Last updated [date]

Privacy Policy

This policy explains what [Legal entity] (“Thalias”, “we”) collects when you use the Thalias website and decision workspace, why we collect it, who we share it with, and the control you have over it.

Thalias is built for consequential decisions, which means the material you upload is often sensitive. We have tried to write this plainly rather than defensively.

1. The two kinds of data here

It helps to separate them, because we treat them differently:

  • Personal data — information about you: your name, work email, company, and how you use the site.
  • Customer content — the documents, figures, notes, and conversations you put into a decision workspace, and the maps derived from them. This belongs to you. We process it on your instructions and for no purpose of our own.

2. What we collect

Information you give us

  • Access requests: when you use the “Request access” form on our website we store the email address you enter, the time you sent it, which button on the page you used, and your browser’s user-agent string. That is all we ask for and all we keep.
  • Enquiry and application forms: name, work email, company, team size, and whatever you write in the message field.
  • Account details, if you create one, and billing details if you buy a paid plan (payment card data is handled by our payment processor, not by us).
  • Support correspondence.

Information collected automatically

  • Server logs: IP address, user agent, pages requested, timestamps. Used for security, debugging, and abuse prevention.
  • Cookies and similar storage strictly necessary to run the site and keep you signed in.
  • Product analytics: Vercel Web Analytics, which counts page views and records the country, referring site, and device type of each visit. It sets no cookies, stores no identifier for you, and cannot tell us who you are.

Customer content

  • The files and text you upload, the sources you connect, and everything Thalias derives from them.

3. Why we use it

  • To provide the Service: extract claims, build and re-derive decision maps, and keep your history.
  • To respond to enquiries and applications you send us.
  • To secure the Service, investigate abuse, and meet legal obligations.
  • To improve the Service using aggregated, de-identified usage patterns — never by reading your content.
  • To send service messages. Marketing email only with your consent, and with an unsubscribe link in every message.

We do not sell personal data, and we do not use customer content to train our own or any third party’s models.

4. Legal bases (UK/EU)

  • Contract — to provide the Service you have asked for.
  • Legitimate interests — security, abuse prevention, and improving the product, balanced against your rights.
  • Consent — marketing email and any non-essential analytics. Withdrawable at any time.
  • Legal obligation — tax, accounting, and lawful requests.

Where you upload customer content containing personal data, you are the controller and we are your processor. A data processing agreement is available at [privacy@thalias.co].

5. Who we share it with

We share data only with providers who need it to run the Service:

  • Hosting and infrastructure — Vercel Inc. hosts the website. Access requests are stored in a Neon (Neon Inc.) Postgres database provisioned through Vercel.
  • Model providers — the AI provider processing your prompts and content. Where you supply your own keys, that is the provider you chose, under your agreement with them. Where we supply inference, we will name the providers on request.
  • Email and support — Resend (Plus Five Five, Inc.), used to notify us that an access request has arrived.
  • Payments — [payment processor].
  • Legal — where required by law. Where we are permitted to tell you about a request, we will.

A current list of subprocessors is available at [privacy@thalias.co].

6. International transfers

Our providers may process data outside your country, including in the United States. Where personal data leaves the UK or EEA we rely on Standard Contractual Clauses or another lawful transfer mechanism, together with additional safeguards where needed.

7. How long we keep it

  • Customer content — for as long as your workspace exists. Deleted content is removed from live systems promptly and from backups within [30] days.
  • Account and billing records — for the life of the account, then as long as tax and accounting law requires.
  • Access requests — until we have answered you and you have told us you are not interested, or [24] months, whichever comes first. Ask us and we will delete yours sooner.
  • Enquiry forms — [24] months, unless you become a customer.
  • Server logs — [90] days.

8. Security

We use encryption in transit and at rest, least-privilege access controls, audit logging, and regular review of who can reach what. No system is perfectly secure, but access to customer content is restricted to the small number of people who need it to operate or support the Service, and that access is logged.

If a breach affects your personal data we will notify you and any regulator within the time the law requires.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. California residents may request disclosure of the categories collected and opt out of “sharing” as that term is defined there — we do not sell or share personal data for cross-context behavioural advertising.

Exercise any of these at [privacy@thalias.co]. We will respond within the statutory period. You may also complain to your supervisory authority; in the UK that is the Information Commissioner’s Office.

10. Cookies

We use cookies that are strictly necessary to serve the site and maintain a session. Any non-essential cookie is set only with your consent, and you can change that choice at any time.

11. Children

Thalias is a business product and is not directed at anyone under 18. We do not knowingly collect their data; if we learn we have, we will delete it.

12. Changes

We will post any update here and change the date at the top. If a change materially affects how we handle your data, we will tell you before it takes effect.

13. Contact

[privacy@thalias.co] — or write to [Legal entity], [registered address]. Our data protection representative, where one is required, is [name / none].

Not legal advice. This is a starting draft written to match how Thalias is described on this site, and it describes practices for the product as intended — the enquiry forms on this site do not currently transmit anything. Have counsel review it, confirm every statement is true of your actual setup, and fill in every highlighted value before you publish it.