1. Introduction
At SECURE NEW HORIZONS SRL (operating as amgres.com), we take your privacy seriously. This Privacy & Cookie Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
Legal Basis for Data Collection — No Consent Required
We collect and process security data under GDPR Article 6(1)(f) — Legitimate Interest. This legal basis explicitly permits data processing without consent when necessary for the legitimate interests of the data controller.
GDPR-Recognized Legitimate Interests for Security:
- Preventing fraud and security incidents
- Network and information security
- Protecting against malicious or criminal activity
- Ensuring system integrity and availability
This data is used internally and is NOT shared with third-party tracking or analytics platforms.
Our Privacy Commitment
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- First and last name
- Username
- Email address
- Password (encrypted and hashed)
2.2 Address Information
For service delivery and billing purposes, we collect:
- Street address
- City, state/region, country
- Postal code
2.3 Business Information (Optional)
- Company name
- Business type
- VAT/Tax identification number
- Business address
2.4 Project Information
- Project requirements and specifications
- Design preferences and assets
- Content and data you provide for the application
- Communications regarding the project
2.5 Payment Information
Payment card data is processed securely through third-party payment processors (such as Stripe) and is NOT stored on our servers. We only retain:
- Transaction IDs
- Payment dates and amounts
- Last 4 digits of card numbers (for reference)
2.6 Security & Analytics Information
Critical Security Information
We automatically collect certain information for security purposes, which may include:
- IP address and geographic location data
- Browser information and user agent details
- Pages accessed and navigation patterns
- Session identifiers and authentication tokens
- Request timestamps and access times
- Referring URLs and traffic sources
- Request data and interaction patterns
- Device and system information
Security Necessity & Legitimate Interest Analysis
Under GDPR Article 6(1)(f), we have assessed that our legitimate interest in protecting our systems and users outweighs any potential impact on your privacy because:
- Necessity: Essential to detect and prevent attacks in real-time
- Proportionality: We collect only the minimum data needed
- Transparency: We clearly inform you about what data we collect
- No Alternative: Security monitoring cannot be effective without this data
- User Benefit: Protecting our infrastructure protects your data
Your Privacy is Protected
We DO NOT:
- Sell your data to third parties under any circumstances
- Share your data with advertisers or marketing companies
- Use this data for targeted advertising or marketing purposes
- Track your browsing behavior across other websites
- Share data with third-party analytics platforms (no Google Analytics, no Facebook Pixel, etc.)
4. How We Use Your Information
We use collected information solely for the following purposes:
4.1 Service Delivery
- Developing and delivering your mobile application and/or backend services
- Communicating with you about your project
- Providing customer support
- Managing hosting and maintenance services
4.2 Billing and Payments
- Processing payments and invoices
- Managing subscriptions
- Detecting and preventing fraud
4.3 Legal Obligations
- Complying with applicable laws and regulations
- Responding to legal requests
- Protecting our rights and property
4.4 Service Improvement
- Understanding how our services are used (without individual tracking)
- Improving service quality and performance
- Developing new features
5. Information Sharing & Disclosure
We share your information only in the following limited circumstances:
5.1 Service Providers
- Payment Processors: Stripe or similar services for payment processing
- Hosting Providers: Cloud infrastructure providers for hosting services (Vultr)
- Email Services: For sending transactional emails
These providers are contractually obligated to protect your data and use it only for the specified purposes.
5.2 Legal Requirements
- Valid legal processes (subpoenas, court orders)
- Government requests
- Protecting rights, safety, or property
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. You will be notified of any such change.
5.4 With Your Consent
We may share information with third parties when you explicitly consent to such sharing.
6. Data Security
6.1 Technical Measures
- SSL/TLS encryption for data in transit
- Encrypted storage for sensitive data
- Password hashing using industry-standard algorithms
- Regular security updates and patches
- Firewall protection
- Access controls and authentication
6.2 Administrative Measures
- Limited employee access to personal data (need-to-know basis)
- Regular security training
- Data backup procedures
- Incident response protocols
6.3 Your Responsibility
- Maintaining the confidentiality of your password
- Logging out of your account when finished
- Notifying us of any unauthorized access
7. Data Retention
7.1 Active Accounts
We retain your personal information as long as your account is active or as needed to provide services to you.
7.2 Inactive Accounts
If your account is inactive for more than 2 years, we may delete your account and associated data after providing notice to your registered email address.
7.3 Legal and Business Requirements
- Legal obligations (tax records, contracts)
- Dispute resolution
- Fraud prevention
- Backup systems (typically 30–90 days)
7.4 Application Data
For Server Only and Amber plans, we retain application and database data as long as you maintain an active subscription. Upon cancellation, data is retained for 30 days to allow for service restoration, then permanently deleted unless otherwise requested.
8. Your Privacy Rights
Depending on your location, you may have the following rights:
Access & Portability
Request a copy of your personal information in a structured, commonly used format
Correction
Update or correct inaccurate or incomplete information
Deletion
Request deletion of your personal information (some data may be retained for legal purposes)
Restriction & Objection
Restrict how we process your data or object to certain processing activities
Exercising Your Rights
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If we learn that we have collected personal information from a child under 18, we will take steps to delete such information as soon as possible.
If you believe we have collected information from a child under 18, please contact us immediately at contact@amgres.com.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer your information internationally, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses
- Data processing agreements
- Compliance with applicable data protection regulations
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.
When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email to your registered email address
- Display a prominent notice on our website
Your continued use of our services after such modifications constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Your privacy matters to us. We're committed to protecting your data.
View Terms of Service