Privacy Policy

This notice describes how Anchor handles personal data when you request a workspace, join a trial, or use the evidence trail. Contact hello@anchor.example.

What we collect. Account data (name, work email, organisation, role); identity-provider metadata you connect (for example Okta or AWS IAM group names, not passwords); access events written to the evidence trail (actor, timestamp, system, action); and support correspondence.

Why we collect it. To provision and secure your workspace, map access events onto SOC 2, ISO/IEC 27001, GDPR, and CCPA control language, export auditor-ready packs, and respond to support requests. We do not sell personal data.

Retention. Trail records are kept for the term of your workspace plus 24 months, unless a longer period is required for an active audit. Account data is deleted within 30 days of workspace closure. You may request export or deletion at hello@anchor.example.

Your rights. If you are in the EEA or UK you may access, rectify, erase, restrict, or port your data, and object to processing (GDPR). If you are a California resident you may request know, delete, and correct (CCPA/CPRA). We do not sell or share personal information as those terms are defined under CCPA.

Processors and transfers. Hosting, email delivery, and identity integrations act as processors under written terms. Where data leaves the EEA we use an adequacy decision or standard contractual clauses. Independent assessments: SOC 2 Type II and ISO/IEC 27001, as referenced on the Proof section of this site.

Contact. Privacy requests: hello@anchor.example. We respond within 30 days.

Create a free website with Framer, the website builder loved by startups, designers and agencies.