Our Privacy Policy
Privacy Policy
Last updated: 30 August 2026
Anty Virtual, Inc. (“Anty Virtual,” “us,” “we,” or “our”) takes the privacy of our customers, our customers’ end users, and our website visitors (“User,” “you,” and “your”) seriously. This Privacy Policy describes how we collect, use, share, retain, and delete Personal Information through our website and through the delivery of our Services, as defined in our Terms of Service located at https://antyvirtual.com/terms-of-service/ (“Terms”). Capitalized terms used but not defined here have the meaning given to them in our Terms.
If you have questions about this Policy, contact us at info@antyvirtual.com or 480-741-8608.
1. Our Services
Anty Virtual provides AI-assisted customer communication tools to businesses, including:
- Anty Connect — a messaging platform that allows our business customers to send and receive messages on their own WhatsApp Business and Instagram professional accounts;
- AI Voice Agents — inbound and outbound voice handling;
- Anty Cards — digital business cards;
- Reputation Management — review generation and response tools.
For most of our Services, Anty Virtual acts as a processor (or “service provider”) on behalf of our business customers, who are the controllers of the end-user data processed through the Services. Where we collect information directly from website visitors or prospective customers, we act as a controller.
2. Definitions
“Personal Information” means information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, such as:
- Identifiers (e.g., name, address, telephone number, email address, username, social media handle);
- Sensitive Personal Information (e.g., government identification number; contents of messages when we are not the intended recipient);
- Biometric information (e.g., voice recordings);
- Internet or other similar activity (e.g., browsing history, content interactions);
- Commercial information (e.g., products or services purchased, obtained, or considered);
- Inferences drawn from Personal Information to create a profile about preferences, characteristics, or behavior.
Personal Information does not include (i) publicly available information; (ii) aggregate information from which individual identities have been removed; or (iii) deidentified information that cannot reasonably be linked back to an individual.
“Meta Platform Data” means any data we obtain from or through the WhatsApp Business Platform, the Instagram Platform, the Messenger Platform, or any other Meta API or product.
We collect Personal Information (a) with your consent; (b) where we have a legitimate interest in doing so; or (c) as authorized or required by law.
3. Meta Platform Data — WhatsApp and Instagram
This section applies specifically to data we access through Meta’s platforms in connection with Anty Connect. It takes precedence over any other section of this Policy where the two conflict.
3.1 What we access
When a business customer connects their WhatsApp Business account or Instagram professional account to Anty Connect, we may access and process:
| Data type | Examples |
|---|---|
| Business account data | WhatsApp Business Account ID, business phone number ID, display name, Instagram professional account ID and username |
| Message content | The text, images, documents, audio, and other media sent between the business and the end user |
| End-user identifiers | Phone number, WhatsApp profile name, Instagram username, Instagram-scoped user ID |
| Message metadata | Timestamps, delivery and read status, message IDs, conversation threading |
| Comments and mentions | Where the business has authorized comment management on Instagram |
3.2 Why we process it
We process Meta Platform Data only to provide the Services our business customer has instructed us to provide. Specifically:
- To deliver incoming messages to the business’s Anty Connect inbox;
- To send messages and replies on the business’s behalf;
- To generate suggested or automated replies using AI, at the business’s configuration;
- To route conversations to the correct human agent within the business;
- To maintain conversation history so the business can respond in context;
- To provide the business with aggregate analytics about their own message volumes and response times;
- To maintain the security, integrity, and availability of the Services.
3.3 What we never do with it
We do not:
- Sell Meta Platform Data, or share it for cross-context behavioral advertising, under any circumstance;
- Use Meta Platform Data to build advertising audiences, target advertising, or perform ad measurement or attribution;
- Share Meta Platform Data with data brokers, information brokers, or advertising networks;
- Use Meta Platform Data to train, fine-tune, or improve any general-purpose AI or machine learning model, our own or a third party’s;
- Combine Meta Platform Data from one business customer with data from another;
- Use Meta Platform Data for any purpose other than delivering the Services to the business customer who authorized the connection.
The “Advertisers” disclosure in Section 8 and the CCPA sale and sharing disclosures in Section 13 apply only to website analytics and marketing cookie data collected through antyvirtual.com. They do not apply to Meta Platform Data, service data, or the contents of any customer conversation.
3.4 Automation and AI disclosure
Anty Connect may generate automated replies on behalf of a business. Where a message is generated by AI rather than a human, this is disclosed to the end user at the start of the conversation, and the end user may request a human agent at any time. Businesses using our Services are contractually required to maintain a human escalation path.
Where a business has enabled AI-generated replies, message content may be transmitted to third-party AI model providers solely for the purpose of generating that reply. These providers process the data under contract as our sub-processors, are prohibited from retaining the data beyond what is necessary to return a response, and are prohibited from using it to train their models.
3.5 Retention of Meta Platform Data
- Message content and metadata are retained for the duration of the business customer’s active subscription, so that the business can access their conversation history.
- On termination of a business customer’s account, all Meta Platform Data associated with that account is deleted within 30 days, except where retention is required by law.
- If a business customer disconnects their WhatsApp or Instagram account from Anty Connect, we cease all further processing immediately and delete the associated access tokens within 7 days.
- Where an end user requests deletion of their data, we comply as described in Section 4.
- If our access to Meta’s platforms is revoked or our agreement with Meta terminates, we delete all Meta Platform Data in our possession within 30 days, except where retention is required by law.
3.6 Security of Meta Platform Data
Meta Platform Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. Access tokens are stored encrypted and are never exposed to other customers. Internal access is restricted to personnel with a specific operational need, is logged, and requires multi-factor authentication.
4. Data Deletion
This section is our data deletion instructions page. It can be linked to directly at https://antyvirtual.com/privacy-policy/#data-deletion
4.1 If you are an end user who messaged a business
If you sent a message to a business through WhatsApp or Instagram and that business uses Anty Connect, you can request deletion of your data as follows:
- Email info@antyvirtual.com with the subject line “Data Deletion Request.”
- Include the phone number or Instagram username you used to contact the business, and the name of the business you contacted.
- We will verify the request. Verification may require confirming details already in our records; we will not ask you for more information than is necessary to confirm your identity.
- Because we hold this data on behalf of the business, we will notify that business of your request and act on their instruction where they are the controller. Where we are permitted to act directly, we will delete your data.
- We will complete the deletion, or respond explaining why an exception applies, within 30 days of verifying your request.
Deletion covers your message content, your identifiers, and any profile or inference data we hold about you. We may retain a minimal record of the deletion request itself, and any data we are legally required to keep.
You may also delete your own copy of the conversation within WhatsApp or Instagram directly. That action does not delete the business’s copy, which is why the request above exists.
4.2 If you are a business customer
You may request deletion of your account and all associated data by emailing info@antyvirtual.com or through your account dashboard. On termination, we delete your data within 30 days as described in Section 3.5. You may also export your data before deletion.
4.3 If you are a website visitor
Email info@antyvirtual.com to request deletion of any Personal Information we hold about you as a site visitor or prospective customer.
4.4 Our commitment
We honor verified deletion requests. Where we act as a processor for a business customer, we will either action the request directly or forward it to that customer and act on their documented instruction, and we will tell you which has happened. We will not refuse a deletion request on the basis that the data is commercially useful to us.
5. Information We Collect and From Whom
5.1 Consumers
We interact with consumers (“Consumers”) who call, text, message, or otherwise communicate with businesses we serve:
- We collect and use Personal Information from Consumers via phone, text, chat, email, SMS, MMS, WhatsApp, Instagram, and other channels as needed to provide our Services to our business customers.
- If you are a Consumer contacting one of our customers, we may collect your contact information and other identifiers, as well as the contents of your message. We collect this to support that business in assisting you.
5.2 Customers
- When you sign up as a business customer, we collect information about your company such as name, email, phone, billing details, and identifiers for you and your employees.
- You may provide us with your employees’ identifiers to grant them access to the Services.
- We collect information you submit via our dashboard, mobile application, or other software.
- You are solely responsible for ensuring you are authorized to share Personal Information with us. We reserve the right to refuse instructions to process Personal Information in a manner we determine violates privacy or publicity rights or our Terms, and such instructions may result in termination of Services.
5.3 Inquiries
- If you request information about our Services through a form, chat, text, email, or phone, we collect your name, email address, and other contact information needed to respond.
- Where state law allows, we may record calls with our team for quality monitoring and training. If you are in a state requiring notification, you will be notified. If you do not consent, you may end the call or ask not to be recorded.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect Personal Information, including:
- TLS 1.2 or higher for all data in transit;
- Encryption at rest for stored message content, credentials, and access tokens;
- Role-based access control, with access granted only to personnel with a specific operational need;
- Multi-factor authentication for all internal systems holding Personal Information;
- Access logging and periodic review;
- Regular security training for personnel with access to Personal Information.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your Personal Information, we will notify affected parties and regulators as required by applicable law.
7. Cookies and Web Server Logs
We use cookies and similar technologies on antyvirtual.com for authentication, preferences, analytics, and marketing. Some cookies are session-based and expire when you close your browser; others persist for a defined period.
You can control cookies through your browser settings. Rejecting non-essential cookies will not prevent you from using our Site. We recognize the Global Privacy Control (“GPC”) signal as an opt-out of sale and sharing.
We use IP addresses to analyze trends, administer our Site, and gather aggregate demographic information.
Cookies are not used within Anty Connect conversations and are not applied to Meta Platform Data.
8. Sharing
We may disclose Personal Information for a business purpose to:
- Affiliates. We may share Personal Information with affiliated companies where needed to provide integrated Services, for support, or for technical operations.
- Service Providers and Sub-processors. Vendors that provide services to us may receive Personal Information to perform their contractual obligations. These include cloud hosting providers, telecommunications providers, AI model providers, billing processors, and email providers. We prohibit our Service Providers from selling or disclosing the Personal Information we provide, and require confidentiality and security standards appropriate to the data.
- Advertisers. We may share website visitor data collected through cookies with advertising service providers for behavioral advertising. This never includes Meta Platform Data, message content, or service data.
- Law Enforcement and Government Agencies. Where required by law, court order, or where we perceive an imminent threat to physical safety.
- Business Transitions. In connection with a merger, acquisition, or sale of assets, subject to the acquiring party honoring this Policy.
- Aggregated and Deidentified Information. We may share aggregated or deidentified information that cannot reasonably be linked to an individual.
We do not sell Personal Information for monetary consideration.
9. International Transfers and Non-US Users
Anty Virtual operates in the United States and serves customers in Nigeria, Kenya, and other jurisdictions. Personal Information may be transferred to and processed in the United States or other countries where we or our Service Providers operate.
Where we process the personal data of individuals in Nigeria, we do so in a manner intended to comply with the Nigeria Data Protection Act 2023. Where we process the personal data of individuals in Kenya, we do so in a manner intended to comply with the Kenya Data Protection Act 2019. Where we process the personal data of individuals in the European Economic Area or United Kingdom, we do so in a manner intended to comply with the GDPR and UK GDPR, relying on Standard Contractual Clauses or another lawful transfer mechanism where required.
Individuals in these jurisdictions have rights of access, rectification, erasure, restriction, portability, and objection. Exercise them by emailing info@antyvirtual.com.
10. Children
Our Services are not directed to children. We do not knowingly collect Personal Information from anyone under 16. If you believe a child has provided us with Personal Information, contact info@antyvirtual.com and we will delete it.
11. Links to Other Sites
Our Site may contain links to other websites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy statements.
12. Changes to This Policy
If we change this Privacy Policy, we will post the updated version on our Site and update the “Last updated” date above. Material changes affecting Meta Platform Data will be communicated to affected business customers before taking effect.
13. US State Privacy Rights
State laws including the California Consumer Privacy Act (“CCPA,” as amended by the CPRA), the Virginia Consumer Data Protection Act (“VCDPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), and the Utah Consumer Privacy Act (“UCPA”) provide specific rights to consumers in those states.
For all Services data, Anty Virtual acts as a service provider or processor on behalf of our business customers. We process Personal Information only pursuant to our agreements with those customers, and we do not use it for any purpose outside those agreements.
13.1 Deletion and correction requests
We honor verified deletion and correction requests. Where you submit a request directly to us and we act as a processor, we will forward the request to the relevant business customer and act on their documented instruction, or action it directly where we are permitted to do so. In either case we will respond to you within 30 days of verifying the request. If a legal exception applies to any part of your request, we will identify it in our response.
13.2 Access requests
Business customers can access data through their dashboard. Consumers may submit access requests to info@antyvirtual.com; we will respond within 30 days of verification, and will coordinate with the relevant business customer where we hold the data on their behalf.
13.3 Categories of Personal Information collected
The following applies to the preceding 12 months.
| Category | Collected | Retention |
|---|---|---|
| A. Identifiers | Yes | Duration of the relationship, then deleted within 30 days, or as required by law |
| B. Personal information (Cal. Civ. Code § 1798.80) | Yes | Duration of the relationship, then deleted within 30 days, or as required by law |
| C. Protected classification characteristics | No | N/A |
| D. Commercial information | Yes | Duration of the relationship, or as required by law |
| E. Biometric information | No | N/A |
| F. Internet or network activity | Yes | 24 months |
| G. Geolocation data | Yes (approximate only) | 24 months |
| H. Sensory data (call recordings, voice) | Yes | Duration of the relationship, or as required by law |
| I. Professional or employment information | No | N/A |
| J. Non-public education information | No | N/A |
| K. Inferences | Yes | 24 months |
| L. Sensitive Personal Information (message contents where we are not the intended recipient) | Yes | Duration of the relationship, then deleted within 30 days, or as required by law |
13.4 Sale and sharing
We have not sold Personal Information for monetary consideration.
Our use of analytics and advertising cookies on antyvirtual.com may constitute “sharing” for cross-context behavioral advertising under the CCPA. This applies to categories A, F, and K, and to website visitor data only.
We do not sell or share Meta Platform Data, message content, call recordings, or any other service data, for advertising or any other purpose.
You may opt out of cookie-based sharing via the “Your Privacy Choices” link on our Site or by broadcasting the Global Privacy Control signal.
We do not knowingly sell or share the Personal Information of consumers under 16.
13.5 Limiting use of Sensitive Personal Information
We process Sensitive Personal Information — principally the contents of messages where we are not the intended recipient — solely to provide the Services requested by our business customers. We do not use it to infer characteristics about you, and we do not use or disclose it for any purpose that would trigger a Right to Limit request under California law.
13.6 Non-discrimination
We will not discriminate against you for exercising your privacy rights.
13.7 Verifying requests
To protect your Personal Information, we verify the identity of anyone submitting a request. We may ask for up to three pieces of information to compare against our records, and in some cases a signed declaration. We use information provided in a request only to verify identity and delete it after processing. You do not need an account with us to make a request.
13.8 Authorized agents
You may authorize an agent to submit requests on your behalf. We require written permission from you and may require you to verify your identity directly with us.
14. Contact Us
Anty Virtual, Inc. Email: info@antyvirtual.com Phone: 480-741-8608 Privacy requests: info@antyvirtual.com with subject line “Privacy Request” or “Data Deletion Request”