Privacy Policy
Effective Date: August 22, 2026 · Last Updated: August 22, 2026
01 Who we are, and what this Policy covers
Ampersand Labs, Inc. (“Ampersand,” “we,” “us,” or “our”) is a Delaware corporation with offices at 799 Broadway, New York, NY 10003. We build continuous process mining software: our Companion application observes how work is actually performed on the devices a business customer places in scope, and turns that activity into process maps, timings, and structured findings.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices available to you.
Ampersand’s business is enterprise software. Most of the personal information our software touches is not ours — it belongs to our customers, and we handle it on their instructions. Section 2 explains that distinction, because it determines who you should contact about your information and what rights you have.
This Policy applies to
- our websites, including withampersand.ai and any subdomains (the “Site”);
- our sales, marketing, events, and support activities;
- administrative and account data relating to the individuals who administer, purchase, or are authorized to use our products; and
- evaluation, demonstration, and self-serve access to our products.
This Policy does not govern
- Customer Data — the activity data, screen captures, documents, and derived analysis that the Ampersand Companion application and platform process on behalf of a business customer. That processing is governed by our agreement with that customer and by our Data Processing Addendum, and is described in Section 4 below for transparency;
- our own employment and candidate data, which is covered by a separate notice provided to applicants and personnel; or
- third-party websites or services we link to.
02 Our two roles: controller and processor
We are a controller — we decide why and how information is processed — for information we collect through the Site, through sales and marketing, through support, and for the account and administrative records of the people who use or administer our products. Sections 3, 6, 7, 8, and 13 describe that processing.
We are a processor (a “service provider” under US state privacy laws) for the data our software observes and processes on a customer’s systems and devices. Our business customer is the controller. It decides which of its personnel are in scope, which applications are recorded, what is excluded, and how long data is kept. We act on that customer’s documented instructions.
If you are an employee, contractor, or other member of a customer’s workforce whose work activity was observed by Ampersand software: your employer — not Ampersand — determines that processing and is responsible for notifying you about it and for honoring your rights. Please direct requests to your employer. We will support them in responding, as our agreement with them requires. If you contact us directly, we will refer you to your employer and let them know, unless the law requires otherwise.
03 Information we collect as a controller
Information you give us
| Category | Examples |
|---|---|
| Identifiers and contact data | Name, business email address, telephone number, employer, job title, mailing address |
| Account and authentication data | User ID, workspace or organization identifier, single sign-on identifiers, role and permission assignments, authentication events |
| Commercial data | Products and services inquired about or purchased, order and invoice records, billing contact details |
| Communications | Emails, support tickets, meeting notes, and demonstration or call recordings where we have told you a call is being recorded and, where required, obtained consent |
| Event and marketing data | Registration details, preferences, and marketing responses |
Information collected automatically on the Site
Device and browser type, operating system, language, referring and exit pages, pages viewed and time on page, approximate location derived from IP address, and the IP address itself. We collect this using cookies and similar technologies. See Section 8.
Information from third parties
Business contact and firmographic data from providers and public sources; referral information from partners; authentication assertions from your identity provider when you sign in through single sign-on; and payment confirmations from our payment processor. We do not receive or store full payment card numbers.
We do not knowingly collect sensitive or special-category personal information through the Site or our sales process, and we ask that you not submit any. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit its use under US state law.
04 How the Ampersand Companion application handles data
We describe this here even though we handle this data as a processor, because the honest description matters more than the legal category.
The Companion desktop application observes how work is performed on the devices a customer places in scope. In a typical deployment, the software is installed into a cloud environment inside the customer’s own organization, and the resulting data stays there.
What the application captures
Subject to an on-device exclusion gate, and with personal information scrubbed from extracted text on the device before that text leaves the device:
- screenshots of the screen within the applications on the customer’s agreed recording allowlist;
- which application is in focus, and for how long;
- the active window title;
- the host of the active browser tab — the site, not the full URL;
- the fact and on-screen location of clicks, and the fact that a keypress occurred; and
- on-screen accessibility content and interface element labels.
What the application does not capture
- alphanumeric keys typed — the application records that a keypress occurred, not which characters were entered;
- content within secure fields, such as password entries;
- content behind the customer’s exclusion list — for example banking, health, brokerage, and password-manager windows;
- DRM-protected, streaming, or remote-desktop windows;
- raw audio, which never leaves the device; or
- anything at all while the user is signed out.
Controls
Each user sees an indicator when recording is active and can pause or stop capture and limit the portion of the screen in scope. The customer controls which users, machines, applications, and time periods are subject to capture, and may pause, exclude, or stop capture at any time. Every application excluded from capture is logged, together with the reason.
What we do with it
We turn the observed activity into process maps, timings, and structured findings, and make those available to the customer through a dashboard and an MCP interface. We use it for no other purpose.
Where it lives
In the customer’s own isolated cloud environment, in the region the customer selects (default AWS us-east-1). We do not process or store this data outside the United States without the customer’s prior written consent.
Within the recording allowlist, captured material will include the customer’s own business content — the documents and work product visible on screen. Where a customer operates in a regulated or privileged setting, the material captured may include privileged, client-confidential, or otherwise regulated content by design. We treat all of it as the customer’s confidential information, use it only to perform the services, and return or securely destroy it at the customer’s direction.
05 We do not train models on customer data
We do not use Customer Data — including in de-identified, aggregated, or anonymized form — to train, fine-tune, or improve any artificial intelligence or machine learning model, whether our own or a third party’s, without the customer’s prior written authorization.
Model inference runs in the customer’s own cloud account on Amazon Bedrock. Inference inputs are not used to train Anthropic’s models or any other third party’s models.
We may use aggregate operational metrics that contain no personal information and no customer content — for example, error rates, latency, and feature-usage counts — to operate and improve the service.
06 Why we use information, and our legal bases
Where the EU or UK GDPR applies to our processing as a controller:
| Purpose | Legal basis |
|---|---|
| Providing, securing, and supporting the Site and our products | Performance of a contract; legitimate interests in operating and securing our services |
| Responding to inquiries and providing customer support | Performance of a contract; legitimate interests |
| Sales, marketing, and events | Consent where required; otherwise legitimate interests in promoting our business to other businesses |
| Billing, collections, and financial record-keeping | Performance of a contract; legal obligation |
| Product analytics and improvement of the Site | Consent for non-essential cookies; otherwise legitimate interests |
| Security monitoring, fraud prevention, and incident response | Legitimate interests; legal obligation |
| Legal compliance, regulatory response, and establishing or defending legal claims | Legal obligation; legitimate interests |
| Corporate transactions | Legitimate interests |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights. You may ask us for details of that assessment.
07 How we share information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under US state privacy laws. We have not done so in the preceding twelve months. We do not sell or share the personal information of anyone we know to be under 16.
We disclose personal information to:
- Service providers and subprocessors who process on our behalf under written contract — cloud hosting and infrastructure, model inference, identity and authentication, network security, customer relationship management, support tooling, billing, and analytics. Our current list of subprocessors for Customer Data is maintained in our Data Processing Addendum and is available on request from privacy@withampersand.ai.
- Professional advisors — lawyers, auditors, accountants, and insurers, under duties of confidentiality.
- Authorities and other parties, where we believe in good faith that disclosure is required by law, necessary to protect rights or safety, or necessary to enforce our terms. Where we may lawfully do so, we will notify the affected customer before disclosing their data and will assert all applicable protections on their behalf.
- An acquirer, in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to the acquirer’s continued compliance with this Policy for information collected before the transaction.
- At your direction, or with your consent.
08 Cookies, analytics, and opt-out signals
The Site uses strictly necessary cookies, required for the Site to function and for security; functional cookies, which remember your preferences; and analytics cookies, which help us understand how the Site is used.
Where required by law, we ask for your consent before setting non-essential cookies and give you a way to change that choice at any time through our cookie preferences control. You can also block or delete cookies through your browser, though parts of the Site may not work correctly as a result.
Opt-out preference signals. We honor Global Privacy Control and other browser-based opt-out preference signals as a valid opt-out request under applicable US state law. Because we do not sell or share personal information, receiving such a signal does not change how we handle your information, but we honor it regardless.
Do Not Track. There is no common industry standard for responding to browser “Do Not Track” signals, and we do not currently respond to them. We do honor Global Privacy Control as described above.
09 Retention
We keep personal information for as long as needed for the purpose it was collected, and then delete or de-identify it. In practice:
| Data | Typical retention |
|---|---|
| Prospect and marketing contact data | Until you opt out, or after 24 months of no engagement |
| Account and authentication records | For the term of the customer relationship, plus 12 months |
| Billing and financial records | 7 years, as required by tax and accounting rules |
| Support communications | 24 months after resolution |
| Site analytics | 14 months |
| Security and audit logs | 12 months, unless a longer period is needed for an investigation |
| Customer Data | As the customer instructs. At the customer’s written direction we delete or return it within ten (10) days of the request and certify that in writing. We retain no archival copy of any screen recording or session capture. |
We may retain information longer where a legal hold, an investigation, or a legal obligation requires it. We maintain de-identified information in de-identified form and do not attempt to re-identify it, except as required by law.
10 Security
We maintain technical and organizational measures designed to protect personal information, including per-customer isolation of Customer Data, on-device minimization before upload, TLS 1.2 or higher in transit, AES-256 at rest, single sign-on with organization-level multi-factor authentication, least-privilege access, audited administrative access through a break-glass process, and centralized audit logging in a separate account that no workload can overwrite.
We state our posture plainly and do not claim certifications we have not yet earned. Our SOC 2 Type II examination is in progress and is not yet complete; a SOC 2 report is not yet available. Our current security measures, and the items still on our roadmap, are set out in full in Annex 3 to our Data Processing Addendum, which we provide to customers and prospective customers on request.
No system is perfectly secure. If a breach affecting personal information occurs, we will notify affected customers without undue delay and in any event within forty-eight (48) hours, and will notify individuals and regulators where the law requires.
To report a suspected vulnerability, write to security@withampersand.ai. We will acknowledge your report and will not pursue legal action for good-faith research conducted in accordance with our published guidance.
11 International transfers
We are based in the United States and process personal information there.
Customer Data is stored in the region the customer selects and is not processed or stored outside the United States without the customer’s prior written consent.
For controller-level information transferred from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, an applicable adequacy decision, or another lawful transfer mechanism. You may request a copy of the relevant safeguards using the contact details in Section 17.
12 Automated decision-making and profiling
As a controller, we do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, and we do not engage in profiling for targeted advertising.
As a processor, our software produces analytical outputs about how work is performed. Those outputs are estimates derived from observed activity. Our customer agreements state that they are not to be used as the sole basis for any employment, disciplinary, compensation, or legal decision, and that a customer deploying our software is responsible for the notices and consents its own law requires. How a customer uses those outputs is the customer’s decision and its responsibility, and any rights you have in respect of that use are exercised against the customer as controller.
13 Your privacy rights
If you are in the EEA, the UK, or Switzerland, you may request access to your personal information; correction of inaccurate data; erasure; restriction of processing; portability; and you may object to processing based on legitimate interests, including direct marketing. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. You may lodge a complaint with your supervisory authority.
If you are a resident of a US state with a comprehensive privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as they take effect — see Section 14.
How to exercise a right. Email privacy@withampersand.ai. We will verify your identity in proportion to the sensitivity of the request, usually by confirming control of the email address on file. An authorized agent may submit a request on your behalf with written authorization we can verify. We respond within the time the applicable law requires — generally 30 days under EU and UK law and 45 days under US state laws, each extendable where permitted. We will not discriminate against you for exercising any of these rights.
Requests about Customer Data go to our customer, not to us. See the notice in Section 2.
14 Additional disclosures for US state residents
This section supplements the rest of this Policy and serves as our notice at collection under California law.
Categories of personal information we collect and disclose
Over the preceding twelve months, as a controller we have collected the following statutory categories. We disclose each of them for a business purpose to the recipients described in Section 7. We do not sell any of them and do not share any of them for cross-context behavioral advertising.
| Statutory category | What it includes for us | Where it comes from | Retention |
|---|---|---|---|
| Identifiers | Name, business email, telephone, postal address, IP address, account and workspace identifiers | You; your employer; your identity provider; business data providers | Per Section 9 |
| Customer records (Cal. Civ. Code 1798.80) | Name, contact details, and billing contact information | You; your employer | 7 years for billing records |
| Commercial information | Products inquired about or purchased, order and invoice records | You; our billing processor | 7 years |
| Internet or network activity | Pages viewed, time on page, referring and exit pages, browser and device data, authentication events | Cookies and similar technologies; our systems | 14 months for analytics; 12 months for logs |
| Geolocation data | Approximate location derived from IP address only. We do not collect precise geolocation | Cookies and similar technologies | 14 months |
| Professional or employment information | Employer, job title, role and permission assignments | You; your employer; business data providers | Term of relationship, plus 12 months |
| Audio and visual information | Demonstration and support call recordings, where we have given notice and, where required, obtained consent | You | 24 months |
| Sensitive personal information | None. We do not knowingly collect it and do not use or disclose it for purposes that would trigger a right to limit | Not applicable | Not applicable |
| Inferences | None. We do not draw inferences from this information to create a profile about you | Not applicable | Not applicable |
Your rights
Subject to verification and to the exceptions in your state’s law, you may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients; request deletion; request correction; obtain a portable copy; and opt out of sale, of sharing for cross-context behavioral advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in any of those three activities, so there is nothing to opt out of, but you may still submit a request and we will confirm that in writing.
Appeals. If we deny your request, you may appeal by replying to our decision or writing to privacy@withampersand.ai with “Privacy Appeal” in the subject line. We will respond within the period your state’s law allows and, if we deny the appeal, will tell you how to contact your state attorney general.
15 Children
Our products and Site are for business use and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
16 Changes to this Policy
We may update this Policy. When we do, we will change the “Last Updated” date above. If a change materially affects how we handle personal information, we will provide notice — by email to account administrators, by a notice on the Site, or both — before it takes effect. Continued use of the Site or our products after a change takes effect means you accept the updated Policy.
17 How to contact us
Ampersand Labs, Inc.
799 Broadway, New York, NY 10003, United States
- Privacy and rights requests: privacy@withampersand.ai
- Security and vulnerability disclosure: security@withampersand.ai
- Legal notices: legal@withampersand.ai
This Policy does not create rights beyond those provided by applicable law, and does not modify the terms of any written agreement between Ampersand and a business customer. Where such an agreement conflicts with this Policy as to Customer Data, that agreement controls.