Legal

Privacy Policy

Last updated 17 August 2026. This document is pending final legal review. For a data processing agreement or a data request, email contact@puvigroup.com.

At a glance

We collect as little as we can. Fetching a logo needs no account and no personal data. If you create an account we hold your email address and sign-in details. If you use an API key we count requests against it, but we do not keep a log of which domains you looked up. We do not sell personal data, and we do not use it for advertising or profiling.

1. Controller and contact

Puvi Group ("we", "us") is the controller of personal data processed through AnyLogo. You can reach us at contact@puvigroup.com for any privacy matter, including data subject requests.

We have not appointed a statutory data protection officer, as we are not required to. Privacy enquiries are handled at the address above.

2. Scope

This policy covers the AnyLogo API, dashboard, SDKs and websites. It does not cover third-party sites we link to, or our customers' own products, which have their own policies.

3. Personal data we process

3.1 Anonymous API use

Requests to our public endpoints can be made without an account. We process the IP address of the request transiently to apply rate limits and prevent abuse. It is not stored against an identity and is not used to build a profile.

3.2 Account data

  • Email address — to create and identify your account and to deliver sign-in codes and service messages.
  • Name and profile picture — only where you choose to sign in with Google or GitHub, and only as those providers supply them.
  • Authentication identifiers — the provider name and the identifier that provider assigns you.
  • One-time sign-in codes — stored only as a cryptographic hash, never in plain text, together with expiry and attempt counters to limit brute force.

3.3 Session and device data

For each active sign-in we store a session token, the time it was created and last seen, the browser user agent string, and the IP address at sign-in. This exists so you can review active devices and revoke any you do not recognise, and so we can detect abuse.

3.4 Organisation and team data

If you create or join a team we store the organisation name, membership, each member's role, and pending invitations including the invited email address.

3.5 Audit records

We record security-relevant actions within an organisation — API key creation, rotation and revocation, member invitations, removals and role changes, and session revocations — together with the acting user and the originating IP address. These exist so account owners can see what happened in their own account.

3.6 Usage measurement

We record daily counts of requests per organisation, endpoint and cache outcome. These are aggregate counters used for billing, limits and the usage dashboard. We do not retain a record of which domains you queried.

3.7 Payment data

Where paid plans are purchased, payment is handled by a payment processor. We do not store full card numbers. We retain records of transactions as required for accounting and tax purposes.

3.8 Correspondence

If you email us, we keep the correspondence and contact details in order to respond and to maintain a record of the matter.

3.9 Company Data returned by the Service

Our company endpoint returns information organisations publish about themselves on their own websites. This can include general business contact details such as an enquiries email address or telephone number. Where such a detail identifies an individual, it constitutes personal data, and this section explains our position on it.

  • We process it on the basis of legitimate interests — providing business information that the organisation has itself published for the purpose of being contacted.
  • We limit collection to business contact points published by the organisation. We do not seek out personal contact details of private individuals.
  • We do not enrich, score, segment or profile individuals, and we do not build behavioural profiles.
  • We have carried out a balancing assessment and will provide it on request.
  • If you are identified in a record and want it removed, email us and we will remove it and take steps to prevent it being collected again. We do not require you to explain why.

Customers using this data are independently responsible for their own compliance, including any obligation to inform individuals or to honour objections. See section 11.

4. Sources

We obtain personal data from you directly (when you create an account or contact us), from your device (IP address and user agent when you use the Service), from Google or GitHub if you choose to sign in with them, and, for Company Data, from information organisations publish on their own websites.

5. Purposes and legal bases

PurposeDataLegal basis
Create and operate your accountAccount dataPerformance of a contract
Authenticate sign-inEmail, sign-in codes, sessionsPerformance of a contract
Team membership and invitationsOrganisation dataPerformance of a contract
Billing and plan limitsUsage counts, payment recordsPerformance of a contract; legal obligation (tax)
Security, abuse prevention, rate limitingIP address, sessions, audit recordsLegitimate interests
Service messagesEmail addressPerformance of a contract
Optional product updatesEmail addressConsent (withdrawable at any time)
Providing Company DataPublished business contact detailsLegitimate interests
Complying with law and defending claimsAs relevantLegal obligation; legitimate interests

6. Recipients and processors

We do not sell personal data and do not share it for advertising. We use a small number of service providers who process data on our instructions:

  • Cloudflare — hosting, edge delivery, database, object storage and rate limiting.
  • Cloudflare Email Service — delivery of transactional email such as sign-in codes and invitations.
  • Google and GitHub — identity providers, only where you choose to sign in with them.
  • Payment processor — for paid plans, handling card details directly.

We may also disclose personal data where required by law or valid legal process, to establish or defend legal claims, or to protect the rights and safety of users, the public or the Service. If we are involved in a merger, acquisition or sale of assets, personal data may be transferred, and we will give notice before it becomes subject to a different privacy policy.

7. International transfers

Our infrastructure runs on a global edge network, so personal data may be processed in countries other than your own, including outside the European Economic Area, the United Kingdom and India. Where data is transferred from the EEA or UK to a country without an adequacy decision, we rely on the safeguards implemented by our processors, including Standard Contractual Clauses and the UK International Data Transfer Addendum. A copy of the relevant safeguards is available on request.

8. Retention

DataRetention
Account dataUntil you delete your account
One-time sign-in codes10 minutes, or immediately once used
Sessions30 days, or until revoked or signed out
Audit recordsWhile the account is active; deleted with the account
Usage countersWhile the account is active; deleted with the account
Payment and tax recordsAs required by law, typically 7 years
CorrespondenceUp to 3 years after the matter closes
Company DataRefreshed periodically; removed on valid request

We may retain limited data longer where necessary to comply with law, resolve disputes or enforce our agreements.

9. Your rights

Subject to your local law, you may have the right to:

  • access the personal data we hold about you, and receive a copy;
  • have inaccurate data corrected;
  • have data erased, including Company Data that identifies you;
  • restrict or object to processing, including processing based on legitimate interests;
  • receive data you provided in a portable format;
  • withdraw consent at any time, without affecting prior processing;
  • not be subject to solely automated decisions with legal or similarly significant effects — we do not make such decisions.

To exercise any right, email contact@puvigroup.com. We will respond within 30 days, or tell you if we need longer. We may ask for information to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.

If you are in the EEA or UK you may complain to your supervisory authority. If you are in India you may raise a grievance with us at the address above.

10. Cookies and similar technologies

The dashboard sets one strictly necessary cookie to keep you signed in, and stores your light or dark theme preference locally in your browser. We do not use advertising cookies or third-party analytics trackers, which is why you are not asked to dismiss a cookie banner.

11. Customers using Company Data

Where you use Company Data in your own product, you act as an independent controller of that data. You are responsible for having your own lawful basis, for providing any required notice to individuals, and for honouring their rights. We will cooperate reasonably with you in responding to requests that concern data we supplied.

12. Security

We apply measures appropriate to the risk, including encryption in transit, hashed one-time codes, API keys that can be scoped, expired and rotated, session revocation, audit logging, and least-privilege access to production systems. No system is completely secure. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law and without undue delay.

13. Children

The Service is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

14. Automated decision-making

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Rate limiting and abuse prevention are automated but do not have such effects and can be reviewed by contacting us.

15. Changes to this policy

We may update this policy. The date above shows the latest revision. Where changes are material we will notify account holders by email or by prominent notice on the Service before they take effect.

16. Contact

Puvi Group — contact@puvigroup.com. For removal of a record that identifies you, use the subject line "Data removal request".