Gong
low riskRevenue Intelligence & Conversation Intelligencegong.ioverified 2026-03-30
Data-handling profile
- Trains on input
- No — does not train on customer inputs
- Retention
- Configurable by the customer during the active subscription; upon contract termination, Gong deletes Customer Data within 30 days.
- Data region
- United States (AWS), Germany (AWS), Australia (AWS)
- Certifications
- SOC 2 Type IIISO 27001ISO 27701ISO 27017ISO 27018HIPAA
- DPA available
- Yes
- Breach history
- None identified
- EU AI Act
- Gong's conversational AI and analytics tools generally fall under minimal or low-risk applications under the EU AI Act. Transparency obligations (such as Article 52) may apply, requiring customers to notify participants that conversations are being recorded and analyzed by AI.
Sources
- https://www.gong.io/security/
- https://www.gong.io/privacy-policy/
- https://www.gong.io/gdpr/
- https://www.gong.io/terms-of-service/
Every fact above is drawn from the vendor's public documentation, reviewed by a human, and version-stamped. Monitored daily for changes.
Change history
No material changes recorded since monitoring began.