Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal data in compliance with GDPR and UK data protection laws.
Last Updated: January 2025
For any privacy-related questions, contact us at oscar@thort.ai
Table of Contents
1. Company Information
Data Controller:
THORT.AI
104 Warton Street
Lytham, FY8 5HA
United Kingdom
Contact:
Email: oscar@thort.ai
Phone: +44 7493 626754
For all data protection inquiries, please contact us using the above details.
2. Data We Collect
We collect and process the following types of personal data:
Chat Assistant Data:
Conversation content and messages you send through our AI chat assistant
Business information you share during our 5-question consultancy questionnaire
Technical details about your business needs and challenges
AI-generated summaries of our conversations
Session identifiers and timestamps
Booking Information:
Name and email address for consultation bookings
Preferred appointment times and dates
Meeting notes and consultation context
Communication preferences
Technical Data:
Browser type and version
Device information and operating system
IP address and general location (country/region)
Website usage analytics and interaction patterns
Session data and cookie preferences
Email Communications:
Questionnaire summaries sent to our internal team
Booking confirmations and appointment details
Service-related communications
3. Legal Basis for Processing
We process your personal data under the following legal bases:
Legitimate Interest (Article 6(1)(f) GDPR):
Improving our AI chat assistant and service quality
Understanding client needs for business development
Website analytics and performance optimization
Contract Performance (Article 6(1)(b) GDPR):
Processing bookings and scheduling consultations
Delivering requested consultancy services
Managing client relationships and communications
Consent (Article 6(1)(a) GDPR):
Email marketing communications (where applicable)
Non-essential cookies and tracking
Optional data collection for service enhancement
We only process personal data where we have a valid legal basis and will inform you if this changes.
4. How We Use Your Data
Your personal data is used for the following purposes:
Service Delivery:
Providing AI-powered consultancy assistance through our chat system
Scheduling and conducting consultation appointments
Delivering personalized business recommendations
Following up on consultancy sessions
Business Operations:
Analyzing conversation patterns to improve our AI responses
Understanding client needs to develop relevant services
Managing client relationships and service delivery
Internal reporting and business analysis
Communication:
Sending booking confirmations and appointment reminders
Sharing questionnaire summaries with our consultancy team
Providing service updates and relevant information
Responding to inquiries and support requests
Legal and Compliance:
Meeting legal obligations and regulatory requirements
Protecting against fraud and security threats
Maintaining records for business and legal purposes
5. Data Sharing and Third Parties
We share your personal data with the following third parties:
AI Processing Services:
Anthropic (Claude AI) - Conversation data is sent to Anthropic's servers in the United States for AI processing and response generation
Purpose: Providing intelligent responses through our chat assistant
Safeguards: Standard Contractual Clauses and Anthropic's privacy commitments
Booking Management:
Cal.com - Name, email, and appointment details for scheduling consultations
Location: European Union data centers
Purpose: Managing consultation bookings and calendar integration
Website Analytics:
Vercel Analytics - Anonymous usage data and performance metrics
Purpose: Website optimization and performance monitoring
Data: Anonymized traffic patterns and technical performance data
Email Services:
Internal Email Systems - Questionnaire summaries and consultation notes
Purpose: Internal team collaboration and service delivery
Access: Limited to authorized THORT.AI personnel only
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
6. Data Retention
We retain your personal data for the following periods:
Chat Conversations:
Retention Period: 2 years from last interaction
Purpose: Service improvement and follow-up consultations
Deletion: Automatic deletion after retention period unless legal obligation requires longer retention
Booking Information:
Retention Period: 3 years from consultation date
Purpose: Service delivery, follow-up, and business records
Deletion: Secure deletion after retention period
Technical Data:
Retention Period: 1 year from collection
Purpose: Website optimization and security
Deletion: Automatic anonymization or deletion
Email Communications:
Retention Period: 3 years from last communication
Purpose: Business relationship management and legal compliance
Deletion: Secure deletion unless ongoing business relationship exists
You can request earlier deletion of your data at any time, subject to legal obligations.
7. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
Right of Access (Article 15):
Request copies of your personal data
Receive information about how we process your data
Understand the purposes and legal basis for processing
Right to Rectification (Article 16):
Correct inaccurate personal data
Complete incomplete personal data
Update outdated information
Right to Erasure (Article 17):
Request deletion of your personal data
"Right to be forgotten" in certain circumstances
Immediate deletion where data is no longer necessary
Right to Restrict Processing (Article 18):
Limit how we use your personal data
Suspend processing while verifying accuracy
Alternative to deletion in some circumstances
Right to Data Portability (Article 20):
Receive your data in a structured, commonly used format
Transfer your data to another service provider
Direct transfer where technically feasible
Right to Object (Article 21):
Object to processing based on legitimate interests
Object to direct marketing at any time
Object to automated decision-making and profiling
To Exercise Your Rights:
Email us at oscar@thort.ai with your request. We will respond within 30 days and may ask for identification to verify your identity.
9. International Data Transfers
Some of your personal data may be transferred outside the UK/EEA:
Anthropic (Claude AI) - United States:
Safeguards: Standard Contractual Clauses (SCCs)
Purpose: AI processing and response generation
Protection: Anthropic's data protection commitments and security measures
Other Services:
We ensure all international transfers comply with UK GDPR requirements through:
Standard Contractual Clauses
Adequacy decisions
Binding Corporate Rules
Explicit consent where required
Your Rights:
You have the right to information about international transfers and the safeguards in place.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
Technical Measures:
Encryption of data in transit and at rest
Secure server infrastructure and data centers
Regular security updates and patches
Access controls and authentication systems
Organizational Measures:
Staff training on data protection and privacy
Regular security assessments and audits
Data breach response procedures
Privacy by design principles in system development
Data Breach Response:
In the event of a data breach, we will:
Notify the ICO within 72 hours where required
Inform affected individuals without undue delay
Take immediate steps to contain and remedy the breach
Conduct a full investigation and implement preventive measures
11. Automated Decision-Making
AI Chat Assistant:
Our Claude AI chat assistant provides automated responses based on your questions and business information. This is not used for:
Automated decision-making with legal effects
Profiling that significantly affects you
Decisions about service eligibility or pricing
Your Rights:
You can request human review of AI-generated advice
You are not subject to purely automated decision-making
All significant business decisions involve human oversight
Booking System:
Our Cal.com integration automates appointment scheduling based on availability, but this does not involve profiling or decision-making that significantly affects you.
12. Policy Updates
Policy Changes:
We may update this privacy policy from time to time to reflect:
Changes in our data processing activities
Updates to legal requirements
Improvements to our privacy practices
New features or services
Notification:
Significant changes will be notified via email
Updates will be posted on our website
Continued use constitutes acceptance of changes
You can request clarification of any changes
Version Control:
This policy was last updated: January 2025
Previous versions are available upon request.
Contact Us:
For questions about this policy or our privacy practices, contact oscar@thort.ai
Questions or Concerns?
If you have any questions about this privacy policy or wish to exercise your rights, please contact us:
Email: oscar@thort.ai
Phone: +44 7493 626754
Address: 104 Warton Street, Lytham, FY8 5HA, United Kingdom
Right to Complain: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been breached. Visit ico.org.uk for more information.