Privacy policy
How Ankarex processes the personal data of its customers, of website visitors and of message recipients, and how to exercise your rights.
Dit document wordt in het Spaans en het Engels gepubliceerd. Het wordt hier in het Engels getoond; bij verschillen is de Spaanse versie bindend.
In het kort
- We process your account data to provide the service, charge for it, protect it and comply with the law. We do not sell it or use it for third-party advertising.
- For the numbers and messages you send, you are the controller: we process them on your behalf under the data processing agreement.
- We record technical data (IP, device, activity) for security and fraud prevention.
- The website only uses technical cookies; there is no third-party analytics or advertising.
- You can exercise your rights by writing to [email protected] and lodge a complaint with the supervisory authority.
This summary does not replace the full policy.
1. Controller
The controller of the personal data described in this policy is Ankarex, whose identification details are in the Legal notice. You can contact us about any privacy matter at [email protected].
This policy applies to the data of customers and their authorised users, website visitors and people who contact us. For the data of message recipients, see clause 9.
2. What data we process
- Registration and account data: username, email, display name, language, profile photo if you upload one, role and verification status.
- Access and security data: password hashed with a one-way algorithm (never stored in clear text), passkeys (we only store the public key), sessions, API keys (we store a digest, not the full key), verification codes, history of sign-in IP addresses, user agent and activity logs.
- Device fingerprint: a technical identifier computed at sign-up to detect duplicate accounts and the evasion of suspensions.
- Legal acceptance data: document, version, date and time, IP address, user agent and language of each acceptance of these texts.
- Financial data: balance, movements, top-ups, amounts, currency and network used, payment and transaction identifiers, invoices and, when requested, the company's tax details.
- Service usage data: campaigns, messages, senders, costs, delivery states, failure reasons, tests, lookups, templates, lists, schedules, webhooks and notifications.
- Communications: the messages you send us by email or support and our replies.
- Business verification data you provide when we ask (name, tax ID, address, website, use cases, proof of consent).
- Website browsing data: IP address, language and technical browser data needed to serve and protect the pages; see the Cookie policy.
We do not ask for special categories of data. If you provide them without need, we will delete them.
3. Why we process it and on what legal basis
- Providing the Service: creating and managing your account, verifying your email, authenticating you, carrying out sends, tests and lookups, showing reports, sending service notifications and providing support. Legal basis: performance of the contract (article 6.1.b GDPR).
- Charging and invoicing: managing the balance, top-ups and charges, issuing invoices and keeping accounts. Legal basis: performance of the contract and compliance with tax and commercial obligations (articles 6.1.b and 6.1.c).
- Proving the contract: keeping proof of the acceptance of the terms and of the operations. Legal basis: legitimate interest in proving the contract and defending claims (article 6.1.f).
- Security and prevention of fraud and abuse: logging sign-ins and IPs, computing the device fingerprint, detecting duplicate accounts, applying content and recipient filters, rate limiting, investigating complaints and protecting recipients, carriers and other customers. Legal basis: legitimate interest (article 6.1.f) and, where applicable, compliance with legal obligations.
- Complying with legal obligations: answering authorities' requests, retention obligations, anti-money-laundering and sanctions. Legal basis: legal obligation (article 6.1.c).
- Improving the Service: aggregated usage and performance statistics. Legal basis: legitimate interest (article 6.1.f). We do not build profiles for advertising.
- Commercial communications about our own services similar to those you use, which you may refuse at any time. Legal basis: legitimate interest and article 21.2 LSSI.
Where the basis is legitimate interest, we have assessed that your interests or rights do not override it. You may object under clause 8.
4. Automated decisions
The platform applies automatic rules to block messages or numbers (exclusion lists, detection of virtual numbers, content and link filters) and to limit or hold traffic. These rules protect the Service and do not by themselves suspend your account, which a person decides. You may ask for human intervention, express your point of view and contest any decision by writing to [email protected].
5. Who we share data with
We do not sell personal data. We only share it with:
- Providers that render services to us as processors: cloud hosting and infrastructure, delivery and protection networks, transactional email (Resend), cryptocurrency payment processing (Liddie), text generation tools and technical support.
- Telecommunications carriers and providers and HLR providers, to the extent necessary to deliver the messages, run the tests or resolve the lookups you request.
- Authorities and courts, where there is a legal obligation or it is necessary to defend our rights.
- Professional advisers (lawyers, auditors, tax advisers) bound by confidentiality.
- An acquirer or successor of the business, in the event of a corporate transaction, with appropriate safeguards.
You can request the updated list of providers by writing to [email protected].
6. International transfers
Some providers and destination carriers may be outside the European Economic Area. When we transfer data outside the EEA we do so to countries with an adequacy decision of the European Commission or under the standard contractual clauses approved by the Commission and the necessary supplementary measures. Sending a message to a number in another country necessarily means the number and content reach the carriers of that country.
7. How long we keep data
- Account data: while the account is active. After closure, blocked for the limitation period of any actions that may arise (generally up to six years) and then deleted or anonymised.
- Financial data and invoices: six years from the end of the financial year, for commercial and tax obligations.
- Proof of acceptance of the legal texts: during the relationship and up to six years after it ends. It is not deleted with the account, because it is the proof of the contract.
- Message, test and lookup records: at least thirty days online for operations, reporting and claims, then archived for as long as necessary for invoicing, claims and legal obligations.
- Access, IP and security logs: at least thirty days and up to twelve months, unless needed to investigate an incident or abuse.
- Support communications: up to three years from the last communication.
8. Your rights
You may exercise the rights of access, rectification, erasure, restriction of processing, portability and objection, and withdraw any consent given, by writing to [email protected] from the email associated with your account or proving your identity. We will reply within one month, extendable in the cases provided by law.
Some data cannot be erased while there is a legal obligation to keep it or it is needed to defend claims; in that case it will be blocked.
If you consider we have not handled your rights correctly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) or the supervisory authority of your country.
9. Data of message recipients
Phone numbers, message content, senders and the results of delivery, tests and lookups that the customer enters into the Service are processed by Ankarex on behalf of the customer, who is the controller. That processing is governed by the Data processing agreement.
If you are the recipient of a message sent through Ankarex and want to exercise your rights or stop receiving them, first contact the business that sent it (identified in the message). If you cannot identify it or it does not reply, write to [email protected] and we will help forward the request; we can also block your number so that it no longer receives messages from a specific customer or from the platform.
10. Security
We apply technical and organisational measures appropriate to the risk: encrypted communications, one-way password hashing, passkeys, secrets encrypted at rest, role and permission based access control, activity logging, rate limits, encrypted backups and periodic reviews. No system is invulnerable; if a security breach affects your data, we will tell you and notify the authority where the law requires it.
11. Minors
The Service is aimed exclusively at businesses and professionals of legal age. We do not knowingly process data of minors as customers. If we detect an account of a minor, we will close it.
12. Changes to this policy
We may update this policy. We will publish the new version with its date and, if the change is relevant, notify you by email or in the console.