Skip to content
Legal

Privacy Policy

Last updated 23 August 2026

This Privacy Policy explains how ANYMA LLC collects, uses and protects your personal information. We keep data collection to a minimum — what you send us through our contact form, plus the technical diagnostics our error monitoring records when something on the site breaks — and we never sell it.

Who we are

This website is operated by ANYMA LLC, a limited liability company organised under the laws of Delaware, United States (file number 10702506), with its registered office at 8 The Green, Suite B, Dover, DE 19901, United States.

We are not established in the European Union. Because we offer our services to people in the EU and the EEA, the GDPR applies to us under its Article 3(2), and we apply it to the personal data described in this policy.

ANYMA LLC is the data controller for the personal information described in this policy. For any privacy question, or to exercise your rights, email us at hello@anyma.studio.

What information we collect

The only personal data we collect is what you choose to share through our contact form: your name, your email address, the services you are interested in, and anything you write in the message field.

Please don't include sensitive information — such as health, financial or other special-category data — in your message. We do not track, fingerprint or build profiles on people who simply browse the site.

To keep the form free of automated abuse we use Cloudflare Turnstile. Its script loads on every page that carries our contact form, so Cloudflare receives your IP address and some technical signals about your browser even if you never write to us. Turnstile is an anti-bot check rather than an analytics or advertising tool: Cloudflare states that it does not use it to profile visitors or follow them across sites.

We also use Sentry to find out when something on this site breaks. If a page fails to load or a request goes wrong, Sentry receives a diagnostic report: the address of the page, the page you came from, your browser, operating system and device type, the error message and the stack trace through our own code. We have configured it not to send account identifiers, cookies or the contents of anything you submit, so what you write in the contact form never reaches it. Your IP address is not stored either — but Sentry does read it in passing to work out roughly where the error happened, and keeps that approximate location (country, region and city) with the report. We do not record sessions or replay what visitors do on the site.

Why we use it

We use the information you submit only to respond to your enquiry, to discuss and scope a potential project, and to follow up with you about working together. We do not use it for marketing unrelated to your enquiry.

The diagnostic reports are used only to find, understand and fix faults, and to keep the site secure and working. We do not use them to measure audiences, and we do not try to work out who you are from them.

Our lawful basis

We process this information on the basis of our legitimate interests (Article 6(1)(f) GDPR) — specifically, our interest in responding to and managing enquiries about our services. We have considered your rights and do not believe this processing overrides them.

The same basis covers the diagnostic reports, here our interest in keeping this site functioning and secure — an interest Recital 49 of the GDPR recognises explicitly. Since the monitoring stores nothing on your device, it needs no consent under the cookie rules; you can still object to it under Article 21 by writing to hello@anyma.studio.

If you would prefer we did not handle your enquiry on this basis, email us at hello@anyma.studio and we will stop.

Who we share it with

We do not sell or rent your personal data. We share it only with the providers that help us run the studio and reply to you — Vercel, which hosts this website; Google, whose Workspace and Sheets we use for email and to record enquiries; Cloudflare, whose Turnstile service checks that our form is being used by a person rather than a bot; and Sentry, which receives the diagnostic reports described above — and only so far as they need it to provide their service to us. All of them act as our processors, under a data processing agreement that requires them to keep what they hold secure and to act only on our instructions.

Sentry is the one that never sees what you write: it receives diagnostics about failures, not enquiries. It uses its own subprocessors to run its service, which it lists publicly at sentry.io/legal/subprocessors and may change on 30 days' notice.

Where your data is stored

This website runs on Vercel. Its static pages are served from a global content delivery network, so they reach you from wherever is nearest, but the parts that execute code — the contact form above all — run in Vercel's Washington, D.C. region in the United States. Enquiries you send through the form are then recorded in a Google Sheet, and our email runs on Google Workspace.

Your data is therefore processed in the United States. We are a US company with no establishment in the European Union and you send it to us directly, which under the European Data Protection Board's Guidelines 05/2021 is a direct collection rather than a “transfer” within the meaning of Chapter V of the GDPR. Everything else in this policy — your rights, our lawful basis, how long we keep your data — applies exactly as written.

Google and Cloudflare are US providers too. Both maintain safeguards for European personal data that reach further than our own position requires: Google LLC is certified under the EU–US Data Privacy Framework (Implementing Decision (EU) 2023/1795) and incorporates the Standard Contractual Clauses into its terms, and Cloudflare incorporates the Standard Contractual Clauses into its data processing addendum.

The diagnostic reports go to Sentry's United States region. Sentry is Functional Software, Inc., of 45 Fremont Street, 8th Floor, San Francisco, CA 94105, and it carries the same pair of safeguards: it is certified under the EU–US Data Privacy Framework for non-HR data, and its data processing addendum incorporates the Standard Contractual Clauses as a fallback. It has appointed an EU representative of its own, Sentry Software Netherlands B.V. in Amsterdam.

How long we keep it

We keep enquiry data for up to 24 months after our last contact about it, unless your enquiry becomes an active project — in which case we keep it for as long as we work together and for any period required afterwards. After that, we delete it. You can ask us to delete it sooner at any time.

Diagnostic reports run on a separate and much shorter clock: Sentry deletes them automatically 30 days after they arrive, and we do not copy them anywhere else.

Your rights

Under the GDPR you have a number of rights over your personal data. To exercise any of them, email us at hello@anyma.studio; we will respond within one month. Your rights are:

  • to ask for a copy of the personal data we hold about you (access);
  • to have inaccurate data corrected (rectification);
  • to ask us to delete your data (erasure);
  • to ask us to restrict how we use it;
  • to object to our processing, including where we rely on legitimate interests;
  • to ask us to transfer your data to you or another provider (portability), where that applies; and
  • not to be subject to decisions based solely on automated processing.

Automated decisions

We do not make decisions about you based solely on automated processing, and we do not carry out profiling. We build AI systems for our clients, but this website does not use any to make decisions about visitors.

How to complain

If you have a concern about how we handle your data, please contact us first at hello@anyma.studio so we can put it right.

You also have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU or EEA country where you habitually live, where you work, or where you think the problem happened. The list of authorities is published at edpb.europa.eu. If you are in the United Kingdom, you can complain to the Information Commissioner's Office at ico.org.uk.

Because we are not established in the European Union, the “one-stop-shop” mechanism in Article 56 GDPR does not apply to us: there is no single lead authority, and each national authority is competent for its own territory.

Do you have to provide your data?

Providing your details is not a statutory or contractual requirement. But if you do not give us your name, email and message, we will not be able to respond to your enquiry.

Cookies

This website uses only strictly-necessary storage and no tracking cookies. You can read more in our Cookie Policy.

Do Not Track

Some browsers can send a “Do Not Track” signal. There is no common industry standard for how a website should respond to one. We do not track visitors across other websites, so the signal has nothing to switch off here — our behaviour is the same either way.

We also do not allow third parties to collect personal information about what you do on this site for their own purposes, or to follow you across other sites over time. The error monitoring described above works for us alone, records only failures, and stops at the edge of this site.

Changes to this policy

We may update this policy from time to time. The current version is always on this page, along with the date it was last updated.