Requests from Public Authorities
Updated August 2026
This page explains what Amargi Creative does when a court, a regulator, a police force, a tax authority, or any other public body asks us to hand over personal data belonging to our customers or to the people who message them. It describes what a company of our size actually does, not a procedure borrowed from a larger one. It applies to every Amargi product: Reach, Escalate, Agents, Mail, and Meet.
Our record so far
As of the date at the top of this page, Amargi Creative has never received a request from any public authority, in any country, for personal data held in our products. We have never disclosed customer data or end-customer data to a public authority, and we have never been asked to. We publish this so that it can be checked against this same page later. If it stops being true, we will change this section and say when it changed.
Who deals with a request, and who may not
Amargi Creative is a small company. There is no legal department and no compliance team, and we are not going to describe one that does not exist. Every request from a public authority is handled personally by the founder of Amargi Creative, who is the accountable owner of this policy and the only person who may authorise a disclosure.
No engineer, operator, support agent, or contractor may answer such a request, hand over data, or confirm whether an account exists. Anyone at Amargi Creative who receives a request, by email, by telephone, in person, or through any product channel, must not respond to it and must forward it to contact@amargicreative.com the same day. Where a request raises a question we are not competent to answer ourselves, we instruct an external lawyer qualified in the relevant jurisdiction before we reply.
Amargi Creative is established in the Hashemite Kingdom of Jordan and our production systems are hosted in Frankfurt, Germany, so a request will often touch more than one legal system.
Step 1. We review whether the request is lawful before anyone looks at data
We do not act on a telephone call, an email signature, or an assurance that the matter is urgent. We require the request in writing, and before anything is read, exported, or handed over we check the following, in this order.
Who is asking. We verify the authority and the identity of the officer through a channel we find ourselves, never a telephone number or an address supplied inside the request.
Under what power. The request must identify the legal instrument that compels it, such as a court order, a warrant, a subpoena, or a statutory notice. A request that cites no legal power is a voluntary request, and we refuse voluntary requests for personal data.
Whether that power reaches us. We check that the authority has jurisdiction over Amargi Creative or over the data, and that the instrument is valid, in force, and correctly served.
Whether the data is ours to give at all. Usually it is not, for the reason set out below under the heading about requests that should not come to us.
If any of these checks fails, we do not disclose. Nothing leaves our systems until this review is finished and the founder has approved it in writing.
Step 2. We challenge requests we consider unlawful or overbroad
If we conclude that a request is unlawful, invalid, defective, or wider than the power it relies on, we do not comply with it. We tell the authority so in writing, we give our reasons, and we ask them to withdraw the request or narrow it. If the authority presses it, we take whichever of these steps fits the request and the jurisdiction.
We refuse in writing and require the authority to enforce the request through a court, so that a judge and not Amargi Creative decides the question. This step is available to us whatever our budget, and it is our default.
We file the formal objection or appeal that the relevant procedure provides for.
We apply to the issuing court to set aside or narrow the order, instructing external counsel where the matter warrants it.
Where complying would require us to breach the GDPR or another law that binds us, we say so to the authority, and we notify the affected customer and the competent supervisory authority wherever we are permitted to do so.
We should be honest about the limit. Funding a long court fight is not something a company of our size can promise in every case. What we can promise, and do, is that we will never hand over personal data merely because a request looks official or because refusing would be inconvenient, and that we will always make the authority prove its power before we act.
Step 3. We disclose the minimum, or nothing
Where we are lawfully compelled to disclose, we disclose the least that answers the order and nothing beyond it.
We answer the narrowest question actually asked. If an authority asks whether an account exists, we answer that question and do not attach the messages.
We scope every disclosure to the identifiers named and the time window stated in the order. A request naming one phone number does not become a request for a whole account, and a request covering one month does not become a request for a year.
We prefer metadata to content, and we do not volunteer message bodies where a delivery record answers the order.
We never give bulk access, and we never grant an authority direct or standing access to our systems: no database credentials, no administrator account, no API key, and no continuing feed.
We do not use the internal inspection tool to browse around a request. Access to message content is already restricted and logged, as described in our Privacy Posture, and a lawful order is one of only three grounds on which it is permitted at all.
Where the order covers an identifier or a period for which we hold nothing, we say that the data does not exist rather than offering something adjacent.
Most requests should not come to us in the first place
For the data our customers keep in Amargi products, the customer is the controller and Amargi Creative is only the processor. The conversations, contacts, and messages in Reach belong to the business that runs the account, not to us. When an authority asks us for a customer's data, our first answer is that the request should be directed to that customer, and we tell the authority so.
We notify the affected customer without undue delay so that they can respond, object, or instruct us, unless a court order or a statute forbids us from telling them. Where we are both compelled to produce data ourselves and prohibited from notifying the customer, we record the prohibition, its legal basis, and the date it expires, and we notify the customer as soon as it lapses.
There is also data we simply cannot produce. Message content on WhatsApp, Messenger, and Instagram passes through platforms operated by Meta, and where an authority wants records that Meta holds rather than records we hold, the request belongs to Meta and we say so. We have never built any facility for intercepting messages in real time, and we will not build one to satisfy a request.
How a request is recorded
Every request is recorded, whether or not we disclose anything, whether or not we consider it valid, and whether or not it is later withdrawn. The record is opened on the day the request arrives and completed when the matter closes.
For each request we record: the date it arrived and the channel it arrived through; the authority, the country, and the named officer; the legal instrument relied on, and a copy of the request itself; what data was sought; our assessment of its lawfulness, who made that assessment, and the reasoning that led to the conclusion, including the reasoning behind any decision to challenge; every person inside Amargi Creative who saw the request or the data, and what each of them did; exactly what was disclosed, field by field, or the fact that nothing was disclosed; the date and content of our reply; and whether the affected customer was notified, together with the legal basis for any decision not to notify.
The register is kept with the company's legal records, outside the production systems, and access to it is limited to the founder. Entries are retained for at least seven years after the matter closes. Because no request has ever been received, the register contains no entries today. The first entry will be made on the day the first request arrives.
Contact
Public authorities should send requests in writing to contact@amargicreative.com, marked for the attention of the founder. We do not accept requests for personal data by telephone and we do not act on them.
Customers with questions about this policy, and data protection officers who need it in signed form for their own records, can use the same address. This policy forms part of our Data Processing Agreement, published at https://amargicreative.com/legal/dpa