Skip to main content

    Privacy Policy

    THEO - Positioning Intelligence Platform

    Effective Date: February 23, 2026

    Last Updated: March 9, 2026

    Version: 2.1

    1. Introduction

    Welcome to THEO, a positioning intelligence platform operated by THEO Growth SIA ("THEO," "we," "our," or "us"), a company registered in Latvia with EU operations.

    This Privacy Policy explains how we collect, use, process, and protect your information when you use our platform. We are committed to protecting your privacy and ensuring full compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws.

    Key Privacy Principles:

    • ✅ All data processing occurs on EU-based infrastructure
    • ✅ We never train AI models on your data
    • ✅ Your competitive intelligence never leaves EU jurisdiction
    • ✅ No source data stored - analysis based on publicly available information
    • ✅ End-to-end encryption for all data transmission
    • ✅ You maintain full ownership of all strategic intelligence

    2. Data Controller Information

    Legal Entity: THEO Growth SIA

    Registration: Latvia

    EU Operations: European Union

    Contact Email: privacy@theogrowth.com

    Data Protection Officer: dpo@theogrowth.com

    For all privacy-related inquiries, please contact us at privacy@theogrowth.com.

    3. What Data We Collect

    3.1 Account Information

    When you register for THEO, we collect:

    • Full name
    • Professional email address
    • Agency/company name
    • Job title/role
    • Agency size
    • Country/region of operation

    Legal Basis: Contract performance and legitimate business interests

    3.2 Usage Data

    We automatically collect:

    • Login timestamps and session duration
    • Feature usage patterns (e.g., which analysis tools you use)
    • Project creation and completion data
    • Technical logs (IP address, browser type, device information)
    • Error reports and system performance metrics

    Legal Basis: Legitimate interests in platform improvement and security

    3.3 Content You Provide

    You may provide:

    • Website URLs and project context (brand name, industry, region)
    • Research queries and competitive analysis parameters
    • Feedback and feature requests

    Legal Basis: Contract performance and explicit consent

    3.4 Publicly Collected Data

    THEO automatically collects publicly available information:

    • Public website content (through web crawling)
    • Public social media profiles and content
    • Public reviews, forums, and discussion platforms
    • Public API data (cultural trends, market data)

    Legal Basis: Legitimate interests in competitive intelligence research

    Important: This data is already public and does not require additional consent

    4. How We Use Your Data

    4.1 Primary Processing Purposes

    We use your data to:

    • Provide Core Services: Generate positioning intelligence, strategic frameworks, and competitive analysis
    • Platform Operation: Maintain system functionality, security, and performance
    • Customer Support: Respond to inquiries and technical support requests
    • Product Improvement: Analyze usage patterns to enhance features (aggregated and anonymized only)

    4.2 What We DO NOT Do

    • We never train AI models on your data
    • We never sell or share your competitive intelligence with third parties
    • We never use your client information for our own marketing
    • We never store copies of competitor websites or source data we analyze
    • We never transfer data outside the European Union (except limited API calls to Anthropic and Stripe, protected by SCCs)

    5. Data Processing & Storage

    5.1 Technical Infrastructure

    Primary Processing:

    • Infrastructure: Microsoft Azure and Google Cloud Platform (GCP) - EU regions only
    • Core THEO Engine: Proprietary business context extraction (EU-hosted)

    Third-Party AI Processing (Limited):

    • Anthropic Claude and Google Gemini APIs: Used for interpretation and analysis of gathered materials
    • Data Sent: Text prompts for analysis of publicly collected information (minimal usage)
    • Data NOT Sent: Full strategic context or client identifiers
    • Safeguards: Anonymized prompts, no training data usage
    • Note: 99% of information comes from our own web scraping and public data gathering; AI APIs are used only for interpretation of materials we collect

    5.2 Website-Based Analysis Architecture

    Analysis Flow:

    1. You provide a website URL and project context
    2. THEO crawls and analyzes publicly available information
    3. Intelligence generated → Delivered to your account
    4. No source data stored → Analysis based on public information

    Retention Policy:

    • Generated Intelligence: Stored in your account until you delete it
    • Account Data: Retained for contract duration + 30 days post-termination
    • Technical Logs: Retained for 90 days for security and debugging purposes

    5.3 Sub-processor Register

    The following third-party processors handle data on our behalf. All processors operate under Data Processing Agreements (DPAs) that prohibit use of your data beyond fulfilling THEO's service requests.

    Sub-processorPurposeData ProcessedLocation
    Anthropic (Claude)Strategic analysis & positioning intelligenceAnonymised competitor context, text promptsUS (SCCs in place)
    Google (Gemini)Competitive research & content analysisAnonymised competitor context, text promptsEU
    StripePayment processingBilling details, email addressUS (PCI DSS, SCCs)
    FirecrawlWebsite data extractionPublic URLsEU
    LangfuseAI pipeline observability & qualityAnonymised processing logsEU
    Trigger.devBackground job orchestrationTask metadataEU
    Microsoft Azure / GCPCloud infrastructureAll platform dataEU

    We will notify you of material changes to our sub-processor list at least 30 days in advance. A full list with DPA documentation is available upon request at privacy@theogrowth.com.

    5.4 Data Segregation

    Our Data Isolation Commitments:

    • ✅ Each project's competitive intelligence is logically isolated from all other accounts and projects
    • ✅ No cross-client data access - your strategic insights are never visible to other users
    • ✅ Competitive intelligence gathered for one project is never used to inform analysis for another client
    • ✅ AI processing requests are stateless - no context carries between different clients' analyses
    • ✅ Account deletion removes all associated project data, intelligence outputs, and processing logs

    5.5 Encryption & Security

    Data in Transit:

    • TLS 1.3 encryption for all data transmission
    • End-to-end encryption between your device and EU servers

    Data at Rest:

    • AES-256 encryption for stored data
    • Encrypted database backups (EU-only storage)
    • Access controls with role-based permissions

    Security Measures:

    • Regular security audits and penetration testing
    • Multi-factor authentication for all accounts
    • Automated threat detection and monitoring
    • Enterprise-grade infrastructure security (SOC 2 and ISO 27001 certified providers)

    6. Data Sharing & Disclosure

    6.1 With Whom We Share Data

    Service Providers:

    We work with carefully selected service providers (see Section 5.3 for the full sub-processor register):

    • Cloud infrastructure - Microsoft Azure / GCP (EU regions)
    • AI analysis - Anthropic Claude, Google Gemini
    • Web data extraction - Firecrawl (EU)
    • Job orchestration - Trigger.dev (EU)
    • Observability - Langfuse (EU)
    • Payment processing - Stripe (PCI DSS Level 1 certified)
    • Email communication services (EU-hosted)

    Legal Basis: Legitimate interests and contractual necessity

    Safeguards: Data Processing Agreements (DPAs) with all providers

    6.2 When We Must Disclose Data

    We may disclose information when legally required:

    • Legal Obligations: Court orders, subpoenas, or legal processes
    • Regulatory Compliance: Requests from EU data protection authorities
    • Security Threats: To prevent fraud, abuse, or security breaches
    • Business Transfers: In case of merger, acquisition, or asset sale (with notice to users)

    6.3 Public Data Sources

    Third-Party APIs We Use:

    • Market intelligence APIs (public market data and industry statistics)
    • Google Trends API (public trend data)
    • Social media platform APIs (public profile data only)

    Important: These integrations access only publicly available information and do not share your private data with third parties.

    7. Your Rights Under GDPR

    As an EU-based platform, we fully respect your GDPR rights:

    7.1 Right to Access

    Request a copy of all personal data we hold about you.

    Response Time: Within 30 days

    How: Email privacy@theogrowth.com

    7.2 Right to Rectification

    Correct inaccurate or incomplete personal data.

    Response Time: Within 7 days

    How: Update in account settings or email privacy@theogrowth.com

    7.3 Right to Erasure ("Right to be Forgotten")

    Request deletion of your personal data.

    Response Time: Within 30 days

    How: Email privacy@theogrowth.com with subject "Data Deletion Request"

    Note: Some data may need to be retained for legal compliance (e.g., accounting records for tax purposes).

    7.4 Right to Data Portability

    Receive your data in a structured, machine-readable format.

    Formats Available: JSON, CSV, PDF

    How: Email privacy@theogrowth.com

    7.5 Right to Object

    Object to processing based on legitimate interests.

    How: Email privacy@theogrowth.com

    7.6 Right to Restrict Processing

    Limit how we use your data in specific circumstances.

    How: Email privacy@theogrowth.com

    7.7 Right to Withdraw Consent

    Withdraw consent for processing at any time (where consent is the legal basis).

    How: Email privacy@theogrowth.com or update account settings

    7.8 Right to Lodge a Complaint

    File a complaint with your national data protection authority if you believe we've violated GDPR.

    Latvian Data Protection Authority: https://www.dvi.gov.lv/en

    8. Platform Usage Terms

    8.1 Platform Data Usage

    As part of normal platform operations:

    • We collect usage analytics to improve product features
    • We may request feedback interviews (always optional, never mandatory)
    • We analyze aggregated, anonymized patterns to improve the platform

    Your Data Rights Are Always Protected:

    • ❌ We do not have broader data rights beyond what is stated here
    • ❌ Your positioning intelligence is fully confidential
    • ❌ All GDPR protections apply at all times
    • ❌ All privacy commitments remain fully in effect

    8.2 Feedback & Product Development

    If You Provide Feedback:

    • Feedback is voluntary and at your discretion
    • We may use feedback to improve THEO's features
    • Feedback does not include confidential client information unless you explicitly share it
    • You grant us a non-exclusive license to use feedback for product development

    Protecting Client Confidentiality:

    • Anonymize all client names before sharing feedback
    • Do not share financially sensitive information in feedback
    • Focus feedback on feature functionality, not specific client strategies

    9. International Data Transfers

    Our Commitment:

    • ✅ All core infrastructure and data storage is within the European Union
    • ✅ All servers physically located in EU data centers (Azure / GCP EU regions)
    • ✅ Non-EU transfers limited to two processors with full GDPR safeguards

    Exceptions - US-Based Processors:

    1. Anthropic (Claude API)

    • Limited, anonymised text prompts for strategic analysis
    • No client identifiers or complete strategic context sent

    2. Stripe (Payment Processing)

    • Billing details and email for subscription management
    • PCI DSS Level 1 certified - highest level of payment security

    Safeguards Applied to Both:

    • Standard Contractual Clauses (SCCs) per GDPR Article 46
    • Data Processing Agreements (DPAs) in place
    • Regular transfer impact assessments conducted

    Post-Schrems II Compliance: We follow EDPB guidance on international data transfers and continuously assess transfer mechanisms for adequacy.

    10. Children's Privacy

    THEO is a B2B platform intended for professional use by adults (18+ years old). We do not knowingly collect personal information from individuals under 18.

    If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@theogrowth.com, and we will delete it promptly.

    11. Cookies & Tracking Technologies

    11.1 Cookies We Use

    Essential Cookies (Always Active):

    • Session management and authentication
    • Security and fraud prevention
    • Platform functionality

    Analytics Cookies (Optional - Consent Required):

    • Usage statistics (privacy-first analytics)
    • Feature adoption tracking
    • Performance monitoring

    Marketing Cookies (Optional - Consent Required):

    • None currently used

    11.2 Your Cookie Choices

    How to Manage Cookies:

    • Adjust preferences in your account settings
    • Use browser cookie management tools
    • Opt out of analytics tracking at any time

    Impact of Disabling Cookies:

    • Essential cookies required for platform functionality
    • Disabling analytics cookies does not affect core features

    12. Changes to This Privacy Policy

    We may update this Privacy Policy to reflect:

    • Changes in data processing practices
    • New features or services
    • Legal or regulatory requirements
    • User and customer feedback

    Notification Process:

    • Email notification at least 30 days before changes take effect
    • Prominent notice on platform dashboard
    • Option to review changes and object if desired

    Version History:

    • All previous versions available at: theogrowth.com/privacy-history
    • Current version always displayed with "Last Updated" date

    13. Contact Information

    For Privacy Questions:

    Email: privacy@theogrowth.com

    Response Time: Within 48 hours (business days)

    For Data Protection Officer:

    Email: dpo@theogrowth.com

    Response Time: Within 72 hours (business days)

    For General Inquiries:

    Email: info@theogrowth.com

    Postal Address:

    THEO Growth SIA

    Ventspils, Latvia

    European Union

    14. Legal Framework & Compliance

    Regulations We Comply With:

    • ✅ General Data Protection Regulation (GDPR) - EU Regulation 2016/679
    • ✅ Latvian Personal Data Protection Law
    • ✅ EU ePrivacy Directive (Cookie Law)

    Infrastructure Compliance:

    • All cloud infrastructure providers are SOC 2 and ISO 27001 certified
    • We leverage enterprise-grade, compliant infrastructure (Azure / GCP EU regions)
    • Payment processing via Stripe - PCI DSS Level 1 certified

    By using THEO, you acknowledge that you have read, understood, and agree to this Privacy Policy.

    Last Updated: March 9, 2026

    Effective Date: February 23, 2026

    Version: 2.1

    © 2026 THEO Growth SIA. All rights reserved.