Privacy policy
Last updated 2026-08-25
The short version. We keep business contact information about people at companies we think might want to work with us or with a client of ours. We get it from public sources and from data providers we pay. We use it to contact those companies about business services. We do not sell it. You can ask us what we have about you, ask us to correct it, ask us to delete it, or tell us to stop contacting you, and we will do it.
Who we are
Anaphora, an independent business development firm in San Diego, California. For the purposes of this policy we are the business responsible for the information described below.
[email protected]What personal information we collect
Business contact and professional information about people in their professional capacity:
- Name, job title and employer.
- Business email address and, where published, business telephone number.
- Business mailing address.
- Public professional profile links, such as a company biography page or a professional networking profile.
- Publicly reported information about the employer, such as approximate size, industry, locations, funding or hiring activity, and news coverage.
- A record of our communications with you, including messages we sent, whether they were delivered, and your replies or opt out requests.
If you email us or fill in something on this site, we also keep what you chose to send us.
We do not collect or want sensitive personal information as California defines it, including government identifiers, financial account numbers, precise location, health information, or biometric data. If you send it to us unprompted we will delete it.
Where it comes from
In plain terms: from public sources, from data providers we pay, and from you.
- Public sources. Company websites, published team and leadership pages, press releases, news coverage, job postings, public business filings and registries, conference and association listings, and public professional networking profiles.
- Licensed providers. Commercial business data and email verification services we pay for under contract. We expect those providers to have obtained the information lawfully, and we make that a term of the contracts we sign with them.
- You. Anything you send us directly, or that you give us during an engagement.
- Clients. Where a client engages us to conduct outreach, they may give us their own exclusion lists or contact records. In that situation the client decides what happens to their data and we handle it on their instructions.
We do not scrape sites in violation of their terms, we do not buy consumer data, and we do not use data sourced from a breach or a leak.
Why we use it
- To work out whether a company is a plausible fit for a service we or a client offer.
- To contact people at that company about that service.
- To keep records of what we sent, to whom, and what they said back, including opt outs.
- To provide services to a client under a contract with them.
- To meet our legal obligations, including record keeping obligations that attach to commercial email.
We contact people in a professional capacity about business services. We do not use this information for advertising, for profiling unrelated to that purpose, or for anything targeting people as consumers.
We do not sell or share your personal information
We do not sell personal information, and we do not share it for cross context behavioral advertising. Both of those terms have specific meanings under the California Consumer Privacy Act and we mean them in that sense. We have not sold or shared personal information in the preceding twelve months.
We do disclose personal information to service providers who process it on our behalf and only on our instructions, such as email delivery providers, email verification services and data hosting. Where we conduct outreach for a client, we disclose to that client the information relevant to the accounts we contacted for them.
Your rights
We are not currently a "business" as the California Consumer Privacy Act defines one. We are under its thresholds for revenue, for volume of personal information handled, and for revenue derived from selling data. We give you these rights anyway, to anyone who asks, wherever they are. If we cross those thresholds they stop being a policy and become an obligation, and nothing about how we handle them will need to change.
One point worth stating plainly, because it surprises people. The CCPA exemption for business to business contacts expired on January 1, 2023. Where the Act applies, the fact that a company holds your information because of your job does not reduce your rights. We do not treat it as reducing them here either.
- Know and access. Ask what personal information we hold about you, where we got it, why we have it, and who we disclosed it to.
- Correct. Ask us to fix information that is wrong.
- Delete. Ask us to delete what we hold about you.
- Opt out of sale or sharing. We do not sell or share, so there is nothing to opt out of, but you can ask us to confirm that.
- Limit use of sensitive information. We do not collect it.
- No retaliation. We will not treat you differently for exercising any of these.
How to make a request
Email us. One message is enough and you do not need to use any particular wording.
We confirm receipt within 10 business days and respond substantively within 45 calendar days. If we genuinely need longer we will tell you why and take at most a further 45 days. We may need to verify that the request is really from you, which normally means replying from the email address in question. An authorized agent can make a request on your behalf with written permission.
If we deny a request we will tell you which exception applies. We keep a minimal suppression record after a deletion, consisting of your email address and the fact that you asked not to be contacted, because that is the only way to guarantee we do not contact you again.
Opting out of our emails
Any of these works, and none of them requires you to explain yourself:
- Click the unsubscribe link in any email we send.
- Reply to the email and say stop. A human reads replies.
- Email [email protected].
We process opt outs within 10 business days, which is the maximum CAN-SPAM allows, and in practice much sooner. An opt out is permanent. We add the address to a suppression list, and we do not remove addresses from it.
How long we keep it
- Prospect records: for as long as the company is a plausible fit, and no longer than 24 months after the last contact.
- Opt out and suppression records: indefinitely, because deleting them would let us contact you again by mistake.
- Client engagement records: for the length of the engagement plus the period our contract or the law requires.
- Commercial email records: as long as required for compliance record keeping.
This website
This site sets no cookies, runs no analytics, loads nothing from a third party host, and does not track you across sites. There is no consent banner because there is nothing to consent to. Our hosting provider keeps standard server logs, including IP addresses, for security and reliability.
If we ever add analytics, this section changes first and anything that sets a cookie gets a consent path before it is switched on.
Security
We use encryption in transit, access controls limited to the two of us, multi factor authentication on the accounts that hold data, and managed providers rather than self hosted infrastructure for anything holding personal information. No system is perfectly secure and we will not claim otherwise.
Children
This is a business to business service. It is not directed to anyone under 16 and we do not knowingly collect information about them.
Changes
If we change this policy we will update the date at the top. If a change is material we will say what changed rather than quietly reissuing the document.
Contact
Questions about this policy, or about anything we hold: [email protected].