Who we are
Amoreg is operated by Amoreg Limited, a company registered in Guernsey under company number 74168. Our registered office is Fairbairn House, Level 5, Rohais, St Peter Port, Guernsey GY1 1FE.
For privacy questions and data-rights requests, contact us at amir@amoreg.com.
When we are controller or processor
Amoreg Limited is the controller for personal data we collect and decide how to use, including public website visits, sales enquiries, account administration, security logs, billing administration, and support communications.
For customer content processed inside an Amoreg workspace, we generally act as processor or service provider for the customer organization. The customer remains responsible for deciding what personal data is uploaded, connected, searched, retained, exported, or deleted in that workspace, subject to the customer agreement or data processing terms that apply.
Personal data we handle
Depending on how you use Amoreg, we may handle:
- Contact details, such as name, work email, organization, role, and communication preferences.
- Account and authentication data, such as user identifiers, organization membership, roles, session metadata, and sign-in events.
- Workspace content submitted by customers, such as policies, controls, regulatory notes, evidence files, prompts, chat messages, generated outputs, and related metadata.
- Usage, diagnostic, and security data, such as pages visited, device/browser details, IP address, request logs, audit events, error traces, and product interaction data.
- Commercial and support data, such as subscription, billing, contract, invoice, support, scheduling, and customer success records.
- Cookie and analytics data from our public website and product surfaces.
Customers should avoid uploading unnecessary special category, criminal offence, payment card, or other highly sensitive personal data unless they have confirmed that the workspace and their agreement support that processing.
Purposes and legal bases
We use personal data for the following purposes:
- Providing, securing, maintaining, and improving Amoreg.
- Creating accounts, authenticating users, managing organization access, and supporting customer workspaces.
- Processing customer-submitted content under the customer's instructions.
- Responding to enquiries, support requests, demos, contract administration, and service communications.
- Monitoring availability, abuse, fraud, and security risk.
- Meeting legal, regulatory, accounting, tax, and corporate record obligations.
- Understanding public website performance and the effectiveness of product communications.
Where Amoreg Limited is controller, we rely on contract performance, legitimate interests, legal obligations, and consent where required. Where we process customer workspace content as processor, we process it on the customer's documented instructions and under the relevant customer agreement or data processing terms.
Subprocessors and third parties
We use subprocessors and service providers to operate Amoreg. These may include providers for:
- Cloud hosting, compute, deployment, and content delivery.
- Authentication, session management, and user administration.
- Databases, object storage, vector storage, queues, and observability.
- AI model providers and retrieval infrastructure used to answer customer requests.
- Email, support, scheduling, analytics, billing, and customer communications.
- Security monitoring, logging, backup, and incident response support.
We require these providers to process personal data only for the services they provide to us and to apply appropriate security and confidentiality measures. Customer agreements or data processing terms may provide more specific subprocessor commitments for customer workspace processing.
International transfers
Amoreg Limited is established in Guernsey and uses infrastructure and subprocessors that may process personal data in Guernsey, the United Kingdom, the European Economic Area, the United States, and other locations where our providers operate.
We do not claim EU-only processing. Some retrieval infrastructure currently uses Pinecone infrastructure associated with AWS us-east-1, while an EU migration is in progress. Where personal data is transferred internationally, we use appropriate safeguards such as adequacy decisions, contractual protections, data processing terms, and operational controls as applicable.
Retention
We keep personal data only for as long as needed for the purposes described above, unless a longer period is required for legal, regulatory, security, audit, dispute, tax, accounting, or business continuity reasons.
Customer workspace content is retained according to the customer's configuration, agreement, and deletion instructions, subject to backup, audit, legal, and security retention windows. Security logs and diagnostic records are retained for limited periods appropriate to investigation, reliability, and abuse-prevention needs.
Security
We use administrative, technical, and organizational safeguards designed to protect personal data. These include access controls, organization-scoped authorization checks, encryption in transit, managed cloud infrastructure, logging, backup controls, dependency monitoring, secret scanning, and operational review.
No system is completely secure. This notice does not claim that Amoreg has completed SOC 2 certification, an independent penetration test, database row-level security, or any other control unless expressly stated in a separate executed agreement or current security documentation.
Cookies and analytics
Our website and product may use cookies, local storage, and similar technologies to keep sessions working, remember preferences, measure website usage, understand product performance, and protect the service.
Some cookies are necessary for authentication, security, load balancing, or requested functionality. Analytics and scheduling tools may set additional cookies or collect usage information when enabled. Browser controls can block or delete cookies, but some parts of the service may stop working correctly.
Your rights
Subject to applicable law and any limits that apply, you may have rights to:
- Access personal data about you.
- Correct inaccurate or incomplete data.
- Request erasure.
- Restrict or object to processing.
- Request data portability.
- Withdraw consent where processing is based on consent.
- Object to direct marketing.
- Complain to a supervisory authority.
If your data is inside a customer workspace, we may need to direct your request to the customer organization because they control that workspace processing. We will still help route or support the request where appropriate.
Complaints
Please contact us first at amir@amoreg.com so we can review and respond.
You may also complain to the Office of the Data Protection Authority in Guernsey, the Bailiwick's independent supervisory authority for data protection. The ODPA publishes complaint guidance at odpa.gg/individuals/make-complaint and contact details at odpa.gg/contact. Its listed contact details include info@odpa.gg, +44 (0)1481 742074, and Block A, Lefebvre Court, Lefebvre Street, St Peter Port, GY1 2JP.
Changes to this notice
We may update this notice as Amoreg, our providers, our infrastructure, or legal requirements change. The last-updated date above shows when this public notice was most recently changed.