Legal
Privacy Policy
This is Ambar’s general Privacy Policy. It explains how Ambar processes personal data in connection with its public website and digital channels, Ambar Hauss and its professional community, client and supplier relationships, professional opportunities, events, communications, recruitment and related services. Certain sections apply only to specific categories of individuals and are clearly identified as such.
1. Who is responsible for processing your personal data?
The controller responsible for the processing described in this Privacy Policy is:
| Controller | AMBAR PARTNERS TECH SERVICES, S.L. |
|---|---|
| Tax ID | B88306147 |
| Registered office | Guzmán el Bueno 133, Edificio Britannia, 28003 Madrid, Spain |
| Telephone | +34 697 628 122 |
| Privacy contact | lopd@ambarpartners.com |
References to “Ambar”, “we”, “us” or “our” mean AMBAR PARTNERS TECH SERVICES, S.L. References to “you” mean the individual whose personal data we process.
2. Scope of this Privacy Policy
This is Ambar’s general Privacy Policy. It applies to personal data processed by Ambar in connection with:
- the websites and digital properties operated by Ambar;
- Ambar Hauss, including its web and mobile interfaces;
- the Ambar professional community and its Member, Partner and Eminent Membership Tiers;
- relationships with prospective and existing clients, Users, lawyers, collaborators, suppliers and business contacts;
- professional opportunities and legal-service projects facilitated or coordinated by Ambar;
- events, publications, newsletters, surveys and other communications;
- recruitment and professional-selection processes; and
- support, security, compliance and administration activities.
This Privacy Policy applies to website visitors, prospective and existing clients, Ambar Hauss membership applicants and Users, lawyers and other professional collaborators, suppliers, candidates, event participants and speakers, newsletter subscribers, professional contacts and other individuals whose personal data Ambar processes. Each section identifies the persons and processing activities to which it applies. Website visitors and other individuals are not required to accept this Privacy Policy merely by browsing the website. This Privacy Policy provides the information required under applicable data-protection law. Where consent is required for a specific activity, including non-essential cookies, certain marketing communications or particular uses of photographs or recordings, Ambar will request that consent separately at the relevant collection point.
Users and membership applicants who complete the Ambar Hauss admission or membership process may be required to accept the Ambar Hauss Terms and Conditions and the contractual provisions expressly identified in this Privacy Policy as applying to them, including the international data-transfer terms where relevant.
Where a specific form, service, tool, event or project includes a shorter first-layer notice or a separate privacy notice, that notice supplements this Privacy Policy and will prevail only in relation to the specific processing it describes.
Where Ambar uses a dedicated portal to register, evaluate, admit or manage prospective professional collaborators, a portal-specific privacy notice may apply. That notice will be limited to the processing carried out through that portal and will provide a direct route to the relevant information, rather than a general link to the opening page of an extensive policy.
3. Key terminology used for Ambar Hauss
For consistency with the Ambar Hauss Terms and Conditions of Use:
- “User” means an independent lawyer or other legal professional admitted to the Ambar professional community and authorised to access Ambar Hauss.
- “Membership Tier” means one of the Member, Partner or Eminent membership levels.
- “Platform” or “Ambar Hauss” means the web and mobile platform operated by Ambar.
- “User Content” means information, profile data, posts, comments, messages, documents or other materials made available by a User through the Platform.
- “Third-Party Service” means a product, software tool, application, benefit or service supplied by a third party and made available or accessible through Ambar Hauss.
The designation “Partner” identifies a commercial Membership Tier only. It does not mean that the individual is a shareholder, corporate partner, employee or agent of Ambar.
4. What personal data do we process?
Depending on your relationship with Ambar and the services you use, we may process the following categories of personal data:
- Identification and contact data: name, surname, professional email address, telephone number, postal address, identity documents and signature.
- Professional data: bar admission, practising status, jurisdictions, areas of practice, qualifications, languages, career history, seniority, experience, availability, professional interests and references.
- Membership and account data: Membership Tier, account identifier, authentication information, preferences, subscriptions, benefits, activity and account status.
- Profile and community data: biography, photograph, professional profile, practice-group participation, event attendance, posts, comments, messages and other User Content.
- Client and matter data: organisation, role, instructions, matter or project information, conflicts information, engagement status and communications. Users must not provide privileged or client-confidential information unless authorised and necessary for the relevant purpose.
- Commercial and financial data: proposals, contracts, billing information, bank details, payment status, transaction records and tax data.
- Compliance data: identity-verification information, sanctions and screening results, conflict checks, anti-money-laundering information and records required by law or client policies.
- Technical and usage data: IP address, device and browser information, logs, authentication events, cookie identifiers, Platform activity, security events and interaction data.
- Communications and support data: emails, enquiries, complaints, feedback, support requests and related records.
- Event and media data: registration details, attendance, photographs, video, audio, interviews and speaker materials.
- Recruitment data: CV, application information, employment history, qualifications, interview notes, references and data made available through professional recruitment platforms.
- Marketing and preference data: subscriptions, consent records, interests, campaign interaction and opt-out preferences.
- Any other data that you voluntarily provide or that is reasonably necessary for a clearly identified purpose.
We do not intentionally request special-category data unless it is necessary, proportionate and supported by an appropriate legal basis. Please do not include unnecessary sensitive personal data in free-text fields, community posts, support requests or documents uploaded to the Platform.
5. Why do we process personal data, and on what legal basis?
The following table summarises our principal processing activities. The precise basis may depend on the circumstances and your relationship with Ambar.
| Activity | Purpose | Legal basis |
|---|---|---|
| Website enquiries and business contacts | Responding to enquiries, arranging meetings, preparing proposals and managing prospective business relationships. | Steps requested before entering into a contract where the enquiry concerns a potential individual engagement or proposal. Legitimate interests in responding to and managing corporate or professional enquiries that do not concern an individual contract. Consent or the rules applicable to existing clients for later marketing communications. |
| Client relationships and projects | Onboarding clients, managing engagements, coordinating legal-service projects, communications, invoicing, collections and service quality. | Performance of a contract; compliance with legal obligations; legitimate interests in administering and improving services, including service statistics and relevant communications to existing clients where permitted by law. |
| Ambar Hauss registration and account administration | Verifying eligibility, creating and authenticating accounts, administering Membership Tiers, subscriptions, payments, access rights and support. | Steps requested before entering into a contract; performance of the membership contract; compliance with legal obligations where applicable. |
| Professional verification and community admission | Assessing qualifications, professional standing, experience and suitability for the Ambar community or specific Membership Tiers. | Steps requested before entering into a contract. |
| Profiles, directories and community participation | Displaying professional profiles, enabling practice groups, discussions, direct interactions, events and knowledge-sharing. | Performance of the membership contract; consent for optional elements such as a profile photograph or biography where appropriate. |
| User Content and moderation | Hosting User Content, applying community rules, investigating reports, moderating content and protecting Users and the Platform. | Performance of the membership contract; compliance with legal obligations. |
| Professional opportunities and matching | Searching professional information, assessing suitability through human review, identifying potential opportunities, presenting relevant profiles to clients, and coordinating selection and onboarding. Ambar does not use AI to select, rank, score or exclude Users. | Steps requested before entering into a project engagement; performance of membership or project arrangements; legitimate interests in connecting clients with suitable independent professionals. |
| Conflicts, KYC, AML and regulatory compliance | Conducting identity, sanctions, conflicts and compliance checks; responding to authorities; maintaining legally required records. | Compliance with legal obligations, including applicable AML/CTF requirements; legitimate interests in preventing fraud, conflicts and professional or regulatory risk. |
| Third-Party Services and technology tools | Provisioning access, managing licences, authenticating Users, supporting integrations and administering benefits available through Ambar Hauss. | Performance of the membership contract; consent where an optional service requires the User to connect a third-party account or share data with a separate provider. |
| Artificial-intelligence-enabled professional tools | Providing authorised AI-enabled tools for research, drafting, knowledge management, productivity or other professional purposes; routing requests; maintaining security; and improving Ambar-controlled workflows. These tools are not used to select, rank, score or exclude Users. | Performance of the membership contract; legitimate interests in providing and improving authorised tools; consent where required. Separate notices or third-party terms may apply. |
| Platform security and analytics | Preventing misuse, detecting incidents, troubleshooting, measuring performance and understanding use of the Platform. | Legitimate interests in security, resilience, administration and improvement; consent for non-essential cookies or similar technologies. |
| Suppliers and professional advisers | Vendor onboarding, contract management, payments, audits and administration. | Performance of a contract; compliance with legal obligations. |
| Events and speakers | Managing invitations, registration, attendance, logistics, speaker participation and event communications. | Steps requested before entering into an event or speaker arrangement; performance of a contract; consent for optional promotional uses of images or recordings. |
| Photography, recordings and corporate communications | Documenting events and publishing selected images, recordings, names, titles or professional profiles in Ambar channels. | Consent for featured or promotional uses; Article 8.2(c) of Spanish Organic Law 1/1982 where applicable to general or incidental event images. |
| Newsletters and marketing | Sending Dr. No, invitations and information about Ambar services, events and activities; managing preferences and measuring engagement. | Consent where required; legitimate interests for relevant communications to existing clients where permitted by law. |
| Recruitment and professional selection | Assessing applications for employment or collaboration, conducting interviews and keeping records of selection decisions. | Steps requested before entering into an employment or collaboration contract; consent to retain applications or profiles for future opportunities where appropriate. |
| Claims and legal defence | Handling complaints, disputes, investigations and establishing, exercising or defending legal claims. | Legitimate interests in establishing, exercising or defending legal claims; compliance with legal obligations. |
6. Ambar Hauss profiles, community activity and professional opportunities
Users control much of the professional information displayed in their profile. Depending on the Platform configuration and Membership Tier, profile information may be visible to other Users, authorised Ambar personnel, selected clients or prospective clients, and providers supporting the Platform.
When Ambar considers a User for a professional opportunity, authorised Ambar personnel may search and assess professional profile information, experience, jurisdiction, language capability, seniority, availability, prior project experience and other relevant professional criteria. Technology may support the organisation and presentation of this information, but it does not replace professional judgment. Authorised decision-makers will have sufficient information to assess, question and disregard tool-assisted output and will consider its accuracy, relevance and potential bias. Ambar does not use artificial intelligence to select, rank, score or exclude Users for professional opportunities.
Membership in Ambar Hauss does not guarantee professional opportunities. Decisions concerning admission to the community, Membership Tier, presentation to a client or participation in a professional opportunity are made by appropriately authorised individuals on the basis of professional criteria, client requirements and human assessment.
7. Artificial intelligence and technology tools
Ambar Hauss may provide access to artificial-intelligence-enabled tools operated by Ambar or third parties for legal research, drafting, knowledge management, productivity or other professional purposes. Ambar may also use technology to support the organisation, search and presentation of professional information within Ambar Hauss. Before enabling an AI tool for use with personal data, Ambar will assess, as appropriate, the provider, the parties’ GDPR roles, data locations and international transfers, reuse for training, retention, confidentiality, security and the availability of meaningful human intervention.
- the processing will be limited to the relevant purpose and governed by this Privacy Policy, a specific notice or the provider’s own terms, as applicable;
- Users must not submit personal, privileged, confidential, special-category or client-restricted information to a public or unauthorised AI tool. Such information may be submitted to an approved tool only where the User is authorised to do so and the tool has been approved for that use;
- Ambar will not use User Content to train a general-purpose model for unrelated purposes unless this is expressly disclosed and supported by an appropriate legal basis;
- outputs may be inaccurate and remain subject to professional human review; and
- where a third-party AI provider processes data for its own purposes, that provider may act as a separate controller and its privacy information will apply.
- AI tools do not replace professional assessment. Outputs must be reviewed by an appropriately qualified person who can question and disregard them;
- Users must not use personal data obtained through Ambar to train their own models unless they have a documented lawful basis and Ambar’s prior written authorisation;
- Users must not delegate professional decisions to AI or use AI to extract data from Ambar for profiling, ranking or classifying other Users.
Ambar does not use artificial intelligence systems to select, rank, score or exclude Users for admission to the Ambar community, allocation to a Membership Tier or access to professional opportunities.
Ambar does not use artificial intelligence to make decisions producing legal or similarly significant effects concerning Users. Ambar will not use AI systems for practices prohibited by applicable law. Ambar will maintain reasonable measures for the selection, configuration, supervision and control of AI systems used in its activities, including proportionate checks of accuracy, relevance and potential bias.
Where Ambar materially changes these practices or introduces an AI system that has a significant effect on Users, Ambar will assess the applicable legal requirements and provide appropriate information before or at the time the relevant processing begins.
8. Who receives your personal data?
We may disclose personal data, where necessary and proportionate, to:
- Ambar personnel and authorised contractors who need access for their functions;
- clients and prospective clients evaluating or working with a User on a professional opportunity or project;
- Users and other participants in Ambar Hauss where information is shared through profiles, groups, events, messages or User Content;
- lawyers, professional advisers and other collaborators involved in delivering a service or project;
- technology, hosting, communications, payment, authentication, analytics, customer-support, events, recruitment, compliance and security providers acting as processors under appropriate contractual terms;
- financial institutions, payment providers, insurers, auditors and professional advisers;
- courts, regulators, law-enforcement bodies, tax authorities and other public administrations where required by law or necessary to protect rights;
- a purchaser, investor, financing party or successor in connection with a corporate transaction, subject to appropriate confidentiality and data-protection safeguards; and
- any other recipient where you request or authorise the disclosure.
Service providers acting as processors may use personal data only on Ambar’s documented instructions, for the agreed purposes and subject to confidentiality, security and data-protection obligations. Some third-party services available through Ambar Hauss may act as independent controllers; their own privacy policies will then apply.
9. International data transfers
Ambar operates an international professional community. Users, clients, professional collaborators and service providers may be located inside or outside the European Economic Area (the “EEA”). Personal data may therefore be accessed, disclosed or otherwise transferred internationally where this is necessary for the operation of Ambar Hauss, the evaluation or performance of professional opportunities, the delivery of services or the use of technology providers.
The fact that a User is established or ordinarily resident outside the EEA does not, by itself, mean that every processing activity concerning that User constitutes an international transfer by Ambar. A transfer may occur, however, where personal data protected by the GDPR is made available to, or remotely accessed by, a recipient in a third country.
Where Ambar transfers personal data outside the EEA, it will rely, as applicable, on:
- a. a decision of the European Commission recognising that the recipient country provides an adequate level of protection;
- b. the European Commission’s Standard Contractual Clauses or another appropriate safeguard recognised under Article 46 GDPR, together with supplementary measures where required;
- c. Binding Corporate Rules or another legally recognised transfer mechanism, where applicable; or
- d. exceptionally, a derogation under Article 49 GDPR where the transfer is specific, objectively necessary and satisfies the applicable statutory requirements.
Ambar does not rely on Article 49 GDPR as the ordinary basis for regular, systematic or recurring international transfers.
You may request further information about the relevant transfer mechanism and, where available, a copy of the applicable safeguards by contacting lopd@ambarpartners.com. Certain information may be redacted where necessary to protect confidentiality, legal privilege or security.
10. Contractual privacy terms applicable to Ambar Hauss Users
10.1 Scope, contractual status, acceptance and priority
This Section 10 contains contractual obligations applicable to Users of Ambar Hauss. The transparency information elsewhere in this Privacy Policy does not require acceptance and is not consent. A User is bound by this Section 10 only after an affirmative click-wrap process in which the contractual wording is available before acceptance, the checkbox is not pre-selected, the applicable version is identified, and a durable copy can be downloaded or otherwise retained. Ambar will retain evidence of the User’s identity and capacity, account identifier, exact text and checkbox wording, version, immutable copy or hash, date and time, language, acceptance method and event, and link to the applicable SCC Schedule. This Section 10 prevails over incompatible general terms in relation to its subject matter, without prejudice to the priority of the SCCs stated below.
10.2 General obligations of Users
Each User who receives or accesses personal data through Ambar Hauss, an Ambar-coordinated professional opportunity or an Ambar project must, to the extent applicable:
- a. process such personal data only for the authorised community or professional purpose and in accordance with applicable law, professional duties, the relevant engagement terms and any documented instructions that lawfully apply;
- b. observe professional secrecy and confidentiality and maintain appropriate technical and organisational security measures;
- c. limit access to persons who are authorised and need the information for the relevant purpose;
- d. not sell, reuse, disclose, onward transfer or otherwise make the personal data available to another person except where expressly authorised, lawfully permitted and covered by any transfer safeguard required under Chapter V GDPR;
- e. immediately notify Ambar of any actual or suspected personal-data breach, unauthorised access, legally binding disclosure request, direct access by a public authority or inability to comply with the applicable data-protection obligations, and preserve relevant evidence;
- f. reasonably cooperate with Ambar in responding to data-subject requests, security incidents, regulatory enquiries, transfer assessments and compliance reviews; and
- g. securely delete or return the personal data when it is no longer required for the authorised purpose, subject to applicable legal, regulatory and professional retention duties.
- h. document any authorised onward recipient and the legal basis and transfer safeguard that apply;
- i. review the legality and proportionality of any public-authority request, challenge it where there are reasonable grounds, disclose only the minimum data legally required and keep a record of the request, assessment and response;
- j. cooperate with data-subject requests, complaints, transfer impact assessments, regulatory enquiries and proportionate audits, and complete periodic security or transfer-compliance questionnaires reasonably requested by Ambar; and
- k. cease access and processing immediately if the User cannot comply with these obligations or the applicable transfer safeguards.
10.3 Incorporation and scope of the Standard Contractual Clauses
Where a User located outside the EEA receives regular or recurring access to personal data protected by the GDPR, the recipient country is not covered by an applicable adequacy decision and no other valid transfer mechanism applies, the Module One Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 and reproduced in Annex A to this Privacy Policy (the “SCCs”) are incorporated into and form part of the contractual relationship between Ambar and that User through the affirmative acceptance process described in Section 10.1. A handwritten signature or qualified electronic signature is not required, provided that Ambar maintains an individual, auditable electronic record that unequivocally identifies the User, the capacity in which the User acts, the SCC version and Schedule accepted, and the date and method of acceptance.
The SCCs apply only to the extent required for the relevant transfer. Module One is selected for the ordinary relationship between Ambar and an independent lawyer acting as an independent controller. The application and completion of the SCCs are as follows:
- a. Ambar is the data exporter and the relevant User is the data importer, unless a project-specific Transfer Schedule records another lawful allocation;
- b. Module One (controller to controller) applies where Ambar and the User each act as independent controllers, which will ordinarily be the case where the User provides independent legal services and determines the professional means and purposes of the relevant processing;
- c. where the User acts solely as a processor on documented instructions, Module Two or another module appropriate to the parties’ actual roles must be selected and completed in a separate data-transfer addendum or project-specific Transfer Schedule before access is granted;
- d. the parties are identified through Ambar’s corporate details and an individual electronic record containing the User’s full legal or professional name, professional address, account email, date of adherence, role, applicable module and version of the SCC Schedule;
- e. the data subjects, categories of personal data, sensitive-data safeguards, nature, purposes, frequency and duration of each transfer are those described in Annex I to Annex A and, where needed for sufficient clarity, the applicable project-specific Transfer Schedule;
- f. Spain is the governing Member State, the Spanish Data Protection Agency is the competent supervisory authority, and the courts of Spain are selected under Clauses 17 and 18; and
- g. the technical and organisational measures are those set out in Annex II to Annex A, together with any stricter Platform, client or project-specific requirements recorded in the applicable Transfer Schedule.
The User agrees that information held in the User’s Ambar Hauss account, admission file and engagement documentation may be used to generate the individual SCC record and Transfer Schedule. The User must keep that information accurate and provide any additional information reasonably requested by Ambar. Ambar must be able to determine, for any relevant date, the identity of each data importer and the transfers, module, Schedule and safeguards that applied to that User.
A Transfer Schedule may be generated automatically and does not require a manually prepared or separately signed PDF, provided that it is individualized, durable and auditable. Where the SCCs, the parties’ actual roles or a project require a different module, further detail, supplementary measures or another material change, Ambar may require an additional acknowledgement or project addendum before granting access to the relevant personal data.
10.4 Transfer assessment, supplementary measures and audit
Ambar will document the assessment required by Clause 14 through a practical framework consisting of a master assessment for each country or legally equivalent country group, a matrix for the relevant data, access and project scenarios, and an individual record assigning each User and transfer to the applicable scenario. The assessment must consider the specific transfer and may not remain purely abstract. A separate review is required where the role, country, data, onward recipients, storage arrangements, device environment or safeguards differ materially from the assessed scenario.
Ambar will require each relevant User to complete an onboarding questionnaire and confirm or update it at least annually. The record will cover the User's legal and professional identity, country of establishment and access, data-protection role, device and storage locations, onward recipients and subprocessors, security measures, public-authority access experience, certifications and material changes. The User must provide supporting evidence on request and notify Ambar without undue delay of any material change. Ambar may conduct proportionate reviews or audits, impose supplementary measures and suspend access where an adequate level of protection cannot be ensured.
10.5 Priority, onward transfers and public-authority requests
If there is any conflict between the SCCs and another provision of this Privacy Policy, the Ambar Hauss Terms and Conditions or an engagement document, the SCCs prevail to the extent of that conflict in relation to the relevant international transfer.
A User must not make an onward transfer of personal data received from the EEA unless it is permitted under the SCCs and supported by a valid Chapter V GDPR mechanism. The User must document the onward recipient and safeguard. If a public authority requests or directly accesses transferred data, the User must inform Ambar unless legally prohibited, review legality and proportionality, seek a waiver of any notification prohibition where appropriate, challenge an unlawful request where there are reasonable grounds, disclose only the minimum data legally required, preserve the assessment and response, and make the record available to Ambar or the competent supervisory authority on request. Ambar may suspend the transfer or the User’s access where compliance cannot be ensured.
10.6 Roles of the parties
The allocation of controller, joint-controller or processor responsibilities depends on the relevant activity. A User providing independent legal services will commonly act as an independent controller for the professional advice and services delivered by that User. Other limited processing may be carried out on documented instructions. Nothing in this Privacy Policy changes the parties’ actual legal roles, which will be determined by the facts and, where necessary, clarified in the relevant project documentation.
11. Cookies and similar technologies
Our website and Platform may use cookies, pixels, local storage, SDKs and similar technologies for security, functionality, analytics and marketing. Necessary technologies may operate without consent where permitted by law. Non-essential technologies are disabled until valid consent is obtained.
The consent interface allows users to accept, reject or customise non-essential technologies. Accept and reject choices are presented with equivalent prominence. Preferences can be changed at any time through the Cookie Settings link.
For the current list of technologies, providers, purposes and retention periods, please consult the separate Cookie Policy and the Cookie Settings interface available on the relevant website or Platform. The Cookie Policy is published through a link that is separate from the link to this Privacy Policy.
12. Current operational and infrastructure providers
As at the date of this Privacy Policy, Ambar may use the providers listed below for hosting, infrastructure, communications and business operations. Providers used solely for cookies, website analytics, attribution, session analysis or advertising appear in the Cookie Policy and Cookie Settings interface.
| Provider | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (CloudFront / S3) | Hosting, storage and content delivery | EEA and global edge network | EU-U.S. Data Privacy Framework for transfers to covered U.S. entities; Standard Contractual Clauses or another valid Chapter V mechanism for transfers outside an adequacy decision. |
| GitLab Inc. | Source-code repository and deployment workflows | United States | EU-U.S. Data Privacy Framework while the recipient's certification remains active and covers the service; Standard Contractual Clauses as a fallback where required. |
| Beehiiv, Inc. | Newsletter subscription and delivery for Dr. No | United States | Standard Contractual Clauses incorporated into the provider's data-processing terms. |
| Zoho Corporation | Booking, forms and business communications | EEA, India and United States | Standard Contractual Clauses or another valid Chapter V mechanism for transfers to India, the United States or another destination without an adequacy decision. |
Ambar verifies the transfer mechanism against the exact legal recipient and service. Ambar reviews Data Privacy Framework status at least annually and when the provider, service, data location or subprocessor chain changes.
13. Marketing communications and professional contact data
Ambar may send relevant information about its services, professional community, events and publications to existing clients, Users and professional contacts where permitted by applicable law. Every electronic marketing communication will provide a simple way to unsubscribe or object.
Where consent is required, communications will be sent only after consent has been obtained. Consent may be withdrawn at any time without affecting processing carried out before withdrawal.
Ambar may process limited professional contact information obtained from public sources, professional platforms, referrals or the organisation for which the individual works, where this is necessary to establish or maintain a relationship with that organisation or with the individual in their professional capacity. This processing is based on Ambar’s legitimate interests and Article 19 of the Spanish Organic Law 3/2018, where applicable. Individuals may object at any time.
Ambar does not sell personal data to advertisers.
14. Events, photographs and recordings
Ambar may photograph or record events, interviews, panels and award ceremonies. The applicable event information will explain the intended use and legal basis. Close-up or featured promotional use will normally be based on consent, an agreement with the participant or another appropriate basis. General or incidental images of an event may be used without consent where this is lawful and proportionate under Article 8.2(c) of Spanish Organic Law 1/1982.
Where practical, attendees who do not wish to appear in promotional content may contact the event team or lopd@ambarpartners.com. Withdrawal of consent does not affect processing that occurred before withdrawal and may not require removal of material where another legal basis applies or where removal is technically or legally disproportionate.
15. How long do we retain personal data?
We retain personal data only for as long as reasonably necessary for the relevant purpose, including the duration of a contractual or community relationship, and thereafter for the ordinary periods described below. A longer or shorter period may apply where required by law, necessary for an active project, complaint, investigation or claim, or justified by the nature of the data and the relevant processing purpose.
| Category | Indicative retention approach |
|---|---|
| Client, supplier and project records | For the duration of the relationship and afterwards for the applicable statutory limitation, tax, accounting and professional-liability periods. Core contractual, invoicing and project-administration records will ordinarily be retained for up to six years after the relationship ends, without prejudice to longer mandatory periods or active claims. |
| Ambar Hauss accounts and Membership records | While the account or Membership is active. Following closure, core contractual, billing, compliance and account-administration records may ordinarily be retained for up to six years. Profile preferences, non-essential usage data and information no longer required will be deleted or de-identified earlier where reasonably practicable. |
| User profiles and User Content | While published or required to provide the Platform. Following removal or account closure, Content will ordinarily be removed from active systems within 90 days, subject to legal retention, security, dispute-resolution, moderation and backup requirements. |
| AML/CTF records | For the period required by applicable AML/CTF legislation, which may be ten years in relevant cases. |
| Professional-opportunity and selection records | For the duration of the opportunity and ordinarily for two years after the selection process closes, unless the User is engaged, a longer period is required for conflicts, equal-treatment evidence, client requirements, a complaint or a legal claim. |
| Marketing and professional-prospect records | Until consent is withdrawn or an objection is made. Professional-prospect data will ordinarily be reviewed or deleted 12 months after the last meaningful interaction where no relationship proceeds. Suppression records may be retained to ensure that no further communications are sent. |
| Enquiries, complaints and support | For the time needed to respond and ordinarily for 12 months after closure, unless a longer period is necessary for an actual or reasonably anticipated complaint, claim, security matter or legal obligation. |
| Event registration data | For the event lifecycle and ordinarily for up to 24 months afterwards for administration, relationship management and claims. Invoicing records will be retained for applicable statutory periods. |
| Photographs and recordings | Ordinarily for up to one year after creation or publication. Ambar may retain selected material for longer where it remains necessary for the stated communication, documentary or archival purpose. Ambar will review that material at least annually. The review will consider the continued relevance of the event, the role and public profile of the persons shown, the material's ongoing communication or historical value, any withdrawal of consent and whether a shorter or less identifiable form would meet the purpose. |
| Recruitment records | For the selection process and ordinarily for up to one year after the last update where the candidate has agreed to consideration for future opportunities or another lawful basis applies. |
| Security logs | Ordinarily for 12 months, unless a longer period is necessary to investigate an incident, prevent fraud, comply with audit requirements or establish, exercise or defend legal claims. |
| Cookie and analytics data | For the periods shown in the Cookie Policy or Cookie Settings interface. |
| Social-media interactions | For as long as the relevant interaction, connection or following relationship continues, subject to the platform’s own terms and any earlier objection or deletion request. |
When data are no longer required, they will be securely deleted or anonymised. Data may remain temporarily in restricted backups until overwritten in accordance with normal backup cycles.
16. Security
Ambar applies technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature of the data, the processing context and the risks involved and may include access controls, authentication, encryption, logging, backups, incident procedures, supplier due diligence and staff confidentiality obligations.
No system can guarantee absolute security. Users are responsible for safeguarding their credentials, using the Platform lawfully and promptly reporting suspected unauthorised access or security incidents.
17. Your data-protection rights
Subject to the conditions and limitations established by applicable law, you may exercise the following rights:
- Access: obtain confirmation of whether we process your personal data and receive a copy of relevant data and information.
- Rectification: correct inaccurate or incomplete personal data.
- Erasure: request deletion where the data are no longer necessary, consent has been withdrawn, an objection prevails or processing is unlawful.
- Restriction: request that processing be limited in specified circumstances.
- Objection: object to processing based on legitimate interests and object at any time to direct marketing.
- Portability: receive personal data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have them transmitted to another controller.
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of prior processing.
- Automated decisions: request safeguards in relation to solely automated decisions that produce legal or similarly significant effects, where applicable.
18. How to exercise your rights
You may exercise your rights or raise a privacy question by writing to:
- Email: lopd@ambarpartners.com
- Postal address: AMBAR PARTNERS TECH SERVICES, S.L., Guzmán el Bueno 133, Edificio Britannia, 28003 Madrid, Spain
Please identify the right you wish to exercise and provide enough information for us to locate the relevant data. We may request proportionate proof of identity where necessary to protect your information. Exercising your rights is free of charge, although a reasonable fee may be charged or a request refused where it is manifestly unfounded or excessive, as permitted by law.
We will respond without undue delay and normally within one month. That period may be extended by up to two additional months where necessary due to complexity or the number of requests; we will inform you of any extension within the initial month.
You may lodge a complaint with the Spanish Data Protection Agency at www.aepd.es
19. Data relating to other people
If you provide personal data relating to another person, you must ensure that you are authorised to do so and that the person receives the information required under applicable data-protection law. You must not upload third-party personal data, client information or confidential matter information to Ambar Hauss or a Third-Party Service unless the disclosure is authorised, necessary and compliant with professional obligations.
20. Children
Ambar’s professional services, community and Platform are intended for individuals aged 18 or over. We do not knowingly offer Memberships or professional services to children. If we learn that we have collected a child’s personal data without an appropriate basis, we will take reasonable steps to delete it.
21. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in law, guidance, technology, our services or our processing activities. We will publish the updated version with a revised 'Last updated' date. We will give at least 15 calendar days' notice before material changes take effect. We will normally give 30 calendar days' notice where changes are significant or affect contractual or consumer terms. A shorter period may apply where an urgent legal, regulatory or security requirement makes this necessary.
Where an update introduces or materially changes contractual obligations, SCCs, liability, audit rights, permitted uses or international access to personal data, Ambar will request express acceptance through an affirmative and non-preselected checkbox. Continued use alone does not constitute acceptance of such a change. Ambar may restrict access to third-party data and professional opportunities until acceptance is complete. Users will retain access to the acceptance screen, relevant documents and functions needed to exercise data-protection rights. A new or materially changed processing purpose based on consent requires new and specific consent before the processing begins. Informational changes that do not alter legal bases, purposes, recipients, transfers, rights or contractual obligations may be communicated without re-acceptance. Ambar will retain the evidence described in Section 10.1 for each acceptance event.
22. Contact
Questions about this Privacy Policy or Ambar’s processing of personal data may be addressed to:
AMBAR PARTNERS TECH SERVICES, S.L.
Guzmán el Bueno 133, Edificio Britannia
28003 Madrid, Spain
Email: lopd@ambarpartners.com
Telephone: +34 697 628 122
Annex A. Standard Contractual Clauses (Module One: controller to controller)
This Annex forms part of the contractual terms in Section 10. It reproduces the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, with Module One selected and the permitted options and Appendix completed for Ambar’s ordinary controller-to-controller transfers. If the parties’ actual roles differ, the applicable module must be separately selected and completed before the transfer.
Selections: Clause 7 (docking clause) applies. The optional independent dispute-resolution body in Clause 11 is not selected. Clause 17 Option 1 is selected with Spanish law. Spain is selected under Clause 18. Annex III is not applicable to Module One.
STANDARD CONTRACTUAL CLAUSES
SECTION I
Clause 1 — Purpose and scope
(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (1) for the transfer of personal data to a third country.
(b) The Parties:
(i) the natural or legal person(s), public authority/ies, agency/ies or other body/ies (hereinafter ‘entity/ies’) transferring the personal data, as listed in Annex I.A (hereinafter each ‘data exporter’), and
(ii) the entity/ies in a third country receiving the personal data from the data exporter, directly or indirectly via another entity also Party to these Clauses, as listed in Annex I.A (hereinafter each ‘data importer’)
have agreed to these standard contractual clauses (hereinafter: ‘Clauses’).
(c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.
(d) The Appendix to these Clauses containing the Annexes referred to therein forms an integral part of these Clauses.
Clause 2 — Effect and invariability of the Clauses
(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679 and, with respect to data transfers from controllers to processors and/or processors to processors, standard contractual clauses pursuant to Article 28(7) of Regulation (EU) 2016/679, provided they are not modified, except to select the appropriate Module(s) or to add or update information in the Appendix. This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a wider contract and/or to add other clauses or additional safeguards, provided that they do not contradict, directly or indirectly, these Clauses or prejudice the fundamental rights or freedoms of data subjects.
(b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.
Clause 3 — Third-party beneficiaries
(a) Data subjects may invoke and enforce these Clauses, as third-party beneficiaries, against the data exporter and/or data importer, with the following exceptions:
(i) Clause 1, Clause 2, Clause 3, Clause 6, Clause 7;
(ii) Clause 8 – Module One: Clause 8.5 (e) and Clause 8.9(b); Module Two: Clause 8.1(b), 8.9(a), (c), (d) and (e); Module Three: Clause 8.1(a), (c) and (d) and Clause 8.9(a), (c), (d), (e), (f) and (g); Module Four: Clause 8.1 (b) and Clause 8.3(b);
(iii) Clause 9 – Module Two: Clause 9(a), (c), (d) and (e); Module Three: Clause 9(a), (c), (d) and (e);
(iv) Clause 12 – Module One: Clause 12(a) and (d); Modules Two and Three: Clause 12(a), (d) and (f);
(v) Clause 13;
(vi) Clause 15.1(c), (d) and (e);
(vii) Clause 16(e);
(viii) Clause 18 – Modules One, Two and Three: Clause 18(a) and (b); Module Four: Clause 18.
(b) Paragraph (a) is without prejudice to rights of data subjects under Regulation (EU) 2016/679.
Clause 4 — Interpretation
(a) Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.
(b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679.
(c) These Clauses shall not be interpreted in a way that conflicts with rights and obligations provided for in Regulation (EU) 2016/679.
Clause 5 — Hierarchy
In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, existing at the time these Clauses are agreed or entered into thereafter, these Clauses shall prevail.
Clause 6 — Description of the transfer(s)
The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.
Clause 7 – Optional
Docking clause
(a) An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer, by completing the Appendix and signing Annex I.A.
(b) Once it has completed the Appendix and signed Annex I.A, the acceding entity shall become a Party to these Clauses and have the rights and obligations of a data exporter or data importer in accordance with its designation in Annex I.A.
(c) The acceding entity shall have no rights or obligations arising under these Clauses from the period prior to becoming a Party.
SECTION II – OBLIGATIONS OF THE PARTIES
Clause 8 — Data protection safeguards
The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organisational measures, to satisfy its obligations under these Clauses.
MODULE ONE: Transfer controller to controller
8.1 Purpose limitation
The data importer shall process the personal data only for the specific purpose(s) of the transfer, as set out in Annex I.B. It may only process the personal data for another purpose:
(i) where it has obtained the data subject’s prior consent;
(ii) where necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or
(iii) where necessary in order to protect the vital interests of the data subject or of another natural person.
8.2 Transparency
(a) In order to enable data subjects to effectively exercise their rights pursuant to Clause 10, the data importer shall inform them, either directly or through the data exporter:
(i) of its identity and contact details;
(ii) of the categories of personal data processed;
(iii) of the right to obtain a copy of these Clauses;
(iv) where it intends to onward transfer the personal data to any third party/ies, of the recipient or categories of recipients (as appropriate with a view to providing meaningful information), the purpose of such onward transfer and the ground therefore pursuant to Clause 8.7.
(b) Paragraph (a) shall not apply where the data subject already has the information, including when such information has already been provided by the data exporter, or providing the information proves impossible or would involve a disproportionate effort for the data importer. In the latter case, the data importer shall, to the extent possible, make the information publicly available.
(c) On request, the Parties shall make a copy of these Clauses, including the Appendix as completed by them, available to the data subject free of charge. To the extent necessary to protect business secrets or other confidential information, including personal data, the Parties may redact part of the text of the Appendix prior to sharing a copy, but shall provide a meaningful summary where the data subject would otherwise not be able to understand its content or exercise his/her rights. On request, the Parties shall provide the data subject with the reasons for the redactions, to the extent possible without revealing the redacted information.
(d) Paragraphs (a) to (c) are without prejudice to the obligations of the data exporter under Articles 13 and 14 of Regulation (EU) 2016/679.
8.3 Accuracy and data minimisation
(a) Each Party shall ensure that the personal data is accurate and, where necessary, kept up to date. The data importer shall take every reasonable step to ensure that personal data that is inaccurate, having regard to the purpose(s) of processing, is erased or rectified without delay.
(b) If one of the Parties becomes aware that the personal data it has transferred or received is inaccurate, or has become outdated, it shall inform the other Party without undue delay.
(c) The data importer shall ensure that the personal data is adequate, relevant and limited to what is necessary in relation to the purpose(s) of processing.
8.4 Storage limitation
The data importer shall retain the personal data for no longer than necessary for the purpose(s) for which it is processed. It shall put in place appropriate technical or organisational measures to ensure compliance with this obligation, including erasure or anonymisation (2) of the data and all back-ups at the end of the retention period.
8.5 Security of processing
(a) The data importer and, during transmission, also the data exporter shall implement appropriate technical and organisational measures to ensure the security of the personal data, including protection against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access (hereinafter ‘personal data breach’). In assessing the appropriate level of security, they shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purpose(s) of processing and the risks involved in the processing for the data subject. The Parties shall in particular consider having recourse to encryption or pseudonymisation, including during transmission, where the purpose of processing can be fulfilled in that manner.
(b) The Parties have agreed on the technical and organisational measures set out in Annex II. The data importer shall carry out regular checks to ensure that these measures continue to provide an appropriate level of security.
(c) The data importer shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(d) In the event of a personal data breach concerning personal data processed by the data importer under these Clauses, the data importer shall take appropriate measures to address the personal data breach, including measures to mitigate its possible adverse effects.
(e) In case of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the data importer shall without undue delay notify both the data exporter and the competent supervisory authority pursuant to Clause 13. Such notification shall contain i) a description of the nature of the breach (including, where possible, categories and approximate number of data subjects and personal data records concerned), ii) its likely consequences, iii) the measures taken or proposed to address the breach, and iv) the details of a contact point from whom more information can be obtained. To the extent it is not possible for the data importer to provide all the information at the same time, it may do so in phases without undue further delay.
(f) In case of a personal data breach that is likely to result in a high risk to the rights and freedoms of natural persons, the data importer shall also notify without undue delay the data subjects concerned of the personal data breach and its nature, if necessary in cooperation with the data exporter, together with the information referred to in paragraph (e), points ii) to iv), unless the data importer has implemented measures to significantly reduce the risk to the rights or freedoms of natural persons, or notification would involve disproportionate efforts. In the latter case, the data importer shall instead issue a public communication or take a similar measure to inform the public of the personal data breach.
(g) The data importer shall document all relevant facts relating to the personal data breach, including its effects and any remedial action taken, and keep a record thereof.
8.6 Sensitive data
Where the transfer involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions or offences (hereinafter ‘sensitive data’), the data importer shall apply specific restrictions and/or additional safeguards adapted to the specific nature of the data and the risks involved. This may include restricting the personnel permitted to access the personal data, additional security measures (such as pseudonymisation) and/or additional restrictions with respect to further disclosure.
8.7 Onward transfers
The data importer shall not disclose the personal data to a third party located outside the European Union (3) (in the same country as the data importer or in another third country, hereinafter ‘onward transfer’) unless the third party is or agrees to be bound by these Clauses, under the appropriate Module. Otherwise, an onward transfer by the data importer may only take place if:
(i) it is to a country benefitting from an adequacy decision pursuant to Article 45 of Regulation (EU) 2016/679 that covers the onward transfer;
(ii) the third party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 of Regulation (EU) 2016/679 with respect to the processing in question;
(iii) the third party enters into a binding instrument with the data importer ensuring the same level of data protection as under these Clauses, and the data importer provides a copy of these safeguards to the data exporter;
(iv) it is necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings;
(v) it is necessary in order to protect the vital interests of the data subject or of another natural person; or
(vi) where none of the other conditions apply, the data importer has obtained the explicit consent of the data subject for an onward transfer in a specific situation, after having informed him/her of its purpose(s), the identity of the recipient and the possible risks of such transfer to him/her due to the lack of appropriate data protection safeguards. In this case, the data importer shall inform the data exporter and, at the request of the latter, shall transmit to it a copy of the information provided to the data subject.
Any onward transfer is subject to compliance by the data importer with all the other safeguards under these Clauses, in particular purpose limitation.
8.8 Processing under the authority of the data importer
The data importer shall ensure that any person acting under its authority, including a processor, processes the data only on its instructions.
8.9 Documentation and compliance
(a) Each Party shall be able to demonstrate compliance with its obligations under these Clauses. In particular, the data importer shall keep appropriate documentation of the processing activities carried out under its responsibility.
(b) The data importer shall make such documentation available to the competent supervisory authority on request.
Clause 10 — Data subject rights
MODULE ONE: Transfer controller to controller
(a) The data importer, where relevant with the assistance of the data exporter, shall deal with any enquiries and requests it receives from a data subject relating to the processing of his/her personal data and the exercise of his/her rights under these Clauses without undue delay and at the latest within one month of the receipt of the enquiry or request. (10) The data importer shall take appropriate measures to facilitate such enquiries, requests and the exercise of data subject rights. Any information provided to the data subject shall be in an intelligible and easily accessible form, using clear and plain language.
(b) In particular, upon request by the data subject the data importer shall, free of charge:
(i) provide confirmation to the data subject as to whether personal data concerning him/her is being processed and, where this is the case, a copy of the data relating to him/her and the information in Annex I; if personal data has been or will be onward transferred, provide information on recipients or categories of recipients (as appropriate with a view to providing meaningful information) to which the personal data has been or will be onward transferred, the purpose of such onward transfers and their ground pursuant to Clause 8.7; and provide information on the right to lodge a complaint with a supervisory authority in accordance with Clause 12(c)(i);
(ii) rectify inaccurate or incomplete data concerning the data subject;
(iii) erase personal data concerning the data subject if such data is being or has been processed in violation of any of these Clauses ensuring third-party beneficiary rights, or if the data subject withdraws the consent on which the processing is based.
(c) Where the data importer processes the personal data for direct marketing purposes, it shall cease processing for such purposes if the data subject objects to it.
(d) The data importer shall not make a decision based solely on the automated processing of the personal data transferred (hereinafter ‘automated decision’), which would produce legal effects concerning the data subject or similarly significantly affect him/her, unless with the explicit consent of the data subject or if authorised to do so under the laws of the country of destination, provided that such laws lays down suitable measures to safeguard the data subject’s rights and legitimate interests. In this case, the data importer shall, where necessary in cooperation with the data exporter:
(i) inform the data subject about the envisaged automated decision, the envisaged consequences and the logic involved; and
(ii) implement suitable safeguards, at least by enabling the data subject to contest the decision, express his/her point of view and obtain review by a human being.
(e) Where requests from a data subject are excessive, in particular because of their repetitive character, the data importer may either charge a reasonable fee taking into account the administrative costs of granting the request or refuse to act on the request.
(f) The data importer may refuse a data subject’s request if such refusal is allowed under the laws of the country of destination and is necessary and proportionate in a democratic society to protect one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679.
(g) If the data importer intends to refuse a data subject’s request, it shall inform the data subject of the reasons for the refusal and the possibility of lodging a complaint with the competent supervisory authority and/or seeking judicial redress.
Clause 11 — Redress
(a) The data importer shall inform data subjects in a transparent and easily accessible format, through individual notice or on its website, of a contact point authorised to handle complaints. It shall deal promptly with any complaints it receives from a data subject.
MODULE ONE: Transfer controller to controller
(b) In case of a dispute between a data subject and one of the Parties as regards compliance with these Clauses, that Party shall use its best efforts to resolve the issue amicably in a timely fashion. The Parties shall keep each other informed about such disputes and, where appropriate, cooperate in resolving them.
(c) Where the data subject invokes a third-party beneficiary right pursuant to Clause 3, the data importer shall accept the decision of the data subject to:
(i) lodge a complaint with the supervisory authority in the Member State of his/her habitual residence or place of work, or the competent supervisory authority pursuant to Clause 13;
(ii) refer the dispute to the competent courts within the meaning of Clause 18.
(d) The Parties accept that the data subject may be represented by a not-for-profit body, organisation or association under the conditions set out in Article 80(1) of Regulation (EU) 2016/679.
(e) The data importer shall abide by a decision that is binding under the applicable EU or Member State law.
(f) The data importer agrees that the choice made by the data subject will not prejudice his/her substantive and procedural rights to seek remedies in accordance with applicable laws.
Clause 12 — Liability
MODULE ONE: Transfer controller to controller
(a) Each Party shall be liable to the other Party/ies for any damages it causes the other Party/ies by any breach of these Clauses.
(b) Each Party shall be liable to the data subject, and the data subject shall be entitled to receive compensation, for any material or non-material damages that the Party causes the data subject by breaching the third-party beneficiary rights under these Clauses. This is without prejudice to the liability of the data exporter under Regulation (EU) 2016/679.
(c) Where more than one Party is responsible for any damage caused to the data subject as a result of a breach of these Clauses, all responsible Parties shall be jointly and severally liable and the data subject is entitled to bring an action in court against any of these Parties.
(d) The Parties agree that if one Party is held liable under paragraph (c), it shall be entitled to claim back from the other Party/ies that part of the compensation corresponding to its/their responsibility for the damage.
(e) The data importer may not invoke the conduct of a processor or sub-processor to avoid its own liability.
Clause 13 — Supervision
MODULE ONE: Transfer controller to controller
(a) [Where the data exporter is established in an EU Member State:] The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 as regards the data transfer, as indicated in Annex I.C, shall act as competent supervisory authority.
(b) The data importer agrees to submit itself to the jurisdiction of and cooperate with the competent supervisory authority in any procedures aimed at ensuring compliance with these Clauses. In particular, the data importer agrees to respond to enquiries, submit to audits and comply with the measures adopted by the supervisory authority, including remedial and compensatory measures. It shall provide the supervisory authority with written confirmation that the necessary actions have been taken.
SECTION III – LOCAL LAWS AND OBLIGATIONS IN CASE OF ACCESS BY PUBLIC AUTHORITIES
Clause 14 — Local laws and practices affecting compliance with the Clauses
MODULE ONE: Transfer controller to controller
(a) The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorising access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on the understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society to safeguard one of the objectives listed in Article 23(1) of Regulation (EU) 2016/679, are not in contradiction with these Clauses.
(b) The Parties declare that in providing the warranty in paragraph (a), they have taken due account in particular of the following elements:
(i) the specific circumstances of the transfer, including the length of the processing chain, the number of actors involved and the transmission channels used; intended onward transfers; the type of recipient; the purpose of processing; the categories and format of the transferred personal data; the economic sector in which the transfer occurs; the storage location of the data transferred;
(ii) the laws and practices of the third country of destination– including those requiring the disclosure of data to public authorities or authorising access by such authorities – relevant in light of the specific circumstances of the transfer, and the applicable limitations and safeguards (12);
(iii) any relevant contractual, technical or organisational safeguards put in place to supplement the safeguards under these Clauses, including measures applied during transmission and to the processing of the personal data in the country of destination.
(c) The data importer warrants that, in carrying out the assessment under paragraph (b), it has made its best efforts to provide the data exporter with relevant information and agrees that it will continue to cooperate with the data exporter in ensuring compliance with these Clauses.
(d) The Parties agree to document the assessment under paragraph (b) and make it available to the competent supervisory authority on request.
(e) The data importer agrees to notify the data exporter promptly if, after having agreed to these Clauses and for the duration of the contract, it has reason to believe that it is or has become subject to laws or practices not in line with the requirements under paragraph (a), including following a change in the laws of the third country or a measure (such as a disclosure request) indicating an application of such laws in practice that is not in line with the requirements in paragraph (a).
(f) Following a notification pursuant to paragraph (e), or if the data exporter otherwise has reason to believe that the data importer can no longer fulfil its obligations under these Clauses, the data exporter shall promptly identify appropriate measures (e.g. technical or organisational measures to ensure security and confidentiality) to be adopted by the data exporter and/or data importer to address the situation. The data exporter shall suspend the data transfer if it considers that no appropriate safeguards for such transfer can be ensured, or if instructed by the competent supervisory authority to do so. In this case, the data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses. If the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise. Where the contract is terminated pursuant to this Clause, Clause 16(d) and (e) shall apply.
Clause 15 — Obligations of the data importer in case of access by public authorities
MODULE ONE: Transfer controller to controller
15.1 Notification
(a) The data importer agrees to notify the data exporter and, where possible, the data subject promptly (if necessary with the help of the data exporter) if it:
(i) receives a legally binding request from a public authority, including judicial authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses; such notification shall include information about the personal data requested, the requesting authority, the legal basis for the request and the response provided; or
(ii) becomes aware of any direct access by public authorities to personal data transferred pursuant to these Clauses in accordance with the laws of the country of destination; such notification shall include all information available to the importer.
(b) If the data importer is prohibited from notifying the data exporter and/or the data subject under the laws of the country of destination, the data importer agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. The data importer agrees to document its best efforts in order to be able to demonstrate them on request of the data exporter.
(c) Where permissible under the laws of the country of destination, the data importer agrees to provide the data exporter, at regular intervals for the duration of the contract, with as much relevant information as possible on the requests received (in particular, number of requests, type of data requested, requesting authority/ies, whether requests have been challenged and the outcome of such challenges, etc.).
(d) The data importer agrees to preserve the information pursuant to paragraphs (a) to (c) for the duration of the contract and make it available to the competent supervisory authority on request.
(e) Paragraphs (a) to (c) are without prejudice to the obligation of the data importer pursuant to Clause 14(e) and Clause 16 to inform the data exporter promptly where it is unable to comply with these Clauses.
15.2 Review of legality and data minimisation
(a) The data importer agrees to review the legality of the request for disclosure, in particular whether it remains within the powers granted to the requesting public authority, and to challenge the request if, after careful assessment, it concludes that there are reasonable grounds to consider that the request is unlawful under the laws of the country of destination, applicable obligations under international law and principles of international comity. The data importer shall, under the same conditions, pursue possibilities of appeal. When challenging a request, the data importer shall seek interim measures with a view to suspending the effects of the request until the competent judicial authority has decided on its merits. It shall not disclose the personal data requested until required to do so under the applicable procedural rules. These requirements are without prejudice to the obligations of the data importer under Clause 14(e).
(b) The data importer agrees to document its legal assessment and any challenge to the request for disclosure and, to the extent permissible under the laws of the country of destination, make the documentation available to the data exporter. It shall also make it available to the competent supervisory authority on request.
(c) The data importer agrees to provide the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.
SECTION IV – FINAL PROVISIONS
Clause 16 — Non-compliance with the Clauses and termination
(a) The data importer shall promptly inform the data exporter if it is unable to comply with these Clauses, for whatever reason.
(b) In the event that the data importer is in breach of these Clauses or unable to comply with these Clauses, the data exporter shall suspend the transfer of personal data to the data importer until compliance is again ensured or the contract is terminated. This is without prejudice to Clause 14(f).
(c) The data exporter shall be entitled to terminate the contract, insofar as it concerns the processing of personal data under these Clauses, where:
(i) the data exporter has suspended the transfer of personal data to the data importer pursuant to paragraph (b) and compliance with these Clauses is not restored within a reasonable time and in any event within one month of suspension;
(ii) the data importer is in substantial or persistent breach of these Clauses; or
(iii) the data importer fails to comply with a binding decision of a competent court or supervisory authority regarding its obligations under these Clauses.
In these cases, it shall inform the competent supervisory authority of such non-compliance. Where the contract involves more than two Parties, the data exporter may exercise this right to termination only with respect to the relevant Party, unless the Parties have agreed otherwise.
(d) Personal data that has been transferred prior to the termination of the contract pursuant to paragraph (c) shall at the choice of the data exporter immediately be returned to the data exporter or deleted in its entirety. The same shall apply to any copies of the data. The data importer shall certify the deletion of the data to the data exporter. Until the data is deleted or returned, the data importer shall continue to ensure compliance with these Clauses. In case of local laws applicable to the data importer that prohibit the return or deletion of the transferred personal data, the data importer warrants that it will continue to ensure compliance with these Clauses and will only process the data to the extent and for as long as required under that local law.
(e) Either Party may revoke its agreement to be bound by these Clauses where (i) the European Commission adopts a decision pursuant to Article 45(3) of Regulation (EU) 2016/679 that covers the transfer of personal data to which these Clauses apply; or (ii) Regulation (EU) 2016/679 becomes part of the legal framework of the country to which the personal data is transferred. This is without prejudice to other obligations applying to the processing in question under Regulation (EU) 2016/679.
Clause 17 — Governing law
MODULE ONE: Transfer controller to controller
These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties agree that this shall be the law of Spain.
Clause 18 — Choice of forum and jurisdiction
MODULE ONE: Transfer controller to controller
(a) Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State.
(b) The Parties agree that those shall be the courts of Spain.
(c) A data subject may also bring legal proceedings against the data exporter and/or data importer before the courts of the Member State in which he/she has his/her habitual residence.
(d) The Parties agree to submit themselves to the jurisdiction of such courts.
(1) Where the data exporter is a processor subject to Regulation (EU) 2016/679 acting on behalf of a Union institution or body as controller, reliance on these Clauses when engaging another processor (sub-processing) not subject to Regulation (EU) 2016/679 also ensures compliance with Article 29(4) of Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39), to the extent these Clauses and the data protection obligations as set out in the contract or other legal act between the controller and the processor pursuant to Article 29(3) of Regulation (EU) 2018/1725 are aligned. This will in particular be the case where the controller and processor rely on the standard contractual clauses included in Decision 2021/915.
(2) This requires rendering the data anonymous in such a way that the individual is no longer identifiable by anyone, in line with recital 26 of Regulation (EU) 2016/679, and that this process is irreversible.
(3) The Agreement on the European Economic Area (EEA Agreement) provides for the extension of the European Union’s internal market to the three EEA States Iceland, Liechtenstein and Norway. The Union data protection legislation, including Regulation (EU) 2016/679, is covered by the EEA Agreement and has been incorporated into Annex XI thereto. Therefore, any disclosure by the data importer to a third party located in the EEA does not qualify as an onward transfer for the purpose of these Clauses.
(4) The Agreement on the European Economic Area (EEA Agreement) provides for the extension of the European Union’s internal market to the three EEA States Iceland, Liechtenstein and Norway. The Union data protection legislation, including Regulation (EU) 2016/679, is covered by the EEA Agreement and has been incorporated into Annex XI thereto. Therefore, any disclosure by the data importer to a third party located in the EEA does not qualify as an onward transfer for the purpose of these Clauses.
(5) See Article 28(4) of Regulation (EU) 2016/679 and, where the controller is an EU institution or body, Article 29(4) of Regulation (EU) 2018/1725.
(6) The Agreement on the European Economic Area (EEA Agreement) provides for the extension of the European Union’s internal market to the three EEA States Iceland, Liechtenstein and Norway. The Union data protection legislation, including Regulation (EU) 2016/679, is covered by the EEA Agreement and has been incorporated into Annex XI thereto. Therefore, any disclosure by the data importer to a third party located in the EEA does not qualify as an onward transfer for the purposes of these Clauses.
(7) This includes whether the transfer and further processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions or offences.
(8) This requirement may be satisfied by the sub-processor acceding to these Clauses under the appropriate Module, in accordance with Clause 7.
(9) This requirement may be satisfied by the sub-processor acceding to these Clauses under the appropriate Module, in accordance with Clause 7.
(10) That period may be extended by a maximum of two more months, to the extent necessary taking into account the complexity and number of requests. The data importer shall duly and promptly inform the data subject of any such extension.
(11) The data importer may offer independent dispute resolution through an arbitration body only if it is established in a country that has ratified the New York Convention on Enforcement of Arbitration Awards.
(12) As regards the impact of such laws and practices on compliance with these Clauses, different elements may be considered as part of an overall assessment. Such elements may include relevant and documented practical experience with prior instances of requests for disclosure from public authorities, or the absence of such requests, covering a sufficiently representative time-frame. This refers in particular to internal records or other documentation, drawn up on a continuous basis in accordance with due diligence and certified at senior management level, provided that this information can be lawfully shared with third parties. Where this practical experience is relied upon to conclude that the data importer will not be prevented from complying with these Clauses, it needs to be supported by other relevant, objective elements, and it is for the Parties to consider carefully whether these elements together carry sufficient weight, in terms of their reliability and representativeness, to support this conclusion. In particular, the Parties have to take into account whether their practical experience is corroborated and not contradicted by publicly available or otherwise accessible, reliable information on the existence or absence of requests within the same sector and/or the application of the law in practice, such as case law and reports by independent oversight bodies.
APPENDIX
The information below completes the Appendix for Module One. A project-specific Transfer Schedule supplements it where a transfer requires narrower or additional detail.
ANNEX I
A. LIST OF PARTIES
Data exporter
Name: AMBAR PARTNERS TECH SERVICES, S.L.
Address: Guzmán el Bueno 133, Edificio Britannia, 28003 Madrid, Spain
Contact: lopd@ambarpartners.com
Activities relevant to the data transferred under these Clauses: operation of Ambar Hauss and coordination, evaluation or performance of professional opportunities and legal-service projects involving the relevant User.
Signature and date: electronic acceptance record maintained by Ambar for the applicable SCC version and Transfer Schedule.
Role: controller.
Data importer
Name, professional address and account email: the relevant User identified in the individual electronic acceptance record and applicable Transfer Schedule.
Contact person with responsibility for data protection: the User or other contact recorded in the User’s Ambar Hauss account or Transfer Schedule.
Activities relevant to the data transferred under these Clauses: evaluation or performance of a professional opportunity or independent legal-service project, and related communications, conflict checks, administration and compliance.
Signature and date: the User’s affirmative electronic acceptance, linked to the account identifier, exact SCC text and Schedule, date, time and acceptance event.
Role: controller, unless a different role is expressly recorded in a separately completed module or project addendum.
B. DESCRIPTION OF TRANSFER
Categories of data subjects
Clients and prospective clients and their personnel; Users and professional collaborators; counterparties, advisers, witnesses and other persons involved in a matter; employees, contractors, suppliers and professional contacts; and other individuals whose information is necessarily contained in the relevant opportunity or project materials.
Categories of personal data
Identification and professional contact data; professional and employment information; communications; client, matter, project and conflicts information; compliance, billing and administrative data; technical access and security data; and other personal data that are necessary for the relevant opportunity or project and expressly described in the applicable Transfer Schedule.
Sensitive data and safeguards
Special-category data and data relating to criminal convictions are not transferred as part of the ordinary Ambar Hauss workflow. If a project requires them, access must be specifically authorised and recorded in the Transfer Schedule. Additional safeguards will include strict purpose limitation, need-to-know access, confidentiality, minimisation, secure transmission and storage, restrictions on local copies and onward transfers, enhanced deletion requirements, and any client-specific controls.
Frequency of transfer
One-off, occasional or recurring during the evaluation or performance of the relevant opportunity or project, as recorded in the Transfer Schedule.
Nature of processing
Secure access, review, collection, organisation, use, communication, analysis, drafting, professional advice, limited storage where necessary, return and deletion.
Purposes of the transfer and further processing
To evaluate, commence, administer and perform a professional opportunity or legal-service project; conduct related conflicts and compliance checks; communicate with authorised participants; protect the security and integrity of Ambar Hauss; and establish, exercise or defend legal claims where necessary.
Retention
For the duration of the relevant opportunity or project and thereafter only for a period required by applicable legal, regulatory or professional obligations or for the establishment, exercise or defence of legal claims. When the authorised purpose ends, the data will be returned or securely deleted, subject to those duties and any project-specific Schedule.
C. COMPETENT SUPERVISORY AUTHORITY
Agencia Española de Protección de Datos (Spanish Data Protection Agency).
ANNEX II
TECHNICAL AND ORGANISATIONAL MEASURES
The following measures apply to the User as data importer, together with any stricter measure in the applicable Transfer Schedule:
- access only through the User’s individual account and unique credentials, with multi-factor authentication where available;
- least-privilege access limited to the data necessary for the authorised opportunity or project, with access removed when no longer needed;
- supported and security-patched devices, screen locking, malware protection where appropriate, and full-disk or equivalent encryption for devices storing transferred data;
- encryption in transit through approved services and secure storage. Personal data may not be sent through personal or unauthorised channels;
- no local download or copy unless necessary and authorised. Any authorised local copy must be protected to the same standard and securely deleted when no longer required;
- professional secrecy and confidentiality obligations for every person permitted to access the data, with no credential sharing;
- appropriate physical security for locations where data are accessed, including protection against viewing or access by unauthorised persons;
- logging and preservation of available access, security-incident and disclosure-request evidence, and cooperation with Ambar’s investigations and audits;
- immediate reporting to Ambar of any actual or suspected personal-data breach, unauthorised access, public-authority request or inability to comply, with containment and preservation of evidence;
- data minimisation, accuracy checks where relevant, defined retention and secure deletion or return at the end of the authorised purpose;
- no onward transfer unless authorised, documented and covered by an applicable Chapter V GDPR safeguard;
- no entry of transferred personal, privileged or confidential data into public or unauthorised AI tools, and no use of transferred data for model training, profiling or ranking without a documented lawful basis and Ambar’s prior written authorisation; and
- periodic review of these measures and completion of onboarding and annual security or transfer-compliance confirmations requested by Ambar.
ANNEX III
Not applicable to Module One. If the User acts as a processor under Module Two or Three and specific authorisation of sub-processors is selected, the relevant module and Annex III must be completed in a separate data-transfer addendum or Transfer Schedule before processing begins.