Amplifa – AI sales platform for industrial B2B

Trust Center · DE · Düsseldorf · Frankfurt

Data protection and security – Made in Germany.

German provider and contracting party based in Düsseldorf. The customer application runs on Render in Frankfurt; object data is stored in Amazon S3 eu-central-1.

Core hosting in Germany: Render Frankfurt and Amazon S3 eu-central-1. Other processing and any third-country transfers are documented in the subprocessor list.

  • Made in Germany. Engineering & operations in Düsseldorf
  • GDPR-compliant. DPA, TOMs & subprocessor list
  • Core hosting in Germany. Render Frankfurt · S3 eu-central-1
  • Credentials protected. TLS · tokens and API credentials AES-256-GCM
  • Vendor-onboarding ready for DAX & Mittelstand
  • DPA, TOMs & TIA available within 24 h
  • Auditable per § 9 of our DPA
  • NIS-2 supply-chain ready

Compliance at a glance

Everything your privacy and procurement team reviews.

  • Data processing under Art. 28 GDPR. Ready-to-sign DPA
  • Technical & organizational measures. Art. 32 GDPR
  • Data-breach notification. within 24 hours to the controller
  • Record of processing activities. Art. 30 GDPR
  • No special categories (Art. 9). Business B2B contact data only
  • Privacy by Design & by Default. Privacy-friendly defaults
  • Annual penetration tests. Independent third parties, monthly scans
  • Employee training. Privacy & InfoSec, mandatory yearly
  • ISO 27001 / SOC 2 Type II / BSI C5. Roadmap – in preparation
  • Incident-response process. Aligned with NIS-2

Made in Germany

Fully German. Fully enterprise-ready.

amplifa is a German company and contracting party with product and engineering in Germany. The core application is operated in Frankfurt; other processing is transparently listed in the subprocessor register.

  • HQ & engineering in Düsseldorf. amplifa GmbH, Luisenstraße 9, 40215 Düsseldorf. Registered with the commercial register at Düsseldorf local court. Product and engineering team 100% in Germany.
  • Core hosting in Frankfurt. Rails 8 application, PostgreSQL, Redis and background workers on Render in Frankfurt; object data in Amazon S3 eu-central-1. Provider certifications apply only to the respective provider.
  • German law, jurisdiction Düsseldorf. T&Cs per BGB/HGB, German contracting party, exclusive jurisdiction Düsseldorf. No US or offshore contract constructs.
  • Dedicated EU customer success. Named contacts in Düsseldorf for Sales, Customer Success, Security and Privacy. Full English communication, no offshore hotlines.
  • Compliance stack DE & EU. GDPR, BDSG, UWG, NIS-2 Readiness Statement, EU AI Act conformity declaration, BSI C5:2020 self-assessment, Transfer Impact Assessment (Schrems II).
  • Taxes & invoicing in DE. Invoices with German VAT (VAT ID pending registration), HGB-compliant bookkeeping, payment by SEPA direct debit or bank transfer.

amplifa GmbH · Luisenstraße 9 · 40215 Düsseldorf · Germany. Contracting party for all commercial relationships. Third-country processing by individual subprocessors is listed in AMP-TC-003 and protected by appropriate safeguards.

Subprocessors

Transparent. Complete. Current.

Complete list of all subprocessors per Art. 28 (2) GDPR – broken down by infrastructure, AI inference, sales tooling and tracking. Third-country transfers exclusively under EU Standard Contractual Clauses 2021/914 with a documented Transfer Impact Assessment (Schrems II, AMP-TC-017).

A. Infrastructure, platform & collaboration

Core customer-application infrastructure on Render Frankfurt and Amazon S3 eu-central-1; the marketing website is technically separate.

B. LLM & AI inference

AI providers are selected for data minimisation, training exclusion and appropriate retention terms (see AMP-TC-015).

C. Sales, data enrichment & outreach

Legitimate interest in conjunction with § 7 UWG, whitelist criteria, opt-out mechanics and suppression list (see DPA § 8b).

D. Analytics, tracking & reach (consent-based only)

Activated exclusively after consent via the cookie banner (Art. 6 (1) lit. a GDPR in conjunction with § 25 TDDDG, Consent Mode v2).

Changes to this list are communicated to controllers at least 30 days in advance (Art. 28 (4) GDPR). Full TIA assessment and certificates per provider on request (AMP-TC-003, AMP-TC-017).

Security highlights

Confidentiality. Integrity. Availability.

Confidentiality

  • Tokens and API credentials protected with AES-256-GCM
  • Email-based 2FA for administrators
  • Role-based access following least privilege
  • Logical separation: every record is scoped to an organisation

Integrity

  • TLS for data transmission
  • API keys stored only as SHA-256 hashes
  • HMAC-SHA256-signed, replay-protected webhooks
  • Audit trails for security-relevant actions

Availability

  • Production application on Render in Frankfurt
  • PostgreSQL, Redis, S3 object storage and background workers as separate components
  • Configurable human-review gates before sending
  • Suppression and unsubscribe checks before campaign processing

Incident Response

Clear reporting paths when it matters.

Report a security incident

Vulnerabilities, suspected cases and responsible-disclosure reports are accepted any time at:

Reporting channels & deadlines

  • Notification to the supervisory authority within 72 hours (Art. 33 GDPR)
  • Notification of affected controllers within 24 hours
  • Documented incident lifecycle with severity classification P1 – P4

FAQ

For procurement & data protection officers.

Where is our data hosted?

The production customer application runs on Render in Frankfurt am Main. Object data is stored in Amazon S3 in the eu-central-1 region. Other providers are documented in AMP-TC-003.

Will amplifa sign a DPA with us?

Yes. We provide a ready-to-sign Data Processing Agreement under Art. 28 GDPR including TOMs (Art. 32) and a complete subprocessor list.

Does data leave the EU?

The core application and object storage operate in EU regions. Individual subprocessors may process data outside the EEA; appropriate safeguards under Art. 46 GDPR are used.

How fast are we notified of an incident?

Affected controllers are notified within 24 hours of becoming aware. Notifications to the competent supervisory authority are made within the statutory 72-hour deadline (Art. 33 GDPR).

What data does amplifa process?

Exclusively business B2B contact data (name, business email, role, company). No special categories of personal data under Art. 9 GDPR.

Can we audit amplifa?

Yes. Evidence and on-site audits are possible per § 9 of our DPA after reasonable advance notice.

What happens to our data after the contract ends?

Return or verifiable deletion at the controller's choice per § 11 of our DPA. A deletion confirmation is issued.

Amplifa: Home · Product · AI SDR Agents · ICP Playbook · About · Book a call · Webinar

Resources: Blog · Sales Glossary · Studies · Guides · Workflows · Tool Comparison · Email Finder · Intent Finder · Lookalike Finder · Tools

Industries: Mechanical Engineering · Medical Technology · Automotive · Chemicals · Electronics · Metal Industry · Plastics · Food · Packaging · Consumer Goods · Energy · Software

Success Stories: Overview

Legal: Imprint · Privacy · Terms