Anbesa

Anbesa LLC

Privacy Policy

Effective August 28, 2026 · Last updated August 28, 2026

Anbesa LLC (“Anbesa,” “we,” “us”) builds accountability systems and private language models for organizations that cannot afford to leak their data. We hold ourselves to the same standard. This policy explains what we collect on this website, what we do with information our clients entrust to us, and how our text messaging program works.

The short version. This site collects as little as possible. There are no advertising trackers, no third-party analytics cookies, and no data brokers. Our clients own their data. We access it only when a client has given us explicit, documented permission, and only for the purpose that permission was given for. We never sell personal information, and we never use client data to train models for anyone else.

1Who we are

Anbesa LLC is a Maryland limited liability company operating in the Washington, DC region. We provide two things: field operation accountability software for organizations in construction, landscaping, janitorial, warehouse, trades, engineering, healthcare, energy, government contracting, legal, and logistics; and small language models trained on a client's own documents and deployed inside that client's own environment.

For questions about this policy, or to exercise any right described in it, email amar@anbesaconsult.org or use our contact page. We respond to privacy requests within 30 days.

2Scope of this policy

This policy covers withanbesa.org, our text messaging program, and the software we host or operate for clients.

Where we handle information on behalf of a client — for example, the check-in records of a client's crew, or the documents a client loads into a private language model — the client's own privacy notice governs its relationship with those individuals. We act on that client's written instructions under a services agreement or data processing agreement. Those agreements control if anything in this policy conflicts with them.

3Information we collect

Information you give us

  • Contact submissions. Name, email address, optional company and role, your mobile number if you choose to give it, and the content of your message.
  • Text message enrollment. If you opt in to messages from us, we record your mobile number, the date and time of your consent, the page or form where you gave it, and the exact disclosure text you saw. We are required to keep this record and to produce it on request.
  • Account information. For signed-in users of our software: your email address, your organization, your role, and session data. Sign-in codes expire within minutes.

Information collected automatically

  • Server logs. IP address, request path, timestamp, user agent, and response status, kept for security monitoring, abuse prevention, and debugging.
  • Functional cookies. First-party only. See section 7.

What we do not collect

We do not run advertising pixels, third-party analytics, cross-site trackers, session recording, or fingerprinting. We do not buy personal information from data brokers or append purchased data to records you give us. We do not knowingly collect Social Security numbers, payment card numbers, biometric identifiers, precise geolocation from website visitors, or health information through this website.

4Client data and ownership

Our commitment

Clients own their data. All data a client creates, uploads, generates, or transmits through our software or entrusts to us during an engagement — including documents, records, check-in and photo evidence, model inputs, model outputs, and derived work product — remains the exclusive property of that client. Anbesa claims no ownership interest in it. Nothing in this policy or in any agreement transfers ownership of client data to Anbesa.

The commitment above is operational, not aspirational. In practice it means:

  • Access requires explicit permission. Anbesa personnel do not access client data except where the client has granted explicit, documented authorization — in a signed agreement, a written support request, or a recorded approval in the product. Absent that authorization, we do not read, export, copy, or analyze client data.
  • Permission is scoped and time-bound. Authorization granted for one purpose (say, troubleshooting a failed sync) does not extend to any other purpose. Support access is limited to the narrowest data set that resolves the issue and ends when the issue is resolved.
  • Access is logged. Every instance of Anbesa personnel accessing client data is recorded with the identity of the person, the time, the scope, and the authorization relied on. Clients may request that log.
  • Deployment keeps data in your boundary. Small language models are deployed on-premises or in the client's own cloud account by default. Where a client's data stays inside the client's infrastructure, Anbesa has no standing access to it at all.
  • We do not monetize it. We do not sell client data, license it, share it for anyone's marketing, or use it to build products or benchmarks for other clients.
  • Return and deletion. On request during an engagement, and on termination, we return client data in a usable format and delete our copies, except for records we are legally required to retain or backups that expire on their normal cycle. We confirm deletion in writing when asked.
  • Subprocessors are limited and bound. Where a subprocessor is necessary (hosting, for example), it is bound by written terms no weaker than these, and clients may request the current list.
  • Legal demands. If we receive a subpoena, warrant, or other legal demand for client data, we notify the client before responding unless we are legally prohibited from doing so, and we give the client the opportunity to object.

5How we use information

WhatWhyBasis
Contact submissionsTo respond to you and follow up on your inquiryYour request; our legitimate interest in operating a business
Mobile number and consent recordTo send the messages you opted in to and to prove consentYour express consent; legal obligation
Account and session dataTo authenticate you and keep you signed inPerformance of a contract
Server logsSecurity, abuse prevention, debuggingLegitimate interest in a secure service
Client dataOnly to deliver the contracted service, under client instructionClient's written authorization

We do not use any of the above for automated decision-making that produces legal or similarly significant effects about you, and we do not profile website visitors.

6Text messaging (SMS/MMS)

Anbesa operates an application-to-person (A2P) text messaging program. This section describes it in full; the corresponding contractual terms are in our Terms & Conditions.

6.1 Consent

We send text messages only to people who have given prior express written consent, obtained in one of these ways:

  • Checking an unchecked, optional consent box on a form on withanbesa.org that displays the program disclosure, message frequency, rate notice, opt-out instructions, and links to this policy and our Terms.
  • Enrolling within our software, where an authorized administrator at a client organization has enabled operational messaging and the individual user has confirmed their number and accepted the same disclosure.
  • Texting the keyword ANBESA to our program number, or replying YES to confirm a double opt-in message.

Consent to receive marketing text messages is never a condition of purchase, of receiving a quote, of using our software, or of any service. Consent for one message category does not imply consent for another; marketing consent is collected separately from operational and account messaging.

6.2 Message categories and frequency

CategoryExamplesFrequency
Operational alertsShift and check-in reminders, missed check-in and exception alerts, crew status changes, site assignment updatesVaries by your work schedule; typically up to 10 messages per week
Account and securityOne-time sign-in codes, two-factor codes, password resets, security noticesOnly when you request one or a security event occurs
Client serviceProject status, scheduling and meeting confirmations, implementation milestones, support follow-upsVaries; typically up to 4 messages per month
MarketingProduct announcements, offers, event invitationsUp to 4 messages per month

Message frequency varies. Message and data rates may apply. Your mobile carrier may charge for messages you send or receive; check your plan. Not all mobile devices or carriers support every message type, and carriers are not liable for delayed or undelivered messages.

6.3 Opting out and getting help

Reply STOP to any message to cancel. You will receive one final confirmation that no further messages will be sent, after which we will stop. You can rejoin at any time by signing up again or by replying START or UNSTOP. Reply HELP for help, or reach us at amar@anbesaconsult.org or our contact page.

We honor STOP, END, CANCEL, UNSUBSCRIBE, and QUIT, in any capitalization or punctuation, and we honor HELP and INFO for assistance.

When you reply STOP, we treat your request as a revocation of consent for all Anbesa text message programs — operational, client service, and marketing — unless you tell us you want to keep receiving a specific category. We process every opt-out request within a reasonable time not to exceed ten (10) business days, and we honor opt-out requests made by any reasonable means, including the keywords above, plain-language requests such as “please stop texting me,” and requests sent through our contact page. One-time sign-in and two-factor codes are sent only at your request; opting out of them may prevent you from signing in by SMS code.

6.4 How we treat your mobile information

We do not share, sell, rent, or provide your mobile phone number or SMS consent data to third parties, affiliates, or lead generators for marketing or promotional purposes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. None of the disclosures described in section 8 include text messaging originator opt-in data or consent; this information will not be shared with any third parties. Mobile opt-in data and consent records are never sold, rented, licensed, or disclosed for anyone's marketing.

The only parties that ever touch your mobile number are the licensed messaging providers and mobile carriers that transmit the message on our behalf, and they may use it solely to deliver it. Your number is not shared with advertisers, data brokers, affiliates, or any other client of ours.

7Cookies

We set first-party functional cookies only: a session cookie so you stay signed in, a theme preference cookie so the site renders the way you left it, and a security token to prevent cross-site request forgery. There is no advertising cookie, no analytics cookie, and no cross-site tracker — which is why you do not see a consent banner. There is nothing to consent to.

We honor Global Privacy Control and other opt-out preference signals your browser sends. Because we do not sell or share personal information for cross-context behavioral advertising, there is nothing for that signal to switch off, but we treat it as a valid opt-out regardless.

8Sharing and disclosure

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We disclose information only as follows:

  • Service providers. Hosting, email delivery, and messaging providers who process data solely on our instructions under written contract, and who may not use it for their own purposes.
  • Clients. Data collected through a client's deployment goes to that client — it is theirs.
  • Legal requirements. Where required by law, subpoena, or court order, subject to the notice commitment in section 4.
  • Protection of rights. Where necessary to investigate fraud, abuse, or a threat to the safety of any person.
  • Business transfer. In a merger, acquisition, or sale of assets, information may transfer to the successor, which remains bound by this policy. Mobile opt-in data and SMS consent records are excluded from any such transfer, sale, or assignment for any purpose other than continuing to operate the same messaging program you consented to, and are never transferred for marketing or promotional purposes.

9AI and model training

We do not use client data, contact submissions, or website visitor data to train, fine-tune, or evaluate models for any party other than the client that owns the data, and we do not do so for that client without explicit written authorization. Client-specific models built under an engagement belong to that client, are deployed in that client's environment, and are not reused, ported, or benchmarked elsewhere. We do not submit client data to third-party AI services without prior written client approval identifying the service.

10Retention

  • Contact submissions: up to 24 months from last correspondence, then deleted.
  • SMS consent records: retained for at least 4 years after the consent, as required to demonstrate compliance.
  • SMS opt-out and suppression records: retained indefinitely, because we cannot honor a permanent revocation with a list we delete.
  • Server logs: 90 days, except records preserved for an active security investigation.
  • Account records: for the life of the account, then 30 days.
  • Client data: per the applicable client agreement; see section 4.

11Security

The site is served over HTTPS. Data is encrypted in transit and at rest. Access to production systems is limited to personnel who need it, requires multi-factor authentication, and is logged. We follow least-privilege access, review permissions periodically, and require confidentiality obligations of every person with access. No system is perfectly secure, but if a breach affects your personal information we will notify you and the relevant regulators within the timeframes the law requires.

12Your privacy rights

Depending on where you live, you may have the right to:

  • Know what personal information we hold about you and obtain a copy of it in a portable format.
  • Correct inaccurate personal information.
  • Delete personal information we hold about you.
  • Opt out of sale, sharing, or targeted advertising — none of which we do.
  • Limit the use of sensitive personal information — we do not collect it through this site.
  • Appeal a decision we make on your request.
  • Not be discriminated against for exercising any of these rights.

These rights arise under laws including the Maryland Online Data Privacy Act, the California Consumer Privacy Act as amended by the CPRA, the Virginia, Colorado, and Connecticut consumer privacy statutes, and the GDPR for individuals in the EEA and UK (including the right to lodge a complaint with a supervisory authority). Not every one of these laws applies to a company of our size, and their thresholds change. Our practice is to honor the requests above for anyone who asks, whether or not a particular statute obliges us to.

To make a request, email amar@anbesaconsult.org or use our contact page and tell us what you want. We will verify your identity in proportion to the sensitivity of the request — usually by confirming control of the email address or mobile number on file — and respond within 30 days (extendable once by 45 days where the law allows, with notice to you). An authorized agent may submit a request on your behalf with written proof of authorization. If we deny a request, we will explain why and how to appeal.

If your data sits inside a client's deployment, send your request to that client; we will forward it and assist them in responding.

13Children

Our services are built for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from children, and we do not send text messages to numbers we know belong to minors. If you believe a child has given us information, contact us and we will delete it.

14International visitors

We operate in the United States and process information here. If you use the site from outside the US, you are sending information to the United States, where privacy law differs from your own. Where we transfer personal data out of the EEA or UK, we rely on Standard Contractual Clauses.

15Changes

We update this policy when our practices change. The effective date at the top always reflects the current version. For material changes — particularly to our text messaging program or to how we handle client data — we will give notice on this site before the change takes effect, and where the law requires it, we will obtain fresh consent rather than rely on the old one.

16Contact us

Anbesa LLC
909 Rose Ave
North Bethesda, MD 20852
amar@anbesaconsult.org
withanbesa.org/contact

For text messaging support, reply HELP to any message or email amar@anbesaconsult.org.