1. Introduction
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and Ambigroup Services Ltd (“Ambicast”) and applies where Ambicast processes personal data on the Customer’s behalf in the course of providing the Service.
It reflects the requirements of the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”). Where the Customer is a data controller and Ambicast acts as a data processor, this DPA governs that relationship.
2. Roles of the parties
For personal data processed to deliver the Service on the Customer’s instructions (such as end-user or audience data the Customer chooses to display or collect), the Customer is the controller and Ambicast is the processor. For data Ambicast processes to run its business (such as Customer account and billing data), Ambicast is the controller and its Privacy Policy applies.
3. Subject-matter and details of processing
- Subject-matter: provision of the Ambicast digital-signage Service.
- Duration: the term of the Customer’s subscription, plus deletion periods below.
- Nature and purpose: hosting, storing, transmitting and displaying content and related data to operate the Service.
- Types of data: as determined by the Customer — typically account identifiers, content, and technical/usage data. The Customer should not upload special-category data unless expressly agreed.
- Data subjects: the Customer’s staff and any individuals whose data the Customer chooses to process through the Service.
4. Ambicast’s obligations
- Process personal data only on the Customer’s documented instructions, including as set out in the Terms and this DPA, unless required by law (in which case we will inform the Customer unless legally prohibited).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see section 6).
- Assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification and impact-assessment obligations.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
5. Sub-processors
The Customer provides general authorisation for Ambicast to engage the sub-processors listed on our Sub-processors page. Ambicast imposes data-protection obligations on each sub-processor no less protective than those in this DPA, and remains responsible for their performance. We will update the sub-processors page when we make material changes and, on request, notify Customers with a signed DPA so they may object on reasonable data-protection grounds.
6. Security measures
- Data hosted on AWS in the AWS eu-west-2 (London) region, with encryption of data in transit (HTTPS/TLS).
- Media stored in private object storage accessible only via time-limited signed URLs.
- Passwords stored only as salted hashes; authentication handled by a managed identity provider.
- Role- and organisation-scoped access controls, and least-privilege administrative access.
- Logging and application error monitoring to detect and investigate issues.
7. Personal-data breaches
Ambicast will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s data, and will provide information reasonably available to help the Customer meet its own notification obligations under Data Protection Law.
8. International transfers
Where processing involves a transfer of personal data outside the UK/EEA, the parties will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or reliance on an adequacy decision.
9. Return and deletion
On termination of the Service, and at the Customer’s choice, Ambicast will delete or return the Customer’s personal data, and delete existing copies unless retention is required by law. Content is made available for export for a reasonable period before deletion, consistent with the retention periods in our Privacy Policy.
10. Audits
Ambicast will make available information necessary to demonstrate compliance and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, subject to confidentiality and to not compromising the security of other customers.
11. Requesting a signed copy
Business customers who require a countersigned DPA should contact privacy@ambicast.tv. This online DPA applies by default to all Customers using the Service in a controller-processor capacity.
Questions about this document? Email privacy@ambicast.tv.