Privacy Policy | Ampersand
Read announcement

Privacy Policy for Ampersand

Last updated August 22, 2024

Welcome to Ampersand!

This Privacy Policy (“Policy”) explains how your information is collected, used and disclosed while using our domains, applications and services located or accessed at https://www.withampersand.com which is owned and operated by Onset Labs, Inc. ("Ampersand®"/“we”/ “us” / “our”). This Policy applies where we are acting as a Data Controller, where we determine the purposes and means of the processing of that personal data, for example with respect to the personal data of our website visitors, service users, clients, etc

Who will use my data? Onset Labs, Inc. (Ampersand®)
What for?

We will store and process your data in order to allow us to provide and improve our services. We will use your data when you communicate with us by sending administrative notifications, product updates, and other related communications. Also, to assist you with any questions, issues, or feedback related to Ampersand. We use your personal data to detect, prevent, or address fraud, security, or technical issues and as required by law, legal process, or in the interest of public safety or investigation.

If you contact us, we may also send you information that we think you will be interested in. This may include a range of related services. We will also send any relevant details to authorities and any other organisation that requires them by law.

What will happen if I contact you? If you contact us, we will use your data to send you the information that you have requested and updates, and other information that we think you will be interested in. This may include a range of related services.
What data will be stored? We will store your personal details in order to provide our services and run our company. This includes your contact details, company information, account information, information provided through our support, and financial information.
What data will be shared? We will not share your data with any third parties other than as described here, to fulfil our obligations to you, operate and develop our company, and to protect our interests. We will only share any data that is particularly relevant to our process in order to provide the services that we offer. We may share your information with regulators or legal bodies that request it.
How long? Your data will be stored only for as long as necessary to fulfill our purposes unless otherwise required by law or to meet legal and customer contractual obligations. For more information, please contact us at privacy@withampersand.com.
Who can access my data? We will never sell, share or otherwise distribute your data to any other third party other than as described here. Access to your data is carefully controlled.
How is my data kept secure? We will store your data on secure servers. We use industry-standard security protocols/technology to secure your data.

About This Privacy Policy

This policy sets out how we will collect, store, and process the information you provide to us, the information we collect as a result of our interaction, the information we collect about you from other sources, or the information we service about you by using the information we hold.

This policy helps to protect us from data security risks, including breaches of confidentiality, failing to offer choice, reputational damage, and any other risks inherent in the collection, storage, or processing of your data.

With this policy, we will work towards meeting the following goals:

  • Ensuring the protection of the individual’s privacy rights and personal information
  • Promoting transparency and accountability in the processing of personal information
  • Minimizing the risk of data breaches and unauthorized access to personal information
  • Compliance with applicable laws, regulations, and guidelines
  • Establishing a framework for effective management of personal information

Principles of Processing Personal Information

The General Data Protection Regulation (GDPR) describes how organisations must collect, handle, process, and store personal information. These rules apply regardless of whether data is stored electronically, on paper or other materials. To comply with the law, personal information must be collected and used fairly, stored safely and not disclosed unlawfully. GDPR is underpinned by eight important principles. These say that personal data must:

  • Be processed fairly and lawfully;
  • Be obtained only for specific, lawful purposes;
  • Be adequate, relevant, and not excessive;
  • Be accurate and kept up to date;
  • Not be held for any longer than is necessary;
  • Processed in accordance with the rights of the data subjects;
  • Be protected in appropriate ways;
  • Not be transferred internationally, unless the country or territory also ensures an adequate level of protection;

We take these responsibilities seriously; this document describes our approach to data protection.

Who We Are And How To Contact Us

Ampersand is a development platform for user-facing business-to-business integrations which is owned and operated by Onset Labs, Inc. and is registered in the USA. The Data Protection Officer is Adam Brogden. You can contact us in any of the following ways:

Our Data Protection Officer

or

Our company contact details

  • Company name: Onset Labs, Inc. (Ampersand)
  • Address: 280 Spear St, Unit 1404, San Francisco, CA 94105
  • Contact: privacy@withampersand.com

OUR ARTICLE 27 REPRESENTATIVE

We have appointed EU Representatives under Article 27 of the EU GDPR. Our appointed representatives is

Our EU Representative:

Under Article 27 of the GDPR, we have appointed an EU Representative to act as our data protection agent. Our nominated EU Representative is: Instant EU GDPR Representative Ltd.

  • Adam Brogden contact@gdprlocal.com
  • Tel: +35315549700
  • INSTANT EU GDPR REPRESENTATIVE LTD
  • Office 2, 12A Lower Main Street, Lucan Co. Dublin
  • K78 X5P8
  • Ireland

To whom does this privacy policy apply?

We process your data to offer you our services and to run our company. This applies to all data we hold relating to identifiable individuals, even if that information technically falls outside of the GDPR. This policy relates to the following identified categories of data subjects:

  • employees
  • contractors
  • interns
  • clients
  • third parties

What this policy applies to

This section describes the purposes for processing your data and applies to the information about yourself that you choose to provide us with or that you allow us to collect. This includes:

  • The information you provide when you contact us
  • When you contact us to discuss using our services
  • Information collected when you create an account
  • Information collected through your integrations on our platform
  • Information that we collect while offering support
  • Information we collect about how you use the website
  • Information relating to services we offer to you and other transactions including financial and other personal information required to complete these transactions
  • Information that is given and stored as part of our ongoing relationship
  • Information we collect as a result of our interaction
  • The information we collect about you from other sources
  • or information we service about you by using the information we hold.

We do not routinely collect or process sensitive data about you. However, where this is the case we will ensure we ask for your consent where applicable and take appropriate precautions to protect your data.

What information do we collect

Directly Provided Information

Our users connect their SaaS and on-premise applications (e.g., SaaS systems like CRM, ERP, HRIS, Helpdesk, etc.) to Ampersand via APIs and configuration files made available by Ampersand. We may collect, store and process, on your and/or your organization's behalf, any data (including Personal Information) transmitted to Ampersand. This data is essential for the functionality of our platform, delivering support, or ensuring your user experience is optimized.

Here's a detailed breakdown of this category:

Account Information
  • Email Address: It's the primary means of communication between you and Ampersand. We send account verification emails, notifications, updates, and support information through this channel. Your email address also serves as a unique identifier for your Ampersand account.
  • Password: This confidential data ensures only authorized users can access an Ampersand account. We use robust encryption methods to protect your password. You're advised to use strong, unique passwords and not share them.
  • Profile Data: Depending on our platform's functionalities, you might set up a profile that includes details such as your name, job title, company's name, and contact number. This information can enhance user experience and allow for personalized service.
  • Billing and Payment Information: If Ampersand has premium features or services, we might collect payment details like credit card numbers or other payment methods. This data is typically processed securely using third-party payment gateways.
Integration Data
  • Specifications: Detailed information about the particular integration you want to establish, such as the type of data you wish to sync, frequency of data exchange, or custom functionalities you desire.
  • Configurations: Settings or preferences that define how your Ampersand platform interacts with your customers' SaaS instances.
  • Credentials for Third-party SaaS Platforms:
    • Access Tokens: Temporary credentials often used to authenticate a user. It might be used for single sign-on or to access features of another platform without sharing a password.
    • API Keys: A code passed in by computer programs calling an API (for reading or writing data). It identifies the calling program and provides access control.
    • Other Login Details: Usernames, passwords, or other credentials used to establish and maintain integration connections.
Support and Communication Data
  • Inquiries: When you reach out to our support team with questions or for assistance, you might provide data related to your issue, feedback, or suggestions.
  • Interaction History: Previous interactions, ticket details, or any other historical data that can help us serve you better in subsequent interactions.
  • Feedback: Opinions, testimonials, or reviews you provide about Ampersand.

Each piece of directly provided information has its specific use case and is handled with utmost care, ensuring security and privacy at all stages. We aim to collect only the minimum data required to facilitate your needs and enhance your experience with Ampersand.

Automatically Collected Information

We may collect information that your browser sends whenever you access our product, such as:

  • Log Data: This may include information such as your IP address, browser version, pages visited, time spent on those pages, and other statistics.
  • Device Information: Information about your device, including device type and operating system.
  • Usage Information: Data about how and when you use Ampersand, like access times and feature utilization.

How will your information be collected and used?

We will only use your personal data for the purposes for which we collected it and as you would reasonably expect your data to be processed and only where there is a lawful basis for such processing, for example:

Purpose/Activity Type of data Lawful basis for processing
To create an account
  1. Identity
  2. Contact
  1. Performance of a contract with you
  2. Consent
To provide you with services that you request, and to manage payments, fees and charges.
  1. Identity
  2. Contact
  3. Financial
  4. Transaction
  1. Performance of a contract with you
  2. Necessary to comply with a legal obligation
To provide you with support and essential service notices
  1. Identity
  2. Contact
  3. Technical
  1. Performance of a contract
To manage our ongoing relationship with you which will include notifying you about changes to our terms, services or privacy policy, marketing emails, newsletter
  1. Identity
  2. Contact
  3. Profile
  4. Marketing and Communications
  1. Performance of a contract with you
  2. Necessary to comply with a legal obligation
To administer and protect our business and our site (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
  1. Identity
  2. Contact
  3. Technical
  1. Necessary for our legitimate interests for running our business (administration, IT services, network security, fraud prevention, reorganisation)
  2. Necessary to comply with a legal obligation
  3. Consent
To use data analytics to improve our website, services, marketing, client relationships and experiences, and product analytics for quality/debugging
  1. Contact
  2. Technical
  3. Usage
  1. Necessary for our legitimate interests to define client types, keep the site relevant, develop our business and inform marketing strategy (necessary cookies)
  2. Consent (for accepted cookies)
To use data for our Recruiting purposes
  1. Identity
  2. Contact
  1. Consent

We may collect and process information about you, including your name, contact details (including email address and mobile phone number) for account creation, job title, company name, billing contact information, personal information when we provide support to you and all personal data that you share with us when you contact Ampersand. We may take personal information from a range of sources.

We will use your data for the purpose it was collected. Where we have your consent or another lawful basis, we may also use your personal information to send you marketing communications about our services. This document explains how you can manage your communication preferences. Please note that, even if you opt out of marketing communications, we may still send you important service-related messages, including those necessary for the provision of any services we offer you. You will only receive marketing communications from us if:

  • You requested information from us
  • You provided us with your details and ticked the box at the point of entry of your details for us to send you marketing communications
  • You have not opted out of receiving marketing
  • We have an appropriate lawful basis for processing your personal data for this purpose

We will get your express opt-in consent before we share your personal data with any third party for marketing purposes.

How to change your preferences

We operate in line with the GDPR data protection guidelines. We respect your rights and will respond to any request for access to personal information and requests to delete, rectify, transfer, data and to stop processing. We will also advise you on how to complain to the relevant authorities. Where possible any requests or objections should be made in writing to the Data Controller, or you can visit our website, or email us to contact us to exercise your rights, make a complaint, or change your preferences at any time.

Opting out at a later date

You have the right to amend or withdraw your consent at any time, including opting out of marketing communications or the processing of financial data. You can also object to the processing of your data and request its deletion. We respect all user rights as defined in the GDPR. If you have any questions, comments, or wish to file a complaint, please contact us.

How we store and process your data

Your data will be collected, stored and processed securely. In the case where we transfer your data internationally, we will ensure we take appropriate precautions to protect this data. Your data will be stored only for as long as necessary to fulfill its purposes unless otherwise required by law or to meet legal and customer contractual obligations.

We will only use your personal data for the purposes for which it was collected unless we reasonably believe that another use is necessary and compatible with the original purpose. If you would like more information about the compatibility of a new purpose with the original purpose, please contact us. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis for doing so.

In certain circumstances, we may be legally required to disclose your personal information without your knowledge. These circumstances include legal obligations, ongoing or prospective legal proceedings, or to establish, exercise, or defend our legal rights. This may involve providing information to others for fraud prevention or credit risk reduction. We may also disclose information if we believe a court or other competent authority would likely order us to do so.

Our obligations

As the Data Controller, we are legally responsible for the handling of the information you provide to us. We are committed to complying with the GDPR in all aspects of how we use and share your personal data.

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

  • Request access to your personal data;
  • Request correction of your personal data;
  • Request erasure of your personal data;
  • Object to processing of your personal data;
  • Request restriction of processing your personal data;
  • Request transfer of your personal data;
  • Right to withdraw consent

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response

We aim to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Third Parties

We may have to share your personal data with selected third parties in order to meet our obligations to you and for the purposes described in this document:

  • Third party service providers to facilitate our service, provide the service on our behalf, or assist us in analyzing how our service is used;
  • When you provide us with consent and authorize a third-party app to access your Ampersand account;
  • Professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, fraud protection, insurance and accounting services;
  • Other technology companies providing tracking, analytics, and advertising companies;
  • Social media companies;
  • Partners and other organisations involved in the provision of our services to you and as required to operate our company;
  • Government organisation, regulators, other legal authorities and other relevant jurisdictions who require reporting of processing activities in certain circumstances;
  • Third parties to whom we transfer, or merge parts of our business or our assets;
  • Other companies as required to meet our obligations to you and run our business.

We require all third parties to whom we transfer your data to respect the security of your personal data and to treat it in accordance with the law. We only allow such third parties to process your personal data for specified purposes and in accordance with our instructions.

Ampersand allows integrations with various third-party services like Salesforce and HubSpot. While we facilitate these connections, we are not responsible for the practices employed by these third-party services.

Security

We have implemented appropriate security measures to protect your personal data from accidental loss, unauthorized access, use, alteration, or disclosure. Access to your data is restricted to employees, agents, contractors, and third parties who have a legitimate business need to know. They are authorized to process your data only under our instructions and are bound by confidentiality obligations.

In compliance with GDPR requirements, we will report any data breaches or potential breaches to the relevant authorities within 24 hours of becoming aware of them, and to affected individuals within 72 hours. If you have any questions or concerns regarding your data usage, please contact us.

Our website may contain links to third-party websites, plug-ins, and applications. Interacting with these links or connections may enable third parties to collect or share your data. We have no control over these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policy of each website you visit after leaving our site.

Children

Our Site and Services are not intended for minors and we don’t intentionally collect Personal Information from individuals under 18 years old, following the General Data Protection Regulation (GDPR).

If we learn we have collected or received personal information from a minor under 18, we will delete that information. If you believe we might have any information from or about a minor under 18, please contact us at: privacy@withampersand.com

Cookies

A cookie is a small file that asks permission to be placed on your computer’s hard drive. Once you agree, the file is added, and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.

Overall, cookies help us provide you with a better website by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us.

You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline cookies if you prefer. This may prevent you from taking full advantage of the website.

As well as your ability to accept or reject cookies, we also require your permission to store cookies on your machine, which is why when you visit our site, you are presented with the ability to accept our terms of use, including the storage of cookies on your machine.

Contacting us, exercising your information rights and Complaints

information rights in connection with the personal data you have shared with us or wish to complain, please contact: our DPO - Adam Brogden, Ampersand or on our email address: privacy@withampersand.com. We aim to process data protection requests within 30 days, SAR responses are usually free, but we reserve the right to charge for excessive or unfounded requests. We fully comply with Data Protection legislation and will assist in any investigation or request made by the appropriate authorities.

If you remain dissatisfied, then you have the right to apply directly to your local data protection authority.

https://www.edpb.europa.eu/about-edpb/about-edpb/members_en

Your Privacy Choices

We do not sell personal information. We may disclose personal information to third parties as described in our Privacy Policy in order to provide our services, operate our business, and meet legal obligations.

You may exercise your privacy rights, including opting out of such sharing, by contacting us at privacy@withampersand.com, or filling out the below form. We will not discriminate or retaliate against you for exercising your privacy rights. This includes rights to access, delete, or opt out of the sale or sharing of your personal information.

Similarly, if you have previously opted out of the sharing of your personal information, you may opt back in at any time. To do so, contact us at privacy@withampersand.com, or fill out the below form.

Submit a Data Protection Request

You can reach us by emailing us at privacy@withampersand.com or filling out a data protection request below.

Fill Out Data Protection Request

Response Time: We aim to respond to all legitimate requests within one month.