Privacy Policy

    Last updated: April 2025

    1. Introduction

    Welcome to Amptomic, a service owned and operated by Bearworks LTD ("we", "our", or "us"). We are committed to protecting your personal data and respecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable UK data protection legislation.

    This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website and services.

    Data Controller

    Bearworks LTD

    Williams Yard, Derby Road, Melbourne, Derbyshire DE73 8JR

    Email: hello@bearworks.co

    2. Information We Collect

    We may collect and process the following types of personal data:

    2.1 Information You Provide

    • Account registration details (name, email address, password)
    • Contact form submissions
    • Business information (company name, website URL)
    • Payment and billing information
    • Communications with our support team

    2.2 Information Collected Automatically

    • Device information (browser type, operating system)
    • IP address and approximate location
    • Usage data (pages visited, features used, time spent)
    • Cookies and similar tracking technologies (see our Cookie Policy)

    2.3 Third-Party Service Integrations

    You may choose to connect third-party services to your Amptomic account. When you do, we collect and process data from those services:

    • Google Analytics: Website traffic metrics including sessions, pageviews, bounce rate, and GA4 property metadata. We use the analytics.readonly OAuth scope (read-only access).
    • Google Search Console: Search performance data including impressions, clicks, click-through rate (CTR), and average position. We use the webmaster.readonly OAuth scope (read-only access).

    We store encrypted OAuth refresh tokens to maintain your connection. You can disconnect these integrations at any time from your Settings page, which will delete all stored tokens.

    3. Lawful Basis for Processing

    Under UK GDPR, we rely on the following lawful bases to process your personal data:

    • Contract performance (Article 6(1)(b)): Processing necessary to provide our Service, manage your account, and fulfil subscription obligations
    • Legitimate interests (Article 6(1)(f)): Improving our services, analysing usage patterns, preventing fraud, and ensuring platform security — where these interests are not overridden by your rights
    • Consent (Article 6(1)(a)): Sending marketing communications and connecting third-party integrations such as Google Analytics and Search Console. You may withdraw consent at any time
    • Legal obligation (Article 6(1)(c)): Complying with applicable laws, regulations, and lawful requests from authorities

    4. How We Use Your Information

    • Service provision: To create and manage your account, provide our services, and process transactions
    • Communication: To respond to enquiries, send service updates, and provide customer support
    • Improvement: To analyse usage patterns and improve our services
    • Marketing: To send promotional communications (with your consent)
    • Analytics integration: To display your Google Analytics and Search Console data within the Amptomic dashboard
    • AI-powered features: To generate content suggestions, keyword recommendations, and SEO insights using artificial intelligence. Your data may be processed by AI models to deliver these features but is not used to train third-party AI models
    • Legal compliance: To comply with legal obligations and protect our rights
    • Security: To detect, prevent, and address technical issues and security threats

    4a. Google API Services

    Amptomic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    • We only request the minimum necessary OAuth scopes (read-only access)
    • We do not share Google user data with third parties
    • We do not use Google user data for advertising or marketing purposes
    • We do not allow humans to read Google user data unless required for security purposes, to comply with applicable law, or with your explicit consent

    5. Data Sharing and Third Parties

    We do not sell your personal data. We may share your data with the following categories of recipients:

    • Service providers: Third-party companies that help us operate our Service, including cloud hosting (Supabase), payment processing, email delivery, and analytics
    • AI providers: AI model providers (such as Google and OpenAI) to power content generation and analysis features. Data sent to these providers is used solely to deliver the requested functionality and is not used to train their models
    • Legal requirements: When required by law, regulation, legal process, or governmental request
    • Business transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity
    • With your consent: In any other circumstances where you have given explicit consent

    All third-party service providers are contractually obligated to process your data only as instructed by us and in accordance with applicable data protection laws.

    6. International Data Transfers

    Your data may be transferred to and processed in countries outside the United Kingdom, including the United States and the European Economic Area. When we transfer personal data internationally, we ensure appropriate safeguards are in place, including:

    • Transfers to countries with an adequacy decision from the UK Secretary of State
    • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO)
    • Other legally recognised transfer mechanisms under UK GDPR

    7. Data Retention

    We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

    • Account data: Retained for the duration of your account and up to 30 days after deletion
    • Billing and transaction records: Retained for 7 years to comply with UK financial and tax obligations
    • Usage and analytics data: Retained for up to 26 months from the date of collection
    • Support communications: Retained for up to 3 years after resolution
    • OAuth tokens: Deleted immediately when you disconnect a third-party integration
    • Marketing consent records: Retained for as long as you remain subscribed, plus 12 months after withdrawal

    After the retention period expires, data is securely deleted or anonymised.

    8. Data Security

    We implement appropriate technical and organisational measures to protect your personal data, including:

    • Encryption of data in transit (TLS/SSL) and at rest
    • Secure authentication mechanisms including hashed passwords
    • Row-level security policies to ensure users can only access their own data
    • Regular security assessments and monitoring
    • Access controls limiting employee access to personal data on a need-to-know basis

    While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you and the ICO of any reportable breach within 72 hours as required by UK GDPR.

    9. Your Rights

    Under UK GDPR, you have the following rights:

    • Right of access (Article 15): Request a copy of your personal data. We will respond within one month
    • Right to rectification (Article 16): Request correction of inaccurate or incomplete data
    • Right to erasure (Article 17): Request deletion of your personal data where there is no compelling reason for continued processing
    • Right to restrict processing (Article 18): Request limitation of processing in certain circumstances
    • Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format
    • Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes
    • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
    • Right to lodge a complaint: You have the right to complain to the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated

    To exercise any of these rights, please contact us at hello@bearworks.co. We will respond to your request within one month. In complex cases, we may extend this by a further two months, and we will inform you if this is necessary.

    Information Commissioner's Office (ICO)

    Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

    Telephone: 0303 123 1113

    Website: ico.org.uk

    10. Cookies

    We use cookies and similar tracking technologies to enhance your experience. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy.

    11. Children's Privacy

    Our Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child under 18, we will take steps to delete that information as soon as possible. If you believe a child has provided us with personal data, please contact us at hello@bearworks.co.

    12. Automated Decision-Making

    Our Service uses AI and automated processing to generate content suggestions, keyword recommendations, SEO scores, and marketing insights. These automated outputs are advisory in nature and do not produce legal or similarly significant effects on you. You retain full control over whether to act on any AI-generated recommendations.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

    • Posting the updated policy on this page with a revised "Last updated" date
    • Sending an email notification for significant changes that affect your rights
    • Displaying a notice within the Service

    We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

    14. Contact Us

    If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:

    Bearworks LTD

    Williams Yard, Derby Road, Melbourne, Derbyshire DE73 8JR

    Email: hello@bearworks.co

    Or use our contact form