Privacy Policy

How Anansi collects, uses, and protects your personal information

Last Updated: 2025-Sep-15

Privacy Policy – Anansi Data Analytics Pte. Ltd.

Last updated: 2025-Sep-15

1. Introduction

Anansi Data Analytics Pte. Ltd. (“Anansi”, “Company”, “we”, “our”, “us”) respects your right to privacy. This Privacy Policy explains how we collect, use, and protect your personal data through your use of our websites and services, including when you register, subscribe to newsletters, or purchase products or services. By accessing or using our website and services, you agree to this Privacy Policy. If you have any questions or concerns, please contact us using the details at the end of this Policy.

2. Roles and Scope

Anansi provides multiple offerings under a single corporate entity. This Privacy Policy applies to all websites, products, and services. Depending on the context, Anansi may act as:

  • A data controller (e.g., for CRM, marketing, website analytics, and client account data).
  • A data processor (e.g., for certain customer-directed services such as document digitization, where customers upload their own content).

Controller and processor obligations differ and are described in this Policy and our Data Processing Addendum (DPA).

For particular services, supplemental privacy notices or annexes may apply.

Data products. Our data products consist primarily of macroeconomic, financial, and statistical datasets that are generally non‑personal. Any personal data processed in connection with data products relates to account/registration details, CRM/contact data, and website usage necessary to operate the services.

3. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. The date of the most recent update is shown at the top of this page. When we make material changes, we will bring them to your attention (for example, by noting the updated date, posting the revised Policy here, or sending a notification). Your continued use of our services after the changes take effect constitutes acceptance of the updated Policy.

4. What Personal Data We Collect & Why

We may collect the following categories of personal data, depending on how you interact with us:

  • Identity and Contact Data — such as your name, email address, phone number, job title, and organization.
  • Account and Profile Data — login credentials, account preferences, purchase/subscription details, feedback, and survey responses.
  • Payment & Billing Information — billing address, contact details, and payment method information (such as limited card details processed by third-party providers or bank account identifiers provided for payments). We do not store full credit card data, and payment details are only used for invoicing and reconciliation.
  • Usage and Technical Data — information about how you interact with our services, such as IP address, device and browser type, operating system, pages visited, features used, time spent, error logs, and performance metrics.
  • Marketing & Communications Data — your marketing preferences and communication settings.

5. How We Use Your Information

Service Provision

  • Provide access to our database and analytical tools.
  • Process your requests and transactions.
  • Maintain and improve service functionality.
  • Provide customer support and technical assistance.

Communication

  • Send account‑related notifications and updates.
  • Provide information about new features or data additions.
  • Send newsletters and educational content (with consent).
  • Respond to inquiries and provide customer support.

Service Improvement & Security

  • Analyze usage patterns to improve our service.
  • Develop new features and capabilities.
  • Conduct research on data usage trends.
  • Ensure security and prevent fraud.

Legal and Compliance

  • Comply with legal obligations and regulatory requirements.
  • Protect our rights and enforce our Terms of Service.
  • Respond to legal requests and court orders.
  • Prevent illegal activities and policy violations.

Legal Bases for Processing

We process your personal information based on the following legal grounds:

  • Contract necessity: to fulfil our contractual obligations to you, including providing the service.
  • Legitimate interests: to improve and secure our service, prevent fraud, and ensure compliance, balanced against your rights.
  • Consent: where required, we obtain your consent for specific processing activities.
  • Legal obligation: to comply with applicable laws, regulations, and legal processes.

6. Who We Share Your Personal Information With

We do not sell, trade, or rent your personal information to third parties for marketing purposes.

We may share your personal data with:

  • Third‑party service providers, content providers, and partners.
  • Your employer (if applicable).
  • Law enforcement, regulatory or governmental agencies, courts as required by law.
  • Others with your consent.

Sub‑processors. Where Anansi acts as a processor on behalf of a customer (for example, customer-directed digitization or data-processing services), we engage vetted sub-processors for infrastructure, storage, email delivery, analytics, and similar services.

Contractors/Freelancers. Where contractors or freelancers assist us, they are bound by confidentiality obligations and data protection terms equivalent to our processor commitments.

Corporate service providers (categories). We use trusted third‑party processors to operate our websites and data products. These include providers for: (i) cloud hosting and delivery (infrastructure/CDN, DNS, performance and DDoS mitigation); (ii) productivity and communications; (iii) CRM and marketing operations; (iv) payments and billing; (v) application infrastructure and product analytics; and (vi) email delivery and support tooling. We require processors to implement appropriate security and confidentiality obligations under contract.

7. Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will provide appropriate notice and take reasonable steps to protect your rights and data during such transfers.

8. Third‑Party Links

Our website may contain links to third‑party sites or services (e.g., payment processors). These sites may collect data independently. We are not responsible for their data practices. We recommend reviewing their privacy policies when you visit them.

9. Email Tracking

We may embed pixel tags in emails to track whether emails are opened or links clicked to improve our communications. In the EU/UK, we rely on consent for marketing emails; elsewhere we rely on consent or legitimate interests where permitted by law. You can opt out of marketing emails at any time using the unsubscribe link or by contacting us.

10. International Transfers

Anansi serves customers globally. Where personal data is transferred internationally, we implement appropriate safeguards, including EU Standard Contractual Clauses (SCCs) together with Transfer Impact Assessments (TIAs), the UK Addendum to the SCCs or the International Data Transfer Agreement (IDTA) for UK transfers, and other recognized mechanisms where applicable. We also apply technical and organizational safeguards such as encryption in transit and at rest, access minimization, and role‑based access controls.

11. How We Keep Your Personal Information Secure

We implement industry‑standard security measures to protect your information, including encryption at rest and in transit, multi‑factor authentication (MFA), single sign‑on (SSO) where available, role‑based access controls (RBAC) and least‑privilege access, audit logging, key management, vulnerability management, and network security controls.

Secure Development. We follow a secure software development lifecycle (code reviews, dependency and secret scanning, SAST/DAST) and perform periodic security assessments.

Account Security.

  • Use strong, unique passwords for your account.
  • Enable two‑factor authentication when available.
  • Log out of shared or public computers.
  • Report suspected security issues immediately.

We are pursuing alignment with SOC 2 Type II / ISO 27001 expectations for enterprise customers.

12. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy or as required by law. Examples:

  • CRM/marketing leads: deleted after 24 months of inactivity (or earlier upon request).
  • Contracts/invoices: will be retained for up to 7 years to meet legal obligations.
  • Support and operational logs: will be retained for up to 24 months for security and troubleshooting.

We periodically review data and delete or anonymize it when it is no longer needed.

13. Data Deletion

For processor services, retention is configurable by the customer; we provide export options and verifiable deletion upon request or contract termination.

  • Account information is retained while your account is active.
  • Usage data is retained only as long as necessary for security, troubleshooting, and analytics, typically 12–24 months, unless a longer period is required by law.
  • Payment information is retained according to financial regulations.
  • You may request deletion of your account and associated data.
  • You retain full ownership of the documents you upload. We do not claim ownership of your data or outputs.
  • AI/Model Training. For processor services, we do not use customer uploads or outputs to train foundation models or third-party models, unless expressly permitted in a separate agreement.

14. Your Rights and Choices

Access and Control. Depending on your location, you may have the right to access, correct, delete, or restrict processing of your personal information.

Response timelines and verification. We respond to data subject requests within statutory deadlines (e.g., GDPR/UK: 1 month, extendable by 2 months for complex requests; CCPA/CPRA: 45 days, extendable to 90 days). We may request additional information to verify your identity and we will coordinate with our service providers to fulfil requests.

Communication Preferences.

  • Opt out of marketing communications through email preferences.
  • Adjust notification settings in your account.
  • Contact us to update communication preferences.

Cookie Preferences.

  • Adjust cookie settings through your browser.
  • Use our cookie preference center (where available).
  • Note that disabling cookies may limit certain functionality.

15. Cookies and Tracking Technologies

We currently do not deploy non‑essential cookies or third‑party trackers on our platforms. If we introduce analytics or advertising cookies in the future, we will present a consent banner (particularly for EU/UK visitors) with granular category controls and publish a Cookie Policy describing each cookie and its purpose. You can also manage cookie preferences through your browser settings. Note that disabling cookies may limit certain functionality.

16. Children’s Privacy

Our Service is intended for professional, research, and academic users and is not directed to individuals under the age of 18. We do not knowingly collect or process personal information from anyone under 18 years of age. If you believe we have collected personal information from a minor under 18, please contact us immediately so that we can take appropriate action. We enforce this through our Terms of Service and account workflows and will suspend or terminate accounts if we learn of under‑18 use.

17. Regional Privacy Rights

European Union (GDPR). If you are in the EU, you have additional rights under the GDPR, including the right to object to processing, withdraw consent, and lodge complaints with supervisory authorities. We rely on lawful bases such as contract, legitimate interests, consent (where required), and legal obligations.

United Kingdom (UK GDPR/Data Protection Act 2018). We comply with UK GDPR. For international transfers from the UK, we use the UK Addendum to the EU SCCs or the IDTA. UK data subjects have the same rights as described above.

Singapore (PDPA). We have appointed a Data Protection Officer (DPO) reachable at support@anansidata.com. We protect personal data with reasonable security and cease retention when no longer necessary for the purposes collected. We notify the PDPC and affected individuals of notifiable data breaches where there is a risk of significant harm, generally within 3 calendar days after completing our assessment, consistent with PDPC guidance.

United States (CCPA/CPRA – California). We disclose the categories of personal information collected, purposes, and disclosures. California residents have rights to know, delete, and correct personal information, and to opt out of any “sale” or “sharing” of personal information. We honor Global Privacy Control (GPC) signals. We do not “sell” or “share” personal information as defined by the CPRA, and we do not use sensitive personal information for additional purposes without consent.

18. Contact Information

Email: support@anansidata.com

Data Protection Officer (DPO): support@anansidata.com

Address:

Anansi Data Analytics Pte. Ltd.

22 Sin Ming Lane

#06-76 Midview City

Singapore 573969

19. Effective Date

This Privacy Policy is effective as of the “Last updated” date shown at the top of this document. By using our Service, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.