Skip to main content
Platform Review
PricingSign in
Anana assessment

Anana procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Anana
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow We apply the following measures: Encryption in transit: TLS everywhere; HTTPS-only externally. Encryption at rest: AES-256 via AWS KMS for AWS RDS Postgres 17.4 (including pgvector) and AWS S3 (recordings, attachments, exports). Application-level AES-256-GCM for integration credentials. Multi-tenant isolation: row-level tenant filter enforced in the application data layer. Network protection: AWS WAF with managed rules and rate limiting (2000 requests per 5 minutes). Webhook integrity: HMAC verification on inbound webhooks where the provider supports it. Access controls: multi-factor authentication, role-based access control, least-privilege provisioning. Audit logging: artifact lifecycle events (create, version bump, send) are recorded. Transient stores: Redis is used for sessions and queues; data there is short-lived.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Anana is established in the United States and our production data is stored in AWS eu-central-1 (Frankfurt). Several sub-processors listed in Section 7 process data in the United States or other third countries (notably OpenAI, OpenRouter, Perplexity, Google, Sentry, Vercel, Stytch, Twilio, Resend, AssemblyAI, Deepgram, Firecrawl, Reducto). For transfers of EU/EEA personal data to the United States or other third countries we rely on: Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, plus supplementary measures where required EU–U.S. Data Privacy Framework where the recipient is certified under it Transfer Impact Assessments documenting the level of protection and any supplementary measures A copy of the SCCs and our TIAs is available on request at privacy@getanana.com.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Anana is established in the United States. In accordance with Art. 27 GDPR, Anana has designated the following EU representative for matters relating to the processing of personal data of data subjects in the EU/EEA: Probo Inc, 7 rue Commines, 75003 Paris, France — privacy@probo.com EU/EEA data subjects and supervisory authorities may contact our EU representative directly on all issues related to processing for the purpose of ensuring compliance with the GDPR.Captured 2026-07-19Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Anana: privacy queries and rights requests: privacy@getanana.com EU representative: Probo Inc, 7 rue Commines, 75003 Paris, France — privacy@probo.comCaptured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tierslow Operator user account and authentication data For the life of the customer contract; deleted within 1 year of contract termination. Voice recordings Retained per the venue's configuration and not used for model training; Anana-held copies are deleted on the venue's instruction or within 1 year of contract termination. Voice transcripts Retained per the venue's configuration as part of the conversation record; deleted with the associated tenant data on the venue's instruction or within 1 year of contract termination. Inbound messages (chat, SMS, email) Retained per the venue's configuration as part of the conversation record; deleted on the venue's instruction or within 1 year of contract termination. Booking/guest profile data synced from PMS/CRM Controlled by the venue; Anana deletes on the venue's instruction or contract end. Embeddings in pgvector Tied to the source artifact; deleted when the source is deleted. Audit logs (artifact create / version / send) 2 years. Server logs / WAF logs Application production logs 30 days; AWS CloudFront/WAF edge logs per their configuration. Database backups Daily backups retained 7 days on a rolling cycle. Business contacts (CRM) Until objection or 2 years of inactivity. Accounting and tax records As required by applicable law (typically 7–10 years). Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown After the retention period, data is deleted or irreversibly anonymized. Retention of guest data (recordings, transcripts, messages, bookings) is ultimately set by the venue as controller; the periods above are Anana's own outer limits.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown For personal data of end guests and leads (people who chat with, call, SMS, or email a venue powered by Anana, or whose booking/profile data is synced from a Property Management System or CRM), our hospitality customer is the controller and Anana acts as their processor under a Data Processing Agreement. Where this policy describes guest data, it does so in our capacity as processor and for transparency only; the venue's own privacy notice governs that processing. Contact: privacy@getanana.com We have not appointed a Data Protection Officer; Art. 37 GDPR does not require us to do so. Privacy questions and rights requests are handled at privacy@getanana.com.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown When a venue connects Anana to its own systems (e.g., WebHotelier, Fidelio on-prem, Practice Better, Kanika, Genesys Cloud, HubSpot, Composio), the venue is the controller of that integration and the integration provider is the venue's processor, not ours. Anana acts as the venue's agent only. Other recipients include our professional advisors (legal, accounting) and competent authorities where required by law.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We share personal data only with vetted sub-processors under a DPA. An up-to-date list is available on request at privacy@getanana.com.Captured 2026-07-19Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.