Data Processing Agreement

Last updated: 22 July 2026

This Data Processing Agreement ("DPA") forms part of the Ambital Terms of Service between Ambital Ltd, a company registered in England and Wales (company number 17319695), registered office The Granary, Blakelow Road, Macclesfield, SK11 7ED ("Ambital", "we", the "Processor") and the customer organisation using the Ambital platform (the "Customer", the "Controller"). It applies whenever Ambital processes personal data on the Customer's behalf under UK GDPR and the Data Protection Act 2018.

1. Roles

The Customer is the controller of personal data it enters into Ambital about its own clients, contacts and team members. Ambital is the processor, acting only on the Customer's documented instructions — which are, in the first instance, the instructions embodied in the platform's features. For the Customer's own account data (billing email, login), Ambital is an independent controller as described in the Privacy Policy.

2. Subject matter, duration and nature of processing

Processing covers hosting, storage, display, transmission and backup of the data the Customer manages in Ambital — CRM contacts, project records, timesheets, meeting notes, documents, invoices and related financial records — for the duration of the Customer's subscription, plus the deletion window in clause 8.

3. Categories of data subjects and data

  • Data subjects: the Customer's clients and their staff, the Customer's team members, prospects and suppliers.
  • Personal data: names, business contact details, email content and metadata (where the Customer connects a mailbox), calendar entries, meeting transcripts, time records, and financial records containing personal identifiers. Ambital is not designed for special-category data and the Customer agrees not to submit it.

4. Processor obligations

Ambital shall:

  • process personal data only on the Customer's instructions;
  • ensure persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational measures — encryption in transit and at rest, field-level encryption for integration tokens, tenant isolation enforced at the application layer, role-based access, and audit logging;
  • assist the Customer with data-subject requests (the platform's export and deletion tooling serves this) and with Articles 32–36 obligations;
  • notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's data;
  • delete or return personal data at the end of the engagement (clause 8);
  • make available information necessary to demonstrate compliance, and allow for audits as reasonably required.

5. Sub-processors

The Customer gives general authorisation to the sub-processors listed in the Privacy Policy (hosting, database, file storage, email delivery, payments, AI features and meeting transcription, as applicable to the features the Customer uses). Ambital will give at least 14 days' notice of any intended addition or replacement, during which the Customer may object on reasonable data-protection grounds. Ambital remains liable for its sub-processors' performance.

6. International transfers

Customer data is stored in the UK/EEA where the service's infrastructure allows. Where a sub-processor processes data outside the UK/EEA, transfers rely on UK adequacy regulations or the International Data Transfer Agreement / Addendum with appropriate supplementary measures.

7. Security incident process

On becoming aware of a breach affecting Customer personal data, Ambital will notify the Customer's billing email without undue delay, describe the nature and likely consequences of the incident, and the measures taken or proposed. The Customer remains responsible for its own ICO notifications as controller.

8. Deletion and return

On termination, the Customer may export its data using the platform's export tooling. Ambital deletes the organisation's personal data within 30 days of a verified deletion request or account closure, save for records Ambital must retain by law (e.g. invoicing records for tax purposes).

9. Signed copies

This DPA applies automatically to every Customer. If your compliance process needs a countersigned copy, email hello@ambital.co.uk and we'll arrange one.