What we do with
your customers' data.
You are handing us your contact list and your conversations. Here is how it is stored, who can reach it, and how you get it back.
Short answers here · full detail on request · no NDA needed to ask
Where your data lives
Your contacts, conversations and campaign history are held in our own managed database rather than spread across third-party tools. Backups are taken on a regular schedule and are restorable.
Each workspace's data is isolated. A user can only reach records belonging to a workspace they are a member of, and that check is enforced on the server on every request rather than hidden in the interface.
Who can see it
Access inside your workspace is role-based. You decide who is an admin, who manages a team, and who only sees their own leads. Deactivating someone revokes their access straight away rather than at the next login.
On our side, access to production data is limited to the engineers who need it to operate the service, and is used for support and incident response only. We do not sell your data, we do not share it with advertisers, and we do not use your customers' conversations to train models for anyone else.
How it moves
All traffic to the application and the API is encrypted in transit with TLS. Data is encrypted at rest. Messages leaving on WhatsApp, RCS, SMS and email travel over the carriers' and providers' own secured channels.
Getting it back, and getting out
Export everything, any time, in a standard format. There is no exit fee and no hostage period, and every plan except Enterprise is month to month. We would rather re-earn you every thirty days than trap you for a year.
Reporting something
If you believe you have found a vulnerability, email security@amplifeed.tech with enough detail to reproduce it. We will confirm receipt, keep you updated while we fix it, and we will not pursue anyone who reports in good faith and does not access or alter other people's data while testing.
We are a young company and we would rather say what is true than imply a certification we do not hold. If your procurement process needs something specific - an audit report, a questionnaire, a named subprocessor list - ask and we will tell you straight whether we have it today.
What procurement usually asks
Is our data kept separate from other customers'?
Yes. Every record carries its workspace and every query is scoped to it server-side. Membership of a workspace is what grants access, and it is checked on each request.
Can we get a DPA?
Yes, on any paid plan. Request one here and we will send it over for signature.
Where is the data physically stored?
Our primary database is hosted in India. If you have a specific residency requirement, raise it before you sign and we will confirm exactly what we can commit to in writing.
Do you support SSO?
SAML SSO and SCIM provisioning are Enterprise features, alongside audit logs and session management.
What happens if there is a breach?
We will tell you. You get a direct notification with what happened, what data was involved and what we are doing, not a status page update you have to go looking for.
Who are your subprocessors?
The messaging carriers and infrastructure providers needed to deliver your messages and run the service. The current list is available on request and is named in the DPA.
Ask us the awkward one
If there is a question this page has not answered, it is probably the one that matters to you. Send it over and you will get a straight answer rather than a brochure.