Data privacy policy
Status: 2026-08-21
1. Responsible Party
Anfrimil Establishment, Gapetschstrasse 91, 9494 Schaan, Liechtenstein. Contact for Data Protection Concerns: [email protected].
2. Scope and Legal Basis
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), which is directly applicable in the European Economic Area, including Liechtenstein, and in accordance with the Liechtenstein Data Protection Act. For users from Switzerland, we also comply with the Swiss Data Protection Act (DSG). The legal bases are, in particular, the fulfillment of contracts (Art. 6 para. 1 lit. b GDPR), legitimate interests (lit. f) and, where necessary, your consent (lit. a).
3. What data we process
a) Customer account and business profile
When you register, we collect your company name, email address, and password (encrypted via our login service). During onboarding, we collect public business data (services, address, opening hours, service area), which, by agreement, is displayed on our public comparison pages. We deliberately do not request personal data from employees.
b) Usage data
For error diagnosis, support, and service improvement, we log technical events (e.g., page views in the customer area, triggered actions, error messages) with timestamp and account assignment. When operating the servers, we also process server log data (including IP address, date and time of access, technical details of the end device) to ensure operation and security (Art. 6 para. 1 lit. f GDPR); these logs are deleted after a maximum of 90 days. We do not use third-party advertising or tracking cookies. No cookies are set when merely visiting the website; if you select a language, we store this choice in a technically necessary cookie, and upon login, we use a technically necessary session cookie and the local login storage of our login service (Google Firebase) in the browser. These are required for the requested service and do not require consent; therefore, we do not display a cookie banner.
c) Prospect data (first contact)
For initial contact with businesses, we process publicly available company data (e.g., company name, business contact details from the company's own website). This data comes from publicly accessible sources, particularly the company's website and public company and industry directories. The legal basis is our legitimate interest in direct business contact (Art. 6 para. 1 lit. f GDPR). We use AI service providers for creating personalized messages; only the aforementioned publicly available company data is transmitted. You can object to this use at any time; each message contains an unsubscribe link, and we maintain a block list to prevent repeated contact.
d) Newsletter
We only send our newsletter with your consent (Art. 6 para. 1 lit. a GDPR). For this purpose, your email address and the time of subscription and unsubscription are processed. You can unsubscribe at any time via the link in each issue; this revokes your consent for the future.
4. Recipients and processors
We use carefully selected service providers with whom data processing agreements exist or will be concluded: Google Cloud (hosting and database, EU/Frankfurt region), Firebase (login), Brevo (email delivery, EU), and the AI providers mentioned in section 5. The support chat history is only temporarily stored locally in your browser (24 hours) and can be removed by deleting browser data. Payments are processed via a payment reseller (Merchant of Record: Paddle); Paddle is independently responsible for payment data, and we do not receive complete payment data.
5. Artificial Intelligence (AI)
The service creates and maintains content with the support of AI models. For this purpose, we transmit the required data via the OpenRouter interface (OpenRouter Inc., USA) to the language model used for each task, currently from Anthropic (Claude) or Google (Gemini). For marketing image motifs, we use fal.ai (USA); no personal data is sent there. The transfer to third countries is based on EU standard contractual clauses or equivalent guarantees from the providers.
Depending on the task, the following are processed: the operational data and content of your website provided by you (for profile texts and public comparison pages), your messages in the onboarding and support chat, and during initial contact, the publicly available company data of the contacted business. Please do not enter special categories of personal data into the chats; only operational data is required for the service.
According to the settings we have chosen and the providers' terms, the transmitted inputs are not used for training the AI models. Queries may be temporarily stored by the providers for abuse detection. No automated decision-making with legal effect takes place (see section 7).
6. Storage Duration
We store personal data as long as the customer account exists or as required by legal retention obligations. After account deletion, data is deleted or anonymized, unless retention obligations prevent this. Specifically: server logs are deleted after a maximum of 90 days; invoice and accounting data are retained for the duration of statutory retention periods (up to 10 years); the opt-out list for initial contacts is maintained permanently to ensure a declared objection is always respected; consent records for the GTC (time, version, IP address) are stored permanently for evidentiary purposes.
7. Your Rights
You have the right to information, rectification, erasure, restriction of processing, data portability, and objection. If processing is based on your consent, you can revoke it at any time with future effect. Automated decision-making with legal effect against you within the meaning of Art. 22 GDPR does not take place. Customers can download their data export directly in the customer area and request account deletion there or write to us at [email protected]. The competent supervisory authority is the Data Protection Office of the Principality of Liechtenstein (datenschutzstelle.li); you can also contact the supervisory authority of your country of residence.
8. Data Security
All connections are TLS-encrypted. Access to customer data is limited to what is necessary and is logged. Data is stored in data centers within the EU.
9. Changes
We will adapt this statement if the service or legal situation changes. The version published here at any time shall apply.
Authoritative Language Version
This text is provided in several languages. The translations are for understanding. The German version is exclusively authoritative and legally binding. In case of discrepancies between the language versions, the German wording applies.