This statement summarises Anthia's data protection commitments and the practical steps you can take to exercise your rights. It sits alongside our Privacy Policy and Cookie Policy.
Controller
Anthia Operated by Henry Benzikie (sole trader) Oakhurst, Guildford, GU4 7UR United Kingdom
Contact: contact form
We are the data controller for personal data processed through Anthia. Our ICO registration number will be added here once our registration is processed.
Lawful bases
We rely on the following UK GDPR Article 6 lawful bases:
- Article 6(1)(b) Contract performance for the bulk of processing required to give you the service you have signed up to.
- Article 6(1)(f) Legitimate interests for security, fraud detection, abuse handling and aggregate analysis.
- Article 6(1)(a) Consent for optional marketing communications.
- Article 6(1)(c) Legal obligation for tax and accounting record retention.
We do not process special category data in the normal course of providing Anthia. If you choose to put special category data in your notes or your business profile (for example, health information about a wellness business) you do so at your own discretion.
Your rights and how to exercise them
You have the following rights under UK GDPR:
| Right | What it means | How to exercise it | | --- | --- | --- | | Access | Get a copy of the personal data we hold about you | Use our contact form | | Rectification | Correct inaccurate or incomplete data | Edit in Settings, or use our contact form | | Erasure | Have your personal data deleted | Settings > Account > Delete account, or use our contact form | | Restriction | Pause our processing in certain circumstances | Use our contact form | | Portability | Receive your data in a structured, machine-readable format | Use our contact form | | Object | Object to processing based on legitimate interests, including profiling | Use our contact form | | Withdraw consent | Withdraw any consent you have given | Unsubscribe link in emails, or use our contact form | | Complain to the ICO | Lodge a complaint with the supervisory authority | ico.org.uk or 0303 123 1113 |
We will respond to any request within one calendar month. We can extend this by up to two further months for complex requests, in which case we will tell you within the first month.
There is no fee for exercising these rights unless your request is manifestly unfounded or excessive (in which case we may charge a reasonable administrative fee or refuse to act).
Automated decision-making
Anthia uses AI to generate suggestions and content. We do not make decisions about you that produce legal effects or similarly significant effects solely on the basis of automated processing. You decide which suggestions to follow; Anthia is a tool, not a decision-maker.
Data retention
See the retention table in our Privacy Policy. In short: active account data is kept while you have an account and for 30 days afterwards; payment records are kept for 7 years for HMRC purposes; server logs are kept for 30 days.
International transfers
Most of our processing happens in the UK or EU. Some processors are based in the United States. We rely on the UK-US Data Bridge and, where applicable, the UK Addendum to the EU Standard Contractual Clauses. See the Privacy Policy table for the full list and safeguards.
Data breaches
If a data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, we will:
- Notify the ICO within 72 hours of becoming aware of it.
- Notify affected users directly without undue delay where the risk is high.
- Keep a record of all breaches whether or not notifiable, for at least 2 years.
Children
Anthia is not directed at people under 18. We do not knowingly process the data of under-18s. If you believe we have, use our contact form and we will delete it.
Changes
We may update this statement. The "Last updated" date at the top reflects the most recent change.