Gridex Support Gridex

Privacy Policy

Last updated: October 2, 2026

Introduction

TeleCetli Kft. ("SupportHub", "Gridex AI", "we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, share and protect your personal data when you use our AI-powered customer support platform.

This policy applies to all information collected through our services, including our website, API, support chat and voice widgets, customer portal, and any related services, sales, marketing, or events.

Data Controller Information

Company:TeleCetli Kft.
Address:7634 Pécs, Darázs dűlő 70., Hungary
Company Registration:02 09 085491
VAT ID:HU28954242 (Hungarian: 28954242-2-02)
Contact Email:support@gridex.ai

Definitions

For the purposes of this Privacy Policy:

Information We Collect

Information You Provide Directly

  • Account Information: Name, email address, company name, and password when you register for an account
  • Business Information: Company name, industry, team size, and business configuration details
  • Payment Information: Your billing details, such as your billing address. You enter your card or other payment method details directly with Stripe, our payment processor; they never reach our servers
  • Communication Data: Content of emails, support tickets, and feedback you send us
  • Configuration Data: Custom settings, workflow rules, service-level agreement (SLA) settings, and integration preferences
  • Voice Data: Voice session transcripts and metadata when voice support is enabled
  • Customer Satisfaction (CSAT) Data: Customer satisfaction survey responses and feedback
  • Customer Portal Data: Customer profiles created via magic link authentication

Information Collected Automatically

  • Usage Data: Information about how you interact with our services, including conversation logs, feature usage, and performance metrics
  • Device Information: Browser type, operating system, IP address, and device identifiers
  • Analytics Data: Pages visited, time spent, navigation paths, and interaction patterns
  • Support Widget Data: Customer interactions through embedded chat and voice widgets on your website

Information from End Users

When your customers interact with SupportHub through the support widget on your website, the customer portal or a connected Messenger or WhatsApp channel, we collect:

Signing in with Facebook or Google

The Facebook button on our shared sign-in page at auth.gridex.ai, used by Gridex Support (SupportHub) and QuoteForge, is provided by our Meta app “Gridex Login”. If you use this button and approve the request on Facebook, the app receives only your email address and your public profile. From your public profile we use your name and the ID that Facebook assigns to you for our app.

We use your email address and name only to create your Gridex account or find your existing one, and to show your name in the account menu. Our sign-in service keeps the Facebook ID so that it can recognise you the next time you sign in with Facebook. We do not receive your Facebook password, we do not store your Facebook access token or profile picture, we do not access your friends, posts or any other Facebook data, and we never post on your behalf.

The Google button on the same sign-in page works in a similar way, but we use Google Sign-In only to authenticate you. We ask Google only for the openid, email and profile permissions, so Google shares your name, your email address, your profile picture and an ID for your Google account. We use your name and email address for the same purposes as above, and our sign-in service keeps the Google ID so that it can recognise you the next time you sign in with Google. We do not store your Google access token or profile picture, and we do not access your Gmail, Google Calendar, Google Drive, contacts or any other Google user data.

You can remove the Gridex Login app at any time in your Facebook settings, under Apps and websites. After that, Facebook no longer shares your data with us. This does not delete the account data we already hold; see “How to delete your data” below.

Google API Services

Messenger and WhatsApp

You can connect your Facebook Page or WhatsApp Business number to SupportHub so that SupportHub answers your customers’ messages on your behalf. The connection is made through our Meta app “Gridex AI”, to which you grant the permissions pages_show_list, pages_messaging, pages_manage_metadata, whatsapp_business_management and whatsapp_business_messaging.

What we receive and store

How we use it

We use this data only to answer your customers on your behalf. The AI replies using your knowledge base and hands the conversation over to your staff when a person is needed; your staff then reply from the SupportHub inbox. Replies are delivered through Meta’s platform, so Meta also processes them under its own terms and privacy policy. We never sell Messenger or WhatsApp data, never use it for advertising, and do not use it to train AI models.

Messenger and WhatsApp conversations are kept like other chat transcripts: for as long as your workspace exists, and they are deleted when the workspace is deleted (see Data Retention). If you disconnect a Page or WhatsApp number in SupportHub, we stop receiving and answering its messages. Removing the Gridex AI app in your Facebook or Meta Business settings also revokes the access token.

Legal Basis for Processing

We process personal data based on the following legal grounds under GDPR:

  • Contract Performance: To provide our services and fulfill our contractual obligations
  • Legitimate Interests: To improve our services, ensure security, and conduct business operations
  • Consent: For optional analytics cookies and any future marketing communications you opt into
  • Legal Obligations: To comply with applicable laws and regulations

How We Use Your Information

We use the collected information for the following purposes:

Data Sharing and Disclosure

We do not sell your personal data. We may share your data with the following service providers and in the following circumstances:

Service Providers

  • Microsoft Azure: Cloud infrastructure and data storage (Sweden Central region, EU). Azure OpenAI Service writes the AI replies in the web chat, Messenger and WhatsApp and runs the in-app assistant. Cohere embedding and reranking models (which turn text into numerical representations and rank search results), hosted by Microsoft in Azure AI Foundry, power knowledge-base search. Azure AI Speech (West Europe region, EU) converts speech to text and text to speech. In AI phone calls, the transcribed text of the call is used to generate the AI voice agent’s spoken answers, the Call Copilot’s suggestions to your staff and knowledge-base answers in call flows. These AI models use Microsoft’s Global deployment type: data stored at rest stays in the EU, but prompts and responses may be processed in any Azure region where the model is deployed, including outside the European Economic Area. IMPORTANT: Microsoft commits that your prompts and completions (the text sent to an AI model and the text it returns) and embeddings (numerical representations of text used for search) are NOT available to other customers or to OpenAI or other model providers, and are NEVER used to train, retrain, or improve Azure OpenAI models or any Microsoft products. Your data is stored, encrypted with AES-256, in Gridex’s own Microsoft Azure environment in the EU (Sweden Central region).
  • Stripe: Payment processing (certified as a PCI DSS Level 1 service provider)
  • Keycloak: Authentication and identity management — open-source software that we run ourselves in our Microsoft Azure environment, so no other company receives this data
  • Neo4j: Knowledge graph database for Memory Insights (the topics, trends and relationships found in your support conversations) — software that we run ourselves in our Microsoft Azure environment
  • Weaviate: Vector database for knowledge base search and document retrieval, which we run ourselves in our Microsoft Azure environment. Weaviate stores document embeddings (numerical representations) to enable semantic search across your knowledge base — original documents are not stored in Weaviate, only their vector representations.
  • Google Analytics: Optional website analytics with cookies, loaded only with your consent. Separately from cookies, our servers count product events (public page views, sign-ins, tickets, calls, purchases) and send them to Google Analytics without cookies or your IP address. Anonymous visits are labelled with a keyed hash that changes every day; once you are signed in, the label is a keyed pseudonym of your user and account IDs, which stays the same over time so that we can count returning use. Google never receives your name, email address, IP address or account IDs.

Other Circumstances

AI Model Data Protection Guarantee

Your data privacy is our top priority. We want to be absolutely clear about how your data is protected:

No Training on Customer Data

We never use your conversations, support tickets, knowledge base articles, voice transcripts, customer data or any other data you provide to SupportHub to train, retrain or improve AI models. For the AI features that run on Microsoft Azure OpenAI Service, Microsoft’s terms also state that prompts and completions are not used to train its models.

Microsoft Azure Data Protection

For the AI features that run on Microsoft Azure OpenAI Service, Microsoft makes the following commitments:

Complete Data Isolation

Your business data, support conversations, knowledge base articles, voice transcripts, and configurations are completely isolated from other SupportHub customers and from any model training pipelines. Your data is used only for the purposes described in this Privacy Policy.

Data Retention

We retain your data for as long as necessary to provide our services and fulfill the purposes described in this policy. Below are our standard retention guidelines. You may request deletion of your data at any time by contacting us.

Data TypeRetention Period
Sign-in Account InformationFor as long as your account exists. Deleted within 30 days of a deletion request
Ticket HistoryFor as long as your workspace exists. Deleted when the workspace is deleted
Chat/Voice Transcripts (including Messenger and WhatsApp)For as long as your workspace exists. Deleted when the workspace is deleted
Knowledge Base ContentFor as long as your workspace exists. Deleted when the workspace is deleted
Payment Records8 years (required by the Hungarian Accounting Act, Act C of 2000 on Accounting). Payment card details are never stored — handled entirely by Stripe
Analytics DataUp to 2 years in aggregated/anonymized form
CSAT ResponsesFor as long as your workspace exists; responses are deleted when the workspace is deleted. The respondent’s email address is removed 2 years after the survey was sent
Audit LogsUp to 3 years for security and compliance purposes; personal data in them is removed when the workspace is deleted

How to delete your data

You can ask us to delete your data at any time. Your sign-in account at auth.gridex.ai is shared by SupportHub and QuoteForge; your workspace holds your business’s SupportHub data.

Delete your account, including data from signing in with Facebook

Email support@gridex.ai from the email address of your account and ask us to delete your account. Within 30 days of receiving your request, we delete your Gridex account and the personal data linked to it, including the name, email address and Facebook or Google ID we received when you signed in, and we confirm by email when it is done.

Delete your workspace

A workspace administrator can delete the whole workspace in Settings → Account → Terminate Account, or ask us to do it by emailing support@gridex.ai. The workspace is deleted 30 days after the request, and you can cancel until then. Deletion removes the workspace’s data, including the access tokens of connected Facebook Pages and WhatsApp numbers, all tickets, conversations and messages (including Messenger and WhatsApp conversations), customer records, knowledge base content and uploaded files. Members’ sign-in accounts are not deleted with the workspace, because the same account can be used for QuoteForge; email us if you want yours deleted too.

If you wrote to a business on Messenger or WhatsApp

If you wrote to a business that uses SupportHub, you can ask the business to delete your conversation, or email support@gridex.ai with the name of the business and enough detail for us to find the conversation (for example your WhatsApp number or, for Messenger, the date and time you wrote to the business). We delete the conversation together with your Messenger ID or WhatsApp number within 30 days of receiving your request.

Revoking access

Removing the Gridex Login app in your Facebook settings (Apps and websites) stops Facebook from sharing your data with us. Disconnecting a Page or WhatsApp number in SupportHub stops us from receiving and answering its messages, and removing the Gridex AI app in your Facebook or Meta Business settings also revokes its access token. Removing an app does not by itself delete data we already hold; use the steps above for that.

Some records are kept after deletion: invoices and payment records for 8 years, as required by the Hungarian Accounting Act (Act C of 2000 on Accounting), and security audit logs, with personal data removed, for up to 3 years. See Data Retention.

Data Security

We implement appropriate technical and organizational measures to protect your data:

International Data Transfers

Some of our service providers process personal data outside the European Economic Area (EEA). We transfer personal data outside the EEA only to countries for which the European Commission has adopted an adequacy decision (GDPR Article 45), or subject to appropriate safeguards under GDPR Article 46, such as the Standard Contractual Clauses adopted by the European Commission. You can request information about these safeguards by contacting us at support@gridex.ai. The AI models we use in Microsoft Azure (Azure OpenAI Service and the Cohere models) run on Microsoft’s Global deployment type, so prompts and responses may be processed in Azure regions outside the EEA, while data stored at rest stays in the EU.

Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR regarding your personal data:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of data processing
  • Right to Data Portability: Receive the personal data you provided to us in a structured, commonly used and machine-readable format, transmit it to another controller, and have it transmitted directly from us to another controller where technically feasible
  • Right to Object: Object to certain processing activities
  • Right to Withdraw Consent: Withdraw consent at any time

To exercise any of these rights, please contact us at support@gridex.ai. We will respond within one month of receiving your request. Where necessary, the GDPR allows this period to be extended by two further months; if so, we will tell you within the first month.

Cookies and Similar Technologies

We use browser storage technologies (localStorage and sessionStorage) to provide and improve our Service. Essential storage includes authentication tokens, session state, device identifiers, cookie consent preferences, and language/theme settings. Optional analytics cookies (Google Analytics) are only loaded with your explicit consent; the cookie-free product counts are described under Service Providers. You can manage your cookie preferences at any time through our Cookie Settings page.

We Do Not Sell Your Personal Data

**Important:** We want to be absolutely clear:

This commitment applies to all users, including California residents under CCPA. See the CCPA Compliance section below for your specific rights.

Do Not Track (DNT)

We do not track users for advertising purposes and do not track them across other websites. Analytics cookies (Google Analytics) are optional and consent-based, and you can disable them at any time through our Cookie Consent Banner and Cookie Settings page. The cookie-free product counts described under Service Providers never include your name, email address, IP address or account IDs.

Payment Processing and Security

We use Stripe as our third-party payment processor. Stripe is certified as a PCI DSS Level 1 service provider, the highest level of certification in the payments industry. We do NOT store or collect your payment card details on our servers. Your card and other payment method details are provided directly to Stripe's secure servers using bank-level encryption. For more information, please refer to Stripe's Privacy Policy at https://stripe.com/privacy.

California Consumer Privacy Act (CCPA) Compliance

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA). This section explains those rights. To exercise them, contact us at support@gridex.ai.

Business Transactions and Transfers

If TeleCetli Kft. (SupportHub) is involved in a merger, acquisition, asset sale, or other business transaction, your Personal Data may be transferred as part of that transaction. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy. The acquiring entity will be contractually required to maintain the same level of data protection.

Children's Privacy

Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child under 16, please contact us immediately.

Data Protection Officer

For privacy-related inquiries or to exercise your rights, you can contact our Data Protection Officer at:

Complaint Rights

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement. Our lead supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information:

Nemzeti Adatvédelmi és Információszabadság Hatóság

Address: 1055 Budapest, Falk Miksa utca 9-11.

Website: www.naih.hu

Changes to This Policy

We may update this Privacy Policy from time to time. Every change is published on this page with a new "Last updated" date. For significant changes, we will also notify you by email or through our services.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Address:TeleCetli Kft., 7634 Pécs, Darázs dűlő 70., Hungary

Cookie Settings

We use cookies to improve your experience. You can customize your preferences below.