data processing agreement
terms applying when amber.systems processes personal data on a customer's behalf.
amber.systems data processing agreement
Version 2026-08-18 - last updated 18 August 2026
1. Scope and incorporation
1.1 This Data Processing Agreement (DPA) forms part of each Contract that incorporates it between:
- the Customer identified in the applicable Order Form; and
- amber systems ltd, trading as amber.systems, registered in England and Wales under company number 17349587, with registered office at Unit A, 82 James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, United Kingdom.
1.2 This DPA applies to the extent amber.systems processes Customer Personal Data as a processor on behalf of the Customer or as a subprocessor where the Customer acts as processor for another controller.
1.3 It does not apply to personal data for which amber.systems independently determines the purposes and means, including account, contact, billing, fraud-prevention, service-security and legal-compliance data described in our privacy notice.
1.4 If this DPA conflicts with another Contract document on a matter specifically concerning processing of Customer Personal Data, this DPA prevails. The General Terms govern all other matters, including Fees and liability.
2. Definitions
In this DPA:
- Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, Data (Use and Access) Act 2025, and any other data-protection or privacy law expressly identified in the Order Form, in each case as amended and applicable to the processing.
- Controller, Data Subject, Personal Data, Personal Data Breach, processing and Processor have the meanings in Applicable Data Protection Law.
- Customer Personal Data means Personal Data processed by amber.systems on behalf of the Customer under the Contract.
- Restricted Transfer means a transfer of Personal Data subject to transfer restrictions under Applicable Data Protection Law.
- Subprocessor means another processor engaged by amber.systems to process Customer Personal Data.
- UK GDPR means the retained UK version of Regulation (EU) 2016/679 as amended in UK law.
3. Roles and compliance
3.1 For Customer Personal Data:
- the Customer is Controller and amber.systems is Processor; or
- where the Customer acts as Processor for another Controller, the Customer is Processor and amber.systems is Subprocessor.
3.2 The Customer determines the purposes and essential means of processing, the Customer Personal Data submitted, the Data Subjects concerned, the Service configuration and the lawfulness of its instructions.
3.3 Each party must comply with the obligations directly applicable to it under Applicable Data Protection Law.
3.4 The Customer warrants that:
- it has a lawful basis, required notices and authority for the processing and instructions;
- its instructions do not breach Applicable Data Protection Law or another person’s rights;
- it will not submit Personal Data that the Service is not designed or contractually approved to process; and
- where it acts as Processor, its Controller has authorised the appointment of amber.systems and the Subprocessors used for the Service.
3.5 amber.systems does not determine whether the Customer’s particular processing complies with sector-specific law, professional rules or foreign law unless the Order Form expressly includes that assessment.
4. Processing details
4.1 The subject matter, duration, nature and purpose of the processing, categories of Data Subject and types of Personal Data are described in:
- the Order Form and SOW;
- the applicable Service Schedule and documentation; and
- Annex 1 to this DPA.
4.2 If an Order Form contains more specific processing details, those details supplement or replace the corresponding general description in Annex 1.
4.3 The Customer’s rights and obligations as Controller are those provided by Applicable Data Protection Law and the Contract, including the right to give lawful documented instructions, receive assistance, obtain compliance information and require deletion or return at the end of processing.
5. Documented instructions
5.1 amber.systems will process Customer Personal Data only:
- on the Customer’s documented instructions;
- as reasonably necessary to provide, secure, support and administer the Services;
- as initiated by Authorised Users through normal Service functionality; or
- where required by law.
5.2 Documented instructions include the Contract, selected configuration, deployment region, console actions, support requests and other written instructions consistent with the Contract.
5.3 If law requires processing outside the Customer’s instructions, amber.systems will inform the Customer before processing unless the law prohibits notice.
5.4 amber.systems will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. amber.systems may pause the affected processing until the parties resolve the concern.
5.5 Instructions that materially change scope, risk, cost or technical requirements may require a Change Request and additional Fees.
6. Confidentiality and personnel
6.1 amber.systems will ensure that people authorised to process Customer Personal Data:
- are subject to an appropriate contractual or statutory duty of confidentiality;
- receive access only where needed for their role; and
- receive appropriate data-protection and security guidance.
6.2 Access is removed or adjusted when no longer needed.
7. Security
7.1 Taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing, and risks to people, amber.systems will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
7.2 The baseline measures are described in Annex 2. Measures may vary by Service, risk and selected configuration. The Order Form may add specific controls.
7.3 The Customer acknowledges that security is a shared responsibility. The Customer must configure the Service appropriately, manage its users and credentials, classify data, apply its own endpoint and application controls, and follow documented security guidance.
7.4 amber.systems may change a security measure where the replacement provides materially equivalent or better protection, or where needed to address a threat, law or technical change.
8. Personal Data Breaches
8.1 amber.systems will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notice will include information reasonably available to amber.systems about:
- the nature of the breach;
- affected categories of Data Subject and Personal Data;
- likely consequences;
- measures taken or proposed; and
- a contact for follow-up.
8.3 Information may be provided in phases as the investigation progresses. A notification is not an admission of fault or liability.
8.4 amber.systems will take reasonable steps to contain, investigate and mitigate the breach and will preserve relevant evidence.
8.5 The Customer is responsible for determining whether and when to notify a Controller, regulator or Data Subject, except for notifications that law directly requires amber.systems to make.
9. Data Subject requests
9.1 Taking into account the nature of processing, amber.systems will provide appropriate technical and organisational assistance, insofar as reasonably possible, to help the Customer respond to requests to exercise Data Subject rights.
9.2 If amber.systems receives a request relating to Customer Personal Data, it will, unless prohibited by law:
- direct the requester to the Customer; or
- forward the request to the Customer without responding substantively.
9.3 amber.systems will not disclose Customer Personal Data to a requester except on the Customer’s documented instruction or where required by law.
9.4 Assistance beyond standard Service functionality may be chargeable at the agreed professional-services rate where the request is unusually complex, repetitive or caused by the Customer’s configuration, except to the extent charging would be unlawful.
10. Compliance assistance
10.1 Taking into account the nature of processing and information available, amber.systems will reasonably assist the Customer with obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- data protection impact assessments;
- prior consultation with a regulator; and
- records and information reasonably necessary to demonstrate compliance.
10.2 The Customer remains responsible for its own legal decisions, risk assessment, notices and regulatory submissions.
10.3 Non-routine assistance may be chargeable where the need was not caused by amber.systems’ breach, subject to advance notice of Fees where practicable.
11. Subprocessors
11.1 The Customer gives general written authorisation for amber.systems to use the Subprocessors listed at https://amber.systems/legal/subprocessors, but only to the extent relevant to the selected Services.
11.2 amber.systems will:
- carry out reasonable due diligence before appointing a Subprocessor;
- enter into a written agreement imposing data-protection obligations that provide an equivalent level of protection for Customer Personal Data as required by Article 28 UK GDPR;
- remain responsible to the Customer for the Subprocessor’s performance of those obligations; and
- make the current list available online.
11.3 amber.systems will give at least 14 days’ prior notice of a new or replacement Subprocessor where reasonably practicable. Shorter notice may be given where necessary to address an urgent security, legal, availability or provider-continuity issue.
11.4 The Customer may object during the notice period on reasonable and documented data-protection grounds specific to its Customer Personal Data. The parties will work in good faith to resolve the objection, including through a reasonable configuration change or alternative where available.
11.5 If no reasonable resolution is available, either party may terminate the affected Service on written notice before the new Subprocessor begins processing. The Customer’s remedy is limited to termination of the affected Service and refund of prepaid Fees for its unused period, excluding non-cancellable committed costs, unless amber.systems is otherwise in breach.
11.6 An objection based solely on commercial preference, general opposition to a provider, or a requirement not documented before contracting is not a reasonable data-protection ground.
12. International transfers
12.1 amber.systems will make a Restricted Transfer only on the Customer’s documented instructions, including instructions inherent in the selected Service, region, Subprocessor and configuration, and only where a lawful transfer mechanism applies.
12.2 Depending on the transfer, amber.systems may rely on:
- UK adequacy regulations, including an applicable UK data bridge;
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to the European Commission Standard Contractual Clauses (UK Addendum);
- approved binding corporate rules; or
- another safeguard permitted by Applicable Data Protection Law.
12.3 Where an appropriate safeguard requires a data protection test or transfer risk assessment, the responsible exporter will complete it and apply reasonable supplementary measures where required.
12.4 If a transfer from the EEA to the United Kingdom ceases to be covered by adequacy, the parties will cooperate to put an appropriate transfer mechanism in place. Where appropriate, this may include the European Commission Standard Contractual Clauses using the module matching the parties’ roles.
12.5 The Customer authorises amber.systems to enter into transfer clauses with Subprocessors on the Customer’s behalf where this is necessary to provide the Service and lawful under the applicable mechanism.
12.6 amber.systems will provide reasonable information about applicable safeguards on request, subject to redaction of other customers’ information, security-sensitive material and protected commercial terms.
13. Government and legal requests
13.1 Where amber.systems receives a binding request for Customer Personal Data from a public authority, it will, to the extent lawful and reasonably practicable:
- review whether the request is valid and within the authority’s powers;
- seek clarification or narrow an overbroad request;
- challenge the request where there are reasonable grounds and proportionate means;
- notify the Customer before disclosure; and
- disclose only what is legally required.
13.2 If notice is prohibited, amber.systems will use reasonable efforts to obtain permission to notify the Customer and will provide general transparency information where lawful.
14. Artificial-intelligence processing
14.1 Where a Service routes Customer Personal Data to a third-party artificial-intelligence provider, amber.systems will use approved business or API services subject to appropriate contractual data-protection terms.
14.2 Unless the Order Form expressly permits otherwise:
- Customer Content will be routed only through approved zero-data-retention or equivalent no-content-retention configurations;
- Customer Content will not be used to train a general-purpose provider model;
- provider routing will be restricted to approved endpoints and subprocessors; and
- amber.systems will avoid application logging that persistently records prompts, files or outputs unless the Service requires and documents that retention.
14.3 Zero-data-retention controls apply to Customer Content, not necessarily to separate account, billing, security, abuse-prevention, token-count, latency or request metadata. Narrow retention may occur where required by law or an expressly applicable safety term.
14.4 The Order Form may prohibit AI processing entirely or specify permitted providers, regions, data classes and use cases.
15. Audits and compliance information
15.1 amber.systems will make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and this DPA.
15.2 The Customer should first use available documentation, independent reports, certifications, questionnaires and remote meetings.
15.3 If that information is insufficient to address a material and documented concern, the Customer may conduct or appoint an independent auditor to conduct an audit, subject to:
- at least 30 days’ notice, unless a regulator or confirmed breach requires shorter notice;
- no more than one audit in any 12-month period, unless required by law or following a material breach;
- reasonable scope, duration, confidentiality and security controls;
- no access to another customer’s data, privileged material, source code unrelated to the Service, or information that would materially weaken security;
- coordination to minimise disruption; and
- the Customer paying reasonable costs, unless the audit identifies a material breach by amber.systems.
15.4 amber.systems will promptly address a material non-compliance identified by a valid audit.
16. Return and deletion
16.1 During the Term, the Customer may export Customer Personal Data using standard Service functionality or a method stated in the Order Form.
16.2 On termination, and at the Customer’s choice communicated within 30 days, amber.systems will return or delete Customer Personal Data, except where law requires retention.
16.3 Unless the Order Form says otherwise:
- Customer Personal Data may remain available for standard export for up to 30 days after termination;
- it will be deleted or anonymised from active systems within 90 days after the export period or instruction to delete; and
- residual encrypted backup copies will be placed beyond routine use and deleted through the ordinary backup cycle.
16.4 Immediate deletion from every backup is not required where it is technically impracticable, provided the data remains protected, is not restored except for disaster recovery, and is deleted on the next applicable cycle.
16.5 amber.systems may retain a minimal record required for law, accounting, security, suppression, dispute resolution or legal claims. Retained data will remain protected and used only for that purpose.
17. Liability
17.1 Liability under this DPA is subject to the exclusions and caps in the General Terms, including the enhanced cap for data-protection and expressly agreed security obligations.
17.2 Nothing limits a Data Subject’s rights or a regulator’s powers under Applicable Data Protection Law, or limits liability that cannot lawfully be limited.
17.3 A party is not liable under this DPA to the extent loss was caused by the other party’s unlawful instruction, breach, configuration or failure to meet its own Controller or Processor obligations.
18. Term and termination
18.1 This DPA begins when incorporated into a Contract and continues while amber.systems processes Customer Personal Data.
18.2 Termination of the Contract does not end provisions that must continue to protect Customer Personal Data, including confidentiality, deletion, audit, transfer and liability provisions.
19. Law and jurisdiction
19.1 This DPA is governed by the law governing the General Terms.
19.2 If no law is specified elsewhere, it is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, subject to mandatory rights of a regulator or Data Subject.
Annex 1 - Processing details
The Order Form may provide more specific details.
Subject matter
Processing of Customer Personal Data to provide hosting, managed infrastructure, storage, backup, networking, SaaS, API, software, support, professional, security-testing and related services selected by the Customer.
Duration
For the Term and the return, export, backup and deletion periods described in the Contract, unless law requires longer retention.
Nature and purpose
As required for the selected Service, processing may include receiving, collecting, recording, organising, structuring, hosting, storing, retrieving, consulting, analysing, transmitting, routing, securing, monitoring, backing up, restoring, modifying on instruction, exporting, deleting and anonymising data.
Purposes include providing and supporting the Service; authentication and authorisation; hosting and transmission; monitoring, reliability and security; troubleshooting; backup and recovery where purchased; professional and security work; and complying with documented instructions.
Categories of Data Subject
Depending on Customer use:
- Customer personnel, contractors and Authorised Users;
- the Customer’s clients, customers, users and website visitors;
- suppliers, advisers and business contacts;
- people communicating through Customer systems;
- research participants, students or service recipients where authorised; and
- any other person whose Personal Data the Customer lawfully submits.
Types of Personal Data
Depending on Customer use:
- names, business roles and contact details;
- account, identity, authentication, permission and profile data;
- IP addresses, device, browser, network and telemetry data;
- access, application, audit and security logs;
- communications, files, documents, source code and database content;
- transaction, subscription and service-use data;
- support, incident and vulnerability information;
- audio, messaging or communications content where the Service includes it; and
- other Personal Data chosen by the Customer within the approved Service scope.
Special-category and criminal-offence data
Not intentionally required by default. It may be processed only where the Customer is lawfully authorised, the Service and Order Form permit it, and safeguards appropriate to the risk are documented.
Frequency
Continuous, periodic or ad hoc, depending on Customer use and the selected Service.
Customer obligations and rights
The Customer retains the Controller’s rights and obligations under Applicable Data Protection Law, including determining purposes, lawful basis, transparency, data minimisation, retention, rights responses, risk assessment and instructions.
Annex 2 - Baseline technical and organisational measures
Measures are applied proportionately to the selected Service and risk. Not every measure is technically relevant to every Service.
Governance and confidentiality
- documented security and data-protection responsibilities;
- confidentiality obligations for authorised personnel;
- proportionate training and awareness;
- risk assessment, incident handling and change control; and
- review of processors and subprocessors.
Identity and access management
- unique accounts where practicable;
- least-privilege and role-based access;
- multi-factor authentication for privileged or sensitive access where supported;
- secure credential handling, rotation and revocation;
- periodic access review; and
- separation of customer environments using logical, account, tenant, network or infrastructure controls appropriate to the Service.
Cryptography and transmission
- encryption in transit using current supported protocols where technically applicable;
- encryption at rest where provided by the selected platform or required by the Order Form;
- managed handling of keys and secrets; and
- avoidance of sensitive information in insecure channels.
Infrastructure and application security
- secure configuration and hardening appropriate to the platform;
- vulnerability monitoring, patching and remediation based on risk;
- dependency and software-update management;
- network filtering, segmentation and exposure minimisation where applicable;
- secure development and review practices for software we develop or operate; and
- protection against common application and infrastructure threats.
Logging and monitoring
- authentication, administrative, audit and security logging where appropriate;
- monitoring and alerting proportionate to the Service;
- time synchronisation and access restriction for relevant logs;
- retention controls; and
- protection of logs against unauthorised modification where practicable.
Availability, backup and recovery
Where included in the Service:
- resilience and redundancy appropriate to the architecture;
- encrypted or access-controlled backups;
- documented retention cycles;
- restoration procedures and testing proportionate to the Service; and
- incident and continuity processes.
Backup, recovery-point and recovery-time commitments apply only where expressly stated in the Order Form.
Data minimisation and lifecycle
- collection and access limited to what is needed;
- region and routing controls where available and selected;
- retention and deletion processes;
- secure disposal or cryptographic erasure where appropriate; and
- Customer export and deletion mechanisms.
AI processing
Where third-party AI is used for Customer Content:
- approved business/API accounts;
- zero-data-retention or equivalent no-content-retention routing by default;
- provider-training disabled for Customer Content;
- provider and endpoint allow-listing where technically available;
- minimisation and redaction where appropriate; and
- human review proportionate to the use and risk.
Incident response
- channels for security reports and escalation;
- containment, investigation, remediation and evidence preservation;
- Customer notification under section 8; and
- post-incident review where proportionate.
Annex 3 - Authorised Subprocessors
The authorised list is published at https://amber.systems/legal/subprocessors and is incorporated into this DPA.
Annex 4 - Data-protection contact
- Email: privacy@amber.systems
- Telephone: 01223 230001