Our commitments when we process data on your behalf
Last updated 15 August 2026
For the data your applications process, your organisation is the controller and Anthouse is the processor. We act only on your documented instructions.
Whatever your applications hold, plus the account and audit data described in the privacy policy. We do not know in advance what your applications will contain, which is why the sharing and scanning controls exist.
The measures are listed openly on our security page rather than described in the abstract: envelope encryption for secrets, per-request authorization checks, deploy-time source scanning, named ownership, and separate audit trails for agent and human actions.
The current list is published, with what each does and where it runs. We will give 30 days notice before adding a subprocessor that handles customer data, and you may object.
Application and workspace data stays in the European Union. Authentication is currently processed in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses.
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with what we know at that point and what we are doing. We would rather commit to a deadline we can meet with one on-call engineer than to one that sounds better.
On Enterprise plans we will complete your security questionnaire and support a reasonable audit. On other plans we answer questions in writing at security@anthouse.io.
On termination you may export your application source. We delete your data within 30 days unless the law requires otherwise.
Write to privacy@anthouse.io and we will send a DPA for signature. We do not require you to accept ours; we will review yours.