Privacy Policy

Privacy Policy

Privacy Policy

Effective Date 31 March 2026

Effective Date 31 March 2026

This Privacy Policy describes the policies of AMPLIFYR, 71-75 Shelton Street, London WC2H 9JQ, United Kingdom of Great Britain and Northern Ireland (the “Company”), email: team@amplifyr.me, phone: +447770088358 on the collection, use and disclosure of your information that we collect when you use our website (https://www.amplifyr.me/) and our AI analytics integration service, including the Amplifyr MCP (Model Context Protocol) connector which allows AI assistants such as Claude and ChatGPT to access Amplifyr analytics on your behalf (collectively, the “Service”). By accessing or using the Service, you are consenting to the collection, use and disclosure of your information in accordance with this Privacy Policy. If you do not consent to the same, please do not access or use the Service.

We may modify this Privacy Policy at any time without any prior notice to you, and will post the revised Privacy Policy on the Service. The revised Policy will be effective 180 days from when the revised Policy is posted in the Service, and your continued access or use of the Service after such time will constitute your acceptance of the revised Privacy Policy. We therefore recommend that you periodically review this page.

1. Your Rights:

1. Your Rights:

Depending on the law that applies, you may have a right to access and rectify or erase your personal data or receive a copy of your personal data, restrict or object to the active processing of your data, ask us to share (port) your personal information to another entity, withdraw any consent you provided to us to process your data, a right to lodge a complaint with a statutory authority and such other rights as may be relevant under applicable laws. To exercise these rights, you can write to us at team@amplifyr.me. We will respond to your request in accordance with applicable law. Do note that if you do not allow us to collect or process the required personal information or withdraw the consent to process the same for the required purposes, you may not be able to access or use the services for which your information was sought.

2. Cookies Etc.

2. Cookies Etc.

We use only essential cookies required for authentication and session management. We do not use tracking or advertising cookies.

We use only essential cookies required for authentication and session management. We do not use tracking or advertising cookies.

3. Security:

3. Security:

The security of your information is important to us and we will use reasonable security measures to prevent the loss, misuse or unauthorized alteration of your information under our control. However, given the inherent risks, we cannot guarantee absolute security and consequently, we cannot ensure or warrant the security of any information you transmit to us and you do so at your own risk. To report a security vulnerability, please email team@amplifyr.me with details and we will respond promptly.

4. Grievance / Data Protection Officer:

4. Grievance / Data Protection Officer:

If you have any queries or concerns about the processing of your information that is available with us, you may email our Grievance Officer at AMPLIFYR, 71-75 Shelton Street, email: team@amplifyr.me. We will address your concerns in accordance with applicable law.

5. Information We Collect

When you use the Amplifyr platform or MCP connector, we collect and process the following information:

5a. Account credentials: When your organisation signs up for Amplifyr, we create a user account for you in our authentication system (AWS Cognito). This includes your email address and name, which are provided by your organisation administrator — not directly collected from you. These credentials are used solely to authenticate you and scope your data access to your organisation.

5b. Authentication tokens: When you connect an AI assistant (such as Claude or ChatGPT) to Amplifyr via the MCP connector, an OAuth 2.0 authentication flow is initiated. During this flow, your email address and name from your Cognito account are included in a short-lived access token used to verify your identity. Refresh tokens may be issued to maintain your session without requiring you to log in again. These tokens are managed by AWS Cognito and are not stored by Amplifyr beyond the active session.

5c. Usage metadata and organisation identifier: We log which tools were called (e.g. Performance & KPIs, Competitive Intelligence), by which authenticated organisation, and at what time. We do not log the content of AI prompts or the full data returned in tool responses. Your organisation's account identifier (account name) is included in the response of the "List Clients" tool so the AI assistant can correctly scope follow-up queries to your organisation. This identifier is sent to the connected AI provider as part of the tool response. No other tool responses include your organisation's identifier.

5d. Analytics data: The analytics data you access via Amplifyr (brand mentions, share of voice, KPIs, sentiment, citations, prompts) relates to your organisation’s brand performance and does not contain personal data of individuals. When you query this data through an AI assistant via the MCP connector, the requested analytics data is sent as tool responses to the connected AI provider (see Section 7) so it can generate answers to your queries. Amplifyr sends only the data necessary to fulfil the specific request.

5e. Connector revocation: When you disconnect or revoke the Amplifyr connector from your AI assistant, your authentication session is terminated immediately. Amplifyr does not retain any session tokens after disconnection. Previously returned analytics data may still be retained by the AI provider according to their own data retention policies (see Section 7).

6. How We Use Your Information

6. How We Use Your Information

We use the information described above to:

a. Authenticate you and verify you are an authorised user of your organisation’s Amplifyr account.

b. Scope all data queries to your organisation only, preventing access to other organisations’ data.

c. Maintain audit logs for security and compliance purposes.

d. Provide and improve the Amplifyr Service.

e. Return analytics results to AI assistants you have connected, so they can answer your queries. Only the data required to fulfil your specific request is included in each tool response.

7. Third-Party Services

7. Third-Party Services

To deliver the Service, we use the following third-party providers. Each provider processes data only as necessary to perform their function:

To deliver the Service, we use the following third-party providers. Each provider processes data only as necessary to perform their function:

Provider

Purpose

Location

Safeguards

Amazon Web Services (AWS)

Authentication (Cognito), data storage (S3), query execution (Athena), AI knowledge base (Bedrock), application hosting (ECS)

EU (Ireland, eu-west-1)

AWS GDPR DPA; UK adequacy decision covers EEA transfers

Anthropic

AI model inference when users connect Claude as their AI assistant via the MCP connector

USA (primary)

Anthropic DPA; Standard Contractual Clauses (UK Addendum)

OpenAI

AI model inference when users connect ChatGPT as their AI assistant via the MCP connector; also used for the Custom Analysis tool (SQL generation from natural language)

USA (primary)

OpenAI DPA; Standard Contractual Clauses (UK Addendum)

Other AI model providers

AI model inference for any other MCP-compatible AI assistant a user may connect

Varies by provider

Each provider maintains their own Data Processing Addendum

Provider

Purpose

Location

Safeguards

Amazon Web Services (AWS)

Authentication (Cognito), data storage (S3), query execution (Athena), AI knowledge base (Bedrock), application hosting (ECS)

EU (Ireland, eu-west-1)

AWS GDPR DPA; UK adequacy decision covers EEA transfers

Anthropic

AI model inference when users connect Claude as their AI assistant via the MCP connector

USA (primary)

Anthropic DPA; Standard Contractual Clauses (UK Addendum)

OpenAI

AI model inference when users connect ChatGPT as their AI assistant via the MCP connector; also used for the Custom Analysis tool (SQL generation from natural language)

USA (primary)

OpenAI DPA; Standard Contractual Clauses (UK Addendum)

Other AI model providers

AI model inference for any other MCP-compatible AI assistant a user may connect

Varies by provider

Each provider maintains their own Data Processing Addendum

8. Data Retention

8. Data Retention

a. Authentication tokens are session-based and are not stored by Amplifyr beyond the active session. Refresh tokens issued by our authentication provider (AWS Cognito) are managed by the AI assistant's platform and expire according to the session configuration. Amplifyr does not store or have access to these tokens outside of active request processing.

b. Account credentials (email, name in Cognito) are retained for as long as your organisation holds an active Amplifyr account. Upon account termination, credentials are deleted within 30 days.

c. Audit logs (tool call metadata) are retained for as long as necessary for security and compliance purposes.

d. Analytics data is retained per the terms of your organisation’s service agreement with Amplifyr.