Gong — privacy & data policy

Provider: Gong.io. PromptPrivacy score: 45/100. Last verified August 26, 2026.

What happens to your data?

Gong collects and processes business, user, and customer communication data to provide conversation intelligence services, operate its platform, and optimize AI/ML models. Customer Data is managed on behalf of business customers under a Data Processing Addendum. Personal data is shared with service providers, partners, and analytics vendors as needed to deliver and market the services.

Does it train on your data?

Gong utilizes personal and processed data to analyze service interactions and improve offerings, explicitly including the utilization and optimization of Artificial Intelligence and Machine Learning capabilities under its legitimate interests. Customer Data is processed under instructions set out in the Data Processing Addendum.

Can you opt out?

Yes, users can opt out of promotional emails via unsubscribe links and adjust cookie preferences or opt out of data sharing/sales using the 'Your Privacy Choices' toggle or Global Privacy Control (GPC). Opting out of core service data processing requires contacting privacy@gong.io or submitting a request through the business customer who controls the account.

Data retention

Personal data is retained for as long as deemed reasonably necessary to provide services, fulfill contractual and legal obligations, and resolve potential disputes. Specific retention durations are evaluated based on data sensitivity, potential risks, and legal requirements rather than fixed schedules.

Encryption & security

The policy states that systems, applications, and procedures are implemented to secure personal data against theft, loss, and unauthorized access. Specific encryption protocols (such as TLS or encryption at rest) are not detailed directly in the policy text, which references an external security trust center.

Is it safe for work?

Yes, Gong is built specifically for enterprise business use. It provides Data Processing Addendums (DPAs), complies with the EU-U.S. Data Privacy Framework, and maintains enterprise-level administrative controls, though organizations should review specific contract terms regarding AI/ML optimization.

Source policy: https://www.gong.io/privacy-policy