Privacy Policy
Introduction
This Privacy Policy describes how Concentrix Corporation and its affiliates (“Concentrix,” “we,” “us,” or “our”) collect, use, store, disclose, and otherwise process personal information when you use iX Seller. iX Seller includes the internal admin web portal and the iOS and Android mobile app (collectively, the “Services”).
iX Seller is an internal Concentrix tool for employees. It is not offered to the general public or to external customers. This Privacy Policy is supplemental to Concentrix's employee privacy notices and internal policies that may also apply to you.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not use the Services.
1. Regional and Supplemental Notices
European Economic Area (EEA), United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland, the sections on legal bases, international transfers, and your rights apply to you. Follow Concentrix's internal privacy process or contact the Data Protection Office to exercise statutory rights.
California (United States)
If you are a California resident, please also see Section 12 below and Concentrix's California Privacy Policy: CNX California Privacy Policy v2.0. We do not sell or share personal information for cross-context behavioral advertising through the Services.
Latin America and the Caribbean
If you are located in LATAM or Caribbean countries where Concentrix has commercial presence, we encourage you to read the local privacy materials at concentrix.com/legal (LATAM section). For LATAM and Caribbean privacy inquiries: proteccion.dedatos@concentrix.com.
Other regions
If you are in a jurisdiction with mandatory local privacy requirements, the Your Rights and Contact Us sections below describe how to reach us. We will respond in accordance with applicable law.
2. Who May Use iX Seller
iX Seller is available only to Concentrix employees who have been granted access through Concentrix's Microsoft Entra ID tenant. The Services are not directed to children and we do not knowingly collect personal information from anyone under 16 (or the higher age required in your jurisdiction).
3. Information We Collect
3.1 Information you provide or generate
| Category | Examples | Where / purpose |
|---|---|---|
| Account and identity | Name, work email, Concentrix user ID, role, and group memberships from Microsoft Entra ID when you sign in | Both Services — authentication, authorization, and audit |
| Administration records (admin web) | Changes you make to catalogs, SharePoint configuration, user access, roles, static pages, news feeds, and related admin settings | Admin web — operating and auditing the internal platform |
| Sales enablement content (mobile) | Meeting prep packs, favorites, recently viewed documents, notes, and optional feedback or bug reports you submit | Mobile app — features you use in your sales workflow |
| Optional media (mobile) | Audio you choose to record for transcription, or images you attach to feedback or bug reports | Mobile app — only when you initiate those actions |
3.2 Information collected automatically
| Category | Examples | Where / purpose |
|---|---|---|
| Device and technical data | Browser or device type, OS version, app version, locale, time zone, and online/offline status | Both Services — security, compatibility, and diagnostics |
| Usage and diagnostic telemetry | Sanitized events such as login outcomes, admin configuration actions, search result counts, sync errors, and performance signals sent to Azure Application Insights when enabled | Both Services — reliability, security monitoring, and improvement |
| Product analytics (mobile) | Event names and limited properties (for example, prep-pack workflow steps, device/OS context); your user ID is derived server-side from your sign-in token | Mobile app — understanding feature usage; not used for advertising |
| Device integrity (mobile) | Signals that a device may be rooted or jailbroken, used to block access when that check is enabled | Mobile app — security and compliance with Concentrix device policies |
The admin web portal stores authentication tokens in browser session storage for your active session. The mobile app stores tokens in secure device storage and caches selected content locally for offline use (see Section 8).
3.3 Information accessed from Microsoft services
When you use integrated features, our backend may access Microsoft services on your behalf using permissions granted at sign-in and configured by Concentrix:
| Service | Data accessed | Purpose |
|---|---|---|
| Microsoft Entra ID | Identity tokens and account metadata for your Concentrix work account | Sign-in, session management, and access control |
| Microsoft Graph — Calendar (mobile) | Your Outlook calendar events (subject, time, location, sensitivity) when you use meeting prep features | Agenda and meeting preparation |
| Microsoft SharePoint | Document metadata and content you browse, favorite, or open through iX Seller | Document discovery, prep packs, and offline caching |
| Microsoft Intune (mobile) | App protection enrollment and compliance status — not your Intune admin credentials | Applying Concentrix mobile device management policies |
| Microsoft Authenticator / Company Portal (mobile) | Used as sign-in brokers; we do not receive broker credentials | Enterprise authentication and Conditional Access |
When you use AI-assisted search or document suggestions, your query is processed by Concentrix's backend services (which may use Azure OpenAI) to return results. Raw search text is not included in telemetry or analytics events.
3.4 What we do not collect in telemetry
- Email addresses, full names, or phone numbers in custom telemetry properties
- Authentication tokens, refresh tokens, or API keys
- Raw search queries or full document body content
- Payment or financial account information — iX Seller does not process payments
4. How We Use Personal Information
We use personal information to:
- Provide the Services — sign-in, admin configuration, mobile sales enablement, document access, calendar-based prep, and offline sync
- Operate securely — Intune app protection, device integrity checks, access control, and fraud or misuse prevention
- Maintain and improve — debugging, quality analysis, and internal product analytics
- Support you — responding to feedback or bug reports you submit
- Meet legal and compliance obligations — audit, security, and regulatory requirements
Where required by law, we rely on legitimate interests (operating a secure internal tool), performance of your employment relationship, legal obligation, and consent where required (for example, optional mobile permissions).
5. Aggregated and De-identified Information
We may aggregate or de-identify usage data to analyze trends and improve the Services. We do not attempt to re-identify de-identified information except as required by law.
6. How We Share Personal Information
We may disclose personal information only as needed to operate iX Seller:
| Recipient | Why |
|---|---|
| Microsoft (Azure, Entra ID, Graph, SharePoint, Intune, Application Insights, Azure OpenAI) | Hosting, authentication, calendar and document integration, mobile app protection, monitoring, and AI-assisted features configured by Concentrix |
| Concentrix IT and platform administrators | Account provisioning, role assignment, access reviews, and internal compliance |
| Concentrix affiliates and approved service providers | Internal operations under confidentiality and data-processing obligations |
| Regulators, courts, or law enforcement | When required by law or to protect rights, safety, and integrity |
We do not sell personal information. We do not share personal information with third parties for their independent marketing. iX Seller is not a consumer-facing product and data is not shared with external clients or prospects through normal use of the Services.
7. International Transfers
Personal information may be processed in the United States and other countries where Concentrix or Microsoft operates services (including IT support locations such as India and the Philippines).
When we transfer personal information from the EEA, UK, or Switzerland, we use appropriate safeguards, including Standard Contractual Clauses (2021/914) and applicable UK or Swiss addenda.
8. Device Permissions, Local Storage, and Offline Data
Mobile device permissions
The mobile app may request:
| Permission | Why |
|---|---|
| Microphone | Record audio only when you start transcription during meeting prep |
| Photo library | Attach images to feedback or bug reports when you choose to |
| Network | Connect to Concentrix APIs and Microsoft services |
You can deny permissions in device settings; related features will not work without them.
Local storage
- Admin web: session storage for authentication tokens during your browser session
- Mobile: secure storage for tokens; local SQLite cache for favorites, recent documents, prep packs, agenda items, talking points, and news articles for offline access
Local mobile data is cleared when you log out or uninstall the app. Concentrix Intune policies may additionally encrypt managed app data or restrict copy/paste.
Android backup
Android backup is disabled for the mobile app to reduce risk of sensitive data leaving the device through system backups.
9. Retention
We retain personal information only as long as needed to provide the Services, meet Concentrix's legal and audit requirements, and resolve disputes. When data is no longer required, we delete or de-identify it according to Concentrix retention schedules.
10. Security
We use access controls, encryption in transit (TLS), secure token storage, telemetry sanitization, and incident response procedures to protect personal information. No system is completely secure — protect your device and work credentials.
If a personal data breach affecting you must be reported under applicable law, we will notify you and/or regulators as required.
11. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal information, object to certain processing, withdraw consent where applicable, or lodge a complaint with a supervisory authority.
How to exercise your rights
- For most employee requests, start with your Concentrix HR or privacy contact if directed by internal policy.
- You may also contact DPO@Concentrix.com with "Privacy Policy — iX Seller" in the subject line.
Account and content deletion
Uninstalling the mobile app removes local cached data on your device. Server-side records tied to your Concentrix account are handled per Concentrix retention and IT policies. Contact Concentrix IT or the Data Protection Office for deletion requests.
12. California Privacy Notice (CCPA / CPRA Summary)
This section applies to California residents and supplements the information above.
| Category | Collected | Disclosed for business purposes | Sold / shared for advertising |
|---|---|---|---|
| Identifiers (work email, account IDs) | Yes | Yes — to Microsoft and Concentrix service providers for operations above | No |
| Internet / electronic activity | Yes | Yes — as above | No |
| Professional / employment information | Yes | Yes — as above | No |
| Audio / visual (optional mobile features) | Yes, if you use them | Yes — to provide the feature | No |
We do not sell or share personal information as defined by the CPRA. To exercise California rights, email DPO@Concentrix.com.
13. Third-Party Links and Services
The Services may link to external sites or open Microsoft content. Those services are governed by their own policies. Microsoft SDKs used in the mobile app (MSAL, Intune) are also subject to Microsoft's license terms.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date will change when we do. Material updates will be posted on this page and, where appropriate, surfaced in the Services.
15. Contact Us
Global Data Protection Office
Email: DPO@Concentrix.com
Subject line: Privacy Policy — iX Seller
LATAM and Caribbean: proteccion.dedatos@concentrix.com
For technical support, use in-app feedback on mobile or contact Concentrix IT.
16. Mobile App Store Disclosures (Summary)
Summary for Apple App Store and Google Play data safety forms (mobile app only):
| Data type | Collected | Linked to identity | Used for tracking |
|---|---|---|---|
| Contact info (work email / name via SSO) | Yes | Yes | No |
| User content (prep packs, favorites, feedback) | Yes | Yes | No |
| Identifiers (account, device type) | Yes | Yes | No |
| Usage / diagnostics | Yes | Yes | No |
| Audio / photos | Optional, when you use those features | Yes | No |
Data is used for app functionality, internal analytics, and security — not for third-party advertising.