Data Protection
How AmpliFlow handles personal data
This page shows where customer data is hosted, which sub-processors we use, how breaches are handled, and how you request export or deletion. For binding terms, see the Privacy Policy.
Last updated: 2026-07-01
Data protection starts with operating choices
AmpliFlow's core service runs within the EU/EEA, collects limited data, and shows which sub-processors are used.
Each subscription can include a Data Processing Agreement. AI features are enabled separately, and the tenant administrator approves the selected provider before task-specific content is sent to that provider. That makes the data protection setup easier to review before the system is used.
Where data is hosted and when AI can send data onward
See the default operating locations for the app, files, website, logs, and analytics, plus optional AI flows that are only used after opt-in.
Hosting locations and optional AI flows
The core service runs within the EU/EEA. AI is enabled separately and the provider is actively selected.
EU countries
Operating location
Optional AI within the EU/EEA
Optional AI outside the EU/EEA
Map data © SimpleMaps.com
Protection in the service
These parts are included in how AmpliFlow handles personal data.
EU-Only Hosting
Customer data in the core service is stored on infrastructure within the EU/EEA. If you need a specific country or single data center, we review that before contract signing.
Operational Security
AES-256 encryption at rest, TLS 1.2+ in transit, role-based access control, and isolation between customers. Technical details are on the security page.
Data Subject Rights
Data subjects can request access, rectification, erasure, restriction, portability, and objection. Send requests to info@ampliflow.com, and we handle them within one month.
Sub-Processor Transparency
We show which sub-processors are used for the app and the website. AI is opt-in and requires separate tenant-admin approval for the selected provider. Berget AI and OpenAI can be selected only after the relevant approval and DPA/addendum review.
Breach Notification
We notify the customer contact within 24 hours when we discover a personal data breach. The notice covers what happened, which data may be affected, and which actions are being taken. The controller reports to the supervisory authority within 72 hours when GDPR requires it.
Export at Subscription End
When the subscription ends, you can receive a full data export for a small manual handling fee. Customer data is then deleted according to the agreement.
Our Sub-Processors
See which vendors process data, for what purpose, and in which area.
AmpliFlow App
Marketing website (ampliflow.se / ampliflow.com)
Data Processing Agreement
When your organization uses AmpliFlow, you are the data controller. You decide what personal data enters the system and why. AmpliFlow (operated by Cognit Consulting AB) is the data processor. We process that data on your behalf, strictly according to your instructions and GDPR requirements.
A Data Processing Agreement (DPA) defines each party's responsibilities: what data is processed, how it is protected, and what happens if something goes wrong. AmpliFlow provides a DPA as part of every subscription agreement. No add-on, no extra cost.
In practice, this means your organization stays in control. We handle your data according to the rules you and GDPR set.
Need a DPA? Contact us and we will send the right document.
AI providers as sub-processors
AI providers are not part of the default AmpliFlow core service. They are used only when a tenant administrator enables AI and approves the selected provider inside the application. The approval records the current AmpliFlow Terms, Privacy Policy, approval text, and provider-specific facts shown at the time of approval.
For GDPR roles, the customer remains the controller for customer content. Cognit Consulting AB acts as processor for AmpliFlow, and the approved AI provider acts as an AI sub-processor for the limited purpose of receiving AI requests and returning AI-generated answers.
- Berget AI: Berget publishes a DPA at https://berget.ai/en/dpa (last updated 2026-04-08). Based on that provider documentation, we describe the processing as EEA-based. The documentation does not support a claim that all processing is limited to Sweden.
- OpenAI: OpenAI publishes a data processing addendum at https://openai.com/policies/data-processing-addendum/ and a sub-processor list at https://openai.com/policies/sub-processor-list/. OpenAI should be approved only when the customer accepts the applicable transfer, residency, retention, and subprocessor posture for the configured project.
Core service processing stays in the EU/EEA
AmpliFlow's core service processes customer data within the EU/EEA. This reduces the need for supplementary safeguards for third-country transfers in normal operation.
Microsoft Azure, our infrastructure provider, is certified under the EU-U.S. Data Privacy Framework (DPF). All data centres we use are located within the EU.
Exception: If you explicitly choose to enable AI features, the selected provider may process task-specific AI request data outside the EU/EEA. See our Privacy Policy, Terms of Service, and provider documents for details.
Export when the subscription ends
At the end of your subscription, we can export your data in machine-readable format plus original files, such as attachments you have uploaded. Customer data is then deleted from our systems according to the agreement.
We charge a fee for the export as the process still requires some manual handling. We're actively working to automate this and continuously reduce the cost.
Quick check of common GDPR questions
Answer 7 questions about hosting, DPA, breaches, export, and data subject rights.
7 questions. About 2 minutes.
Frequently Asked Questions
What personal data does AmpliFlow process?
Names, email addresses, and usage data as described in our Privacy Policy. The specific categories depend on how your organization uses the service.
Where is my data stored?
Within the EU/EEA for AmpliFlow core service data. We use infrastructure partners including Microsoft Azure and Hetzner with data centers in Sweden, the Netherlands, Germany, and Finland. AI features are opt-in and require separate approval inside the application. Approved AI providers may process task-specific AI request data in the locations described for that provider.
Can we require data to be stored in a specific country or datacenter?
Yes, that is something we can discuss. We are expanding data residency options, from consolidated EU hosting today toward single-datacenter deployments in any EU/EEA country for customers with those requirements. Get in touch and we will walk you through what is possible for your organization.
How do I exercise my data subject rights?
Email info@ampliflow.com with your request. We respond within one month, as required by GDPR.
What happens to my data when I cancel?
Full data export is available for a small fee so you can retrieve your information. After export, customer data is deleted from our systems. Timelines and format are covered in the Terms of Service.
Is a DPA included?
Yes. AmpliFlow provides a Data Processing Agreement on request. It defines responsibilities, data categories, security measures, and breach notification procedures. Email security@ampliflow.com to request one.
Do you transfer data outside the EU?
AmpliFlow core service data is stored within the EU/EEA. AI features are entirely opt-in and are enabled inside the application. Berget AI is documented by its DPA as EEA data-centre processing. OpenAI should be chosen only when your organization accepts the applicable OpenAI transfer, residency, retention, and subprocessor terms.
Does the website collect data?
This website (ampliflow.se / ampliflow.com) uses Rybbit, a self-hosted, open-source analytics platform running on our own servers. It collects anonymous visitor statistics without cookies and without personal data: page views, navigation, outbound link clicks, campaign parameters, and JavaScript errors. No analytics data leaves our servers.
Questions About Data Protection?
If you have questions about how AmpliFlow handles personal data, need a DPA, or want to exercise your data subject rights, contact us.
Email: info@ampliflow.com