Sub-Processors
Effective Date: July 10, 2026
1. Overview
Amber News engages third-party sub-processors to assist in providing our Services. This page lists all sub-processors that may process personal data on behalf of our customers, the types of data they process, and their geographic location.
All sub-processors are bound by Data Processing Agreements that require them to:
- Process data only according to our instructions.
- Implement and maintain appropriate technical and organisational security measures.
- Notify us promptly of any personal data breaches.
- Delete or return personal data upon termination of services.
- Engage further sub-processors only with our prior written consent.
Amber News undertakes to use a commercially reasonable selection process by which it evaluates the security, privacy, and confidentiality practices of proposed sub-processors prior to engagement.
2. Current Sub-Processors
Infrastructure & Hosting
| Sub-Processor | Service | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, application hosting, object storage (S3), and compute services | All service data including voice recordings, transcripts, account data, user configurations, and call metadata | United States |
AI & Voice Services
| Sub-Processor | Service | Data Processed | Location |
|---|---|---|---|
| ElevenLabs Inc. | AI voice synthesis (text-to-speech via Flash v2.5) and real-time speech-to-text transcription (Scribe v2) | Text inputs, synthesised audio outputs, voice configuration data, call audio streams (STT inference via Scribe v2) | United States, Netherlands, Singapore |
Communication Services
| Sub-Processor | Service | Data Processed | Location |
|---|---|---|---|
| Mailgun Technologies, Inc. (Sinch Group) | Transactional notification and OTP email delivery to users and administrators; used only for operational emails | Email addresses, names, notification and OTP message content, delivery metadata | United States |
Web Security
| Sub-Processor | Service | Data Processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Web application firewall (WAF) and DDoS mitigation for protecting web-facing services and APIs | IP addresses, HTTP request headers, traffic patterns, limited connection metadata (no application-layer content) | Global |
Payment Processing
| Sub-Processor | Service | Data Processed | Location |
|---|---|---|---|
| Amber Pay (via PowerTranz) | Payment processing and payment gateway services | Cardholder names, card numbers (tokenised), transaction amounts, billing addresses, transaction metadata | Caribbean |
| Amber Pay / PowerTranz Payment Gateway Agreement | Amber Pay payment processing sub-processor, covering tokenised cardholder data, transaction processing, and settlement through PowerTranz (Mastercard). PCI DSS Level 1 certified. | Cardholder names, card numbers (tokenised), transaction amounts, billing addresses, transaction metadata | Caribbean |
3. Sub-Processor Details
Amazon Web Services (AWS)
- Entity: Amazon Web Services, Inc.
- Parent Company: Amazon.com, Inc.
- Category: Infrastructure & Hosting
- Purpose: Primary cloud infrastructure provider for application hosting, data storage (including voice recordings stored in Amazon S3), compute services, and database management.
- Data Types: All customer data, including personal data, voice recordings, call transcripts, call metadata, account data, and usage logs.
- Location: United States (primary), data may be stored in other AWS regions as configured.
- Certifications: SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS Level 1, CSA STAR.
- Privacy Policy: aws.amazon.com/privacy
- DPA: AWS Global Data Processing Addendum (incorporated into AWS Service Terms)
- Sub-processor List: AWS sub-processors
- Data Retention: AWS S3 does not impose a fixed vendor-side retention period. Retention is entirely controlled by Amber News via S3 Lifecycle Policies. Amber News retains call recordings and transcripts for up to 3 years from the date of the call.
ElevenLabs Inc.
- Entity: ElevenLabs Inc.
- Category: AI & Voice Services
- Purpose: Provides AI-powered voice synthesis (text-to-speech via Flash v2.5 model) and real-time speech-to-text transcription (via Scribe v2 realtime model) for Amber News voice agents.
- Data Types: Text inputs submitted for synthesis, synthesised audio outputs, voice configuration and model data, call audio streams (for speech-to-text inference via Scribe v2).
- Location: United States (primary), processing may also occur in the Netherlands and Singapore.
- Privacy Policy: elevenlabs.io/privacy
- DPA: ElevenLabs Data Processing Addendum
- Trust Center: compliance.elevenlabs.io
- Data Retention: Data is permanently erased upon account deletion or when the customer deletes data. Backups are retained for up to a maximum of 50 days, after which they are automatically erased. This applies to both the ElevenLabs Scribe v2 realtime model (STT) and the ElevenLabs Flash v2.5 model (TTS). Zero Retention Mode is available for enterprise customers, in which case no data is held once the requested job is completed.
- Note: Voice data may be used by ElevenLabs for AI model improvement. An opt-out is available via ElevenLabs account settings or upon request to ElevenLabs support. Under Zero Retention Mode, data is not retained after processing.
Mailgun Technologies, Inc.
- Entity: Mailgun Technologies, Inc.
- Parent Company: Sinch Group
- Category: Communication Services
- Purpose: Transactional email delivery for customer-facing notifications and one-time passwords (OTPs) only. Mailgun is not used for marketing communications.
- Data Types: Recipient email addresses, names, email subject lines and OTP/notification message content, email delivery metadata.
- Location: United States
- Privacy Policy: mailgun.com/legal/privacy-policy
- DPA: Mailgun Data Processing Addendum
- Data Retention: Email message bodies (including notification and OTP content) are securely purged after 3 days. Email event logs (delivery status, timestamps, bounce records) are retained for up to 30 days.
Cloudflare, Inc.
- Entity: Cloudflare, Inc.
- Category: Web Security
- Purpose: Provides web application firewall (WAF) services and DDoS mitigation for protecting Amber News web-facing services and APIs against application-layer threats.
- Data Types: IP addresses, HTTP request headers, traffic patterns, and limited connection metadata. Cloudflare does not access or store call recordings, transcripts, voice data, or application-layer content.
- Location: Global (Cloudflare processes traffic at data centres worldwide for WAF and DDoS inspection).
- Certifications: SOC 2 Type II, ISO 27001, ISO 27018, PCI DSS Level 1, FedRAMP.
- Privacy Policy: cloudflare.com/privacypolicy
- DPA: Cloudflare Data Processing Addendum
- Data Retention: Real-time security logs retained for up to 72 hours for threat detection and analysis. Enterprise log retention may extend to 30 days. Cloudflare does not store application-layer content or Personal Data beyond what is necessary for security analysis.
Amber Pay (via PowerTranz)
- Entity: Amber Pay Limited
- Payment Gateway: PowerTranz (a Mastercard company)
- Category: Payment Processing
- Purpose: Payment processing and payment gateway services for Amber News. Amber Pay provides PCI DSS-compliant payment acceptance, processing, and settlement services. Transactions are routed through PowerTranz, a Mastercard-owned payment gateway operating in the Caribbean and Americas region.
- Data Types: Cardholder names, card numbers (tokenised at point of capture), transaction amounts and currency, billing addresses, transaction reference identifiers, payment status and settlement metadata.
- Location: Caribbean and United States. Payment transactions are processed through PowerTranz data centres with primary operations in the Caribbean region.
- Certifications: PCI DSS Level 1 (Amber Pay). PowerTranz is a PCI DSS Level 1 certified payment gateway and a Mastercard subsidiary.
- Website: myamberpay.com
- Payment Gateway: powertranz.com
- Data Retention: Card numbers are tokenised at point of capture and are never stored in their original form. Transaction records are retained for the period required by applicable financial regulations and card scheme rules (typically up to 7 years for audit and chargeback purposes). Tokenised payment data is purged upon account closure and expiry of regulatory retention obligations.
- Note: Amber Pay does not store raw card numbers, CVVs, or magnetic stripe data. All sensitive cardholder data is tokenised and encrypted in transit via TLS 1.2+. PowerTranz, as a Mastercard subsidiary, operates under Mastercard's global security and compliance standards.
4. Data Transfer Safeguards
For sub-processors located outside your jurisdiction, we implement appropriate safeguards for the international transfer of personal data:
| Safeguard | Applicable To |
|---|---|
| Standard Contractual Clauses (SCCs) | All non-EEA sub-processors processing personal data of EEA residents |
| UK International Data Transfer Agreement (IDTA) | Sub-processors processing personal data of UK residents |
| EU-U.S. Data Privacy Framework | Certified US-based sub-processors where applicable |
| Data Processing Agreements (DPAs) | All sub-processors, across all jurisdictions |
| DPDPA Cross-Border Transfer Compliance | Sub-processors processing personal data of residents of India, pursuant to the Digital Personal Data Protection Act, 2023 |
| Jamaica Data Protection Act Compliance | Sub-processors processing personal data of residents of Jamaica, pursuant to the Data Protection Act, 2020 |
| Cloudflare Data Processing Addendum | Cloudflare WAF sub-processor, covering web security metadata processed for firewall and DDoS mitigation |
5. Changes to Sub-Processors
Notification Process
We may update our sub-processors from time to time. When we add or replace a sub-processor that processes personal data:
- We will update this page with the new sub-processor details and the effective date of the change.
- Enterprise customers with Data Processing Agreements in place will receive email notification at least 30 days prior to the change becoming effective.
- Changes become effective 30 days after the date of posting, unless otherwise agreed in writing.
Objection Process
If you have legitimate concerns about a new or replacement sub-processor on grounds related to data protection or data security:
- Contact us at [email protected] within 30 days of the date of notification.
- We will work with you in good faith to address any legitimate data protection or security concerns.
- If concerns cannot be resolved, you may within 30 days of concluded negotiations terminate the affected Services upon written notice.
6. Contact
For questions about our sub-processors or to request copies of Data Processing Agreements:
Email: [email protected]
Address: Data Protection Officer, Amber Connect Limited, 5th Floor, 13, Haining Road, Kingston 5, Jamaica.