Data processing.
Last updated 5 October 2026
This page summarises how Anthill handles customer data when an organisation uses ant.. The binding terms are in the Data Processing Agreement (DPA) that forms part of each customer agreement. To request a copy, email us.
1. Where ant. runs
ant. is deployed inside the customer’s own environment, on premises or in the customer’s cloud, with the AI model included. Customer data stays in that environment and is not sent to Anthill, AI providers or the internet.
2. Roles
The customer is the controller (or data fiduciary) of its data. Where Anthill processes customer personal data, for example when a customer gives our engineers access to provide support, Anthill acts as processor and only on the customer’s documented instructions.
3. Access and approvals
ant. sees only what each person it works for is allowed to see, using the customer’s existing access controls. Consequential actions wait for a person’s approval.
4. Security measures
- Access that mirrors the customer’s own permissions.
- An audit trail of every action ant. takes.
- Encryption of data in transit and at rest within the deployment.
- Access by Anthill staff only with the customer’s authorisation, logged and time-limited.
5. Sub-processors
We list any sub-processors in the DPA and give customers notice before adding or replacing one, with the right to object.
6. Incidents
If we become aware of a personal data breach affecting customer data in our care, we will notify the customer without undue delay and help it meet its own notification duties, including to regulators.
7. Customer support
We help customers respond to data subject requests, carry out impact assessments and demonstrate compliance, including through audits on reasonable notice.
8. End of service
When the agreement ends, we return or delete any customer data in our possession, unless the law requires us to keep it. Contact: founders@theanthill.ai.