1. Data controller
The controller of your personal data is Amberbook s.r.o., a company being incorporated in Slovakia. Until incorporation completes, the service is operated by Samuel Struharik, sole trader, on the same legal terms. The registered office address will be added to this policy once filed with the Slovak Commercial Register; in the meantime, postal correspondence may be sent care of the contact email below.
We do not have a Data Protection Officer because we do not meet the GDPR Art. 37 thresholds. The privacy mailbox is monitored directly by the founder.
2. What we collect
We process two distinct categories of personal data.
2.1 Customer account data. When you sign up we store your name, email address, hashed password, organisation, billing address, VAT identifier, country, and role. We also log access tokens, IP addresses, user-agent strings, and timestamps for sign-in events to keep your account secure. Pricing and access limits are agreed per customer in an order form rather than via standard self-service tiers.
2.2 Public business records. Amberbook aggregates publicly available data about companies and the individuals who hold registered roles in them - directors, ultimate beneficial owners, statutory representatives, sole proprietors who chose public registration, and authorised signatories. This data comes exclusively from official national company registers, EU open data portals, and other public-record sources listed in §5.
2.3 Usage data. We record what searches and exports you run, which pages and endpoints you call, and basic device characteristics. This is used for billing, abuse prevention, and product improvement.
3. Why we process it
- To provide the Amberbook platform you signed up for.
- To bill you and meet our accounting obligations under Slovak law.
- To keep the service secure and detect abuse, scraping, or fraud.
- To make public business records searchable and analysable, which is the core value of the product.
- To respond to your requests, including GDPR data subject requests.
- To send service announcements (not marketing without separate consent).
4. Legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)) - for providing the platform to subscribers.
- Legitimate interest (Art. 6(1)(f)) - for processing public-register data about company officers and UBOs in support of due diligence, KYC, AML, and economic-research use cases. We have completed a Legitimate Interest Assessment which is available on request.
- Legal obligation (Art. 6(1)(c)) - for tax records, anti-money-laundering, and responding to lawful authority requests.
- Consent (Art. 6(1)(a)) - for non-essential cookies and any future marketing emails. Consent can be withdrawn at any time.
5. Where data comes from
Public-record data is collected from official sources only. The authoritative list of sources is published in our Source Directory. Examples include:
- National business and commercial registers of the 12 covered EU markets, including registers of legal persons and of beneficial owners
- National registers of financial statements and equivalent statutory filings
- EU TED public-procurement portal and national tender registers
- EU sanctions lists, PEP lists, and insolvency registers
- Eurostat, ECB, and national statistics offices for region-level indicators
- Public company websites for officer names, contacts published by the company itself, and product information
We do not buy data from data brokers and we do not scrape closed social-media or private databases.
6. Recipients and subprocessors
We share personal data only with the EU-based subprocessors required to operate the service:
- Cloudflare - content delivery, DNS, and DDoS protection (EU data plane).
- Postmark - transactional email delivery for sign-ups, password resets, and notifications.
- Hetzner Online GmbH - primary hosting in Falkenstein, Germany.
Company descriptions and enriched data fields are generated by self-hosted language models running on EU infrastructure; no personal data is transmitted to any external model provider.
An up-to-date subprocessor list is available on request. We notify subscribers in advance of material changes.
7. International transfers
All production data is stored within the European Economic Area. We do not transfer personal data outside the EEA. If this changes, we will rely on Standard Contractual Clauses or another valid transfer mechanism and update this policy.
8. Retention
- Account data - for the lifetime of your account, then 30 days for backup rotation. Closed accounts are anonymised within 30 days.
- Billing records - 10 years, as required by Slovak Act 431/2002 on Accounting.
- Access and security logs - 24 months.
- Public-register data about company officers - for as long as the source register publishes it, plus 7 years for historical analysis (consistent with industry practice for credit-bureau and due-diligence products).
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have data erased where possible (Art. 17)
- Restrict or object to processing (Arts. 18, 21)
- Receive your data in a portable format (Art. 20)
- Lodge a complaint with a supervisory authority
The supervisory authority for Slovakia is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), Hraničná 12, 820 07 Bratislava.
To exercise any of these rights, file a request via /privacy-request or email privacy@amberbook.eu. We respond within 30 days. Where the law allows, we may extend this by up to two months for complex requests; we will tell you if we do.
If you appear in our records as a company officer or beneficial owner, our processing of that public-register data is based on Art. 6(1)(f) legitimate interest as a data provider. You can object via the same form; we evaluate every objection on its own merits, balancing your interests against the legitimate interests of our customers (due-diligence, KYC, AML, journalism, academic research). A successful objection results in your record being suppressed from default search results and, where applicable, anonymised.
Account holders also have two self-service tools: a one-click data download (Art. 15 + 20) and account deletion (Art. 17, 30-day grace) under Account → Privacy & data.
10. Security
We use industry-standard controls: TLS 1.3 in transit, encryption at rest, hashed passwords (bcrypt with per-user salt), least-privilege access, audit logging, and regular dependency patching. We do not currently hold a SOC 2 or ISO 27001 certification; we will update this policy if and when we obtain one.
12. Updates
We may update this policy as the product evolves. The "last updated" date at the top reflects the most recent change. Material changes will be announced by email and via an in-product notice.
13. Contact
Privacy enquiries: privacy@amberbook.eu
General support: support@amberbook.eu