Skip to main content

    Privacy Policy

    Last Updated: July 2026

    Version: 1.2

    Important – Disclaimer

    This document is an operational and general information agreement. It does not constitute legal advice and does not replace consultation with a qualified attorney specializing in technology law, data protection, XR, and international regulations. Gossip Analytics recommends independent legal review before relying on this document for operations in multiple jurisdictions.

    1. Introduction

    Gossip Analytics ("Gossip Analytics", "we", "our", or "us") respects your privacy and is committed to protecting personal data in accordance with applicable data protection and privacy principles.

    This Privacy Policy explains how we collect, use, process, store, and protect personal data when providing our B2B analytics platform for immersive, spatial, and interactive environments.

    This policy applies to:

    • Business customers and their authorized users
    • Visitors to our website
    • Individuals whose data is processed through customer integrations

    Gossip Analytics operates as a business-to-business (B2B) service provider and does not offer consumer-facing services.

    2. Company Information

    Legal name: Gossip Analytics

    Legal entity status: Entity formation in progress

    Country of operation: Mexico

    Privacy contact: privacy@gossipanalytics.com

    Legal contact: legal@gossipanalytics.com

    3. Scope of Services

    Gossip Analytics provides analytics software for XR, VR, AR, MR, and 2D/3D interactive environments. The platform generates insights related to user interaction patterns, system performance, and spatial behavior.

    Gossip Analytics acts primarily as a Data Processor, while its customers act as Data Controllers with respect to end-user data processed through the platform.

    4. Personal Data We Collect

    Depending on usage and integration, we may process the following categories of data:

    4.1 Account and Contact Information

    • Name
    • Email address
    • Company name
    • Role or job title

    4.2 Technical and Device Data

    • IP address
    • Device type
    • Operating system
    • Browser type
    • Session identifiers
    • Log and diagnostic data

    4.3 Usage and Telemetry Data

    • Feature usage
    • Interaction events
    • Performance metrics
    • Error and crash reports

    4.4 XR and Spatial Analytics Data

    • Session-level XR data
    • Aggregated movement paths
    • Interaction heatmaps
    • Spatial behavior metrics

    4.5 Eye Tracking Data

    • Real eye tracking data, when supported and enabled by compatible hardware
    • Simulated eye tracking data, generated when hardware eye tracking is not available

    Eye tracking data is processed exclusively for analytics and visualization purposes and is not used to identify individuals.

    Data Retention & Storage

    We retain collected telemetry only for as long as necessary to provide insights to our customers or as required by law. Technical and usage data is retained for 30–90 days. Aggregated analytics data is retained for the duration of the customer account. After account termination, data is retained for the export window defined by your plan (Easy: 30 days, Advanced: 90 days, Enterprise: 365 days — see Terms of Service §15A) and then permanently deleted. Raw audio is never retained (see Section 9B).

    Third-Party Sub-processors

    To deliver our services, we rely on trusted infrastructure providers who meet high security standards:

    • Infrastructure: Amazon Web Services (AWS) — data storage and processing (US/EU regions).
    • Communication: Proton Mail — secure handling of support and inquiries.
    • Analytics (Web only): minimal, privacy-friendly web analytics to improve our landing page experience.

    5. Data Explicitly Not Collected

    Gossip Analytics does not intentionally collect or process:

    • Biometric identifiers such as facial recognition data, fingerprints, or iris scans
    • Sensitive personal data as defined under applicable laws
    • Data from minors

    5A. Children's Data and COPPA Compliance

    We do not knowingly collect or process personal data from children under 13 years old (or 16 in jurisdictions requiring higher age). The Service is not directed to minors.

    If a Customer processes data involving minors in XR environments, the Customer must implement appropriate age verification, obtain verifiable parental consent where required (e.g., COPPA), and notify us to apply any necessary restrictions.

    6. Purposes of Data Processing

    We process personal data solely for legitimate business purposes, including:

    • Providing and operating the platform
    • Delivering analytics and insights
    • Improving product functionality and performance
    • Ensuring platform security and integrity
    • Customer support and communications
    • Compliance with legal and contractual obligations

    7. Legal Basis for Processing (GDPR-Aligned Principles)

    Where applicable (e.g., GDPR, LGPD, UK GDPR), data processing is based on:

    • Performance of a contract (e.g., account data, service delivery).
    • Legitimate interests (e.g., platform improvement, security, aggregated analytics) – we conduct internal Legitimate Interests Assessments (LIA) to balance interests.
    • Consent, where required by law (e.g., non-essential cookies or certain marketing).

    For XR/eye-tracking data, processing typically relies on the Customer's legitimate interests or end-user consent obtained by the Customer.

    8. Data Sharing and Subprocessors

    We do not sell personal data. Personal data is never shared for marketing purposes or cross-context behavioral advertising.

    Personal data may be shared with trusted subprocessors strictly necessary for providing and supporting the Service, including cloud infrastructure, storage, caching, database management, and specialized AI analysis. All subprocessors are bound by written agreements that impose data protection obligations at least as protective as those in this Privacy Policy and applicable data protection laws (including GDPR-equivalent standards).

    Key subprocessors include:

    Amazon Web Services, Inc. (AWS) – Cloud infrastructure and related services, including compute (ECS Fargate), load balancing (Application Load Balancer – ALB), and object storage (S3). AWS hosts most of our backend processing, storage of images, and telemetry data. Audio is never stored (see Section 9B). AWS is certified under the EU-U.S. Data Privacy Framework (DPF) and we incorporate Standard Contractual Clauses (SCCs 2021) where required. For the full list of AWS subprocessors, see: aws.amazon.com/compliance/sub-processors.

    Upstash, Inc. – Managed Redis caching service for high-performance temporary storage of session and interaction data. Upstash acts as a data processor and complies with GDPR requirements through appropriate safeguards.

    MongoDB, Inc. – Database hosting via MongoDB Atlas for general data storage, including analytics metadata, user account information, and processed XR/spatial data. MongoDB acts as our data processor, uses SCCs/DPF for international transfers, and supports data subject rights.

    Google (Gemini API) – AI service used for behavioral signal interpretation and content generation. Gemini processes only the minimum metadata required for inference, with no audio recording or storage and no use of customer data to train Google's foundation models. We rely on Google's Standard Contractual Clauses (SCCs) and Data Processing Addendum (DPA) for international transfers. To request our DPA including Gemini, contact privacy@gossipanalytics.com.

    Subprocessors may be added or changed over time for operational reasons (e.g., new regions or features). We will notify Customers of material changes to this list via email to account contacts or through the dashboard at least 30 days in advance where contractually or legally required. A current full list of subprocessors, their purposes, and applicable safeguards (including SCCs/DPA details) is available upon request to privacy@gossipanalytics.com.

    We conduct due diligence on all subprocessors and require them to implement technical and organizational measures consistent with industry standards.

    8A. International Data Transfers

    Much of our infrastructure and subprocessors operate in the United States (e.g., AWS US regions (e.g., us-east-2), MongoDB Atlas, Upstash, Google Cloud / Gemini API). Personal data may therefore be transferred to and processed in the United States or other countries outside Mexico, the EU/EEA, or the Customer's country.

    To ensure an adequate level of protection:

    • For transfers from the EU/EEA or UK: We rely on the EU-U.S. Data Privacy Framework (DPF) certification of AWS and MongoDB (where applicable), and/or Standard Contractual Clauses (SCCs 2021) incorporated into our Data Processing Agreements with subprocessors and Customers.
    • Supplementary measures: We use encryption in transit and at rest, pseudonymization where feasible, and conduct Transfer Impact Assessments (TIAs) as required post-Schrems II.
    • For other jurisdictions (e.g., LGPD in Brazil): We apply equivalent safeguards.

    A copy of our executed SCCs (module 2 or 3 as processor) and any supplementary documentation is available upon request to privacy@gossipanalytics.com.

    8B. Data Processing Agreement (DPA)

    As a data processor, we offer a standard Data Processing Agreement (DPA) that incorporates:

    • Roles and responsibilities under GDPR Art. 28 (or equivalent in LGPD/CCPA).
    • Authorized subprocessors (the list above).
    • Security measures (Art. 32).
    • Subprocessing conditions.
    • International transfer mechanisms (SCCs/DPF).
    • Assistance with data subject rights and breach notification.

    The DPA is incorporated by reference into our Terms of Service (section 10) and is available for download or signature upon request to legal@gossipanalytics.com or privacy@gossipanalytics.com. Enterprise customers may negotiate custom DPAs.

    9. Aggregated and Anonymized Data

    We may generate and use aggregated or anonymized data that cannot reasonably be linked to an individual for:

    • Platform analytics
    • Product improvement
    • Benchmarking and research

    Such data does not constitute personal data.

    9A. Automated Processing and AI

    We use automated processing and AI to generate insights, heatmaps, predictions, and analytics from Customer Data. These outputs are probabilistic, may contain errors, and are for informational purposes only.

    We do not use automated processing (including AI) to make decisions with legal or similarly significant effects on individuals without appropriate safeguards and Customer agreement.

    No Customer Data is used to train foundational AI models without explicit, separate consent.

    9B. Audio Processing (Exceptional and Transient)

    Audio is processed only on an exceptional, event-triggered basis (a specific user action/reaction). Short audio segments are analyzed in real time solely to derive an emotion signal. The raw audio is permanently deleted from our systems immediately after inference and is never stored or retained. Only the derived, non-identifying emotion signal is kept as analytics data. Audio is not used for identification, voice printing, or to train AI models.

    10. Data Retention

    Unless otherwise agreed with the customer:

    • Technical and usage data is retained for 30 to 90 days
    • Aggregated analytics data is retained for the duration of the customer account

    Data may be deleted upon customer request, subject to legal or contractual obligations.

    11. Data Security

    We implement technical and organizational measures designed to protect personal data, including:

    • Encryption of data in transit and at rest
    • Role-based access control
    • Multi-factor authentication for internal systems
    • Logging and monitoring of system access

    While no system is completely secure, we continuously improve our security practices.

    12. International Data Transfers

    For details on international data transfers, including transfer mechanisms (DPF, SCCs) and supplementary safeguards, see Section 8A above.

    13. User Rights

    Depending on applicable law (GDPR, CCPA/CPRA, LGPD, etc.), individuals may have rights to:

    • Access, rectification, erasure, restriction, objection, portability.

    For California Residents (CCPA/CPRA)

    • Right to know what personal data is collected
    • Right to request deletion
    • Right to opt-out of sale/sharing (we do not sell or share for cross-context behavioral advertising)
    • Non-discrimination

    Procedure

    Submit requests to privacy@gossipanalytics.com with proof of identity. We respond within 30 days (extendable to 45/90 if complex). Customers (Controllers) handle end-user requests primarily.

    14. Cookies and Tracking Technologies

    Our website may use essential and analytics cookies to operate and improve the service. Where required, consent mechanisms are provided.

    15. Compliance Positioning

    Gossip Analytics follows privacy-by-design and data minimization principles.

    At this time, Gossip Analytics does not hold formal third-party certifications such as SOC 2 or ISO 27001. A formal compliance program and certifications may be pursued as the company scales.

    We align our practices with GDPR, CCPA/CPRA, LGPD and COPPA principles.

    16. Changes to This Policy

    We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date and, where appropriate, by providing notice.

    Material changes will be notified via email to account contacts or through the dashboard.

    17. Governing Law and Jurisdiction

    This Privacy Policy is governed by the laws of the United Mexican States. Disputes shall be resolved exclusively in the competent courts of Mexico City, Mexico.

    For EU/EEA residents, mandatory consumer protections under GDPR may apply additionally.

    18. Contact Us

    For privacy or data protection inquiries, contact:

    This document is not legal advice. Consult a specialized attorney.