Data Processing Agreement for Anytype for Business
Last updated: July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Any Association (“Any”, “we”, “us”) and the customer organization (“Customer”) for the use of Anytype for Business (the “Agreement”). The Agreement is the Anytype for Business Terms of Service at https://business.anytype.io/tos, or a signed agreement or order form between Customer and Any that references those Terms or this DPA.
This DPA applies where Any processes personal data on behalf of Customer as a processor in the course of providing Anytype for Business.
How This DPA Applies
This DPA is incorporated into the Agreement and applies automatically, without signature, whenever Any processes Customer Personal Data as a processor for Customer under the Agreement.
If Customer requires an executed copy, both parties may also sign this DPA using the signature blocks at the end. A signed copy has the same content and effect as the incorporated version; signing is not required for this DPA to apply.
If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control.
Definitions
- “Customer Personal Data” means personal data that Any processes on behalf of Customer in providing Anytype for Business, as described in Annex 1.
- “Data Protection Laws” means the data protection laws applicable to the processing of Customer Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as incorporated into the law of the United Kingdom (“UK GDPR”), and the Swiss Federal Act on Data Protection (“FADP”).
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission in decision 2021/914 for the transfer of personal data to third countries.
- “Subprocessor” means a third party engaged by Any to process Customer Personal Data on Customer’s behalf.
- “Personal data”, “controller”, “processor”, “data subject”, “processing”, “personal data breach”, and similar terms have the meanings given in Data Protection Laws.
Roles and Scope
For Customer Personal Data, Customer is the controller (or, where Customer acts for another controller, a processor acting with that controller’s authorization) and Any is the processor.
This DPA does not apply to personal data that Any processes as an independent controller, such as billing and account records, website visits, marketing communications, and security logs Any maintains for its own purposes. That processing is described in the Anytype for Business Privacy Policy at https://business.anytype.io/privacy.
The subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects are described in Annex 1.
Customer Instructions
Any will process Customer Personal Data only on documented instructions from Customer, including regarding transfers of personal data to a third country, unless required to do otherwise by law to which Any is subject. In that case, Any will inform Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
Customer’s instructions are:
- The Agreement and this DPA.
- Customer’s and its users’ configuration of and use of Anytype for Business, including organization settings, channel management, sign-in configuration, invitations, and deletion actions.
- Other documented written instructions agreed between the parties.
Any will inform Customer if, in Any’s opinion, an instruction infringes Data Protection Laws. Any may suspend the affected processing until the instruction is confirmed or changed.
Customer Responsibilities
Customer is responsible for:
- Having a lawful basis for the processing of Customer Personal Data and complying with Data Protection Laws as controller.
- Providing privacy notices to, and obtaining any required consents from, its users and other data subjects.
- The accuracy, quality, and legality of Customer Personal Data and the means by which it was obtained.
- Configuring and using Anytype for Business appropriately for the sensitivity of the data it processes, including access management, identity-provider configuration, and organization settings.
- Not submitting special categories of personal data outside encrypted Content unless the parties have agreed to it in writing.
Confidentiality
Any ensures that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process Customer Personal Data only as needed to provide Anytype for Business.
Security
Any implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks for data subjects.
The current measures are described in Annex 2. Any may update these measures from time to time, provided the updates do not materially reduce the overall level of protection during the term of the Agreement.
Anytype content is encrypted, and encryption and decryption of content happens on device. Where Anytype for Business uses a separate sign-in service, it stores an association between a user’s corporate email address and encrypted private key material, protected with master-key encryption, access controls, monitoring, and operational security measures.
Subprocessors
Customer provides a general authorization for Any to engage Subprocessors to provide Anytype for Business. The Subprocessors engaged at the date of this DPA are listed in Annex 3.
Any will:
- Impose data protection obligations on each Subprocessor that are materially no less protective than those in this DPA, by way of a written contract.
- Remain responsible to Customer for the performance of each Subprocessor’s obligations.
- Notify Customer at least 30 days before a new Subprocessor processes Customer Personal Data, or before a change in an existing Subprocessor’s role. Notice may be given by email to the organization admin contact or through the product or the business.anytype.io website.
Customer may object to a new Subprocessor on reasonable, documented data-protection grounds within 30 days of the notice. The parties will then discuss the concern in good faith. If Any cannot reasonably address the objection — for example by offering a configuration that avoids the Subprocessor — Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the remaining term. This is Customer’s sole remedy for an objection.
International Transfers
Any is based in Switzerland. Customer Personal Data may be processed in Switzerland, the European Economic Area, the United States, and other countries where Any or its Subprocessors operate, as described in Annex 3.
Where the transfer of Customer Personal Data to Any or a Subprocessor requires a transfer mechanism under Data Protection Laws, the parties agree:
- Transfers from the EEA to countries without an adequacy decision are governed by the SCCs, Module Two (controller to processor), which are incorporated into this DPA by reference. For the SCCs: Customer is the data exporter and Any is the data importer; Clause 7 (docking) applies; in Clause 9, Option 2 (general authorization) applies with the notice period in the Subprocessors section above; in Clause 11, the optional language does not apply; in Clauses 17 and 18, the governing law and forum are those of Ireland unless the SCCs require the law or forum of another EU member state; Annexes I, II, and III of the SCCs are completed with the information in Annexes 1, 2, and 3 of this DPA.
- For transfers subject to the FADP, the SCCs apply as adapted in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are understood as references to the FADP, the competent supervisory authority is the FDPIC, the governing law and forum may be Switzerland, and data subjects in Switzerland may enforce their rights in Switzerland.
- For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the UK Information Commissioner’s Office, completed with the information in the Annexes of this DPA.
- Transfers to countries covered by an applicable adequacy decision, including transfers to Switzerland from the EEA and the UK, may rely on that adequacy decision.
If a transfer mechanism relied on under this DPA is invalidated or replaced, the parties will cooperate in good faith to put an alternative lawful mechanism in place.
Assistance to Customer
Taking into account the nature of the processing, Any will:
- Assist Customer through appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). Where Anytype for Business provides admin or user tools for this, Customer will use those tools first.
- Promptly notify Customer if Any receives a request from a data subject that identifies Customer Personal Data, and not respond to the request other than to direct the data subject to Customer, unless required by law.
- Assist Customer, insofar as this is possible and taking into account the information available to Any, with Customer’s obligations regarding security of processing, personal data breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
Any may charge reasonable fees for assistance that goes materially beyond the standard features of Anytype for Business, and will notify Customer of any expected fees before performing the work.
If a court, authority, or regulator demands disclosure of Customer Personal Data, Any will, unless legally prohibited, notify Customer before disclosing, challenge overbroad demands where reasonable, and disclose only the minimum required.
Personal Data Breach
Any will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
The notification will, to the extent the information is available, describe the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for more information. Information may be provided in phases as the investigation progresses.
Any will take reasonable steps to contain and remediate the breach and will cooperate with Customer’s reasonable requests in connection with Customer’s own notification obligations. Any’s notification of a breach is not an acknowledgement of fault or liability.
Deletion and Return
During the term, Customer and its users can delete Customer Personal Data using the features of Anytype for Business, and can export Content where the product supports it.
After the end of the provision of the service, Any will, at Customer’s choice, delete or return Customer Personal Data, and delete existing copies, unless law requires storage of the personal data. Unless Customer requests deletion earlier or an agreement says otherwise, Any will delete Customer Personal Data within 90 days after the end of the Agreement, with deletion from backups following Any’s backup rotation cycles thereafter.
Data stored locally on user devices is outside Any’s control and must be deleted by Customer or its users on those devices.
Audits and Information
Any will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. On written request, no more than once per year, Any will respond to Customer’s reasonable written security and data-protection questionnaires and provide available relevant documentation, such as descriptions of technical and organizational measures and available summaries of assessments or reports.
If the information provided is reasonably insufficient to demonstrate compliance, or where an audit is required by a supervisory authority or mandatory Data Protection Laws, Customer (or an independent auditor on its behalf that is not a competitor of Any and is bound by confidentiality) may conduct an audit, including an inspection, of the processing covered by this DPA, subject to:
- At least 30 days’ prior written notice, unless a shorter period is mandated by a supervisory authority.
- Scope, timing, duration, and security and confidentiality controls agreed in advance, during normal business hours, no more than once per year unless a personal data breach affecting Customer Personal Data or a supervisory authority requires otherwise.
- No access to data of other customers or to information that would compromise the security of the service.
- Customer bearing its own costs and Any’s reasonable costs for support beyond standard information provision.
Audit rights under the SCCs remain unaffected; the parties agree that the process above is the way those rights are ordinarily exercised.
Liability
Each party’s liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, except where liability cannot be limited under Data Protection Laws, and without limiting either party’s liability to data subjects or supervisory authorities under Data Protection Laws.
Term
This DPA applies for as long as Any processes Customer Personal Data on behalf of Customer under the Agreement, and the obligations regarding deletion, confidentiality, and liability survive until fulfilled.
Governing Law and Jurisdiction
This DPA is governed by the same law and subject to the same jurisdiction as the Agreement — the laws of Switzerland and the courts of the Canton of Zug — except where the SCCs or mandatory Data Protection Laws require otherwise.
Contact
Questions about this DPA and privacy requests can be sent to:
Any Association c/o Sielva Management AG Gubelstrasse 11 CH-6300 Zug Switzerland
Email: association@anytype.io
EU representative (Article 27 GDPR):
Anylab GmbH Meinekestrasse 27 10719 Berlin Germany
Email: anylab@anytype.io
Annex 1: Description of Processing
Subject matter. The provision of Anytype for Business to Customer, including the app, business account features, organization administration, channels, business sign-in, sync, backup, and support.
Duration. The term of the Agreement, plus the deletion period described in the Deletion and Return section.
Nature and purpose. Hosting, storage, synchronization, backup, transmission, display, deletion, and related processing needed to provide, secure, maintain, troubleshoot, and support Anytype for Business, according to the product architecture, Customer’s settings, and Customer’s instructions. Anytype content is encrypted; encryption and decryption of content happens on device.
Categories of data subjects.
- Customer’s users, such as employees, contractors, and other persons Customer invites to its organization.
- Other individuals whose personal data is contained in Content that users create, upload, store, sync, or share through Anytype for Business.
Types of personal data.
- Account and identity data: name, corporate email address, Anytype ID, organization membership, role, seat status, cryptographic identifiers, device identifiers, profile details such as avatar or display name.
- Sign-in data: provider account identifier, organization or tenant identifier, sign-in status, timestamps, and authentication metadata from Google or Microsoft login where used.
- Key-management data: associations between corporate email addresses and encrypted private key material.
- Content and channel data: encrypted content and files; channel IDs, object IDs, account IDs, device IDs, and membership records; organization settings, permissions, and audit or security information.
- Usage, security, and diagnostics data: app version and configuration, operating system and device model, network mode and sync status, session and feature usage events, crash reports and diagnostic metadata, IP addresses and request logs.
- Support data: messages and related records when users contact support.
Special categories of personal data. Not intended. Users may include special categories of data in encrypted Content at Customer’s discretion; such Content is encrypted and decrypted on device.
Frequency. Continuous, for the duration of the Agreement.
Annex 2: Technical and Organizational Measures
Any maintains the following measures, as further described in the Anytype for Business Privacy Policy:
- Encryption of content. Anytype content is encrypted, with encryption and decryption performed on the user’s device. Data is encrypted in transit and at rest.
- Key management. Business sign-in private key material is encrypted using master-key encryption and protected with access controls, monitoring, and operational security measures.
- Access control. Access to systems processing Customer Personal Data is limited to authorized personnel on a least-privilege, need-to-know basis, with authentication controls and access reviews.
- Confidentiality of personnel. Personnel with access to Customer Personal Data are bound by confidentiality obligations.
- Monitoring and incident response. Logging, monitoring, and documented incident response processes designed to detect, investigate, and remediate security incidents, including personal data breaches.
- Infrastructure security. Use of established infrastructure providers with their own certified security controls; network protections; separation between production and non-production environments.
- Availability and recovery. Backups and recovery processes designed to restore availability and access to personal data in a timely manner after an incident.
- Secure development and operations. Review and testing of changes, vulnerability management, and open-source transparency for core protocol components.
- Data minimization. Collection of the minimum personal data needed to provide, secure, bill for, support, and improve the service; operational metadata is used only to provide, secure, sync, troubleshoot, and delete the service.
- Deletion. Processes for deleting Customer Personal Data on request, on account or organization deletion, and at the end of retention periods, subject to backup rotation cycles.
- Subprocessor management. Written contracts with Subprocessors imposing data-protection and security obligations, and review of Subprocessor security practices.
- Self-hosting option. For full zero-knowledge guarantees, Anytype for Business can be self-hosted on Customer’s own infrastructure, in which case Any does not process the self-hosted data.
Annex 3: Subprocessors
Any uses the following Subprocessors to process Customer Personal Data:
| Subprocessor | Purpose | Typical data | Main processing location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, security, network delivery, form queue infrastructure | IP address, request logs, encrypted payloads, operational metadata | Global |
| Google LLC | Optional Google sign-in | Email, name, profile picture, account identifiers, authentication metadata | Global |
| Microsoft Corporation | Optional Microsoft sign-in | Email, name, profile picture, tenant/account identifiers, authentication metadata | Global |
| Stripe, Inc. | Payments and billing for Customer’s subscription | Billing contact, transaction, payment, tax, and invoice data | United States and global |
| Loops (Astrodon, Inc.) | Transactional emails and service communications | Email, name, communication preferences, message metadata | United States |
| Amplitude, Inc. | App analytics and diagnostics | Usage events and technical analytics identifiers | United States |
Providers that Any uses as an independent controller (for example, website analytics for business.anytype.io) are listed in the Anytype for Business Privacy Policy.
Signatures
This DPA applies without signature as described in “How This DPA Applies”. Where the parties choose to execute it:
Customer
Organization: ____________________________
Name: ____________________________
Title: ____________________________
Date: ____________________________
Signature: ____________________________
Any Association
Name: ____________________________
Title: ____________________________
Date: ____________________________
Signature: ____________________________