Privacy Policy
Last updated 20 August 2026 · Applies to mplfy.ai and its sub-domains
This Privacy Policy explains how AMPLIFI collects, uses, shares and protects personal information when you use the AMPLIFI platform — our identity and customer-data services, content management, media and streaming, advertising, commerce, loyalty and related products (together, the "Service"). We process personal information in line with the Protection of Personal Information Act 4 of 2013 (POPIA) and, where it applies, the EU/UK General Data Protection Regulation (GDPR) and other applicable data-protection laws.
1. Two different roles — please read this first
The Service is multi-tenant, and our responsibilities differ depending on whose data is involved:
- Where we are the responsible party (a "controller" under the GDPR) — the account and identity data of the people who sign in to operate the Service: platform users, organisation members, advertisers and publishers. This Policy governs that data directly.
- Where we are an operator (a "processor") — the audience, customer, viewer, subscriber and campaign data that a customer organisation loads into, or generates through, its own tenant. There, the customer organisation decides why and how the data is processed; we act on its documented instructions under our agreement with it. If you are a viewer, subscriber or customer of an organisation that uses AMPLIFI, that organisation's own privacy notice governs, and requests about your data are best directed to them. We will refer you to them, or assist them in responding.
The rest of this Policy describes our own processing, and describes our operator processing where that helps you understand what the platform does.
2. Information we collect
Information you give us
- Account and identity data — your name, email address, mobile number where you supply one, password (stored only as a salted hash, never in readable form), two-factor and one-time-passcode state, and the organisations and roles attached to your account.
- Profile and preferences — display settings such as your interface theme, saved views, and notification choices.
- Content and campaign data — the content, media, creatives, catalogue, audience definitions, settings and files you upload or configure.
- Communications — support requests, feedback and correspondence with us.
- Billing details — where the Service is paid for, the billing contact and transaction records. Card data is handled by our payment providers; we do not store full card numbers.
Information we collect automatically
- Usage and event data — pages and screens viewed, features used, actions taken, timestamps, and referring URLs.
- Device and connection data — IP address, browser and operating-system details, device type, language, and approximate location derived from the IP address (city or region level, not precise GPS).
- Media and playback data — where you watch or listen: what was played, playback position and completion, quality and buffering events, and whether an item was saved or shared.
- Advertising events — ad requests, impressions, viewable impressions, quartile completions, clicks and conversions, together with the identifiers needed to cap frequency and attribute a result.
- Security and integrity data — sign-in attempts, session records, and signals used to detect fraud, invalid traffic and abuse.
Information from third parties — identity providers when you use social sign-in (see section 4), our customers where they load data into their tenant, and fraud-prevention and measurement partners.
3. Special categories and children
We do not seek out special personal information (as POPIA defines it) — such as health, religious or philosophical beliefs, biometrics, or trade-union membership — and we ask customers not to load it into the Service without a lawful basis and appropriate safeguards. We do not use such information to build advertising segments. The Service is built for organisations and adults; we do not knowingly collect personal information from children under 18 without the consent of a competent person, and we will delete it promptly if we learn we have.
4. Signing in with Google, Apple or Microsoft
You can create an account or sign in using a third-party identity provider. When you sign in with Google, we ask Google only for the openid, email and profile scopes. Google then returns a signed token containing your Google account identifier, your email address and whether it is verified, and your basic profile details (name and profile picture URL).
We use that information for one purpose: to authenticate you and to create or link your AMPLIFI account. Specifically, we store the Google account identifier so we can recognise you on your next sign-in, and your name and email so your account is usable and so colleagues can identify you. If the email address Google returns is verified and already belongs to an existing account, we link the two rather than creating a duplicate.
We do not use Google sign-in data for advertising, we do not sell or transfer it, and we do not use it to build audience segments or profiles. We request no access to Gmail, Drive, Calendar, Contacts or any other Google service as part of signing in. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect AMPLIFI at any time from your Google account permissions page; you will then need another sign-in method, or you can ask us to delete the account entirely. Sign-in with Apple and Microsoft works the same way, using the equivalent minimum scopes. Apple's Hide My Email relay addresses never match an existing account, so those sign-ins always create a new one.
5. How we use information, and on what legal basis
- To provide the Service — authenticate you, maintain your session across our products, apply your roles and permissions, deliver content and media, and run the features you ask for. Basis: performance of our contract with you or your organisation.
- To keep the Service secure — detect and prevent fraud, invalid traffic, credential stuffing and abuse, and maintain audit trails. Basis: our legitimate interests in protecting the Service and its users; compliance with law.
- To deliver and measure advertising — select and serve ads, cap how often you see the same one, and report on delivery and performance. Basis: legitimate interests for delivery, frequency capping and measurement; consent where the law requires it for tracking technologies or personalised advertising.
- To support and communicate with you — answer requests, send service and security notices, and send product updates you can unsubscribe from. Basis: contract; legitimate interests; consent for marketing where required.
- To improve and develop the Service — understand how features are used, debug faults, and plan capacity, using aggregated or de-identified data wherever it will do. Basis: legitimate interests.
- To meet legal and accounting obligations — tax and company records, responding to lawful requests, and establishing or defending legal claims. Basis: legal obligation; legitimate interests.
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you may object — see section 11.
6. Cookies, identifiers and similar technologies
We use a small number of cookies and equivalent identifiers:
- Strictly necessary — the session cookie that keeps you signed in across our products, and short-lived cookies that protect sign-in and form submissions against cross-site request forgery. The Service does not work without these.
- Preference — remembering choices such as your light or dark theme and layout settings.
- Analytics and performance — understanding aggregate usage so we can improve the Service.
- Advertising — identifiers used to cap frequency, prevent repeated or fraudulent impressions, and attribute conversions. On connected-TV and server-side inserted advertising, the equivalent role is played by device advertising identifiers supplied by the platform, which you can reset or limit in your device settings.
You can control cookies through your browser and your device's advertising settings. Blocking strictly necessary cookies will stop you from signing in. Where the law requires consent for non-essential cookies, we ask for it before setting them, and you can change your mind at any time.
7. Audiences, segments and profiling
The Service includes customer-data features that let an organisation combine the event and profile data in its own tenant into traits, segments and audiences, and use those to target content, offers and advertising. Where we do this on a customer's behalf we act as an operator: the organisation chooses the segments and is responsible for having a lawful basis and for giving the notices its own privacy notice requires.
We do not create cross-customer profiles. We do not combine one organisation's tenant data with another's to build shared audiences, and we do not sell personal information or share it for cross-context behavioural advertising in exchange for money or other valuable consideration.
Advertising selection is automated, but it does not produce legal effects or similarly significant effects on you. Where any automated processing would have such an effect, we will tell you and provide a route to human review.
8. How we share information
We share personal information only as needed to run the Service:
- Within your organisation — other members see what their roles and permissions allow, and administrators can see account, role and audit information for their organisation.
- With service providers (our operators) — hosting and infrastructure, content delivery, email and SMS delivery, payment processing, error monitoring, and fraud prevention. They act on our instructions, under written contracts, and may not use the data for their own purposes.
- With advertising counterparties — in real-time bidding, an ad request carries the technical and contextual data needed to value the opportunity (such as the ad slot, approximate location, device type and a capping identifier). Reporting shared with advertisers and publishers is aggregated.
- With identity providers — when you choose social sign-in, the provider necessarily learns that you signed in to AMPLIFI.
- Where the law requires it — to comply with a valid legal process, to enforce our terms, or to protect the rights, safety and property of AMPLIFI, our users or the public. We assess each request, resist those that are overbroad, and tell you where we are lawfully able to.
- In a corporate transaction — in connection with a merger, acquisition, financing or sale of assets, subject to this Policy continuing to apply.
A current list of our sub-processors is available to customer organisations on request, and we give reasonable notice before adding a new one.
9. International transfers
We are based in South Africa and host the Service primarily there. Some service providers process data in other countries. Where personal information leaves South Africa, we transfer it only where the recipient is subject to a law, binding rules or contract that upholds principles for lawful processing substantially similar to POPIA, or where another basis in section 72 of POPIA applies. For personal data covered by the GDPR, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses, with additional safeguards where needed.
10. How long we keep information
- Account and identity data — for as long as the account is active, and for up to 12 months after closure so it can be restored and disputes resolved, unless you ask us to delete it sooner.
- Session and sign-in records — sessions expire on their own schedule; security logs of sign-in attempts are kept for up to 12 months.
- Content, campaign and tenant data — for the term of the customer organisation's agreement, then deleted or returned on the timetable in that agreement.
- Advertising and playback events — detailed event records are kept for up to 13 months, after which we retain only aggregated or de-identified metrics.
- Billing and tax records — for the period South African tax and company law requires, generally five years.
Where information is de-identified so that it can no longer be linked to a person, we may keep and use it indefinitely.
11. Your rights
Subject to applicable law, you may:
- ask what personal information we hold about you, and get a copy;
- ask us to correct or complete information that is inaccurate, irrelevant, excessive, out of date or misleading;
- ask us to delete or destroy information we no longer have grounds to keep;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- ask us to restrict processing while a dispute about accuracy or lawfulness is resolved;
- ask for a portable copy of information you gave us, where that right applies; and
- withdraw consent where we rely on it, without affecting processing already carried out.
Contact us at support@nandie.com to exercise any of these. We may need to verify your identity first, and we will respond within the period the law allows. If your data sits in a customer organisation's tenant, we will pass your request on to that organisation. You may also lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za, or with your local supervisory authority if you are in the EU or UK.
12. Security
We use technical and organisational measures appropriate to the risk: encryption in transit, encryption of sensitive fields at rest, password hashing, optional two-factor authentication, least-privilege role-based access with audit trails, network segmentation between our internal services, and regular patching and review. No system is completely secure, so we cannot guarantee absolute security. If a security compromise affects your personal information, we will notify you and the Information Regulator as soon as reasonably possible after establishing the scope, as section 22 of POPIA requires.
13. Third-party links and embedded content
The Service can display content, players and links from third parties. Those parties set their own cookies and follow their own privacy practices, which we do not control. Their notices govern what they collect.
14. Changes to this Policy
We may update this Policy as the Service and the law develop. If we make material changes we will take reasonable steps to notify you — in the Service or by email — before they take effect, and the "last updated" date above will always show the current version.
Questions, requests, or to reach our Information Officer: support@nandie.com. See also our Terms of Service.