GDPR

Last updated 25 September 2026

Thayu.AI is built to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and similar laws around the world. This page explains our role, your rights and how to use them, and the commitments we make to customers who process personal data with Thayu. Read it with our Privacy Policy and Terms & Conditions.

1. Our role

  • Controller for account holders' data, website visitors, and the public business information we analyse to find demand.
  • Processor for the leads, contacts and conversations our customers save and message. The customer is the controller and decides how that data is used.

2. How we apply the GDPR principles

  • Lawful and transparent: every use of data has a legal basis, listed in our Privacy Policy.
  • Purpose limitation and minimisation: we only use information businesses and people chose to publish, and only store contact details a lead published or sent.
  • Accuracy: every lead keeps its evidence (quote, date and source link), so it can be checked and corrected.
  • Storage limitation: data is deleted when an account is deleted or a business asks to be removed. Opt-outs are kept only to make sure people are not contacted again.
  • Security: see section 7.
  • Privacy by default: analytics and advertising cookies are off until you accept them, and outreach honours STOP and unsubscribe automatically.

3. Public business information and legitimate interests

Finding businesses and people who publicly ask for a product or service helps both sides: buyers get answers and sellers find customers. We balance this interest against people's rights by using only public information, keeping the source of every lead, never collecting special category data, limiting outreach to one personal conversation at a time, and making objection easy. If you don't want your business analysed, use the removal page. If a business contacted you through Thayu.AI, reply STOP on WhatsApp or unsubscribe from the email.

4. Your rights and how to use them

  • Access and portability (Articles 15 and 20): download a copy of all your data in Settings → Privacy & your data.
  • Erasure (Article 17): delete your account and everything in it in the same place. Any plan is cancelled first.
  • Rectification (Article 16): edit your details in Settings, or ask us to correct anything else.
  • Objection and restriction (Articles 18 and 21): ask us to stop or limit a use of your data. Objections to direct marketing are always honoured.
  • Withdrawing consent (Article 7): change your choice at any time with "Cookie settings" in the footer.
  • Automated decisions (Article 22): Thayu.AI does not make decisions with legal or similarly significant effects. Lead scores are suggestions for people to review.

For anything else, email privacy@thayu.ai. Requests are free. We reply within one month (extendable by two months for complex requests, in which case we'll tell you), and we may ask you to confirm your identity first. If a request concerns data a Thayu.AI customer controls, we'll pass it to them and help them respond.

5. Data Processing Addendum (for customers)

This addendum forms part of our Terms & Conditions and applies when we process personal data on your behalf under Article 28 of the GDPR. We will:

  1. process personal data only on your documented instructions, which are your use of Thayu.AI and these terms, unless the law requires otherwise;
  2. make sure everyone who processes it is bound by confidentiality;
  3. apply the security measures in section 7 and keep them up to date;
  4. use the subprocessors listed in section 6 under written terms that give the same protection, and tell you before adding or replacing one so you can object;
  5. help you respond to people exercising their rights, and with security, breach notification, impact assessments and consultations with authorities;
  6. tell you without undue delay after becoming aware of a personal data breach affecting your data;
  7. delete your data when you delete your account, unless the law requires us to keep it;
  8. give you the information you need to show compliance, and allow reasonable audits with advance notice.

You are responsible for having a lawful basis for the leads you save and contact, and for giving them the information the GDPR requires. The data processed is business contact details, public posts and messages of leads and contacts, for the purpose of business outreach, for as long as your account is open. Transfers outside the EEA, UK and Switzerland are covered by the Standard Contractual Clauses (Module 2 or 3 as appropriate) and their UK and Swiss equivalents, which are incorporated by reference.

6. Subprocessors

ProviderPurposeLocation
Vercel Inc.Website and application hostingUnited States, global edge network
Managed PostgreSQL provider (e.g. Neon Inc.)Database hosting and backupsRegion chosen at setup
Anthropic PBCAI analysis, lead search and message writing (Claude)United States
Google LLCGoogle Business profiles, reviews, maps and YouTube statisticsUnited States
Meta Platforms Ireland Ltd.WhatsApp Business messagingIreland, United States
StripeCard payments and subscriptionsIreland, United States
PaystackCard and local paymentsNigeria, global
Safaricom PLC (M-Pesa)Mobile money paymentsKenya

7. Security measures

  • HTTPS everywhere, and signature-checked payment and messaging webhooks.
  • Passwords hashed with scrypt. Session tokens and IP addresses stored only as one-way hashes.
  • WhatsApp access tokens and payment credentials encrypted at rest with AES-256-GCM.
  • Every database query scoped to a single workspace, so customers can't see each other's data.
  • Links you give Thayu.AI are fetched through a protected fetcher that blocks internal network addresses.
  • Rate limits on sign-in, sign-up, previews and data exports. Access to production systems limited to people who need it.

8. International transfers

Where personal data leaves the EEA, the UK or Switzerland, we rely on adequacy decisions (including the EU-US Data Privacy Framework for certified providers) or on Standard Contractual Clauses with additional safeguards where needed.

9. Breaches

If a personal data breach is likely to put people at risk, we notify the competent supervisory authority within 72 hours of becoming aware of it, and the people affected without undue delay when the risk is high.

10. Contact and complaints

Privacy team: privacy@thayu.ai · Reliancy Kenya Limited, 7545-1000 Thika, Kenya.

You have the right to complain to a data protection authority, in particular in the EU country where you live or work. The European Data Protection Board lists every authority at edpb.europa.eu. In the UK, contact the Information Commissioner's Office at ico.org.uk.