Last updated: 2026
This describes real data flows for the ANTON platform, but has not been reviewed by a lawyer. Have it checked against your actual processing activities before relying on it for compliance purposes.
ANTON is operated by:
Agile Networks Technologies GmbH
Kennedyallee 113, 60596 Frankfurt am Main, Germany
Email: [email protected]
Data Protection Officer: [email protected]
For data your organization enters into ANTON about its own leads and contacts, your organization is the data controller and Agile Networks Technologies GmbH acts as processor on its behalf (see a separate Data Processing Agreement where applicable). For your own account data (name, email, login activity), Agile Networks Technologies GmbH is the controller.
Account data (name, work email, password hash, login timestamps), data your organization enters into the Service (leads, deals, outreach drafts, uploaded documents), and standard technical logs (IP address, timestamps, user-agent) for security and reliability.
We process this data to perform our contract with your organization (Art. 6(1)(b) GDPR) — providing and operating the Service, authenticating you, sending account-related notifications — and, where applicable, on the basis of our legitimate interest (Art. 6(1)(f) GDPR) in keeping the Service secure and reliable. Where your organization configures an AI feature (e.g. outreach draft generation), the specific request content is sent to the AI provider your organization selected (OpenAI or Anthropic) strictly to produce the result requested — this only happens for tenants who have opted into that feature.
ANTON is multi-tenant: your organization's data is logically isolated from every other organization's data and is never shared across tenants.
We use sub-processors for hosting, email delivery, and — only when your organization has configured it — an AI provider (OpenAI, L.L.C. or Anthropic, PBC, both US-based). Where data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. We do not sell personal data.
We retain personal data for as long as your account is active, or as needed to provide the Service. You may request erasure of your personal data; see our GDPR page for how to exercise this right.
We apply reasonable technical and organizational measures to protect personal data, including encryption of sensitive fields at rest and access controls scoped to your organization.
Under the GDPR, you have the right to access, rectify, erase, restrict or object to processing, and receive your data in a portable format. Contact your workspace administrator, or [email protected] directly, to exercise these rights. You also have the right to lodge a complaint with a supervisory authority — in Germany, the competent authority for Hesse is the Hessischer Beauftragter für Datenschutz und Informationsfreiheit.
We may update this policy from time to time. Material changes will be announced through the Service.
We use only strictly-necessary cookies to keep you signed in. See our Cookie Policy.