Privacy Policy
Last Updated: 27th January 2026
1. Purpose and Scope
This Privacy Policy outlines in detail how Thumba (referred to as "we," "our," or "us") collects, processes, uses, discloses, and protects your personal information when you interact with our website, mobile applications, or engage with any of the services we provide (collectively referred to as "Services"). We are committed to maintaining the privacy and security of your personal data in compliance with applicable data protection laws and regulations, ensuring transparency in the way we manage and protect your information.
This Policy is intended to inform you about your rights regarding your personal data, how we handle and safeguard that data, and the options available to you for controlling the use and sharing of your personal information.
By accessing or using any of our Services, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by its terms. If you do not agree with the provisions set forth herein, we advise that you discontinue the use of our Services immediately.
2. Collection of Personal and Non-Personal Data
We are committed to protecting your privacy and ensuring transparency about the types of information we collect from users. The information we gather depends on how you interact with our services and includes both personal and non-personal data. This information is collected through various means, such as when you register on our platform, engage in transactions, or interact with our services.
2.1 Personal Information
"Personal Information" refers to any data that can be used to uniquely identify you as an individual. This includes, but is not limited to, your name, email address, physical mailing address, telephone number, payment or financial information, and any other information that you voluntarily provide to us in the course of using our services. We collect this information when you:
- Create an account or register for an event,
- Make a purchase or transaction,
- Subscribe to our newsletters or promotional materials,
- Participate in surveys, contests, or other interactive features,
- Contact customer support or otherwise engage with our services.
We may also collect personal information through other means, where you voluntarily submit such data to us.
2.2 Non-Personal Information
"Non-Personal Information" refers to data that does not directly identify you as an individual. This may include, but is not limited to:
- Your IP address,
- Browser type and version,
- Device identifiers, such as your device's operating system, language settings, and hardware model,
- The dates and times of your access to our services,
- Referring website addresses,
- Usage data such as the pages you view, the time spent on our website, and interactions with our services.
We automatically collect non-personal information through cookies, web beacons, log files, and other similar technologies to enhance the functionality of our services, improve user experience, and provide a more personalized experience. This data may be used in aggregated form for analytical purposes, enabling us to understand user behaviour and improve the content and services we offer.
Both personal and non-personal information are collected and processed in accordance with applicable data protection laws, ensuring the highest standard of confidentiality and security for your data.
3. Data Usage and Processing
The information we collect may be utilized for various purposes necessary to provide and improve our services, including but not limited to the following:
(a) Service Provision and Enhancement: To deliver, operate, and improve our products, services, and offerings, ensuring that the features and functionality of the Services are maintained and optimized;
(b) Order Processing and Fulfilments: To accurately process transactions, fulfil product or service requests, and manage billing and payment activities in accordance with contractual obligations;
(c) Customer Communication and Support: To communicate with you regarding your account, respond to inquiries, provide technical support, resolve issues, and offer assistance in relation to our Services;
(d) Marketing and Promotional Activities: Where permitted by applicable laws and regulations, to send you marketing communications, promotional materials, and updates regarding new products, services, or offers that may be of interest to you. You will have the opportunity to opt out of these communications at any time;
(e) Service Improvement: To better understand how users interact with our Services by analysing usage patterns, trends, and preferences, allowing us to enhance user experience and develop new features and services;
(f) Fraud Prevention and Security: To monitor and mitigate security risks, detect and prevent fraud or unauthorized access, and ensure compliance with legal, regulatory, or contractual obligations, including enforcing our terms of service and protecting our rights and the rights of others.
4. Information Sharing and Disclosure
We are committed to protecting your personal information and will not sell or rent your data to third parties. However, in certain circumstances, we may share your information with third parties, as outlined below:
(a) With Service Providers: We may disclose your personal information to trusted third-party service providers who assist us in operating our business, such as payment processors, cloud service providers, customer support services, or marketing agencies. These third parties are contractually obligated to safeguard your personal data and use it only for the purposes specified by us;
(b) In Compliance with Legal Requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or in response to valid legal demands such as subpoenas, court orders, or to comply with applicable laws;
(c) Business Transfers: In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, your personal information may be transferred as part of the transaction. We will take reasonable steps to ensure the confidentiality of your data in such circumstances;
(d) To Protect Our Rights: We may disclose your information when we believe it is necessary to protect our legal rights, enforce our terms of service, prevent fraud or security breaches, or to protect the safety and rights of our users, employees, or the public.
Each of these disclosures is subject to appropriate confidentiality and data protection obligations in compliance with applicable privacy laws.
4.1 Service Providers
We may engage with third-party service providers to facilitate and enhance the delivery of our Services. These providers may assist us in various operational activities, such as transaction processing, data hosting, and communication delivery. In such instances, we may share your personal information with these providers solely to the extent necessary for them to perform their contracted functions. These third-party service providers are contractually bound to maintain the confidentiality, security, and integrity of your personal information in accordance with the standards outlined in this Privacy Policy, and they are prohibited from using your information for any purpose other than as specified in their agreements with us.
4.2 Legal Compliance and Requirements
We may disclose your personal information when required to do so by applicable law, legal process, or governmental request. Furthermore, we may disclose information if we, in good faith, believe such disclosure is necessary to: (a) comply with our legal obligations; (b) protect or defend our rights, property, or safety, including the enforcement of our agreements or policies; (c) protect against fraud, illegal activities, or potential harm to our users or the public.
4.3 Privacy Requirement for Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of our business or assets, your personal information may be disclosed to the acquiring entity or relevant third party as part of the transaction. We will take appropriate steps to ensure that your personal information remains protected and handled in accordance with this Privacy Policy. In the event of any such transfer, we will notify you of the change in ownership or control of your personal information and any related changes to the Privacy Policy, as required by applicable law.
5. Data Retention Policy
We will retain your personal data only for the period necessary to fulfil the purposes for which it was collected, including to meet any legal, regulatory, accounting, or reporting requirements. Upon the expiration of that period, or if the personal data is no longer required for the specified purposes, we will securely erase, anonymize, or otherwise de-identify the data in accordance with applicable data protection laws. In certain cases, we may retain your data for a longer period if required to comply with legal obligations or defend our legal rights.
6. Data Protection and Privacy Statement
Personal data that is recorded during product registration and subsequent addition of user(s) is processed in accordance with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). Thumba processes only such personal data as is necessary for the provision of its services and in compliance with applicable law.
Thumba processes personal data only in accordance with its documented internal procedures and applicable legal requirements. Where processing is required by law, Thumba will comply with such obligations, subject to any legal restrictions on disclosure.
Thumba stores only personal data and project-related information required for service delivery. All such data is encrypted at rest and in transit. Project inputs and outputs processed by Thumba are not accessible to Thumba personnel and are not transmitted, accessed, or retrieved by them. Users remain responsible for the storage and ongoing management of project data within their own systems and integrated platforms.
Thumba ensures that all personnel authorised to process personal data are bound by appropriate confidentiality obligations, whether contractual or statutory.
Take all measures required pursuant to Article 32 of the UK GDPR, including implementing appropriate technical and organisational measures to ensure a level of security appropriate to the risk;
Thumba does not transfer personal data outside the United Kingdom unless appropriate safeguards are in place in accordance with Chapter V of the UK GDPR.
Thumba supports the exercise of data subject rights and provides reasonable assistance, where required, to comply with applicable data protection obligations, including access, rectification, erasure, restriction, portability, objection, and breach notification.
Upon termination of services or when personal data is no longer required, Thumba will securely delete or anonymize personal data unless retention is required by applicable law.
Thumba maintains appropriate records of processing activities to demonstrate compliance with applicable data protection laws and internal governance requirements.
In the event of a personal data breach, Thumba will notify relevant authorities and affected individuals in accordance with applicable legal requirements and within prescribed timelines.
Thumba affirms its commitment to protecting personal data and privacy in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws. Thumba shall collect, process, and store personal data with paramount regard to legal compliance, ensuring all data processing activities are executed with transparency, fairness, and accountability. The fundamental principles of data protection shall be maintained, with explicit protection of individual rights and freedoms concerning personal data processing.
Thumba shall only collect and process personal data for specified, explicit, and legitimate purposes, maintaining full compatibility with the initial purpose of data collection. The legal bases for data processing shall include, but not be limited to: explicit consent, contractual necessity, legal obligation, protection of vital interests, performance of a public task, and legitimate interests of the data controller. Individuals are granted comprehensive rights, including but not limited to: right of access, right to rectification, right to erasure, right to restriction of processing, right to data portability, and right to object. Thumba commits to implementing appropriate technical and organizational measures to ensure a level of data security commensurate with the associated risks.
Personal data shall be retained exclusively for the duration necessary to fulfil the originally specified processing purposes, in full compliance with applicable legal and regulatory requirements. Data transfer to third-party processors or recipients shall occur only when adequate safeguards are established, including but not limited to standard contractual clauses, binding corporate rules, or explicit data subject consent. In the event of a personal data breach, Thumba shall comply with applicable legal and regulatory notification requirements and, where necessary, inform affected parties. Thumba shall process personal data in accordance with its Privacy Policy and Data Protection Policy, ensuring full compliance with the General Data Protection Regulation (GDPR) and all other applicable data protection laws, including regional, national, and industry-specific regulations and other applicable data protection laws.
Thumba shall retain personal information only for such duration as is reasonably necessary to fulfil the legitimate business purposes for which the data was originally collected, or as may be required to comply with applicable legal, regulatory, contractual, or audit obligations. The retention period shall be determined based on the nature and sensitivity of the information, the threat posed by misuse or unintended disclosure, the purposes for which the data is processed, and whether such purposes may be achieved through other means.
All personal data shall be subject to periodic review to assess whether continued retention remains necessary. Upon determination that the data is no longer required for the stated purposes or that the applicable retention period has expired, Thumba shall take appropriate steps to ensure secure disposal of the information. Such disposal may include, but is not limited to, permanent deletion from all systems and backups, anonymization such that the data can no longer be associated with any identifiable individual, or secure physical destruction where applicable.
Thumba shall implement technical and organizational safeguards to ensure that the deletion or destruction process is conducted in a manner that prevents unauthorized access, restoration, or misuse of the data. These measures shall include irreversible deletion tools, encryption standards, access controls, and audit logging where appropriate.
Data subjects may, subject to applicable limitations, request access to their personal information, seek rectification or deletion, or object to the continued processing or retention of such information by Thumba. Any such requests shall be handled in accordance with Thumba's internal procedures and applicable laws.
7. Information Security Measures
We are committed to ensuring the security of your personal information and have implemented industry-standard security measures to protect it against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and regular security audits. However, no system of electronic transmission or storage is infallible, and while we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security. We recommend you also take steps to safeguard your personal information, such as using strong passwords and maintaining the security of your own devices.
8. Use of Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to collect information and enhance your experience. These technologies help us understand how you interact with our services, improve functionality, and deliver personalized content.
Cookies may also be used for analytics purposes and to serve targeted advertisements. You have the option to control or disable cookies through your browser settings; however, doing so may limit your access to certain features of our website or affect the functionality of our services. For more information on how we use cookies and how you can manage them, please refer to our Cookies Policy.
9. Data Security and Transmission
We implement appropriate technical and organizational measures to protect data during transmission between systems, applications, and users. Industry-standard encryption mechanisms are applied to safeguard data in transit and to prevent unauthorized interception, alteration, or access.
Secure communication protocols are enforced by design, and insecure or unencrypted access paths are restricted through controlled application and network configurations. Reasonable security hardening practices are followed to reduce exposure to common threats and vulnerabilities.
Security controls are periodically reviewed and assessed using recognized industry frameworks and best practices. Where applicable, independent or internal security assessments may be conducted to evaluate the effectiveness of implemented safeguards, including testing against commonly identified application security risks.
10. Application Security Controls
Access to systems and data is governed by appropriate access control mechanisms, including role-based access, least-privilege principles, and authentication safeguards.
Additional measures such as input validation, data minimization, monitoring, logging, and masking are implemented where appropriate to mitigate the risk of unauthorized access, data leakage, or misuse.
Security measures are continuously reviewed and enhanced in line with evolving security standards, business requirements, and regulatory expectations.
11. Use of Automated and AI-Enabled Processing
The application may leverage automated or artificial intelligence–enabled services to provide certain features or functionalities. Any data processed for such purposes is limited to what is reasonably necessary to perform the requested operation.
Customer data is not used to train machine learning models or artificial intelligence systems.
Where third-party service providers are involved in automated processing, data is handled in accordance with their applicable contractual, privacy, and security obligations.
Appropriate safeguards are maintained to ensure that data is processed solely for the intended purpose and is not retained or used beyond what is necessary to deliver the service.
Reasonable measures are taken to avoid the unnecessary transmission of personally identifiable information, and controls are implemented to reduce the risk of unauthorized disclosure or misuse.
Information voluntarily provided by users for the purpose of generation or scanning of project artefacts is not used for training, fine-tuning, or improving any in-house or external large language models.
12. Security Assurance
While no system can be guaranteed to be completely secure, we take reasonable and proportionate steps to protect data against unauthorized access, loss, misuse, or alteration.
Our security practices are designed to align with generally accepted industry standards and are adapted as needed to address emerging risks and technological change.
13. User Rights and Data Subject Access Requests
You are entitled to exercise several rights concerning your personal information in accordance with applicable data protection laws.
Specifically, you have the right to access your personal information, to request its correction or updating, and to request its deletion at any time.
Additionally, you hold the right to withdraw your consent for the processing of your personal information, as well as the right to request a restriction on the processing of such information.
To exercise any of these rights or for any inquiries related to your personal information, please contact us at thumba.admin@thumba.ai
We will respond to your request in a timely manner and in accordance with the relevant legal framework.
14. Protection of Minors' Privacy
Our Services are specifically designed for individuals aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18.
If we discover that we have inadvertently collected personal information from a child under 18, we will take prompt action to delete that information from our records.
If you believe that we have collected personal information from a child under 18, please contact us immediately at thumba.admin@thumba.ai, and we will take the necessary steps to address your concerns.
15. Cross-Border Data Transfers
Please be advised that your personal information may be transferred and processed in countries outside your country of residence, which may have different data protection laws and regulations than those in your home country.
While such countries may not provide the same level of data protection as your home country, we are committed to ensuring that appropriate safeguards are implemented to protect your personal information during such transfers.
These safeguards may include contractual agreements, adherence to recognized data protection frameworks, and other mechanisms designed to ensure the confidentiality and security of your information in accordance with applicable legal standards.
16. Review
We reserve the right to amend or modify this Privacy Policy at our discretion and at any time for effectiveness and suitability as part of the management.
Any such changes will be effective immediately upon posting the revised policy on this webpage, and the date of the latest revision will be indicated at the top of this document as the "Last Updated" date.
We strongly encourage our users to periodically review this Privacy Policy to remain informed about how we collect, use, disclose, and protect your personal information.
Your continued use of our services following the posting of any changes constitutes your acceptance of those changes.
In the event of significant changes to this Privacy Policy that materially affect your rights or the way we handle your personal information, we will provide additional notice, which may include sending an email to the address associated with your account or providing a prominent notice on our website prior to the change taking effect. We value your privacy and are committed to keeping you informed about how we safeguard your information. In the event of changes in applicable laws, regulations, or amendments relevant to this policy, we will conduct a review to ensure compliance with current legal requirements.