How AmpliFlow handles personal data
This page shows where customer data is hosted, which sub-processors we use, how breaches are handled, and how you request export or deletion. For binding terms, see the Privacy Policy.
Last updated: 2026-07-01
Data protection starts with operating choices
AmpliFlow's core service runs within the EU/EEA, collects limited data, and shows which sub-processors are used.
Each subscription can include a Data Processing Agreement. AI features are enabled separately, and the tenant administrator approves the selected provider before task-specific content is sent to that provider. That makes the data protection setup easier to review before the system is used.
Where data is hosted and when AI can send data onward
See the default operating locations for the app, files, website, logs, and analytics, plus optional AI flows that are only used after opt-in.
Hosting locations and optional AI flows
The core service runs within the EU/EEA. AI is enabled separately and the provider is actively selected.
Map data © SimpleMaps.com
Protection in the service
These parts are included in how AmpliFlow handles personal data.
EU-Only Hosting
Customer data in the core service is stored on infrastructure within the EU/EEA. If you need a specific country or single data center, we review that before contract signing.
Operational Security
AES-256 encryption at rest, TLS 1.2+ in transit, role-based access control, and isolation between customers. Technical details are on the security page.
Data Subject Rights
Data subjects can request access, rectification, erasure, restriction, portability, and objection. Send requests to info@ampliflow.com, and we handle them within one month.
Sub-Processor Transparency
We show which sub-processors are used for the app and the website. AI is opt-in and requires separate tenant-admin approval for the selected provider. Berget AI and OpenAI can be selected only after the relevant approval and DPA/addendum review.
Breach Notification
We notify the customer contact within 24 hours when we discover a personal data breach. The notice covers what happened, which data may be affected, and which actions are being taken. The controller reports to the supervisory authority within 72 hours when GDPR requires it.
Export at Subscription End
When the subscription ends, you can receive a full data export for a small manual handling fee. Customer data is then deleted according to the agreement.
Our Sub-Processors
See which vendors process data, for what purpose, and in which area.
AmpliFlow App
Marketing website (ampliflow.se / ampliflow.com)
Data Processing Agreement
When your organization uses AmpliFlow, you are the data controller. You decide what personal data enters the system and why. AmpliFlow (operated by Cognit Consulting AB) is the data processor. We process that data on your behalf, strictly according to your instructions and GDPR requirements.
A Data Processing Agreement (DPA) defines each party's responsibilities: what data is processed, how it is protected, and what happens if something goes wrong. AmpliFlow provides a DPA as part of every subscription agreement. No add-on, no extra cost.
In practice, this means your organization stays in control. We handle your data according to the rules you and GDPR set.
Need a DPA? Contact us and we will send the right document.
AI providers as sub-processors
AI providers are not part of the default AmpliFlow core service. They are used only when a tenant administrator enables AI and approves the selected provider inside the application. The approval records the current AmpliFlow Terms, Privacy Policy, approval text, and provider-specific facts shown at the time of approval.
For GDPR roles, the customer remains the controller for customer content. Cognit Consulting AB acts as processor for AmpliFlow, and the approved AI provider acts as an AI sub-processor for the limited purpose of receiving AI requests and returning AI-generated answers.
- Berget AI: Berget publishes a DPA at https://berget.ai/en/dpa (last updated 2026-04-08). We describe it as EEA data-centre processing based on that provider documentation, not as a guarantee that all processing is limited to Sweden.
- OpenAI: OpenAI publishes a data processing addendum at https://openai.com/policies/data-processing-addendum/ and a sub-processor list at https://openai.com/policies/sub-processor-list/. OpenAI should be approved only when the customer accepts the applicable transfer, residency, retention, and subprocessor posture for the configured project.
We avoid unsupported blanket claims such as "EU-only AI" or "zero retention" unless the exact provider and project control is documented and approved.
Core service processing stays in the EU/EEA
AmpliFlow's core service processes customer data within the EU/EEA. This reduces the need for supplementary safeguards for third-country transfers in normal operation.
Microsoft Azure, our infrastructure provider, is certified under the EU-U.S. Data Privacy Framework (DPF). All data centres we use are located within the EU.
Exception: If you explicitly choose to enable AI features, the selected provider may process task-specific AI request data outside the EU/EEA. See our Privacy Policy, Terms of Service, and provider documents for details.
Export when the subscription ends
At the end of your subscription, we can export your data in machine-readable format plus original files, such as attachments you have uploaded. Customer data is then deleted from our systems according to the agreement.
We charge a fee for the export as the process still requires some manual handling. We're actively working to automate this and continuously reduce the cost.
Quick check of common GDPR questions
Answer 7 questions about hosting, DPA, breaches, export, and data subject rights.
7 questions. About 2 minutes.
Frequently Asked Questions
What personal data does AmpliFlow process?
Where is my data stored?
Can we require data to be stored in a specific country or datacenter?
How do I exercise my data subject rights?
What happens to my data when I cancel?
Is a DPA included?
Do you transfer data outside the EU?
Does the website collect data?
Questions About Data Protection?
If you have questions about how AmpliFlow handles personal data, need a DPA, or want to exercise your data subject rights, contact us.
Email: info@ampliflow.com