Privacy
Policy
for the anymize service
§ 1 Controller and data protection officer
1.1 Controller
anymize GmbH
Schauenburgerstr. 116
24118 Kiel, Germany
Email: info@anymize.ai
Phone: +49 431 729 85 2320
Commercial register: AG Kiel HRB 29239 KI
VAT ID: DE461722394
Managing directors: Nikolai Raitschew und Raitschin Raitschew
1.2 Data protection officer
We have appointed a data protection officer:
Manuel Langeheinecke (digitalNORD GmbH Kiel, Schleswig-Holstein)
You can reach them as follows: by post at our company address marked “Data protection officer” or by email at datenschutz@anymize.ai
Governing language
anymize GmbH is a limited liability company incorporated under German law, based in Kiel, Germany. This privacy policy is governed by German law and by the GDPR.
This English version is provided for ease of understanding only. In the event of any discrepancy, the German version alone is authoritative and can be found at https://anymize.ai/datenschutz.
2 Principles of data processing
2.1 Scope of processing
We process our users' personal data only to the extent necessary to provide the anymize service, or where a legal basis exists.
2.2 Legal bases
Personal data is processed on the basis of the following legal grounds under the GDPR:
- Art. 6 (1) (b) GDPR: Performance of a contract
- Art. 6 (1) (c) GDPR: Legal obligation
- Art. 6 (1) (f) GDPR: Legitimate interests
- Art. 6 (1) (a) GDPR: Consent (for optional additional services)
3 Data processing when visiting the website
3.1 Log files
Each time our website is accessed, information is automatically stored in server log files:
- IP address of the requesting computer
- Date and time of access
- Name and URL of the file retrieved
- Website from which the access originates (referrer URL)
- Browser used and, where applicable, the operating system
Legal basis: Art. 6 (1) (f) GDPR (legitimate interests: system security and stability)
Retention period: 30 days, then automatic deletion
3.2 Cookies and tracking technologies
Technically necessary cookies: Session cookies for website functionality, cookie consent status, login status and security features. Legal basis: Art. 6 (1) (f) GDPR. Retention period: end of session or 30 days.
Language preference cookie (anymize_lang): Stores the language you selected or that was detected automatically (German, English or Norwegian), so that future visits take you straight to the right language version. Legal basis: Art. 6 (1) (f) GDPR in conjunction with Sec. 25 (2) no. 2 TDDDG (technically necessary, no consent required). Retention period: 12 months.
Analytics cookies: Google Analytics for website analysis, PostHog for user behaviour and product analytics. Legal basis: Art. 6 (1) (a) GDPR (consent). Retention period: up to 26 months.
Marketing cookies: Meta Pixel (Facebook) for advertising purposes, LinkedIn Pixel for B2B marketing, Microsoft UET tag for conversion tracking. Legal basis: Art. 6 (1) (a) GDPR. Retention period: up to 2 years.
B2B tracking (cookieless): LeadInfo for company identification. Legal basis: Art. 6 (1) (f) GDPR. Note: no cookies, no personal data relating to individuals.
3.3 Locally stored functional data (localStorage)
To provide necessary functions we store one value exclusively in your device's browser storage (localStorage). This data does not leave your device and is not transmitted to our servers.
anymize_partner: Slug and display name of the partner through whose referral link you entered our site, plus a timestamp. Purpose: consistent display of the partner conditions that apply to you as you navigate to other pages. Retention period: 30 days since the last partner visit, then automatic deletion.
Legal basis: Art. 6 (1) (f) GDPR in conjunction with Sec. 25 (2) no. 2 TDDDG (strictly necessary storage, no consent required, as it serves the function only and has no personal reference).
Objection: Values can be deleted at any time via your browser's developer tools (Application or Storage → Local Storage → anymize.ai).
3.4 Google Tag Manager
We use Google Tag Manager to manage website tags.
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Purpose: Central management of tracking codes
Data transfer: EU-US Data Privacy Framework
Objection: Browser settings or opt-out available
3.5 Cookiebot (consent management)
We use Cookiebot to obtain and manage consent for non-technical cookies.
Provider: Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark
Data processed: Consent ID, consent status, timestamp, IP address (truncated), browser data
Purpose: Documentation and management of consent given or withdrawn, in accordance with the GDPR and the TDDDG
Legal basis: Art. 6 (1) (c) GDPR (legal obligation to document consent)
Retention period: Up to 12 months
4 Marketing and analytics tools
4.1 Google Analytics
Data processed: IP address (anonymized), page views, time on page, device type
Purpose: Website optimization, understanding user behaviour
Retention period: 26 months
Opt-out: https://tools.google.com/dlpage/gaoptout
4.2 PostHog Analytics
Provider: PostHog Inc., San Francisco, CA, USA
Hosting: Exclusively on EU servers (Frankfurt/Ireland), no data transfer to the USA
Data processed: User interactions, feature usage, session replays (anonymized)
Retention period: 12 months
Data protection: Fully GDPR-compliant, EU servers, ISO 27001 certified
4.3 Meta Pixel (Facebook)
Provider: Meta Platforms Inc., Menlo Park, CA, USA
Data processed: Page views, conversion events, hashed email addresses
Purpose: Ad optimization, custom audiences, lookalike audiences
Retention period: 180 days
4.4 LinkedIn Insight Tag
Provider: LinkedIn Corporation, Mountain View, CA, USA
Data processed: Professional demographic data, page interactions
Purpose: B2B advertising, website demographic insights
4.5 LeadInfo
Provider: Leadinfo B.V., The Hague, Netherlands
Hosting: Exclusively within the EU (Ireland/Frankfurt)
Data processed: IP addresses of companies (no personal data relating to individuals), page views, visit duration, referrer URL
How it works: Cookieless tracking, matching IP addresses to companies via public business databases
LeadInfo identifies companies only, never individuals. 100% GDPR-compliant, ISO 27001 certified, EU hosting.
4.6 Microsoft Advertising (UET tag)
Provider: Microsoft Corporation, Redmond, WA, USA / Microsoft Ireland Operations Limited, Dublin
Data processed: IP address, cookie ID, page views, conversion events, device information
Purpose: Conversion tracking, campaign optimization, remarketing
Retention period: Up to 390 days
4.7 HubSpot CRM
Provider: HubSpot, Inc., Cambridge, MA, USA / HubSpot Ireland Limited, Dublin
Hosting: EU data centre in Frankfurt, Germany, with backup in Ireland
Data processed: Contact details, email address, communication history, lead scoring, interactions
Purpose: CRM, lead management, customer communication, marketing automation
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) / Art. 6 (1) (f) GDPR (legitimate interests)
5 Cookie settings and objection
5.1 Cookie consent banner
On your first visit to our website a cookie banner appears, through which you can give your consent for non-technical cookies.
5.2 Objection and opt-out options
Google Analytics: Browser add-on or opt-out cookie via our website
Meta Pixel: Facebook ad settings or Your Online Choices (http://www.youronlinechoices.com/)
LinkedIn Insight Tag: LinkedIn privacy settings (https://www.linkedin.com/psettings/)
PostHog: Opt-out via our cookie settings. The browser Do-Not-Track setting is respected.
LeadInfo: Cookieless tracking, no opt-out required. Identifies companies only.
Microsoft Advertising: Opt-out via Microsoft privacy settings or the cookie banner
5.3 Browser settings
You can disable cookies in your browser settings. Please note that this may limit the functionality of our website.
6 Data processing on registration and use
6.1 Account data
On registration we process:
Master data: Company name, contact person, email address
Technical data: API keys, usage statistics
Account management: Login credentials, account status, chosen plan
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)
Retention period: Until termination + 10 years (commercial law retention periods)
6.2 Billing and payment data
To process payments we process, in cooperation with Stripe: invoicing data (company name, billing address, VAT ID), payment information processed via Stripe, transaction history and billing-relevant data (credit consumption, plan changes, terminations).
Retention period: 10 years for billing purposes and commercial law retention periods
6.3 Usage data
To provide the service we process: processing statistics (number of credits processed, API calls), chat usage (number of chat messages per model category), technical logs (error messages, performance data) and service usage (credit consumption, usage times, feature usage).
Retention period: 3 years for billing purposes
6.4 Credit system
Use of the service is billed via a credit system: 1 credit = 1 word processed during anonymization. Individual plans have 12 months of rollover (FIFO); team plans have no rollover.
7 Specifics of document anonymization
7.1 Customer documents
Important note: Original documents are NOT stored. Processing takes place exclusively in memory and is discarded after anonymization.
7.2 Hash-original pairs
To enable de-anonymization we store: the randomly generated placeholders (hash values), the corresponding original values (for controlled restoration) and job IDs (to link them to specific processing operations). The placeholders are random tokens and are not cryptographically derived from the original data.
Storage location: exclusively in Germany (Hetzner), isolated per customer workspace
Retention period: Selectable by the customer (24h to unlimited)
Access: Possible only for the customer who originally carried out the processing
7.3 The customer's duty to check and own responsibility
(1) The customer is obliged to check all anonymized documents independently before passing them on to LLM services or third parties. The service achieves a target detection rate of >95%; complete detection of all personal data cannot be technically guaranteed.
(2) The customer bears sole responsibility for ensuring that the anonymization is sufficient and complete for their use case.
(3) Manual review is particularly important in the case of unusual spellings, industry-specific terms, context-dependent identifiers or handwritten documents.
7.4 Processing on behalf of the customer
Where customer documents contain personal data of third parties, we act as a processor pursuant to Art. 28 GDPR. Details are governed by the separate data processing agreement (DPA), which takes effect automatically upon acceptance of the terms and conditions.
8 Chat function with AI models
8.1 How it works
The anymize service offers a chat function through which customers can communicate with various AI models (LLMs). When this function is used, data is transmitted to external LLM providers.
8.2 Anonymization before transmission
Where anonymization is enabled, personal data is anonymized BEFORE transmission to LLM providers. The LLM providers therefore do not receive any personal data.
8.3 LLM providers
When the chat function is used, (anonymized) data may be transmitted to the following providers:
| Provider | Models | Location | Safeguards |
|---|---|---|---|
| OpenAI, Inc. | GPT | USA | EU SCCs, DPA |
| Anthropic | Claude Opus, Sonnet, Haiku | USA | EU SCCs, DPA |
| Google LLC | Gemini | USA | EU-US DPF |
| Mistral AI | Mistral | France/EU | GDPR |
8.4 No storage by LLM providers
The (anonymized) data transmitted is not used by the LLM providers for training purposes.
9 Connectors
anymize offers the option of connecting external services to the service via connectors. Following explicit authorization by the user, anymize may access data from the connected services in order to perform the requested functions. The following sections describe the connectors currently available.
9.1 Google Workspace
How it works: The user connects their Google account via OAuth. anymize receives only the permissions the user explicitly grants.
Scope of data access: Depending on the permissions (scopes) granted, anymize may access the following services:
- Gmail: Reading and searching emails, and sending emails
- Google Drive: Listing and reading existing files, and creating and editing files
- Google Docs: Reading, creating and editing documents
- Google Sheets: Reading, creating and editing spreadsheets
- Google Slides: Reading existing presentations
- Google Calendar: Reading, and creating and editing events
Access takes place solely at the user's instigation. The user can revoke access at any time by disconnecting the Google integration in the settings of their anymize account, or by withdrawing the permission at https://myaccount.google.com/permissions.
Processing and pseudonymization: The retrieved data is first processed by an AI model operated internally by anymize. This produces a pseudonymized briefing for the downstream AI agent. Only this pseudonymized briefing is transmitted to external LLM providers; raw personal data from Google services is not passed on to external models. The safeguards described in section 8 apply to external LLM providers.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (a) GDPR (consent via OAuth authorization).
Storage: Only the intermediate results (outputs) of the processing are stored. These are deleted together with the associated artifacts as soon as the user deletes the corresponding chat. No further permanent storage of the retrieved Google data takes place.
Limited Use (Google API Services User Data Policy): The use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular, this information is not used to serve advertising, for credit scoring, for sale to data brokers, or to train generalized AI models, and is not read by humans, except with the user's explicit consent, for security or compliance purposes, to comply with legal obligations, or in aggregated, anonymized form for internal operational purposes.
9.2 Microsoft 365 add-in (Word, Excel & PowerPoint)
How it works: The add-in "anymize for Word, Excel & PowerPoint" is installed by the user in Word, Excel or PowerPoint. It appears in the Home ribbon and enables documents to be anonymized directly within the respective Office application. Authentication uses the user's existing anymize account.
Scope of data access: The add-in accesses only the content of the document currently open and actively selected by the user for processing (text in Word, spreadsheet data in Excel, presentation content in PowerPoint). No metadata from the Microsoft account, no other documents and no OneDrive or SharePoint content is retrieved.
Processing and pseudonymization: The selected document content is transmitted for processing to the anymize servers (Hetzner, Germany). The anymize anonymization model processes the content and returns the anonymized text to the add-in, which inserts it directly into the document. Only pseudonymized material is transmitted to external LLM providers; raw personal data from the document is not passed on to external models. The safeguards described in section 8 apply to external LLM providers.
Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (a) GDPR (consent through active use of the add-in).
Storage: The transmitted document content is not permanently stored on the anymize servers. So that the anonymization remains traceable and reversible, the add-in stores the mapping table (original value ↔ placeholder) and the chat history in the document itself — in Word and Excel as custom XML parts, in PowerPoint via the document settings; failing that, in the local storage of the device used. This data therefore remains in the file and is passed on when the file is shared. Using the placeholder overview in the add-in, the user can revert individual mappings or all of them at any time; this undoes the anonymization and removes the mapping table from the document accordingly. The anonymized output remains exclusively in the user's document.
Uninstallation: The user can remove the add-in at any time via the Office application (Windows: using the PowerShell uninstall script; Mac: by deleting the manifest file from the application folders; enterprise deployment: via the Microsoft 365 admin center). Uninstalling ends any further access to document content.
10 Data transfer, sub-processors and third countries
10.1 Website hosting (Vercel)
Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA
The website is hosted via Vercel. In doing so, Vercel processes technical connection data (IP address, browser information) on the basis of Art. 6 (1) (f) GDPR (legitimate interest in secure and stable website operation). Data transfers to the USA take place on the basis of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.
10.2 Service hosting (Hetzner)
Provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
All product data and customer data remain within the EU (German data centres).
10.3 Marketing and analytics services
The following services process data partly in the USA on the basis of adequacy decisions or standard contractual clauses:
Google Analytics & Tag Manager: EU-US Data Privacy Framework
PostHog: EU servers (Frankfurt/Ireland), no data transfer to the USA
LeadInfo: EU servers (Ireland/Frankfurt), Netherlands-based company, GDPR-compliant
HubSpot CRM: EU data centre (Frankfurt) with backup in Ireland, EU-US DPF and SCCs
10.4 Technical development and operations (anymize GmbH)
Provider: anymize GmbH, Schauenburger Str. 116, 24118 Kiel, Germany
Function: Sub-processor pursuant to Art. 28 GDPR – technical development, maintenance and operation of the anymize service on behalf of anymize GmbH
Data processed: Technical usage data, logs and system data in the course of operating the service
Legal basis: Data processing agreement pursuant to Art. 28 GDPR
10.5 Payment processing (Stripe)
Provider: Stripe Inc., South San Francisco, USA / Stripe Technology Europe Ltd., Dublin
Data processed: Payment data, billing address, email address, IP address, transaction history
Purpose: Payment processing, fraud prevention, compliance, invoicing
Retention period: In accordance with statutory retention periods (up to 10 years)
Stripe acts as an independent controller for fraud prevention and compliance. Payment data is transmitted and stored in encrypted form (PCI DSS Level 1). No credit card data is stored on our servers.
11 Data subject rights
You have the following rights:
11.1 Right of access (Art. 15 GDPR): You may request information about the personal data we process.
11.2 Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
11.3 Right to erasure (Art. 17 GDPR): You may request the deletion of your data, provided no statutory retention obligations apply.
11.4 Right to restriction (Art. 18 GDPR): You may request the restriction of processing.
11.5 Data portability (Art. 20 GDPR): You may receive your data in a structured format.
11.6 Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.
11.7 Right to withdraw consent (Art. 7 (3) GDPR): Where processing is based on consent, you may withdraw it at any time with effect for the future.
11.8 Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
Email: mail@datenschutzzentrum.de
Website: https://www.datenschutzzentrum.de
12 Data security
12.1 Technical measures
- Encryption of data transmission (TLS 1.3)
- Data processing and storage exclusively in Germany (Hetzner)
- Regular security updates
- Access control and logging
- Redundant systems and backups
12.2 Organizational measures
- Staff training
- Access authorization concept
- Data protection impact assessment
- Incident response procedures
- Regular review of security measures
13 Automated decision-making
13.1 AI system for anonymization
Our service uses a specialized AI system for the automatic detection of personal data. This serves data protection purposes only and involves no profiling.
13.2 Transparency
The AI system works on the basis of: pattern recognition for typical data formats, context analysis to identify personal references, and statistical evaluations without personal reference.
13.3 No profiling
No automated decision-making within the meaning of Art. 22 GDPR takes place that produces legal effects or similarly significantly affects you.
14 Currency and changes
This privacy policy is dated 23 June 2025. Further development of our website or changes in legal requirements may make it necessary to amend this privacy policy. We will inform you of material changes by email to the address stored in your user account.
The current version is available on our website at https://anymize.ai/datenschutz.
Version: 1.5 | As of: 23 June 2025