Legal
Last updated: April 13, 2026
Thriven is the data controller for personal data collected through our website (thriven.nanocorp.app) and our AI SEO platform. For any privacy-related enquiries, please contact us at privacy@thriven.ai.
Payment card details are processed exclusively by Stripe, Inc. We receive only a tokenised reference and the last four digits of your card. We never store full card numbers.
| Purpose | Data category | Legal basis |
|---|---|---|
| Provide and operate the platform | Account, Usage, Content | Contract (Art. 6(1)(b) GDPR) |
| Process payments | Billing, Payment | Contract (Art. 6(1)(b) GDPR) |
| Send transactional emails | Email, Account | Contract (Art. 6(1)(b) GDPR) |
| Improve the service and fix bugs | Usage, Technical | Legitimate interests (Art. 6(1)(f) GDPR) |
| Send marketing communications | Consent (Art. 6(1)(a) GDPR) | |
| Analytics and product insights | Usage, Technical | Consent (Art. 6(1)(a) GDPR) |
| Comply with legal obligations | All relevant data | Legal obligation (Art. 6(1)(c) GDPR) |
| Fraud prevention and security | Usage, Technical | Legitimate interests (Art. 6(1)(f) GDPR) |
| Data type | Retention period | Rationale |
|---|---|---|
| Account data | Duration of contract + 30 days after deletion request | Contract fulfilment |
| Billing records | 7 years from invoice date | Legal / tax obligation |
| Usage logs | 12 months rolling | Security, debugging |
| SEO content & briefs | Duration of contract + 30 days | Customer data ownership |
| Support correspondence | 3 years from last contact | Legitimate interests |
| Marketing consent records | Until withdrawn + 3 years | Proof of consent |
| Anonymised analytics | Indefinitely (no personal data) | Product analytics |
We share personal data only as described below. We do not sell personal data.
We engage the following sub-processors to operate the service:
| Sub-processor | Role | Location |
|---|---|---|
| Vercel, Inc. | Hosting & CDN | USA (EU adequacy / SCCs) |
| Neon, Inc. | PostgreSQL database | USA (SCCs) |
| Stripe, Inc. | Payment processing | USA (SCCs) |
| OpenAI, L.L.C. | AI content generation | USA (SCCs) |
| Resend / Postmark | Transactional email delivery | USA (SCCs) |
We may disclose data to law enforcement or regulatory authorities where required by applicable law, court order, or to protect the rights, property, or safety of Thriven, our customers, or the public.
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity, subject to equivalent data protection obligations.
Thriven is operated from within the EU/EEA. Some sub-processors are located in the United States. Where we transfer personal data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism, to ensure adequate protection.
If you are located in the EEA, UK, or another jurisdiction with equivalent data protection laws, you have the following rights:
| Right | What it means |
|---|---|
| Right of access (Art. 15) | Request a copy of all personal data we hold about you. |
| Right to rectification (Art. 16) | Ask us to correct inaccurate or incomplete data. |
| Right to erasure (Art. 17) | Request deletion of your personal data ('right to be forgotten'). |
| Right to restriction (Art. 18) | Ask us to pause processing while a dispute is resolved. |
| Right to portability (Art. 20) | Receive your data in a machine-readable format (JSON/CSV). |
| Right to object (Art. 21) | Object to processing based on legitimate interests or for marketing. |
| Right to withdraw consent (Art. 7(3)) | Withdraw marketing or analytics consent at any time. |
| Right to lodge a complaint | Complain to your local supervisory authority. |
To exercise any of these rights, email privacy@thriven.ai. We will respond within 30 days. We may ask you to verify your identity before processing requests.
We use cookies and similar tracking technologies. Please see our Cookie Policy for full details. You can manage your cookie preferences at any time via the cookie banner.
We implement industry-standard technical and organisational security measures including: encryption in transit (TLS 1.2+), encryption at rest (AES-256), access controls with least-privilege principles, regular security reviews, and incident response procedures. Despite these measures, no transmission over the internet is 100% secure.
Our services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@thriven.ai.
We may update this Privacy Policy from time to time. Material changes will be communicated via email (to registered users) and/or a prominent notice on our website at least 14 days before taking effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.
Data Controller: Thriven
Email: privacy@thriven.ai
Subject line: GDPR / Privacy Request
If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.