfortunately, the internet is not inherently secure, and we cannot guarantee that any safeguards or security measures will be sufficient to prevent a security issue with information transmitted over the internet. Any transmission is at Your own risk and Your personal data may be disclosed to third parties in unforeseeable situations or situations that are not preventable even when commercially reasonable protections are employed, such as in the case that Gorgias is subject to a hacking or other attack.
You must take reasonable precautions to prevent unauthorized access to Your account and personal data used to access our Services, such as by selecting and protecting passwords and/or other sign-on mechanisms appropriately, limiting access to Your device used to sign-in into Your account or other authenticated pages on our Services, and by turning off or logging-off from Your device if You have auto-login enabled. We also recommend that You take steps to protect against unauthorized access to any devices, networks and applications connected to, or integrated with, the Services.
The time periods for which we retain Your personal data depend on the purposes for which we use it. We will keep Your personal data for as long as You are a registered account holder or user of our Services, or for as long as we have another business purpose to do so (e.g., for business, tax, or legal purposes). We otherwise will not retain Your personal data for longer than is required or permitted by law, or longer than our records retention policy, or longer than reasonably necessary for internal reporting and reconciliation purposes, or to provide You with feedback or information You might request.
Following termination or deactivation of Your user account or contact with Gorgias, we may retain all information posted to public areas of the Service. Following termination or deactivation of Your account or contract, if any, we may retain Your personal data and other data, but will maintain it as confidential according to this Notice, and as required by applicable law or the contract with Gorgias. Except as provided under an agreement between the Client and Us, we have the right to delete all of Your personal data and other data after termination of Your account or agreement with Us without notice.
We may retain information that is de-identified, aggregated, or anonymized for as long as we deem appropriate.
Even if You delete Your account (e.g., Referral Program Portal), the deletion by our service providers may not be immediate and the deleted information may persist in backup copies for a reasonable period of time. When we have no ongoing business need to process Your personal data, we may also anonymize or aggregate it or, if this is not possible (for example, because the information has been stored in backup archives), then we will store the information and isolate it from any further use until deletion is possible.
The Services contain links to other websites or other digital services not owned or controlled by us. We are not responsible for the practices or the content of those third-party websites or other online services. Your use of such third-party Services and digital services is at Your own risk. We encourage You to review such third-party privacy notices and practices before You share Your personal data with such third parties or on a third-party’s website as we are not responsible for how such third parties will handle information You share.
This Notice applies solely to information collected by us or by third parties solely on our behalf.
We may modify or amend this Notice from time to time. If we make any material changes, as determined by Us, we will notify You of these changes by modification of this Notice, which will be available for review by You on the Services. If any of such changes are unacceptable to You, You should cease interacting with us. Your continued use of our Services following the posting of such changes constitutes Your acceptance of those changes.
To facilitate our global operations, We transfer information to other countries. When making any transfers of personal data from the EEA, Switzerland and the U.K. we will comply with applicable legal and regulatory obligations to ensure an adequate level of protection for the personal data. Certain third countries have been officially recognized by the EEA, Swiss, and U.K. authorities as providing an adequate level of protection and no further safeguards are necessary when transferring to these countries. When transferring
Your personal data to countries which do not have the same data protection laws as the EEA, Switzerland and the U.K., we will, where required by applicable law, use specific contracts approved in the U.K., EEA and Switzerland which give personal data the same protection it has in these jurisdictions (e.g., Standard Contractual Clauses (EU) 2021/914 and/or the U.K. Addendum to such clause). This is true whether or not the transfer is within our group, or to a third party. With respect to inter-company transfers between Gorgias’ affiliates in EEA to our affiliates in the United States, Gorgias also relies on standard contractual clauses.
Your rights: You may exercise certain rights regarding Your personal data.
Making a Request: You can exercise Your rights by using the profile editing tools on the Services or by sending an email request to legal@gorgias.com. We will not discriminate against You for exercising these rights. We will respond to any reasonable request by a user to review or amend his or her account information. We reserve the right to verify Your identity in order to process such request as permitted under applicable law.
If You are contacting us to exercise Your rights with respect to Your personal data as detailed in this Notice, we ask You to please adhere to the following guidelines:
We may refuse to act on requests to exercise data protection rights in certain cases (e.g., where providing access infringe on another data subject’s rights, where we need to collect personal data by law or to enter into or carry out a contract with You).
If You have questions or complaints regarding this Notice or our compliance with data protection laws, please email: legal@gorgias.com or write to us at:
Attn: Legal Department
180 Sansome St, Suite 1800,
San Francisco, CA 94014