LEGAL · PRIVACY

Privacy Policy

We are incorporated in India under the Companies Act, 2013 and operate as a UK-facing service provider. We are subject to UK GDPR, EU GDPR for EEA clients, and India’s Digital Personal Data Protection Act, 2023.

✓ No advertising cookiesUK GDPR · DPDPA 2023Last updated: 2 Oct 2026
01 · Identity

Who We Are

THRIVEFINITY (OPC) PRIVATE LIMITED (“ThriveFinity”, “we”, “us”, or “our”) is a One Person Company incorporated in India on 11 August 2020 under the Companies Act, 2013. Our principal contact for all data protection matters is om@thrivefinity.uk.

Data processing details
DetailValue
CINU72900TN2020OPC137043
PANAAICT0116B
GST33AAICT0116B1Z3
MSMEUDYAM-TN-02-0006768
Registered addressNo. 115, Pilliyer Koil Street, Arumbakkam, Chennai, Tamil Nadu 600106, India

We are subject to: the Digital Personal Data Protection Act, 2023 (DPDPA) for all data principals located in India; the UK GDPR (as retained by the European Union (Withdrawal) Act 2018) for clients in the United Kingdom; and the EU GDPR for clients in the European Economic Area.

02 · Collection

What Data We Collect

We collect the following categories of personal data:

  • Identity data: name, job title, and company name, as provided in intake forms or email correspondence.
  • Contact data: email address and, where provided, telephone number.
  • Document data: pitch decks, strategy documents, idea briefs, and other materials you upload or share with us for review. These may contain personal data about third parties.
  • Financial data: payment method details processed exclusively by Razorpay Software Private Limited. We do not store card numbers or full payment credentials on our systems.
  • Usage data: pages visited, referring site and browser type, collected by cookieless page statistics (Plausible, run on our own servers, and Cloudflare Web Analytics) that store nothing on your device and do not identify you, and by server logs. If you arrive from a campaign or referral link, that link’s details are kept for your browsing session only and reach us only if you submit a form. We do not use Google Analytics or advertising pixels.
  • Data we receive from others: if someone refers you to us (for example, through our Refer a Founder page), they give us your name, email address, company website and any note they add. Our first email to you names who referred you and explains how we got your details. We use them only to send that one introduction (legitimate interests) and do not email you again unless you reply. You can ask us not to contact you again, and we will keep a suppression record so we don’t. Referral records are deleted after 30 days.
  • Communications data: emails, messages, and feedback you send us.
03 · Lawful Bases

Why We Collect It

UK GDPR (for UK clients) — Article 6:

  • Performance of a contract (Art. 6(1)(b)): to deliver the Offer Validation, Release Assurance, Decision Brief, and Go-to-Market Build services you have ordered.
  • Legitimate interests (Art. 6(1)(f)): to improve our services, prevent fraud, respond to enquiries, and maintain security. We have conducted a Legitimate Interest Assessment and determined our interests do not override your rights.
  • Consent (Art. 6(1)(a)): for marketing communications such as the Friday Notes newsletter. You may withdraw consent at any time by unsubscribing or emailing om@thrivefinity.uk.
  • Legal obligation (Art. 6(1)(c)): where required by applicable law, such as invoices and accounting records, which we keep for the period required by applicable tax and company law.

DPDPA 2023 (for Indian residents) — Section 4:

  • Consent: obtained at the point of data collection via our intake forms, clearly describing the purpose of processing.
  • Legitimate uses: processing necessary for the performance of service contracts entered into at your request, and for compliance with applicable law.
04 · Storage

How We Store Your Data

Your data is stored across our infrastructure providers: website and static content on Vercel, Inc. (EEA data residency selected); the API, workflow, and report-generation systems that process your submission on Hetzner Online GmbH's servers in Germany (EEA). Some processors below operate outside the EEA (see the table underneath) under the transfer safeguards described in this section. Free-check submissions that are never confirmed by email, and referral records, are deleted after 30 days. We apply 90-day retention for project-related documents, after which they are permanently deleted unless you have an active paid engagement. Backup copies are retained for 30 days beyond deletion. You may request deletion at any time (see Section 7).

Encryption standard

We use industry-standard TLS encryption in transit and AES-256 encryption at rest for all document storage.

05 · Third Parties

Sub-processors

We use a small number of providers to host our systems, send email, take payments, keep records and run AI models. Each is bound by data processing terms with us. The full, versioned list — with what each provider does, where it operates and the transfer safeguard relied on — is on our Sub-processors page. We update that page before adding or replacing a provider that processes client material.

We do not sell, rent or trade your personal data. We do not use your material to train AI models. We serve all website fonts ourselves — no data is sent to Google Fonts or any external font service.

06 · Transfers

International Transfers

As an India-incorporated company serving UK and EEA clients, personal data flows from your jurisdiction to our team in India and to our EU-hosted infrastructure, and is processed by the providers listed on our Sub-processors page, including AI providers outside the EU. For UK clients, we rely on the UK International Data Transfer Agreement (IDTA); for EEA clients, we rely on EU Standard Contractual Clauses (SCCs) as the lawful basis for these transfers.

For Indian residents, data is stored on our EEA-based infrastructure (Vercel and Hetzner, both described above). Cross-border transfers are conducted in accordance with Section 16 of the DPDPA 2023 and any applicable government notifications regarding permissible recipient countries.

07 · Your Rights

Your Rights

UK & EU clients — under GDPR Chapter III:

Art. 15

Right of Access

Request a copy of the personal data we hold about you.

Art. 16

Right to Rectification

Request correction of inaccurate or incomplete data.

Art. 17

Right to Erasure

Request deletion of your data, subject to legal retention obligations.

Art. 20

Right to Portability

Receive your data in a structured, machine-readable format.

Art. 21

Right to Object

Object to processing based on legitimate interests or direct marketing.

Art. 18

Right to Restriction

Request restricted processing in certain circumstances.

Indian residents — under DPDPA 2023:

§ 11

Right to Information

Know what personal data is being processed, for what purpose, and by which processors.

§ 12

Right to Correction & Erasure

Request correction of inaccurate data or erasure when no longer necessary for the stated purpose.

§ 13

Right to Grievance Redressal

Lodge a grievance with us, to be acknowledged within 48 hours and resolved within 30 days.

§ 14

Right to Nominate

Nominate another individual to exercise your data rights in the event of death or incapacity.

Exercise your rights

Email om@thrivefinity.uk with the subject line “Data Rights Request”. We acknowledge every request within 2 working days and respond within one month (UK and EU GDPR). DPDPA grievances are acknowledged within 48 hours and resolved within 30 days. You can also use our Privacy Centre.

08 · Cookies

Cookies

Our public pages set no cookies. We use browser storage only for settings you choose (such as theme and currency) and, for the current session only, the campaign or referral link that brought you here. See our Cookie Policy for the full list.

09 · Complaints

How to Complain

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the relevant supervisory authority:

  • UK clients: Information Commissioner’s Office (ICO) — ico.org.uk/make-a-complaint
  • EEA clients: your local data protection authority (listed at edpb.europa.eu).
  • Indian residents: the Data Protection Board of India (once constituted under DPDPA 2023); in the interim, you may write to the Ministry of Electronics and Information Technology (MeitY), Government of India.

We would always appreciate the opportunity to address your concern before you escalate — please contact om@thrivefinity.uk first.

10 · Updates

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email to active clients and flagged in Friday Notes. The “Last updated” date at the top of this page indicates the most recent revision. Continued use of our services following a material update constitutes acceptance of the revised policy.

Questions About Your Data?

We reply within one business day. Formal data requests are acknowledged within 2 working days.