Privacy Policy
This Privacy Notice describes how Mistlabs Limited d/b/a Ambi (“we”, “us”, “our”) collects, uses and discloses information about you when you use our website (https://www.ambi.ai), applications, services, tools and features — including our AI work assistant app (Ambi) (“App”), our cloud and synchronization services, and our AI-powered features such as recording, transcription, summarization, search, memory, tasks and connectors — or otherwise interact with us (collectively, the “Services”).
For the purposes of applicable data protection laws, Mistlabs Limited d/b/a Ambi is the data controller responsible for the processing described in this Privacy Notice. If you have any privacy-related questions, please contact our data protection team at support@ambi.ai. Our address appears under “How to Contact Us”.
Please read this Privacy Notice carefully. It explains our information practices and your choices and rights. Where applicable law requires consent for particular processing, we will seek that consent separately; using the Services or acknowledging this Privacy Notice does not replace it.
1.Changes to this privacy notice
We may modify this Privacy Notice from time to time, in which case we will update the “Last Updated” date above. We will provide notice of material changes as required by applicable law, for example through the Services or by email, and obtain consent or take other steps where required. Changes will not retrospectively override commitments concerning information already collected without a lawful basis and any required notice or consent.
2.Collection and use of information
When you use or access the Services, we collect the categories of information described below from you, your use of the Services and other sources. We use information to provide the features you request, maintain your account, provide support, administer payments, protect security, prevent misuse, comply with legal obligations and establish or defend legal claims. We also use usage and diagnostic information to understand and improve the Services, subject to the private-content restrictions below. The legal bases described in this Notice apply only where recognized by applicable law; additional regional information appears under “Privacy Rights”.
Information You Provide to Us
Some features of the Services require information to function. You may elect not to provide it, but this may prevent you from using the relevant feature. Information you provide and information generated from your use of these features includes:
- Contact information, such as your email address and other contact details you choose to provide. We use this information to create and maintain your account and provide the Services under our contract with you. We also use it to send our own marketing communications, with your consent where legally required. You may opt out as described below.
- Account information, such as your username, profile details, language, account ID and authentication information. You may create or access your account using email registration or a supported third-party provider such as Google or Apple. We use this information to create, maintain and secure your account and perform our contract with you. You are responsible for keeping your account credentials safe. If you believe your account has been compromised, please contact us immediately.
- Recordings and user content, such as audio, transcripts, speaker labels, summaries, prompts, notes, uploaded files, photos, documents and messages, together with metadata such as file names and timestamps. We process this information through the recording, chat, capture and content-creation features you use to perform our contract with you. Audio may include the voices of other people within range of your device.
Listening and Recording process audio when you grant microphone access and start the relevant feature in Ambi. You can pause or stop Listening or Recording through the App. Audio needed for transcription and AI processing is sent to cloud services, directly or through our backend. Listening audio is streamed to Soniox for real-time transcription and is not stored in the cloud. Listening supports ongoing context; active Recording enables recorded audio to be saved for later use. Audio, transcripts, summaries and Memory have distinct retention rules, as explained under “Data Security and Retention”.
Speaker labels help distinguish speakers in a conversation and are not proof of identity. The launch version does not extract or store voiceprints or use voiceprints to identify a particular person. If a voice-identification feature is offered, we will explain its purpose and provide any additional notice and obtain any consent or written authorization required before the relevant processing. An account holder’s acceptance of this Notice does not authorize enrollment of another person’s voice.
- Input and Output. We process information you submit to our AI-powered tools (“Input”) to generate responses or other content (“Output”), such as transcripts, summaries, answers, action items, labels, search results and memory items, to perform our contract with you. AI processing can produce inaccurate or incomplete information.
- Memory and personalization information, including information you save or ask us to remember and information automatically extracted or inferred from captures, recordings, conversations, completed tasks and your interactions. This can include preferences, recurring context, facts, summaries, profiles of people and relationship history. We use it to personalize your own Outputs, maintain context and organize information as part of the Services you request. Memory may be incomplete or incorrect and may contain personal information about you or other people. You can request access, correction or deletion as described under “Privacy Rights”, including where a self-service control is unavailable.
- Tasks, reminders and proactive engagement information, such as task titles, due dates, statuses, source references, reminder rules, notification settings, completion history, and records of proactive prompts (for example, “Heads Up,” “Suggested” and “Need You” interactions), which we use to provide task management, reminders and proactive features, as required to perform our contract with you.
- Sharing and collaboration information, such as recipient information, sharing links, access controls, when you choose to share recordings, summaries, links or other content with third parties (including those that do not have a registered account for the Services), as required to perform our contract with you.
- Actions taken on your behalf in other services, including content, recipients, destination accounts, action parameters, confirmation records, status, timestamps and action logs. We use this information to perform, secure and troubleshoot the action you request. External actions, such as sending an email, changing a calendar event, sharing or modifying a file, making a payment or accepting third-party terms, require the authorization and confirmation described in our Terms of Service. Connecting an account or receiving a suggestion does not by itself authorize an external action.
- Subscription and payment information, such as your selected plan, subscription status, Credit balances and usage, purchase and transaction records, and billing details you provide. We use this information to process purchases, administer subscriptions and Credits, provide billing support and comply with accounting and tax obligations. Payment providers also process information under their own privacy notices.
- Any other information you choose to include in communications with us, for example, when contacting our customer support team, as required to perform our contract with you.
We do not use your private content, including recordings, transcripts, prompts, files, messages, summaries, Memory, connector-derived content and other Input or Output, to train, optimize or develop the Services. Processing that is needed to respond to your requests, maintain context and personalize your own experience is part of providing the Services. The use of usage and diagnostic information described below does not authorize using private content for general product development.
Third-party AI model and automatic speech recognition (“ASR”) providers process the content needed to provide requested features, including transcription and generation of Outputs. Our principal providers include OpenAI, Anthropic and Google (Gemini) for AI processing, Soniox for speech recognition and Google Cloud Platform for cloud infrastructure; integration providers also support these workflows. Our providers’ processing remains subject to the purposes and restrictions described in this Notice and applicable arrangements. The absence of model training does not mean that no information is transmitted to or retained by a provider.
Access to account and technical information by authorized personnel is limited to service, support, security and legal purposes permitted by this Notice. Optional human review of recaps, tasks and Memory is disabled by default. If you separately opt in through Settings, only a small number of authorized personnel in the United States may review those categories for the purpose explained when you opt in. Recordings, transcripts and chats are not available for human review by Ambi personnel, whether or not you enable that option. You may withdraw your choice for future review. This option does not override our private-content restrictions, other individuals’ rights or applicable platform restrictions.
Information Collected Automatically
We automatically collect device and usage information to operate, secure and troubleshoot the Services, understand feature usage and improve performance. This includes:
- Device information, such as your device model, app version, operating system and device identifiers.
- Interaction and diagnostic information, such as feature use, clicks, error and crash logs, and account or device identifiers associated with those events.
Our product analytics, including PostHog, use structured usage events and identifiers rather than the contents of recordings, transcripts, prompts or other private content. Identifiers linked to an account remain personal information even if a name or email address is removed. Where cookies, SDKs or similar technologies require consent, we seek that consent before their use and provide the choices required by applicable law. Essential technologies may be needed for requested functionality and security.
Information Collected from Other Sources
We may obtain information about you from outside sources, including information that we collect directly from third parties and information from third parties that you choose to share with us. Such information includes:
- Information we receive when you choose to sign in to or access the Services through a third-party provider, such as Google or Apple, which we use to maintain your account and login information, as required to perform our contract with you. These providers process authentication data under their own terms and provide us with your sign-in information such as your name, email address and additional account information you authorize.
- Information we receive from connectors, such as Google Calendar, Gmail, Google Drive, Google Docs, Google Sheets, Slack and Lark, when you choose to connect a supported service. Depending on the permissions you authorize, this can include calendar details, email or message content and metadata, documents, files, account identifiers, access tokens and permission scopes. We use this information to provide the connected features and authorized actions you request. Permissions are limited by the authorization you grant; they do not necessarily give Ambi access to your entire third-party account. Third-party integration providers may facilitate a connection.
You can revoke connector access in Ambi Settings or through the connected platform’s account permissions. Revocation stops future access and pending or retried actions that depend on that permission. An action already submitted to a third party may have taken effect and may not be reversible. Information already imported is subject to the retention rules below. For Google data, we stop obtaining new data after disconnection and delete previously obtained Google data within 30 days, unless retention is required by law.
Our use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements, and applicable Google Workspace API policies. These restrictions also apply to covered derived data, including relevant Memory. We do not use covered Google data to train or improve generalized AI models, or permit such use by AI or ASR providers. Human review, disclosure and other uses remain subject to those policies; general acceptance of this Notice or an optional review choice does not authorize a prohibited use.
Information obtained from other sources is handled under this Privacy Notice. Third parties remain responsible for their independent processing under their own policies. This does not limit our responsibility for information that we process. See “Third-Party Websites and Materials” below.
Information About Other People
Recordings, uploaded content, connected accounts, sharing and authorized actions may contain information about meeting participants, correspondents, contacts or other people who do not have an Ambi account. We may receive their voices, names, communications, files and related context from an Ambi user or that user’s connected service, and generate transcripts, summaries or Memory from that information to provide the requested features. Users must provide required notices and obtain necessary permissions before recording or providing others’ information, and stop recording where the required permission is absent or withdrawn. This does not replace our own legal obligations.
If your information appears in content processed by Ambi, you may contact support@ambi.ai without creating an account. We may ask for information reasonably needed to identify the relevant content and verify your request while protecting other people’s information. Content and resulting inferences may include sensitive information, such as health information, depending on what is provided or captured. We process such information only where an applicable legal basis and any additional conditions or permissions required by law are met.
Deidentified Information
We may deidentify or anonymize information so that it cannot reasonably be linked to or used to infer information about an individual, or collect information already in that form. We may use it for purposes permitted by law, subject to the private-content restrictions and applicable platform requirements described above. We maintain and use deidentified information in deidentified form and do not attempt to re-identify it, except where permitted by law to test our deidentification process. Replacing names with identifiers alone does not make information anonymous.
3.Disclosure of your information
We may disclose your information for legitimate purposes subject to this Privacy Notice, including:
- Vendors or other service providers who help us provide the Services, including cloud hosting and storage, AI model and ASR processing, connector integration, authentication, analytics, notifications, customer support and payment or subscription administration. We provide information relevant to their functions, subject to applicable purpose, confidentiality and data-protection requirements.
- Our affiliates or others within our corporate group, as a matter of our legitimate interests to efficiently provide the Services.
- Third-party integrations and external agents at your direction, including the calendar, email, storage, document, messaging or agent services you choose to connect or use. Requested tasks or actions may require sending content, relevant context, action parameters and recipient details to those services. Their independent processing is governed by their own policies.
- Other users or recipients, but only when you choose to share summaries, links or other content, or otherwise make information visible to others, to perform our contract with you and in our legitimate interests to provide you with access to the Services.
- Professional advisors, such as auditors, law firms or accounting firms, as a matter of our legitimate interests to assess, protect, enforce and defend our rights and to comply with our legal and regulatory obligations.
- Third parties in connection with or anticipation of an asset sale, merger, acquisition, or other business transaction, including in the context of a bankruptcy proceeding or other restructuring matter, as a matter of our legitimate interests to run a successful and efficient business.
- For legal and security reasons, where required or permitted by law, including responding to valid legal process and regulatory inquiries, preventing fraud or unlawful activity, establishing or defending legal claims, protecting the safety and security of our business and individuals, and enforcing our terms or other agreements.
4.Third-party websites and materials
We may provide links to third-party websites or platforms and display or make available content, data, applications or materials from third parties. If you follow links to sites or platforms that we do not control and are not affiliated with us, you should review the applicable privacy notice, policies and other terms. We are not responsible for the privacy or security of, or information found on, these sites or platforms, or the accuracy, completeness or reliability of third-party materials. Information you provide on public or semi-public venues, such as third-party social networking platforms, may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators.
5.Minors
Our Services are intended for users who are at least 18 years old and have reached the legal age of majority in their country or region of residence, whichever age is higher. We do not knowingly permit anyone below that age threshold to create an account. Content supplied by adult users may nevertheless contain information about children or other minors. If we learn that a minor has registered or that a child’s information has been processed unlawfully, we will take appropriate steps as required by law, including deletion where applicable. A parent or guardian may contact us using the details below about a child’s information.
6.Data security and retention
We use commercially reasonable technical and organizational security measures designed to protect personal information from unauthorized access, use or disclosure, including encryption and access restrictions. No system is completely secure, and we cannot guarantee absolute security. Please safeguard your credentials and avoid sending sensitive information through unsecured channels.
We retain information for the periods or purposes below, subject to valid deletion requests and applicable law. Where a fixed period is not specified, we consider the type and sensitivity of the information, the feature requested, account activity, legal and accounting requirements, security needs and the establishment or defense of legal claims. Any exceptional retention is limited to the relevant purpose and does not authorize continued personalization or a new use.
The following rules distinguish original files, saved content, usage logs and connector data:
| Personal Information | Retention Policy |
|---|---|
| Account, contact, subscription and transaction information | Account and contact information is retained while your account is active and deleted when you confirm account deletion, subject to the limited legal-retention exceptions described in this Notice. Billing and transaction records are retained as needed to administer purchases and meet applicable accounting, tax, dispute and fraud-prevention requirements. Limited records may be kept after account deletion for those purposes. |
| Original audio recordings and uploaded raw files | Audio saved through Recording and user-uploaded raw files are retained for 90 days, subject to earlier deletion where applicable. Audio streamed during Listening without Recording is not stored in the cloud. Transcripts, summaries and other derived content are treated separately below. |
| Transcripts, summaries, other saved user content, Input and Output, Memory and personalization information, tasks, sharing records and action records | Generally retained while your account remains active, unless you delete the relevant information, request deletion under applicable law or select a shorter available retention setting. The separate periods for raw files, technical logs and Google data apply where relevant. |
| Device, usage, diagnostic and technical log information and other non-persistent intermediate data | Operational logs and other non-persistent intermediate data are retained for 180 days, subject to earlier deletion where applicable. Logs and intermediate data linked to your account are deleted when you confirm account deletion, subject to the limited legal-retention exceptions described in this Notice. This period does not apply to audio processed without storage during Listening, raw files covered by the 90-day rule, or transcripts, summaries and Memory retained with your active account. |
| Connector-derived data | Generally retained while your account remains active, unless deleted earlier. Disconnection stops new access. Previously obtained Google data is deleted within 30 days after disconnection unless retention is required by law; this rule takes precedence over general account-based retention. |
| Support communications and privacy-request records | Retained as needed to resolve and document the request, provide follow-up support and meet applicable legal, security or claims-handling requirements. |
| Contact information for marketing | Retained until you opt out or the information is no longer needed for permitted marketing, whichever occurs first. We may retain a limited suppression record to honor your opt-out. |
You can delete your account through Settings. Once you confirm deletion, we immediately delete your account information and stored user content, including recordings, transcripts, summaries, chats, tasks and Memory, together with account-linked operational logs and intermediate data under our control. Account deletion has no cooling-off or recovery period. You may also make a request concerning particular personal information through the process below without deleting your account. Valid requests extend to relevant derived information, including Memory, and to recipients where required by law. The separate legal-retention rules for billing, transaction and privacy-request records above still apply. Service-provider processing remains subject to our applicable deletion instructions and legal requirements. Independently retained provider records required for their own lawful obligations are subject to their applicable retention rules and may not be used for continued Ambi personalization. Copies held independently by recipients or connected services are subject to their own processes and applicable law.
7.Data transfers
We are based in the United States, and our principal servers and storage, including Google Cloud infrastructure, are located in the United States. Information is also processed by the providers that support the Services. Authorized support and engineering personnel in the United States may access information for permitted purposes. Personnel in China have restricted access to account-linked identifiers and usage information; those identifiers are not anonymous merely because names or email addresses are removed.
International transfers and remote access are subject to applicable data-protection requirements. For information protected by EU/EEA law, a transfer requires an applicable adequacy decision or appropriate safeguards, such as the European Commission’s standard contractual clauses, with supplementary measures where necessary, or a permitted derogation. An adequacy framework covers only recipients within its scope. You may contact support@ambi.ai for information about the safeguards applicable to your information and a copy where available, with necessary redactions. Acknowledging this Notice does not itself constitute consent to an international transfer.
8.Privacy rights
Depending on where you live, you may have certain rights in relation to your personal information. However, please note that a number of these rights only apply in certain circumstances, and all of these rights may be limited by law.
- Access / Know: You may have the right to request access to the personal information we hold about you and to obtain details about what personal information we have collected about you, including the categories of personal information, the categories of sources from which the information was collected, the business or commercial purposes for collecting personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about you. You may also request to obtain a list of specific third parties, other than natural persons, to which we have disclosed your personal information.
- Deletion / Erasure: You may have the right to request that we delete personal information we hold about you.
- Correction: You may have the right to request that we correct inaccurate personal information we hold about you.
- Portability: You may have the right to receive a copy of the personal information we hold about you in a portable and, to the extent technically feasible, readily usable format, and to request that we transfer it to a third party.
- Restriction of Processing: You may have the right to require us to stop, suspend or restrict our processing of personal information we hold about you.
- Objection: You may have the right to object to processing based on legitimate interests on grounds relating to your particular situation, and to object at any time to processing for direct marketing.
- Opt-Out of Marketing: You may opt out of marketing at any time by using the unsubscribe / opt-out instructions provided in our communications to you. If you opt out, we may still send you transactional or administrative messages, such as emails about your account.
- Withdrawal of Consent: Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal and may prevent us from providing a feature that depends on that consent.
- Additional U.S. State Rights: Where applicable, you may opt out of sale, targeted advertising or profiling used for decisions producing legal or similarly significant effects, and exercise rights relating to sensitive data. We do not sell personal information or share it for cross-context behavioral advertising. Where required, we honor recognized opt-out preference signals for covered processing. These rights do not automatically apply to every form of personalization.
Submitting a Request
To make a request, please email support@ambi.ai. You do not need to create an account, close your account or cancel a subscription to exercise an applicable privacy right. You may identify the specific recording, communication, Memory item or other information concerned and provide context sufficient for us to locate it.
We will not retaliate or unlawfully discriminate against you for exercising your rights. We may request information reasonably needed to verify your identity and authority, such as your registered email address or context relating to the information requested. Where permitted by law, you may use an authorized agent; we may require proof of authorization and proportionate identity checks. We respond within the applicable legal time limits and explain a refusal or limitation where required. If you have a right to appeal, email support@ambi.ai with the subject “Privacy Appeal”. We will provide the outcome and reasons within the applicable period, and, where required, explain how to complain to the relevant state Attorney General or other authority if an appeal is denied.
We limit verification information to what is necessary to handle the request or appeal securely. Requests are generally free of charge; we will charge a reasonable fee or refuse a request only where applicable law permits and will explain the reason. There is no fee for verification. You may complain to the relevant data protection authority without first contacting us or completing an appeal where applicable law allows.
EU and EEA Residents
Where the GDPR applies, we rely on contract for processing objectively necessary to create and maintain your account, provide requested recording, transcription, Memory and action features, and administer purchases. We rely on legal obligations under applicable EU or Member State law; legitimate interests for proportionate security, fraud prevention, support, permitted usage analytics, business administration and legal claims, subject to your rights; and consent for processing that legally requires it, including relevant optional tracking and marketing.
For information about people who are not parties to our contract, we do not rely on the account holder’s contract as their legal basis. We rely on legitimate interests in providing the requested functionality only where lawful and after considering the affected person’s interests and rights, or obtain consent where required. Special-category information requires an additional condition under Article 9, such as explicit consent where applicable; permission from the user alone does not establish that condition for another person.
You have the applicable rights described above and may complain to a supervisory authority, including where you live, work or believe an infringement occurred. Where Article 22 applies, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to its exceptions and safeguards, including human intervention and an opportunity to contest the decision where required. Ordinary personalization does not itself establish that such a decision is being made. You may ask us for information about any covered decision and the applicable safeguards.
United Kingdom Residents
Where the UK GDPR applies, we rely on contract, applicable UK legal obligations, legitimate interests and consent for the corresponding purposes described in the EU/EEA section, subject to UK law and the safeguards for information about non-users and special-category information described there. You have the applicable rights listed above and may complain to the UK data-protection authority at https://ico.org.uk. Where UK law applies to a significant decision based solely on automated processing, you may obtain information, make representations, contest the decision and request human intervention, with additional restrictions where special-category information is involved. Ordinary personalization does not by itself establish such a decision. You may complain to us about our processing at support@ambi.ai. We will acknowledge a data-protection complaint within 30 days, investigate without undue delay, keep you informed and explain the outcome.
For information protected by UK law, a restricted transfer requires applicable UK adequacy regulations, appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s standard contractual clauses, together with the required data protection test and additional protections, or a legally permitted exception.
Brazil Residents
Where Brazil’s Lei Geral de Proteção de Dados (“LGPD”) applies, the purposes above are supported by the applicable LGPD basis, such as performance of a contract with you, legal obligations, exercise of rights, lawful legitimate interests or consent. Sensitive personal data requires a separate basis permitted under Article 11; legitimate interests alone do not suffice.
You may request confirmation of processing, access, correction, portability where applicable, information about recipients with whom data is shared, and anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data. You may request deletion of consent-based data subject to lawful retention exceptions, withdraw consent, obtain information about the option and consequences of refusing consent, object to unlawful processing not based on consent, and request review of solely automated decisions affecting your interests and information about their criteria and procedures, subject to protected trade secrets. You may petition the ANPD or competent consumer-protection authorities. Use the request channel above.
Transfers from Brazil require a mechanism permitted by the LGPD and ANPD rules, such as an applicable adequacy decision, approved contractual safeguards or another statutory basis. Where ANPD standard contractual clauses apply, you may request information about the transfer and a copy of the applicable clauses, subject to lawful protection of commercial and industrial secrets, within the required period, including 15 days for a request covered by those clauses.
Japan Residents
Where Japan’s Act on the Protection of Personal Information (“APPI”) applies, Mistlabs Limited is the personal information handling business operator. Our purposes of use are the purposes specified above. We obtain consent for acquisition of special care-required personal information and for use beyond the permitted scope where required. We provide personal data to third parties only with consent or an applicable legal exception. Entrusting processing for a stated purpose does not remove applicable foreign-transfer requirements.
For provision to a foreign recipient, the applicable APPI route may be a recognized equivalent jurisdiction, arrangements ensuring continued equivalent protective measures, or prior informed consent. If consent is the basis, the required information about the destination, its privacy system and the recipient’s measures must be provided before consent. Where equivalent measures are the basis, we take the required continuing steps and provide prescribed information on request.
For retained personal data, you may request notification of purposes of use, disclosure, correction, addition or deletion of inaccurate information, cessation of use, erasure or cessation of third-party provision on statutory grounds, and disclosure of applicable third-party provision records. Use the request channel above and specify your preferred disclosure method where applicable. We respond without delay as required and explain any lawful refusal. Information about our corporate representative, security-management measures and relevant foreign handling environments is available on request through that channel, subject to lawful security exceptions. You may also raise concerns with the Personal Information Protection Commission.
Canada Residents
Where Canadian privacy law applies, we collect, use and disclose personal information with meaningful consent or an applicable statutory exception. Consent is based on an explanation of the information, purposes, recipients and material consequences; accepting our Terms alone does not provide consent where a separate choice is required. We obtain express consent where required for sensitive information or processing outside reasonable expectations. You may request access, correction and information about our handling of your information, withdraw consent subject to lawful restrictions, and raise a privacy complaint with us or the applicable federal or provincial privacy regulator. Service-provider transfers remain subject to our accountability and contractual or other safeguards providing the protection required by applicable law. Your information may be processed outside Canada, including in the United States and, for the restricted personnel access described under Data Transfers, China. Information processed abroad may be accessible to the courts, law-enforcement or national-security authorities of those jurisdictions under their laws.
Quebec Residents
Where Quebec privacy law applies, we seek consent separately from other information where required, including express consent for sensitive information. You may request access, rectification and, where applicable, a structured, commonly used technological copy of computerized personal information collected from you. You may also request cessation of dissemination or de-indexing where the statutory conditions are met. Where we use personal information to make a decision exclusively by automated processing, we will give the required notice and, on request, information about the data, principal factors and parameters used, and an opportunity to submit observations to a person able to review the decision. You may raise a concern with the Commission d’accès à l’information du Québec.
South Korea Residents
Where Korea’s Personal Information Protection Act applies, you may exercise applicable rights to access, correction, deletion, suspension of processing and withdrawal of consent through the request channel above, and complain to the Personal Information Protection Commission or seek statutory dispute resolution. Where required, we obtain separate consent for sensitive information, third-party provision or overseas transfers. Necessary overseas outsourcing or storage for entering into or performing a contract with you may instead rely on the statutory route requiring the prescribed transfer information to be disclosed or individually notified. We provide the legally required details of outsourced processing and overseas transfers before the relevant processing and obtain any required consent separately; acknowledgment of this Notice does not supply it.
9.How to contact us
Should you have any questions about our privacy practices or this Privacy Notice, please email support@ambi.ai or write to Mistlabs Limited d/b/a Ambi, 8 The Green, Suite A, Dover, Kent County, Delaware 19901, United States.