Privacy Policy
Last updated 17 August 2026. This document is pending final legal review. For a data processing agreement or a data request, email contact@puvigroup.com.
At a glance
We collect as little as we can. Fetching a logo needs no account and no personal data. If you create an account we hold your email address and sign-in details. If you use an API key we count requests against it, but we do not keep a log of which domains you looked up. We do not sell personal data, and we do not use it for advertising or profiling.
1. Controller and contact
Puvi Group ("we", "us") is the controller of personal data processed through AnyLogo. You can reach us at contact@puvigroup.com for any privacy matter, including data subject requests.
We have not appointed a statutory data protection officer, as we are not required to. Privacy enquiries are handled at the address above.
2. Scope
This policy covers the AnyLogo API, dashboard, SDKs and websites. It does not cover third-party sites we link to, or our customers' own products, which have their own policies.
3. Personal data we process
3.1 Anonymous API use
Requests to our public endpoints can be made without an account. We process the IP address of the request transiently to apply rate limits and prevent abuse. It is not stored against an identity and is not used to build a profile.
3.2 Account data
- Email address — to create and identify your account and to deliver sign-in codes and service messages.
- Name and profile picture — only where you choose to sign in with Google or GitHub, and only as those providers supply them.
- Authentication identifiers — the provider name and the identifier that provider assigns you.
- One-time sign-in codes — stored only as a cryptographic hash, never in plain text, together with expiry and attempt counters to limit brute force.
3.3 Session and device data
For each active sign-in we store a session token, the time it was created and last seen, the browser user agent string, and the IP address at sign-in. This exists so you can review active devices and revoke any you do not recognise, and so we can detect abuse.
3.4 Organisation and team data
If you create or join a team we store the organisation name, membership, each member's role, and pending invitations including the invited email address.
3.5 Audit records
We record security-relevant actions within an organisation — API key creation, rotation and revocation, member invitations, removals and role changes, and session revocations — together with the acting user and the originating IP address. These exist so account owners can see what happened in their own account.
3.6 Usage measurement
We record daily counts of requests per organisation, endpoint and cache outcome. These are aggregate counters used for billing, limits and the usage dashboard. We do not retain a record of which domains you queried.
3.7 Payment data
Where paid plans are purchased, payment is handled by a payment processor. We do not store full card numbers. We retain records of transactions as required for accounting and tax purposes.
3.8 Correspondence
If you email us, we keep the correspondence and contact details in order to respond and to maintain a record of the matter.
3.9 Company Data returned by the Service
Our company endpoint returns information organisations publish about themselves on their own websites. This can include general business contact details such as an enquiries email address or telephone number. Where such a detail identifies an individual, it constitutes personal data, and this section explains our position on it.
- We process it on the basis of legitimate interests — providing business information that the organisation has itself published for the purpose of being contacted.
- We limit collection to business contact points published by the organisation. We do not seek out personal contact details of private individuals.
- We do not enrich, score, segment or profile individuals, and we do not build behavioural profiles.
- We have carried out a balancing assessment and will provide it on request.
- If you are identified in a record and want it removed, email us and we will remove it and take steps to prevent it being collected again. We do not require you to explain why.
Customers using this data are independently responsible for their own compliance, including any obligation to inform individuals or to honour objections. See section 11.
4. Sources
We obtain personal data from you directly (when you create an account or contact us), from your device (IP address and user agent when you use the Service), from Google or GitHub if you choose to sign in with them, and, for Company Data, from information organisations publish on their own websites.
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account | Account data | Performance of a contract |
| Authenticate sign-in | Email, sign-in codes, sessions | Performance of a contract |
| Team membership and invitations | Organisation data | Performance of a contract |
| Billing and plan limits | Usage counts, payment records | Performance of a contract; legal obligation (tax) |
| Security, abuse prevention, rate limiting | IP address, sessions, audit records | Legitimate interests |
| Service messages | Email address | Performance of a contract |
| Optional product updates | Email address | Consent (withdrawable at any time) |
| Providing Company Data | Published business contact details | Legitimate interests |
| Complying with law and defending claims | As relevant | Legal obligation; legitimate interests |
6. Recipients and processors
We do not sell personal data and do not share it for advertising. We use a small number of service providers who process data on our instructions:
- Cloudflare — hosting, edge delivery, database, object storage and rate limiting.
- Cloudflare Email Service — delivery of transactional email such as sign-in codes and invitations.
- Google and GitHub — identity providers, only where you choose to sign in with them.
- Payment processor — for paid plans, handling card details directly.
We may also disclose personal data where required by law or valid legal process, to establish or defend legal claims, or to protect the rights and safety of users, the public or the Service. If we are involved in a merger, acquisition or sale of assets, personal data may be transferred, and we will give notice before it becomes subject to a different privacy policy.
7. International transfers
Our infrastructure runs on a global edge network, so personal data may be processed in countries other than your own, including outside the European Economic Area, the United Kingdom and India. Where data is transferred from the EEA or UK to a country without an adequacy decision, we rely on the safeguards implemented by our processors, including Standard Contractual Clauses and the UK International Data Transfer Addendum. A copy of the relevant safeguards is available on request.
8. Retention
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| One-time sign-in codes | 10 minutes, or immediately once used |
| Sessions | 30 days, or until revoked or signed out |
| Audit records | While the account is active; deleted with the account |
| Usage counters | While the account is active; deleted with the account |
| Payment and tax records | As required by law, typically 7 years |
| Correspondence | Up to 3 years after the matter closes |
| Company Data | Refreshed periodically; removed on valid request |
We may retain limited data longer where necessary to comply with law, resolve disputes or enforce our agreements.
9. Your rights
Subject to your local law, you may have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have data erased, including Company Data that identifies you;
- restrict or object to processing, including processing based on legitimate interests;
- receive data you provided in a portable format;
- withdraw consent at any time, without affecting prior processing;
- not be subject to solely automated decisions with legal or similarly significant effects — we do not make such decisions.
To exercise any right, email contact@puvigroup.com. We will respond within 30 days, or tell you if we need longer. We may ask for information to verify your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If you are in the EEA or UK you may complain to your supervisory authority. If you are in India you may raise a grievance with us at the address above.
10. Cookies and similar technologies
The dashboard sets one strictly necessary cookie to keep you signed in, and stores your light or dark theme preference locally in your browser. We do not use advertising cookies or third-party analytics trackers, which is why you are not asked to dismiss a cookie banner.
11. Customers using Company Data
Where you use Company Data in your own product, you act as an independent controller of that data. You are responsible for having your own lawful basis, for providing any required notice to individuals, and for honouring their rights. We will cooperate reasonably with you in responding to requests that concern data we supplied.
12. Security
We apply measures appropriate to the risk, including encryption in transit, hashed one-time codes, API keys that can be scoped, expired and rotated, session revocation, audit logging, and least-privilege access to production systems. No system is completely secure. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law and without undue delay.
13. Children
The Service is not directed at children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
14. Automated decision-making
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Rate limiting and abuse prevention are automated but do not have such effects and can be reviewed by contacting us.
15. Changes to this policy
We may update this policy. The date above shows the latest revision. Where changes are material we will notify account holders by email or by prominent notice on the Service before they take effect.
16. Contact
Puvi Group — contact@puvigroup.com. For removal of a record that identifies you, use the subject line "Data removal request".