Anvil and GDPR
CertReports found no public GDPR evidence for Anvil as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 22 Jan 2026
- Expires or valid through
- 22 Jan 2027
- Scope
- Anvil processes personal data to provide, secure, and improve its document infrastructure and e-signature services. The data processed may include customer and client contact details, account and billing information, and end-user information submitted through Anvil Workflows or Etch E-sign packets (such as names, addresses, identification numbers, and signatures) for the purposes of completing documents. For Anvil's PDF Filling API, documents are filled via an encrypted API call and streamed back, after which data is dropped and never stored. Personal data may be disclosed to trusted service providers and integration partners that support hosting, storage, analytics, payments, and security, or as required by law. Data is processed solely to deliver contracted services, meet legal obligations, and ensure system security and integrity. Anvil does not sell personal data to third parties.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Anvil: Active: EU-US Certification, UK Extension Certification | Live pagesha256 747c80b6c4 |
- Kind
- listing
- Issued or listed
- 7 Dec 2016
- Scope
- Processing clients related information in the provision of traveler tracking services. The SaaS products collects information provided to us by you, travel mangement companies or GDS providers and processes this data for and on behalf of your employer for business travel tracking and security overwatch. Ways that we collect information Some areas of the software we provide require you to actively submit information in order for you to benefit from specific features (such as our range of online services). You will be informed at each information collection point what information is required and what information is optional. Some of this information may be personal (information that can be uniquely identified with you, such as your full name, address, email address, phone number etc.).We only collect such information when you choose to supply it to us. Information is also gathered without you actively providing it, through the use of various technologies and methods such as Internet Protocol (IP) addresses and cookies. These methods do not collect or store personal information. An IP address is a number assigned to your computer by your Internet Service Provider (ISP), so you can access the Internet. It is generally considered to be non-personally identifiable information, because in most cases an IP address is dynamic. We use your IP address to diagnose problems with our server, report aggregate information, and determine the fastest route for your computer to use in connecting to our site, and to administer and improve the site. Cookies A cookie is a piece of data stored locally on your computer and contains information about your activities on the Internet. On our website, we use cookies to track users' progress through the site, allowing us to make improvements based on usage data. The information in a cookie does not contain any personally identifiable information you submit to our site. Once you close your browser, our access to the cookie terminates. You have the ability to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. If you choose not to accept the cookie, this will not affect your access to the majority of information available on our website. However, you will not be able to make full use of our online services. Monitoring of e-mail We may monitor e-mail communications with The Anvil Group (this includes any Anvil Group member of staff). Any such monitoring will take place in accordance with the law. Web Statistics We use log files generated by our web servers to analyse site usage and statistics but the files do not identify any personal information. Log file analysis helps us to understand usage patterns on our website and to make improvements to our service. Disclosure Except as otherwise stated, we may use information you provide via this site to improve the content, to customise the site to your preferences, to communicate information to you (if you have requested it), for internal marketing and research purposes, and for the purposes specified in this Privacy Policy. We do not disclose any information you provide via the site to any third parties or other government departments except where: Such disclosures are necessary to fulfill our service obligations to you in which case we will require such third parties to agree to treat it in accordance with this Privacy Policy. Required by applicable laws, courts orders, or government regulations (for example to prevent or detect crime). You give us permission to do so. Access to and correction of personal information We will take all reasonable steps in accordance with our legal obligations to update or correct personally identifiable information in our possession that you submit via this site. You have a right to ask to see details of any personal information that we hold about you. If you wish to do so please contact us with your request
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Anvil Group, LLC: Inactive | Live pagesha256 c96328e13a |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Anvil GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.