Privacy
Policy

for the anymize service

§ 1 Controller and data protection officer

1.1 Controller

anymize GmbH

Schauenburgerstr. 116

24118 Kiel, Germany

Email: info@anymize.ai

Phone: +49 431 729 85 2320

Commercial register: AG Kiel HRB 29239 KI

VAT ID: DE461722394

Managing directors: Nikolai Raitschew und Raitschin Raitschew

1.2 Data protection officer

We have appointed a data protection officer:

Manuel Langeheinecke (digitalNORD GmbH Kiel, Schleswig-Holstein)

You can reach them as follows: by post at our company address marked “Data protection officer” or by email at datenschutz@anymize.ai

Governing language

anymize GmbH is a limited liability company incorporated under German law, based in Kiel, Germany. This privacy policy is governed by German law and by the GDPR.

This English version is provided for ease of understanding only. In the event of any discrepancy, the German version alone is authoritative and can be found at https://anymize.ai/datenschutz.

2 Principles of data processing

2.1 Scope of processing

We process our users' personal data only to the extent necessary to provide the anymize service, or where a legal basis exists.

2.2 Legal bases

Personal data is processed on the basis of the following legal grounds under the GDPR:

  • Art. 6 (1) (b) GDPR: Performance of a contract
  • Art. 6 (1) (c) GDPR: Legal obligation
  • Art. 6 (1) (f) GDPR: Legitimate interests
  • Art. 6 (1) (a) GDPR: Consent (for optional additional services)

3 Data processing when visiting the website

3.1 Log files

Each time our website is accessed, information is automatically stored in server log files:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the file retrieved
  • Website from which the access originates (referrer URL)
  • Browser used and, where applicable, the operating system

Legal basis: Art. 6 (1) (f) GDPR (legitimate interests: system security and stability)

Retention period: 30 days, then automatic deletion

3.2 Cookies and tracking technologies

Technically necessary cookies: Session cookies for website functionality, cookie consent status, login status and security features. Legal basis: Art. 6 (1) (f) GDPR. Retention period: end of session or 30 days.

Language preference cookie (anymize_lang): Stores the language you selected or that was detected automatically (German, English or Norwegian), so that future visits take you straight to the right language version. Legal basis: Art. 6 (1) (f) GDPR in conjunction with Sec. 25 (2) no. 2 TDDDG (technically necessary, no consent required). Retention period: 12 months.

Analytics cookies: Google Analytics for website analysis, PostHog for user behaviour and product analytics. Legal basis: Art. 6 (1) (a) GDPR (consent). Retention period: up to 26 months.

Marketing cookies: Meta Pixel (Facebook) for advertising purposes, LinkedIn Pixel for B2B marketing, Microsoft UET tag for conversion tracking. Legal basis: Art. 6 (1) (a) GDPR. Retention period: up to 2 years.

B2B tracking (cookieless): LeadInfo for company identification. Legal basis: Art. 6 (1) (f) GDPR. Note: no cookies, no personal data relating to individuals.

3.3 Locally stored functional data (localStorage)

To provide necessary functions we store one value exclusively in your device's browser storage (localStorage). This data does not leave your device and is not transmitted to our servers.

anymize_partner: Slug and display name of the partner through whose referral link you entered our site, plus a timestamp. Purpose: consistent display of the partner conditions that apply to you as you navigate to other pages. Retention period: 30 days since the last partner visit, then automatic deletion.

Legal basis: Art. 6 (1) (f) GDPR in conjunction with Sec. 25 (2) no. 2 TDDDG (strictly necessary storage, no consent required, as it serves the function only and has no personal reference).

Objection: Values can be deleted at any time via your browser's developer tools (Application or Storage → Local Storage → anymize.ai).

3.4 Google Tag Manager

We use Google Tag Manager to manage website tags.

Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Purpose: Central management of tracking codes

Data transfer: EU-US Data Privacy Framework

Objection: Browser settings or opt-out available

3.5 Cookiebot (consent management)

We use Cookiebot to obtain and manage consent for non-technical cookies.

Provider: Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark

Data processed: Consent ID, consent status, timestamp, IP address (truncated), browser data

Purpose: Documentation and management of consent given or withdrawn, in accordance with the GDPR and the TDDDG

Legal basis: Art. 6 (1) (c) GDPR (legal obligation to document consent)

Retention period: Up to 12 months

4 Marketing and analytics tools

4.1 Google Analytics

Data processed: IP address (anonymized), page views, time on page, device type

Purpose: Website optimization, understanding user behaviour

Retention period: 26 months

Opt-out: https://tools.google.com/dlpage/gaoptout

4.2 PostHog Analytics

Provider: PostHog Inc., San Francisco, CA, USA

Hosting: Exclusively on EU servers (Frankfurt/Ireland), no data transfer to the USA

Data processed: User interactions, feature usage, session replays (anonymized)

Retention period: 12 months

Data protection: Fully GDPR-compliant, EU servers, ISO 27001 certified

4.3 Meta Pixel (Facebook)

Provider: Meta Platforms Inc., Menlo Park, CA, USA

Data processed: Page views, conversion events, hashed email addresses

Purpose: Ad optimization, custom audiences, lookalike audiences

Retention period: 180 days

4.4 LinkedIn Insight Tag

Provider: LinkedIn Corporation, Mountain View, CA, USA

Data processed: Professional demographic data, page interactions

Purpose: B2B advertising, website demographic insights

4.5 LeadInfo

Provider: Leadinfo B.V., The Hague, Netherlands

Hosting: Exclusively within the EU (Ireland/Frankfurt)

Data processed: IP addresses of companies (no personal data relating to individuals), page views, visit duration, referrer URL

How it works: Cookieless tracking, matching IP addresses to companies via public business databases

LeadInfo identifies companies only, never individuals. 100% GDPR-compliant, ISO 27001 certified, EU hosting.

4.6 Microsoft Advertising (UET tag)

Provider: Microsoft Corporation, Redmond, WA, USA / Microsoft Ireland Operations Limited, Dublin

Data processed: IP address, cookie ID, page views, conversion events, device information

Purpose: Conversion tracking, campaign optimization, remarketing

Retention period: Up to 390 days

4.7 HubSpot CRM

Provider: HubSpot, Inc., Cambridge, MA, USA / HubSpot Ireland Limited, Dublin

Hosting: EU data centre in Frankfurt, Germany, with backup in Ireland

Data processed: Contact details, email address, communication history, lead scoring, interactions

Purpose: CRM, lead management, customer communication, marketing automation

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) / Art. 6 (1) (f) GDPR (legitimate interests)

5 Cookie settings and objection

5.1 Cookie consent banner

On your first visit to our website a cookie banner appears, through which you can give your consent for non-technical cookies.

5.2 Objection and opt-out options

Google Analytics: Browser add-on or opt-out cookie via our website

Meta Pixel: Facebook ad settings or Your Online Choices (http://www.youronlinechoices.com/)

LinkedIn Insight Tag: LinkedIn privacy settings (https://www.linkedin.com/psettings/)

PostHog: Opt-out via our cookie settings. The browser Do-Not-Track setting is respected.

LeadInfo: Cookieless tracking, no opt-out required. Identifies companies only.

Microsoft Advertising: Opt-out via Microsoft privacy settings or the cookie banner

5.3 Browser settings

You can disable cookies in your browser settings. Please note that this may limit the functionality of our website.

6 Data processing on registration and use

6.1 Account data

On registration we process:

Master data: Company name, contact person, email address

Technical data: API keys, usage statistics

Account management: Login credentials, account status, chosen plan

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)

Retention period: Until termination + 10 years (commercial law retention periods)

6.2 Billing and payment data

To process payments we process, in cooperation with Stripe: invoicing data (company name, billing address, VAT ID), payment information processed via Stripe, transaction history and billing-relevant data (credit consumption, plan changes, terminations).

Retention period: 10 years for billing purposes and commercial law retention periods

6.3 Usage data

To provide the service we process: processing statistics (number of credits processed, API calls), chat usage (number of chat messages per model category), technical logs (error messages, performance data) and service usage (credit consumption, usage times, feature usage).

Retention period: 3 years for billing purposes

6.4 Credit system

Use of the service is billed via a credit system: 1 credit = 1 word processed during anonymization. Individual plans have 12 months of rollover (FIFO); team plans have no rollover.

7 Specifics of document anonymization

7.1 Customer documents

Important note: Original documents are NOT stored. Processing takes place exclusively in memory and is discarded after anonymization.

7.2 Hash-original pairs

To enable de-anonymization we store: the randomly generated placeholders (hash values), the corresponding original values (for controlled restoration) and job IDs (to link them to specific processing operations). The placeholders are random tokens and are not cryptographically derived from the original data.

Storage location: exclusively in Germany (Hetzner), isolated per customer workspace

Retention period: Selectable by the customer (24h to unlimited)

Access: Possible only for the customer who originally carried out the processing

7.3 The customer's duty to check and own responsibility

(1) The customer is obliged to check all anonymized documents independently before passing them on to LLM services or third parties. The service achieves a target detection rate of >95%; complete detection of all personal data cannot be technically guaranteed.

(2) The customer bears sole responsibility for ensuring that the anonymization is sufficient and complete for their use case.

(3) Manual review is particularly important in the case of unusual spellings, industry-specific terms, context-dependent identifiers or handwritten documents.

7.4 Processing on behalf of the customer

Where customer documents contain personal data of third parties, we act as a processor pursuant to Art. 28 GDPR. Details are governed by the separate data processing agreement (DPA), which takes effect automatically upon acceptance of the terms and conditions.

8 Chat function with AI models

8.1 How it works

The anymize service offers a chat function through which customers can communicate with various AI models (LLMs). When this function is used, data is transmitted to external LLM providers.

8.2 Anonymization before transmission

Where anonymization is enabled, personal data is anonymized BEFORE transmission to LLM providers. The LLM providers therefore do not receive any personal data.

8.3 LLM providers

When the chat function is used, (anonymized) data may be transmitted to the following providers:

ProviderModelsLocationSafeguards
OpenAI, Inc.GPTUSAEU SCCs, DPA
AnthropicClaude Opus, Sonnet, HaikuUSAEU SCCs, DPA
Google LLCGeminiUSAEU-US DPF
Mistral AIMistralFrance/EUGDPR

8.4 No storage by LLM providers

The (anonymized) data transmitted is not used by the LLM providers for training purposes.

9 Connectors

anymize offers the option of connecting external services to the service via connectors. Following explicit authorization by the user, anymize may access data from the connected services in order to perform the requested functions. The following sections describe the connectors currently available.

9.1 Google Workspace

How it works: The user connects their Google account via OAuth. anymize receives only the permissions the user explicitly grants.

Scope of data access: Depending on the permissions (scopes) granted, anymize may access the following services:

  • Gmail: Reading and searching emails, and sending emails
  • Google Drive: Listing and reading existing files, and creating and editing files
  • Google Docs: Reading, creating and editing documents
  • Google Sheets: Reading, creating and editing spreadsheets
  • Google Slides: Reading existing presentations
  • Google Calendar: Reading, and creating and editing events

Access takes place solely at the user's instigation. The user can revoke access at any time by disconnecting the Google integration in the settings of their anymize account, or by withdrawing the permission at https://myaccount.google.com/permissions.

Processing and pseudonymization: The retrieved data is first processed by an AI model operated internally by anymize. This produces a pseudonymized briefing for the downstream AI agent. Only this pseudonymized briefing is transmitted to external LLM providers; raw personal data from Google services is not passed on to external models. The safeguards described in section 8 apply to external LLM providers.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (a) GDPR (consent via OAuth authorization).

Storage: Only the intermediate results (outputs) of the processing are stored. These are deleted together with the associated artifacts as soon as the user deletes the corresponding chat. No further permanent storage of the retrieved Google data takes place.

Limited Use (Google API Services User Data Policy): The use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular, this information is not used to serve advertising, for credit scoring, for sale to data brokers, or to train generalized AI models, and is not read by humans, except with the user's explicit consent, for security or compliance purposes, to comply with legal obligations, or in aggregated, anonymized form for internal operational purposes.

9.2 Microsoft 365 add-in (Word, Excel & PowerPoint)

How it works: The add-in "anymize for Word, Excel & PowerPoint" is installed by the user in Word, Excel or PowerPoint. It appears in the Home ribbon and enables documents to be anonymized directly within the respective Office application. Authentication uses the user's existing anymize account.

Scope of data access: The add-in accesses only the content of the document currently open and actively selected by the user for processing (text in Word, spreadsheet data in Excel, presentation content in PowerPoint). No metadata from the Microsoft account, no other documents and no OneDrive or SharePoint content is retrieved.

Processing and pseudonymization: The selected document content is transmitted for processing to the anymize servers (Hetzner, Germany). The anymize anonymization model processes the content and returns the anonymized text to the add-in, which inserts it directly into the document. Only pseudonymized material is transmitted to external LLM providers; raw personal data from the document is not passed on to external models. The safeguards described in section 8 apply to external LLM providers.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (a) GDPR (consent through active use of the add-in).

Storage: The transmitted document content is not permanently stored on the anymize servers. So that the anonymization remains traceable and reversible, the add-in stores the mapping table (original value ↔ placeholder) and the chat history in the document itself — in Word and Excel as custom XML parts, in PowerPoint via the document settings; failing that, in the local storage of the device used. This data therefore remains in the file and is passed on when the file is shared. Using the placeholder overview in the add-in, the user can revert individual mappings or all of them at any time; this undoes the anonymization and removes the mapping table from the document accordingly. The anonymized output remains exclusively in the user's document.

Uninstallation: The user can remove the add-in at any time via the Office application (Windows: using the PowerShell uninstall script; Mac: by deleting the manifest file from the application folders; enterprise deployment: via the Microsoft 365 admin center). Uninstalling ends any further access to document content.

10 Data transfer, sub-processors and third countries

10.1 Website hosting (Vercel)

Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA

The website is hosted via Vercel. In doing so, Vercel processes technical connection data (IP address, browser information) on the basis of Art. 6 (1) (f) GDPR (legitimate interest in secure and stable website operation). Data transfers to the USA take place on the basis of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

10.2 Service hosting (Hetzner)

Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

All product data and customer data remain within the EU (German data centres).

10.3 Marketing and analytics services

The following services process data partly in the USA on the basis of adequacy decisions or standard contractual clauses:

Google Analytics & Tag Manager: EU-US Data Privacy Framework

PostHog: EU servers (Frankfurt/Ireland), no data transfer to the USA

LeadInfo: EU servers (Ireland/Frankfurt), Netherlands-based company, GDPR-compliant

HubSpot CRM: EU data centre (Frankfurt) with backup in Ireland, EU-US DPF and SCCs

10.4 Technical development and operations (anymize GmbH)

Provider: anymize GmbH, Schauenburger Str. 116, 24118 Kiel, Germany

Function: Sub-processor pursuant to Art. 28 GDPR – technical development, maintenance and operation of the anymize service on behalf of anymize GmbH

Data processed: Technical usage data, logs and system data in the course of operating the service

Legal basis: Data processing agreement pursuant to Art. 28 GDPR

10.5 Payment processing (Stripe)

Provider: Stripe Inc., South San Francisco, USA / Stripe Technology Europe Ltd., Dublin

Data processed: Payment data, billing address, email address, IP address, transaction history

Purpose: Payment processing, fraud prevention, compliance, invoicing

Retention period: In accordance with statutory retention periods (up to 10 years)

Stripe acts as an independent controller for fraud prevention and compliance. Payment data is transmitted and stored in encrypted form (PCI DSS Level 1). No credit card data is stored on our servers.

11 Data subject rights

You have the following rights:

11.1 Right of access (Art. 15 GDPR): You may request information about the personal data we process.

11.2 Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.

11.3 Right to erasure (Art. 17 GDPR): You may request the deletion of your data, provided no statutory retention obligations apply.

11.4 Right to restriction (Art. 18 GDPR): You may request the restriction of processing.

11.5 Data portability (Art. 20 GDPR): You may receive your data in a structured format.

11.6 Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.

11.7 Right to withdraw consent (Art. 7 (3) GDPR): Where processing is based on consent, you may withdraw it at any time with effect for the future.

11.8 Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)

Holstenstraße 98, 24103 Kiel, Germany

Email: mail@datenschutzzentrum.de

Website: https://www.datenschutzzentrum.de

12 Data security

12.1 Technical measures

  • Encryption of data transmission (TLS 1.3)
  • Data processing and storage exclusively in Germany (Hetzner)
  • Regular security updates
  • Access control and logging
  • Redundant systems and backups

12.2 Organizational measures

  • Staff training
  • Access authorization concept
  • Data protection impact assessment
  • Incident response procedures
  • Regular review of security measures

13 Automated decision-making

13.1 AI system for anonymization

Our service uses a specialized AI system for the automatic detection of personal data. This serves data protection purposes only and involves no profiling.

13.2 Transparency

The AI system works on the basis of: pattern recognition for typical data formats, context analysis to identify personal references, and statistical evaluations without personal reference.

13.3 No profiling

No automated decision-making within the meaning of Art. 22 GDPR takes place that produces legal effects or similarly significantly affects you.

14 Currency and changes

This privacy policy is dated 23 June 2025. Further development of our website or changes in legal requirements may make it necessary to amend this privacy policy. We will inform you of material changes by email to the address stored in your user account.

The current version is available on our website at https://anymize.ai/datenschutz.

Version: 1.5 | As of: 23 June 2025