Privacy Policy
Template notice
This is a working draft based on standard GDPR practice. Have it reviewed by qualified counsel before relying on it — laws and your exact data flows vary.
AmPhi Labs™ ("AmPhi Labs", "we", "us") is operated by Amphi Labs BV, Singel 542, 1017 AZ Amsterdam, Netherlands. We respect your privacy and handle personal data in line with the EU General Data Protection Regulation (GDPR).
What we collect
- Contact data you provide via our forms (name, email, company, your message and selected interests).
- Newsletter data (email address) when you subscribe.
- Technical data — aggregated, anonymised usage statistics collected by Cloudflare Web Analytics. This is cookieless: it sets no cookies, stores no identifiers on your device, and does not track you across sites or build a profile of you.
Why we use it (legal basis)
- To respond to your enquiry and provide our services — performance of a contract / your request.
- To send updates you asked for — your consent, withdrawable at any time.
- To improve and secure the site — our legitimate interest.
How long we keep it
We keep personal data only as long as needed for the purpose it was collected, or as required by law. Newsletter data is kept until you unsubscribe.
Who we share it with
We use a small number of trusted processors to run the site and our communications. Each acts only on our instructions and under appropriate safeguards (including EU Standard Contractual Clauses where data is processed outside the EEA). We never sell your data.
- Netlify — website hosting and form handling (your contact and newsletter form submissions are stored in Netlify Forms). Netlify, Inc. is US-based; transfers are covered by Standard Contractual Clauses.
- Cloudflare — cookieless, aggregated Web Analytics. No cookies or personal identifiers are set.
- Google (Google Workspace) — email. Messages you send us, and our replies, are processed through Google's mail servers.
- Resend — transactional email. When you submit a form, Resend delivers our notification and confirmation emails (using EU-based sending infrastructure). Resend, Inc. is US-based and certified under the EU-US Data Privacy Framework, with Standard Contractual Clauses as an additional safeguard.
Your rights
Under the GDPR you may request access, correction, deletion, restriction, or portability of your data, and object to certain processing. To exercise any right, email . You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Cookies
This website does not use cookies. We set no advertising, tracking, or analytics cookies, and we do not use third-party trackers. Our analytics (Cloudflare Web Analytics) is cookieless, and our hosting and forms (Netlify) do not set cookies for visitors. Because we store no information on your device and use no non-essential cookies, no cookie-consent banner is required under the GDPR and the ePrivacy Directive. If we ever introduce cookies that require consent, we will ask for it first and update this policy.
