privacy notice
how amber systems ltd uses personal information when acting as a controller.
amber.systems privacy notice
Last updated: 18 August 2026
This privacy notice explains how amber systems ltd, trading as amber.systems, collects and uses personal information when it acts as a controller.
1. Who we are
amber systems ltd, trading as amber.systems, is a company registered in England and Wales under company number 17349587.
- Website: https://amber.systems
- Registered office: Unit A, 82 James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, United Kingdom
- Data protection contact: privacy@amber.systems
- Telephone: 01223 230001
In this notice, “amber.systems”, “we”, “us” and “our” mean amber systems ltd.
At a glance
- We use personal information to respond to enquiries, provide and secure services, operate accounts, bill clients, meet legal obligations and handle support, complaints and claims.
- We collect only information relevant to those purposes and apply a documented retention schedule.
- We use infrastructure, communications, payment, accounting and AI providers. Not every provider receives information about every client or user.
- Customer content sent to approved AI services is subject to zero-data-retention controls and is not used for provider model training, subject to narrow legal and safety exceptions described below.
- Privacy enquiries and rights requests can be sent to privacy@amber.systems. Data protection complaints can be sent to complaints@amber.systems.
When we act as a processor
For some hosting, infrastructure, security, engineering and support work, we process information solely on a client’s documented instructions. In those circumstances, the client is normally the controller and we act as its processor. That processing is governed by our contract and data processing terms with the client, and the client’s privacy notice is the primary notice for the people concerned.
This notice applies to personal information for which we decide the purposes and means of processing, including information about website visitors, prospective and current clients, client representatives and authorised users, suppliers, and people who contact us or make a complaint.
2. Personal information we collect
Depending on your relationship with us, we may collect or use:
- Identity, business and contact information - such as your name, organisation, role, email address, telephone number and billing or service address.
- Account and service information - such as registration details, authorised users, permissions, account identifiers, services ordered, service history, configuration and support information.
- Billing and transaction information - such as invoices, payment status, transaction identifiers, refunds and accounting records. Payment card details are normally collected directly by Stripe. We do not ordinarily receive full card numbers or card security codes.
- Technical, usage and security information - such as IP addresses, timestamps, user agents, browser and operating system information, device and network identifiers, authentication events, access and request logs, audit records, security alerts and information about how our websites, accounts and services are used.
- Communications and case information - such as enquiries, proposals, emails, support tickets, meeting records, complaints, dispute records, and call recordings where recording is enabled and you have been informed.
- Legal and compliance information - such as information needed for accounting, tax, regulatory enquiries, lawful requests, fraud or abuse investigations, and the establishment, exercise or defence of legal claims.
We do not intentionally ask for special category information or criminal offence information as part of ordinary account or service administration. You may nevertheless include such information in a communication, or we may encounter it while working on systems controlled by a client. We minimise access to that information and process it only where necessary and lawful. Where we handle it solely on a client’s instructions, we do so as the client’s processor.
3. Why we use personal information and our lawful bases
| Purpose | Personal information typically used | Lawful basis |
|---|---|---|
| Responding to enquiries, preparing proposals and taking steps requested before a contract | Identity, business and contact information; correspondence; service requirements | Contract, where you ask us to take steps before entering a contract with you; legitimate interests, where you act for an organisation or the processing is otherwise reasonably necessary to respond and manage prospective business relationships |
| Providing, maintaining and improving products and services | Identity and contact information; account and service information; transaction, usage, technical and security information; communications | Contract, where necessary to perform a contract with you; legitimate interests in delivering reliable services, communicating with client representatives, maintaining quality, diagnosing faults and making proportionate improvements |
| Creating and operating client or customer accounts | Identity and contact information; account details; permissions; service history; authentication, technical and security information | Contract, where necessary to perform a contract with you; legitimate interests in administering organisational accounts, enabling authorised access and protecting accounts and services |
| Billing, accounting, tax and business administration | Identity and contact information; billing addresses; invoices; transaction and payment information; contracts | Contract and legal obligation |
| Preventing misuse and protecting our services, clients and systems | Account, authentication, network, technical, usage, audit and security information | Legitimate interests in securing systems, detecting unauthorised access, preventing abuse, investigating incidents and maintaining service integrity; legal obligation where a specific law requires processing |
| Responding to queries, support requests, complaints, disputes and claims | Contact details; correspondence; account, service and transaction records; call recordings where applicable; relevant technical and security records | Contract, legal obligation, and legitimate interests in investigating matters fairly, resolving them, and establishing, exercising or defending legal claims |
| Complying with laws, court orders and lawful requests | Any relevant information within the scope of the obligation or request | Legal obligation |
Where information is necessary to enter into or perform a contract, failing to provide it may mean that we cannot open an account, provide a quotation, enter into the contract, or deliver the relevant service.
We do not rely on consent where the processing is necessary for a contract, legal obligation or legitimate interest. Where we specifically ask for consent for an optional activity, you may withdraw it at any time without affecting processing that took place before withdrawal.
4. Our legitimate interests
We rely on legitimate interests only where the processing is necessary and proportionate and those interests are not overridden by your rights and interests.
Delivering, securing and improving services
We have a legitimate interest in delivering, maintaining, securing and improving our products and services, and in communicating with people who act on behalf of clients. This is particularly relevant where our contract is with an organisation but we need to process information about its employees, contractors or authorised users.
The processing enables us to provide reliable services, resolve faults, prevent misuse, understand service operation and make appropriate improvements. We limit the information used, restrict access, apply security controls and avoid using it in ways that people would not reasonably expect. We consider the benefits to clients, users and service security to outweigh the limited impact of this proportionate processing.
Operating accounts and access controls
We have a legitimate interest in administering organisational accounts, maintaining account and service records, communicating with authorised users, managing permissions and authentication, and investigating suspicious or unauthorised activity.
These purposes cannot reasonably be achieved without processing limited information about the people authorised to use or administer an account. The processing benefits both clients and users by protecting accounts and maintaining reliable services. We minimise the information involved, use access and security controls, and do not use it for unrelated purposes.
Queries, complaints, disputes and claims
We have a legitimate interest in responding to enquiries, resolving complaints and disputes, investigating service issues, and establishing, exercising or defending legal claims.
We use only information relevant to the particular matter, restrict access where appropriate and retain records only for a justified period. This allows issues to be considered accurately and fairly while limiting the potential impact on the people involved.
Your right to object to legitimate-interests processing
You have the right to object to our processing of your personal information where we rely on legitimate interests. We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for the establishment, exercise or defence of legal claims. See section 13.
5. Where we obtain personal information
We obtain personal information:
- directly from you, including through our websites, account interfaces, email, telephone, meetings and support channels;
- from clients and prospective clients, including information about their employees, contractors, authorised users and other contacts;
- from suppliers, subcontractors, payment providers and other service providers involved in providing or administering services;
- from other people involved in an enquiry, complaint, dispute, incident or claim; and
- automatically from websites, systems and services when you access or use them, including through logs, authentication systems and security tooling.
6. How long we keep personal information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. We apply the following standard schedule unless a contract, documented client instruction, legal hold or specific legal obligation requires a different period.
| Category | Standard retention period |
|---|---|
| Unsuccessful enquiries, proposals and prospective-client correspondence | 24 months after the last substantive contact |
| Client contact, account, contract, order, statement of work and service records | For the relationship and 6 years after termination or completion |
| Authentication secrets, active sessions and access tokens | For as long as required for the account or session, then revoked or deleted promptly after closure; residual backup copies expire with the backup cycle |
| Invoices, accounting records and payment transaction records | 6 years from the end of the financial year to which the record relates, or longer where law requires it |
| Routine support tickets and service correspondence | 3 years after closure, or 6 years where the record is material to a contract, complaint, dispute or claim |
| Complaints, disputes, incident investigations and legal claims | 6 years after final closure, or longer while a legal hold, investigation or proceeding remains active |
| Signed security-testing authorisations, scope records and final engagement records | 6 years after completion or termination of the engagement |
| Client-supplied working data, temporary test evidence, scans, exports and other project working copies | Deleted or returned within 30 days after final delivery or engagement closure, unless the statement of work requires an earlier or later period or retention is necessary for an unresolved incident or claim |
| Routine website, CDN, network and request logs | Normally 90 days |
| Authentication, audit and security logs | Normally 12 months; records linked to a confirmed incident may be retained with the incident record |
| Call recordings, where enabled | Normally 90 days; longer only where needed for an active complaint, dispute, legal obligation or claim |
| Call and message metadata held by us | Normally 12 months, subject to longer periods imposed on telecommunications providers acting for their own legal and regulatory purposes |
| Data protection rights-request records | 3 years after the request is completed |
| Backups | Rolling cycles normally lasting 30 to 90 days. Deleted information may remain in encrypted backups until the relevant backup expires, and is not restored except for disaster recovery or continuity purposes |
| Customer content submitted to approved AI services | Not routinely retained by the AI provider after processing under our applicable zero-data-retention arrangements or equivalent controls, and not used for provider model training. Narrow retention may still occur where required by law or under specifically applicable safety and abuse-prevention terms. Limited account, billing, security and request metadata may be retained separately. If we deliberately save an input or output in our own project or case records, the relevant category above applies |
We may retain a minimal record for longer where necessary to document deletion, honour an objection or suppression request, demonstrate compliance, prevent repeated abuse, or establish, exercise or defend legal claims. When a retention period ends, we delete, anonymise or securely dispose of the information.
7. Who we share personal information with
We disclose personal information only where necessary for the purposes described in this notice. This may include providers of infrastructure, hosting, networking, storage, payments, accounting, email, communications and artificial-intelligence services.
Our current provider names, their purposes, potential processing locations and relevant data-handling notes are maintained in our subprocessor list. Not every listed provider is used for every person, client, service or item of personal information.
When we act as controller, a listed provider may act as our processor. When we act as a processor for a client, it may instead act as our subprocessor. Some providers also act as independent controllers for limited purposes of their own, such as billing, fraud prevention, regulatory compliance, telecommunications records or service security. Their own privacy notices apply to that independent processing.
We may also disclose relevant information to:
- professional advisers, including lawyers, accountants and security or technical consultants;
- regulators, courts, law-enforcement bodies and public authorities where disclosure is lawful and necessary;
- organisations to which we are legally required to disclose information;
- suppliers, subcontractors or other service providers acting as independent controllers; and
- a purchaser, investor or successor in connection with a proposed or completed sale, restructuring or transfer of all or part of our business, subject to appropriate confidentiality and data protection controls.
We do not sell personal information.
8. Artificial-intelligence processing
We may use artificial-intelligence services to assist with software engineering, security analysis, infrastructure work, document processing and other professional services.
Where customer content may contain personal information, we use approved business or API services subject to contractual data protection terms and zero-data-retention arrangements or equivalent enforced controls. We minimise content before submission, restrict access and configure model routing so that customer content is not routinely retained after processing or used to train provider models.
Zero data retention applies to customer content processed through the approved service, not necessarily to separate account, billing, security, abuse-prevention or request metadata. Narrow retention may also occur where a provider is legally required to preserve information or where specifically applicable safety terms permit limited processing. We do not treat AI output as inherently accurate and apply human review appropriate to the context and risk.
9. Automated decision-making
We do not currently use personal information to make decisions about people based solely on automated processing, including profiling, that produce legal effects or similarly significant effects. AI systems may assist our work, but decisions that materially affect a person are subject to appropriate human review.
10. International transfers
Some providers and their subprocessors operate outside the United Kingdom. Personal information may therefore be stored in, accessed from or transmitted through the European Economic Area, the United States and other countries in which a provider or its approved subprocessor operates. Network, CDN, email and telecommunications services may also route information through locations selected dynamically for resilience, performance or security.
Where practical, we select UK or EEA service regions and apply provider region and routing controls. Where a restricted transfer is made, we rely on one or more of:
- UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the US recipient is eligible and certified;
- the UK International Data Transfer Agreement;
- the UK Addendum to the European Commission’s Standard Contractual Clauses;
- approved binding corporate rules; or
- another safeguard permitted by UK data protection law.
Where required, we assess whether the safeguards provide protection that is not materially lower than the protection available under UK law and apply supplementary measures. We do not rely on an exception under Article 49 UK GDPR for routine or systematic transfers.
You may request further information about the applicable transfer safeguard by emailing privacy@amber.systems. Commercially sensitive terms and information affecting the rights of others may be redacted from any copy provided.
11. Security
We use technical and organisational measures appropriate to the nature and risk of the processing. Depending on the service, these may include access controls, least-privilege permissions, multi-factor authentication, encryption in transit and at rest, network segmentation, security logging, vulnerability management, encrypted backups, data minimisation, retention controls, processor agreements and incident-response procedures.
No system can be guaranteed completely secure. Please contact privacy@amber.systems promptly if you believe information or an account has been compromised.
12. Cookies and similar technologies
Our websites and account interfaces may use cookies, local storage or similar technologies that are necessary for authentication, session management, security, fraud prevention, service operation and user preferences.
Where we use non-essential technologies, we will explain their purpose at the point of use and obtain consent where required. Browser or device controls can also be used to manage stored information, although blocking necessary storage may prevent parts of a service from working.
13. Your data protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- access your personal information and receive related information about our processing;
- rectify inaccurate information and complete incomplete information;
- erase personal information in certain circumstances;
- restrict how we use personal information in certain circumstances;
- object to processing based on legitimate interests;
- receive or transfer information you provided to us in a structured, commonly used and machine-readable format where the right to data portability applies; and
- withdraw consent at any time where we rely on consent, without affecting the lawfulness of earlier processing.
These rights are not absolute and exemptions may apply. In particular, if you object to processing based on legitimate interests, we may continue where we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing is needed for legal claims.
To exercise a right, contact privacy@amber.systems. We may ask for information reasonably necessary to verify your identity or authority to act for another person. The response period begins once we have information reasonably required for that verification. We normally respond without undue delay and within one calendar month. Where permitted because a request is complex or you have made several requests, we may extend the period by up to two further months and will explain this within the first month.
14. Data protection complaints
You can make a data protection complaint to us using any of these channels:
- Email: complaints@amber.systems
- Telephone: 01223 230001
Our complaints procedure is available at https://amber.systems/legal/data-protection-complaints.
We will acknowledge a data protection complaint within 30 days, take appropriate steps to investigate it, keep you informed as appropriate, and communicate the outcome without undue delay.
If you remain dissatisfied after raising the matter with us, you can complain to the Information Commissioner’s Office:
- Website: https://ico.org.uk/make-a-complaint/
- Telephone: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
15. Changes to this notice
We may update this notice to reflect changes to our services, providers, processing or legal obligations. The date at the top shows when it was last updated. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected people.