LEGAL / 01
Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how the operator of Whispering Instruments, developed and operated under the Anumys brand (“Anumys”, “we”, “us” or “our”), collects and uses personal data when you visit our website, create an account, purchase or download software, activate a licence, contact Support, submit a review, subscribe to communications, or use our AI shopping assistant.
1. Who is responsible for your data?
The data controller within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) is:
Anumystrading as Anumys / Whispering Instruments
Hungary, 2421 Nagyvenyim, Fuzfa 2.
Tax number: 92214442-1-27
Email: anumys.studio@gmail.com
For privacy questions, rights requests or complaints, contact the privacy email above.
2. Scope of this policy
This policy applies to the Whispering Instruments webshop, product pages, checkout pages, account pages, Support and Tickets pages, the LicenseServer API and admin-operated email delivery connected to these services. It also applies to the software activation and deactivation requests sent by supported applications.
External services such as payment providers, social-login providers, hosting providers, email providers and OpenAI may process personal data under their own privacy notices. We remain responsible for selecting appropriate providers and using them only for defined purposes, while those providers may act as independent controllers or as processors depending on the service.
3. What personal data do we process?
We apply data minimisation and process only the information reasonably required for the relevant purpose. Depending on how you use the services, this may include:
- Account and identity data: email address, display name, password hash, email-verification status, social-login provider and provider account identifier.
- Billing data: legal name, first and last name, company name, billing address, country, VAT or tax identifiers and related billing-profile information.
- Order and payment data: order identifier, purchased product or bundle, quantity, currency, amounts, payment-provider identifiers, payment status, fulfilment status and refund status. Payment-card details are handled by the selected payment provider and are not stored by the Shop database.
- Licence data: licence key, application/product, licence status, expiry, activation limit, activation count and the licence group belonging to a bundle.
- Activation and technical data: machine identifier, application identifier, operating system or product format where provided, IP address, request timestamps and allowed/denied licence-check results.
- Support data: ticket subject, messages, status and the preference to receive email notifications when a ticket status changes.
- Review data: displayed name, rating, review text, product, publication status and timestamps. Reviews are shown publicly only according to the publication rules of the service.
- Communication data: newsletter and product-update subscription choices, email delivery status and communication preferences.
- Security and operational data: session identifiers stored in protected cookies, CSRF-related values, authentication events, rate-limit/security events and server logs.
- AI assistant data: the questions and conversation content you voluntarily submit to the website assistant, together with limited technical context needed to answer and protect the service. Do not submit passwords, licence keys, payment details or other unnecessary personal data to the assistant.
4. How do we collect data?
- directly from you when you create or update an account, place an order, open a ticket, submit a review or choose communication preferences;
- from payment and fulfilment providers when an order, refund or fulfilment event is reported;
- from social-login providers when you authorise a login and the provider returns the requested profile information;
- from the application or plugin when it sends a licence activation, deactivation or verification request;
- automatically from your browser or device through essential cookies, security logs and standard HTTP request data.
5. Purposes and GDPR legal bases
For each processing activity we rely on an applicable legal basis under Article 6 GDPR. We do not make the provision of a purchase conditional on consenting to unrelated marketing.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Account creation, login and account security | Email, display name, password hash, session and security data | Contract performance; legitimate interest in security; legal obligation where applicable |
| Order processing, payment, fulfilment and licence delivery | Billing, order, provider, product and licence data | Contract performance; legal obligation for accounting and tax records |
| Licence activation, deactivation and fraud prevention | Licence, application, machine, IP and usage data | Contract performance; legitimate interest in preventing misuse and protecting software |
| Customer support and ticket notifications | Email, ticket messages, ticket status and notification choice | Contract performance or pre-contractual steps; consent for optional notifications |
| Product reviews | Product, displayed name, rating and review text | Contract-related eligibility check; consent/publication choice for displaying the review |
| Newsletter and product-update messages | Email and subscription preference | Consent; unsubscribe is available at any time. Transactional messages rely on contract performance or legal obligation. |
| Essential cookies, technical logs and service protection | Session, CSRF, IP, browser and request data | Legitimate interest in providing a secure service; contract performance for requested account features |
| AI shopping assistance | Voluntarily submitted questions and conversation context | Consent or your request to use the assistant; legitimate interest in abuse prevention |
6. Payments, checkout and external providers
Checkout may be provided through FastSpring or another configured payment provider. The provider may collect payment, billing, fraud-prevention and tax information directly. We receive the order and fulfilment information required to provide the purchased product, issue licences, send transactional emails and handle refunds.
If Gumroad or another sales channel is enabled, that provider may send order, sale, refund and licence-verification events to the LicenseServer. We use those events only to reconcile purchases, provide entitlements and protect against duplicate or fraudulent fulfilment. Review the provider’s own privacy notice before completing a purchase through that provider.
Social login is optional. When you choose Google, GitHub, X or Amazon, the relevant provider may receive your request and return an identifier and, where available and authorised, your email address and basic profile information. We do not use a social provider as a substitute for your internal account record.
7. AI assistant and OpenAI
The website may offer an AI assistant to help with product questions and checkout guidance. When enabled, your submitted question and the limited conversation context required to answer it may be sent to OpenAI through our server-side integration. The assistant is not authorised to access your private account, order, payment or licence state, and it cannot place an order or change an account.
Product documentation may be stored in an OpenAI vector store so the assistant can retrieve relevant product information. We do not intentionally place customer account records, payment details or licence keys in that knowledge base. The assistant may be unavailable or may provide an incomplete answer; product terms, checkout information and Support remain authoritative.
8. Cookies and similar technologies
We use cookies and comparable storage technologies in the following categories:
- Strictly necessary: session cookies, CSRF protection and the cookie-notice preference. These are required for login, account security and requested webshop functionality.
- Preference: settings needed to remember a choice you make, such as dismissing the cookie notice.
- Optional analytics or marketing: currently not required for the core service. If introduced, they must be blocked until valid consent is obtained, and the cookie notice and this policy must be updated before deployment.
You can delete or block cookies through your browser. Blocking strictly necessary cookies may prevent login, account features, checkout or other requested functions from working correctly.
9. Who may receive personal data?
We disclose personal data only when necessary for a stated purpose, under a contract or data-processing arrangement where required, or where disclosure is required by law. Categories of recipients may include:
- hosting, infrastructure, database, security and domain providers;
- payment, checkout, tax, fraud-prevention and sales-channel providers;
- email delivery and customer-support providers;
- social-login providers when you select social login;
- OpenAI when you actively use the AI assistant;
- professional advisers, auditors, insurers, courts, regulators and law-enforcement authorities where necessary and lawful.
We do not sell personal data. We do not allow service providers to use customer data for their own unrelated purposes where they act as our processor. A current provider list, including processor/controller status and applicable privacy links, should be maintained internally and made available on request.
10. International transfers
Some providers may process data outside the European Economic Area. Before using such a provider, we assess the transfer mechanism and safeguards required by GDPR Chapter V, such as an adequacy decision, Standard Contractual Clauses and, where appropriate, supplementary technical or organisational measures. Contact us if you want information about the safeguards applicable to a particular provider.
11. Data retention
We retain personal data only for as long as necessary for the purpose for which it was collected, to provide the service, resolve disputes, enforce agreements, prevent abuse, maintain security, or satisfy accounting, tax and other legal obligations. Typical retention rules are:
- account, order, licence and support records: while the account or contractual relationship exists and afterwards for the period required for legal claims, fraud prevention and mandatory records;
- billing and invoice records: for the statutory accounting and tax retention period applicable to the controller;
- authentication tokens: until consumed or expired, followed by secure deletion or anonymisation;
- security and technical logs: for the shortest period reasonably necessary for security, troubleshooting and legal claims;
- newsletter and update subscriptions: until you unsubscribe or the purpose ends, with evidence of consent retained where necessary to demonstrate compliance;
- AI conversations and support emails: for the period needed to provide the service, investigate abuse or resolve a request, subject to provider-specific retention controls.
Controller action required: insert the exact retention schedule required by the applicable accounting, tax, consumer-protection and limitation rules in the country of establishment. A generic statement cannot replace that documented schedule.
12. Security
We use proportionate technical and organisational measures, including authenticated HTTPS between the Shop and LicenseServer, HTTP-only session cookies, CSRF protection, input validation, rate limiting, security headers, access control, password hashing, least-privilege database access, backups and audit logging where appropriate. No internet transmission or storage system can be guaranteed to be completely secure.
We do not ask you to send passwords or payment-card details by email or support ticket. If you suspect unauthorised access, contact us immediately through the Support page and change any reused password.
13. Your GDPR rights
Subject to the conditions and exceptions in GDPR Articles 15–22, you may have the right to:
- receive clear information about processing;
- access a copy of personal data we hold about you;
- rectify inaccurate or incomplete information;
- request erasure (“right to be forgotten”);
- request restriction of processing;
- object to processing based on legitimate interests, including direct marketing;
- receive portable data where the legal conditions are met;
- withdraw consent at any time, without affecting processing that took place before withdrawal;
- object to direct marketing at any time; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where a GDPR exception applies.
You can manage profile data and communication preferences in your Account page, unsubscribe from marketing emails through the unsubscribe link, or contact the controller for access, correction, deletion, export or restriction. We may request reasonable information to verify identity and protect the account. We normally respond without undue delay and, in any event, within one month, subject to the GDPR rules for complex or manifestly unfounded requests.
Account deactivation does not automatically erase records that we must retain for a legal obligation, an active licence entitlement, security, fraud prevention, dispute resolution or the establishment, exercise or defence of legal claims. Where possible, retained records are restricted, anonymised or separated from active account use.
14. Children
The services are intended for adults and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.
15. Changes to this policy
We may update this policy when the services, providers, legal requirements or processing purposes change. The “Last updated” date will be changed when the policy is revised. If a change materially affects your rights or the purposes of processing, we will provide an appropriate notice and, where required, obtain consent before the new processing begins.
16. Complaints and supervisory authority
Please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the competent data protection supervisory authority, in particular in the EU/EEA country of your habitual residence, place of work or the alleged infringement. The competent authority for the controller’s establishment should be identified here: https://www.naih.hu.
17. Contact
For privacy requests, data-protection questions or a complaint, use:
Anumys
Privacy contact: anumys.studio@gmail.com
General Support: Support
Account and deletion information: User Data Deletion