LEGAL / 01

Privacy & GDPR

Data Protection Notice · Last updated: 27 September 2026

This Privacy Policy explains how the operator of Whispering Instruments, developed and operated under the Anumys brand (“Anumys”, “we”, “us” or “our”), collects and uses personal data when you visit our website, create an account, purchase or download software, activate a licence, contact Support, submit a review, subscribe to communications, or use our AI shopping assistant. Our separate AI Transparency Notice explains when you are interacting with AI.

1. Who is responsible for your data?

The data controller within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) is:

For privacy questions or to exercise a GDPR right, contact us at the email address above. No data protection officer contact has been designated for this service; you may contact the supervisory authority directly if you prefer.

2. Scope of this policy

This policy applies to the Whispering Instruments webshop, product pages, checkout pages, account pages, the public Wishmaster idea board, Support and Tickets pages, the LicenseServer API and admin-operated email delivery connected to these services. It also applies to the software activation and deactivation requests sent by supported applications.

External services such as payment providers, social-login providers, hosting providers, email providers, YouTube and OpenAI may process personal data under their own privacy notices. Their role depends on the service: some process data for us under instructions, while payment, social-login and video providers may also act as independent controllers for their own services.

3. What personal data do we process?

We apply data minimisation and process only the information reasonably required for the relevant purpose. Depending on how you use the services, this may include:

4. How do we collect data?

5. Purposes and GDPR legal bases

For each processing activity we rely on an applicable legal basis under Article 6 GDPR. We do not make the provision of a purchase conditional on consenting to unrelated marketing.

6. Payments, checkout and external providers

Checkout may be provided through FastSpring or another configured payment provider. The provider may collect payment, billing, fraud-prevention and tax information directly. We receive the order and fulfilment information required to provide the purchased product, issue licences, send transactional emails and handle refunds.

When enabled, the withdrawal form uses Cloudflare Turnstile to help prevent automated abuse. Cloudflare processes browser and device security signals for this purpose; our API sends the client IP address and the one-time verification token to Cloudflare for server-side validation. This integration does not send your name, email address, order reference or withdrawal statement to Cloudflare. See Cloudflare’s Turnstile Privacy Addendum.

If Gumroad or another sales channel is enabled, that provider may send order, sale, refund and licence-verification events to the LicenseServer. We use those events only to reconcile purchases, provide entitlements and protect against duplicate or fraudulent fulfilment. Review the provider’s own privacy notice before completing a purchase through that provider.

Social login is optional. When you choose Google, GitHub, X, Apple, Amazon or PayPal, the selected provider may receive your request and return an identifier and, where available and authorised, your email address and basic profile information. We do not use a social provider as a substitute for your internal account record.

7. AI assistant and OpenAI

The website may offer an AI assistant to help with product questions and checkout guidance. When you submit a question, its text and the limited conversation context required to answer it may be sent to OpenAI through our server-side integration. The assistant is not authorised to access your private account, order, payment or licence state, and it cannot place an order or change an account.

AI-assisted support replies are a separate, optional feature. You can open and use a support ticket without enabling it. If you enable it, a support agent must still choose to run the documentation assistant; only the text of the latest customer message in that ticket is sent to OpenAI. The integration does not attach your ticket subject, account ID, email address or profile fields, but the message is sent as written, so please do not include personal contact details, passwords, licence keys or payment data. The generated response is labelled as AI-generated and is not human-reviewed before sending; the assistant may close the ticket if your message clearly says the issue is resolved. You can turn off permission for future AI processing from the ticket at any time; this does not recall text already sent.

Emails sent to support@anumys.eu are processed with the help of Anumys’s AI support agent to classify and summarise your request and help prepare a response. The agent processes the email as sent, including personal data you choose to include, through the AI service provider configured for that workflow. If you do not want AI-assisted handling, write to noaisupport@anumys.eu; that address is for support handled without the AI agent. Please do not send passwords, licence keys, payment details or unnecessary personal data. AI-generated assistance can be inaccurate and is not used to decide your purchase, refund eligibility, licence entitlement or legal rights.

The website assistant and the optional ticket-assistance feature use OpenAI’s Responses API with persistent response storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default, but API abuse-monitoring logs may contain prompts and responses and are generally retained for up to 30 days unless a longer period is legally required. The website assistant searches product documentation in Anumys’s own knowledge service at ai.anumys.eu. Search questions and limited recent user context may be processed there with OpenAI for query rewriting and embeddings. Optional ticket assistance may store product documentation in its separately configured OpenAI vector store until Anumys removes it; we do not intentionally place customer account records, payment details or licence keys in that knowledge base. OpenAI’s current API data controls and Data Processing Addendum describe its processing and transfer safeguards. The assistant may be unavailable or may provide an incomplete answer; product terms, checkout information and human Support remain authoritative.

8. Cookies and similar technologies

We use cookies and comparable storage technologies in the following categories:

You can delete or block cookies through your browser. Blocking strictly necessary cookies may prevent login, account features, checkout or other requested functions from working correctly. See our Cookie Notice.

9. Who may receive personal data?

We disclose personal data only when necessary for a stated purpose, under a contract or data-processing arrangement where required, or where disclosure is required by law. Categories of recipients may include:

We do not sell personal data. When a provider acts as our processor, we require it to process personal data only for our documented purposes and under the applicable data-processing terms. Providers acting as independent controllers handle data under their own privacy notices.

10. International transfers

Some providers may process data outside the European Economic Area. This may include Google when externally hosted fonts are requested, OpenAI when an AI feature is used, or the AI provider configured for the support-email agent. Before using such a provider, we assess the transfer mechanism and safeguards required by GDPR Chapter V, such as an adequacy decision, Standard Contractual Clauses and, where appropriate, supplementary technical or organisational measures. Contact us if you want information about the safeguards applicable to a particular provider.

11. Data retention

We retain personal data only for the period needed for the stated purpose, and then delete or anonymise it unless a legal obligation or a legal claim requires retention. For statutory accounting records we apply the Hungarian Accounting Act: accounting vouchers are retained for at least eight years, and the accounting records listed in section 169(1) for at least ten years. Tax records are retained for the period required by the applicable tax rules. The current criteria for other data are:

The applicable accounting periods are set by section 169 of Act C of 2000 on Accounting. Non-accounting data are not assigned a single fixed period where the necessary duration depends on the request, licence, security event or legal claim.

12. Security

We use proportionate technical and organisational measures, including authenticated HTTPS between the Shop and LicenseServer, HTTP-only session cookies, CSRF protection, input validation, rate limiting, security headers, access control, password hashing, least-privilege database access, backups and audit logging where appropriate. No internet transmission or storage system can be guaranteed to be completely secure.

We do not ask you to send passwords or payment-card details by email or support ticket. If you suspect unauthorised access, contact us immediately through the Support page and change any reused password.

13. Your GDPR rights

Subject to the conditions and exceptions in GDPR Articles 15–22, you may have the right to:

You can manage profile data and communication preferences in your Account page, change optional ticket AI permission in the relevant ticket, or object to AI-assisted processing of support emails by writing to noaisupport@anumys.eu. You can also unsubscribe from marketing emails through the unsubscribe link, or contact the controller for access, correction, deletion, export or restriction. These choices apply to future processing and do not undo processing that already took place. We may request only the additional information reasonably needed to verify identity and protect the account. We respond without undue delay and normally within one month; where the GDPR permits an extension for complex or numerous requests, we will tell you within the first month and explain why.

Account deactivation does not automatically erase records that we must retain for a legal obligation, an active licence entitlement, security, fraud prevention, dispute resolution or the establishment, exercise or defence of legal claims. Where possible, retained records are restricted, anonymised or separated from active account use.

14. Children

The services are intended for adults and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.

15. Changes to this policy

We may update this policy when the services, providers, legal requirements or processing purposes change. The “Last updated” date will be changed when the policy is revised. If a change materially affects your rights or the purposes of processing, we will provide an appropriate notice and, where required, obtain consent before the new processing begins.

16. Complaints and supervisory authority

You may contact us first so we can try to resolve your concern, but this is not a condition for contacting a supervisory authority. You may lodge a complaint with the authority in your habitual residence, place of work or the place of the alleged infringement. The Hungarian authority is the National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9–11, Hungary; postal address 1363 Budapest, Pf. 9; email ugyfelszolgalat@naih.hu; phone +36 (1) 391-1400. See NAIH contact and complaint information.

17. Contact

For privacy requests, data-protection questions or a complaint, use:

Anumys
Privacy contact: support@anumys.eu
General Support: Support
Account and deletion information: User Data Deletion