Our commitments when we process data on your behalf

Data processing

Last updated 15 August 2026

Roles

For the data your applications process, your organisation is the controller and Anthouse is the processor. We act only on your documented instructions.

What we process

Whatever your applications hold, plus the account and audit data described in the privacy policy. We do not know in advance what your applications will contain, which is why the sharing and scanning controls exist.

Security

The measures are listed openly on our security page rather than described in the abstract: envelope encryption for secrets, per-request authorization checks, deploy-time source scanning, named ownership, and separate audit trails for agent and human actions.

Subprocessors

The current list is published, with what each does and where it runs. We will give 30 days notice before adding a subprocessor that handles customer data, and you may object.

Transfers

Application and workspace data stays in the European Union. Authentication is currently processed in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses.

Breach

We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at that point and what we are doing. We would rather commit to a deadline we can meet with one on-call engineer than to one that sounds better.

Audit

On Enterprise plans we will complete your security questionnaire and support a reasonable audit. On other plans we answer questions in writing at security@anthouse.io.

Return and deletion

On termination you may export your application source. We delete your data within 30 days unless the law requires otherwise.

Signing one

Write to privacy@anthouse.io and we will send a DPA for signature. We do not require you to accept ours; we will review yours.