Who we are
ANTHONY OLIVA, INC. (“Anthony Oliva”, “we”, “us”, or “our”) is a corporation organized under the laws of the State of New York, with its principal place of business at 6724 Thompson Road, Syracuse, NY 13211, United States.
We operate an application-to-person (A2P) messaging platform that our business customers use to send SMS and MMS messages to their own recipients in the United States. This policy covers personal information we handle in two distinct roles:
- As a controller, for information about our own customers, prospects, applicants, and visitors to anthonyoliva.com.
- As a processor or service provider, for information our customers submit to the platform in order to send messages to their recipients. In that role we act on our customer’s documented instructions, and our customer is the party responsible for obtaining consent from the recipient.
If you received a text message and want to understand why, contact the business that sent it. If you cannot identify the sender, write to privacy@anthonyoliva.com or use our opt-out form and we will trace the traffic and act.
Mobile information and SMS consent
This section governs every mobile phone number and every record of messaging consent that passes through our platform or that we collect on our own website.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes at any time. All of the categories of personal information described in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of the text message services who are strictly necessary to deliver the message you asked to receive.
Concretely, this means:
- We do not sell mobile phone numbers.
- We do not rent, trade, or license mobile phone numbers.
- We do not share mobile numbers or SMS consent records with lead generators, data brokers, advertising networks, or affiliates.
- We do not use mobile numbers collected for one messaging program to send messages for a different program or a different business.
- Consent is never transferred or assigned between businesses.
The only parties that receive a mobile number in connection with a message are the ones required to physically deliver it: our connectivity partners and direct connect aggregators, the mobile network operators, and The Campaign Registry for the purposes of A2P campaign registration. These parties are contractually restricted to using the data solely to deliver and register the traffic.
We retain proof of consent for as long as the recipient remains subscribed and for four years after opt-out, so that consent can be produced on request by a carrier, an aggregator, or a regulator.
Information we collect
Information you give us
- Account information. Legal business name, employer identification number, business address, website, contact name, business email address, and business telephone number.
- Verification information. Documents and identifiers required to register your brand and campaigns with The Campaign Registry and to satisfy carrier know-your-customer obligations.
- Billing information. Billing contact, billing address, and the last four digits and expiry of a payment card. Full card numbers are handled by our payment processor and never stored on our systems.
- Support information. The contents of emails, tickets, and call notes when you contact us.
- Website submissions. Anything you enter into a form on anthonyoliva.com, including our SMS alerts sign-up, contact form, opt-out form, and abuse reporting form.
Information generated by using the platform
- Message metadata. Sending number, destination number, timestamp, segment count, direction, campaign identifier, carrier, and delivery status.
- Message content. The body of the messages you send and receive through the platform.
- Consent records. Opt-in method, timestamp, source URL or keyword, the exact disclosure text presented, and any subsequent opt-out.
- Technical logs. IP address, API key identifier, user agent, request path, and response code.
Information collected automatically on our website
We use a small number of first-party cookies and privacy-respecting analytics to understand which pages are used. See our Cookie Policy for the full list. We do not run third-party advertising trackers on anthonyoliva.com.
How we use information
| Purpose | Categories used | Legal basis (where GDPR applies) |
|---|---|---|
| Delivering messages you send | Message metadata, message content | Performance of a contract |
| Registering brands and campaigns with carriers | Account and verification information | Legal obligation and legitimate interests |
| Billing and collections | Account and billing information | Performance of a contract |
| Preventing fraud, spam, and platform abuse | Technical logs, message metadata, limited content analysis | Legitimate interests |
| Responding to support and abuse reports | Support information, consent records | Legitimate interests |
| Complying with carrier rules, subpoenas, and law | Any category, as required | Legal obligation |
| Product announcements to existing customers | Account information | Legitimate interests, with opt-out |
We do not use the content of customer messages to train machine learning models, to build advertising profiles, or for any purpose other than delivering the message, keeping the platform secure, and complying with law.
We do run automated content screening on message traffic to detect spam, phishing, and content that carriers prohibit. This screening is a condition of carrier access and is described in our Messaging Policy.
When we disclose information
We disclose personal information only in the situations below, and never in exchange for money or other valuable consideration.
- To deliver traffic. Connectivity partners, direct connect aggregators, and mobile network operators receive the sending number, destination number, and message body because they physically carry the message.
- To register campaigns. The Campaign Registry and carrier vetting partners receive brand and campaign information as required by the A2P 10DLC framework.
- To sub-processors. Vendors that host our infrastructure, process payments, or run our support desk. Each is bound by a written agreement and appears on our Sub-Processors page.
- For legal reasons. When required by valid legal process, or when disclosure is necessary to investigate suspected fraud, protect our rights, or protect someone’s safety.
- In a corporate transaction. If we are acquired or merged, information may transfer to the successor, which remains bound by this policy. Mobile opt-in data and consent records remain subject to the restrictions in the Mobile information section above.
Data security
We protect personal information with controls appropriate to its sensitivity:
- TLS 1.2 or higher for all data in transit, including every API request and webhook delivery.
- Encryption at rest for databases and backups.
- Role-based access control, with production access limited to named personnel who require it for their role.
- Mandatory multi-factor authentication for all administrative accounts.
- API authentication using scoped keys that customers can rotate or revoke at any time.
- Audit logging of administrative actions, retained for twelve months.
- Written security due diligence and a data processing agreement with every sub-processor.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities within the timeframes required by applicable law. Further detail is on our Security page.
Data retention
- Account and billing records: for the life of the account and seven years afterwards, for tax and audit purposes.
- Message content: 30 days by default, configurable down to zero retention on request.
- Message metadata and delivery logs: 18 months.
- Consent and opt-out records: for the life of the subscription and four years after opt-out.
- Website form submissions: 24 months.
Your privacy rights
United States
If you are a resident of California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you may have the right to know what personal information we hold, to obtain a copy, to correct it, to delete it, and to appeal a refusal. You also have the right to opt out of the sale or sharing of personal information and of targeted advertising.
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not use personal information for cross-context behavioral advertising. We have not done so in the preceding twelve months, including for consumers under 16.
Europe and the United Kingdom
Where the GDPR or UK GDPR applies, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Where we transfer personal data outside the EEA or UK we rely on the Standard Contractual Clauses, as described in our Data Processing Addendum.
Making a request
Send requests to privacy@anthonyoliva.com or call +1 (332) 231-6423. We will verify your identity before acting and respond within 45 days, extendable once where the law permits. You may use an authorized agent. We will not discriminate against you for exercising a privacy right.
If your request relates to messages you received from one of our customers, we will route it to that customer, who is the controller of that data, and confirm back to you once it has been actioned.
Children
The platform and this website are intended for businesses. Our services are not directed to anyone under 18, and we do not knowingly collect personal information from children. Recipients of messaging programs run on our platform must be 18 or older. If you believe a child has provided us with personal information, write to privacy@anthonyoliva.com and we will delete it.
Changes to this policy
We will post any revised version on this page and update the “last updated” date. For changes that materially reduce your rights, we will give at least 30 days’ notice by email to account administrators before the change takes effect. The restrictions in the Mobile information and SMS consent section will not be weakened by any future revision.
How to reach us
Questions about this document can be sent tolegal@anthonyoliva.com. Privacy requests go toprivacy@anthonyoliva.com. Abuse reports go toabuse@anthonyoliva.com or through ourabuse reporting form.
ANTHONY OLIVA, INC.
6724 Thompson Road, Syracuse, NY 13211, United States
+1 (332) 231-6423
support@anthonyoliva.com