Sageforce Privacy Notice
Last Updated: August 19, 2026
1. Introduction
Sageforce Inc. ("Sageforce," "we," "us," or "our") provides an AI-powered platform and related services (the "Platform") that may be used directly by Sageforce or provided on behalf of customer and partner organizations.
This Privacy Notice explains how personal information, also referred to as personally identifiable information ("PII") or personal data, may be processed when you use the Platform.
The organization responsible for determining the purposes of processing your personal information depends on how you access and use the Platform, as explained below.
2. Who Is the PII Controller?
Sageforce may act either as a PII controller or as a PII processor, depending on the service and processing activity.
2.1 Services Provided on Behalf of a Customer or Partner
If you access the Platform through, or participate in a session provided on behalf of, a customer or partner organization, that organization is the PII controller for the personal information processed for that session or service.
The applicable PII controller is the organization that invited you to participate, provided you with access to the Platform, or on whose behalf the applicable session or service is being provided. The identity of that organization is provided through the relevant invitation, communication, landing page, session, or service context.
In these circumstances, Sageforce acts as a PII processor and processes personal information on behalf of and in accordance with the instructions of the applicable customer or partner organization and the applicable contractual agreement.
Questions regarding the purposes of processing or requests to exercise privacy rights relating to such processing should generally be directed to the applicable customer or partner organization. Sageforce will assist the applicable controller with privacy requests as required by applicable law and our contractual obligations.
2.2 Services Where Sageforce Is the Controller
For certain services and processing activities provided directly by Sageforce, including where Sageforce determines the purposes and means of processing, Sageforce Inc. is the PII controller.
This may include, as applicable, directly managed Sageforce accounts and services, business and administrative contacts, security and fraud-prevention activities, and other processing undertaken by Sageforce for its own legitimate operational purposes.
Where Sageforce is the PII controller, privacy-related questions or requests may be submitted to:
3. Information We Process
The information processed through the Platform depends on the service configuration and the instructions of the applicable PII controller.
3.1 Session and Interaction Information
Information processed during a session may include:
- Chat messages and conversation transcripts
- Audio recordings, where recording is enabled and the required consent or other lawful basis applies
- Video recordings, where recording is enabled and the required consent or other lawful basis applies
- Responses submitted during a session
- Interaction and engagement information
- Session identifiers
- Session duration and usage information
- Analytics generated from interactions
3.2 Account and Identifying Information
In many customer-managed sessions, Sageforce may receive a pseudonymous session identifier rather than the participant's direct identifying information.
Depending on the service, configuration, and applicable controller's instructions, Sageforce may also process information such as:
- Name
- Email address
- Organization or professional affiliation
- Account information
- User or participant identifiers
- Other information voluntarily provided during use of the Platform
The applicable customer or partner organization may separately hold information that enables it to associate a Platform session with an identified individual.
3.3 Technical Information
We may process technical information necessary to operate and secure the Platform, including:
- Device and browser information
- Platform usage and navigation information
- Application and error logs
- Security events
- Network and technical identifiers
4. How Personal Information Is Used
Depending on the applicable service and controller instructions, personal information may be processed to:
- Provide and operate Platform functionality
- Enable AI-powered interactions
- Process and respond to user requests
- Conduct analyses requested by the applicable controller
- Generate reports and insights
- Maintain quality and reliability
- Monitor Platform performance
- Provide customer support
- Protect the Platform against unauthorized access, misuse, fraud, or security threats
- Meet legal, regulatory, contractual, and compliance obligations
- Improve Platform functionality using appropriately protected, aggregated, or de-identified information where permitted
Where Sageforce acts as a PII processor, Sageforce processes personal information only for the purposes authorized by the applicable PII controller and in accordance with the applicable contractual agreement.
5. Sharing and Disclosure
5.1 Applicable Customer or Partner Organization
Where Sageforce acts as a processor, information generated through the Platform may be made available to the customer or partner organization acting as the applicable PII controller.
Depending on the service, this may include:
- Session transcripts and responses
- Interaction information
- Analytics
- Reports
- Usage information
- Other outputs configured by the applicable controller
The controller determines its purposes for using this information and is responsible for providing any additional privacy information required regarding its own processing activities.
5.2 Service Providers and Subprocessors
Sageforce uses service providers and subprocessors to support the operation of the Platform. These providers may perform functions such as:
- Cloud hosting and storage
- AI and language processing
- Speech and audio processing
- Analytics and monitoring
- Security
- Technical support
Such providers may process personal information only as necessary to provide their services and are subject to appropriate contractual and security requirements.
5.3 Legal Requirements
Information may also be disclosed where required to:
- Comply with applicable law or valid legal process
- Respond to lawful requests from competent authorities
- Protect the security, rights, or safety of Sageforce, its customers, Platform users, or others
- Investigate fraud, misuse, or security incidents
5.4 Corporate Transactions
Information may be transferred as part of a merger, acquisition, reorganization, financing, sale of assets, or similar corporate transaction, subject to applicable legal requirements.
6. Data Retention
Retention periods depend on the nature of the processing and whether Sageforce acts as a controller or processor.
Where Sageforce acts as a PII processor, personal information is retained in accordance with the applicable controller's instructions, the applicable customer agreement, configured retention requirements, and applicable legal obligations.
Where Sageforce acts as a PII controller, personal information is retained only for as long as necessary for the purposes for which it was collected and in accordance with applicable legal, contractual, security, and record-retention requirements.
Information that has been irreversibly anonymized may be retained for longer periods where permitted by applicable law.
7. Information Security
Sageforce implements technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, or misuse.
These measures include, as appropriate:
- Encryption in transit and at rest
- Access controls and authentication
- Security monitoring
- Secure cloud infrastructure
- Vulnerability and security assessments
- Personnel security and privacy training
- Controls governing access to personal information
8. Your Privacy Rights
Depending on your location and applicable law, you may have rights relating to your personal information, including rights to:
- Request access to personal information
- Request correction of inaccurate information
- Request deletion of personal information
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Request portability where applicable
- Exercise other rights provided under applicable privacy laws
8.1 Where a Customer or Partner Is the Controller
If your personal information was processed through a service provided on behalf of a customer or partner organization, privacy rights requests should generally be submitted to the organization that invited you, provided you access, or on whose behalf the service was provided.
That organization is the applicable PII controller and is responsible for determining how your request is handled.
If Sageforce receives a request relating to processing for which a customer or partner is the controller, Sageforce will direct or transmit the request to the applicable controller and provide reasonable assistance as required.
8.2 Where Sageforce Is the Controller
Where Sageforce is the PII controller, you may submit a privacy request to:
Sageforce may take reasonable steps to verify your identity before responding to a request.
9. Audio and Video Recording
Where a Platform experience includes audio or video recording, information regarding the recording will be provided through the applicable Platform experience.
Where consent is required, recording will occur only after the required consent has been obtained. Where available, you may decline or withdraw consent in accordance with the applicable service functionality and applicable law.
10. Children's Privacy
Unless specifically configured by an applicable controller for a legally permitted use case with appropriate safeguards, the Platform is not intended for use by children.
If Sageforce becomes aware that personal information relating to a child has been processed contrary to applicable requirements, Sageforce will take appropriate action in cooperation with the applicable controller.
11. International Data Transfers
Personal information may be processed in countries other than the country in which you are located.
Where required by applicable law, Sageforce and the applicable PII controller implement appropriate safeguards for international transfers of personal information.
12. Changes to This Privacy Notice
We may update this Privacy Notice from time to time to reflect changes to our services, processing activities, legal requirements, or privacy practices.
The current version will be made available through the Platform.
13. Contact
Processing Controlled by a Customer or Partner
If you access Sageforce through a customer or partner organization, please contact the organization identified in your invitation, communication, landing page, session, or service context regarding its processing of your personal information.
Processing Controlled by Sageforce
For processing for which Sageforce Inc. is the PII controller, or for general questions regarding this Privacy Notice, contact:
Sageforce Inc.
Email: privacy@sageforce.ai
If you are unsure which organization is the applicable PII controller, you may contact Sageforce at privacy@sageforce.ai, and we will assist in identifying the appropriate controller for the relevant processing activity.