Legal
Privacy Policy
How we collect, use, and protect personal information, and the choices and rights you have.
Last updated: August 13, 2026
Be Heard Labs, Inc. ("Gather," "Be Heard Labs," "we," "us," or "our") provides an AI-native customer intelligence and voice-of-customer platform. This Privacy Policy explains what personal information we collect, how we use and share it, the choices you have, and the rights available to you under laws including the EU and UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
This Policy covers our websites at https://gobeheard.com and https://www.gatherhq.com (the "Site"), our application at https://app.gobeheard.com and related products (the "Platform"), our Slack agent, and our other related services (collectively, the "Services").
Sections
- Our Role: Controller and Processor
- Information We Collect
- How We Use Information
- Legal Bases for Processing (GDPR)
- How We Share Information
- Subprocessors
- Sale and Sharing of Personal Information
- Data Retention
- How We Protect Information
- International Data Transfers
- Your Privacy Rights
- Notice to California Residents (CCPA/CPRA)
- Notice to EU, EEA, UK, and Swiss Residents (GDPR)
- Cookies and Tracking
- Information from Minors
- External Websites
- Changes to This Policy
- How to Contact Us
1. Our Role: Controller and Processor
We handle personal information in two capacities:
- As a controller (a "business" under CCPA/CPRA): for personal information about our own website visitors, prospects, account users, and marketing contacts, where we determine the purposes and means of processing.
- As a processor (a "service provider" under CCPA/CPRA): for personal information we process on behalf of our business customers ("Customers") to deliver the Platform, including research participants and buyer data our Customers bring to or generate through the Services. In this role, the Customer is the controller and directs our processing under our agreement and Data Processing Addendum ("DPA"). If you are a research participant or your data was provided by a Customer, please refer to that Customer's privacy notice for details of their practices, and contact them to exercise your rights; we will assist them as required.
2. Information We Collect
Depending on how you interact with us, we may collect the following categories of information.
Information you provide.
- Identifiers and contact details: name, email address, postal address, organization, job title, phone number.
- Account credentials: username, authentication data, and profile details for Authorized Users of the Platform.
- Research and interview content: responses, feedback, and audio, video, or voice recordings and transcripts generated when participants take part in AI-moderated or text interviews, where we process this on behalf of a Customer.
- Communications: correspondence, support requests, and information you submit through forms, demo requests, or scheduling tools.
- Billing information you provide to enter into or manage a subscription.
Information collected automatically.
- Device and connection data: device type, operating system, browser type, IP address, and unique identifiers.
- Usage data: pages viewed, features used, and interactions with the Site, Platform, and our emails.
- Cookies and similar technologies: as described in Section 14.
Information from third parties.
- Business contact and enrichment data from marketing partners and publicly available sources.
- Website visitor identification data from our identity resolution provider.
- Data our Customers upload to or connect with the Platform (for example, CRM records, sales call transcripts, survey results, and reviews) for processing on their behalf.
3. How We Use Information
We use personal information to:
- provide, operate, secure, maintain, and improve the Services;
- create and manage accounts and authenticate users;
- deliver research studies and generate insights for Customers, as directed by the Customer;
- respond to inquiries, provide support, and communicate about the Services;
- send marketing communications, subject to your choices;
- analyze usage and improve product performance and reliability;
- detect, prevent, and investigate fraud, abuse, security incidents, and unlawful activity; and
- comply with legal obligations and enforce our agreements.
We do not use personal information contained in Customer research data for our own independent marketing purposes. When we develop or improve our models and Services, we do so consistent with our agreements with Customers and applicable law.
4. Legal Bases for Processing (GDPR)
Where GDPR applies and we act as a controller, we rely on the following legal bases:
- Performance of a contract: to provide the Services you or your organization have requested.
- Legitimate interests: to operate, secure, analyze, and improve the Services and to conduct business-to-business marketing, balanced against your rights.
- Consent: for certain marketing, cookies, and other processing where required; you may withdraw consent at any time.
- Legal obligation: to comply with applicable laws.
Where we act as a processor, we process personal data on the documented instructions of the Customer (the controller) under our DPA.
5. How We Share Information
We share personal information with:
- Subprocessors and service providers who perform services on our behalf, such as cloud hosting, storage, analytics, communications, AI model providers, and payment processing, under contracts that limit their use of the information. See Section 6.
- Our Customers, where you provide feedback or participate in research facilitated through the Services.
- Professional advisors such as auditors, lawyers, and accountants.
- Authorities and others where required to comply with law, respond to lawful requests, protect rights and safety, or enforce our terms.
- In a corporate transaction, such as a merger, acquisition, financing, or sale of assets, subject to this Policy.
6. Subprocessors
When we act as a processor for Customers, we engage subprocessors to help deliver the Services. We maintain a current list of subprocessors and make it available to Customers. Each subprocessor is bound by a written agreement imposing data protection obligations consistent with our DPA and applicable law. We remain responsible for our subprocessors' processing of Customer personal data. Our current subprocessor list is available at https://www.gatherhq.com/subprocessors and on request.
7. Sale and Sharing of Personal Information
We do not sell personal information for monetary consideration.
We use analytics and website visitor identification technologies on our Site (see Sections 6 and 14) that may involve "sharing" of certain identifiers and internet activity for cross-context behavioral advertising and marketing, as those terms are defined under CCPA/CPRA. You can opt out of this "sharing" using the "Do Not Sell or Share My Personal Information" link in our Site footer, by enabling a Global Privacy Control signal in your browser, and by using the self-regulatory opt-outs in Section 14.
We do not knowingly sell or share the personal information of individuals under 16 years of age.
8. Data Retention
We retain personal information for as long as needed to provide the Services, fulfill the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods depend on the nature and sensitivity of the data and applicable legal, tax, and regulatory requirements. When acting as a processor, we retain and delete Customer personal data in accordance with the Customer's instructions and our DPA. When information is no longer needed, we delete or de-identify it.
9. How We Protect Information
We maintain administrative, technical, and organizational measures designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These include encryption of data in transit and at rest, role-based access controls and least-privilege permissions, multi-factor authentication for administrative access, logging and monitoring, and a documented incident response process. No system is completely secure, and we cannot guarantee absolute security.
10. International Data Transfers
We are headquartered in the United States and may process personal information in the United States. Where we transfer personal data from the EU, EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where appropriate. A copy of the relevant transfer mechanism is available on request and is incorporated into our DPA.
11. Your Privacy Rights
Subject to applicable law, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate personal information;
- delete your personal information;
- receive a portable copy of your personal information;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent; and
- opt out of marketing communications and of "sharing" for targeted advertising.
To exercise any of these rights, contact us at hi@gobeheard.com. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights. If we act as a processor for a Customer, we will forward your request to the relevant Customer or assist them in responding.
12. Notice to California Residents (CCPA/CPRA)
This section applies to California residents and supplements the rest of this Policy.
Categories of personal information we collect. In the past 12 months we have collected the following CCPA categories: identifiers; customer records; commercial information; internet or other electronic network activity; geolocation data (approximate); audio, electronic, or visual information (for example, interview recordings processed for Customers); professional or employment-related information; and inferences drawn from the above.
Sources, purposes, and disclosures. Sources and business purposes are described in Sections 2 and 3. We disclose personal information to the categories of recipients in Section 5 for business purposes.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted under CPRA. We do not use sensitive personal information to infer characteristics about you.
Sale and sharing. See Section 7. We do not sell personal information. We may "share" identifiers and internet activity for cross-context behavioral advertising and marketing, and we provide an opt-out.
Your California rights: to know and access, to delete, to correct, to opt out of sale/sharing, to limit the use of sensitive personal information, and to non-discrimination.
How to exercise. Submit a request at hi@gobeheard.com, or use the "Do Not Sell or Share My Personal Information" link in our Site footer. We will verify your request using the information associated with you. You may use an authorized agent, who must provide proof of authorization.
13. Notice to EU, EEA, UK, and Swiss Residents (GDPR)
This section applies where GDPR or UK GDPR governs the processing of your personal data.
- Controller and processor roles: see Section 1.
- Legal bases: see Section 4.
- Your rights: access, rectification, erasure, restriction, data portability, objection, and the right not to be subject to solely automated decisions producing legal or similarly significant effects. We do not make solely automated decisions that produce legal effects about you.
- Withdrawing consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
- International transfers: see Section 10.
- Right to complain: you may lodge a complaint with your local supervisory authority.
- EU representative: we have appointed Prighter as our representative under Article 27 of the GDPR. You may contact our representative about the processing of your personal data, in addition to or instead of contacting us directly, using the request form at https://app.prighter.com/portal/19905774573, or by post at Prighter EU Rep GmbH, Schellinggasse 3, 1010 Vienna, Austria.
14. Cookies and Tracking
We and our partners use cookies, pixels, tags, and similar technologies to operate the Site, analyze usage, and support marketing. We use Google Analytics and Google Tag Manager for analytics, and a website visitor identification provider for marketing. For visitors in the EU, EEA, and UK, we request consent for non-essential cookies through our cookie consent banner before they are set, and you can change your choices at any time. You can also control cookies through your browser settings. For interest-based advertising opt-outs, visit the Digital Advertising Alliance and the Network Advertising Initiative. We honor Global Privacy Control signals as an opt-out of "sharing" where required.
15. Information from Minors
Our Services are not directed to children. When acting as a controller, we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it. When acting as a processor, we process information about minors only if a Customer instructs us to and only as directed by that Customer.
16. External Websites
The Services may link to third-party websites we do not control. We are not responsible for their content or privacy practices. Please review the privacy policy of any third-party site you visit.
17. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date, and where required by law we will provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
18. How to Contact Us
Be Heard Labs, Inc. 548 Market Street, PMB 786440 San Francisco, CA 94104 Email: hi@gobeheard.com
For privacy requests, include "Privacy Request" in the subject line.