AMPLIFY LABS, INC.
Privacy Policy
Scope and Applicability
- This Privacy Policy applies to information processed in connection with Amplify’s Platform and Services, including websites, web applications, hosted software, cloud faxing, communications services, secure chat, calling, video collaboration, document routing, electronic signature workflows, fillable forms, OCR and extraction tools, AI-assisted workflows, workflow automations, secure storage, APIs, webhooks, integrations, customer support interactions, and related hosted functionality.
This Privacy Policy applies to website visitors, customers, business users, authorized users, enterprise users, prospective customers, support contacts, and platform administrators.
This Privacy Policy does not override separate contractual privacy, data protection, or healthcare-specific obligations expressly agreed in writing, including Business Associate Agreements (“BAAs”), Data Processing Agreements (“DPAs”), or other Supplemental Terms. Where those agreements exist, they govern in their respective areas of applicability.This Privacy Policy applies to website visitors, customers, business users, authorized users, enterprise users, prospective customers, support contacts, and platform administrators.
Information We Collect
We may collect information directly from you, automatically through your use of the Platform, from authorized users, from integrations, or from service providers acting on our behalf. The categories below describe what we may collect depending on how you use the Services.
Account and Registration Information
When you create an account or register for the Services, we may collect your name, email address, phone number, organization name, billing details, user credentials, account settings, authentication data, and administrator details.
Customer Data
We may process information submitted to, transmitted through, stored within, routed through, or otherwise made available through the Platform (“Customer Data”). Customer Data may include uploaded documents, faxed materials, text records, communications, forms, attachments, shared files, routing instructions, signature-related content, workflow data, metadata, and user-generated content. Customer Data may include personal information depending on how Customers use the Services.
Communications Information
Depending on the Services used, we may process sender and recipient details, phone numbers, communication routing data, fax metadata, timestamps, call-related records, messaging-related records, chat-related content, file-sharing activity, video participation information, and communication logs.
Payment and Commercial Information
Where applicable, we may collect billing records, subscription data, invoices, payment confirmations, purchase history, and commercial account information. Payment processing is typically handled by third-party payment providers, and we do not store full payment card data on our systems.
Technical and Usage Information
We may automatically collect IP addresses, browser type, operating system, device identifiers, approximate location, access and usage logs, crash reports, diagnostics, session activity, feature interaction data, security event logs, authentication history, network data, and telemetry.
Support and Inquiry Information
We may collect information submitted through support requests, emails, chat interactions, account inquiries, feedback submissions, technical troubleshooting sessions, and legal or compliance communications.
Information from Integrations and Third Parties
We may receive information from APIs, webhooks, identity providers, integrations, telecom providers, cloud providers, storage providers, CRM tools, EHR and EMR systems, and external software platforms — only as necessary to provide or support the Services.
How We Use Information
We use information we collect for the following purposes:
Delivering the Services
To create accounts, authenticate users, provide Platform functionality, transmit communications, route documents, support workflows, store records, process signatures, and support integrations.
Maintaining and Improving the Services
To diagnose issues, improve reliability and performance, enhance workflows, optimize routing, and improve AI features and service functionality (subject to the restrictions on AI and automated processing described in Section 6).
Security and Abuse Prevention
To detect fraud, prevent abuse, investigate misuse, detect malicious activity, preserve system integrity, monitor for unauthorized access, and enforce our contractual rights.
Customer Support and Business Operations
To respond to inquiries, provide technical support, manage subscriptions, communicate operational updates, administer accounts, and provide required notices.
Legal and Regulatory Compliance
To comply with applicable law, respond to legal requests, enforce our agreements, protect our rights, address disputes, and manage security incidents.
Analytics and Operational Insights
To create service analytics, usage trends, reliability metrics, de-identified operational reports, and performance insights. Where feasible, we use aggregated or de-identified information for these purposes.
Legal Bases for Processing
Where required under applicable law — including the EU General Data Protection Regulation (“GDPR”), UK GDPR, or similar privacy laws — we process personal information on one or more of the following legal bases: performance of a contract with you or your organization; our legitimate interests (including maintaining service integrity, fraud prevention, service optimization, customer support, operational analytics, and platform security); compliance with a legal obligation; or your consent, where we have obtained it.
Where we rely on legitimate interests, we balance those interests against your rights and interests and do not process information in ways that would override your fundamental privacy rights.
Our Role: Controller and Processor
When Amplify Acts as a Controller
Amplify acts as a data controller for information we process for our own purposes, including account administration, billing, website analytics, security monitoring, fraud prevention, service improvement, support operations, legal compliance, and direct communications with customers and users.
When Amplify Acts as a Processor or Service Provider
Amplify acts as a data processor, service provider, or equivalent role when processing Customer Data on behalf of Customers pursuant to their instructions. This includes communications processing, document workflows, hosted storage, routing, faxing, messaging, forms, integrations, automation workflows, and hosted records. In these cases, Customers remain responsible for the lawfulness of their instructions and for obtaining any required permissions from the individuals whose data they submit.
Healthcare and PHI
Where PHI or regulated healthcare data is involved, separate BAAs or healthcare-specific agreements govern applicable obligations. This Privacy Policy does not independently expand PHI-specific obligations beyond what is contained in executed agreements.
AI Features, OCR, and Automation
Certain Services include OCR, AI-assisted workflows, extraction tools, automation tools, classification tools, including natural language processing (NLP)-based data classification and extraction, summarization tools, analytics, and related machine-assisted functionality (“AI Features”). We may process information through AI Features to extract text, classify content, route workflows, summarize content, automate tasks, improve reliability, detect abuse, and improve service functionality.
We may retain Service Data, diagnostics, telemetry, and de-identified or aggregated operational insights derived from use of AI Features. We do not sell Customer Data by virtue of processing it through AI Features. Customers remain responsible for reviewing, validating, and making downstream decisions based on AI-assisted outputs.
For customers operating under a BAA, PHI processed through AI Features remains subject to the restrictions and protections of that BAA and applicable HIPAA obligations.
We do not use Customer Data or PHI to train, fine-tune, validate, or improve any third-party generalized AI or machine learning model, regardless of whether such use is incidental to or combined with any other processing purpose, or disclose Customer Data or PHI to any third-party AI model provider for training or model improvement purposes, in each case unless the applicable Customer provides express prior written authorization signed by an authorized representative of that Customer. To the extent such authorization relates to PHI, the applicable Customer represents and warrants that it has obtained any additional authorization required under HIPAA for such use, including any applicable patient-level authorization under 45 C.F.R. §164.508, and Amplify's acceptance and reliance on that authorization does not constitute Amplify's independent verification of, or substitute for, the Customer's compliance with HIPAA or any other applicable law. Nothing in this Section prohibits Amplify from using data that has been de-identified consistent with 45 C.F.R. §164.514 (or, for non-PHI Customer Data, equivalently de-identified, anonymized, or aggregated data) that does not identify any individual, to improve the reliability, performance, and security of Amplify-controlled systems.
Communications, Calling, Messaging, and Collaboration Data
Certain Services include faxing, calling, secure chat, video collaboration, messaging, file-sharing, routing, and notification functionality (“Communications Services”). In delivering these Services, we may process sender and recipient information, phone numbers, routing details, delivery confirmations, retries, communication metadata, timestamps, message records, call records, chat content, file-sharing records, and workflow routing data.
This information is used to provide communications functionality, route transmissions, troubleshoot failures, detect misuse, improve reliability, maintain integrity, and enforce security. Where Customers use communications recording, outreach, routing, or messaging features, Customers remain responsible for required notices, consents, and lawful use under applicable telecom and privacy law.
Cookies, Analytics, and Tracking Technologies
We may use cookies, pixels, local storage, SDKs, server logs, device identifiers, analytics tools, and similar technologies (“Tracking Technologies”) to maintain sessions, authenticate users, improve usability, understand feature adoption, analyze performance, detect abuse, investigate incidents, support fraud prevention, preserve security, and improve reliability.
Through Tracking Technologies, we may collect IP addresses, browser and device data, session activity, diagnostics, feature usage, authentication events, performance logs, approximate location, and security data.
Users may manage certain tracking preferences through browser settings, device controls, consent banners, or Platform settings where available. Disabling certain technologies may affect the functionality or availability of Services.
How We Share Information
Amplify does not sell Customer Data. We share or disclose information only as reasonably necessary to provide, operate, support, secure, or improve the Services, comply with applicable law, or protect our legitimate business interests.
Service Providers and Subprocessors
We may share information with vendors, subprocessors, contractors, or service providers acting on Amplify’s behalf, including providers supporting cloud hosting, infrastructure, storage, telecom routing, payment processing, analytics, customer support, communications delivery, authentication, fraud prevention, security monitoring, logging, workflow processing, AI or automation support, backup and disaster recovery, and compliance operations. Such providers may process information only as reasonably necessary to perform services for Amplify, subject to contractual, operational, or technical controls appropriate to the Services.
A current list of Amplify's subprocessors is available to customers upon request, and is set forth for contracting customers in Exhibit B to the applicable Master Services Agreement and Data Processing Agreement.
Customer-Directed Integrations
Where Customers enable APIs, integrations, webhooks, routing tools, third-party workflows, or external systems, information may be shared or transmitted based on Customer instructions or Service functionality. Examples include EHR and EMR systems, CRM tools, cloud storage providers, communication providers, identity providers, workflow platforms, and external collaboration tools. Customers remain responsible for lawful use, required permissions, and third-party configuration choices.
Legal and Regulatory Disclosures
We may disclose information where reasonably necessary to comply with applicable law; respond to subpoenas, court orders, or lawful requests; cooperate with regulators or law enforcement; protect rights, safety, or security; investigate fraud, abuse, misuse, or security incidents; enforce our agreements; preserve evidence; or defend legal claims.
Corporate Transactions
Information may be disclosed, transferred, or assigned in connection with a merger, acquisition, restructuring, financing, reorganization, asset sale, bankruptcy, or other corporate transition, subject to applicable legal obligations.
Aggregated and De-Identified Information
Amplify may use, disclose, or share de-identified, anonymized, or aggregated information that does not identify an individual or Customer, as permitted by applicable law.
Data Retention
Amplify retains information only for as long as reasonably necessary to fulfill legitimate business, legal, contractual, operational, security, or regulatory purposes. Retention periods may vary depending on the type of data, account status, subscription terms, legal obligations, contractual commitments, dispute resolution needs, and backup and recovery requirements. Where multiple retention obligations apply to the same data, including statutory, regulatory, contractual, and operational requirements, Amplify retains for the longest applicable period.
Customer Data
Customer Data may be retained for active service delivery, hosted storage, workflow processing, lawful retention, backup integrity, dispute handling, and contract administration. Where applicable, retention may also be governed by BAAs, DPAs, enterprise agreements, Customer instructions, or regulatory obligations.
Service Data, Logs, and Security Records
Amplify may retain Service Data, logs, diagnostics, telemetry, and security records for troubleshooting, fraud detection, abuse prevention, operational continuity, reliability improvement, and legal compliance.
Indicative Retention Periods
The following table provides general guidance on Amplify’s standard retention periods. Specific periods may vary based on applicable BAAs, DPAs, enterprise agreements, Customer instructions, or legal requirements. Bracketed periods should be confirmed with operations before publication.
Data Category
Standard Retention Period
Customer Data (fax content, documents, forms, records)
Active subscription; up to 90 days post-termination, then deleted from active systems
Communications metadata (routing, delivery, timestamps)
Communications metadata (routing, delivery, timestamps)
Application and security logs
Up to 12 months from creation
Encrypted backups
30 days rolling retention; automatic purge upon expiration
Account and registration information
Active account period + 3 years for commercial record purposes
Billing and payment records
As required by law
These periods are subject to applicable legal retention requirements, contractual commitments, security obligations, and dispute-resolution needs. Where applicable law requires longer retention, Amplify will retain information for the legally required period.
Deletion
Where required by law, contract, or applicable data rights requests, Amplify may delete, anonymize, or restrict processing of information, subject to lawful retention rights, technical limitations (such as backup rotation cycles), and security obligations. The same retention and deletion obligations applicable to primary data apply equally to backup copies, archived copies, and replicated data. Deletion of backup copies occurs consistent with applicable backup rotation cycles and retention schedules.
Amplify maintains internal records of deletion or destruction of personal information and PHI consistent with applicable legal and contractual obligations.
Security
Amplify maintains administrative, technical, and organizational measures designed to protect information from unauthorized access, misuse, disclosure, alteration, destruction, or loss. Our primary infrastructure operates on Amazon Web Services ("AWS"), which provides foundational physical security, data center controls, geographic storage protections, and cloud infrastructure safeguards consistent with AWS's published compliance certifications and security documentation.
At the infrastructure layer, Amplify's measures include cloud-based access controls, encrypted backup procedures, geographic data storage controls, system availability monitoring, and incident response capabilities supported by our cloud infrastructure provider. Amplify leverages AWS's native security controls, availability commitments, and service continuity capabilities as part of its overall security posture.
At the application and operational layer, Amplify implements controls including role-based access management, authentication requirements, logging, and operational security procedures. These controls are subject to ongoing review and improvement as part of Amplify's security program.
No Absolute Security Guarantee
No system, transmission method, network, AI workflow, telecom routing environment, cloud provider, or storage system can be guaranteed to be fully secure. Amplify cannot guarantee absolute security, and we encourage Customers to implement appropriate safeguards on their end as well.
Customer Security Responsibilities
Customers remain responsible for account credential security, role-based access decisions, internal permissions, endpoint and device security, lawful configuration choices, third-party integrations, retention settings, user access governance, and lawful disclosures.
Incident Handling
Where required by law or contract, Amplify will investigate, mitigate, notify, and respond to security incidents consistent with applicable obligations. Where PHI is involved, the applicable BAA governs breach notification obligations and timelines.
International Transfers
Amplify may store, access, process, or transfer information in jurisdictions where Amplify, affiliates, subprocessors, service providers, or infrastructure providers operate. These locations may differ from the Customer’s or user’s jurisdiction.
Cross-Border Infrastructure
Services may rely on cloud providers, telecom carriers, infrastructure vendors, support providers, integrations, and global routing partners. Information may move across systems where necessary to provide the Services. Where required by applicable law, Amplify implements appropriate transfer mechanisms, contractual safeguards, or operational controls to protect personal information in cross-border transfers.
EU and UK Data Processing
Where Amplify processes personal data of individuals located in the European Economic Area (“EEA”) or United Kingdom (“UK”):
(a) Transfer Mechanisms. Amplify implements appropriate safeguards for transfers of personal data from the EEA or UK to third countries, including Standard Contractual Clauses (“SCCs”) approved by the European Commission and/or the UK International Data Transfer Agreement (“IDTA”) as applicable.
(b) EU/UK Representative. Pursuant to Article 27 of the GDPR and Article 27 of the UK GDPR, Amplify Labs, Inc. has designated Amplify Ventures Limited, a company registered in England and Wales, as its representative in the European Union and the United Kingdom for matters relating to Amplify Labs, Inc.'s processing of personal data of individuals located in the EEA or UK.
Amplify Ventures Limited acts in this capacity solely as Amplify Labs, Inc.'s designated representative under GDPR Article 27 and UK GDPR Article 27, and not as a controller or processor of the personal data it represents. This designation is separate and distinct from any role Amplify Ventures Limited holds as a data controller in its own right with respect to its own customers and services. Individuals and supervisory authorities may contact Amplify Ventures Limited in its capacity as Amplify Labs, Inc.'s representative at [need email address for this]
(c) Supervisory Authority. EU and UK data subjects may lodge complaints with their applicable supervisory authority. UK data subjects may contact the Information Commissioner’s Office (ICO) at ico.org.uk.
Incident Handling
Where required by law or contract, Amplify will investigate, mitigate, notify, and respond to security incidents consistent with applicable obligations. Where PHI is involved, the applicable BAA governs breach notification obligations and timelines.
Privacy Rights and Requests
Where Amplify processes Customer Data on behalf of Customers in a processor or service provider role, privacy rights requests relating to that data may need to be directed to the applicable Customer, who is responsible for determining how to respond. Amplify will cooperate with Customers in fulfilling applicable data subject requests consistent with our contractual obligations.
Verification
Amplify may request verification reasonably necessary to confirm your identity, authority, or the lawful scope of a rights request before we act on it.
Non-Discrimination
Where required by applicable law, Amplify will not unlawfully discriminate against individuals for exercising their privacy rights.
Children’s Privacy
The Platform and Services are not intended for use by children under the age required by applicable law to independently provide consent to the collection and processing of their personal information. Amplify does not knowingly collect personal information directly from children where prohibited by law. If we become aware that we have inadvertently collected such information, we will take reasonable steps to delete it.
Changes to This Privacy Policy
Amplify may update this Privacy Policy from time to time to reflect legal or regulatory developments, new or changed Services, AI functionality, integrations, product changes, security updates, or operational changes. The updated Privacy Policy will be posted with an updated effective date. Where required by law, we will provide additional notice of material changes. Continued use of the Platform or Services after an update takes effect may constitute acceptance where legally permitted.
Contact Information
If you have questions about this Privacy Policy, wish to submit a privacy rights request, or need to deliver a legal notice, please contact:
Where applicable, privacy rights requests may also be submitted through designated Platform workflows, support channels, or customer-directed administrative contacts.