Ambia
Back to Ambia
On this page
RolesSubject matter and durationOur obligationsSubprocessorsInternational transfersAudit and assistanceBreach notificationDeletion and return
Last updated
Not yet effective
Legal — draftDraft — not legal advice

Data processing

The processing terms that apply when Ambia handles personal data on your studio's instruction — principally named-viewer lists and walk records. This page summarises the DPA; procurement teams can request the signable document.

This document is a working draft for review, not a signed or effective agreement. Nothing on this page creates a binding obligation until Ambia publishes a final version with a real effective date.

Version
v0.1 draft
Effective
Not yet effective
Governing law
England & Wales
01

Roles

For your account data Ambia is the controller. For personal data you put into the platform — named-viewer email lists, and any personal data embedded in model metadata — you are the controller and Ambia is the processor acting on your documented instructions.

02

Subject matter and duration

Processing lasts as long as your account, plus the retention windows in the privacy policy. It covers storage, processing and delivery of models, issuing access codes, and producing walk analytics.

CategoriesStudio staff, and end viewers you invite by name.
Data typesEmail addresses, access events, coarse device and region data.
Special categoryNone. Do not upload it.
03

Our obligations

We process only on your instructions, keep processing confidential, apply the security measures described in the privacy policy, assist with data subject requests and impact assessments, and delete or return data on termination.

In plain terms

If you ask us to do something with your data that we think is unlawful, we will tell you rather than quietly comply.

04

Subprocessors

You give general authorisation for the published subprocessor list. We give 30 days' notice of additions and you may object on reasonable data-protection grounds, in which case we will either propose an alternative or let you terminate the affected service without penalty.

05

International transfers

Transfers outside the UK or EEA rely on adequacy, the UK IDTA, or EU standard contractual clauses as appropriate. Enterprise customers can pin storage to a named region.

06

Audit and assistance

We provide our security overview and completed questionnaires on request. Where a regulator requires an on-site audit we will cooperate on reasonable notice, once per year, at the auditing party's cost.

07

Breach notification

We notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data, with the facts known at that time, the likely consequences, and the measures taken.

08

Deletion and return

On termination you can export everything. After the export window we delete personal data from live systems immediately and from backups within 90 days, except where we must retain it by law.

Questions about this document

Write to legal@ambia.build. If you need a signed copy, a DPA, or a security questionnaire completed for procurement, say so and we will send it rather than make you chase it.

Previous versionsSubprocessorsSecurity overview
© 2026 Ambia