Privacy Notice of AmplifAI Oncology, Inc.
Scope of this Notice
This Privacy Notice describes how AmplifAI Oncology, Inc. (“AmplifAI,” “we,” “our,” or “us”) (the “Company”) collects, uses, discloses, and protects personal information collected through its public website located at https://amplifai-oncology.com (the “Website”), including through the Website’s general contact form (“Talk to us”), its demo-scheduling function (“Schedule a demo”), its specialist-network registration function (“Join the Network”), its newsletter sign-up (“Notes from the Network”), and its ASTRO 2026 meeting booking.
This Privacy Notice applies only to the Website. It does not apply to information collected through the AmplifAI platform used by registered clinics, specialists, provider organizations, or other authorized users to coordinate radiotherapy treatment planning services. Use of the AmplifAI platform is governed by a separate Platform Privacy Notice.
Data Controller
AmplifAI Oncology, Inc., a Delaware corporation (the “Company”). The Company does not have an establishment in the European Union.
Data Protection Officer
The Company has not appointed a Data Protection Officer. For any inquiries regarding the processing of your personal data, please contact: business@amplifai-oncology.com.
Data Processing
| Categories of Personal Data Collected | Purposes of Processing | Legal Basis for Processing | Data Retention |
|---|---|---|---|
| Name E-mail address Organization name Message content and any additional information voluntarily provided |
To respond to inquiries and requests submitted through the Website’s contact form (“Talk to us”), including inquiries from clinics, networks, service providers, and technology partners, and, where the message concerns the exercise of a right under the GDPR, to facilitate the exercise of that right. | Art. 6(1)(f) GDPR — the Company’s legitimate interest in being able to provide an appropriate response to your message; where applicable, Art. 6(1)(c) GDPR — compliance with the Company’s legal obligation under Art. 12(2) GDPR to facilitate the exercise of data subject rights |
Until the successful closure of the communication with you |
| Any personal data arising from the contact and subsequent communication, following a case-by-case assessment | To secure evidence of the Company’s position in the event of a potential legal claim (e.g., to demonstrate what correspondence took place and its subject matter). | Art. 6(1)(f) GDPR — the Company’s legitimate interest in having appropriate evidence available in the event of a legal claim | The applicable civil-law limitation period (5 years), running from the successful closure of the communication |
| Name E-mail address Organization name Selected appointment date and time Additional data collected by the scheduling tool (Google Calendar appointment scheduling) |
To schedule and conduct product demonstrations of the Company’s services (“Schedule a demo”) and to communicate with you in relation to the scheduled demonstration. | Art. 6(1)(f) GDPR — the Company’s legitimate interest in being able to organize and deliver the requested demonstration | Until the successful closure of the communication with you (i.e., completion of the scheduled demonstration or related correspondence) |
| Any personal data arising from the scheduling and subsequent communication, following a case-by-case assessment | To secure evidence of the Company’s position in the event of a potential legal claim. | Art. 6(1)(f) GDPR — the Company’s legitimate interest in having appropriate evidence available in the event of a legal claim | The applicable civil-law limitation period (5 years), running from the successful closure of the communication |
| Area of interest (client, provider or partner) Name Organization name and, optionally, organization website Country Contact e-mail address and work e-mail address Message (optional) |
To register your interest in the Company’s specialist network (“Join the Network”) and to contact you with further information. | Your consent (Art. 6(1)(a) GDPR), given on the registration form | Until your request has been handled, or until you withdraw your consent or ask for removal, whichever occurs first. Thereafter, personal data required for the establishment, exercise or defence of legal claims is retained for the applicable civil-law limitation period (5 years). |
| E-mail address The page you subscribed from The dates of your request, confirmation and, where applicable, unsubscription |
To send you new articles from “Notes from the Network” by e-mail. You are added only after you click the confirmation link we e-mail you, and every e-mail contains a link to unsubscribe. | Your consent (Art. 6(1)(a) GDPR), given when you confirm your subscription; after you unsubscribe, Art. 6(1)(f) GDPR — the Company’s legitimate interest in making sure you are not e-mailed again |
Until you unsubscribe. An address that is never confirmed is deleted within 30 days of the request. After you unsubscribe, only your address and its unsubscribed status are kept, so that no further e-mails are sent to you. |
| Name E-mail address Organization name Chosen meeting slot Topics of interest and any note you add E-mail addresses of colleagues you invite (up to 8) |
To organize the meeting you request at the Company’s ASTRO 2026 booth, to send you a confirmation and calendar invitation, and to send each colleague you name one invitation to the meeting and one e-mail asking whether they would like the Company’s articles (nothing further is sent to them unless they confirm). | Art. 6(1)(f) GDPR — the Company’s legitimate interest in organizing and holding the meeting you requested and, for the colleagues you name, in inviting them to it at your request | Until the meeting and any related correspondence are closed. Thereafter, personal data required for the establishment, exercise or defence of legal claims is retained for the applicable civil-law limitation period (5 years). |
EU Representative (Article 27 GDPR)
The Company has appointed Erkkel Solutions Kft. (seat: 2096 Üröm, Táborföld utca 4.; registration number: 13-09-231382), a company established in Hungary, as its representative in the European Union pursuant to Article 27 GDPR. The EU Representative acts as the Company’s point of contact for data subjects and supervisory authorities on all issues related to processing, and maintains the record of processing activities on behalf of the Company as required by Article 27(4) GDPR. Contact details: 2096 Üröm, Táborföld utca 4.; info.erkkel@gmail.com.
Special Categories of Personal Data
The Company does not request or intend to process special categories of personal data within the meaning of Article 9 GDPR through the Website.
Recipients of Personal Data
Your personal data may be disclosed to the following recipients:
| Recipient | Category | Purpose of Transfer |
|---|---|---|
| Erkkel Solutions Kft. (seat: 2096 Üröm, Táborföld utca 4., Hungary) | Sub-processor | Software development services |
| Microsoft Corporation (Microsoft Azure, including Azure Communication Services) Data is stored and processed on Azure services in the Sweden Central region (European Union), e-mail is sent through Azure Communication Services with its data location in Europe, and support access may occur from the United States |
Sub-processor | Hosting, infrastructure and sending of e-mails |
| Google (Google Calendar appointment scheduling) | Sub-processor | Scheduling of product demonstrations |
International Transfers of Personal Data
Your personal data is hosted in the European Union and may be transferred to, and processed in, the United States of America. This section distinguishes between two legs of those transfers, each of which relies on a different mechanism.
(a) Hosting in the European Union, and residual support access by Microsoft Corporation. Personal data processed through the Website is hosted on Microsoft Azure services located in the Sweden Central region of the European Union, and e-mails are sent through Azure Communication Services with its data location in Europe. To the extent that Microsoft Corporation additionally accesses personal data from the United States (for example, in connection with technical support), that access is covered as follows: Microsoft Corporation, acting as the Company’s sub-processor for hosting and infrastructure services, is included on the official Data Privacy Framework List maintained by the U.S. Department of Commerce (EU-U.S. Data Privacy Framework: Active). Accordingly, personal data accessed or processed by Microsoft Corporation in the United States (for example, in connection with technical support) is transferred in reliance on the European Commission’s adequacy decision of 10 July 2023 concerning the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), pursuant to Article 45 GDPR. No additional safeguards or separate consent are required for this specific leg of the transfer, for as long as Microsoft Corporation’s Data Privacy Framework certification remains active and covers the relevant processing. Should the EU-U.S. Data Privacy Framework be invalidated or otherwise cease to be applicable, transfers to Microsoft Corporation will instead rely on the data-transfer arrangements approved by the European Commission (Standard Contractual Clauses) that Microsoft Corporation applies in such circumstances.
(b) Receipt and use of personal data by the Company itself. The Company (AmplifAI Oncology, Inc.) receives personal data of data subjects in the European Union in the United States. This occurs both where you submit personal data directly through the Website — for example by completing the contact form, requesting a demonstration, or registering through the “Join the Network” function — and where personal data is made available to the Company by its processors established in the European Union, including Erkkel Solutions Kft., acting as the Company’s processor for software development purposes. All such transfers are made in reliance on the Company’s own self-certification under the EU-U.S. Data Privacy Framework, pursuant to Article 45 GDPR and the European Commission’s adequacy decision of 10 July 2023. The Company applies this basis uniformly to all personal data it receives from the European Union, without distinguishing between data submitted directly by data subjects and data received through its processors.
Cookies
A cookie is a small text file that a website you visit stores on the device you use to browse the internet. Your device stores the cookie for a defined period. Some cookies are deleted as soon as you close your browser (“session cookies”), while others are stored for a longer period and allow a given website to remember certain parameters (e.g., your selected language), so that they are loaded automatically when you revisit the website.
Websites use cookies for multiple purposes. Some cookies are needed so that the website functions properly and all of its content displays correctly on your device — these are therefore strictly necessary. Other cookies serve marketing purposes.
Cookies do not pose a security risk to your device and do not cause malfunctions.
Given that some cookies may, in the course of their operation, record information that qualifies as personal data (such as the IP address, type of the device used to browse, and your activity on the Website), their use is only permitted where it complies with applicable data protection law.
Cookies can be categorized on several bases. On one basis, according to whether they are used by the Company itself (“first-party cookies”) or by a third-party organization (“third-party cookies”). Another possible categorization follows the categories described below. The Website uses two such categories: strictly necessary cookies and marketing cookies. It does not use functional or statistical (analytics) cookies.
The cookies available on the Website fall into the following categories:
- Strictly necessary cookies. Necessary for the technical operation of the Website (e.g., for the error-free display of graphical content and for navigation); their use cannot therefore be disabled. These cookies are placed automatically on your computer or other device when you visit the Website, for the purpose of the Website’s uninterrupted use. Their purpose is to guarantee the security of the Website, ensure error-free display of its content, and balance the Website’s load. The Website’s only strictly necessary cookie, ampl_consent, stores your cookie choice and nothing else. It is processed by the Company on the basis of its legitimate interest in the secure and uninterrupted operation of the Website (Art. 6(1)(f) GDPR), for one year.
- Marketing (targeting and advertising) cookies. The Website’s only marketing cookie, NID, is set by Google when the demo booking calendar is opened; Google uses it to recognise your device and for advertising. The Company itself shows no advertising. These cookies are only used with your consent, which you can withdraw at any time via the cookie-settings interface.
Please note that you can also manage cookies in your browser settings, and you can delete any cookie stored on your device at any time. However, if you also delete cookies that are indispensable for the proper functioning of the Website, certain functions of the Website may not work, or may not work properly.
The following table sets out further information on which specific cookies run on the Website :
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
| ampl_consent | amplifai-oncology.com (first-party) | Records your cookie choice so that you are not asked again on each visit. Strictly necessary. | 1 year |
| NID | google.com (third-party) | Set by Google when the demo booking calendar is opened. Google uses it to recognise your device and for advertising. Placed only with your consent. If you decline, the booking button opens Google’s own booking page in a new tab, so nothing is stored from our Website; anything set on Google’s page is governed by Google’s own policies. | 6 months |
Security of Processing
The Company implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Article 32 GDPR), including access controls and least-privilege practices, encryption in transit and at rest where feasible, network and application logging and monitoring, vulnerability and patch management, data minimization and retention controls, and an incident response process.
Your Rights
Under the GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, please contact: business@amplifai-oncology.com. The Company will respond to your request without undue delay and in any event within one (1) month of receipt of the request. This period may be extended by two (2) further months where necessary, taking into account the complexity and number of requests. The Company will inform you of any such extension within one (1) month of receipt of the request, together with the reasons for the delay. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the Company may either charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested, or refuse to act on the request.
Right of Access (Article 15 GDPR)
You have the right to obtain from the Company confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data together with the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; the existence of the right to request from the Company rectification or erasure of personal data or restriction of processing of personal data concerning you or to object to such processing; the right to lodge a complaint with a supervisory authority; where the personal data are not collected from you, any available information as to their source; and the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for you. Where personal data are transferred to a third country or to an international organisation, you have the right to be informed of the appropriate safeguards pursuant to Article 46 of the GDPR relating to the transfer. The Company shall provide a copy of the personal data undergoing processing. For any further copies requested by you, the Company may charge a reasonable fee based on administrative costs.
Right to Rectification (Article 16 GDPR)
You have the right to obtain from the Company without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to Erasure (Article 17 GDPR)
You have the right to obtain from the Company the erasure of personal data concerning you without undue delay where one of the following grounds applies: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw your consent on which the processing is based and there is no other legal ground for the processing; you object to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2) of the GDPR; the personal data have been unlawfully processed; the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Company is subject; or the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR. Where the Company has made the personal data public and is obliged to erase the personal data, the Company, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data. The right to erasure does not apply to the extent that processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest in the area of public health, for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, or for the establishment, exercise, or defence of legal claims.
Right to Restriction of Processing (Article 18 GDPR)
You have the right to obtain from the Company restriction of processing where one of the following applies: you contest the accuracy of the personal data, for a period enabling the Company to verify the accuracy of the personal data; the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead; the Company no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise, or defence of legal claims; or you have objected to processing pursuant to Article 21(1) of the GDPR pending the verification whether the legitimate grounds of the Company override yours. Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise, or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. The Company will inform you before the restriction of processing is lifted.
Right to Data Portability (Article 20 GDPR)
You have the right to receive the personal data concerning you, which you have provided to the Company, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the Company, where the processing is based on your consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR, and the processing is carried out by automated means. In exercising your right to data portability, you have the right to have the personal data transmitted directly from the Company to another controller, where technically feasible. The exercise of this right is without prejudice to the right to erasure and shall not adversely affect the rights and freedoms of others.
Right to Object (Article 21 GDPR)
Where personal data are processed on the basis of Article 6(1)(e) or (f) of the GDPR, you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you. The Company shall no longer process the personal data unless the Company demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise, or defence of legal claims. Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, including profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
Right to Withdraw Consent (Article 7(3) GDPR)
Where the processing of your personal data is based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. You shall be informed thereof before giving consent.
Right Not to Be Subject to Automated Decision-Making (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except where such decision is necessary for entering into, or performance of, a contract between you and the Company, is authorised by Union or Member State law to which the Company is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or is based on your explicit consent. In the cases referred to above, the Company shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the Company, to express your point of view and to contest the decision.
Competent Supervisory Authority
As the Company’s EU Representative is established under Hungarian law, the competent supervisory authority for the purposes of this processing is the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság; “NAIH”), H-1055 Budapest, Falk Miksa utca 9-11, Hungary (website: www.naih.hu).
Right to Lodge a Complaint (Article 77 GDPR)
You have the right to lodge a complaint with the competent supervisory authority, in particular the NAIH (as identified above), if you consider that the processing of personal data relating to you infringes the GDPR.
Date of this Notice: September 18, 2026