ANNANIKSANNANIKS

ENRUFR

Privacy Policy

Last updated: 15 September 2026

This Privacy Policy explains what personal data Annaniks processes when you use the Annaniks AI Office website and client cabinet, why we process it, and the choices you have.

1. Data we collect

We collect only what the service needs to operate:

  • Account data: email, name and organization name.
  • Authentication data: hashed passwords and Google or GitHub identifiers when you use social sign-in.
  • Project content you submit: briefs, chat messages, documents and attachments.
  • Technical and audit data: log records, correlation identifiers, IP address and timestamps.
  • Strictly necessary cookies used to keep you signed in.

2. Voice input

Voice input is transcribed to text. The text is shown to you and stays editable; nothing is sent until you confirm it. Audio is not stored in AI Office memory. If a transcription provider processes your audio, this is disclosed at the point of use.

3. How we use data

We use personal data to:

  • Provide, secure and maintain the service.
  • Create and manage your account and organization.
  • Run the projects you request and produce estimates and documents.
  • Keep an immutable audit trail of security-sensitive actions.
  • Comply with legal obligations and prevent abuse.

4. Sharing and subprocessors

We do not sell personal data. We share data with service providers that operate the platform on our behalf: cloud hosting, large-language-model providers used to run your project, an email provider and a payment processor. Each acts under contract and only to the extent needed to deliver the service.

5. Payments

When checkout is enabled, payments are handled by our payment processor. We do not store full card details. Until a processor is configured for your account, no charge is made and no “paid” state is shown.

6. Security

We encrypt data in transit and, where supported, at rest. Access is restricted by role. Security-sensitive actions are written to an append-only audit log that cannot be edited or deleted, and secrets and personal data are masked in logs and model inputs.

7. Retention and deletion

We keep personal data while your account is active and for as long as needed for legal and audit purposes. Deletion of persistent data is a controlled action that requires owner approval. Some audit records may be retained where the law requires.

8. Your rights and international transfers

Subject to applicable law, you may request access, correction, deletion, portability, or object to or restrict processing, and you may withdraw consent. You may also complain to a supervisory authority. Data may be processed in countries other than your own; where it is, we rely on appropriate safeguards.

9. Changes and contact

We may update this policy and will revise the date above when we do. For any privacy request, contact contact@annaniks.com.