Amblash.AI

Privacy Policy

1. INTRODUCTION

Welcome to Amblash.AI. Amblash.AI is a proprietary software-as-a-service platform owned and operated by Adforn LLC, a company registered at Wilmington, DE 19801 ("Adforn LLC," "we," "us," "our," or "Company"). This Privacy Policy explains how we collect, use, disclose, and protect information about you when you access or use our website at https://amblash.ai (the "Website") and our B2B sales email automation software-as-a-service platform, powered by advanced machine learning and artificial intelligence (collectively, the "Services").

We are committed to protecting your privacy and ensuring the security of your personal data in accordance with applicable United States privacy laws. Where applicable, we also honor the protections of the General Data Protection Regulation (GDPR) for users located in the European Union or European Economic Area, and the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents.

By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Privacy Policy, you must not use our Services.

2. DEFINITIONS

For the purposes of this Privacy Policy:

  • "Adforn LLC," "Company," "Amblash.AI," "we," "us," or "our" means Adforn LLC, a company registered at Wilmington, DE 19801, which owns and operates the Amblash.AI platform (Amblash.AI is a trading name of Adforn LLC, not a separate legal entity).
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, or deletion.
  • "Data Controller" means the entity that determines the purposes and means of Processing Personal Data. Adforn LLC, operating as Amblash.AI, is the Data Controller for Personal Data collected through the Services.
  • "Data Subject" means an individual whose Personal Data is being Processed.
  • "Services" means the Amblash.AI platform, including the Website and all associated features and functionality, powered by advanced machine learning and artificial intelligence.

3. INFORMATION WE COLLECT

We practice data minimization and collect only the information necessary to provide and improve our Services.

3.1 Information You Provide Directly

When you register for an account or use our Services, we collect:

  • Email Address: Used for account creation, authentication, service communications, and customer support.
  • Name: Your first name and last name for account identification and personalization.
  • Company Data: Including company name, website URL, industry classification, and company size for service functionality and customization.

3.2 Information Collected Automatically

When you access our Services, we may automatically collect:

  • Technical Information: IP address, browser type, device identifiers, operating system, and access times.
  • Usage Information: Information about how you interact with our Services, including features used and actions taken.
  • Cookies and Similar Technologies: We use cookies and similar tracking technologies as described in our Cookie Policy.

3.3 Information We Do NOT Collect

We explicitly do NOT collect or store:

  • Credit card or debit card information (all payment processing is handled securely by Stripe)
  • Sensitive personal data such as health information, biometric data, or government identification numbers

4. HOW WE USE YOUR INFORMATION

We Process your Personal Data for the following purposes:

4.1 Service Delivery

  • To create and manage your account
  • To provide access to our B2B sales email automation platform, powered by advanced machine learning and artificial intelligence
  • To process and fulfill your subscription
  • To authenticate your identity and prevent unauthorized access
  • To provide customer support and respond to your inquiries

4.2 Service Improvement

  • To analyze usage patterns and improve our Services
  • To develop new features and functionality
  • To conduct research and analytics regarding service performance

4.3 Communication

  • To send transactional emails related to your account and service usage
  • To provide important updates regarding our Services
  • To respond to your questions and requests

4.4 Legal and Security

  • To comply with legal obligations and respond to lawful requests
  • To detect, prevent, and address fraud, security issues, or technical problems
  • To enforce our Terms of Service and protect our rights and property

4.5 Business Operations

  • To process payments through our payment processor
  • To maintain business records and conduct internal accounting
  • To assess and improve our business operations

5. LEGAL BASIS FOR PROCESSING (EU/EEA USERS)

For users located in the European Union or European Economic Area, GDPR requires us to identify a legal basis for Processing. We Process your Personal Data based on the following legal grounds:

5.1 Contractual Necessity (Article 6(1)(b) GDPR)

Processing is necessary for the performance of our contract with you, including providing the Services you have subscribed to.

5.2 Legitimate Interests (Article 6(1)(f) GDPR)

Processing is necessary for our legitimate business interests, including:

  • Improving and optimizing our Services
  • Ensuring security and preventing fraud
  • Analyzing service usage and performance
  • Conducting business operations

We conduct balancing tests to ensure our legitimate interests do not override your fundamental rights and freedoms.

5.3 Legal Obligation (Article 6(1)(c) GDPR)

Processing is necessary to comply with legal obligations, including tax, accounting, and regulatory requirements.

5.4 Consent (Article 6(1)(a) GDPR)

Where required, we obtain your explicit consent before Processing your Personal Data. You may withdraw consent at any time without affecting the lawfulness of Processing based on consent before its withdrawal.

6. DATA RETENTION

We retain your Personal Data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

6.1 Active Accounts

Personal Data associated with active accounts is retained for the duration of your subscription and as long as your account remains active.

6.2 Closed Accounts

Deleting your account is final from the moment you request it. Only the account owner may delete the account; an invited team member cannot. Requesting deletion closes the account immediately: you are signed out on every device, and nobody on your workspace can sign back in. A deletion request cannot be withdrawn. It cannot be stopped by you, by anyone else on your workspace, or by our support team, and there is no route by which an account returns from a pending deletion to a normal one.

Closing the account and removing the data are two separate moments. Nothing is removed at the moment you make the request. Your data is removed at the end of your current subscription period, if one is still running, or thirty days after you request the deletion, whichever comes first. The removal runs unattended, overnight, and once it has run it is permanent and cannot be undone. No minimum notice period sits beneath this: where your subscription period ends sooner, your data is removed sooner, and where more than thirty days of a period you have already paid for remain, your data is removed before that period ends.

The time between your request and that date is a scheduled wait, not a grace period. It is not a period in which the deletion can still be stopped or the account recovered, by any route or on any request. The decision is already made and the date is already set; the wait exists only so that the removal lands at the end of a paid period rather than inside one.

Deletion reaches the whole workspace: your own Personal Data, the company record, and every colleague's account on that workspace are removed together. Billing history and invoices are retained for tax and legal compliance, including the corresponding records held by our payment processor, Stripe, in its own systems; everything else is removed.

Following account closure or termination, we retain Personal Data for:

  • Legal Compliance: As required by applicable laws, including U.S. federal and state tax and accounting regulations
  • Dispute Resolution: As necessary to resolve disputes or enforce our agreements
  • Fraud Prevention: To prevent fraudulent activities and maintain security

After the retention period expires, we securely delete or anonymize your Personal Data in accordance with our data retention schedule and applicable legal requirements.

7. DATA TRANSFERS

7.1 Primary Data Location

Your Personal Data is primarily processed and stored in the United States, where our infrastructure is located.

7.2 International Transfers

If you are located in the European Union or European Economic Area (EEA), using our Services involves transferring your Personal Data to the United States. When such transfers occur, we rely on appropriate safeguards to ensure your Personal Data continues to receive a comparable level of protection, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission, where applicable
  • Other legally compliant transfer mechanisms under GDPR Chapter V

Our third-party service providers that may process data include:

  • Stripe: Payment processing services
  • Amazon Web Services (AWS): Cloud hosting infrastructure

8. DATA SHARING AND DISCLOSURE

8.1 No Sale or Sharing

We do NOT sell, rent, or share your Personal Data with third parties for their marketing purposes. We do NOT share your data with affiliates or other companies except as explicitly described in this Privacy Policy.

8.2 Service Providers

We share Personal Data only with trusted third-party service providers who assist us in operating our Services:

  • Stripe: For secure payment processing. Stripe processes payment information in accordance with their privacy policy and PCI-DSS compliance standards.
  • Amazon Web Services (AWS): For cloud hosting and infrastructure services. AWS processes data in accordance with their data processing agreements and GDPR commitments.

These service providers are contractually obligated to:

  • Process Personal Data only as necessary to provide their services
  • Implement appropriate security measures
  • Comply with GDPR and applicable data protection laws
  • Not use Personal Data for their own purposes

8.3 Legal Requirements

We may disclose Personal Data when required by law, including:

  • In response to valid legal processes (subpoenas, court orders, or government requests)
  • To comply with applicable laws and regulations
  • To protect the rights, property, or safety of Amblash.AI, our users, or the public
  • To enforce our Terms of Service or investigate potential violations

8.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, Personal Data may be transferred to the successor entity, subject to the same privacy protections described in this Privacy Policy.

9. DATA SECURITY

We implement appropriate technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction.

9.1 Security Measures

Our security measures include:

  • Encryption: Data transmission is encrypted using industry-standard TLS/SSL protocols
  • Access Controls: Role-based access controls and authentication mechanisms
  • Infrastructure Security: Secure cloud hosting with AWS, including network security, firewalls, and monitoring
  • Regular Security Assessments: Periodic security audits and vulnerability assessments
  • Employee Training: Security awareness training for personnel with access to Personal Data
  • Incident Response: Procedures for detecting, responding to, and reporting security incidents

9.2 Limitation of Security

While we strive to protect your Personal Data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, and you acknowledge that you provide Personal Data at your own risk.

9.3 Data Breach Notification

In the event of a Personal Data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33 and 34.

10. CHILDREN'S PRIVACY

Our Services are not intended for individuals under the age of 18. We do not knowingly collect Personal Data from children under 18. If you are under 18, you must not use our Services or provide any information to us.

If we become aware that we have collected Personal Data from a child under 18 without parental consent, we will take steps to delete such information promptly. If you believe we have collected information from a child under 18, please contact us immediately.

11. YOUR RIGHTS UNDER GDPR (EU/EEA USERS)

If you are located in the European Union or European Economic Area, you have the following rights under GDPR regarding your Personal Data:

11.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether your Personal Data is being Processed and, if so, to access that data and receive information about the Processing.

11.2 Right to Rectification (Article 16 GDPR)

You have the right to request correction of inaccurate Personal Data and to complete incomplete Personal Data.

11.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request deletion of your Personal Data under certain circumstances, including:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for Processing
  • You object to Processing and there are no overriding legitimate grounds
  • The data has been unlawfully Processed
  • Deletion is required to comply with a legal obligation

This right is subject to exceptions, including legal obligations to retain data.

11.4 Right to Restriction of Processing (Article 18 GDPR)

You have the right to request restriction of Processing under certain circumstances, including when you contest the accuracy of the data or object to Processing.

11.5 Right to Data Portability (Article 20 GDPR)

You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

11.6 Right to Object (Article 21 GDPR)

You have the right to object to Processing based on legitimate interests or for direct marketing purposes.

11.7 Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR)

You have the right not to be subject to decisions based solely on automated Processing, including profiling, which produces legal effects or similarly significantly affects you.

11.8 Right to Withdraw Consent

Where Processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of Processing based on consent before withdrawal.

11.9 Right to Lodge a Complaint

If you are located in the EU/EEA, you have the right to lodge a complaint with your local data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

11.10 Exercising Your Rights

To exercise any of these rights, please contact us. We will respond to your request within one month of receipt, or within two months for complex requests. We may request additional information to verify your identity before processing your request.

12. CALIFORNIA PRIVACY RIGHTS (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

12.1 Right to Know

You have the right to know what Personal Data we collect, use, disclose, and sell (though we do not sell Personal Data).

12.2 Right to Delete

You have the right to request deletion of Personal Data we have collected from you, subject to certain exceptions.

12.3 Right to Opt-Out

You have the right to opt-out of the sale of Personal Data. We do NOT sell Personal Data.

12.4 Right to Non-Discrimination

You have the right not to receive discriminatory treatment for exercising your CCPA rights.

To exercise your CCPA rights, contact us.

13. INTERNATIONAL USERS

Our Services are operated from the United States, and our data processing practices comply with applicable U.S. privacy laws, as well as GDPR for EU/EEA users and CCPA/CPRA for California residents. If you access our Services from outside the United States, you acknowledge that your Personal Data will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction.

By using our Services, you consent to the transfer and Processing of your Personal Data in accordance with this Privacy Policy and applicable law.

14. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to enhance your experience, analyze usage, and improve our Services. For detailed information about the cookies we use and your choices regarding cookies, please refer to our Cookie Policy available on our Website.

You can control cookies through your browser settings and other tools. However, disabling cookies may affect your ability to use certain features of our Services.

15. THIRD-PARTY LINKS

Our Services may contain links to third-party websites or services that are not operated by us. This Privacy Policy does not apply to third-party websites or services. We are not responsible for the privacy practices of third parties, and we encourage you to review their privacy policies before providing any Personal Data.

16. CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this Privacy Policy at any time. Changes will be effective immediately upon posting the updated Privacy Policy on our Website with a new "Last Updated" date.

We will notify you of material changes through:

  • Email notification to the email address associated with your account
  • Prominent notice on our Website
  • In-app notification when you next access our Services

Your continued use of our Services after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you must discontinue use of our Services and may request account closure.

17. CONTACT INFORMATION

For questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Amblash.AI, operated by Adforn LLC

Registered address: 1007 Orange St, Wilmington, DE 19801

Email: hello@amblash.ai

Contact us: contact us page

Website: https://amblash.ai

We will respond to all legitimate inquiries within a reasonable timeframe, typically within 30 to 40 business days.


Governing Language: This Privacy Policy is written in English. If this Privacy Policy is translated into other languages, the English version shall prevail in case of any inconsistencies or discrepancies.

Severability: If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

Entire Agreement: This Privacy Policy, together with our Terms of Service, constitutes the entire agreement between you and Adforn LLC (operating as Amblash.AI) regarding the privacy and protection of your Personal Data when using our Services.


Effective Date: September 01, 2026

Last Updated: April 01, 2026

© 2024–2026 Amblash.AI. All rights reserved. Powered by Adforn LLC.