LEGAL / 01
Privacy & GDPR
Data Protection Notice · Last updated: 27 September 2026
This Privacy Policy explains how the operator of Whispering Instruments, developed and operated under the Anumys brand (“Anumys”, “we”, “us” or “our”), collects and uses personal data when you visit our website, create an account, purchase or download software, activate a licence, contact Support, submit a review, subscribe to communications, or use our AI shopping assistant. Our separate AI Transparency Notice explains when you are interacting with AI.
1. Who is responsible for your data?
The data controller within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) is:
AnumysTrading as Anumys / Whispering Instruments
Hungary, 2421 Nagyvenyim, Fűzfa 2.
Registration number: 62567297
Tax number: 92214442-1-27
Email: support@anumys.eu
Telephone: +36 20 320 6053
For privacy questions or to exercise a GDPR right, contact us at the email address above. No data protection officer contact has been designated for this service; you may contact the supervisory authority directly if you prefer.
2. Scope of this policy
This policy applies to the Whispering Instruments webshop, product pages, checkout pages, account pages, the public Wishmaster idea board, Support and Tickets pages, the LicenseServer API and admin-operated email delivery connected to these services. It also applies to the software activation and deactivation requests sent by supported applications.
External services such as payment providers, social-login providers, hosting providers, email providers, YouTube and OpenAI may process personal data under their own privacy notices. Their role depends on the service: some process data for us under instructions, while payment, social-login and video providers may also act as independent controllers for their own services.
3. What personal data do we process?
We apply data minimisation and process only the information reasonably required for the relevant purpose. Depending on how you use the services, this may include:
- Account and identity data: email address, display name, password hash, email-verification status, social-login provider and provider account identifier.
- Billing data: legal name, first and last name, company name, billing address, country, VAT or tax identifiers and related billing-profile information.
- Order and payment data: order identifier, purchased product or bundle, quantity, currency, amounts, payment-provider identifiers, payment status, fulfilment status and refund status. Payment-card details are handled by the selected payment provider and are not stored by the Shop database.
- Licence data: licence key, application/product, licence status, expiry, activation limit, activation count and the licence group belonging to a bundle.
- Activation and technical data: machine identifier, application identifier, operating system or product format where provided, IP address, request timestamps and allowed/denied licence-check results.
- Support data: ticket subjects, messages, status, notification preferences and your optional choice about AI-assisted ticket replies. Messages sent to support@anumys.eu are also processed with AI assistance as described below; this can include personal data you put in the message. For support without the AI agent, contact noaisupport@anumys.eu.
- Review data: displayed name, rating, review text, product, publication status and timestamps. Reviews are shown publicly only according to the publication rules of the service.
- Wishmaster data: the title, description, requested platform(s), idea type and optional non-binding willingness-to-pay amount you submit; your acceptance of the Wishmaster Community Terms; and, if you report a wish, your name, email, good-faith confirmation, selected reason and explanation. Published wishes can be read by visitors; the author's account name and email and a reporter's contact details are not shown publicly. A purpose-specific keyed HMAC derived from the IP address limits each network address to one vote and one report per wish; the raw IP address is not saved in the wish-voting or reporting tables. Reports, review status and moderation reasons are available to authorised administrators.
- Communication data: newsletter and product-update subscription choices, email delivery status and communication preferences.
- Legal request data: the name, email, order reference, product, declaration and submission time provided through the online withdrawal form, plus the receipt and case correspondence.
- Security and operational data: session identifiers stored in protected cookies, CSRF-related values, authentication events, rate-limit/security events and server logs.
- Website visitor-count data: a keyed HMAC derived from the client IP address and the first-seen time, used to avoid counting repeat requests from the same IP. The raw IP address is not saved in the visitor-counter tables. Wishmaster feedback uses a separately scoped keyed HMAC to recognise a repeat vote on an individual wish; raw IP addresses are not saved in the wish-voting table.
- Temporary basket data: product identifiers, selected product options and basket count stored in the browser session to keep your requested checkout basket available while that session remains open.
- AI assistant data: the questions and conversation content you voluntarily submit to the website assistant, together with limited technical context needed to answer and protect the service. Do not submit passwords, licence keys, payment details or other unnecessary personal data to the assistant.
4. How do we collect data?
- directly from you when you create or update an account, place an order, open a ticket, submit a review or wish, vote on an idea, or choose communication preferences;
- from payment and fulfilment providers when an order, refund or fulfilment event is reported;
- from social-login providers when you authorise a login and the provider returns the requested profile information;
- from the application or plugin when it sends a licence activation, deactivation or verification request;
- from FastSpring or another configured checkout provider when it reports orders, refunds or fulfilment events;
- automatically from your browser or device through essential cookies, security logs and standard HTTP request data.
5. Purposes and GDPR legal bases
For each processing activity we rely on an applicable legal basis under Article 6 GDPR. We do not make the provision of a purchase conditional on consenting to unrelated marketing.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Account creation, login and account security | Email, display name, password hash, session and security data | Contract performance; legitimate interest in security; legal obligation where applicable |
| Order processing, payment, fulfilment and licence delivery | Billing, order, provider, product and licence data | Contract performance; legal obligation for accounting and tax records |
| Licence activation, deactivation and fraud prevention | Licence, application, machine, IP and usage data | Contract performance; legitimate interest in preventing misuse and protecting software |
| Human customer support and ticket notifications | Email, ticket messages, status and notification choice | Contract performance or pre-contractual steps; our legitimate interest in handling support requests and sending requested service updates |
| Optional AI-assisted ticket replies | Only the latest customer message text for a ticket where you have enabled AI assistance | Your consent (GDPR Article 6(1)(a)). AI consent is optional; you can open a ticket without it and turn it off at any time. |
| AI-assisted processing of emails sent to support@anumys.eu | The email content and personal data you include in it, as needed to handle your request | Our legitimate interest in triaging and responding to support requests efficiently (GDPR Article 6(1)(f)); you can object by using the AI-free support address noaisupport@anumys.eu. |
| Product reviews | Product, displayed name, rating and review text | Contract-related eligibility check; consent/publication choice for displaying the review |
| Publish and organise Wishmaster ideas | Wish title, description, platform, type and optional willingness-to-pay signal | Steps taken at your request and our legitimate interest in planning useful products; publication is part of the community board you choose to use |
| Limit repeated Wishmaster feedback and reports | A separate purpose-scoped keyed HMAC derived from the IP address for each wish; vote and report details are stored separately | Legitimate interest in keeping feedback useful, handling content concerns and limiting repeat activity; no raw IP address is stored in the wish-voting or reporting tables |
| Review Wishmaster reports and moderate posts | Reporter name and email, report reason and explanation, wish content, report and moderation status, decision reason and timestamps | Legitimate interest in protecting users and enforcing the Wishmaster Community Terms; legal obligation where applicable |
| Newsletter and product-update messages | Email and subscription preference | Consent; unsubscribe is available at any time. Transactional messages rely on contract performance or legal obligation. |
| Essential cookies, technical logs and service protection | Session, CSRF, IP, browser and request data | Legitimate interest in providing a secure service; contract performance for requested account features |
| Display an aggregate unique-IP visitor count | Keyed HMAC of the client IP address and first-seen time | Legitimate interest in showing the website’s approximate reach and preventing repeat page loads from increasing the count |
| Automated-abuse prevention on the withdrawal form, when Turnstile is enabled | Client IP, browser/device security signals and a one-time verification token/result | Our legitimate interest in protecting the legal-request form, API and email system from automated abuse |
| Delivery of externally hosted web fonts | IP address, browser information and requested font resource | Legitimate interest in providing a consistent website presentation |
| AI shopping assistance | Questions and limited conversation context | Responding to a product or pre-contract question you submit; otherwise our legitimate interest in answering product questions; legitimate interest in preventing abuse |
| Handling a consumer withdrawal notice | Name, email, order reference, product and the withdrawal statement | Compliance with consumer-protection law; establishing, exercising or defending legal claims |
6. Payments, checkout and external providers
Checkout may be provided through FastSpring or another configured payment provider. The provider may collect payment, billing, fraud-prevention and tax information directly. We receive the order and fulfilment information required to provide the purchased product, issue licences, send transactional emails and handle refunds.
When enabled, the withdrawal form uses Cloudflare Turnstile to help prevent automated abuse. Cloudflare processes browser and device security signals for this purpose; our API sends the client IP address and the one-time verification token to Cloudflare for server-side validation. This integration does not send your name, email address, order reference or withdrawal statement to Cloudflare. See Cloudflare’s Turnstile Privacy Addendum.
If Gumroad or another sales channel is enabled, that provider may send order, sale, refund and licence-verification events to the LicenseServer. We use those events only to reconcile purchases, provide entitlements and protect against duplicate or fraudulent fulfilment. Review the provider’s own privacy notice before completing a purchase through that provider.
Social login is optional. When you choose Google, GitHub, X, Apple, Amazon or PayPal, the selected provider may receive your request and return an identifier and, where available and authorised, your email address and basic profile information. We do not use a social provider as a substitute for your internal account record.
7. AI assistant and OpenAI
The website may offer an AI assistant to help with product questions and checkout guidance. When you submit a question, its text and the limited conversation context required to answer it may be sent to OpenAI through our server-side integration. The assistant is not authorised to access your private account, order, payment or licence state, and it cannot place an order or change an account.
AI-assisted support replies are a separate, optional feature. You can open and use a support ticket without enabling it. If you enable it, a support agent must still choose to run the documentation assistant; only the text of the latest customer message in that ticket is sent to OpenAI. The integration does not attach your ticket subject, account ID, email address or profile fields, but the message is sent as written, so please do not include personal contact details, passwords, licence keys or payment data. The generated response is labelled as AI-generated and is not human-reviewed before sending; the assistant may close the ticket if your message clearly says the issue is resolved. You can turn off permission for future AI processing from the ticket at any time; this does not recall text already sent.
Emails sent to support@anumys.eu are processed with the help of Anumys’s AI support agent to classify and summarise your request and help prepare a response. The agent processes the email as sent, including personal data you choose to include, through the AI service provider configured for that workflow. If you do not want AI-assisted handling, write to noaisupport@anumys.eu; that address is for support handled without the AI agent. Please do not send passwords, licence keys, payment details or unnecessary personal data. AI-generated assistance can be inaccurate and is not used to decide your purchase, refund eligibility, licence entitlement or legal rights.
The website assistant and the optional ticket-assistance feature use OpenAI’s Responses API with persistent response storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default, but API abuse-monitoring logs may contain prompts and responses and are generally retained for up to 30 days unless a longer period is legally required. The website assistant searches product documentation in Anumys’s own knowledge service at ai.anumys.eu. Search questions and limited recent user context may be processed there with OpenAI for query rewriting and embeddings. Optional ticket assistance may store product documentation in its separately configured OpenAI vector store until Anumys removes it; we do not intentionally place customer account records, payment details or licence keys in that knowledge base. OpenAI’s current API data controls and Data Processing Addendum describe its processing and transfer safeguards. The assistant may be unavailable or may provide an incomplete answer; product terms, checkout information and human Support remain authoritative.
8. Cookies and similar technologies
We use cookies and comparable storage technologies in the following categories:
- Strictly necessary: session cookies, CSRF protection and the cookie-notice preference. These are required for login, account security and requested webshop functionality.
- Preference storage: local browser storage remembers when you dismiss the cookie notice. It is not a cookie and can be cleared in your browser.
- First-party visitor counter and Wishmaster voting/reporting: the footer shows an aggregate count of distinct IP addresses. Wishmaster uses separate, purpose-scoped keyed HMACs to limit each IP to one vote and one report on a wish. Reporting does not require an account, but it asks for a name, email, reason and explanation. The IP matching itself does not use a tracking cookie or browser storage; submitting a vote or report uses the necessary CSRF security cookie described in our Cookie Notice. The raw IP is not saved in the counter, wish-voting or wish-reporting tables. An IP address is not the same as a person: people sharing a network may share one vote or report, and a changed IP may be counted separately. Three pending reports from distinct IP-based fingerprints temporarily hide a wish for review; this is a precaution, not a finding of wrongdoing.
- Third-party video: an embedded YouTube demonstration player is loaded only when you choose to play the video. At that point, your browser connects to YouTube/Google and may disclose technical data such as your IP address, browser information and the video request. YouTube’s own privacy terms then apply.
- External fonts: the home page and pages using the music stylesheet, including product and legal pages, load fonts from Google Fonts. Your browser requests font styles and files from Google servers, which receive ordinary connection data such as your IP address, browser and requested resource. Anumys does not set a cookie for this purpose. See Google’s privacy information.
- Advertising and third-party analytics: the core storefront does not currently use advertising cookies or third-party analytics tools. Any future non-essential tracking technology will be described here and activated only after any consent required by law.
You can delete or block cookies through your browser. Blocking strictly necessary cookies may prevent login, account features, checkout or other requested functions from working correctly. See our Cookie Notice.
9. Who may receive personal data?
We disclose personal data only when necessary for a stated purpose, under a contract or data-processing arrangement where required, or where disclosure is required by law. Categories of recipients may include:
- hosting, infrastructure, database, security and domain providers;
- Cloudflare when Turnstile is enabled on the withdrawal form, for bot and abuse prevention;
- payment, checkout, tax, fraud-prevention and sales-channel providers;
- email delivery and customer-support providers;
- social-login providers when you select social login;
- Google Fonts when you visit the home page or a page using the music stylesheet, which receives the technical data needed to deliver externally hosted font files; see Google’s privacy information;
- the AI service provider configured for support-email processing when the AI support agent is used;
- OpenAI when you submit a question to the website assistant, or when you have enabled optional AI ticket assistance and a support agent chooses to process a ticket message;
- YouTube/Google when you choose to play an embedded demonstration video;
- FastSpring when it provides checkout, payment, order, refund or fulfilment services;
- the email delivery provider used to send account, support, legal-request and transactional messages;
- professional advisers, auditors, insurers, courts, regulators and law-enforcement authorities where necessary and lawful.
We do not sell personal data. When a provider acts as our processor, we require it to process personal data only for our documented purposes and under the applicable data-processing terms. Providers acting as independent controllers handle data under their own privacy notices.
10. International transfers
Some providers may process data outside the European Economic Area. This may include Google when externally hosted fonts are requested, OpenAI when an AI feature is used, or the AI provider configured for the support-email agent. Before using such a provider, we assess the transfer mechanism and safeguards required by GDPR Chapter V, such as an adequacy decision, Standard Contractual Clauses and, where appropriate, supplementary technical or organisational measures. Contact us if you want information about the safeguards applicable to a particular provider.
11. Data retention
We retain personal data only for the period needed for the stated purpose, and then delete or anonymise it unless a legal obligation or a legal claim requires retention. For statutory accounting records we apply the Hungarian Accounting Act: accounting vouchers are retained for at least eight years, and the accounting records listed in section 169(1) for at least ten years. Tax records are retained for the period required by the applicable tax rules. The current criteria for other data are:
- account, order, licence and support records, including support emails and any AI-assisted summaries or replies: while the request is being handled and afterwards for the period needed to document the outcome, prevent fraud or establish, exercise or defend legal claims; formal written consumer-complaint records and response copies are kept for three years as required by Hungarian consumer-protection law;
- billing and invoice records: at least eight years when they are accounting vouchers, and longer where another accounting or tax rule requires it;
- authentication tokens: until consumed or expired, followed by secure deletion or anonymisation;
- security and technical logs: for the shortest period reasonably necessary for security, troubleshooting and legal claims;
- newsletter and update subscriptions: until you unsubscribe or the purpose ends, with evidence of consent retained where necessary to demonstrate compliance;
- Wishmaster ideas, platform selections, terms-acceptance evidence, reports and moderation records: while the wish and its moderation record remain stored or until the associated account is deleted; deleting the account removes its wishes and linked reports. Report and vote HMACs are kept with the wish and deleted with it; deleting a wish or rotating the IP-fingerprint key may allow later activity from that address to be counted separately;
- visitor-counter HMAC hashes: while the lifetime counter is active, so repeat visits from an IP are not counted again; the raw IP address is not stored in the counter tables. Rotating the counter key or deleting these hashes can cause an IP to be counted again;
- Website-assistant questions are not stored as an account conversation by the website. Support tickets and emails remain in the relevant support systems; a ticket AI reply is processed by OpenAI only when you enabled that optional feature and an agent starts it, while emails sent to support@ are processed with the AI-assisted handling described above. The noaisupport@ route is not sent to the AI support agent. AI output may be inaccurate. Evidence of ticket AI-consent changes is recorded in the security/audit log. Support messages, relevant AI-assisted summaries or replies, consent evidence and legal withdrawal requests are kept while they are handled and for the period needed to document the outcome or defend a legal claim.
The applicable accounting periods are set by section 169 of Act C of 2000 on Accounting. Non-accounting data are not assigned a single fixed period where the necessary duration depends on the request, licence, security event or legal claim.
12. Security
We use proportionate technical and organisational measures, including authenticated HTTPS between the Shop and LicenseServer, HTTP-only session cookies, CSRF protection, input validation, rate limiting, security headers, access control, password hashing, least-privilege database access, backups and audit logging where appropriate. No internet transmission or storage system can be guaranteed to be completely secure.
We do not ask you to send passwords or payment-card details by email or support ticket. If you suspect unauthorised access, contact us immediately through the Support page and change any reused password.
13. Your GDPR rights
Subject to the conditions and exceptions in GDPR Articles 15–22, you may have the right to:
- receive clear information about processing;
- access a copy of personal data we hold about you;
- rectify inaccurate or incomplete information;
- request erasure (“right to be forgotten”);
- request restriction of processing;
- object to processing based on legitimate interests, including direct marketing;
- receive portable data where the legal conditions are met;
- withdraw consent at any time, without affecting processing that took place before withdrawal;
- object to direct marketing at any time; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where a GDPR exception applies.
You can manage profile data and communication preferences in your Account page, change optional ticket AI permission in the relevant ticket, or object to AI-assisted processing of support emails by writing to noaisupport@anumys.eu. You can also unsubscribe from marketing emails through the unsubscribe link, or contact the controller for access, correction, deletion, export or restriction. These choices apply to future processing and do not undo processing that already took place. We may request only the additional information reasonably needed to verify identity and protect the account. We respond without undue delay and normally within one month; where the GDPR permits an extension for complex or numerous requests, we will tell you within the first month and explain why.
Account deactivation does not automatically erase records that we must retain for a legal obligation, an active licence entitlement, security, fraud prevention, dispute resolution or the establishment, exercise or defence of legal claims. Where possible, retained records are restricted, anonymised or separated from active account use.
14. Children
The services are intended for adults and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.
15. Changes to this policy
We may update this policy when the services, providers, legal requirements or processing purposes change. The “Last updated” date will be changed when the policy is revised. If a change materially affects your rights or the purposes of processing, we will provide an appropriate notice and, where required, obtain consent before the new processing begins.
16. Complaints and supervisory authority
You may contact us first so we can try to resolve your concern, but this is not a condition for contacting a supervisory authority. You may lodge a complaint with the authority in your habitual residence, place of work or the place of the alleged infringement. The Hungarian authority is the National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9–11, Hungary; postal address 1363 Budapest, Pf. 9; email ugyfelszolgalat@naih.hu; phone +36 (1) 391-1400. See NAIH contact and complaint information.
17. Contact
For privacy requests, data-protection questions or a complaint, use:
Anumys
Privacy contact: support@anumys.eu
General Support: Support
Account and deletion information: User Data Deletion