Antropo Solutions LLC

Privacy Policy

Antropo Solutions LLC

Effective Date: July 2026

Last Updated: July 2026


1. Introduction and Scope

This Privacy Policy ("Policy") describes how Antropo Solutions LLC, a Commonwealth of Puerto Rico limited liability company ("Company," "we," "us," or "our"), collects, uses, discloses, retains, and otherwise processes personal data in connection with its consulting, advisory, and export trade services and related web properties (collectively, the "Services"), and the rights available to individuals whose personal data we process.

The Company provides international strategic, management, and marketing consulting services and export trade services to business clients. This Policy applies to personal data processed through the Company's websites, communications, client engagements, and related back-end systems that constitute the Services. It does not govern the practices of any third party that the Company does not control, including independent advertising, analytics, hosting, or payment platforms.

This Policy forms part of, and is governed by, the Company's Terms of Service, which control in the event of any conflict and which contain binding arbitration, class-action and collective-action waiver, jury-trial waiver, limitation-of-liability, and contractual-limitations provisions that apply to disputes relating to the Services and to this Policy, except to the extent any such provision is unenforceable as to a particular claim or right under applicable data-protection law, including non-waivable rights and remedies under the California Consumer Privacy Act, as amended ("CCPA/CPRA"), and the European Union General Data Protection Regulation ("GDPR"), which are expressly preserved.

The Services are intended solely for persons eighteen (18) years of age or older. The Services are not directed to, and are not intended to be used by, minors. See Section 13 (Children's Privacy).


2. Controller Identity and How to Contact Us

For purposes of the GDPR, the United Kingdom GDPR, and analogous data-protection laws, the controller of personal data described in this Policy is:

Antropo Solutions LLC, a Commonwealth of Puerto Rico limited liability company.

The Company maintains a single channel for all privacy notices, data-subject and consumer requests, data-deletion requests, and other communications regarding this Policy:

info@antropo.us

All requests, questions, notices, and communications concerning this Policy, the processing of personal data, or the exercise of any right described herein must be directed to info@antropo.us. The Company, which operates exclusively online with respect to the Services, designates info@antropo.us as its method for receiving privacy and consumer requests. The Company will also honor opt-out preference signals (including the Global Privacy Control) and any additional request method required by applicable law.

All privacy and data-protection matters, including any request or inquiry described in this Policy, are handled through info@antropo.us, which is the Company's designated point of contact for such matters.

Where the Company processes business records, customer or contact lists, or other personal data on behalf of and under the instructions of a client in the course of a consulting, advisory, or export trade engagement, that client is generally the controller of such data and the Company acts as a processor or service provider. In that capacity, individuals should direct requests to the relevant client; the Company will assist that client in responding to the extent required by applicable law. For all data the Company processes as a controller — including site-visitor technical data described in Section 4, communications sent to the Company, and data processed for the Company's own web properties — the Company is the responsible controller and info@antropo.us is the operative contact.


3. Roles: Controller and Processor

The Company processes personal data in two distinct capacities:

(a) As a controller. With respect to ordinary visitors to the Company's own web properties, recipients of the Company's own communications, client representatives and prospective clients with whom the Company deals, and the Company's own records of its engagements, the Company determines the purposes and means of processing and acts as a controller. For all such data, the Company is the controller and will action data-subject and deletion requests directly under Section 12.

(b) As a processor / service provider. As a provider of consulting, advisory, and export trade services, the Company may receive, process, and store business records, customer or contact lists, market data, and related information on behalf of, and under the documented instructions of, the client that engages the Services. In that capacity the Company acts as a processor (GDPR) or service provider (California law) for that client, which is the controller of such data and bears primary responsibility for establishing a lawful basis and obtaining any required consents. The Company does not "sell" such data and processes it only to provide, secure, and perform the engaged Services as instructed and as permitted by applicable law.

(c) Written agreement governing the processor role. The Company's processing on behalf of a business is governed by a written data-processing agreement satisfying GDPR Article 28(3) (or the service-provider contract terms required by the CCPA/CPRA), which controls the Company's obligations in that capacity and is available to the business that uses the Services.

(d) Telephone-contact responsibility. Where client-provided data includes a telephone number, the client that engages the Services is the sole party responsible for obtaining any prior express consent or prior express written consent required under the Telephone Consumer Protection Act (47 U.S.C. § 227) and analogous federal and state laws before contacting an individual. The Company handles such data only as instructed and does not itself initiate marketing communications to individuals whose data it processes as a processor.


4. Categories of Personal Data We Process

Depending on how you interact with the Services, the Company may process the following categories of personal data:

CategoryExamplesSource
Technical / device identifiersIP address, device and browser type, operating system, language, screen attributes, referring/exit pages, timestamps, and similar request metadata.Collected automatically from site visitors.
Usage and interaction dataPages and resources requested, navigation paths, and diagnostic logs.Collected automatically.
Cookie and similar-technology identifiersCookie identifiers and local-storage values used for site operation and analytics.Collected automatically, subject to consent where required.
Business contact and engagement dataName, title, business email address, business telephone number, and employer or company details of client representatives, prospective clients, and counterparties; proposal, contract, and correspondence records.Provided by you or your organization.
Client-provided business dataBusiness records, customer or contact lists, market data, and other materials a client provides in the course of an engagement, which may incidentally include personal data.Provided by the client that engages the Services; processed by the Company as a processor or service provider.
Billing and transaction dataInvoicing details, transaction amounts and history, and payment status.Provided by you or generated in connection with an engagement; payment-card data is handled by independent payment platforms.
CommunicationsThe content of communications you send to info@antropo.us and related metadata.Provided by you.

The Company does not seek to collect, and asks that you not transmit to it, special categories of personal data (GDPR Article 9) or sensitive personal information beyond what is strictly necessary for an engagement. Where a client's materials incidentally include such data, the Company acts solely as a processor or service provider on the documented instructions of the controlling client, which is responsible for establishing the lawful basis and obtaining any consent required under GDPR Article 9 or the CCPA/CPRA before such data is provided to the Company.

The Company does not collect or process full payment-card numbers. Where payment is involved in any context, card data is handled by an independent payment platform and is not stored by the Company.


5. Purposes of Processing and Legal Bases

The Company processes personal data for the purposes set out below. For individuals in the European Economic Area ("EEA"), the United Kingdom, and Switzerland, the corresponding GDPR Article 6 (or, where applicable, Article 9) legal basis is identified.

PurposeDescriptionGDPR Legal Basis
Providing and operating the ServicesDelivering consulting, advisory, and export trade services under an engagement, and operating and maintaining the Company's web properties.Performance of a contract — Art. 6(1)(b); and/or processing on behalf of a controller under Art. 28 where the Company acts as processor.
Client relationship managementCommunicating with clients and prospective clients, preparing proposals and statements of work, and administering engagements.Performance of a contract or pre-contractual steps — Art. 6(1)(b); and/or legitimate interests — Art. 6(1)(f).
Billing and paymentsInvoicing, collecting payment through independent payment platforms, and maintaining transaction and accounting records.Performance of a contract — Art. 6(1)(b); and legal obligation — Art. 6(1)(c).
Security, fraud prevention, and integrityProtecting the Services, detecting and preventing abuse, fraud, and unauthorized access, and maintaining diagnostic and audit logs.Legitimate interests — Art. 6(1)(f); and legal obligation — Art. 6(1)(c).
Service improvement and analyticsUnderstanding usage in aggregate and improving the reliability, performance, and features of the Services.Legitimate interests — Art. 6(1)(f); or consent — Art. 6(1)(a) — where required.
Communications and request handlingResponding to inquiries and to data-subject and consumer requests submitted to info@antropo.us.Performance of a contract or pre-contractual steps — Art. 6(1)(b); legal obligation — Art. 6(1)(c); and/or legitimate interests — Art. 6(1)(f).
Legal compliance and defenseComplying with applicable law, responding to lawful requests, and establishing, exercising, or defending legal claims.Legal obligation — Art. 6(1)(c); and legitimate interests — Art. 6(1)(f).

For any non-essential analytics or advertising technologies deployed on the Company's web properties, the Company relies on consent (Art. 6(1)(a)) where required, including in the EEA, the United Kingdom, and Switzerland. Where the Company relies on legitimate interests, those interests are the operation, security, and improvement of the Services and the administration of client engagements; the Company has assessed that such processing is not overridden by the interests or fundamental rights and freedoms of data subjects, and you may object as described in Section 11. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.


6. Cookies and Similar Technologies

The Company and the Services use cookies, pixels, tags, software development kits, local storage, and similar technologies for the following general categories of purpose:

Where required by applicable law, non-essential cookies and similar technologies are deployed only with consent, which you may manage or withdraw through available controls.

Opt-out preference signals (Global Privacy Control). The Company recognizes, processes, and honors the Global Privacy Control ("GPC") and other recognized browser- or device-level opt-out preference signals as a valid request to opt out of the "sale" or "sharing" of personal information, and of targeted and cross-context behavioral advertising, for the browser or device from which the signal is sent. When such a signal is detected, the Company suppresses the loading and firing of non-essential advertising and measurement technologies, and the transmission of advertising or measurement event signals to third-party platforms, for that browser or device, and maintains records sufficient to demonstrate that the signal was processed, where required by applicable law. The Company honors GPC; it does not separately respond to legacy "Do Not Track" browser signals.

Your consent to tracking technologies and electronic communications. By accessing or using the Services without enabling an opt-out preference signal (such as GPC) and, where a consent mechanism is presented, by accepting it, you knowingly and voluntarily consent to the use of the cookies, pixels, tags, software development kits, session and analytics tools, and similar technologies described in this Policy, and to the collection, recording, processing, and transmission of your interactions with the Services to the Company, its service providers, and the third-party platforms described in Section 7, for the purposes described in this Policy. To the fullest extent permitted by law, this consent constitutes your consent to, and authorization of, any "recording," "interception," "reading," "monitoring," or "eavesdropping" upon your communications or interactions with the Services within the meaning of any applicable federal or state electronic-communications, wiretapping, eavesdropping, or privacy statute, including the California Invasion of Privacy Act (Cal. Penal Code §§ 630 et seq.) and analogous laws of other jurisdictions. You may withdraw this consent at any time by enabling GPC, adjusting available controls, or discontinuing use of the Services; withdrawal does not affect the lawfulness of any processing carried out before withdrawal.


7. How We Disclose Personal Data

The Company does not sell personal data for monetary consideration. The Company discloses personal data only in the following circumstances:

(a) Service providers and processors. To vendors that perform services on the Company's behalf, such as hosting, content delivery, infrastructure, security, payment processing, and analytics, under contractual obligations to protect the data and use it only as instructed.

(b) Analytics and advertising platforms. Where the Company's web properties deploy third-party analytics or advertising tools, technical and usage data may be shared with the providers of those tools — which may include, among others, Google, Meta Platforms, Inc., or similar providers — through those providers' published interfaces. Such platforms process that data under their own privacy policies and terms, which govern their independent practices and over which the Company has no control. Certain of these disclosures may constitute a "sale" or "sharing" of personal information under California law, and you may opt out as described in Section 10. As of the Last Updated date, the Company's web properties do not deploy non-essential third-party advertising or measurement technologies.

(c) Payment platforms. To independent payment platforms that process transactions, which handle payment-card and transaction data under their own policies.

(d) Legal, safety, and compliance. To courts, regulators, law-enforcement authorities, or other parties when the Company believes in good faith that disclosure is necessary to comply with applicable law or legal process, to enforce the Company's terms, to protect the rights, property, or safety of the Company or others, or to detect, prevent, or address fraud or security issues.

(e) Business transfers and successors. In connection with, or during negotiations of, any merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or transition of service, personal data may be transferred to a successor or affiliate as part of that transaction or transition. Any successor will be bound to honor the commitments in this Policy with respect to personal data collected before the transfer unless and until you are provided notice of, and (where required by applicable law) consent to, a materially different policy.

(f) With consent or at your direction. When you have otherwise consented to or directed the disclosure.

(g) Aggregated or de-identified data. The Company may create and disclose aggregated or de-identified data that does not reasonably identify any individual, and will maintain and use such data only in de-identified form except as permitted by law.


8. International Data Transfers

The Company is established in the Commonwealth of Puerto Rico, United States, and its service providers and the third-party platforms it integrates with are located in the United States and other jurisdictions. As a result, personal data may be transferred to, stored in, and processed in countries other than the country in which it was collected, including countries that may not provide the same level of data protection as your home jurisdiction.

Where personal data of individuals in the EEA, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy determination, the Company relies on appropriate safeguards recognized under applicable law, including the European Commission's Standard Contractual Clauses and, for transfers subject to UK law, the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses, together with supplementary measures where appropriate. You may request further information about these safeguards by contacting info@antropo.us.


9. Data Security

The Company maintains administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, taking into account the nature of the data and the state of the art. These measures may include encryption in transit, access controls, network protections, and logging.

No method of transmission over the internet or method of electronic storage is completely secure, and the Company cannot and does not guarantee absolute security. While the Company maintains reasonable security measures, no system is completely secure, and this disclaimer does not limit any right or remedy that cannot be waived under applicable law.

Where the Company processes personal data as a processor on behalf of a business that uses the Services, the Company will notify that business of a personal-data breach affecting such data without undue delay after becoming aware of it, and will reasonably assist the business with its own notification obligations. In the event of a personal-data breach affecting data for which the Company is a controller, the Company will notify affected individuals and the relevant authorities to the extent and within the timeframes required by applicable law.


10. United States State Privacy Rights (Including California)

This Section applies to residents of U.S. states that have enacted comprehensive consumer-privacy laws, including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, in each case to the extent the applicable law applies to the Company's processing of your personal data.

10.1 Your Rights

Subject to applicable law and verification, you may have the right to:

10.2 California — CCPA / CPRA Disclosures

Under the CCPA/CPRA, the Company discloses the following regarding its collection of personal information over the preceding twelve (12) months, or, if shorter, the period since the Company began operating the Services:

To opt out of "sale" or "sharing," you may (i) submit a request to info@antropo.us, and/or (ii) enable the Global Privacy Control, which the Company recognizes as a valid opt-out signal for the browser or device from which it is sent. The Company does not discriminate against you for exercising any right.

California residents may use an authorized agent to submit requests; the Company may require the agent to demonstrate authority and may require you to verify your identity directly.

10.3 Non-Applicability Statements

The Company is not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act ("HIPAA"), and the Services are not intended to process protected health information. The Company is not a "data broker" as that term is defined under applicable state law.


11. Rights of Individuals in the EEA, the United Kingdom, and Switzerland

If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights under the GDPR and equivalent laws, subject to the conditions and exceptions provided by applicable law:

To exercise any of these rights, contact info@antropo.us. The Company will respond within the timeframe required by applicable law (see Section 12). Where the Company processes your data as a processor on behalf of a business that uses the Services, the Company will refer your request to that business or assist it in responding, as appropriate.

Automated decision-making. The Company does not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing within the meaning of GDPR Article 22. Analytics carried out through the Company's web properties are statistical and aggregate and are not used by the Company to make such decisions about individuals. Clients that engage the Services are responsible for any automated decision-making they perform using data or Output provided through the Services.


12. How to Submit a Request and How We Verify It

All data-subject, consumer, and data-deletion requests are submitted to a single channel: info@antropo.us. To help us process your request, please include enough information for us to identify the relevant data and the right you wish to exercise.

Response timeframes. For requests under California and other U.S. state privacy laws, the Company will confirm receipt within ten (10) business days and provide a substantive response within forty-five (45) calendar days, extendable by an additional forty-five (45) days where permitted, with notice. For requests under the GDPR or UK GDPR, the Company will respond within one (1) month, extendable by two (2) further months for complex or numerous requests, with notice.

Data-deletion path — plain steps:

  1. Send an email to info@antropo.us with the subject line "Data Deletion Request."
  2. Describe the personal data or the interaction (for example, the website, the approximate date, and the email address, device, or identifier involved) so that we can locate the relevant records.
  3. We will acknowledge your request and may take reasonable steps to verify your identity or authority, proportionate to the sensitivity of the data, before acting.
  4. Upon verification, we will delete or de-identify the personal data we hold as a controller, and instruct our processors to do the same, within thirty (30) days of verifying the request (or such shorter period as applicable law requires), except where retention is permitted or required by law (see Section 14).
  5. Where the data was processed on behalf of a business that uses the Services, we will forward or coordinate the request with that business, which is the controller of such data.
  6. We will confirm completion to you by reply to info@antropo.us.

We do not charge a fee to process most requests, but we may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive, as permitted by applicable law, and will explain any such decision.


13. Children's Privacy

The Services are intended exclusively for persons eighteen (18) years of age or older. The Company does not direct the Services to minors and does not knowingly collect personal data from anyone under the age of eighteen. Consistent with the Children's Online Privacy Protection Act ("COPPA"), the Company does not knowingly collect personal data from children under thirteen (13); if it learns that it has done so, it will delete that data promptly. If the Company learns that it has collected personal data from a person under eighteen, it will take reasonable steps to delete that data. If you believe a minor has provided personal data through the Services, contact info@antropo.us.


14. Data Retention

The Company retains personal data only for as long as necessary to fulfill the purposes for which it was collected, including to provide and secure the Services, to comply with legal, accounting, or reporting obligations, to resolve disputes, and to enforce agreements. Retention periods are determined by criteria including: the nature and sensitivity of the data; the purposes of processing; the period necessary to deliver and measure the Services; applicable legal, tax, and regulatory retention requirements; and the existence of any actual or anticipated legal claim.

As general guidance, and subject to the criteria above and to any contrary instruction from a client or requirement of law: diagnostic and security logs are generally retained for up to ninety (90) days; proposal, engagement, billing, and tax records are retained for the periods required by applicable commercial, tax, and accounting law; client-provided business data is retained for the duration of the engagement and is generally returned or deleted within a reasonable period after its conclusion; and communications are generally retained for as long as needed to handle and document the matter to which they relate.


15. Third-Party Platforms and Automated Systems — Disclaimer

The Services interoperate with independent third-party platforms, including analytics, hosting, and payment platforms, and with automated systems. The Company is not affiliated with, endorsed by, sponsored by, or acting on behalf of any such third-party platform, and all third-party names and marks are the property of their respective owners and are used solely for identification and interoperability.

Such third-party platforms collect and process data under their own privacy policies and terms, which govern their independent practices and over which the Company has no control. The Company's access to and use of any third-party platform is subject to that platform's terms, policies, and technical requirements, which the platform may change, restrict, suspend, or terminate at any time and outside the Company's control. To the fullest extent permitted by applicable law, the Company disclaims responsibility and liability for the independent data-handling practices, availability, accuracy, security, acts, or omissions of any third-party platform that the Company does not control, and for any measurement, attribution, or conversion output, which is inherently estimative and may be incomplete, delayed, or different from a platform's own reporting. Nothing in this Section limits the Company's own obligations as a controller or processor under applicable data-protection law, or any liability that cannot be disclaimed. You should review the privacy policies of any third-party platform with which you interact.

Artificial intelligence and automated systems. The Services may incorporate artificial-intelligence, machine-learning, and other automated systems, and certain content or output made available through the Services may be generated or assisted by such systems. Where the Company makes AI-generated or AI-assisted output available, it identifies that output as such where required by applicable law. Such output is provided for general informational purposes, may be inaccurate, incomplete, or unsuited to your particular circumstances, and is not professional, legal, financial, medical, psychological, or other regulated advice; you are responsible for independently evaluating any output before relying on it. The Company does not use solely-automated processing to make decisions producing legal or similarly significant effects concerning you except as disclosed and as permitted under applicable law.

This Section is provided in addition to, and does not limit, the disclaimers, limitations of liability, and other protective provisions set forth in the Company's Terms of Service.


16. Changes to This Policy

The Company may modify this Policy from time to time. The Company will indicate the date of the most recent revision by updating the "Last Updated" date at the top of this Policy, and, for material changes, will provide additional notice as required by applicable law, including by posting the revised Policy. Changes take effect on the stated effective date.

For changes that do not materially affect your rights, your continued use of the Services after the effective date constitutes acknowledgment of the updated Policy to the extent permitted by applicable law. The Company will not apply materially different processing — including any new category of "sale" or "sharing," or any new purpose incompatible with the purpose for which data was collected — to previously collected personal data without providing notice and, where required by applicable law, obtaining your consent. We encourage you to review this Policy periodically.


17. Contact

For all matters relating to this Policy, the processing of your personal data, or the exercise of any right described herein — including data-deletion requests — contact:

Antropo Solutions LLC
151 Calle de San Francisco, Suite 200 (PMB 0151)
San Juan, Puerto Rico 00901
info@antropo.us

This is the sole and operative channel for privacy notices and requests. The Company will also honor opt-out preference signals (including the Global Privacy Control) and any additional request method required by applicable law.

18. State-Specific Privacy Rights Addendum

This Section supplements, and does not replace, limit, or supersede, the United States state privacy disclosures set out in Section 10, the Global Privacy Control and opt-out-signal commitments set out in Sections 6 and 10, the sensitive-data treatment described in Sections 4 and 10, and the request-handling procedures described in Section 12. To the extent a right described in this Section is also described in Section 10, the two are cumulative and are read together; nothing in this Section narrows any right granted in Section 10. The rights enumerated below apply only to residents of the identified state, only to the extent the applicable state comprehensive consumer-privacy law applies to the Company's processing of that resident's personal data, and only subject to the verification, authorized-agent, exception, and exemption provisions of that law and of Sections 12 and 19. Where the Company processes personal data as a processor or service provider on behalf of a business that uses the Services, the Company will refer the request to, or assist, the controlling business as described in Sections 3, 10, and 12, and the rights below are exercised against that controlling business in the first instance. Each right described below is exercised through, and only through, info@antropo.us, together with the Global Privacy Control and any additional request method required by the applicable law, as described in Sections 6, 10, and 12.

18.1 California (CCPA/CPRA — California Consumer Privacy Act, as amended by the California Privacy Rights Act). A California resident has the rights described in Sections 10.1 and 10.2, which are incorporated here by reference, including the rights to know and access, to delete, to correct, to opt out of the "sale" or "sharing" of personal information and of cross-context behavioral advertising, to limit the use and disclosure of sensitive personal information to the extent a limitation right is triggered, to non-discrimination and non-retaliation for exercising any right, and, where provided, to appeal. The Company recognizes the Global Privacy Control as a valid opt-out preference signal as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.2 Virginia (VCDPA — Virginia Consumer Data Protection Act). A Virginia resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal the Company's refusal to act on a request within a reasonable period, with the ability to contact the Attorney General if the appeal is denied. These rights are exercised through info@antropo.us.

18.3 Colorado (CPA — Colorado Privacy Act). A Colorado resident has the rights to access and confirm processing; to correct inaccuracies; to delete personal data; to obtain a portable copy of personal data the resident previously provided in a portable and, to the extent technically feasible, readily usable format; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.4 Connecticut (CTDPA — Connecticut Data Privacy Act). A Connecticut resident has the rights to confirm processing and access; to correct inaccuracies; to delete personal data; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to submit a complaint to the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.5 Utah (UCPA — Utah Consumer Privacy Act). A Utah resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to delete personal data the resident provided to the Company; to obtain a portable copy of personal data the resident previously provided; and to opt out of the processing of personal data for purposes of targeted advertising and the sale of personal data. These rights are exercised through info@antropo.us.

18.6 Texas (TDPSA — Texas Data Privacy and Security Act). A Texas resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.7 Oregon (Oregon Consumer Privacy Act). An Oregon resident has the rights to confirm whether the Company processes the resident's personal data and to obtain a list of the specific categories of third parties to which the Company has disclosed personal data; to access that data; to correct inaccuracies; to delete personal data; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to submit a complaint to the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.8 Montana (MCDPA — Montana Consumer Data Privacy Act). A Montana resident has the rights to confirm processing and access; to correct inaccuracies; to delete personal data; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.9 Delaware (Delaware Personal Data Privacy Act). A Delaware resident has the rights to confirm whether the Company processes the resident's personal data and to obtain a list of the categories of third parties to which the Company has disclosed personal data; to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.10 Iowa (Iowa Consumer Data Protection Act). An Iowa resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to delete personal data the resident previously provided; to obtain a portable copy of personal data the resident previously provided; and to opt out of the sale of personal data, together with the disclosures and opt-out treatment required by the applicable law; and to appeal a refusal to act, with the ability to contact the Attorney General. These rights are exercised through info@antropo.us.

18.11 Nebraska (Nebraska Data Privacy Act). A Nebraska resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.12 New Hampshire (New Hampshire privacy law — SB 255). A New Hampshire resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.13 New Jersey (New Jersey Data Privacy Act). A New Jersey resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to submit a complaint to the relevant Division of Consumer Affairs or Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.14 Minnesota (Minnesota Consumer Data Privacy Act). A Minnesota resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; to obtain a list of the specific categories of third parties to which the Company has disclosed personal data; to question the result of profiling and, where applicable, to be informed of the reason; and to appeal a refusal to act, with the ability to submit a complaint to the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.15 Maryland (Maryland Online Data Privacy Act). A Maryland resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to obtain a list of the categories of third parties to which the Company has disclosed personal data; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. Consistent with the heightened sensitive-data and data-minimization limitations of the applicable law, the Company's processing of any data that constitutes sensitive data is constrained as described in Sections 4 and 10. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.16 Tennessee (TIPA — Tennessee Information Protection Act). A Tennessee resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. These rights are exercised through info@antropo.us.

18.17 Indiana (Indiana Consumer Data Protection Act). An Indiana resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain either a copy or a representative summary of personal data the resident previously provided in a portable and, to the extent technically feasible, readily usable format; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. These rights are exercised through info@antropo.us.

18.18 Kentucky (Kentucky Consumer Data Protection Act). A Kentucky resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects; and to appeal a refusal to act, with the ability to contact the Attorney General. These rights are exercised through info@antropo.us.

18.19 Rhode Island (Rhode Island Data Transparency and Privacy Protection Act). A Rhode Island resident has the rights to confirm whether the Company processes the resident's personal data and to access that data; to correct inaccuracies; to delete personal data provided by or obtained about the resident; to obtain a portable copy of personal data the resident previously provided; and to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects, together with the categories-of-third-parties and other disclosures required by the applicable law; and to appeal a refusal to act, with the ability to contact the Attorney General. The Company recognizes a universal opt-out mechanism, including the Global Privacy Control, where and as required by the applicable law and as described in Sections 6 and 10. These rights are exercised through info@antropo.us.

18.20 General provisions applicable to all states in this Section. (i) The rights stated above are subject to the exemptions, exceptions, thresholds, applicability conditions, and entity- and data-level carve-outs of each respective law, and the Company's obligation to act on any request is conditioned on the applicable law actually applying to the Company and to the personal data at issue. (ii) Nothing in this Section creates a private right of action, a contractual right, or any remedy not provided by the applicable state law; enforcement of the underlying statutes is vested in the respective state authorities. (iii) Where a resident's state is not separately enumerated above but has enacted a comprehensive consumer-privacy law that applies to the Company's processing, the resident may exercise the rights granted by that law through info@antropo.us, and this Section is read to extend to that state to the extent the law requires. (iv) All rights in this Section are exercised, verified, and (where permitted) limited or declined in accordance with Sections 12 and 19, including the identity-verification, authorized-agent, anti-abuse, fee, and rate-limit provisions of Section 19.


19. Verification, Authorized Agents, Anti-Abuse, Fees, and Rate Limits for Requests

This Section supplements the request-handling and verification provisions of Section 12 and the appeal and opt-out provisions of Sections 10 and 18, and applies to every request, inquiry, complaint, appeal, or other communication submitted under this Policy. Nothing in this Section is intended to, or shall, deny, defeat, or impair the exercise of any right that cannot be conditioned, charged for, or denied under applicable data-protection law, including the non-waivable rights and remedies of the CCPA/CPRA and the GDPR, which are expressly preserved; this Section operates only to the extent the applicable law permits identity verification, agent authentication, fees, and refusal or rate-limiting of abusive requests.

19.1 Identity verification. Before acting on a request, the Company may take reasonable steps, proportionate to the nature and sensitivity of the personal data and to the right asserted, to verify that the requester is the individual who is the subject of the personal data, or a person lawfully authorized to act on that individual's behalf. The Company may request additional information reasonably necessary to verify identity and to match the requester to the personal data the Company holds, may decline to act where it cannot verify identity to a reasonable degree of certainty as permitted by applicable law, and will not use information collected for verification for any purpose other than verification, fraud prevention, security, and recordkeeping required by law. Where applicable law requires the Company to delete personal data collected solely for verification, the Company will do so following completion of the request.

19.2 Authorized agents. A requester may use an authorized agent to submit a request where applicable law so permits. The Company may require the authorized agent to provide proof of the agent's authority to act on the individual's behalf — including, as permitted by applicable law, written and signed permission, a valid power of attorney, or other documentation sufficient to demonstrate the agent's authority — and may additionally require the individual on whose behalf the request is made to verify their own identity directly with the Company and to confirm to the Company that they authorized the agent to submit the request. The Company may deny a request from a purported agent who does not submit proof of authority satisfying these requirements, as permitted by applicable law.

19.3 Manifestly unfounded, excessive, repetitive, automated, or bulk requests. To the extent permitted by, and subject to, applicable law, where a request is manifestly unfounded, frivolous, excessive, repetitive, or made in bad faith — including, without limitation, requests that are duplicative of a request the Company has already substantively answered within a recent period, requests that are part of a coordinated, mass, or campaign-driven submission, requests submitted by or through automated means or in bulk, and requests whose evident purpose is to harass the Company, to extract proprietary or competitive information, to burden the Company's operations, or to weaponize the request process — the Company may, as the applicable law allows, either (i) charge a reasonable fee taking into account the administrative costs of providing the information, communication, or action requested, or (ii) decline to act on the request. Where the Company charges a fee or declines to act, it will inform the requester and, where required by applicable law, explain the basis for the decision and describe any available appeal or complaint mechanism. The burden of demonstrating that a request is manifestly unfounded or excessive remains with the Company to the extent the applicable law so provides.

19.4 Reasonable rate limits. The Company may apply reasonable limits on the number of requests it will process from a single individual, household, device, agent, or coordinated group within a defined period, consistent with the per-period request limits and "twice in a twelve-month period" or analogous thresholds recognized by applicable law. The Company may aggregate, for purposes of these limits, requests that originate from a common source, that are substantially similar in form or content, or that the Company reasonably determines to be part of a single coordinated submission, and may treat such aggregated requests as repetitive or excessive under Section 19.3 to the extent the applicable law permits.

19.5 Abuse of regulatory, complaint, chargeback, and dispute processes. Submission of a request under this Policy does not waive, and the Company does not waive, any of its rights or defenses. Nothing in this Policy limits the Company's right to defend itself against, and to pursue all remedies available at law or in equity in response to, the bad-faith, vexatious, fraudulent, or coordinated abuse or weaponization of privacy-request, data-subject-request, regulatory-complaint, chargeback, payment-dispute, or litigation processes, including the assertion of knowingly false statements to a regulator, payment provider, or tribunal. Such remedies, to the extent permitted by applicable law and subject to the non-waivable rights preserved throughout this Policy and in the Company's Terms of Service, include actual damages, injunctive and other equitable relief, and recovery of costs and fees as permitted by law. This Section does not abridge any genuine right of an individual to submit a request, to lodge a complaint with a supervisory authority or regulator, or to dispute a charge through a lawful and good-faith process.

19.6 Recordkeeping. The Company may retain records of requests, verifications, fees, refusals, rate-limit determinations, and related correspondence to the extent reasonably necessary to demonstrate compliance with applicable law, to evaluate whether subsequent requests are repetitive or excessive, and to detect and prevent abuse, consistent with the retention criteria in Sections 14 and 21.


20. No Scraping, No Automated Harvesting, and Permitted-Use Restrictions

This Section governs the access to, and use of, this Policy, the Company's web properties, content, interfaces, application programming interfaces, and the Services (collectively for purposes of this Section, the "Properties"), and is in addition to, and does not limit, the access, use, license, and conduct restrictions in the Company's Terms of Service, which control in the event of conflict.

20.1 Prohibited automated access and harvesting. Except as expressly authorized in writing by the Company or as required to be permitted by applicable law, you shall not, and shall not authorize, enable, or assist any person or automated system to: (i) access, scrape, crawl, spider, index, harvest, scan, mine, copy, download, cache, reproduce, or extract this Policy, any other Company policy or content, or any portion of the Properties, by any automated or bulk means, including bots, crawlers, scrapers, headless browsers, scripts, data-mining tools, or similar technologies, other than the operation of a standards-compliant search-engine crawler acting in accordance with the Company's published machine-readable access directives; (ii) bypass, disable, or circumvent any robots-exclusion directive, rate limit, access control, technical measure, or other restriction the Company employs to control access to or use of the Properties; (iii) aggregate, republish, redistribute, frame, mirror, or create a derivative database from the Properties; or (iv) access the Properties through any automated process at a volume, frequency, or in a manner that imposes, or is intended to impose, an unreasonable or disproportionate burden on the Company's infrastructure.

20.2 No competitive, benchmarking, or intelligence use. Except as expressly authorized in writing by the Company, you shall not access or use this Policy, the Properties, or any data, content, or output obtained from them for purposes of competitive intelligence, market or competitive analysis, benchmarking, monitoring, or comparison; to design, develop, train, market, or operate a competing or substantially similar product, service, or offering; to reverse engineer, reverse compile, disassemble, or otherwise attempt to derive the source code, structure, organization, methods, or underlying ideas of the Services except to the limited extent such restriction is prohibited by applicable law; or to build, populate, or enrich any product, dataset, model, or service intended to compete with, replicate, or displace the Company's Services.

20.3 No use for AI or machine-learning training. Except as expressly authorized in writing by the Company, you shall not use this Policy, the Properties, or any data, content, text, output, or other material obtained from them, in whole or in part, as input to, or to develop, train, fine-tune, evaluate, benchmark, ground, retrieve-augment, or otherwise improve, any artificial-intelligence, machine-learning, large-language-model, or other automated or generative system or dataset. The Company expressly reserves all rights with respect to text-and-data-mining and machine-learning uses of the Properties to the fullest extent permitted by applicable law, and the availability of any portion of the Properties to the public does not constitute a license, waiver, or grant of permission for any use restricted by this Section.

20.4 Reservation of rights and remedies. All rights not expressly granted are reserved by the Company. Unauthorized access to or use of the Properties in violation of this Section is without license and may violate intellectual-property, computer-fraud, contract, trespass-to-chattels, unfair-competition, and other laws. To the fullest extent permitted by applicable law, the Company may pursue all available remedies for any violation of this Section, including actual damages, injunctive and other equitable relief, restitution and disgorgement where available, and recovery of costs and fees as permitted by law, and may revoke access, deploy technical countermeasures, and report violations to the appropriate authorities. Nothing in this Section restricts any use that applicable law makes non-restrictable, or any genuine exercise by an individual of a data-protection right described elsewhere in this Policy.


21. Supplemental Security, Breach-Response, Retention-Criteria, and International-Transfer Provisions

This Section supplements, and does not limit or replace, the data-security provisions of Section 9, the data-retention provisions of Section 14, the international-data-transfer provisions of Section 8, and the disclosure provisions of Section 7. The "no absolute security" disclaimer in Section 9, the retention criteria and indicative periods in Section 14, and the transfer-safeguard mechanisms in Section 8 remain fully in force and are read together with the detail below.

21.1 Supplemental security detail. The administrative, technical, and organizational measures referenced in Section 9 may, depending on the nature of the data and the state of the art, include: encryption of personal data in transit and, where appropriate, at rest; role-based and least-privilege access controls and authentication requirements for personnel and systems; network segmentation, firewalling, and traffic-filtering controls; logging, monitoring, and anomaly-detection of access to and use of systems that process personal data; secure software-development and change-management practices; vendor and processor due-diligence and contractual security obligations; and periodic review of the foregoing. The Company does not represent or warrant that these measures are exhaustive, uninterrupted, or proof against every threat, and, as stated in Section 9, no method of transmission or storage is completely secure and the Company cannot and does not guarantee absolute security; this provision does not limit any right or remedy that cannot be waived under applicable law.

21.2 Prohibited interference with the Company's security. Except as expressly authorized in writing by the Company, you shall not conduct, attempt, or facilitate any security testing, vulnerability scanning, penetration testing, credential testing, denial-of-service activity, or other probing, scanning, or testing of the security, integrity, or availability of the Properties or the Company's systems; circumvent, disable, or interfere with any security-related feature, authentication, rate limit, or access control; or access any account, system, data, or network without authorization. Unauthorized security testing is not consented to, is not authorized, and may violate applicable computer-fraud and other laws; the Company reserves all rights and remedies described in Sections 19.5 and 20.4 with respect to any such activity, in each case subject to the non-waivable rights preserved throughout this Policy.

21.3 Supplemental breach-response detail. In addition to the notification commitments in Section 9, in the event of a personal-data breach the Company will, to the extent and within the timeframes required by applicable law: assess the nature, scope, categories of data, and approximate number of individuals and records affected; take reasonable steps to contain and remediate the incident and to mitigate adverse effects; where the Company is a controller, notify affected individuals and the competent supervisory authority or regulator where and as required, including within the timeframes prescribed by applicable law; and, where the Company processes the affected data as a processor or service provider on behalf of a business that uses the Services, notify that business without undue delay after becoming aware of the breach and reasonably assist that business with its own assessment and notification obligations. The Company's provision of breach notice is not, and shall not be construed as, an acknowledgment of fault, liability, or wrongdoing, except to the extent applicable law provides otherwise.

21.4 Supplemental retention-criteria detail. In applying the retention criteria stated in Section 14, the Company determines retention periods by reference to, among other factors: the nature, volume, and sensitivity of the personal data and the potential risk of harm from unauthorized use or disclosure; the purposes for which the data is processed and whether those purposes can be achieved by other means; the configuration and documented instructions of any business that uses the Services with respect to data the Company processes as a processor; applicable statutory, tax, accounting, regulatory, and contractual retention requirements and limitation periods; the existence, anticipation, or reasonable foreseeability of any claim, dispute, investigation, audit, or legal hold, during the pendency of which the Company may retain relevant data notwithstanding the indicative periods in Section 14; and the records reasonably necessary to demonstrate compliance with this Policy and applicable law and to detect and prevent abuse, fraud, and security incidents. When personal data is no longer required under these criteria, the Company deletes or de-identifies it as described in Sections 14 and 12. The indicative retention periods in Section 14 are maximum general guidance and do not create a right to have data retained for any particular period.

21.5 Supplemental international-transfer detail. Further to Section 8, where the Company transfers personal data of individuals in the EEA, the United Kingdom, or Switzerland to a jurisdiction that has not received an adequacy determination, the Company relies on the appropriate safeguards identified in Section 8 — including the European Commission's Standard Contractual Clauses and, for transfers subject to UK law, the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses — and, where appropriate, implements supplementary technical, organizational, and contractual measures, conducts or reviews transfer risk assessments, and imposes onward-transfer and confidentiality obligations on recipients. Where the Company processes data as a processor on behalf of a business that uses the Services, transfers are additionally governed by the data-processing agreement referenced in Section 3. You may request further information about the transfer safeguards applicable to your personal data by contacting info@antropo.us.


22. Relationship to Other Sections; No Limitation of Preserved Rights

The provisions added in Sections 18 through 21 are supplemental to, and shall be read together with and so as not to conflict with, the remainder of this Policy, including the Global Privacy Control and opt-out-signal commitments in Sections 6 and 10, the electronic-communications consent and California Invasion of Privacy Act provisions in Section 6, the sensitive-data and special-category-data treatment in Sections 4 and 10, the legal-basis and transparency disclosures in Section 5, the United States state privacy rights in Section 10, the EEA/UK/Switzerland rights in Section 11, the request-handling procedures in Section 12, and the security, retention, and international-transfer provisions in Sections 8, 9, and 14. In the event of any apparent conflict between a provision added in Sections 18 through 21 and a right that cannot be waived, conditioned, or limited under applicable data-protection law — including the non-waivable rights and remedies of the CCPA/CPRA and the GDPR, and the protections of any applicable consumer-protection, unfair-or-deceptive-acts-or-practices, or other mandatory law — the non-waivable right controls and the supplemental provision is enforced only to the maximum extent it lawfully may be. Nothing in Sections 18 through 21 is intended to, or shall be construed to, waive or disclaim liability for fraud, gross negligence, or willful misconduct, or for death or bodily injury caused by negligence, or to limit any statutory right or remedy that applicable law prohibits limiting.


*This Policy is self-contained and references third-party platform policies only generically. It does not incorporate by reference any external document except the Company's Terms of Service, which control in the event of conflict.*