Skip to content
anyutil.io

Data processing agreement

In effect from 1 August 2026

If you use the tools on documents containing other people's personal data (clients, employees, patients), under the GDPR you are the controller and we are the processor. Article 28 of the Regulation then requires a written agreement. This page is its text; by accepting the terms of service it becomes part of the contractual relationship, without you having to sign anything.

If you need it signed on our side or on your own form, ask for it at hello@anyutil.io.

1. Parties

The processor is Matěj Wernisch, Sokolská 1883/8, Prague 2, Czech Republic, company ID 29519641. The controller is the customer, that is the natural or legal person using the tools.

2. Subject matter and duration

We process the personal data contained in files and text that the controller puts into the tools that run on the server, solely for the purpose of performing the requested operation. The duration of processing is the duration of one request: the data is processed in memory and deleted once the result is sent back. For queued jobs, such as audio transcription, processing lasts until the job is finished at the latest.

The other tools (86 of the total) run entirely in the controller's browser. No processing takes place on our side there, because we never reach the data.

3. Categories of data subjects and data

These are determined by the controller through the file they put into a tool. We neither limit nor inspect the content, and therefore do not know which categories of data it contains. The controller is responsible for having a legal basis for the processing.

4. Obligations of the processor

  • Process the data only on the controller's instructions, that is according to the requested operation.
  • Bind everyone who can reach the data to confidentiality.
  • Take appropriate technical measures under Article 32: encrypted connection, processing in memory, separation from backups, restricted server access. They are described in more detail on Security.
  • Engage no further sub-processor without prior notice. The current list is below.
  • Assist with responses to data subject requests and with reporting personal data breaches.
  • Report a personal data breach to the controller without undue delay after becoming aware of it, within 48 hours at the latest.
  • Delete the data once processing ends. With the server-side tools this happens automatically within minutes.
  • Give the controller the information needed to demonstrate compliance and allow an audit to a reasonable extent.

5. Sub-processors

The controller gives general authorisation for engaging the sub-processors listed below. We announce a change by email at least 30 days in advance and the controller may object; in that case they have the right to end the subscription without penalty.

Sub-processorPurposeLocationData
Hostinger International Ltd.Running the server, the database and backupsGermany (EU)Account, presets, files temporarily uploaded to the server-side tools
Stripe Payments Europe, Ltd.Processing payments and issuing documentsIreland (EU), with transfer to the USA under standard contractual clausesE-mail, billing details, payment history
Spacemail (Hostinger)Sending operational email, such as address verification and password resetsEUE-mail address, message content

6. Transfers outside the EU

The servers and the database are in Germany. The only transfer outside the EU is with Stripe, which carries out part of the processing in the USA under standard contractual clauses approved by the European Commission.

7. Liability

The liability of the parties is governed by the GDPR and by the terms of service. The controller is responsible for the lawfulness of the data they put into the tools and for having a legal basis for processing it.

8. Changes

We announce changes to this text by email to registered customers at least 30 days in advance. The effective date is always stated at the top.