Skip to content
anserra
Language:ENRUPublished on this site: · Version 1.0.

Anserra Privacy Policy

Terms and Definitions

"Policy" means this Privacy Policy.

"Company" means Individual Entrepreneur Igor Dar, Georgia, identification number 305877637, legal address Georgia, Tbilisi, Saburtalo district, Bakhtrioni str., N22, flat 25.

"Service" means the Anserra web service located at anserra.io.

"User" means the person using the Service.

"Terms" means the Terms of Service of the Anserra Service, of which this Policy forms an integral part.

1. Data Controller

1.1. The controller of personal data processed in connection with the use of the Service is Individual Entrepreneur Igor Dar, Georgia, identification number 305877637, legal address Georgia, Tbilisi, Saburtalo district, Bakhtrioni str., N22, flat 25.

1.2. For questions regarding the processing of personal data, the User may contact the Company at the email address listed on the Service website.

2. Data Collected

The Company processes the following categories of data:

2.1. Account data, including name, email address, company name, and account settings.

2.2. Website scan result data, including page snapshots, HTML markup, robots.txt and llms.txt content, and the history of readiness score changes.

2.3. AI response data, including raw text of responses from third-party AI systems to questions the Service asks about the User's business, including mentions of third parties, in particular the User's competitors, contained in such responses, and aggregated metrics derived from such responses (share of mentions, position, sources).

2.4. Automated agent action records, stored in the agent_tests table, including domain, task identifier, the trajectory of the model's navigation and decisions, the final outcome, and execution time.

2.5. Payment and billing data, processed by the payment partner Paddle.com Market Ltd as an independent controller; the Company receives from Paddle only the information about payment necessary to provide access to the Service.

2.6. Technical data and logs, including IP address, user-agent string, and Service operation and error data.

2.7. Providing account data is necessary to register for and use the paid plans of the Service. If the User declines to provide such data, it will not be able to create an account or use the corresponding features of the Service. Providing other data, such as when contacting support, is voluntary.

2.8. The Service is not intended for persons under 18 years old, and the Company does not knowingly collect or process personal data of such persons. If the Company becomes aware that data of a person under 18 years old has been obtained without an appropriate legal basis, such data will be deleted.

3. Subprocessors

The Company engages the following subprocessors to provide the Service.

SubprocessorRoleRegion
Vercel Inc.Frontend and API hostingUnited States (Washington D.C. region; edge network is global)
Supabase Inc.Database, authentication, file storageeu-west-1 region, Ireland, European Union
Railway Corp.Background workers (BullMQ), Redis, Playwright browserams region, Amsterdam, Netherlands, European Union
Upstash Inc.Background job queueeu-west-1 region, Ireland, European Union
Resend Inc.Transactional emailUnited States
Functional Software Inc. (Sentry)Error monitoringUnited States
OpenAI OpCo LLCChatGPT queries, base engineUnited States
Perplexity AI Inc.Perplexity queries, base engineUnited States
Google LLCGoogle AI Overviews, base engine; Gemini API as a paid add-onUnited States
Anthropic PBCClaude API as a paid add-on; model powering the Observatory browser agentUnited States

3.1. Paddle.com Market Ltd (United Kingdom) is not a subprocessor of the Company and acts as an independent controller, as Merchant of Record, in respect of the User's payment data. Paddle's processing of such data is governed by Paddle's own privacy policy.

3.2. GitHub is used solely for storing the Service's source code, no personal data of Users is processed there, and it is not a subprocessor within the meaning of this Policy.

3.3. The automated engines Yandex Alice, GigaChat (Sber), and DeepSeek are present in the Service's codebase as additional modules but are not used in plans offered to Users outside the Russian Federation and are not included among the subprocessors for the international version of the Service.

3.4. The Company may change the composition of its subprocessors, including replacing an existing subprocessor with a new one performing an equivalent function, and may change the location of data processing within the limits described in Section 8 of this Policy, upon notice to the User by publishing an updated version of this Policy on the Service website at least 14 days before the change takes effect. Re-execution of this Policy or the User's separate consent to such a change is not required, unless otherwise expressly provided by applicable law.

4. Data Shared with AI Providers

4.1. Queries to the subprocessors OpenAI, Perplexity, Google, and Anthropic include only publicly available information about the User's business, such as the company name, city, category of services, and the content of publicly accessible pages of the website being checked.

4.2. Personal data from the User's account, such as name, email address, and payment details, is not included in queries to the AI providers listed above.

4.3. In the course of the Observatory automated agent's operation, at each step the Company sends to Anthropic the address of the current page, the first 6,000 characters of visible page text, and up to 80 links with their link text. Screenshots of pages are not retained or transmitted.

4.4. Under the standard API terms applied by OpenAI, Anthropic, Google, and Perplexity to their business and API customers, data submitted through the Service's queries is not used by default by these providers to train their artificial intelligence models. The Company does not alter these provider settings and does not grant the providers any additional consent to use the User's data for training purposes.

5. Legal Basis for Processing

5.1. Processing of account data and payment data is carried out for the performance of the contract with the User.

5.2. Processing of website scan results and agent action records is carried out for the performance of the contract and on the basis of the Company's legitimate interest in improving the quality of the Service.

5.3. Processing of anonymized data in the Agent-Ready research dataset is carried out on the basis of the Company's legitimate interest in developing the open specification and public research, and such data does not allow identification of the User or its client.

5.4. The Company may use anonymized and aggregated data derived from check results and other data processed by the Service for its own research, publications, including industry research, and product development. Such data does not allow the User, its client, or a specific website being checked to be identified, directly or indirectly, and its use for these purposes is based on the Company's legitimate interest.

5.5. The Company does not make legally significant decisions about natural persons based solely on automated processing, including profiling, without human involvement. The readiness score generated by the Service relates to the website as such, not to a specific natural person, and does not give rise to legal effects for natural persons.

5.6. The Company sends marketing or informational email communications to registered Users only where the User has given consent, including by a separate opt-in confirmation on the Service website. Separately, the Company may send business-to-business outreach emails to publicly available corporate contact addresses of legal entities and sole proprietorships in the United States, the United Kingdom, and other jurisdictions where such outreach is permitted without prior consent, on the basis of the Company's legitimate interest in promoting the Service and in compliance with the US CAN-SPAM Act and the UK Privacy and Electronic Communications Regulations (PECR). Each such email identifies the Company as the sender, states the Company's physical postal address, and contains a functioning unsubscribe mechanism. The Company, and not the email delivery provider it engages, is the controller of the recipients' personal data. Any recipient may opt out at any time using the method indicated in the relevant email or by contacting the Company; opt-out requests are honored, and processing for such communications ceases, within 7 business days.

5.7. The Company does not sell the User's personal data and does not share it with third parties for targeted advertising purposes within the meaning of US state privacy laws.

6. Data Retention

Data categoryRetention period
Client website data, scan results, page snapshots, markup, robots.txt/llms.txtThe current snapshot is retained for the duration of the subscription; change history is retained for 12 months; after account closure, data is retained for 30 days and then deleted
AI system responses, raw textRaw text is retained for 12 months; aggregated metrics (share of mentions, position, sources) are retained for the subscription period plus 30 days
Agent action records (agent_tests)Data linked to the User is retained for 12 months; an anonymized version is retained indefinitely as the Agent-Ready research dataset
Account dataRetained for the term of the contract and 30 days after account deletion
Payment and billing dataRetained for 5 years in accordance with applicable tax law requirements
Technical logsRetained for 90 days
Database backupsRetained for up to 30 days after deletion of the underlying data
Results of the free check without registrationRetained for 30 days; an anonymized version is retained indefinitely

6.1. Upon the User's request, all data is deleted within 30 days of the request, except for accounting records, whose retention is required by law, and the anonymized research dataset.

6.2. The Company has assessed the need for a Data Protection Impact Assessment in respect of its processing activities and has concluded that such processing does not fall within the categories for which Georgian law requires such an assessment, as the Service does not make fully automated legally significant decisions about natural persons and does not process special categories of data at a significant scale.

7. User Rights

The User may request confirmation from the Company of whether its personal data is being processed, access to such data, correction, deletion, restriction of processing, and receipt of its data in a structured format for transfer to another controller. The User may also withdraw, at any time, any consent it has given to the processing of its personal data, without affecting the lawfulness of processing carried out before the withdrawal; processing based solely on such consent is discontinued within 10 days of receipt of the withdrawal, unless another legal basis for processing exists. To exercise these rights, the User should contact the Company at the email address listed on the Service website.

7.1. The Company handles requests to exercise User rights within 10 business days. For Users located in the European Union, the European Economic Area, or the United Kingdom, the response period is one month from receipt of the request and may be extended in cases permitted by applicable law, with notice to the User of the reasons for the extension.

8. International Data Transfers

8.1. Some of the Company's subprocessors are located in the European Union, namely Supabase in the eu-west-1 region, Railway in the ams region, and Upstash in the eu-west-1 region, while other subprocessors are located in the United States, namely Vercel, Resend, Sentry, OpenAI, Perplexity, Google, and Anthropic.

8.2. Transfers of data to subprocessors located in the United States are carried out using applicable data protection mechanisms, including Standard Contractual Clauses or other mechanisms provided by the relevant subprocessor for cross-border data transfer.

9. Cookies and Similar Technologies

This section supplements the rest of this Policy and describes the Service's use of cookies and similar technologies, including localStorage and sessionStorage records, pixels, and scripts. The Company does not use cookies to establish the identity of the User.

CategoryPurpose
Strictly necessaryLogin session, security, including protection against cross-site request forgery, remembering the User's choices in the cookie banner, operation of the Paddle checkout form
FunctionalRemembering interface preferences, including language and the display settings for check results
AnalyticsAggregated statistics on visits and use of the Service for the purpose of improving it

9.1. On a User's first visit from a jurisdiction where consent is required, including the European Union, the European Economic Area, and the United Kingdom, the Service displays a cookie banner with options of equal prominence to accept all cookies or reject non-essential cookies, as well as granular settings for each category. Pre-ticked boxes are not used. Non-essential cookies are not set prior to the User's consent.

9.2. The User may change or withdraw its choices at any time through the "Cookie settings" link on the Service website; withdrawing consent is no more difficult than giving it. The User may also delete or block cookies in its browser settings, though blocking strictly necessary cookies may make it impossible to log in or complete payment through Paddle.

9.3. Where consent is not required by the law of the User's country, the Company nevertheless uses only the categories of cookies listed in this section and honors the User's choice to reject non-essential cookies.

9.4. Where required by applicable law, the Service honors recognized opt-out preference signals, including the Global Privacy Control signal, as an opt-out from the corresponding categories. The Service does not respond to the legacy Do Not Track header, for which no common standard exists.

9.5. Certain functional and analytics cookies may be set by the Company's subprocessors listed in Section 3 of this Policy, only after the User's consent to the relevant category. The current list of such cookies is available in the cookie settings on the Service website.

10. Data Security

10.1. The Company applies technical and organizational security measures appropriate to the nature and scope of the data processed, including encryption in transit and role-based access controls.

11. Changes to this Policy

11.1. The Company may amend this Policy by publishing the current version on the Service website with an effective date.

12. Contact

12.1. For all questions related to the processing of personal data, the User may contact the Company at the email address listed on anserra.io.

13. Applicable Law and Supervisory Authority

13.1. The processing of personal data under this Policy is governed by the Law of Georgia on Personal Data Protection No. 3144 of 14 June 2023.

13.2. The supervisory authority for personal data protection in Georgia is the State Audit Office of Georgia. The User may lodge a complaint with the State Audit Office of Georgia (pdp.sao.ge) regarding unlawful processing of its personal data, and may also challenge the Company's actions in court.

13.3. For Users located in the European Union or the United Kingdom, the Company additionally takes into account the requirements of the General Data Protection Regulation (GDPR) to the extent applicable to the processing of their data. Users in the European Union and the European Economic Area may also lodge a complaint with the data protection supervisory authority of the member state in which they reside or work, and Users in the United Kingdom may lodge a complaint with the Information Commissioner's Office (ico.org.uk).

13.4. Because the Company's processing of personal data of residents of the European Union and the United Kingdom is occasional in nature, is not carried out at a large scale, and does not involve special categories of data, the Company has not appointed a representative in the European Union under Article 27 of the GDPR or a representative in the United Kingdom under Article 27 of the UK GDPR. The Company will appoint such representatives if the nature or scale of such processing changes and will update this Policy accordingly.

13.5. The Company has not appointed a dedicated data protection officer or special representative, as the volume of data processed does not reach the thresholds established by Georgian law for mandatory appointment of such a person. Should the relevant thresholds be met, the Company will appoint such a person and update this Policy accordingly.

13.6. In the event of a data security incident posing a significant threat to the rights and freedoms of data subjects, the Company notifies the State Audit Office of Georgia in the manner and within the timeframes prescribed by Georgian law.

14. Government and Law Enforcement Requests

14.1. The Company may disclose the User's personal data in response to a mandatory request from a government authority, court, or other authorized body, where such disclosure is required by applicable law. Upon receiving such a request, the Company notifies the User before disclosure where possible, except where such notice is expressly prohibited by law or a court order.

15. Data Processing Agreement

15.1. Users acting as independent controllers of their clients' personal data must enter into personal data processing agreements with their clients. The Company bears no liability for a User's violation of this provision.

Company Details and Date

Individual Entrepreneur Igor Dar, Georgia, identification number 305877637, legal address Georgia, Tbilisi, Saburtalo district, Bakhtrioni str., N22, flat 25.

Version 1.0.

The effective date is 11.09.2026.