Γλώσσα / Language

Επιλέξτε γλώσσα για την Πολιτική Απορρήτου.

PRIVACY POLICY

Last updated: 13 August 2026

In the event of any discrepancy between the Greek and English versions of this Privacy Notice, the Greek version shall prevail.

This Privacy Notice for __________ Ltd, a company registered in England and Wales (company number: __________), trading as "Thalis" ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Visit our website at https://www.thalisapp.com or any website of ours that links to this Privacy Notice.
  • Download and use our mobile application (Thalis), or any other application of ours that links to this Privacy Notice.
  • Engage with us in other related ways, including any marketing or events.

We are the controller of your personal information. Because we are established in the United Kingdom and offer our Services to people in the European Union (in particular Greece and Cyprus), both the UK GDPR and the EU GDPR apply to our processing. Our representative in the European Union for the purposes of Article 27 GDPR is: __________.

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by using our table of contents below.

  • What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
  • Do we process any sensitive personal information? We do not process sensitive personal information.
  • Do we collect any information from third parties? We do not collect any information from third parties.
  • How do we process your information? We process your information to provide, improve, and administer our Services (including tracking educational progress and assessing submitted work), process payments, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so.
  • In what situations and with which types of parties do we share personal information? We may share information in specific situations and with specific categories of third parties.
  • Is your information transferred internationally? Some of our service providers are located outside the United Kingdom and the European Economic Area. Where that is the case, we use recognised safeguards such as adequacy decisions and Standard Contractual Clauses.
  • How do we keep your information safe? We have adequate organisational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure.
  • What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
  • How do you exercise your rights? The easiest way to exercise your rights is by submitting a data subject access request, or by contacting us.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE PROCESS YOUR INFORMATION?
  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
  4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
  6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
  7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
  8. HOW LONG DO WE KEEP YOUR INFORMATION?
  9. HOW DO WE KEEP YOUR INFORMATION SAFE?
  10. WHAT ARE YOUR PRIVACY RIGHTS?
  11. CONTROLS FOR DO-NOT-TRACK FEATURES
  12. DO WE MAKE UPDATES TO THIS NOTICE?
  13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
  14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:

  • names
  • email addresses
  • usernames
  • passwords
  • billing addresses
  • educational level or school grade
  • academic performance and educational progress data
  • test results, assignments, and questionnaire responses

Data of Minors and Parental Consent. Our Services are designed for school students, including children below the age of digital consent (15 in Greece under Law 4624/2019; 14 in Cyprus under Law 125(I)/2018). For users below the applicable age of digital consent in their country of residence, we require a parent or legal guardian to create or authorise the account and to provide explicit consent for the processing of the child's personal data, in compliance with Article 8 of the GDPR. We take reasonable steps to verify that consent is given or authorised by the holder of parental responsibility.

Sensitive Information. We do not process sensitive information.

Payment Data. We may collect data necessary to process your payment if you choose to make purchases (such as your billing details and the date of your transaction). All payment card data is collected, handled, and stored directly by our payment processor, Stripe — we never see or store your full card number. You may find Stripe's privacy notice here: https://stripe.com/gb/privacy.

Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:

  • Mobile Device Data. We automatically collect device information, operating system, device and application identification numbers, browser type, IP address, and information about the features of our application(s) you accessed.
  • Push Notifications. We may request to send you push notifications regarding your account or certain features. You may turn them off in your device's settings.

Information automatically collected In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, approximate location, and information about how and when you use our Services.

The information we collect includes:

  • Log and Usage Data. Diagnostic, usage, and performance information our servers automatically collect when you access or use our Services.
  • Device Data. Information about your computer, phone, tablet, or other device you use to access the Services.
  • Location Data. Approximate location information derived from your IP address. We do not collect precise geolocation data.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, including:

  • To provide the educational Services you have purchased or signed up for, including delivering course material, recording answers and submitted work, grading and assessing that work, and tracking educational progress over time.
  • To facilitate account creation and authentication and otherwise manage user accounts, including linked guardian and student accounts.
  • To process your payments and enrolments and to send you order confirmations, receipts, and other transactional communications.
  • To respond to your enquiries and provide support.
  • To send you administrative and service information, such as changes to our terms and policies.
  • To request feedback.
  • To ensure the security of our Services, including preventing fraud, abuse, and unauthorised access.
  • To comply with our legal obligations, such as tax and accounting requirements and responding to lawful requests.
  • To improve our Services, using aggregated or consent-based analytics.
  • To send marketing communications, only where you have consented (you can withdraw consent at any time).
  • To save or protect an individual's vital interest.

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason to do so under applicable law.

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information:

  • Performance of a Contract. We process most of your information because it is necessary to perform our contract with you — to provide the courses, record your progress, and manage your account and enrolments.
  • Consent. We may process your information if you have given us permission to use your personal information for a specific purpose (for example, analytics cookies or marketing emails). For children below the age of digital consent, consent is given or authorised by a parent or legal guardian (Article 8 GDPR).
  • Legitimate Interests. We may process your information when it is reasonably necessary to achieve our legitimate business interests (for example, securing our Services and preventing fraud), provided those interests are not overridden by your rights and freedoms. Given that many of our users are children, we apply this basis with particular caution.
  • Legal Obligations. We may process your information where it is necessary for compliance with our legal obligations (for example, retaining transaction records for tax purposes).
  • Vital Interests. We may process your information where it is necessary to protect your vital interests or the vital interests of a third party.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We may share information in specific situations described in this section and/or with the following categories of third parties.

Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors who perform services for us under written data processing agreements. They cannot do anything with your personal information unless we have instructed them to do it. Our main service providers are:

  • Supabase — database, authentication, and data storage
  • Vercel — website hosting, performance monitoring, and privacy-friendly analytics
  • Stripe — payment processing
  • Microsoft (Clarity) — usage analytics (only if you consent to analytics cookies)
  • Umami — privacy-focused, cookieless website analytics
  • AI service providers — see Section 6

Teachers and staff involved in delivering your course can see the student work and progress data needed to teach and assess. Where a guardian account is linked to a student account, the guardian can see the student's progress and account information.

We also may need to share your personal information during Business Transfers (e.g., mergers, acquisitions), and where required by law, court order, or a competent authority.

We do not sell your personal information, and we do not share it with third parties for their own advertising purposes.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We use essential cookies to make the Services work, and optional analytics technologies that run only with your consent.

We use cookies and similar technologies that are strictly necessary for the Services to operate (such as keeping you signed in and remembering your cookie preferences). With your consent, we also use analytics tools to understand how the Services are used:

  • Microsoft Clarity — session analytics; loads and sets cookies only in line with the consent you give in our Cookie Preference Centre.
  • Umami — cookieless, aggregated visit statistics served from our own domain.
  • Vercel Analytics and Speed Insights — cookieless performance and traffic measurement.

Specific information about the cookies we use, and how to change your preferences at any time, is set out in our Cookie Policy.

6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.

As part of our Services, we offer features powered by AI (for example, help with exercises). We provide these through third-party AI service providers, which may include Google, OpenAI, and Groq. When you use an AI feature, the input you provide (for example, your question or your answer to an exercise) is sent to the provider to generate a response. Our agreements with these providers restrict them to processing this data in order to provide the service to us. All personal information processed using our AI features is handled in line with this Privacy Notice.

AI features assist learning; they are not used to make decisions producing legal or similarly significant effects about you without human involvement.

7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: We are a UK company serving users in the EU, and some of our service providers are located in other countries. We use recognised safeguards for these transfers.

Your information is processed by us as a company established in the United Kingdom. Transfers of personal data between the European Economic Area and the United Kingdom are covered by the European Commission's adequacy decisions for the UK.

Some of our service providers (such as Stripe, Microsoft, and our AI providers) are located in, or may process data in, the United States or other countries outside the UK and EEA. Where that is the case, we rely on appropriate safeguards recognised by the GDPR and UK GDPR, such as adequacy decisions (including the EU–US Data Privacy Framework, where the provider is certified) and/or Standard Contractual Clauses, together with additional technical and organisational measures where appropriate. You can contact us for more information about the safeguards used for a specific transfer.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfil the purposes outlined in this Privacy Notice unless otherwise required by law.

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice. Specifically, user account data and educational records will be retained for a maximum period of two (2) years following the expiration of your service contract or documented account inactivity, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organisational and technical security measures.

We have implemented appropriate technical and organisational security measures. However, no electronic transmission over the Internet can be guaranteed to be 100% secure.

10. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: In the European Economic Area (EEA), United Kingdom (UK), and Switzerland, you have rights that allow you greater access to and control over your personal information.

Under the GDPR and UK GDPR you have the right to:

  • request access to and obtain a copy of your personal information;
  • request rectification of inaccurate or incomplete information;
  • request erasure of your personal information;
  • restrict the processing of your personal information;
  • data portability — receive the information you provided to us in a structured, commonly used, machine-readable format;
  • object to processing based on our legitimate interests, and object at any time to processing for direct marketing;
  • withdraw your consent at any time where we rely on consent (this does not affect the lawfulness of processing before withdrawal); and
  • not be subject to a decision based solely on automated processing which produces legal or similarly significant effects.

You also have the right to complain to a data protection authority:

Account Information: If you would at any time like to review or change the information in your account or terminate your account, you can log in to your account settings, or contact us at contact@thalisapp.com.

11. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers include a Do-Not-Track ("DNT") feature. At this stage, no uniform technology standard for recognising and implementing DNT signals has been finalised. As such, we do not currently respond to DNT browser signals.

12. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. We encourage you to review this Privacy Notice frequently.

13. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, you may email us at contact@thalisapp.com or contact us by post at:

__________ Ltd (trading as "Thalis") Registered office: __________ EU representative (Article 27 GDPR): __________

14. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country, you may have the right to request access to, correct, or delete your personal information. To request to review, update, or delete your personal information, please submit a data subject access request or email us at contact@thalisapp.com. We will respond within one month, as required by the GDPR.

Επικοινωνία: contact@thalisapp.com

© 2026 Thalis Education. All rights reserved.