Privacy Statement
The platform is certified to ISO 27001, aligns with SOC 2 controls, and maintains
compliance with GDPR and related frameworks. Thesis also performs annual
penetration testing through a CREST-accredited third party,
Privacy We process your personal data with due care, in accordance with all applicable laws and regulations, in particular the GDPR.
Security We take all reasonable, appropriate security measures to protect against unauthorised access to, or alteration, disclosure or destruction of, the personal data we hold.
International transfers We only transfer personal data outside the EEA where there is an adequate level of data protection, using EU Standard Contractual Clauses where an adequacy decision is not in place.
Your rights You can access your data, correct or delete it, object to or restrict its use, move it, and withdraw consent at any time.
How and why we use your data
Privacy
We process your personal data with due care, in accordance with all applicable laws and regulations, in particular the GDPR.
Security
We take all reasonable, appropriate security measures to protect against unauthorised access to, or alteration, disclosure or destruction of, the personal data we hold.
International transfers
We only transfer personal data outside the EEA where there is an adequate level of data protection, using EU Standard Contractual Clauses where an adequacy decision is not in place.
Your rights
You can access your data, correct or delete it, object to or restrict its use, move it, and withdraw consent at any time.
Privacy
Your privacy is important to us. We process your personal data with due care, in accordance with all applicable laws and regulations, in particular the General Data Protection Regulation (EU) 2016/679.
We do not store your personal data longer than is legally permitted and necessary for the purposes for which it was collected. The storage period depends on the nature of the information and the purpose of processing, and data is automatically deleted once we no longer have a legal ground to keep it.
Security
We take all reasonable, appropriate security measures to protect Thesis and our customers from unauthorised access to, or unauthorised alteration, disclosure or destruction of, the personal data we hold. If you are a customer, your account manager can provide details about the security measures relevant to the services you receive.
Should a security breach occur that is likely to have negative effects on your privacy, we will inform you as soon as reasonably possible. Thesis maintains a data breach protocol for this purpose.
International transfers
We will only pass personal data from the European Economic Area (EEA) to a country outside the EEA where there is an adequate level of data protection, comparable to the level applicable in the EU.
Where processing takes place in a country outside the EEA for which the European Commission has not provided an adequacy decision, it will only proceed where there are appropriate safeguards that provide an adequate level of protection, including the EU Standard Contractual Clauses.
This privacy statement applies worldwide, to all of the services offered by Thesis.
How we share your data?
We will not simply pass your personal data to individuals or other organisations. We only do so where it is compatible with the purpose for which the data was collected, and where a lawful ground applies: your explicit consent, performing an agreement, a legal obligation, vital interests, a task in the public interest, or the legitimate interest of Thesis.
If you are visiting our website, we share information with our customer relationship management, marketing automation and email platform providers (HubSpot).
We may engage other parties to perform part of our services. Where they need access to personal data to do so, we put contractual and organisational measures in place to ensure the data is processed only for the purposes set out in our privacy statement and in accordance with all applicable laws.
We may share aggregated, non-personally-identifiable data with partners or the public; for example, to show trends about the use of our services. Such data is anonymised beforehand and is no longer personal data.
What rights you have?
Depending on where you are located, you have a number of rights in relation to the personal data we hold about you. These include:
Right of access
Request a copy of the personal data we hold about you.
Right to rectification
Ask us to correct any inaccurate or incomplete information.
Right to erasure
Request that we delete your personal data, subject to legal or contractual obligations to retain it.
Right to restrict processing
Ask us to limit how we use your data in certain circumstances.
Right to data portability
Receive your data in a structured, machine-readable format and ask us to transfer it to another controller.
Right to object
Object to processing based on legitimate interests or used for direct marketing purposes.
Right to withdraw consent
Where we rely on your consent, you can withdraw it at any time without affecting prior processing.
Where we rely on legitimate interests, you can request further information, including a copy of our legitimate interests balancing test, by contacting privacy@thesiscloud.com.
Where we rely on your consent, you may withdraw it at any time without affecting processing that has already taken place.
These rights are not absolute, they may be limited where, for example, fulfilling a request would affect another person's rights, or where we are legally required to retain data. We will always inform you of any exemptions we rely on. If you have unresolved concerns, you have the right to complain to the data protection authority in your country.
To exercise any of these rights, contact us at privacy@thesiscloud.com.
Questions about your data?
You can raise any question about the processing of your personal data by emailing privacy@thesiscloud.com, including your name, address, phone number and a copy of a valid ID. You will receive a response in writing within four weeks.
If you have a complaint about how Thesis processes your personal data, please contact our Data Protection Officer at privacy@thesiscloud.com. As a data subject, you also have the right to file a complaint with the supervisory authority.
Registered offices:
C/O TMF Group, 13th Floor, One Angel Court, London, United Kingdom, EC2R 7HJ
C/O TMF Canada Inc., Suite 1700, 777 Dunsmuir Street, Vancouver, British Columbia, V7Y 1K4
400 Chesterfield Center, Suite 400, Chesterfield, MO 63017
Our privacy statement may be updated from time to time. Please always check the latest version.