1. Definitions
- "Customer Personal Data" means Personal Data contained in Customer Data that Amber processes on behalf of the Customer.
- "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (the "CCPA"), and other comprehensive U.S. state privacy laws.
- "Security Incident" means a breach of Amber's security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Sub-processor" means a third party that Amber engages to process Customer Personal Data on Amber's behalf.
- "Business", "Controller", "Processor", "Service Provider", "Contractor", "Consumer", "Sell", and "Share" have the meanings given in the applicable Data Protection Laws.
2. Roles and Scope
2.1 Roles. The Customer is the Business or Controller of Customer Personal Data, and Amber is the Customer's Service Provider or Processor.
2.2 Scope. This DPA applies only to Customer Personal Data. It does not apply to personal information that Amber processes for its own purposes as a Business or Controller, such as account administration, billing, and communications with Customer's Users, which is described in Amber's Privacy Policy at amber.ai/legal/privacy.
2.3 Details. Annex 1 describes the subject matter, nature, purposes, and duration of the processing, and the types of Personal Data and individuals involved.
3. Processing on Customer's Instructions
3.1 Instructions. Amber will process Customer Personal Data only on the Customer's documented instructions, which consist of: (a) the Agreement; (b) the Customer's use and configuration of the Services, including its integrations, Partner invitations, and Digital Worker settings; and (c) other reasonable written instructions consistent with the Agreement.
3.2 Unlawful instructions. Amber will inform the Customer if, in Amber's opinion, an instruction infringes Data Protection Laws. Amber is not required to follow an instruction that it reasonably believes would violate the law.
3.3 Processing required by law. Amber may process Customer Personal Data as required by law, in which case Amber will inform the Customer before processing unless the law prohibits it.
4. U.S. Privacy Law Commitments
4.1 Business purposes. Amber processes Customer Personal Data for the limited and specified business purposes of providing, securing, supporting, and maintaining the Services for the Customer, as described in Annex 1 (the "Business Purposes").
4.2 Restrictions. Amber will not:
(a) Sell or Share Customer Personal Data;
(b) retain, use, or disclose Customer Personal Data for any purpose other than the Business Purposes, including for any commercial purpose other than the Business Purposes, or as otherwise permitted by the CCPA;
(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Amber and the Customer; or
(d) combine Customer Personal Data with personal information that Amber receives from or on behalf of another person, or collects from its own interactions with individuals, except as permitted by the CCPA and its regulations.
4.3 De-identified data. Where Amber creates Aggregated Data from Customer Personal Data under Section 7 of the Terms, Amber will: (a) take reasonable measures to ensure the data cannot be associated with an individual or household; (b) publicly commit to maintain and use the data only in de-identified form and not attempt to re-identify it; and (c) contractually require any recipient to do the same.
4.4 Compliance. Amber will comply with its obligations under the CCPA and other Data Protection Laws that apply to it as a Service Provider or Processor, and will provide the same level of privacy protection as those laws require. Amber will notify the Customer if it determines that it can no longer meet these obligations.
4.5 Customer's rights. The Customer may take reasonable and appropriate steps to ensure that Amber uses Customer Personal Data consistently with the Customer's obligations under Data Protection Laws, and, on notice, to stop and remediate any unauthorized use of Customer Personal Data.
4.6 Certification. Amber certifies that it understands and will comply with the restrictions in this Section 4.
5. Confidentiality of Personnel
Amber will ensure that each person it authorizes to process Customer Personal Data, including employees and contractors, is subject to a duty of confidentiality, and will limit access to those who need it to provide, secure, or support the Services.
6. Sub-processors
6.1 Authorization. The Customer authorizes Amber to engage the Sub-processors listed at amber.ai/legal/subprocessors (the "Sub-processor List") and new Sub-processors under this Section 6.
6.2 Sub-processor obligations. Amber will enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable to the services the Sub-processor provides. Amber remains responsible for each Sub-processor's performance of those obligations.
6.3 Notice of new Sub-processors. Amber will update the Sub-processor List and notify the Customer by email to its account's primary email address at least 30 days before a new Sub-processor begins processing Customer Personal Data. Amber may give shorter notice where it must replace a Sub-processor urgently to maintain the security or availability of the Services, in which case Amber will notify the Customer as soon as practical.
6.4 Objection. The Customer may object to a new Sub-processor on reasonable data protection grounds by emailing legal@amber.ai within 30 days after notice. The parties will discuss the objection in good faith. If they cannot resolve it, the Customer may, as its sole remedy, cancel its Subscription by notice to Amber before the new Sub-processor begins processing its Customer Personal Data, and Amber will refund any prepaid Fees for the remaining part of the Billing Period.
6.5 Not Sub-processors. Partners, Logistics Providers, and Third-Party Services that the Customer invites or connects are not Sub-processors, except to the extent they are listed on the Sub-processor List. When the Customer directs Amber to share Customer Personal Data with them, the Customer's own agreements with those parties govern their processing.
7. Security
Amber will implement and maintain the technical and organizational measures described in Annex 2 and on Amber's Security page at amber.ai/security. Amber may update these measures from time to time, provided that the updates do not materially reduce the overall protection of Customer Personal Data.
8. Security Incidents
8.1 Notice. Amber will notify the Customer without undue delay, and in any event within 72 hours, after Amber confirms a Security Incident.
8.2 Information and cooperation. Amber's notice will describe, to the extent then known, the nature of the Security Incident, the categories of Customer Personal Data affected, the likely consequences, and the measures Amber has taken or proposes to take. Amber will update the Customer as more information becomes available, take reasonable steps to contain and remediate the Security Incident, and provide reasonable assistance to help the Customer meet its own notification obligations.
8.3 No admission. Amber's notice of or response to a Security Incident is not an admission of fault or liability.
8.4 Exclusions. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans, and failed log-in attempts, are not Security Incidents.
9. Assistance to Customer
9.1 Individual requests. If Amber receives a request from an individual to exercise privacy rights regarding Customer Personal Data, Amber will not respond to it except to direct the individual to the Customer, unless the law requires otherwise. Taking into account the nature of the processing, Amber will provide reasonable assistance to help the Customer respond to such requests, including through the features of the Services.
9.2 Assessments. Amber will provide reasonably available information to help the Customer carry out data protection assessments required by Data Protection Laws.
9.3 Cost. Assistance beyond what is available through the features of the Services and this DPA may be subject to Amber's reasonable fees, which Amber will agree with the Customer in advance.
10. Deletion and Return
The Customer may export Customer Personal Data during its Subscription and after it ends as described in Section 6.5 of the Terms. Amber will then delete Customer Personal Data as described in that Section, except where the law requires Amber to keep it, in which case Amber will continue to protect it under this DPA and will process it only for the purpose of that legal requirement.
11. Reviews and Assessments
11.1 Information. On written request, no more than once per year, Amber will respond to a reasonable written security and privacy questionnaire and provide other information reasonably necessary to demonstrate its compliance with this DPA.
11.2 Assessments. If the information in Section 11.1 is not sufficient to meet a requirement of Data Protection Laws, or following a Security Incident, the Customer may request a reasonable assessment of Amber's compliance with this DPA, either by the Customer or by an independent assessor bound by confidentiality. The parties will agree the scope, timing, and duration in advance. Assessments will be conducted with at least 30 days' notice, during business hours, without unreasonable disruption to Amber's operations, and at the Customer's expense. Amber may instead arrange for an independent assessor to conduct the assessment and share a summary of its results.
11.3 Confidentiality. Information provided under this Section 11 is Amber's Confidential Information.
12. Location of Processing
12.1 Hosting. Amber hosts Customer Personal Data in the United States. The locations of Sub-processors are shown on the Sub-processor List.
12.2 Laws outside the United States. If the Customer's processing of Customer Personal Data is subject to the EU or UK General Data Protection Regulation, the Swiss Federal Act on Data Protection, or another law that requires specific contract terms or transfer mechanisms, the Customer will notify Amber before submitting that data, and the parties will agree any required supplementary terms in a separate written agreement signed by both parties.
13. Customer Responsibilities
The Customer is responsible for:
(a) its compliance with Data Protection Laws, including providing all notices and obtaining all consents and permissions needed for Amber to process Customer Personal Data under the Agreement;
(b) complying with any requirements of the laws of the countries where its Partners and other individuals are located that apply to transferring their Personal Data to Amber;
(c) not submitting Prohibited Data, as defined in the Terms; and
(d) the security of its own accounts, credentials, devices, and connected Third-Party Services.
14. Liability, Changes, and Precedence
14.1 Liability. Each party's liability arising out of or relating to this DPA is subject to Section 14 of the Terms.
14.2 Changes. Amber may update this DPA under Section 17 of the Terms, except that changes to Sub-processors follow Section 6 of this DPA. Amber will not update this DPA in a way that reduces its obligations below what Data Protection Laws require.
14.3 Precedence. If this DPA conflicts with the Terms regarding the processing of Customer Personal Data, this DPA controls.
Annex 1: Details of Processing
Subject matter and nature. Hosting, storage, retrieval, analysis, organization, AI-assisted processing, transmission, and deletion of Customer Personal Data in providing the Services.
Business Purposes. Providing the Services to the Customer, including product development, supplier management, quotes and landed-cost calculations, purchase orders, freight coordination, document processing, integrations, Digital Workers, and AI features; securing, supporting, and maintaining the Services; preventing fraud and abuse; and complying with law.
Categories of individuals.
- The Customer's Users (employees and contractors of the Customer and its Affiliates).
- Personnel of the Customer's Partners, such as suppliers, factories, agents, freight forwarders, and customs brokers.
- Other individuals whose information appears in Customer Data, such as senders and recipients of email in connected accounts and individuals named in uploaded documents.
Categories of Personal Data.
- Contact and professional details: names, business email addresses, phone numbers, job titles, employer, business addresses.
- Account data for Users and Partners: user IDs, roles, permissions, and log-in records.
- Business communications and documents: emails and messages in connected accounts, comments, and documents such as purchase orders, invoices, quotes, packing lists, and specifications, and the Personal Data they contain.
- Business financial details that may relate to an individual, such as bank details of a sole-proprietor supplier.
- Technical data: IP addresses, device and browser information, and activity logs.
Sensitive data. The Customer may not submit Prohibited Data under the Terms. Amber does not intend to process sensitive personal information as Customer Personal Data.
Frequency. Continuous, for the duration of the Customer's use of the Services.
Duration. For the term of the Agreement and until deletion under Section 10.
Annex 2: Security Measures
Infrastructure. Customer Data is hosted in the United States on infrastructure provided by the Sub-processors on the Sub-processor List, which provide physical and environmental security for their data centers.
Independent assessment. Amber completes the Cloud Application Security Assessment (CASA) Tier 2, the independent security assessment Google requires for applications that access restricted Google user data, and keeps it current.
Encryption. Customer Data is encrypted in transit using TLS and encrypted at rest.
Access control. Access to production systems and Customer Data is limited to authorized personnel who need it for their role, uses individual accounts with multi-factor authentication, and is removed promptly when no longer needed.
Logging and monitoring. Access to production systems is logged, and systems are monitored for security events.
Secure development. Code changes are reviewed before deployment, and dependencies and infrastructure are kept up to date with security patches.
Separation. Each customer's Customer Data is logically separated from other customers' data.
Backups and resilience. Customer Data is backed up regularly, and backups are protected with the same level of security as production data.
Vendors. Sub-processors are assessed for security before engagement and bound by written data protection terms.
Personnel. Personnel with access to Customer Data are bound by confidentiality obligations and receive security training.
Incident response. Amber maintains a process for identifying, responding to, and notifying customers of Security Incidents under Section 8.