BlankProductSecurity
Request Access
On this page
IntroductionData controllerOur role (controller / processor)Data collectedUse of dataThird-party processingLegal bases for processingData retentionConfidentiality of co-built formatsInternational data transfersCookiesSystem logs and maintenanceUse for legal purposesSecurityData breachYour rightsMinorsFurther informationAmendmentsContact

Privacy policy

Version: July 18, 2026

Introduction

This privacy policy describes how Ambre LLC ("Blank", "we") collects, uses and protects the personal data of individuals who use the Blank service (the "Service").

Scope. Documents uploaded to the Service, data extracted from those documents, and generated deliverables (collectively, "Customer Data") are processed by Blank solely as a data processor, on behalf of and on the instructions of the user or the client organisation, which acts as data controller. Customer Data is governed by the data processing agreement between the parties where one has been executed and, in any event, by the commitments set out in the terms of service and in this policy. The retention and deletion commitments applicable to Customer Data are nonetheless described in this policy for transparency. Requests to exercise rights relating to Customer Data should be directed to the client organisation, which relays them to us where applicable.

This policy otherwise governs the processing for which Blank acts as data controller: account data, technical data and commercial contact data.

Data controller

The data controller for data collected in connection with the Service is:

Ambre LLC
1010 Waugh Drive, Houston, TX 77019, United States
Email: [email protected]

Our role: controller and processor

Depending on the nature of the data, Blank acts in two distinct capacities:

  • Controller — for the data we collect in our own right to operate the Service: email address, account data, technical connection data. The rights described below are exercised directly with us.
  • Processor — for the content of the documents you upload, whether under the Free plan or on behalf of your organisation under the Enterprise plan. In that case, you or your organisation are the controller and Blank acts solely on your instructions. Requests to exercise rights relating to that content are addressed to the controller, which relays them to us where applicable.

Data collected

Blank collects only data strictly necessary for the operation of the Service:

  • Email address — collected at login, used for identification and communication.
  • Source documents — files uploaded by the user for deliverable generation (business plans, information memoranda, financial data, etc.). These are Customer Data, processed by Blank as a processor (see Scope above).
  • Technical data — standard connection information (IP address, browser type, timestamp) collected automatically for security and diagnostic purposes.
  • Commercial contact requests — when a user wishes to be contacted about the Enterprise plan, they send us their request by email from their own mail client, after confirming in the Service interface. The email address so provided is used solely for that purpose, based on the consent expressed at the time of the request.
  • User feedback — when a user submits feedback via the interface, the category, the feedback text, the technical account identifier and, where applicable, the identifier of the generation concerned are transmitted to our team by email, through our transactional email provider, solely to handle the feedback and improve the Service.

Blank does not collect browsing data for advertising purposes and does not use third-party cookies.

Use of data

Data collected is used for the following purposes:

  • Service provision: processing source documents to generate the requested deliverables.
  • Authentication and access management.
  • Communication with the user in connection with the Service (generation confirmation, technical notifications).
  • Processing commercial contact requests: when a user consents to be contacted about the Enterprise plan, their email address is used solely for that purpose by our team.
  • Security and Service integrity: detection of abusive or fraudulent use.
  • Compliance with our legal obligations.

Third-party processing

Deliverable generation relies on artificial intelligence models provided by third-party suppliers. Source documents uploaded may be transmitted to these suppliers solely for the purpose of producing the requested deliverable. These suppliers are subject to strict contractual confidentiality obligations and are not authorised to use your data for any other purpose. In particular, they are not authorised to use your data to train or improve AI models.

Blank does not sell, rent or share your personal data with third parties for commercial or advertising purposes.

The full list of our sub-processors, their location and transfer safeguards is published on our sub-processors page.

Legal bases for processing

In accordance with the General Data Protection Regulation (GDPR), each processing of personal data is based on one of the following legal grounds:

  • Contract performance — processing is necessary to provide the Service: authentication, processing of source documents, generation of deliverables.
  • Legitimate interest — processing is necessary for the security and integrity of the Service, prevention of fraudulent use, and improvement of the Service, in compliance with your fundamental rights. Service improvement is based exclusively on technical metadata (timestamps, volumes, operation statuses) and never on document content.
  • Legal obligation — processing is required to satisfy legal obligations applicable to Blank, in particular in tax matters or in response to requests from competent authorities.
  • Consent — where required by law, we seek your explicit consent before any processing. You may withdraw this consent at any time without affecting the lawfulness of prior processing.

Data retention

Storage location. Source documents and generated deliverables are stored in a dedicated storage bucket located in the European Union. They are not durably stored on our application servers: during generation, they only pass through a temporary workspace that is automatically wiped at the end of each run.

Source documents are automatically and permanently deleted upon completion of processing; deletion is enforced by automated routines running at short, regular intervals. A document uploaded but never processed is automatically deleted no later than 24 hours after upload. Blank does not maintain any backup or archive of source documents or deliverables — they are not written to any backup store. AI sub-processors to which source documents are transmitted for processing may temporarily retain them for safety and abuse-detection purposes, in accordance with their contractual commitments, before permanent deletion. For Mistral AI (OCR), Blank has activated Zero Data Retention: transmitted data is not retained beyond the processing of the request.

Generated deliverables are retained for 48 hours by default; the user may adjust this period between 1 hour and 168 hours according to their needs. Upon expiry of the applicable period, they are automatically deleted by the same routines.

No content is retained, indexed, profiled or used to train a model beyond these periods. Blank does not attempt to re-identify pseudonymised or aggregated data, except as required by law.

For other data categories, retention periods are as follows:

  • Data collected for contract performance — retained until the end of the contractual relationship with the client organisation.
  • Data collected on the basis of legitimate interest — retained as long as necessary for the relevant purpose (security, fraud prevention, Service improvement).
  • Data collected on the basis of consent — retained until consent is withdrawn. Commercial contact requests (Enterprise plan) are retained until processed by our team, and for a maximum of 12 months.
  • Data retained pursuant to a legal obligation — retained for the period required by applicable regulations (e.g. accounting records: 7 years).

Upon expiry of the applicable retention period, data is deleted.

Confidentiality of co-built formats

Templates and formats co-built with your organisation are specific to your structure and are never shared, communicated or made accessible to other organisations, including competing organisations. They constitute confidential assets of your organisation.

International data transfers

Ambre LLC is established in the United States. Although source documents and deliverables are stored in the European Union, their processing involves access by Blank from the United States and transmission to AI sub-processors that may process data outside the European Economic Area (EEA). Your personal data may therefore be transferred to and processed in countries whose data protection legislation may differ from that applicable in your country.

Transfer to Blank. The transfer of data from the EEA to Ambre LLC is governed by the European Commission Standard Contractual Clauses (Decision 2021/914, Module 2 — controller to processor, or Module 3 — processor to sub-processor where the client organisation itself acts as processor), incorporated into our data processing agreement (DPA).

Transfers to sub-processors. The safeguards in place with our sub-processors (Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework depending on certification) are detailed on our sub-processors page.

For any questions about the safeguards applicable to your situation, contact us at [email protected].

Cookies

The Service uses only functional cookies, strictly necessary for its operation: maintaining your session, remembering your language preferences and securing your access.

Blank does not use advertising cookies, behavioural tracking cookies, or cookies placed by third parties for targeting purposes. No browsing data is transmitted to advertising networks.

System logs and maintenance

For Service operation and maintenance purposes, technical data may be recorded automatically, including IP address, timestamps and any errors encountered. This data is used exclusively for diagnostic and troubleshooting purposes.

Pseudonymised audit logs are retained for up to one year for security and fraud prevention purposes. These logs contain only technical metadata (timestamps, operation status, volume of data processed) — no document content, company name or IP address is included. IP addresses may however appear in the technical logs of our hosting providers, for security and diagnostic purposes; they constitute personal data under the GDPR, are subject to the rights described below and are retained for limited periods.

Use for legal purposes

User personal data may be used by Blank for legal purposes before courts or in proceedings preliminary to legal action arising from misuse of the Service. The user acknowledges that Blank may be required to disclose personal data at the request of competent public authorities.

Security

Blank implements appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration. These measures include encryption of data in transit and at rest, as well as restriction of access to authorised personnel only.

Data breach

In the event of a personal data breach within the meaning of Article 4(12) GDPR, Blank undertakes to notify the client organisation without undue delay after becoming aware of it, and within 72 hours at the latest, with the information required by Article 33 GDPR (nature of the breach, categories and volume of data affected, likely consequences, measures taken or envisaged).

Where Blank acts as controller (account and technical data), Blank will notify affected individuals in the cases provided for by Article 34 GDPR (high risk to their rights and freedoms). Where Blank acts as processor (document content), Blank will assist the client organisation in fulfilling its own notification obligations under Article 34.

Pursuant to Texas Business & Commerce Code §521.053, in the event of a breach affecting Texas residents, Blank will notify affected individuals without unreasonable delay and within 60 days at the latest and, if 250 or more Texas residents are affected, the Texas Attorney General as soon as practicable and within 30 days at the latest, electronically via the form available on the Attorney General's website.

Your rights

In accordance with applicable personal data protection regulations, you have the following rights:

  • Right of access — you may request to consult the personal data we hold about you.
  • Right of rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data, subject to our legal obligations.
  • Right to object — you may object to the processing of your data in certain circumstances.
  • Right to restriction — you may request restriction of the processing of your data in the cases provided for by the GDPR.
  • Right to portability — you may request to receive your data in a structured, machine-readable format.
  • Right to lodge a complaint — you may lodge a complaint with the supervisory authority of your place of residence or work (for example the CNIL in France, the Garante in Italy, or the competent authority in your EEA Member State).

These requests are free of charge and may be addressed to [email protected]. We will respond as promptly as possible and within one month at the latest, in accordance with applicable regulations.

Where a request for rectification, erasure or restriction of processing is granted, Blank will inform each recipient to whom the data has been communicated, unless this proves impossible or requires disproportionate effort.

Minors

The Service is intended exclusively for professionals and organisations. It is not intended for persons under 16 years of age. Blank does not knowingly collect personal data relating to minors. If you believe that a minor has communicated personal data to us, contact us at [email protected] so that we may delete it.

Further information

Additional information on the collection or processing of personal data may be requested at any time from Blank at [email protected].

Amendments

We may update this policy at any time. The version date at the top of this document will be modified accordingly. In the event of a material update, express re-acceptance will be requested before your next deliverable generation. Use of the Service following that acceptance constitutes acknowledgment of the revised policy.

Contact

For any questions regarding this policy or the processing of your data: [email protected]

© 2026 Blank
[email protected]
SecurityLegal noticeTermsPrivacy
/