© 2026 Amberbook. The Amber Book of European Private Markets.

PrivacyTermsCookiesSecurityLicencesPrivacy requestsupport@amberbook.eu
Amberbook
PlatformWhy AmberbookCoverage
Sign inRequest a pilot
Sign in

Legal

Privacy Policy

What personal data Amberbook holds, why, where it is processed, and how to exercise your rights - whether you are a customer or a person named in a public register.

Last updated: 2026-09-24

Contents

  1. Data controller
  2. What we collect
  3. Why we process it
  4. Legal bases
  5. Where data comes from
  6. Recipients and sub-processors
  7. International transfers
  8. Retention
  9. Your rights
  10. Security
  11. Cookies
  12. Updates
  13. Contact

1. Data controller

The controller of your personal data is Samuel Struharik, Slovakia, who operates Amberbook. Contact is by email, at the address in section 13. A registered address will be published here once a legal entity is formed to take over the service.

We do not have a Data Protection Officer because we do not meet the GDPR Art. 37 thresholds. The privacy mailbox is monitored directly by the founder.

2. What we collect

We process three distinct categories of personal data.

2.1 Customer account data

When you accept an invitation we store your name, email address, hashed password, organisation and role, and, where we invoice you, your billing details and VAT identifier. If you sign in with Google we receive your name and email address from Google and nothing else. We log IP addresses, user-agent strings and timestamps for sign-in and other security-relevant events to keep your account safe.

2.2 Public business records

Amberbook aggregates publicly available data about companies and the individuals who hold registered roles in them - directors, ultimate beneficial owners, statutory representatives and authorised signatories. This data comes from official national company registers, EU open-data portals and other public-record sources described in section 5. Sole proprietors are excluded from the customer-facing product. Dates of birth and personal identification numbers are never shown to customers.

2.3 Usage data

We record which searches and exports you run, which pages and API endpoints you call, and basic device characteristics. This is used for billing, quota enforcement, abuse prevention and product improvement.

3. Why we process it

  • To provide the Amberbook platform to your organisation.
  • To bill you and meet our accounting obligations under Slovak law.
  • To keep the service secure and detect abuse, scraping or fraud.
  • To make public business records searchable and analysable, which is the core value of the product.
  • To respond to your requests, including GDPR data-subject requests.
  • To send service announcements. Marketing email requires separate consent.

4. Legal bases (GDPR Art. 6)

  • Contract (Art. 6(1)(b)) - for providing the platform to trial and paying customers.
  • Legitimate interest (Art. 6(1)(f)) - for processing public-register data about company officers and beneficial owners in support of due diligence, KYC, AML and economic-research use cases. We have completed a Legitimate Interest Assessment, available on request.
  • Legal obligation (Art. 6(1)(c)) - for tax records, anti-money-laundering duties and lawful authority requests.
  • Consent (Art. 6(1)(a)) - for optional browser storage and any future marketing email. Consent can be withdrawn at any time.

5. Where data comes from

Public-record data is collected from official and openly licensed sources only. Across the 12 covered markets these include:

  • National business and commercial registers, including registers of legal persons and of beneficial owners
  • National registers of financial statements and equivalent statutory filings
  • The EU TED public-procurement portal and national tender registers
  • EU sanctions lists, politically-exposed-person lists and insolvency registers
  • Eurostat, the ECB and national statistics offices for region-level indicators
  • Public company websites, for information the company publishes about itself

We do not buy data from data brokers and we do not scrape closed social-media or private databases. The licensors behind the material shown on our public pages are credited on the licences page; the complete source list is an annex to each subscription agreement.

6. Recipients and sub-processors

We share personal data only with the processors required to operate the service:

  • Hetzner Online GmbH (Germany) - hosting of the application, databases and backups in Falkenstein.
  • Postmark, an ActiveCampaign, LLC service (USA) - delivery of transactional email such as invitations, password resets and alerts. Postmark receives your name and email address.
  • Google LLC (USA) - only if you choose to sign in with Google. Google processes the sign-in itself; we receive your name and email address.
  • Ollama, Inc. (USA) - hosted language-model inference used to translate, describe and structure public business records. Inputs are public records and company web pages, never customer account data.

Cloudflare, Inc. provides DNS for our domain and sees DNS queries only; no application traffic or personal data passes through it. An up-to-date sub-processor list is available on request, and we notify customers in advance of material changes.

7. International transfers

The application, both databases and all backups are stored within the European Economic Area. Three of the processors above are in the United States: Postmark, Google and Ollama. Transfers to them rest on the EU-US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses, and are limited to the data named in section 6.

8. Retention

  • Account data - for the lifetime of your account. Deleted accounts enter a 30-day grace period, after which they are anonymised; backups rotate out within a further 30 days.
  • Billing records - 10 years, as required by Slovak Act 431/2002 on Accounting.
  • Access and security logs - up to 24 months.
  • Exports you generate - stored for your account; download links expire five minutes after issue.
  • Public-register data about company officers - for as long as the source register publishes it, plus 7 years for historical analysis, consistent with industry practice for due-diligence products.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Have inaccurate data corrected (Art. 16)
  • Have data erased where possible (Art. 17)
  • Restrict or object to processing (Arts. 18, 21)
  • Receive your data in a portable format (Art. 20)
  • Lodge a complaint with a supervisory authority

The supervisory authority for Slovakia is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR), Hraničná 12, 820 07 Bratislava.

To exercise any of these rights, file a request via /privacy-request or email support@amberbook.eu. We respond within 30 days. Where the law allows, we may extend this by up to two months for complex requests; we will tell you if we do.

If you appear in our records as a company officer or beneficial owner, our processing of that public-register data is based on Art. 6(1)(f) legitimate interest as a data provider. You can object via the same form; we evaluate every objection on its own merits, balancing your interests against the legitimate interests of our customers. A successful objection results in your record being suppressed from default search results and, where applicable, anonymised.

Account holders also have two self-service tools under Account, Privacy & data: a data download (Art. 15 and 20) and account deletion (Art. 17, 30-day grace period).

10. Security

We use industry-standard controls: TLS in transit with HSTS, passwords hashed with bcrypt, short-lived HttpOnly session cookies with CSRF protection, key-only server access, least-privilege access to production, audit logging of sensitive actions and automatic security updates. Backups are copied daily to Hetzner Object Storage in Germany. We do not currently hold a SOC 2 or ISO 27001 certification; we will update this policy if and when we obtain one. The security page has the full picture.

11. Cookies

See our Cookie Policy for the full list of cookies and browser-storage items we use, what they do and how to control them.

12. Updates

We may update this policy as the product evolves. The “last updated” date at the top reflects the most recent change. Material changes will be announced by email and via an in-product notice.

13. Contact

Privacy enquiries and general support: support@amberbook.eu