Legal

Privacy Policy

Last updated: April 13, 2026

This Privacy Policy explains how Thriven (“Thriven”, “we”, “us”, or “our”) processes personal data in connection with our AI SEO platform. It applies to all users of our website and services. If you are a business customer, please also review our Data Processing Agreement.

1. Who We Are

Thriven is the data controller for personal data collected through our website (thriven.nanocorp.app) and our AI SEO platform. For any privacy-related enquiries, please contact us at privacy@thriven.ai.

2. Data We Collect

2.1 Account & Identity Data

  • Full name and email address (on registration)
  • Company name and job title (optional, for B2B personalisation)
  • Billing name and address (collected by Stripe on checkout)
  • Password hash (we never store plain-text passwords)

2.2 Usage & Technical Data

  • IP address and approximate geolocation (country/city)
  • Browser type, device type, and operating system
  • Pages visited, features used, session duration
  • API request logs (endpoint, timestamp, response code)

2.3 Content Data

  • URLs and web pages you submit for SEO analysis
  • Generated SEO briefs and audit reports
  • Any text or configuration you enter into the platform

2.4 Payment Data

Payment card details are processed exclusively by Stripe, Inc. We receive only a tokenised reference and the last four digits of your card. We never store full card numbers.

2.5 Communications Data

  • Email correspondence with our support team
  • Marketing email open/click events (only with consent)

3. Legal Basis for Processing

PurposeData categoryLegal basis
Provide and operate the platformAccount, Usage, ContentContract (Art. 6(1)(b) GDPR)
Process paymentsBilling, PaymentContract (Art. 6(1)(b) GDPR)
Send transactional emailsEmail, AccountContract (Art. 6(1)(b) GDPR)
Improve the service and fix bugsUsage, TechnicalLegitimate interests (Art. 6(1)(f) GDPR)
Send marketing communicationsEmailConsent (Art. 6(1)(a) GDPR)
Analytics and product insightsUsage, TechnicalConsent (Art. 6(1)(a) GDPR)
Comply with legal obligationsAll relevant dataLegal obligation (Art. 6(1)(c) GDPR)
Fraud prevention and securityUsage, TechnicalLegitimate interests (Art. 6(1)(f) GDPR)

4. How We Use Your Data

  • Create and manage your account
  • Deliver the SEO analysis, audit, and brief generation features
  • Process billing and issue invoices
  • Send password reset and account notification emails
  • Respond to support requests
  • Detect, prevent, and investigate fraud or abuse
  • Improve our models and product features (using aggregated, de-identified data)
  • Send marketing emails where you have opted in

5. Data Retention

Data typeRetention periodRationale
Account dataDuration of contract + 30 days after deletion requestContract fulfilment
Billing records7 years from invoice dateLegal / tax obligation
Usage logs12 months rollingSecurity, debugging
SEO content & briefsDuration of contract + 30 daysCustomer data ownership
Support correspondence3 years from last contactLegitimate interests
Marketing consent recordsUntil withdrawn + 3 yearsProof of consent
Anonymised analyticsIndefinitely (no personal data)Product analytics

6. Sharing Your Data

We share personal data only as described below. We do not sell personal data.

6.1 Sub-processors

We engage the following sub-processors to operate the service:

Sub-processorRoleLocation
Vercel, Inc.Hosting & CDNUSA (EU adequacy / SCCs)
Neon, Inc.PostgreSQL databaseUSA (SCCs)
Stripe, Inc.Payment processingUSA (SCCs)
OpenAI, L.L.C.AI content generationUSA (SCCs)
Resend / PostmarkTransactional email deliveryUSA (SCCs)

6.2 Legal Disclosures

We may disclose data to law enforcement or regulatory authorities where required by applicable law, court order, or to protect the rights, property, or safety of Thriven, our customers, or the public.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity, subject to equivalent data protection obligations.

7. International Transfers

Thriven is operated from within the EU/EEA. Some sub-processors are located in the United States. Where we transfer personal data outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or another lawful transfer mechanism, to ensure adequate protection.

8. Your Rights Under GDPR

If you are located in the EEA, UK, or another jurisdiction with equivalent data protection laws, you have the following rights:

RightWhat it means
Right of access (Art. 15)Request a copy of all personal data we hold about you.
Right to rectification (Art. 16)Ask us to correct inaccurate or incomplete data.
Right to erasure (Art. 17)Request deletion of your personal data ('right to be forgotten').
Right to restriction (Art. 18)Ask us to pause processing while a dispute is resolved.
Right to portability (Art. 20)Receive your data in a machine-readable format (JSON/CSV).
Right to object (Art. 21)Object to processing based on legitimate interests or for marketing.
Right to withdraw consent (Art. 7(3))Withdraw marketing or analytics consent at any time.
Right to lodge a complaintComplain to your local supervisory authority.

To exercise any of these rights, email privacy@thriven.ai. We will respond within 30 days. We may ask you to verify your identity before processing requests.

9. Cookies

We use cookies and similar tracking technologies. Please see our Cookie Policy for full details. You can manage your cookie preferences at any time via the cookie banner.

10. Security

We implement industry-standard technical and organisational security measures including: encryption in transit (TLS 1.2+), encryption at rest (AES-256), access controls with least-privilege principles, regular security reviews, and incident response procedures. Despite these measures, no transmission over the internet is 100% secure.

11. Children

Our services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@thriven.ai.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email (to registered users) and/or a prominent notice on our website at least 14 days before taking effect. Continued use of the service after the effective date constitutes acceptance of the updated policy.

13. Contact Us

Data Controller: Thriven
Email: privacy@thriven.ai
Subject line: GDPR / Privacy Request

If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.

© 2026 Thriven. All rights reserved.  ·  Security · Privacy · Terms · Cookies · DPA · Blog · Referral