Last Updated: September 1, 2026
1. Introduction & Overview
This Privacy Policy sets out the principles and practices governing the collection, processing, storage, and disclosure of personal data by Anakrio AS ("Company," "we," "us," or "our"). This policy applies to all visitors, registered users, software applications, APIs, call-to-action (CTA) overlay tools, and shortened link services hosted on or accessed via https://anakrio.com
By accessing our Site or utilizing any of our Services, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. We are fully committed to protecting your fundamental right to privacy and maintaining compliance with all applicable European and international data protection laws, including the General Data Protection Regulation (EU 2016/679) ("GDPR") and the Norwegian Personal Data Act (Personopplysningsloven).
2. Data Controller & Contact Information
Data Controller Identification
Under Article 4(7) of the GDPR, Anakrio AS acts as the primary Data Controller for personal data processed through our platform.
Legal Entity Name: Anakrio AS
Mailing Address: Postboks 60234, 3202 Sandefjord, Norway
Data Protection Contact: support@anakrio.com
Official Website: https://anakrio.com
https://anakrio.com
3. Comprehensive Categories of Data We Collect
We process different categories of information depending on whether you are an Account Holder creating short links and bio pages, or an End-User visiting a link routed through our platform.
3.1 Account Holder Data
When you create an account, purchase a subscription, or communicate with us, we collect:
Identity & Account Credentials: Usernames, full names, hashed account passwords, profile avatars, and preferred language/localization settings.
Contact Details: Primary email address used for account creation, transactional notifications, and system alerts.
Financial & Transactional Records: Timestamped logs of purchases, invoice history, payment plan subscriptions, and masked payment tokens provided by our payment gateways (we do not directly process or store raw credit card credentials).
Communication Logs: Full record history of support tickets, technical inquiries, and user feedback sent directly to our support inbox or via integrated contact forms.
3.2 End-User / Link Visitor Data
When an end-user clicks a shortened link (e.g., [https://anakrio.com/VNK42o](https://anakrio.com/VNK42o)) or views a bio page hosted on our domain, we process technical telemetry to compile stats for creators and protect our network:
Internet Protocol (IP) Address: Collected for security inspection, DDoS mitigation, fraud prevention, and country/city-level geolocation matching.
Approximate Geolocation (GEO Data): Derived from the IP address to show creators top geographic regions (e.g., country, region, city) without exposing exact precise physical coordinates.
HTTP User-Agent & Device Attributes: Operating system family (iOS, Android, Windows, macOS), browser type, screen resolution, device category (Mobile, Tablet, Desktop), and referral sources (HTTP Referer headers).
Click Event Timestamp & Telemetry: Exact time and date of redirection, destination URL hit, and aggregated click volume counts.
3.3 Security, Bot Mitigation & Advertising Data
Cloudflare & Cloudflare Turnstile: Processes IP addresses, HTTP headers, TLS fingerprinting data, and user interaction signals to distinguish human traffic from automated bots without requiring intrusive visual CAPTCHAs.
Google AdSense: Collects non-personally identifiable identifiers and ad interaction signals to render, measure, and optimize advertising banners displayed across public-facing platform modules.
4. Legal Bases & Purposes for Data Processing
In compliance with Article 6 of the GDPR, every processing activity conducted by Anakrio AS relies on a specific lawful legal basis:
Performance of a Contract (GDPR Art. 6(1)(b)): Operating account infrastructure, routing shortened URLs (e.g.,
[https://anakrio.com/VNK42o](https://anakrio.com/VNK42o)), serving custom bio pages, rendering CTA overlays, and processing billing subscriptions.Legitimate Interests (GDPR Art. 6(1)(f)): Protecting system infrastructure against cyber threats, detecting malware/phishing links, generating aggregated non-identifiable link click statistics for content creators, and improving platform response times.
Compliance with Legal Obligations (GDPR Art. 6(1)(c)): Retaining financial records, VAT reports, and invoice logs to fulfill Norwegian statutory accounting and corporate tax regulations.
Consent (GDPR Art. 6(1)(a)): Utilizing non-essential cookies, running personalized advertising via Google AdSense, or sending promotional marketing updates where explicitly requested by the user.
5. In-Depth Cookie & Tracking Technology Framework
Cookie Governance & Transparency
Anakrio uses cookies, local storage objects, and session tokens to secure account authentication, remember user dashboard preferences, prevent fraud, analyze traffic trends, and deliver advertising. You may manage, block, or delete cookies at any time via your browser settings or our explicit Cookie Consent Banner.
Comprehensive Cookie Index
| Category | Technical Identifier | Operational Purpose & Technical Function | Expiration / Lifespan |
|---|---|---|---|
| Strictly Necessary | anakrio_session | Authentication & State: Encrypted session token that maintains your active login state and user preferences as you navigate the control panel. | Session / 2 Hours |
| Strictly Necessary | XSRF-TOKEN | Security Protection: Cross-Site Request Forgery (CSRF) protection token that verifies that form submissions originate from authenticated users. | Session |
| Security & CDN | cf_clearance, cf_bm | Bot Mitigation: Set by Cloudflare to track device reputation and bypass repeated challenge tests once a visitor proves they are human. | 30 Minutes to 1 Year |
| Analytics | _ga, _ga_* | Google Analytics: Generates a randomized unique client ID to calculate session counts, bounce rates, and overall site usability without identifying individuals. | 2 Years |
| Analytics | anakrio_click_* | In-House Link Tracking: Internal session token ensuring accurate click counts and preventing double-counting rapid multi-clicks on short links. | 24 Hours |
| Advertising | __gads, __gpi | Google AdSense: Tracks ad performance, prevents repeating identical ads to the same visitor, and supports ad frequency capping. | 13 Months |
6. Data Sharing, Sub-Processors & Service Providers
We do not sell, rent, or trade personal information under any circumstances. We share data strictly on a need-to-know basis with vetted third-party service providers (Data Processors) under enforceable Data Processing Agreements (DPAs):
Payment Infrastructure: Stripe Inc. and PayPal Holdings Inc. handle all payment processing. Financial data is transmitted securely to their PCI-DSS-compliant gateways.
CDN, DDoS Defense & Anti-Bot: Cloudflare Inc. operates edge routing, caching, and Cloudflare Turnstile bot verification to shield our platform against cyberattacks.
Performance Analytics: Google LLC (Google Analytics) processes anonymized telemetry to provide aggregated user traffic Insights.
Advertising Networks: Google LLC (Google AdSense) serves advertising units on eligible pages based on non-sensitive context or user consent choices.
Law Enforcement & Statutory Requests: We may disclose data if legally compelled to do so by court orders, search warrants, or formal law enforcement demands issued under valid Norwegian law.
7. International Data Transfers & European Safeguards
Anakrio AS operates primarily out of Norway within the European Economic Area (EEA). Technical infrastructure provided by partners like Cloudflare or Google may process data globally on distributed edge servers.
For any international data transfers occurring outside the EEA/EU to countries without an adequacy decision, Anakrio AS enforces appropriate safeguards under GDPR Chapter V, including:
Execution of standard contractual clauses approved by the European Commission (EU Standard Contractual Clauses - SCCs).
Technical encryption of data in transit via strict SSL/TLS protocols.
Strict organizational access controls and minimization measures.
8. Data Security Measures
Security Infrastructure
We maintain comprehensive technical and organizational safeguards designed to secure personal data against accidental loss, unauthorized access, alteration, and disclosure.
End-to-End Transport Encryption: Mandatory HTTPS enforcement across all endpoints using TLS 1.3/1.2 protocols.
Self-Hosted Transactional Email Architecture: Transactional emails (password resets, account activations) are routed directly via our proprietary, self-managed SMTP server, preventing email data exposure to third-party email providers.
Database Password Hashing: Passwords are cryptographically hashed using industry-standard strong hashing algorithms (
bcrypt/Argon2).System Audits & Rate Limiting: Automated rate-limiting algorithms block brute-force attack attempts on login endpoints and API routes.
9. Data Retention & Self-Service Account Erasure
Self-Service Account & Data Deletion
You maintain full control over your personal data. You may permanently delete your account, generated short links, custom bio pages, overlay campaigns, and personal settings at any time directly through your dashboard at:
https://anakrio.com/user/settings Executing account deletion via this self-service mechanism immediately initiates a purge that permanently removes your profile credentials and user-generated records from our live production databases.
Retention Timelines:
Active Accounts: Personal data is retained as long as your user account remains open and operational.
Archived Analytics Logs: Raw server click logs, IP lookup references, and user-agent strings are aggregated into non-identifiable statistical metrics and automatically purged on a rolling basis.
Accounting & Tax Records: Invoices and transactional logs are retained for up to 5 years to meet statutory tax obligations under Norwegian bookkeeping laws (Bokføringsloven).
SMTP Mail Delivery Logs: Server transmission logs are automatically purged every 30 days.
10. Your Rights Under the GDPR
If you are a resident of the EEA, EU, or UK, you enjoy the following enforceable legal rights regarding your personal data:
Right to Erasure ("Right to be Forgotten"): Request the complete deletion of your personal data. You can instantly exercise this right via
.https://anakrio.com/user/settings Right of Access (Art. 15 GDPR): Request confirmation of whether your data is processed and obtain a copy of your personal records.
Right to Rectification (Art. 16 GDPR): Request immediate correction of inaccurate or incomplete personal data.
Right to Restrict Processing (Art. 18 GDPR): Request the temporary suspension of data processing under certain legal conditions.
Right to Data Portability (Art. 20 GDPR): Request a copy of your personal data in a structured, commonly used, and machine-readable format (JSON/CSV).
Right to Object (Art. 21 GDPR): Object to data processing based on legitimate interests or direct marketing activities.
Create custom bio pages, shorten long URLs, and generate dynamic QR codes for your Instagram, TikTok, and marketing campaigns.
Resources
© 2026 Anakrio. All Rights Reserved