Privacy Policy

Last Updated: September 1, 2026

1. Introduction & Overview

This Privacy Policy sets out the principles and practices governing the collection, processing, storage, and disclosure of personal data by Anakrio AS ("Company," "we," "us," or "our"). This policy applies to all visitors, registered users, software applications, APIs, call-to-action (CTA) overlay tools, and shortened link services hosted on or accessed via https://anakrio.com https://anakrio.com(collectively, the "Services").

By accessing our Site or utilizing any of our Services, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. We are fully committed to protecting your fundamental right to privacy and maintaining compliance with all applicable European and international data protection laws, including the General Data Protection Regulation (EU 2016/679) ("GDPR") and the Norwegian Personal Data Act (Personopplysningsloven).

2. Data Controller & Contact Information

Data Controller Identification

Under Article 4(7) of the GDPR, Anakrio AS acts as the primary Data Controller for personal data processed through our platform.

3. Comprehensive Categories of Data We Collect

We process different categories of information depending on whether you are an Account Holder creating short links and bio pages, or an End-User visiting a link routed through our platform.

3.1 Account Holder Data

When you create an account, purchase a subscription, or communicate with us, we collect:

  • Identity & Account Credentials: Usernames, full names, hashed account passwords, profile avatars, and preferred language/localization settings.

  • Contact Details: Primary email address used for account creation, transactional notifications, and system alerts.

  • Financial & Transactional Records: Timestamped logs of purchases, invoice history, payment plan subscriptions, and masked payment tokens provided by our payment gateways (we do not directly process or store raw credit card credentials).

  • Communication Logs: Full record history of support tickets, technical inquiries, and user feedback sent directly to our support inbox or via integrated contact forms.

3.2 End-User / Link Visitor Data

When an end-user clicks a shortened link (e.g., [https://anakrio.com/VNK42o](https://anakrio.com/VNK42o)) or views a bio page hosted on our domain, we process technical telemetry to compile stats for creators and protect our network:

  • Internet Protocol (IP) Address: Collected for security inspection, DDoS mitigation, fraud prevention, and country/city-level geolocation matching.

  • Approximate Geolocation (GEO Data): Derived from the IP address to show creators top geographic regions (e.g., country, region, city) without exposing exact precise physical coordinates.

  • HTTP User-Agent & Device Attributes: Operating system family (iOS, Android, Windows, macOS), browser type, screen resolution, device category (Mobile, Tablet, Desktop), and referral sources (HTTP Referer headers).

  • Click Event Timestamp & Telemetry: Exact time and date of redirection, destination URL hit, and aggregated click volume counts.

3.3 Security, Bot Mitigation & Advertising Data

  • Cloudflare & Cloudflare Turnstile: Processes IP addresses, HTTP headers, TLS fingerprinting data, and user interaction signals to distinguish human traffic from automated bots without requiring intrusive visual CAPTCHAs.

  • Google AdSense: Collects non-personally identifiable identifiers and ad interaction signals to render, measure, and optimize advertising banners displayed across public-facing platform modules.

4. Legal Bases & Purposes for Data Processing

In compliance with Article 6 of the GDPR, every processing activity conducted by Anakrio AS relies on a specific lawful legal basis:

  • Performance of a Contract (GDPR Art. 6(1)(b)): Operating account infrastructure, routing shortened URLs (e.g., [https://anakrio.com/VNK42o](https://anakrio.com/VNK42o)), serving custom bio pages, rendering CTA overlays, and processing billing subscriptions.

  • Legitimate Interests (GDPR Art. 6(1)(f)): Protecting system infrastructure against cyber threats, detecting malware/phishing links, generating aggregated non-identifiable link click statistics for content creators, and improving platform response times.

  • Compliance with Legal Obligations (GDPR Art. 6(1)(c)): Retaining financial records, VAT reports, and invoice logs to fulfill Norwegian statutory accounting and corporate tax regulations.

  • Consent (GDPR Art. 6(1)(a)): Utilizing non-essential cookies, running personalized advertising via Google AdSense, or sending promotional marketing updates where explicitly requested by the user.

5. In-Depth Cookie & Tracking Technology Framework

Cookie Governance & Transparency

Anakrio uses cookies, local storage objects, and session tokens to secure account authentication, remember user dashboard preferences, prevent fraud, analyze traffic trends, and deliver advertising. You may manage, block, or delete cookies at any time via your browser settings or our explicit Cookie Consent Banner.

Comprehensive Cookie Index

CategoryTechnical IdentifierOperational Purpose & Technical FunctionExpiration / Lifespan
Strictly Necessaryanakrio_sessionAuthentication & State: Encrypted session token that maintains your active login state and user preferences as you navigate the control panel.Session / 2 Hours
Strictly NecessaryXSRF-TOKENSecurity Protection: Cross-Site Request Forgery (CSRF) protection token that verifies that form submissions originate from authenticated users.Session
Security & CDNcf_clearance, cf_bmBot Mitigation: Set by Cloudflare to track device reputation and bypass repeated challenge tests once a visitor proves they are human.30 Minutes to 1 Year
Analytics_ga, _ga_*Google Analytics: Generates a randomized unique client ID to calculate session counts, bounce rates, and overall site usability without identifying individuals.2 Years
Analyticsanakrio_click_*In-House Link Tracking: Internal session token ensuring accurate click counts and preventing double-counting rapid multi-clicks on short links.24 Hours
Advertising__gads, __gpiGoogle AdSense: Tracks ad performance, prevents repeating identical ads to the same visitor, and supports ad frequency capping.13 Months

6. Data Sharing, Sub-Processors & Service Providers

We do not sell, rent, or trade personal information under any circumstances. We share data strictly on a need-to-know basis with vetted third-party service providers (Data Processors) under enforceable Data Processing Agreements (DPAs):

  • Payment Infrastructure: Stripe Inc. and PayPal Holdings Inc. handle all payment processing. Financial data is transmitted securely to their PCI-DSS-compliant gateways.

  • CDN, DDoS Defense & Anti-Bot: Cloudflare Inc. operates edge routing, caching, and Cloudflare Turnstile bot verification to shield our platform against cyberattacks.

  • Performance Analytics: Google LLC (Google Analytics) processes anonymized telemetry to provide aggregated user traffic Insights.

  • Advertising Networks: Google LLC (Google AdSense) serves advertising units on eligible pages based on non-sensitive context or user consent choices.

  • Law Enforcement & Statutory Requests: We may disclose data if legally compelled to do so by court orders, search warrants, or formal law enforcement demands issued under valid Norwegian law.

7. International Data Transfers & European Safeguards

Anakrio AS operates primarily out of Norway within the European Economic Area (EEA). Technical infrastructure provided by partners like Cloudflare or Google may process data globally on distributed edge servers.

For any international data transfers occurring outside the EEA/EU to countries without an adequacy decision, Anakrio AS enforces appropriate safeguards under GDPR Chapter V, including:

  • Execution of standard contractual clauses approved by the European Commission (EU Standard Contractual Clauses - SCCs).

  • Technical encryption of data in transit via strict SSL/TLS protocols.

  • Strict organizational access controls and minimization measures.

8. Data Security Measures

Security Infrastructure

We maintain comprehensive technical and organizational safeguards designed to secure personal data against accidental loss, unauthorized access, alteration, and disclosure.

  • End-to-End Transport Encryption: Mandatory HTTPS enforcement across all endpoints using TLS 1.3/1.2 protocols.

  • Self-Hosted Transactional Email Architecture: Transactional emails (password resets, account activations) are routed directly via our proprietary, self-managed SMTP server, preventing email data exposure to third-party email providers.

  • Database Password Hashing: Passwords are cryptographically hashed using industry-standard strong hashing algorithms (bcrypt / Argon2).

  • System Audits & Rate Limiting: Automated rate-limiting algorithms block brute-force attack attempts on login endpoints and API routes.

9. Data Retention & Self-Service Account Erasure

Self-Service Account & Data Deletion

You maintain full control over your personal data. You may permanently delete your account, generated short links, custom bio pages, overlay campaigns, and personal settings at any time directly through your dashboard at:

https://anakrio.com/user/settings

Executing account deletion via this self-service mechanism immediately initiates a purge that permanently removes your profile credentials and user-generated records from our live production databases.

Retention Timelines:

  • Active Accounts: Personal data is retained as long as your user account remains open and operational.

  • Archived Analytics Logs: Raw server click logs, IP lookup references, and user-agent strings are aggregated into non-identifiable statistical metrics and automatically purged on a rolling basis.

  • Accounting & Tax Records: Invoices and transactional logs are retained for up to 5 years to meet statutory tax obligations under Norwegian bookkeeping laws (Bokføringsloven).

  • SMTP Mail Delivery Logs: Server transmission logs are automatically purged every 30 days.

10. Your Rights Under the GDPR

If you are a resident of the EEA, EU, or UK, you enjoy the following enforceable legal rights regarding your personal data:

  • Right to Erasure ("Right to be Forgotten"): Request the complete deletion of your personal data. You can instantly exercise this right via https://anakrio.com/user/settings.

  • Right of Access (Art. 15 GDPR): Request confirmation of whether your data is processed and obtain a copy of your personal records.

  • Right to Rectification (Art. 16 GDPR): Request immediate correction of inaccurate or incomplete personal data.

  • Right to Restrict Processing (Art. 18 GDPR): Request the temporary suspension of data processing under certain legal conditions.

  • Right to Data Portability (Art. 20 GDPR): Request a copy of your personal data in a structured, commonly used, and machine-readable format (JSON/CSV).

  • Right to Object (Art. 21 GDPR): Object to data processing based on legitimate interests or direct marketing activities.

  • Create custom bio pages, shorten long URLs, and generate dynamic QR codes for your Instagram, TikTok, and marketing campaigns.

    Solutions