Privacy Policy
How Ambassador collects, uses, and protects information across our website, platform, and services.
Privacy Policy v.09.02.26
i2H, Inc. dba Ambassador (“Ambassador” or “we”, “us”, “our”) is a technology company that enables our customers (“Customers”) to acquire, engage, and retain customers through advocacy programs, loyalty and engagement tools, AI-powered intelligence, automated incentive management, and communications across digital channels including online, mobile, email, SMS, and addressable TV.
This privacy policy (“Policy”) explains what kinds of information we collect and how Ambassador strives to collect, use and disclose information in a manner consistent with the laws of the countries in which we do business. This Policy applies to our data platform (the “Platform”) and our associated services (the “Service(s)”), including certain artificial intelligence and machine-learning features and functionality (collectively, “AI Services”), as described below, as well as our website located at https://getambassador.com (our “Website”).
PRIVACY PRACTICES FOR OUR WEBSITE AND BUSINESS OPERATIONS
Personally Identifiable Information (PII)
Ambassador collects Personally Identifiable Information (“PII”) from its Website when you choose to provide it to us. PII is any information that can be used to identify or locate a particular person or entity. This includes, but is not limited to: name, postal address, telephone number, or email address. For example, you may choose to send PII about yourself in an email, or by completing a form on the Website. Ambassador uses this information only to contact you to respond to your inquiry.
Technical and Usage Information
Ambassador also collects technical and usage information from visitors to the Website. This may include your IP host address, pages viewed, browser type, Internet browsing and usage habits, Internet Service Provider, domain name, the time/date of your visit to this Website, the referring URL and your computer’s operating system. Some of this information may constitute personal information or personal data under applicable law. We reserve the right to aggregate information collected from visitors to the Website for any reasonable purpose, including publishing aggregate statistics about Website usage, counting and better understanding our site visitors and protecting our Website from security issues or fraud.
Cookies and other Tracking Technologies
Ambassador and our partners use cookies or similar technologies to analyze trends, administer the Website, and track users’ movements around the Website. You may also be able to control the use of cookies at the individual browser level.
Our third-party partners may use cookies or similar technologies on the Website in order to provide you advertising based upon your browsing activities on this and other websites. This practice is sometimes called interest-based-advertising. Some of these third parties enable us to advertise our products and services using information collected via the Website and/or to conduct analytics and remarketing based upon your visits to the Website. These cookies often involve the placement of a pseudonymous UID onto your browser which may be deemed a sale of information in certain jurisdictions, and may require your consent in other jurisdictions under applicable law. Where required, we will provide a notice and provide the ability to opt-out of such sales and/or obtain your consent for the placement of cookies. If you wish to learn more about interest-based advertising and understand the choices available to you, please visit https://aboutads.info/.
Third-Party Websites
The Website may contain links to and advertisements for websites operated by third parties whose privacy practices may differ from Ambassador policies. While the company endeavors to associate only with reputable entities, Ambassador cannot guarantee the privacy practices of other websites will reflect ours; we encourage you to check the privacy policies of all websites that you visit.
Mobile Messaging Privacy (SMS/MMS/RCS)
If you opt in to receive SMS, MMS, or RCS communications (“Mobile Messages”) from a Customer or from Ambassador, we process your mobile phone number, message content (including any media), and related technical/delivery metadata solely to transmit and deliver Mobile Messages and operate the Services. Message frequency varies. Message & data rates may apply. You may opt out at any time by replying “STOP.” For help, reply “HELP” or contact us at security@getambassador.com.
No mobile information will be shared with third parties/affiliates for marketing or promotional purposes.
For clarity, we do not sell, rent, or share Mobile Message opt-in data and consent with third parties/affiliates for marketing or promotional purposes.
Service Providers
We may share mobile information with third-party messaging providers and telecommunications carriers strictly to transmit and deliver Mobile Messages on our behalf. These providers act as our processors/subprocessors and do not use mobile information for their own marketing purposes.
We honor standard opt-out keywords (e.g., “STOP”) and provide assistance via “HELP” consistent with carrier and CTIA expectations.
PRIVACY PRACTICES FOR OUR PLATFORMS AND SERVICES
Overview of the Ambassador Platform and Services
Ambassador provides The Customer Lifecycle Operating System, orchestrated by HiroAI: an end-to-end platform that enables Customer to grow, retain, and prove the value of its customer relationships across the full customer lifecycle. The Platform and Services help Customers manage their relationship with affiliates, partners, influencers and advocates (“Ambassadors”) to enable such Customers to more effectively grow, retain, and engage their customer base.
When you register for our Services as either a Customer or an “Ambassador” we require an email address that may be used for communications. Email messages may contain code that helps our systems collect certain technical and usage information and use cookies and web beacons in connection with the Platform and Services in order to track your usage of these emails. We reserve the right to send you email regarding service announcements, administrative messages, and privacy policy and terms of use changes.
The data stored on our Platforms is used solely on behalf of each Customer and we do not generally intermingle data across Customers unless directed to do so by Customers. Some Customers may choose to leverage both the Ambassador Platform in conjunction with our other Platforms and Services.
AI SERVICES AND INTELLIGENT FEATURES
AI Services
Our Platform includes AI Services that help our Customers grow and retain their customer base more effectively. These AI Services include: (a) HiroAI, our AI orchestration layer that coordinates intelligence across the Platform; (b) Agent Studio, which enables Customers to design and deploy AI agents that automate customer engagement workflows; (c) predictive analytics that forecast customer behavior such as churn risk, conversion likelihood, and segment affinity; (d) AI-generated content including email copy, SMS messages, and campaign recommendations; (e) programmatic audience building; and (f) the Context API, which enables Customers to access processed intelligence from their own data.
Information We Process for AI Services (as Processor for Customers)
When our Customers use AI Services, we process the following categories of information on their behalf: (i) customer engagement data (clicks, conversions, referral outcomes, loyalty actions) used to generate predictions and recommendations; (ii) text inputs submitted by Customers or their contacts to AI Services; (iii) behavioral and transactional data used for AI model training within the Customer’s isolated environment; (iv) AI agent workflow data including actions taken, decisions made, and integration triggers; and (v) AI-generated outputs such as predictions, recommendations, content, and audience segments that may contain or be derived from personal information.
Customer Ecosystem Isolation
Each Customer’s data is processed by AI Services within a logically isolated environment (the “Customer Ecosystem”), as described in the applicable Agreement. We do not use one Customer’s data to train, improve, or generate AI predictions, recommendations, or content for any other Customer. AI agents configured by one Customer cannot access another Customer’s data. Customer AI Configuration and Customer Outcome Data (as defined in the applicable agreement with Ambassador) remain within the Customer Ecosystem and are owned by Customer as set forth in such agreement.
No Cross-Customer AI Training
We do not use personal information processed through AI Services for one Customer to train AI models that serve other Customers. We do not sell AI-derived insights to third parties. The AI Services are designed to serve each Customer independently within their own Customer Ecosystem.
Benchmarking (Opt-In Only)
With a Customer’s explicit opt-in consent, we may include their de-identified and aggregated data in industry benchmarking reports that help all Customers understand how their programs compare to peers. This benchmarking data is irreversibly anonymized, cannot be attributed to any individual Customer, contact, or end user, and is presented only in aggregate form with a minimum of ten contributing Customers per benchmark category. Customers may opt out of benchmarking at any time.
Automated Decision-Making
Some AI Services may involve automated processing of personal information that could produce recommendations or actions affecting end users (e.g., predictive churn scores, AI agent-triggered communications, or programmatic audience segmentation). Our Customers, as controllers of their data, are responsible for determining whether such processing requires notice to or consent from their end users under applicable law (including GDPR Article 22). We provide Customers with information about how AI Services process data to help them fulfill their transparency obligations. Where a Customer uses AI Services or automated systems to communicate with end users, the Customer is solely responsible for any legally required disclosure that an end user is interacting with an automated or AI system, including under emerging automated-communication and chatbot-disclosure laws (for example, applicable bot-disclosure, automated-communication and AI-transparency laws and Article 50 of the EU AI Act).
Third-Party AI Providers
We use third-party AI and machine learning providers (including large language model and inference providers) to power certain AI Services (each, an “AI Provider”). AI Providers that process personal information on Ambassador’s behalf act as our sub-processors and process such information only to provide the applicable AI functionality for our Customers. AI Providers are contractually prohibited from using Customer data for their own model training or improvement, and they do not retain Customer data beyond what is necessary to process each request. A list of our sub-processors, including AI Providers, is available at https://trust.getambassador.com/subprocessors.
External Agents
Some Customers use the Ambassador platform as the operating system for their own agents (“External Agents”) that the Customer builds and runs outside the Ambassador platform to interact with the Customer’s end users. When a Customer routes data to an External Agent, that data leaves the Ambassador platform and the Customer controls it from that point forward. The Customer is responsible for the External Agent’s communications, disclosures, and compliance, including any legally required notice that an end user is interacting with an automated agent.
AI Data Retention
Data processed through AI Services is retained in accordance with our standard data retention practices and Customer instructions. AI agent configurations, workflow intelligence, and Customer-specific model tuning are retained in accordance with the applicable Agreement and our standard retention practices and may be exported by the Customer in machine-readable format upon termination. Following termination, Customer-specific AI data will be retained or deleted in accordance with the applicable Agreement, our DPA and Customer instructions.
MESSAGING SERVICES (SMS, MMS, RCS)
Messaging Functionality
Our Services include messaging functionality that enables our Customers to communicate with their end users through SMS (short message service), MMS (multimedia messaging service), and RCS (rich communication services). These Services may include one-way or two-way messaging and may involve the transmission of text, images, videos, files, and interactive content.
Information We Process (as Processor for Customers)
In providing these Services, we process the following categories of information on behalf of our Customers: (i) phone numbers used to send and receive messages; (ii) message content, including text, images, videos, and files; (iii) technical and delivery metadata (such as timestamps, routing information, and delivery status); and (iv) end user responses in two-way communications.
Customer Responsibility and Legal Basis
Customers are responsible for determining the lawful basis for sending messages to their end users (e.g., consent or legitimate interests) and for ensuring compliance with applicable laws and industry guidelines, including without limitation the U.S. Telephone Consumer Protection Act (TCPA) and CTIA messaging principles, the California Consumer Privacy Act (CCPA/CPRA) and other U.S. state privacy laws, and the EEA/UK General Data Protection Regulation (GDPR).
Opt-Outs and Help (CTIA/Carrier-Aligned)
End users may opt out of receiving messages at any time by replying “STOP”. We honor standard equivalents including STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT. To re-subscribe (where permitted), end users may reply START, YES, or UNSTOP. For assistance, end users may reply “HELP” to receive help information. Message and data rates may apply. Message frequency varies. Carriers are not liable for delayed or undelivered messages. Customers are responsible for honoring opt-out requests promptly, maintaining appropriate suppression lists, and ensuring opt-out confirmations are sent where required.
Sensitive Information
Customers must not use the messaging features to request or transmit sensitive personal information (such as health, financial, biometric, or government ID data) unless Ambassador expressly agrees in writing and any additional terms and safeguards required by Ambassador are in place.
Service Providers for Messaging
We use third-party messaging and telecommunications providers to deliver messaging Services. These providers act as our subprocessors and process personal information only to transmit and deliver communications on behalf of our Customers and subject to our instructions and agreements.
Data Retention and Security for Messaging
We retain messaging-related data only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Message content, including multimedia files, is generally retained only for transmission and delivery unless longer retention is required for troubleshooting, compliance, or at the written request of our Customers. We maintain appropriate technical and organizational measures, consistent with our SOC 2 Type II certification, to safeguard personal information processed through SMS, MMS, and RCS messaging.
PROGRAMMATIC ADVERTISING (RTB)
Programmatic / Real-Time Bidding
If a Customer uses Ambassador’s programmatic advertising services (the “Programmatic Services”), currently branded as Humming, Ambassador builds and activates advertising audiences and delivers advertising on the Customer’s behalf through third-party media vendors using real-time bidding (RTB). This may involve pseudonymous identifiers, audience attributes, and impression and interaction data.
Media Vendors as Recipients
To deliver the Programmatic Services, Ambassador shares the necessary data with third-party media vendors, and, downstream, advertising exchanges and publishers selected by the media vendor. Media vendors may independently process advertising and device data on an aggregated basis across their own customer bases, outside the Ambassador platform and under their own terms. The current list of media vendors is maintained at https://trust.getambassador.com/subprocessors.
Your Choices / Opt-Out (NAI & DAA)
You can opt out of interest-based advertising from participating companies through the Network Advertising Initiative (NAI) at https://optout.networkadvertising.org and the Digital Advertising Alliance (DAA) at https://optout.aboutads.info. You can also use browser and device controls, including Global Privacy Control (GPC) signals, which we and our Customers honor where required by law. Customers operating programmatic campaigns are responsible for maintaining the required notices and opt-out mechanisms on their own properties.
Overview of Ambassador’s Connectivity Services
The Ambassador Connectivity and Context Services include data onboarding, linking, and distribution to companies and many of the players in the digital advertising industry to enable smarter targeting with more relevant messages and more accurate measurement. Onboarding is a service that loads 1st, 2nd and 3rd party data into the digital ecosystem (Customer Data Platform (CDP)), so it can be used for digital advertising purposes. The players include advertisers wishing to reach consumers, advertising supported websites, advertising supported apps, email marketing services, and addressable TV channels.
Today consumers interact with advertisers and brands through a variety of channels – offline and digital. This cross-channel interaction is known as “omni channel.” Ambassador services are used to support these interactions for several types of entities in the digital advertising industry, including consumer brands, companies that enable the delivery of advertising and marketing messages, and companies that provide consumer data and insights to brands to help them better understand their current and prospective customers. Brands are interested in understanding consumers anywhere: while online, while watching television, while using their mobile devices and virtually everywhere their customers are making purchasing decisions. All that requires lots of data and Ambassador helps brands connect that data in order to help them make intelligent decisions.
PII and Digital Identifiers uses on the Platform across channels
Due to technical differences across the channels, Ambassador uses different approaches tailored specifically to each channel to provide our Connectivity Services. The common basis of these services is an ID that Ambassador assigns to an individual. The ID may be used in a personally identifiable state or in a manner that is not used to identify the individual, depending on the channel and the use.
Ambassador collects certain types of information in connection with our Connectivity Services. This includes personal data such as name, postal address, email address, and phone number if permitted by our partners and Customers through policy notices they have provided to consumers. We also collect other data such as IP address, mobile device ID, and browser and operating system type and version. In addition, we handle, process, and share this data with our marketing platform partners in the course of performing our services; however, we do not retain or use this data for our own internal business purposes unless permitted by our Customers.
Ambassador Cookie-based Connectivity Services
Connectivity Services for cookie-based integrations are based on a Ambassador ID and an Ambassador cookie that together identify a browser. The cookie containing the ID is set when a consumer clicks on an offer, reward, or survey, visits the website of one of our cookie match partners as a registered user, or when a consumer opens certain emails from a cookie match partner. Because match partners know the consumer, they enable Ambassador to recognize the consumer as well and set the Ambassador cookie containing the appropriate ID.
Ambassador cookies are set with an RLCDN.com name and expire from Ambassador’s system after 90 days unless they are renewed or refreshed. Unlike web “tracking” cookies, Ambassador cookies do not “track” users’ behavior across websites. Instead, Ambassador cookies are used to recognize an individual so that relevant ads and email marketing can be delivered to the intended recipient.
Ambassador Mobile Connectivity Services
Connectivity Services for mobile ID integrations are similar to cookie integrations except they use the mobile advertising ID assigned to the device instead of a cookie – namely the Apple ID for Advertising (IDFA) and the Android Advertising ID (AAID). We associate the Ambassador ID with the mobile ID just like we would associate the cookie. Ambassador links marketing platform partners, third-party data providers, and data from a brand to mobile devices through the Ambassador ID.
Ambassador Addressable TV Connectivity Services
Connectivity Services for addressable TV integrations are similar to online and mobile services except they use the subscriber ID assigned by the carrier to the set-top box instead of a cookie or a mobile ID. We associate the Ambassador ID with the subscriber ID just like we would associate the cookie or mobile ID.
Pseudonymization Processes
Ambassador may recognize an online, mobile or addressable TV user in two ways. First when our match partner shares personal data with us, or second when they share other information with us that is not used to identify individuals. When they share personal data, we can recognize a consumer on an identifiable basis. However, to preserve user privacy, we create a unique Ambassador ID when we combine it with other anonymous data. Ambassador values the preservation of consumer privacy, designing its systems and services to treat personal data and other information that is not used to identify individuals with utmost care.
ADDITIONAL INFORMATION ABOUT OUR PRIVACY PRACTICES
Updating and Deleting Your Information
Upon request, and as required under applicable law, Ambassador will provide you with information about whether we hold any of your data. If you’d like to update, correct, delete, port or deactivate any data that you have provided to the company on the Website or otherwise via our business operations, please send your request to security@getambassador.com, and Ambassador will process your request. We will respond to your request to access within a reasonable timeframe – for data subjects located in the EEA, that time frame will be 30 days and Ambassador will honor such requests as they pertain to personal data.
If your personal information has been processed through AI Services on behalf of one of our Customers, please direct your access, correction, deletion, or objection request to the relevant Customer, who is the controller of your data. We will assist our Customers in fulfilling such requests as described in our Data Processing Addendum.
Choice Mechanisms
Ambassador wants to make sure you are informed of the privacy choices that are available to you. We require that our partners meet the same high standards we have. We contractually require that our match partners employ notice and choice mechanisms, and we work with other information service providers and our partners to assist them in following their respective industry standards. While we only process data as directed by our Customers with respect to the Platforms and Services, we believe the following information may be helpful.
Opt-out from Interest Based Advertising from third-party companies – Many of our partners that enable targeted advertising are members of one or more digital advertising industry self-regulatory programs. You may visit the Network Advertising Initiative (NAI), Digital Advertising Alliance (DAA) and European Digital Advertising Alliance (eDAA) opt-out tools to learn more.
Mobile Application Choices – Mobile operating systems (e.g., iOS and Android) offer opt-out choice mechanisms applicable to mobile applications and these choice mechanisms may be found via your mobile device settings.
CALIFORNIA DATA SUBJECTS
The California Consumer Privacy Act (the “CCPA”) provides additional privacy protections for California residents, including: (a) the right to see what data we have about you, your computer or device (i.e., the right to know), (b) the right to delete the data we have about you, your computer or device (i.e., the right to delete), (c) the right to correct inaccurate personal information, (d) the right to opt out of the sale or sharing of personal information, and (e) where applicable, the right to limit the use and disclosure of sensitive personal information. We do not discriminate against you if you exercise any of the above rights. Moreover, we may not be able to honor a right if doing so would violate applicable law.
With respect to personal information processed through AI Services, Ambassador does not sell or share personal information for Ambassador’s own cross-context behavioral advertising purposes. Where a Customer directs Ambassador to disclose personal information through Programmatic Services, such disclosure is governed by the Programmatic-specific provisions below. We do not use personal information received from one Customer to train AI models that serve other Customers. Ambassador processes personal information through its AI Services on behalf of the applicable Customer and in accordance with the Customer’s instructions, consistent with Ambassador’s role as a service provider under the CCPA, subject to any uses of aggregated or de-identified data permitted under our agreements and this Policy.
If you are a Customer or partner and have questions about your ability to see the data used to login to our systems, we ask that you direct your question to the person at Ambassador that owns the business relationship with your company. If you are a consumer and want to see what data we may have on behalf of one of our Customers, kindly reach out to that individual Customer directly. Ambassador is contractually prohibited from honoring such requests without specific written instructions from the applicable Customer.
If you want to see or delete any data we may have collected pursuant to our Website or internal business operations, you may access those rights with respect to Ambassador by sending us an email to security@getambassador.com.
As a California resident, if you make a request to know, delete, or correct as set out in this Policy, we will confirm receipt within 10 business days and respond within 45 calendar days, subject to any extension permitted by law.
Programmatic-specific
When a Customer uses the Programmatic Services, delivery of advertising through media vendors may constitute “sharing” for cross-context behavioral advertising under CPRA. The Customer is responsible, as the business, for providing the notice at collection and honoring opt-out-of-sale/sharing and Global Privacy Control signals on its properties. Ambassador passes through Customer opt-out instructions to media vendors to the extent supported. You may exercise opt-out choices through the NAI and DAA tools linked above.
INDIVIDUALS IN THE EEA, SWITZERLAND AND UNITED KINGDOM
Individuals located in the European Economic Area (the “EEA”) are granted additional privacy rights under the General Data Protection Regulation (the “GDPR”). For example, an EEA, UK or Swiss individual who seeks access, or who seeks to correct, amend, port over and/or delete inaccurate data, or who wishes to limit the use and disclosure of their Personal Information, should send us an email.
If you are a Customer or partner and have questions about your ability to see the data used to login to our systems, we ask that you direct your question to the person at Ambassador that owns the business relationship with your company. If you are a consumer and want to see what data we may have on behalf of one of our Customers, kindly reach out to that individual Customer directly. Ambassador is contractually prohibited from honoring such requests without specific written instructions from the applicable Customer.
If you want to see or delete any data we may have collected pursuant to our Website or internal business operations, you may access those rights with respect to Ambassador and its affiliated company by sending us an email to security@getambassador.com.
With respect to EEA data subjects, personal data includes pseudonymous data such as an IP address, a mobile advertising ID or a cookie ID.
Ambassador operates each of our Platforms and provides the Services as a “data processor” under the GDPR. That means Ambassador only processes data via the Platforms and Services as directed by our Customers and for no other purpose. We process certain personal data provided by Customers and partners under contractual necessity.
With respect to personal data processed through our AI Services: Ambassador operates AI Services as a “data processor” under the GDPR. We process AI-related personal data only as directed by our Customers (controllers) and for no other purpose. We do not use personal data processed through AI Services for one Customer to train AI models serving other Customers. Where AI Services involve automated decision-making within the meaning of GDPR Article 22, our Customers (as controllers) are responsible for ensuring lawfulness, providing appropriate safeguards, and informing data subjects. We provide Customers with information about how the AI Services process personal data to support their transparency obligations. AI Providers that process personal data are disclosed on our Subprocessor Page and, as applicable, act as our subprocessors and are contractually prohibited from using Customer personal data for their own purposes.
We will provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To request to limit the use and disclosure of your personal information, please submit a written request to security@getambassador.com.
Automated agents / bot disclosure
Where a Customer uses an External Agent or other automated system to communicate with end users, the Customer is responsible for any legally required disclosure that the end user is interacting with an automated agent, including under emerging automated-communication and chatbot-disclosure laws (for example, applicable bot-disclosure, automated-communication and AI-transparency laws and Article 50 of the EU AI Act). Ambassador provides the platform capability; the Customer controls the consumer-facing disclosure.
ONWARD TRANSFER OF PERSONAL DATA
Ambassador may share data with trusted agents, including PII. These third-party agents are prohibited by contract from using the information for purposes other than performing services for Ambassador. In the EEA, such companies are sometimes called “data processors;” in California, they are referred to as “service providers.” The types of service providers to which we share data include: (a) cloud computer and data storage providers, (b) companies offering tools to send emails and similar communications on our behalf, (c) website and b2b sales analytics providers, (d) customer relationship management and project management software providers, (e) customer billing systems partners, (f) outsourced computer programmers helping ensure our systems are operating properly, (g) auditing, debugging and security vendors, (h) marketing service providers, and (i) artificial intelligence and machine learning providers engaged to support AI Services on our Platform (including large language model APIs), which are contractually prohibited from using Customer data for their own model training or improvement and do not retain data beyond request-level processing.
For messaging Services, subprocessors may include telecommunications providers and messaging delivery platforms engaged solely to transmit and deliver communications on our behalf and subject to our instructions. Notwithstanding the foregoing, end-user mobile information (including phone numbers, Mobile Message opt-in data and consent, and Mobile Message content) is not shared with third parties/affiliates for marketing or promotional purposes.
For AI Services, sub-processors may include large language model providers and machine learning inference services engaged to process data in connection with AI predictions, content generation, and other intelligent features. These providers act as our sub-processors and are contractually prohibited from: (a) using Customer data for their own model training or improvement; (b) retaining Customer data beyond request-level processing; and (c) commingling Customer data with data from other sources. A current list of all sub-processors is available at https://trust.getambassador.com/subprocessors.
For Programmatic Services, a media vendor acts as our sub-processor only to the extent it processes personal information solely on Ambassador’s behalf and instructions. To the extent a media vendor independently determines the purposes or means of processing or processes data across its own customer base, that processing is outside Ambassador’s processor role and is governed by the media vendor’s own terms and privacy practices. A current list is available at https://trust.getambassador.com/subprocessors.
Ambassador may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements. Ambassador may also disclose your information to third parties when obligated to do so by law and in order to investigate, prevent, or take action regarding suspected, or actual prohibited activities, including but not limited to fraud and situations involving potential threats to the physical safety of any person.
Finally, Ambassador may transfer information, including any personally identifiable information, to a successor entity in connection with a corporate merger, consolidation, sale of assets, bankruptcy, or other corporate change. If Ambassador is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via a notice on our Website of any change in ownership or uses of your personal data, as well as any choices you may have regarding your personal data.
DATA RETENTION
We retain data on the Platforms as directed by our Customers and strongly encourage our Customers to retain data only for as long as is reasonably necessary.
Messaging-related data is retained only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Message content, including multimedia files, is generally retained only for transmission and delivery unless longer retention is required for troubleshooting, compliance, or at the written request of our Customers.
Data processed through AI Services is retained in accordance with Customer instructions and our standard retention practices. AI agent configurations, workflow intelligence, and Customer-specific model tuning are retained in accordance with the applicable Agreement and our standard retention practices. Upon termination, Customers may request export of their AI configurations in machine-readable format. Following termination, Customer-specific AI data will be retained or deleted in accordance with the applicable Agreement, our DPA and Customer instructions. Data processed by AI sub-processors is not retained by those providers beyond the time necessary to process each individual request.
The data collected via our Website and our internal business operations is retained for up to 13 months after our last interaction with a particular data subject unless such data is required to be held longer under applicable law.
Ambassador cookies are set with a custom domain set by the Customer and expire from Ambassador’s system after up to 1 year as determined by the Customer unless they are renewed or refreshed.
DATA INTEGRITY, PURPOSE LIMITATION
We process information in a way that is compatible with and relevant for the purpose for which it was collected. To the extent necessary for those purposes, we take reasonable steps to ensure that any information in our care is accurate, complete, current and reliable for its intended use as described above.
ENFORCEMENT
Changes To This Privacy Policy
This Policy may be amended from time to time. When we do, we will also revise the version stamp at the top of this Policy. We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting the information we collect.
Privacy Questions and Complaints
Ambassador commits to resolve complaints about your privacy and our collection or use of your personal information. Persons who have inquiries or complaints regarding this privacy policy should contact us at security@getambassador.com with the word “Privacy Office” in the Subject Line. If you are located in the United Kingdom, you may lodge a data protection complaint directly with Ambassador using the contact details in this section. We will acknowledge your complaint within 30 days and respond without undue delay, in accordance with the UK Data (Use and Access) Act 2025. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk. If you are located in the EEA, you may lodge a complaint with your local data protection supervisory authority.
You may contact our Data Protection Officer Mark Steffler at security@getambassador.com.
You may also contact us at:
Data Protection Officer/Legal
i2H, Inc. dba Ambassador
2212 Queen Anne Ave North, Suite 767
Seattle, WA, 98109
Privacy Policy v.09.02.26