Authentication
Amplify utilizes services provided by Auth0 for authentication - more information on the service is available at https://auth0.com/docs.
Data protection compliance documentation for Auth0 is available at https://auth0.com/docs/secure/data-privacy-and-compliance/gdpr.
Customer information
Login data, username, and password, for users are handled and stored by Auth0. Every transaction, confirming a login, is handled by Auth0. The user roles, and the level of access a user has in Amplify, is also stored in Auth0.
For information on the organisations and users, Amplify uses the services of Stripe. Stripe is primarily a payment and invoicing service and contains all information needed to invoice and charge Amplify clients. The data stored in Stripe includes addresses, phone numbers, emails, VAT/Tax related information, payment/credit-card information, and information on the primary owner of the organisations account in Amplify.
For more information on Stripe in general, please go to https://stripe.com/.
To utilize the information stored in Stripe and Auth0, Amplify retains a reference to ids relevant to Stripe and Auth0, but no other information is retained in the AWS data stores used by Amplify.
3rd party data processors
Any data is removed from 3rd party services when the data is no longer required for Amplify. Data can be removed on request, please contact Amplify Support with any requests for deletion of data.
Some data will be anonymized for statistical and legal reasons.
Stripe
Stripe processes payments and handles all relevant information for invoicing and credit-card payments. Contact information related to the owner of an organisation in Amplify as well as company information is stored in Stripe. This includes address, phone numbers, emails, credit-card information, VAT/TAX-related information as well as names of contacts.
https://stripe.com/en-gb-dk/legal/dpa
Auth0
Auth0 processes login and signup for the Amplify solution. To do this it stores the login information, which is the user's email, and the password for a user. The role setting for a user is also stored here, but no other data is stored in Auth0.
https://auth0.com/docs/secure/data-privacy-and-compliance/gdpr
Amazon Web Services - AWS
Amplify uses AWS as a hosting partner, this includes data stores and databases. Only data references to data stored in Auth0 and Stripe are stored in AWS.
https://aws.amazon.com/compliance/gdpr-center/
Cloudinary - DAM
If no other service is active and integrated, Amplify uses Cloudinary as the default DAM integration. The same instance of Cloudinary is used to store data across clients.
https://cloudinary.com/gdpr/dpa
Storage in browser
Part of the service provided in the Amplify solution is the chat/conversation solution.
When the end user interacts with the service the progress and other input from the user are stored in local storage in the browser.
This enables the user to resume the conversation at any time from where they last participated in the conversation - also across browser sessions in the same browser.