Role
Amanect acts as a data controller for personal data processed to deliver its verification and platform services. Where Amanect processes personal data on behalf of a business customer (for example, employee contacts on a Strategic Member engagement), Amanect may act as a processor under a written DPA.
Sub-processors
Amanect relies on the following categories of sub-processors:
- Cloud hosting and database (EU region).
- Email delivery and support ticketing.
- Authentication and identity management.
- Payment processing (PCI-DSS certified provider).
- Sanctions and adverse-media screening providers.
- Product analytics (privacy-respecting).
A current list with legal entity names and locations is available on request from privacy@amanect.com.
International transfers
Where sub-processors are located outside the EEA, Amanect relies on European Commission adequacy decisions where available, and otherwise on Standard Contractual Clauses (2021/914) with additional safeguards where required.
Data Processing Agreement (DPA)
Business customers may request Amanect’s standard DPA by writing to privacy@amanect.com. The DPA reflects Art. 28 GDPR requirements.
Security
Encryption in transit, role-based access controls, least-privilege administration, audit logging, incident-response procedures and staff confidentiality obligations.
Breach notification
Amanect will notify affected customers without undue delay and no later than 72 hours after becoming aware of a personal data breach, as required by Art. 33 GDPR.
Contact
Data protection queries: privacy@amanect.com. Supervisory authority: Polish Personal Data Protection Office (UODO), uodo.gov.pl.
This page is maintained by Amanect (operated as a private beta project by Amanect Sp. z o.o., in formation, Wrocław, Poland) to help visitors understand our operating practices. It is provided for general information only and does not constitute legal advice. Users should seek independent legal counsel for their own circumstances. Contact: hello@amanect.com.