Privacy Policy
THEO - Positioning Intelligence Platform
Effective Date: February 23, 2026
Last Updated: March 9, 2026
Version: 2.1
1. Introduction
Welcome to THEO, a positioning intelligence platform operated by THEO Growth SIA ("THEO," "we," "our," or "us"), a company registered in Latvia with EU operations.
This Privacy Policy explains how we collect, use, process, and protect your information when you use our platform. We are committed to protecting your privacy and ensuring full compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws.
Key Privacy Principles:
- ✅ All data processing occurs on EU-based infrastructure
- ✅ We never train AI models on your data
- ✅ Your competitive intelligence never leaves EU jurisdiction
- ✅ No source data stored - analysis based on publicly available information
- ✅ End-to-end encryption for all data transmission
- ✅ You maintain full ownership of all strategic intelligence
2. Data Controller Information
Legal Entity: THEO Growth SIA
Registration: Latvia
EU Operations: European Union
Contact Email: privacy@theogrowth.com
Data Protection Officer: dpo@theogrowth.com
For all privacy-related inquiries, please contact us at privacy@theogrowth.com.
3. What Data We Collect
3.1 Account Information
When you register for THEO, we collect:
- Full name
- Professional email address
- Agency/company name
- Job title/role
- Agency size
- Country/region of operation
Legal Basis: Contract performance and legitimate business interests
3.2 Usage Data
We automatically collect:
- Login timestamps and session duration
- Feature usage patterns (e.g., which analysis tools you use)
- Project creation and completion data
- Technical logs (IP address, browser type, device information)
- Error reports and system performance metrics
Legal Basis: Legitimate interests in platform improvement and security
3.3 Content You Provide
You may provide:
- Website URLs and project context (brand name, industry, region)
- Research queries and competitive analysis parameters
- Feedback and feature requests
Legal Basis: Contract performance and explicit consent
3.4 Publicly Collected Data
THEO automatically collects publicly available information:
- Public website content (through web crawling)
- Public social media profiles and content
- Public reviews, forums, and discussion platforms
- Public API data (cultural trends, market data)
Legal Basis: Legitimate interests in competitive intelligence research
Important: This data is already public and does not require additional consent
4. How We Use Your Data
4.1 Primary Processing Purposes
We use your data to:
- Provide Core Services: Generate positioning intelligence, strategic frameworks, and competitive analysis
- Platform Operation: Maintain system functionality, security, and performance
- Customer Support: Respond to inquiries and technical support requests
- Product Improvement: Analyze usage patterns to enhance features (aggregated and anonymized only)
4.2 What We DO NOT Do
- ❌ We never train AI models on your data
- ❌ We never sell or share your competitive intelligence with third parties
- ❌ We never use your client information for our own marketing
- ❌ We never store copies of competitor websites or source data we analyze
- ❌ We never transfer data outside the European Union (except limited API calls to Anthropic and Stripe, protected by SCCs)
5. Data Processing & Storage
5.1 Technical Infrastructure
Primary Processing:
- Infrastructure: Microsoft Azure and Google Cloud Platform (GCP) - EU regions only
- Core THEO Engine: Proprietary business context extraction (EU-hosted)
Third-Party AI Processing (Limited):
- Anthropic Claude and Google Gemini APIs: Used for interpretation and analysis of gathered materials
- Data Sent: Text prompts for analysis of publicly collected information (minimal usage)
- Data NOT Sent: Full strategic context or client identifiers
- Safeguards: Anonymized prompts, no training data usage
- Note: 99% of information comes from our own web scraping and public data gathering; AI APIs are used only for interpretation of materials we collect
5.2 Website-Based Analysis Architecture
Analysis Flow:
- You provide a website URL and project context
- THEO crawls and analyzes publicly available information
- Intelligence generated → Delivered to your account
- No source data stored → Analysis based on public information
Retention Policy:
- Generated Intelligence: Stored in your account until you delete it
- Account Data: Retained for contract duration + 30 days post-termination
- Technical Logs: Retained for 90 days for security and debugging purposes
5.3 Sub-processor Register
The following third-party processors handle data on our behalf. All processors operate under Data Processing Agreements (DPAs) that prohibit use of your data beyond fulfilling THEO's service requests.
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Anthropic (Claude) | Strategic analysis & positioning intelligence | Anonymised competitor context, text prompts | US (SCCs in place) |
| Google (Gemini) | Competitive research & content analysis | Anonymised competitor context, text prompts | EU |
| Stripe | Payment processing | Billing details, email address | US (PCI DSS, SCCs) |
| Firecrawl | Website data extraction | Public URLs | EU |
| Langfuse | AI pipeline observability & quality | Anonymised processing logs | EU |
| Trigger.dev | Background job orchestration | Task metadata | EU |
| Microsoft Azure / GCP | Cloud infrastructure | All platform data | EU |
We will notify you of material changes to our sub-processor list at least 30 days in advance. A full list with DPA documentation is available upon request at privacy@theogrowth.com.
5.4 Data Segregation
Our Data Isolation Commitments:
- ✅ Each project's competitive intelligence is logically isolated from all other accounts and projects
- ✅ No cross-client data access - your strategic insights are never visible to other users
- ✅ Competitive intelligence gathered for one project is never used to inform analysis for another client
- ✅ AI processing requests are stateless - no context carries between different clients' analyses
- ✅ Account deletion removes all associated project data, intelligence outputs, and processing logs
5.5 Encryption & Security
Data in Transit:
- TLS 1.3 encryption for all data transmission
- End-to-end encryption between your device and EU servers
Data at Rest:
- AES-256 encryption for stored data
- Encrypted database backups (EU-only storage)
- Access controls with role-based permissions
Security Measures:
- Regular security audits and penetration testing
- Multi-factor authentication for all accounts
- Automated threat detection and monitoring
- Enterprise-grade infrastructure security (SOC 2 and ISO 27001 certified providers)
6. Data Sharing & Disclosure
6.1 With Whom We Share Data
Service Providers:
We work with carefully selected service providers (see Section 5.3 for the full sub-processor register):
- Cloud infrastructure - Microsoft Azure / GCP (EU regions)
- AI analysis - Anthropic Claude, Google Gemini
- Web data extraction - Firecrawl (EU)
- Job orchestration - Trigger.dev (EU)
- Observability - Langfuse (EU)
- Payment processing - Stripe (PCI DSS Level 1 certified)
- Email communication services (EU-hosted)
Legal Basis: Legitimate interests and contractual necessity
Safeguards: Data Processing Agreements (DPAs) with all providers
6.2 When We Must Disclose Data
We may disclose information when legally required:
- Legal Obligations: Court orders, subpoenas, or legal processes
- Regulatory Compliance: Requests from EU data protection authorities
- Security Threats: To prevent fraud, abuse, or security breaches
- Business Transfers: In case of merger, acquisition, or asset sale (with notice to users)
6.3 Public Data Sources
Third-Party APIs We Use:
- Market intelligence APIs (public market data and industry statistics)
- Google Trends API (public trend data)
- Social media platform APIs (public profile data only)
Important: These integrations access only publicly available information and do not share your private data with third parties.
7. Your Rights Under GDPR
As an EU-based platform, we fully respect your GDPR rights:
7.1 Right to Access
Request a copy of all personal data we hold about you.
Response Time: Within 30 days
How: Email privacy@theogrowth.com
7.2 Right to Rectification
Correct inaccurate or incomplete personal data.
Response Time: Within 7 days
How: Update in account settings or email privacy@theogrowth.com
7.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data.
Response Time: Within 30 days
How: Email privacy@theogrowth.com with subject "Data Deletion Request"
Note: Some data may need to be retained for legal compliance (e.g., accounting records for tax purposes).
7.4 Right to Data Portability
Receive your data in a structured, machine-readable format.
Formats Available: JSON, CSV, PDF
How: Email privacy@theogrowth.com
7.5 Right to Object
Object to processing based on legitimate interests.
How: Email privacy@theogrowth.com
7.6 Right to Restrict Processing
Limit how we use your data in specific circumstances.
How: Email privacy@theogrowth.com
7.7 Right to Withdraw Consent
Withdraw consent for processing at any time (where consent is the legal basis).
How: Email privacy@theogrowth.com or update account settings
7.8 Right to Lodge a Complaint
File a complaint with your national data protection authority if you believe we've violated GDPR.
Latvian Data Protection Authority: https://www.dvi.gov.lv/en
8. Platform Usage Terms
8.1 Platform Data Usage
As part of normal platform operations:
- We collect usage analytics to improve product features
- We may request feedback interviews (always optional, never mandatory)
- We analyze aggregated, anonymized patterns to improve the platform
Your Data Rights Are Always Protected:
- ❌ We do not have broader data rights beyond what is stated here
- ❌ Your positioning intelligence is fully confidential
- ❌ All GDPR protections apply at all times
- ❌ All privacy commitments remain fully in effect
8.2 Feedback & Product Development
If You Provide Feedback:
- Feedback is voluntary and at your discretion
- We may use feedback to improve THEO's features
- Feedback does not include confidential client information unless you explicitly share it
- You grant us a non-exclusive license to use feedback for product development
Protecting Client Confidentiality:
- Anonymize all client names before sharing feedback
- Do not share financially sensitive information in feedback
- Focus feedback on feature functionality, not specific client strategies
9. International Data Transfers
Our Commitment:
- ✅ All core infrastructure and data storage is within the European Union
- ✅ All servers physically located in EU data centers (Azure / GCP EU regions)
- ✅ Non-EU transfers limited to two processors with full GDPR safeguards
Exceptions - US-Based Processors:
1. Anthropic (Claude API)
- Limited, anonymised text prompts for strategic analysis
- No client identifiers or complete strategic context sent
2. Stripe (Payment Processing)
- Billing details and email for subscription management
- PCI DSS Level 1 certified - highest level of payment security
Safeguards Applied to Both:
- Standard Contractual Clauses (SCCs) per GDPR Article 46
- Data Processing Agreements (DPAs) in place
- Regular transfer impact assessments conducted
Post-Schrems II Compliance: We follow EDPB guidance on international data transfers and continuously assess transfer mechanisms for adequacy.
10. Children's Privacy
THEO is a B2B platform intended for professional use by adults (18+ years old). We do not knowingly collect personal information from individuals under 18.
If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@theogrowth.com, and we will delete it promptly.
11. Cookies & Tracking Technologies
11.1 Cookies We Use
Essential Cookies (Always Active):
- Session management and authentication
- Security and fraud prevention
- Platform functionality
Analytics Cookies (Optional - Consent Required):
- Usage statistics (privacy-first analytics)
- Feature adoption tracking
- Performance monitoring
Marketing Cookies (Optional - Consent Required):
- None currently used
11.2 Your Cookie Choices
How to Manage Cookies:
- Adjust preferences in your account settings
- Use browser cookie management tools
- Opt out of analytics tracking at any time
Impact of Disabling Cookies:
- Essential cookies required for platform functionality
- Disabling analytics cookies does not affect core features
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- Changes in data processing practices
- New features or services
- Legal or regulatory requirements
- User and customer feedback
Notification Process:
- Email notification at least 30 days before changes take effect
- Prominent notice on platform dashboard
- Option to review changes and object if desired
Version History:
- All previous versions available at: theogrowth.com/privacy-history
- Current version always displayed with "Last Updated" date
13. Contact Information
For General Inquiries:
Email: info@theogrowth.com
Postal Address:
THEO Growth SIA
Ventspils, Latvia
European Union
14. Legal Framework & Compliance
Regulations We Comply With:
- ✅ General Data Protection Regulation (GDPR) - EU Regulation 2016/679
- ✅ Latvian Personal Data Protection Law
- ✅ EU ePrivacy Directive (Cookie Law)
Infrastructure Compliance:
- All cloud infrastructure providers are SOC 2 and ISO 27001 certified
- We leverage enterprise-grade, compliant infrastructure (Azure / GCP EU regions)
- Payment processing via Stripe - PCI DSS Level 1 certified
By using THEO, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last Updated: March 9, 2026
Effective Date: February 23, 2026
Version: 2.1
© 2026 THEO Growth SIA. All rights reserved.