Privacy
Policy

for the anymize service

§ 1 Controller and data protection officer

1.1 Controller

anymize GmbH

Schauenburgerstr. 116

24118 Kiel, Germany

Email: info@anymize.ai

Phone: +49 431 729 85 2320

Commercial register: AG Kiel HRB 29239 KI

VAT ID: DE461722394

Managing directors: Nikolai Raitschew und Raitschin Raitschew

1.2 Data protection officer

We have appointed a data protection officer:

Manuel Langeheinecke (digitalNORD GmbH Kiel, Schleswig-Holstein)

You can reach them as follows: by post at our company address marked “Data protection officer” or by email at datenschutz@anymize.ai

Governing language

anymize GmbH is a limited liability company incorporated under German law, based in Kiel, Germany. This privacy policy is governed by German law and by the GDPR.

This English version is provided for ease of understanding only. In the event of any discrepancy, the German version alone is authoritative and can be found at https://anymize.ai/datenschutz.

2 Principles of data processing

2.1 Scope of processing

We process our users' personal data only to the extent necessary to provide the anymize service, or where a legal basis exists.

2.2 Legal bases

Personal data is processed on the basis of the following legal grounds under the GDPR:

  • Art. 6 (1) (b) GDPR: Performance of a contract
  • Art. 6 (1) (c) GDPR: Legal obligation
  • Art. 6 (1) (f) GDPR: Legitimate interests
  • Art. 6 (1) (a) GDPR: Consent (for optional additional services)

3 Data processing when visiting the website

3.1 Log files

Each time our website is accessed, information is automatically stored in server log files:

  • IP address of the requesting computer
  • Date and time of access
  • Name and URL of the file retrieved
  • Website from which the access originates (referrer URL)
  • Browser used and, where applicable, the operating system

Legal basis: Art. 6 (1) (f) GDPR (legitimate interests: system security and stability)

Retention period: 30 days, then automatic deletion

3.2 Cookies and tracking technologies

Technically necessary cookies: Session cookies for website functionality, cookie consent status, login status and security features. Legal basis: Art. 6 (1) (f) GDPR. Retention period: end of session or 30 days.

Language preference cookie (anymize_lang): Stores the language you selected or that was detected automatically (German, English or Norwegian), so that future visits take you straight to the right language version. Legal basis: Art. 6 (1) (f) GDPR in conjunction with Sec. 25 (2) no. 2 TDDDG (technically necessary, no consent required). Retention period: 12 months.

Analytics cookies: Google Analytics for website analysis, PostHog for user behaviour and product analytics. Legal basis: Art. 6 (1) (a) GDPR (consent). Retention period: up to 26 months.

Marketing cookies: Meta Pixel (Facebook) for advertising purposes, LinkedIn Pixel for B2B marketing, Microsoft UET tag for conversion tracking. Legal basis: Art. 6 (1) (a) GDPR. Retention period: up to 2 years.

B2B tracking (cookieless): LeadInfo for company identification. Legal basis: Art. 6 (1) (f) GDPR. Note: no cookies, no personal data relating to individuals.

3.3 Locally stored functional data (localStorage)

To provide necessary functions we store one value exclusively in your device's browser storage (localStorage). This data does not leave your device and is not transmitted to our servers.

anymize_partner: Slug and display name of the partner through whose referral link you entered our site, plus a timestamp. Purpose: consistent display of the partner conditions that apply to you as you navigate to other pages. Retention period: 30 days since the last partner visit, then automatic deletion.

Legal basis: Art. 6 (1) (f) GDPR in conjunction with Sec. 25 (2) no. 2 TDDDG (strictly necessary storage, no consent required, as it serves the function only and has no personal reference).

Objection: Values can be deleted at any time via your browser's developer tools (Application or Storage → Local Storage → anymize.ai).

3.4 Google Tag Manager

We use Google Tag Manager to manage website tags.

Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Purpose: Central management of tracking codes

Data transfer: EU-US Data Privacy Framework

Objection: Browser settings or opt-out available

3.5 Cookiebot (consent management)

We use Cookiebot to obtain and manage consent for non-technical cookies.

Provider: Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark

Data processed: Consent ID, consent status, timestamp, IP address (truncated), browser data

Purpose: Documentation and management of consent given or withdrawn, in accordance with the GDPR and the TDDDG

Legal basis: Art. 6 (1) (c) GDPR (legal obligation to document consent)

Retention period: Up to 12 months

4 Marketing and analytics tools

4.1 Google Analytics

Data processed: IP address (anonymized), page views, time on page, device type

Purpose: Website optimization, understanding user behaviour

Retention period: 26 months

Opt-out: https://tools.google.com/dlpage/gaoptout

4.2 PostHog Analytics

Provider: PostHog Inc., San Francisco, CA, USA

Hosting: Exclusively on EU servers (Frankfurt/Ireland), no data transfer to the USA

Data processed: User interactions, feature usage, session replays (anonymized)

Retention period: 12 months

Data protection: Fully GDPR-compliant, EU servers, ISO 27001 certified

4.3 Meta Pixel (Facebook)

Provider: Meta Platforms Inc., Menlo Park, CA, USA

Data processed: Page views, conversion events, hashed email addresses

Purpose: Ad optimization, custom audiences, lookalike audiences

Retention period: 180 days

4.4 LinkedIn Insight Tag

Provider: LinkedIn Corporation, Mountain View, CA, USA

Data processed: Professional demographic data, page interactions

Purpose: B2B advertising, website demographic insights

4.5 LeadInfo

Provider: Leadinfo B.V., The Hague, Netherlands

Hosting: Exclusively within the EU (Ireland/Frankfurt)

Data processed: IP addresses of companies (no personal data relating to individuals), page views, visit duration, referrer URL

How it works: Cookieless tracking, matching IP addresses to companies via public business databases

LeadInfo identifies companies only, never individuals. 100% GDPR-compliant, ISO 27001 certified, EU hosting.

4.6 Microsoft Advertising (UET tag)

Provider: Microsoft Corporation, Redmond, WA, USA / Microsoft Ireland Operations Limited, Dublin

Data processed: IP address, cookie ID, page views, conversion events, device information

Purpose: Conversion tracking, campaign optimization, remarketing

Retention period: Up to 390 days

4.7 HubSpot CRM

Provider: HubSpot, Inc., Cambridge, MA, USA / HubSpot Ireland Limited, Dublin

Hosting: EU data centre in Frankfurt, Germany, with backup in Ireland

Data processed: Contact details, email address, communication history, lead scoring, interactions

Purpose: CRM, lead management, customer communication, marketing automation

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) / Art. 6 (1) (f) GDPR (legitimate interests)

5 Cookie settings and objection

5.1 Cookie consent banner

On your first visit to our website a cookie banner appears, through which you can give your consent for non-technical cookies.

5.2 Objection and opt-out options

Google Analytics: Browser add-on or opt-out cookie via our website

Meta Pixel: Facebook ad settings or Your Online Choices (http://www.youronlinechoices.com/)

LinkedIn Insight Tag: LinkedIn privacy settings (https://www.linkedin.com/psettings/)

PostHog: Opt-out via our cookie settings. The browser Do-Not-Track setting is respected.

LeadInfo: Cookieless tracking, no opt-out required. Identifies companies only.

Microsoft Advertising: Opt-out via Microsoft privacy settings or the cookie banner

5.3 Browser settings

You can disable cookies in your browser settings. Please note that this may limit the functionality of our website.

6 Data processing on registration and use

6.1 Account data

On registration we process:

Master data: Company name, contact person, email address

Technical data: API keys, usage statistics

Account management: Login credentials, account status, chosen plan

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)

Retention period: Until termination + 10 years (commercial law retention periods)

6.2 Billing and payment data

To process payments we process, in cooperation with Stripe: invoicing data (company name, billing address, VAT ID), payment information processed via Stripe, transaction history and billing-relevant data (credit consumption, plan changes, terminations).

Retention period: 10 years for billing purposes and commercial law retention periods

6.3 Usage data

To provide the service we process: processing statistics (number of credits processed, API calls), chat usage (number of chat messages per model category), technical logs (error messages, performance data) and service usage (credit consumption, usage times, feature usage).

Retention period: 3 years for billing purposes

6.4 Credit system

Use of the service is billed via a credit system: 1 credit = 1 word processed during anonymization. Individual plans have 12 months of rollover (FIFO); team plans have no rollover.

7 Specifics of document anonymization

7.1 Customer documents

Important note: Uploaded original documents are not stored in their original form after content extraction; extraction takes place in memory. The extracted document content and chat histories are stored in encrypted form (AES-256, workspace-specific key) on servers in Germany so that they can be reused within the workspace, and can be deleted by the customer at any time; at the latest, they are removed when the account is deleted.

7.2 Hash-original pairs

To enable de-anonymization we store: the randomly generated placeholders (hash values), the corresponding original values (for controlled restoration) and job IDs (to link them to specific processing operations). The placeholders are random tokens and are not cryptographically derived from the original data.

Storage location: in Germany (Hetzner), isolated per customer workspace; encrypted backups on separate infrastructure in Germany/France (OVH)

Retention period: Selectable by the customer: immediate deletion after processing, 24 hours, 7 days (default), 30 days or unlimited

Access: Possible only for the customer who originally carried out the processing

7.3 The customer's duty to check and own responsibility

(1) The customer is obliged to check all anonymized documents independently before passing them on to LLM services or third parties. The service achieves a target detection rate of >95%; complete detection of all personal data cannot be technically guaranteed.

(2) The customer decides on their own responsibility whether the anonymization is sufficient for their use case. Before data is passed on, the service shows which values were replaced; team administrators can make anonymization and an active approval before every send mandatory for all users.

(3) Manual review is particularly important in the case of unusual spellings, industry-specific terms, context-dependent identifiers or handwritten documents.

7.4 Processing on behalf of the customer

Where customer documents contain personal data of third parties, we act as a processor pursuant to Art. 28 GDPR. Details are governed by the separate data processing agreement (DPA), which takes effect automatically upon acceptance of the terms and conditions.

8 Chat function with AI models

8.1 How it works

The anymize service offers a chat function through which customers can communicate with various AI models (LLMs). When this function is used, data is transmitted to external LLM providers.

8.2 Pseudonymization before transmission

Where anonymization is enabled, personal data is replaced by placeholders before transmission to LLM providers. Legally, this constitutes pseudonymization pursuant to Art. 4 (5) GDPR: the mapping between placeholders and original values remains encrypted with anymize in Germany and is not transmitted. Without this mapping, the LLM provider cannot attribute the content to any person. We nevertheless treat the transmission as processing of personal data and contractually bind the LLM providers as sub-processors pursuant to Art. 28 GDPR (Annex 2 of the data processing agreement). If a user deactivates anonymization for a request, the content of that request is transmitted in plain text; team administrators can make anonymization mandatory for all users.

8.3 LLM providers

When the chat function is used, pseudonymized content may be transmitted to the following providers. They are only involved if the user selects the respective model; the AI gateway is involved for EU-hosted models:

ProviderModelsLocationSafeguards
OpenAIGPTUSADPA pursuant to Art. 28 GDPR, EU standard contractual clauses
AnthropicClaude Opus, Sonnet, HaikuUSADPA pursuant to Art. 28 GDPR, EU standard contractual clauses, EU-US Data Privacy Framework
Google LLCGeminiUSADPA pursuant to Art. 28 GDPR, EU standard contractual clauses, EU-US Data Privacy Framework
Mistral AIMistralFrance/EUDPA pursuant to Art. 28 GDPR, processing within the EU
Perplexity AIPerplexity (language models with web search); for web search only the search queryUSADPA pursuant to Art. 28 GDPR, EU standard contractual clauses, EU-US Data Privacy Framework
xAI (SpaceXAI LLC)GrokUSADPA pursuant to Art. 28 GDPR, EU standard contractual clauses
Requesty Ltd (AI gateway)No model of its own; forwards requests to EU-hosted models (GPT, Claude, Gemini including image generation, GLM). Inference is carried out by Requesty's sub-processors in EU regions (Microsoft Azure, Amazon Web Services, Google Cloud, Nebius)United Kingdom; EU endpoint Frankfurt am MainDPA pursuant to Art. 28 GDPR, zero data retention, European Commission adequacy decision for the United Kingdom (Art. 45 GDPR)

8.4 Protection when transmitting to LLM providers

anymize uses only the providers' business interfaces. Under the terms applicable to these, the providers do not use the transmitted content to train their models and store it only for a limited period. Transfers to the USA are based on EU standard contractual clauses and, where the provider is certified, on the EU-US Data Privacy Framework. EU-hosted models are connected through the AI gateway of Requesty Ltd (London); inference runs on cloud platforms in EU regions that Requesty uses as its sub-processors. International models processed in the USA, web search and the models of Mistral AI (France) are connected directly to the provider's interface. The gateway is connected exclusively via its EU endpoint in Frankfurt am Main, forwards the requests to the selected model and does not store their content; Requesty is covered by the European Commission's adequacy decision for the United Kingdom (Art. 45 GDPR). Retention periods and safeguards per provider are listed in Annex 2 of the data processing agreement and at https://anymize.ai/legal/unterauftragsverarbeiter. When users paste a YouTube link or a public web address, anymize retrieves the transcript or page content through the Supadata service (provider based in the USA); only the address is transmitted, no content from documents or conversations.

9 Connectors

anymize offers the option of connecting external services to the service via connectors. Following explicit authorization by the user, anymize may access data from the connected services in order to perform the requested functions. The following sections describe the connectors currently available.

9.1 Google Workspace

How it works: The user connects their Google account via OAuth. anymize receives only the permissions the user explicitly grants.

Scope of data access: Depending on the permissions (scopes) granted, anymize may access the following services:

  • Gmail: Reading and searching emails, and sending emails
  • Google Drive: Listing and reading existing files, and creating and editing files
  • Google Docs: Reading, creating and editing documents
  • Google Sheets: Reading, creating and editing spreadsheets
  • Google Slides: Reading existing presentations
  • Google Calendar: Reading, and creating and editing events

Access takes place solely at the user's instigation. The user can revoke access at any time by disconnecting the Google integration in the settings of their anymize account, or by withdrawing the permission at https://myaccount.google.com/permissions.

Processing and pseudonymization: The retrieved data is first processed by an AI model operated internally by anymize. This produces a pseudonymized briefing for the downstream AI agent. Only this pseudonymized briefing is transmitted to external LLM providers; raw personal data from Google services is not passed on to external models. The safeguards described in section 8 apply to external LLM providers.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (a) GDPR (consent via OAuth authorization).

Storage: Only the intermediate results (outputs) of the processing are stored. These are deleted together with the associated artifacts as soon as the user deletes the corresponding chat. No further permanent storage of the retrieved Google data takes place.

Limited Use (Google API Services User Data Policy): The use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular, this information is not used to serve advertising, for credit scoring, for sale to data brokers, or to train generalized AI models, and is not read by humans, except with the user's explicit consent, for security or compliance purposes, to comply with legal obligations, or in aggregated, anonymized form for internal operational purposes.

9.2 Microsoft 365 add-in (Word, Excel & PowerPoint)

How it works: The add-in "anymize for Word, Excel & PowerPoint" is installed by the user in Word, Excel or PowerPoint. It appears in the Home ribbon and enables documents to be anonymized directly within the respective Office application. Authentication uses the user's existing anymize account.

Scope of data access: The add-in accesses only the content of the document currently open and actively selected by the user for processing (text in Word, spreadsheet data in Excel, presentation content in PowerPoint). No metadata from the Microsoft account, no other documents and no OneDrive or SharePoint content is retrieved.

Processing and pseudonymization: The selected document content is transmitted for processing to the anymize servers (Hetzner, Germany). The anymize anonymization model processes the content and returns the anonymized text to the add-in, which inserts it directly into the document. Only pseudonymized material is transmitted to external LLM providers; raw personal data from the document is not passed on to external models. The safeguards described in section 8 apply to external LLM providers.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (a) GDPR (consent through active use of the add-in).

Storage: The transmitted document content is not permanently stored on the anymize servers. So that the anonymization remains traceable and reversible, the add-in stores the mapping table (original value ↔ placeholder) and the chat history in the document itself — in Word and Excel as custom XML parts, in PowerPoint via the document settings; failing that, in the local storage of the device used. This data therefore remains in the file and is passed on when the file is shared. Using the placeholder overview in the add-in, the user can revert individual mappings or all of them at any time; this undoes the anonymization and removes the mapping table from the document accordingly. The anonymized output remains exclusively in the user's document.

Uninstallation: The user can remove the add-in at any time via the Office application (Windows: using the PowerShell uninstall script; Mac: by deleting the manifest file from the application folders; enterprise deployment: via the Microsoft 365 admin center). Uninstalling ends any further access to document content.

10 Data transfer, sub-processors and third countries

10.1 Website hosting (Vercel)

Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA

The website is hosted via Vercel. In doing so, Vercel processes technical connection data (IP address, browser information) on the basis of Art. 6 (1) (f) GDPR (legitimate interest in secure and stable website operation). Data transfers to the USA take place on the basis of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

10.2 Service hosting (Hetzner)

Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

The platform and all customer data are hosted in German data centres; encrypted backups are kept on separate infrastructure in Germany and France (see 10.6).

10.3 Marketing and analytics services

The following services process data partly in the USA on the basis of adequacy decisions or standard contractual clauses:

Google Analytics & Tag Manager: EU-US Data Privacy Framework

PostHog: EU servers (Frankfurt/Ireland), no data transfer to the USA

LeadInfo: EU servers (Ireland/Frankfurt), Netherlands-based company, GDPR-compliant

HubSpot CRM: EU data centre (Frankfurt) with backup in Ireland, EU-US DPF and SCCs

10.4 Account, team and billing platform (GRVITY GmbH, Florentin.ai)

Provider: GRVITY GmbH, Schauenburgerstr. 116, 24118 Kiel, Germany (affiliated with anymize GmbH under company law, operator of the Florentin.ai platform)

Function: Sub-processor pursuant to Art. 28 GDPR: management of user accounts, teams, billing and API keys (SaaS backend). No access to document content or hash-original pairs.

Data processed: Account and master data, team and role assignments, billing data, usage statistics, API keys (encrypted)

Legal basis: Intra-group data processing agreement pursuant to Art. 28 GDPR; obligation under Section 203 (4) German Criminal Code (StGB)

10.5 Payment processing (Stripe)

Provider: Stripe Inc., South San Francisco, USA / Stripe Technology Europe Ltd., Dublin

Data processed: Payment data, billing address, email address, IP address, transaction history

Purpose: Payment processing, fraud prevention, compliance, invoicing

Retention period: In accordance with statutory retention periods (up to 10 years)

Stripe acts as an independent controller for fraud prevention and compliance. Payment data is transmitted and stored in encrypted form (PCI DSS Level 1). No credit card data is stored on our servers.

10.6 Server and backup infrastructure (OVH)

Provider: OVH GmbH, St. Johanner Str. 41-43, 66111 Saarbrücken, Germany

Function: Sub-processor pursuant to Art. 28 GDPR: server infrastructure and data storage, in particular separate infrastructure for encrypted backups of the platform

Processing location: Germany/France (EU)

Safeguards: Data processing agreement pursuant to Art. 28 GDPR, ISO/IEC 27001, obligation under Section 203 (4) StGB

10.7 AI model providers

The LLM providers involved when the chat function is used, their locations and safeguards are described in Sections 8.3 and 8.4. They are usage-dependent sub-processors and are only involved if the user selects the respective model. The AI gateway of Requesty Ltd, through which the EU-hosted models are connected, is described there as well. When anymize's own models are used, no external provider is involved.

11 Data subject rights

You have the following rights:

11.1 Right of access (Art. 15 GDPR): You may request information about the personal data we process.

11.2 Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.

11.3 Right to erasure (Art. 17 GDPR): You may request the deletion of your data, provided no statutory retention obligations apply.

11.4 Right to restriction (Art. 18 GDPR): You may request the restriction of processing.

11.5 Data portability (Art. 20 GDPR): You may receive your data in a structured format.

11.6 Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.

11.7 Right to withdraw consent (Art. 7 (3) GDPR): Where processing is based on consent, you may withdraw it at any time with effect for the future.

11.8 Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)

Holstenstraße 98, 24103 Kiel, Germany

Email: mail@datenschutzzentrum.de

Website: https://www.datenschutzzentrum.de

12 Data security

12.1 Technical measures

  • Encryption of data transmission (TLS 1.3)
  • Data processing and storage in Germany (Hetzner); encrypted backups in Germany/France (OVH)
  • Regular security updates
  • Access control and logging
  • Redundant systems and backups

12.2 Organizational measures

  • Staff training
  • Access authorization concept
  • Risk analysis and security concept
  • Incident response procedures
  • Regular review of security measures

13 Automated decision-making

13.1 AI system for anonymization

Our service uses a specialized AI system for the automatic detection of personal data. This serves data protection purposes only and involves no profiling.

13.2 Transparency

The AI system works on the basis of: pattern recognition for typical data formats, context analysis to identify personal references, and statistical evaluations without personal reference.

13.3 No profiling

No automated decision-making within the meaning of Art. 22 GDPR takes place that produces legal effects or similarly significantly affects you.

14 Currency and changes

This privacy policy is dated 24 September 2026 (version 1.6). Further development of our website or changes in legal requirements may make it necessary to amend this privacy policy. We will inform you of material changes by email to the address stored in your user account.

The current version is available on our website at https://anymize.ai/datenschutz.

15 Change history

VersionAs ofChanges
1.624 September 2026Storage of extracted document content and chat histories described transparently (7.1, 7.2); duty to check without blanket sole responsibility (7.3); transmission to LLM providers classified as pseudonymization, LLM providers as sub-processors, plain-text mode disclosed (8.2 to 8.4); GRVITY GmbH (Florentin.ai) and OVH added as sub-processors, AI gateway Requesty Ltd added as sub-processor (8.3, 8.4, 10.7), outdated entry on anymize GmbH replaced (10.4, 10.6, 10.7); details on backup locations and organizational measures corrected (12).
1.523 June 2025 (date not updated afterwards)Previous version; content updates up to September 2026 (data protection officer, HubSpot CRM, connectors, Microsoft 365 add-in) were published without adjusting the date.

Version: 1.6 | As of: 24 September 2026