This page summarises the Data Processing Agreement (DPA) that AmpVerve enters into with every customer who provides personal data through our platform. An executable copy is available on request.
Customer is the Controller. AmpVerve is the Processor. Where AmpVerve processes data on its own determination (e.g. service-improvement analytics on aggregated, non-identifying data), AmpVerve acts as Controller and the relevant terms of our privacy notice apply.
The current list is published at /subprocessors. Customers receive 30 days’ notice of any change.
For UK customers, transfers outside the UK rely on the UK International Data Transfer Addendum (IDTA). For EU customers, transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses (SCCs). Where Article 49 derogations apply, we obtain explicit consent.
Customers may request our security evidence pack under NDA: SOC 2 and ISO 27001 controls documentation (certification in progress) and a penetration-test executive summary. Once per calendar year, an enterprise customer may also commission an independent audit, with reasonable notice and at the customer’s cost.
AmpVerve will notify the customer without undue delay, and in any event within 72 hours of becoming aware of a personal-data breach affecting that customer’s data, including the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed.
The DPA is effective from the date the master subscription agreement is signed and remains in force as long as AmpVerve processes the customer’s personal data. On termination, AmpVerve returns or deletes all personal data within 90 days, subject to any legal-hold or regulatory retention requirement.
Email dpo@ampverve.com with your legal entity name and territory. We will return a counter-signed PDF within 5 business days.