Data Portability
This page describes Amio’s current operational and technical approach to switching and data portability for customers under the EU Data Act. It complements Section 13 of Amio’s Terms of Service. If this page conflicts with the Terms, the Terms control.
This is a living technical and compliance resource. Amio may update the procedures, export structure, formats, interfaces, infrastructure information and technical limitations described here as the Services evolve, provided that doing so does not reduce customers’ rights under the Terms or applicable law.
1. Requesting a switch or data export
To start a switching or portability request, an authorised Customer representative should email support@amio.io.
Please include:
- Customer organisation name
- Whether you want to switch to another provider, move the data to your own infrastructure, or request erasure
- The destination provider and a contact person there, if applicable
- The requested scope of the export
- Any relevant target timing
Amio may ask for information needed to verify the request and the requesting person’s authority, identify the relevant organisation and data, and coordinate with a destination provider where applicable.
Switching requests are handled operationally. Amio makes documented interfaces available for portability and switching to the extent required by applicable law. A complete portability export may additionally be prepared through an assisted export process and secure handover. Timing and transition obligations are governed by Section 13 of the Terms and applicable law. The assisted export required to fulfil Customer’s switching rights is included without a switching charge under Section 13.10 of the Terms. Standard service fees and any separately agreed lawful early-termination amount remain governed by the Terms and applicable Order.
2. What is included
The legally binding categories of Exportable Data and portable digital assets, and the categories excluded from portability, are defined in Section 13.7 of the Terms of Service.
For practical portability, Amio may provide structured customer-specific records together with retained Customer files or media where applicable. Amio may transform, consolidate or normalise the data for export and does not reproduce its user interface, production database schema, storage architecture or other internal technical representation.
3. Current export formats and Article 26 online register
This section is Amio’s up-to-date online register for the purposes of Article 26(b) of the EU Data Act. It describes the portability export, not Amio’s production database schema, storage architecture or internal implementation.
Current export structure
Amio portability exports use UTF-8 encoded JSON for structured data. The current export structure is:
{
"generatedAt": "ISO 8601 datetime",
"customer": {
"id": "string",
"name": "string"
},
"contacts": [
{
"id": "string",
"externalId": "string|null",
"channelId": "string",
"platformContactId": "string|null",
"name": "string|null",
"phoneNumber": "string|null",
"attributes": "object|null"
}
],
"messages": [
{
"id": "string",
"contactId": "string",
"direction": "string",
"content": "object",
"metadata": "object|null",
"createdAt": "ISO 8601 datetime",
"deliveredAt": "ISO 8601 datetime|null",
"readAt": "ISO 8601 datetime|null",
"platformMessageId": "string|null"
}
],
"agents": [
{
"id": "string",
"name": "string|null",
"type": "string",
"language": "string",
"timezone": "string",
"active": "boolean",
"marketId": "string|null",
"configuration": "object"
}
],
"markets": [
{
"id": "string",
"name": "string",
"language": "string|null",
"configuration": "object|null"
}
],
"knowledgeSources": [
{
"id": "string",
"name": "string",
"type": "string",
"format": "string|null",
"url": "string|null",
"marketId": "string|null",
"schedule": "object|null",
"configuration": "object|null"
}
],
"productSources": [
{
"id": "string",
"name": "string",
"type": "string",
"format": "string|null",
"url": "string|null",
"marketId": "string|null",
"schedule": "object|null",
"configuration": "object|null"
}
],
"integrations": [
{
"id": "string",
"kind": "string",
"name": "string|null",
"configuration": "object"
}
],
"analytics": [
{
"type": "string",
"data": "object"
}
],
"files": [
{
"path": "string",
"name": "string",
"mediaType": "string|null",
"relatedResourceType": "string|null",
"relatedResourceId": "string|null"
}
]
}
Resource groups and fields that are not applicable to a Customer may be omitted. Relationships between records are represented by identifiers where applicable. Dates and timestamps use ISO 8601-compatible values.
Fields described as `object` are JSON objects whose keys and values depend on the applicable resource type or Customer configuration and do not have a fixed common sub-schema. Those objects must preserve portable Customer-created or Customer-configured content, settings, outputs and relationships within the relevant categories in Section 13.7 of the Terms, including Customer-authored prompts, instructions, flows, templates, mappings and relevant metadata where applicable. A portable category is not excluded merely because it has no separate top-level field in the structure shown above. Where field meanings or relationships are not self-explanatory, Amio will provide the information reasonably necessary to interpret and use the export. This does not require disclosure of protected internal implementation.
Files and binary media may be supplied separately from the JSON package in their original or another commonly used format and may be referenced from the structured export.
For integrations, configuration contains only non-secret configuration. Credentials, tokens, keys and other secrets are excluded as described in Section 5.
The export structure describes the portability package and does not reproduce Amio’s internal database schema.
Standards and maintenance
The export structure is not fixed contractually. Amio may update the structure when the Services or portability implementation changes, and this online register will be updated to reflect the current export structure.
Relevant standards and interoperability specifications: JSON (RFC 8259), UTF-8, ISO 8601 / RFC 3339-compatible timestamps, URI-form references and standard MIME media types where applicable.
No specific service-type interoperability standard or open interoperability specification currently applies to the portability export unless stated otherwise on this page. If one becomes applicable, Amio will update this register in accordance with applicable law.
4. Existing APIs and interfaces
Amio makes its relevant documented REST APIs and webhooks available for portability and switching, to the extent required by applicable law, to Customers and concerned destination providers authorised by them. Such interfaces are made available on an equal basis and without a separate switching charge.
The current public API reference is available at:
https://docs.amio.io/reference/introduction
The documented interfaces include, among other things, APIs for messages, channels, contacts and settings, together with webhook events for messaging activity.
The interfaces support software communication with the relevant Amio services for portability and interoperability within their documented scope. They do not necessarily expose every category of Exportable Data. A complete portability export may therefore be prepared separately through the assisted export process.
5. Credentials and secrets are not exported
Portability exports do not include security-sensitive credentials or secrets, including:
- Passwords or password hashes
- API keys
- Access or refresh tokens
- OAuth or other authentication credentials
- Webhook or signing secrets
- Private or cryptographic keys
- Session material
- Equivalent security-sensitive credentials
This exclusion applies regardless of whether the credential was issued by Amio, supplied by the Customer or obtained from a third-party service. Such credentials may instead be revoked or deleted as part of switching or termination. The exclusion applies only to the extent permitted by applicable law and Section 13.7(c) of the Terms and must not unlawfully impede or delay switching. This page does not create additional exclusions.
Non-secret configuration of an integration remains portable where it falls within the categories described in the Terms.
6. Known technical limitations
Portability is subject to the following current technical and legal limitations:
- The export does not reproduce Amio’s user interface, internal database schema, internal APIs, storage architecture or proprietary runtime behaviour
- Only data retained by Amio at the time the export is prepared can be exported, subject to applicable retention and deletion rules. This limitation does not permit routine account closure or retention processes to shorten a contractual or mandatory switching, transition or retrieval period
- External content that Amio does not retain may be represented by a reference or configuration rather than by a new copy of the content
- Third-party rights, intellectual-property rights, trade secrets, security requirements and other exclusions described in Section 13.7 of the Terms continue to apply
- Large files or binary assets may be transferred separately from the structured data package
- A destination provider may need to map or transform the exported data to its own schema and functionality
- The export schema and implementation details may change over time
7. Infrastructure jurisdictions
Amio’s primary application hosting, database, object/file storage, backup, vector-search and logging/monitoring infrastructure is operated in Frankfurt, Germany. AI inference infrastructure is operated in Sweden. These jurisdictions will be kept up to date as configurations or hosting locations change. Personal-data processing and international transfers are governed separately by Amio’s Data Processing Agreement.
8. Safeguards against unlawful governmental access
Amio uses technical, organisational and contractual measures designed to protect data held in the European Union against unauthorised or unlawful access or transfer, including:
- Hosting primary infrastructure in the European Union
- Encryption of Customer Data in transit and encryption at rest for production databases storing Customer Personal Data, as described in the DPA
- Role- and need-based access controls and authentication for production systems
- Logical separation of customer data
- Contractual confidentiality, security and data-protection obligations with relevant service providers
- Data minimisation, retention controls and deletion practices, including automatic AWS backup lifecycle controls
These measures are designed to reduce the risk of unauthorised or unlawful access, including access by public authorities without a valid legal basis. Amio takes the adequate technical, organisational and legal measures required by Article 32 of the EU Data Act to prevent access or transfer that would conflict with Union law or the national law of the relevant Member State. Where Amio receives a request from a third-country authority for access to or transfer of non-personal data held in the European Union, Amio assesses the request against applicable Union and Member State law before complying. A third-country court judgment or administrative order does not by itself provide a sufficient basis for disclosure; access or transfer must satisfy the conditions in Article 32(2) or (3). Where disclosure is legally permitted or required, Amio limits the disclosure to the minimum amount permissible and informs the affected Customer before compliance, except where and for as long as applicable law permits or requires that notification to be withheld for law-enforcement purposes. Where appropriate under applicable law, Amio may seek the opinion of a competent authority or reject a request that does not satisfy the applicable legal conditions. Additional security information is available in Amio’s Data Processing Agreement.
9. Updates to this page
Amio may update this page when its Services, export schema, formats, interfaces, infrastructure or technical limitations change. An update to this page does not by itself reduce a Customer’s contractual switching, transition, retrieval or deletion rights under Section 13 of the Terms and does not expand the contractual categories excluded from Exportable Data.
References
Terms of Service:
https://www.amio.io/terms-of-service
Data Processing Agreement:
https://www.amio.io/legal/data-processing-agreement
API Reference:
https://docs.amio.io/reference/introduction