Skip to main content

Privacy Policy

Effective date: July 7, 2026

ANANKE Labs ("ANANKE", "we", "us", or "our") operates the ANANKE trust infrastructure platform, including the web application, mobile application (where available), and related services. Integration services are made available only where enabled for an organization. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our services. We aim to be transparent about what we collect, why we collect it, and the choices available to you.

1. Who we are

ANANKE Labs is a trust infrastructure company based in Morocco. We provide digital trust services that help organizations protect, verify, and manage the lifecycle of documents and physical items.

For personal data we collect through our website and platform, ANANKE Labs acts as a data controller. When we process documents or other personal data on behalf of an organization, we act as a data processor under that organization's instructions.

2. Data we collect

We collect and process the following categories of personal data:

Account and identity data

  • Full name, email address, and organization affiliation when an account is created
  • Authentication credentials and related security information (passwords are hashed and never stored in readable form)
  • Role and permission assignments within an organization

Document and item data

  • Documents uploaded to the platform and the metadata needed to process and verify them
  • Document titles, template configurations, lifecycle status, timestamps, and related operational metadata
  • Cryptographic fingerprints (hashes), verification records, and audit trail data
  • T-CODE identifiers and associated metadata for physical items

Usage and technical data

  • IP address, browser type, device information, operating system, and request timestamps
  • Pages visited, features used, and actions performed within the platform
  • API and application logs used for security, troubleshooting, and service reliability
  • Public-site analytics and performance telemetry only when you consent on the marketing site

Communication data

  • Information you provide when contacting us by email, form, or support channel
  • Feedback, questions, and correspondence related to your use of the services

3. How we use your data

We process personal data for the following purposes:

  • Providing and operating the ANANKE platform, including document protection, verification, lifecycle management, and T-CODE workflows
  • Authenticating users and managing access to organization workspaces
  • Generating cryptographic proofs, verification records, and audit trails
  • Maintaining service security, preventing abuse, investigating incidents, and troubleshooting technical issues
  • Sending service-related communications, including security notices and operational updates
  • Improving the performance, usability, and reliability of our website and services
  • Complying with legal obligations, responding to lawful requests, and establishing or defending legal claims

5. Data sharing and third parties

We do not sell your personal data. We share data only in the limited situations described below:

  • Service providers - we use third-party providers for hosting, infrastructure, delivery, monitoring, support, and related technical operations under contractual obligations
  • Analytics and performance providers - on the public marketing site only, and only after consent, we may use limited analytics and performance measurement providers to understand traffic and site reliability
  • External verification records - where our services generate external trust references, we publish only non-personal verification references and never publish document contents
  • Legal requirements - we may disclose data when required by law, court order, or regulatory authority, or when necessary to protect the rights, property, or safety of ANANKE Labs, our users, or the public
  • With your consent - we may share data with a third party when you have explicitly asked us to do so or consented to a specific use

6. Data retention

We retain personal data only for as long as necessary for the purposes described in this policy, unless a longer retention period is required by law.

Account data is retained while the account remains active and for up to three years after account closure for security, compliance, continuity, and account recovery purposes.

Document data, verification records, cryptographic hashes, and audit trails are retained for as long as required to preserve verification integrity and meet contractual requirements. For anchored trust records, this retention may be indefinite — the long-term verifiability of issued records is a core property of the service.

Operational logs and technical records are retained for up to twelve months for security, troubleshooting, and service improvement, then deleted or anonymized.

Browser-stored preferences or draft data remain in your browser until they expire, are overwritten, or are removed by you or your browser.

7. Your rights

Depending on the laws that apply to you, you may have the following rights regarding your personal data:

  • Right of access - request a copy of the personal data we hold about you
  • Right to rectification - ask us to correct inaccurate or incomplete data
  • Right to erasure - request deletion of personal data, subject to legal, security, and verification-retention requirements
  • Right to restriction - ask us to limit processing in certain circumstances
  • Right to data portability - request your data in a structured, machine-readable format where applicable
  • Right to object - object to processing based on legitimate interests where applicable
  • Right to withdraw consent - withdraw consent at any time for processing that depends on consent, including marketing-site analytics

To exercise these rights, contact us at privacy@anankelabs.net. We will review and respond in accordance with applicable law.

If you are not satisfied with our response, and depending on the laws applicable in your jurisdiction, you may have the right to lodge a complaint with the competent data protection supervisory authority in your country.

8. How we protect your data

We apply technical and organizational measures designed to protect personal data and the integrity of the ANANKE platform.

  • Encryption in transit: all communication between the platform and its services is protected by TLS
  • Encryption at rest: object storage uses server-side encryption managed through a dedicated key management service; database-level field encryption for sensitive personal data is designed into the platform
  • Isolated key management: signing keys are held outside the application database in a dedicated key management service
  • Role-based access controls and organization-level data separation enforced at the database layer
  • API keys hashed with Argon2id; raw keys shown once at creation and never stored in readable form
  • Secure session handling with cryptographically signed tokens and automatic expiration
  • Audit trails for security-relevant events
  • Restricted and monitored access to production systems

9. Cookies, local storage, and analytics

Our website and platform use essential cookies and similar browser storage needed for the service to function. Depending on the part of the product you use, this can include session cookies, authentication cookies, locale preferences, theme preferences, and interface state preferences.

Parts of the platform may also store limited draft or preference data in your browser's local storage to improve usability and reduce accidental data loss.

On the public marketing site only, we enable limited analytics and performance measurement only after you accept the consent notice. These tools help us measure visits, referrers, device and browser characteristics, and page performance in aggregated form.

We do not use third-party advertising cookies, and we do not use cross-site advertising trackers.

10. International data transfers

ANANKE Labs is based in Morocco, and some of our service providers may process data in other jurisdictions.

When personal data is transferred to countries that do not benefit from an adequacy decision, we seek to use appropriate transfer mechanisms, including standard contractual clauses where applicable.

Where external trust references are generated, they are designed to avoid publishing personal data or document contents.

11. Children's privacy

Our services are designed for organizations and their authorized users. We do not knowingly target or collect personal data from children through our services. If you believe a child has provided us with personal data, contact us at privacy@anankelabs.net.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data practices. When we make material changes, we will update the effective date and post the revised policy on this page.

Your continued use of the services after an updated policy becomes effective means the updated policy applies to your ongoing use, to the extent permitted by law.

13. Contact us

If you have questions about this Privacy Policy or our privacy practices, you can contact us at:

ANANKE Labs
Morocco

Please include "Privacy Request" in the subject line if you are submitting a data rights request. Organizations requiring a Data Processing Agreement (DPA) for compliance with applicable data protection law may request one at legal@anankelabs.net.