ANVL Privacy Policy
Last updated: 2026-09-01 In force from: 2026-09-01 Version: 1.0
1. About this policy
This policy describes how Dalarna Digital Marketing Agency AB ("we", "us", "ANVL") processes personal data when you use ANVL — our AI-driven platform for websites, brand profiles, presentations and content.
The policy covers:
- the marketing site anvl.work,
- the application app.anvl.work and the supporting services that run it,
- the public customer sites published with ANVL — but only to the extent that we process data on our own behalf. See section 3 on our dual role.
The policy does not cover how our customers use their own tools outside ANVL, or third-party services you choose to connect (see section 16).
2. Definitions
| Term | Meaning in this policy |
|---|---|
| Data protection law | The EU General Data Protection Regulation (GDPR, 2016/679), the Swedish supplementary Data Protection Act (2018:218), and the Swedish Electronic Communications Act (2022:482) as regards cookies. |
| Personal data | Any information that can be linked, directly or indirectly, to a living natural person — name, email address, IP address, session ID, user ID, log entries, and data inside content you upload. |
| Customer content | What you create or upload in ANVL: pages, text, images, brand profiles, presentations, social posts, uploaded files and AI prompts. |
| Service data | Data that arises when the platform runs: sign-in events, security events, error logs, AI consumption, performance measurements. Service data may contain personal data, and is then processed under this policy. |
| User | Someone who signs in to ANVL — with us or with a customer. |
| Visitor | Someone who visits a public site built in ANVL, without signing in. |
3. Controller — and when we are a processor instead
We have two roles, and which one applies determines what you can ask of us.
3.1 We are the controller
…for data where we determine the purposes ourselves:
- accounts, sign-in and security (users, passkeys, sessions, security logs),
- access requests, invitations and trial periods,
- invoicing, consumption metering and customer care,
- our own marketing and communication,
- operations, troubleshooting, abuse prevention and improving the platform.
Controller: Dalarna Digital Marketing Agency AB, company registration number 556942-8427, Slaggatan 13, 791 71 Falun, Sweden. Contact: privacy@anvl.work.
3.2 We are a processor
…for personal data that our customers put into, or collect through, their own sites and projects in ANVL: contact forms, newsletter sign-ups, email arriving in contact details in brand material, photographs of people in the media library, and visitor statistics on the customer's site.
There the customer is the controller and determines the purposes. We process the data on the customer's documented instructions and under the data processing agreement (DPA) that forms part of our contract. If you are a visitor or a contact of one of our customers, address your request to that customer first — we help the customer answer.
4. What personal data we process
4.1 Data you give us
| Category | Examples |
|---|---|
| Account details | Name, email address, role and permissions, organisational affiliation. |
| Sign-in credentials | Passkey credentials: public key, device type, the name you gave the device ("iPhone", "Work laptop") and when it was last used. We never store passwords in clear text, and your private passkey never leaves your device — we cannot read it. Accounts from before the passkey migration may still carry a hashed password. |
| Access request | Name, email, company, event code and campaign parameters (utm_source, utm_medium, utm_campaign) when you apply via /register. |
| Communication | The content of emails, support cases and messages you send us. |
| Payment and contract details | Billing details, contract terms, price level and consumption. |
4.2 Data collected automatically
| Category | Examples |
|---|---|
| Session data | Session ID, timestamp, validity period. |
| Security events | Event type (sign-in, failed attempt, passkey registration, sign-out and similar), IP address, user agent (browser/OS), timestamp. |
| Operational and error logs | Technical logs from the application and web servers, which may contain IP address, path and error code. |
| AI consumption | Which function was called, which model, token count, cost, run time, user ID and site ID. The prompt and the brand material sent with it may be stored — see section 6. |
| Consent events | Your cookie choice, timestamp, masked IP address and user agent. This is the evidence that consent was given, which the GDPR requires. |
4.3 Customer content
Pages, text, images, logotypes, brand profiles, presentations, social posts, uploaded files, chat messages to the AI assistant, interview answers and version history. The content may contain personal data if you choose to put it there — photographs of staff, customer quotes, contact details.
We keep version history for pages, brand profiles, presentations and designs. Deleted text may therefore remain in an earlier version until the history is erased.
4.4 Data about websites we analyse for you
If you ask an agent to analyse a web address — brand import, SEO review, accessibility scan, performance measurement or screenshot — we fetch the public page and process its content. If the page contains personal data, that data is processed as part of the task.
4.5 Visitors to sites built in ANVL
On a published customer site we process:
- Always: technical information required to deliver the page (IP address in server logs), the consent cookie, and the password cookie for password-protected pages.
- Always, to a third party: fonts are fetched from Google's font service, which means the visitor's IP address is sent to Google on page load. See section 9.3.
- If the visitor submits data: email address on newsletter sign-up, and whatever the visitor writes in contact forms.
- Only with consent: statistics via Google Analytics 4 and Google Tag Manager, where the customer has configured it.
- With embedded content: if a page embeds a YouTube video it uses the mode without tracking cookies (youtube-nocookie.com), but the video still loads from Google's servers and the visitor's IP address reaches them on playback.
4.6 Sensitive data
Do not put sensitive data into ANVL. That means health, ethnicity, religion, political opinions, trade union membership or sex life, and it also means biometric data, national identity numbers, criminal records and payment card numbers.
The service is not built to handle those, and nothing in it asks you for them. If such data ends up here anyway, we still protect it under this policy and our agreement — but we may ask you to remove it.
5. Why we process the data — purposes and legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Create and administer accounts, grant access | Account details, sign-in credentials | Performance of a contract (Art. 6(1)(b)) |
| Deliver the platform's functions — editor, agents, presentations, publishing | Customer content, service data | Performance of a contract (Art. 6(1)(b)) |
| Handle access requests and trial periods | Name, email, company, event code | Steps prior to entering a contract (Art. 6(1)(b)) |
| Authentication and session handling | Sessions, passkeys | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, intrusion detection | Security events, IP, user agent | Legitimate interests (Art. 6(1)(f)) — protecting the service and its users |
| Troubleshooting, operations, capacity planning | Operational and error logs, AI consumption | Legitimate interests (Art. 6(1)(f)) |
| Improve the platform and the quality of AI generation | Aggregated consumption, stored prompts | Legitimate interests (Art. 6(1)(f)) — see section 6 on how to object |
| Invoicing and consumption metering | Consumption, contract details | Performance of a contract (Art. 6(1)(b)) |
| Bookkeeping and archiving | Invoice records | Legal obligation (Art. 6(1)(c)), the Swedish Accounting Act |
| Statistics and marketing cookies | Cookie data | Consent (Art. 6(1)(a) + the Electronic Communications Act) |
| Newsletters and marketing | Name, email | Consent (Art. 6(1)(a)), or legitimate interests within an existing customer relationship |
| Responding to legal claims | Relevant data | Legitimate interests (Art. 6(1)(f)) |
You may withdraw consent at any time without affecting the lawfulness of processing before the withdrawal, and object to processing based on legitimate interests — see section 13.
6. AI processing
ANVL generates content using large language models and image models.
How the calls are made. Generation runs on language and image models from external providers. Every call goes through our own AI proxy, which holds the API keys and logs consumption. We use the providers' API services, not their consumer products. Which providers are engaged, and where each of them processes data, is listed in section 7.
What is sent there. The prompt the function builds — which may contain your customer content, your brand material, and text from a website you asked us to read. Do not send personal data you do not want to leave our infrastructure.
No model training. We do not permit our providers to use content sent via the API to train their models, and we do not train models of our own on your content. We may use de-identified and aggregated statistics (number of runs, token consumption, error rate) to improve the service.
What we log ourselves. Every AI call is logged with function, model, token consumption, cost, run time, and a link to user and site. The prompt and the brand material that accompanied it may be stored for troubleshooting and quality follow-up. If you want prompt logging switched off for your account, contact privacy@anvl.work.
Brand memory. The platform may keep a per-customer memory of how you steer generation — what you create and how you adjust it — to make future suggestions more accurate. The memory is tied to your organisation, not to an individual, and is used only for your own generation.
Automated decision-making. We make no automated decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). The AI proposes content — a human reviews and publishes.
AI output is not fact. Generated content can contain errors. You are responsible for reviewing it before you publish.
7. Recipients and sub-processors
We never sell personal data. We share it only with the recipients below, and only to the extent necessary.
| Recipient | Purpose | Place of processing |
|---|---|---|
| Oderland Webbhotell AB | Operation of servers, database and backups. | Gothenburg, Sweden |
| Oderland Webbhotell AB (Postal) | Email sent and received by the platform. | Gothenburg, Sweden |
| Anthropic | AI generation of text and analysis. | USA (SCC) |
| OpenAI | AI image generation. | USA (SCC) |
| Replicate | AI image generation. | USA (SCC) |
| Berget AI | Text and image generation, where we run generation on Swedish infrastructure. | Sweden |
| Requesty | Model routing, where we keep generation inside the EU. | EU |
| Google — the font service | Fonts on published sites. The visitor's IP address is transferred. See 9.3. | USA (SCC) |
| Google — PageSpeed Insights | Performance measurement of public URLs you ask us to measure. | USA (SCC) |
| Google — Analytics 4 / Tag Manager | Visitor statistics on customer sites — only where the customer has configured it and the visitor has consented. | USA (SCC) |
| Google — YouTube | Playback of embedded video, in cookieless mode. | USA (SCC) |
| Unsplash | Stock image search. Only the search term is sent — no user data. | USA (SCC) |
| ScreenshotOne | Screenshots of public URLs in the research function. | USA (see 7.1) |
| Oderland Webbhotell AB (object storage) | Storage of uploaded files. | Gothenburg, Sweden |
| Auditor, lawyer, accounting firm | Statutory and contractual purposes. | EU |
| Public authority | Where we are legally obliged (section 8). | Sweden/EU |
7.1 ScreenshotOne — a disclosed shortcoming
ScreenshotOne states in its own privacy policy (last updated 2025-11-15) that the company "is not yet compliant with the GDPR", and that a data processing agreement is "available on request" — that is, not entered into. Their database and API run on DigitalOcean in the USA; the headless browsers that take the screenshot run on Google Cloud in the USA.
The function is used by the research agent in the presentation tool and takes screenshots of public URLs you specify yourself. It sends no account details and no customer content. The service is disabled when no API key is configured.
We have not entered into a processor agreement with ScreenshotOne, and we disclose that openly rather than claim otherwise. The service is on its way out — we are moving the function to our own rendering service.
All sub-processors are bound by data processing agreements with obligations equivalent to our own. If we replace or add a sub-processor that processes customer data, we inform affected customers in reasonable time in advance, and the customer has the right to object. If you are a customer, the notice period stated in the data processing agreement applies — it is binding and takes precedence over this wording.
8. Disclosure on legal demand and abuse
We may disclose personal data where it is necessary to
- comply with law, a court order or a valid request from a competent authority,
- investigate, prevent or address fraud, security incidents or abuse of the service,
- establish, exercise or defend legal claims.
We disclose only what is actually requested, assess every request, and notify the affected customer unless we are legally prevented from doing so.
9. Cookies and similar technologies
9.1 How consent works
Necessary cookies are set without consent — they are required for the service to work. Statistics and marketing cookies are set only after active consent: the default is off, and no such scripts load before you have chosen.
9.2 Cookies we use
| Cookie | Provider | Purpose | Lifetime | Category |
|---|---|---|---|---|
cms_session |
ANVL (first party) | Keeps you signed in to the admin surface. | 7 days | Necessary |
sommr_consent |
ANVL (first party) | Stores your cookie choices so the banner is not shown again. | 12 months | Necessary |
sb-gate-* |
ANVL (first party) | Preserves access to a password-protected page. Set only on such pages. | Session | Necessary |
_ga, _ga_* |
Google Analytics 4 | Pseudonymous visitor ID and session data. Only on sites where GA4 is configured. | 24 months | Statistics |
_gcl_au |
Google Tag Manager | Measures the effect of ads via Google Ads. Only where GTM is configured. | 3 months | Statistics |
Google Consent Mode v2 is used where Google tags are present: the default state is "denied" and is sent before the tags load, and is updated when you make your choice.
Change your mind whenever you like. Click "Cookie settings" in the footer, or clear cookies in your browser. Declining statistics and marketing does not affect how the service works. When we change the categories, you are asked again.
9.3 Transfers that are not cookies
Some functions send the visitor's IP address to a third party without setting any cookie. That still counts as processing of personal data:
- Fonts. Published sites fetch fonts from Google's font service (fonts.googleapis.com / fonts.gstatic.com). The visitor's IP address is transferred to Google on every page load. We are working to serve the fonts from our own infrastructure instead.
- Embedded video. Where a page embeds YouTube, the cookieless mode is used, but the IP address reaches Google when the video loads.
- Maps and other embeds that a customer chooses to add work the same way and are controlled by the customer.
10. Logs and security events
We log sign-ins, failed sign-in attempts, changes to security settings, registration of passkeys and similar, together with IP address, user agent and timestamp. The logs are used to detect intrusion attempts, to troubleshoot, and to be able to show what has happened on an account — not to monitor how individual employees work.
11. How long we keep the data
| Data | Retention period |
|---|---|
| Account details and customer content | For as long as the account is active. |
| After the contract ends | Erased or anonymised within 30 days, unless we must keep it by law. |
| Sessions | Expire automatically after 7 days. |
| Invitation and registration links | 7 days, then invalid. |
| Security events | 12 months. |
| Operational and error logs | 30 days. |
| AI consumption log, including stored prompts | 30 days. |
| Version history for pages, brands and presentations | 30 days. |
| Review snapshots (SEO, accessibility, performance) | 12 months. |
| Consent events | 12 months after the consent, as evidence. |
| Cookies | Per the table in 9.2. |
| Accounting records | 7 years (the Swedish Accounting Act). |
| Backups | Overwritten on a rolling basis, at the latest within 30 days. |
Erasure in live operation takes effect in backups only once the backup has been rotated out.
12. Security
- Sign-in without passwords. ANVL uses passkeys (WebAuthn/FIDO2). The private key never leaves your device, and the passkey is bound to our domain — which makes phishing ineffective. Password sign-in and one-time codes are being phased out and are used only for accounts that have not yet moved over.
- Encryption. All traffic runs over TLS. Session cookies are
httpOnly,secureandsameSite. - Authorisation. Role-based access per organisation and site — users reach only what they are entitled to.
- Isolation. Each customer is its own tenant; content and files are separated by site ID.
- Backup. Regular backups of database and files.
- Personal data breach. On a confirmed incident carrying risk, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware of it. Affected customers are notified without undue delay and no later than 48 hours — that deadline is stated in the data processing agreement and is binding.
Your responsibility. Protect your device and your sign-in methods, do not share accounts, and contact security@anvl.work immediately if you suspect unauthorised access.
No service is entirely without risk. We cannot guarantee uninterrupted availability at our suppliers, and outages at them may affect access to the service.
13. Your rights
Under the GDPR you have the right to
- access the personal data we process about you (a subject access request),
- have inaccurate data corrected,
- have data erased when it is no longer needed, or where the processing rested on consent,
- request restriction of the processing,
- object to processing based on legitimate interests, and always to direct marketing,
- receive your data in a machine-readable format and transmit it (data portability),
- withdraw consent at any time.
How to do it: email privacy@anvl.work. We may need to verify your identity. We respond without undue delay and at the latest within one month; where a request is complex we may extend by two months and will then tell you why.
If you are a visitor or a contact of one of our customers — address the customer (see 3.2).
Complaints. You always have the right to lodge a complaint with the supervisory authority:
Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection Box 8114, 104 20 Stockholm, Sweden imy@imy.se — +46 8 657 61 00 — imy.se
14. Children
ANVL is a service for businesses and is not directed at children. We do not knowingly collect personal data from people under 18. If we learn that an account belongs to a child, we erase the data.
15. Transfers to third countries
Our database, our servers and our uploaded files are held by Oderland Webbhotell AB in Gothenburg, Sweden. Several of our sub-processors — chiefly the AI providers and Google — process data in the USA. Such transfers are made on the basis of
- the European Commission's Standard Contractual Clauses (SCC), module 2 (controller to processor), decision 2021/914, and
- the EU–US Data Privacy Framework where the provider is certified,
together with supplementary safeguards: encryption in transit, data minimisation, and no training on your content.
You may request a copy of the safeguards we apply via privacy@anvl.work.
16. Links and integrations
ANVL may link to or integrate with services we do not control — Google, social platforms, domain and email providers, and the websites you ask our agents to analyse. When you use such a service, their privacy policy applies. We are not responsible for how they process your data.
17. Changes to this policy
We update the policy when the service, the law or our suppliers change. The latest version is always at anvl.work/privacy with the update date at the top.
For material changes — those that reduce your rights or extend the purposes — we notify you by email or by a notice in the product at least 30 days before they take effect.
18. Contact
| Item | Contact |
|---|---|
| Controller | Dalarna Digital Marketing Agency AB, company registration number 556942-8427 |
| Address | Slaggatan 13, 791 71 Falun, Sweden |
| Data protection enquiries | privacy@anvl.work |
| Security incidents | security@anvl.work |
| General enquiries | hi@anvl.work |
| Data protection officer | None appointed — see 18.1. |
18.1 Data protection officer
We have no data protection officer, and that is a considered decision rather than an oversight. We assessed Art. 37(1) GDPR on 2026-08-31:
- 37(1)(a) — we are not a public authority or body.
- 37(1)(b) — our core activity is developing the platform, not regular and systematic monitoring of people on a large scale. We carry out no behavioural analysis and no automatic profiling of individuals.
- 37(1)(c) — we do not process sensitive data on a large scale. The service is built for design and content, and we never ask for such data (see 4.6).
The decision is reassessed on three events: when the platform moves from closed beta to general availability, when the number of active users means the processing could be regarded as "large scale", or if the service begins to store or analyse sensitive personal data. The assessment is documented internally and signed by the company's owner.
19. Severability
Should any provision be found invalid or unenforceable, it shall be interpreted so as to achieve its purpose as closely as possible. The remaining provisions apply unchanged.
20. Governing law
Swedish law applies to this policy and to the processing of personal data in ANVL, together with the GDPR and other applicable EU law.