Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between you, the customer (the "Customer"), and Adforn LLC, a company registered at 1007 Orange St, Wilmington, DE 19801, which provides the Amblash AI platform ("Amblash AI," "we," "us," or "our"). Amblash AI is a SaaS (software as a service) platform of Adforn LLC and is not a separate legal entity.
This DPA applies whenever Amblash AI processes Personal Data on the Customer's behalf in providing the Services. It is the Data Processing Agreement referred to in our Terms of Service. This DPA is governed by the laws of the State of Delaware, as the Terms of Service are, except where Section 8.1 provides otherwise for the Standard Contractual Clauses. If this DPA and the Terms of Service conflict on the protection of Personal Data, this DPA prevails. On every other matter, the Terms of Service prevail.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that Amblash AI processes on the Customer's behalf in providing the Services.
- "Data Protection Laws" means every law on privacy and the protection of personal data that applies to the processing of Personal Data under this DPA. This includes, where they apply, the General Data Protection Regulation (EU) 2016/679 (the "GDPR"), the GDPR as it forms part of the law of the United Kingdom, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (together, the "CCPA").
- "Subprocessor" means any third party that Amblash AI engages to process Personal Data on the Customer's behalf.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "Processing" and "process" mean any operation performed on Personal Data, including collecting, recording, storing, using, disclosing and deleting it.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Roles and Responsibilities
2.1 Customer as Controller
The Customer is the controller of the Personal Data. The Customer decides why Personal Data is processed and gives the instructions that decide how the Services process it, including the description of the people it wants to reach, the message it wants to send, and the campaigns it runs.
The Customer is responsible for:
- having a lawful basis under Data Protection Laws for every processing activity it instructs, including contacting each prospect;
- giving every notice and obtaining every consent that Data Protection Laws require of a controller;
- making sure its instructions comply with Data Protection Laws and with the laws that govern commercial email in every place where its recipients are located; and
- the accuracy of any Personal Data it provides to us.
2.2 Amblash AI as Processor
Amblash AI is a processor of the Personal Data. We process Personal Data only on the Customer's documented instructions, as set out in the Terms of Service, in this DPA, and in the Customer's configuration and use of the Services. We will tell the Customer promptly if we believe an instruction breaks Data Protection Laws, and we may suspend the affected processing until the instruction is confirmed or changed.
This DPA does not cover the personal information we collect about the Customer's own account users in order to run the account, bill for it and keep it secure. We process that information as a controller, and our Privacy Policy describes how.
3. Processing Details
- Subject matter. Providing the Services described in the Terms of Service.
- Duration. For as long as Amblash AI processes Personal Data for the Customer, as described in Section 11.
- Nature and purpose. Finding business contacts who match the Customer's description of the people it wants to reach; evaluating each contact against fixed criteria; writing an individual email for each contact; sending those emails within each recipient's working day; and recording and reporting the results to the Customer.
- Categories of Data Subjects. Prospects and recipients of the Customer's outreach, and the Customer's own users who operate the Services.
- Categories of Personal Data. Names; business email addresses; job titles; employer and company details; business location and time zone; the content of emails written and sent for the Customer; notes the Customer's users write about a prospect; and records of what happened to each email that the Services receive.
- Special categories of data. None. The Customer must not provide special categories of personal data, or data about criminal convictions, through the Services.
4. Amblash AI Obligations
Amblash AI shall:
- process Personal Data only on the Customer's documented instructions, unless the law requires otherwise, in which case we will tell the Customer about that legal requirement before processing, unless the law forbids us from doing so;
- ensure that every person we authorize to process Personal Data is bound by a duty of confidentiality;
- put in place and keep in place the security measures described in Section 5;
- engage Subprocessors only as Section 6 allows;
- help the Customer, taking into account the nature of the processing, to respond to requests from Data Subjects exercising their rights, as Section 7 describes;
- help the Customer meet its obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to us;
- delete Personal Data at the end of the Services as Section 11 describes, unless the law requires us to keep it; and
- make available to the Customer the information needed to show that we meet this DPA, as Section 10 describes.
5. Security Measures
Amblash AI shall put in place appropriate technical and organizational measures to protect Personal Data against a Personal Data Breach, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risks to Data Subjects.
These measures include:
- keeping each customer's data separate, so that it is not shown to any other customer;
- deciding who may see and do what inside each account according to the roles and permissions the Customer's administrators assign, and checking those permissions on our servers;
- encrypting all traffic between the Customer's browser and the Services;
- storing passwords only in a form that cannot be reversed;
- offering every user a second verification step at sign in using an authenticator app; and
- asking a signed in user to confirm their identity again before certain sensitive actions.
Our Security page describes these measures in more detail. We may change our security measures over time, but we will not reduce the overall level of protection they give to Personal Data.
6. Subprocessors
6.1 Authorization
The Customer gives Amblash AI general authorization to engage Subprocessors. Before a Subprocessor processes any Personal Data, we will put in place a written contract with it that imposes data protection obligations giving at least the same level of protection as this DPA.
6.2 Current Subprocessors
Our current Subprocessors are:
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting of the Services and the data they hold |
| Stripe | Payment processing for subscriptions |
| Analytics about how people use our website and the Services |
Our Subprocessors page at https://amblash.ai/subprocessors lists our current Subprocessors.
6.3 Changes
We will tell the Customer about any intended addition or replacement of a Subprocessor by updating our Subprocessors page before the new Subprocessor begins to process Personal Data.
The Customer may object to a new Subprocessor on reasonable grounds relating to the protection of Personal Data by writing to hello@amblash.ai before the new Subprocessor begins to process Personal Data. If the Customer objects, we will discuss the objection with the Customer in good faith. If we cannot resolve it, the Customer may end its subscription by giving us written notice before the new Subprocessor begins processing, and that ending will be treated as a termination by the Customer under the Terms of Service.
6.4 Liability
Amblash AI remains responsible to the Customer for the performance of each Subprocessor's data protection obligations, as if they were our own, subject to Section 13.
7. Data Subject Rights
If we receive a request from a Data Subject to exercise a right under Data Protection Laws in relation to Personal Data we process for the Customer, we will not answer the request ourselves unless the Customer authorizes us to. Where we can identify the Customer concerned, we will pass the request to the Customer without undue delay.
The Customer can respond to many requests itself using the Services, including:
- exporting its prospect records; and
- stopping any further automated emails to an individual prospect.
Where the Customer cannot respond to a request using the Services, we will give the Customer reasonable help, on written request to hello@amblash.ai, to the extent the law requires and taking into account the nature of the processing.
8. International Transfers
8.1 Transfer Mechanisms
Where Personal Data is transferred from the European Economic Area, the United Kingdom or Switzerland to Amblash AI in the United States, or onward from Amblash AI to a Subprocessor outside those places, the transfer is made under the Standard Contractual Clauses, which are incorporated into this DPA by reference as follows:
- The European Economic Area. The standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 (the "EU Standard Contractual Clauses"), Module Two (controller to processor), with the Customer as data exporter and Amblash AI as data importer. Where those clauses offer a choice: Subprocessors are engaged under general written authorization, with notice as Section 6.3 describes; the clauses are governed by the law of the EU Member State in which the Customer is established; and disputes under them are resolved by the courts of that EU Member State. The information those clauses require in their annexes is set out in Section 3 (details of the processing), Section 5 (security measures) and Section 6.2 (Subprocessors) of this DPA.
- The United Kingdom. The EU Standard Contractual Clauses, as amended by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, with the tables in that Addendum completed with the information in this DPA.
- Switzerland. The EU Standard Contractual Clauses, with the changes Swiss law requires: references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, and Data Subjects in Switzerland may bring claims in Switzerland.
If the Standard Contractual Clauses and this DPA conflict, the Standard Contractual Clauses prevail. If a transfer mechanism stops being valid, we will work with the Customer to put a valid mechanism in place.
8.2 US Processing
Amblash AI is established in the United States. Personal Data is transferred to the United States and processed there, and may also be processed wherever our Subprocessors process it. By using the Services, the Customer agrees to this, subject to the safeguards in this DPA.
9. Data Breach Notification
If Amblash AI becomes aware of a Personal Data Breach affecting Personal Data we process for the Customer, we will notify the Customer without undue delay. We will send the notice by email to the account's administrator.
The notice will describe, as far as the information is then available to us:
- the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned;
- the likely consequences of the Personal Data Breach;
- the measures we have taken or propose to take to address it and to reduce its possible harm; and
- who the Customer can contact for more information.
Where we cannot give all of this information at once, we will give it in stages as it becomes available, without further undue delay. We will take reasonable steps to contain and investigate the Personal Data Breach. Our notice is not an admission of fault or liability.
10. Audit Rights
On the Customer's written request to hello@amblash.ai, Amblash AI will provide the documentation and information reasonably necessary to show that we meet our obligations under this DPA.
We do not permit audits or inspections on our premises or of our systems, unless Data Protection Laws require us to allow one. Where they do, the Customer must give us reasonable written notice, the audit must take place during normal business hours, must not disrupt the Services or reveal any other customer's data, and must be carried out under a duty of confidentiality. The Customer bears its own costs of any audit.
11. Term and Deletion
11.1 Term
This DPA takes effect when the Customer accepts the Terms of Service, or on the Effective date shown on this page if that is later, and continues for as long as Amblash AI processes Personal Data on the Customer's behalf.
11.2 Keeping Records
While the Customer's account exists, we keep the Customer's records with no time limit. We do not expire, cap or automatically remove them. They remain until the Customer deletes them, where the Services provide a way to do so, or until the Customer deletes its account.
11.3 Deleting the Account
Only the account's owner can delete the account. A deletion request is final from the moment it is made and cannot be withdrawn.
Once a deletion request is made, we permanently remove the Personal Data we hold for the Customer at the end of the Customer's current subscription period, or thirty days after the request, whichever comes first. Removal then cannot be undone. Removal covers the whole account, including the company record, its campaigns and prospects, and every user's account in that company.
Before making a deletion request, the Customer should export any records it wants to keep.
11.4 What We Keep After Deletion
After deletion we keep only billing history and invoices, which we must keep for tax and legal reasons, together with the matching records our payment processor, Stripe, holds in its own systems. We keep these only for as long as the law requires.
12. CCPA Provisions
To the extent the CCPA applies to Personal Data we process for the Customer, Amblash AI is a service provider, and we:
- will not sell or share Personal Data, as the CCPA defines those words;
- will not keep, use or disclose Personal Data for any purpose other than providing the Services to the Customer, or as the CCPA otherwise permits;
- will not keep, use or disclose Personal Data outside our direct business relationship with the Customer;
- will not combine Personal Data with personal information we receive from or on behalf of anyone else, or collect from our own dealings with a consumer, except as the CCPA permits;
- will give Personal Data the same level of privacy protection that the CCPA requires;
- will tell the Customer if we can no longer meet our obligations under the CCPA; and
- allow the Customer, on notice, to take reasonable and appropriate steps to stop and correct any use of Personal Data that the CCPA does not allow.
We understand and will comply with these restrictions.
13. Liability
Each party's liability arising out of or relating to this DPA, however it arises, is subject to the limitations and exclusions in the "Limitation of Liability" section of the Terms of Service. In particular, our total liability under the Terms of Service and this DPA together will not exceed the greater of the total amount the Customer paid us in the twelve (12) months before the event giving rise to the claim, or one hundred U.S. dollars (US$100).
Nothing in this DPA limits any right a Data Subject has under Data Protection Laws or under the Standard Contractual Clauses, or any liability that cannot be limited under applicable law.
14. Contact
For any question about this DPA, or to make any request or give any notice under it, please contact us:
Adforn LLC (Amblash AI platform)
Registered address: 1007 Orange St, Wilmington, DE 19801
Email: hello@amblash.ai
Last Updated: September 2026
Effective: October 2026
© 2024–2026 Amblash AI. All rights reserved. Powered by Adforn LLC.