Privacy Policy

Thryve Pro Academy — Homepage Privacy Policy

Last updated: 21 August 2026

This Privacy Policy explains how Thryve Pro Academy (company number 16573922) ("we", "us", "our") collects, uses, stores, and protects your personal data when you visit our homepage, browse the services we offer, and use our contact form.

We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).

Scope of this Privacy Policy. This Privacy Policy applies only to our homepage — the page that showcases the services we offer and allows you to contact us through our contact form. Other pages and services on our website (including our retreats pages) are governed by their own separate privacy policy and terms of use. Please see Section 14 for further detail, and review the relevant policy when you use those services.

  1. Who We Are

Thryve Pro Academy is a company registered in England and Wales (company number 16573922), with its registered office at 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.

For the purposes of UK data protection law, we are the data controller responsible for your personal data.

Data protection contact: Michael Chalmers

Email: hello@thryve3.com

Postal address: 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE

ICO registration number: ZC019699

We are not required under UK GDPR to appoint a Data Protection Officer (DPO) because we are a small organisation that does not carry out large-scale processing of special category data or large-scale systematic monitoring. Michael Chalmers serves as the primary data protection contact and is responsible for overseeing compliance with this Privacy Policy.

  1. What Personal Data We Collect

Through our homepage, we collect and process the following categories of personal data:

Information you provide to us:

  1. Contact form information — when you complete our contact form, we collect your name, your email address, and the content of the message or enquiry you send us. We do not collect any other information through the contact form.

Information collected automatically:

  1. Website analytics data — when you visit our homepage, we collect information about how you use it through Google Analytics, including pages visited, time spent on pages, referral sources, browser type, device type, and approximate geographic location (at city level). This data is collected using cookies and is typically pseudonymised.
  2. Cookie data — our website uses cookies, including Google Analytics cookies and basic session and functional cookies. Full details are set out in Section 6 of this Privacy Policy.

No special category data. We do not collect or process any special category data (such as health data) through our homepage. We do not collect payment information or process bookings through our homepage.

Nature of data provision (Article 13(2)(e)). You are not under any statutory or contractual obligation to provide personal data through our homepage. Completing the contact form is entirely voluntary — however, if you choose not to provide your name and email address, we will be unable to respond to your enquiry. Website analytics data is collected via cookies only where you have provided consent, which you may withhold or withdraw at any time without affecting your ability to use the homepage.

  1. How We Use Your Personal Data and Our Lawful Bases

Under UK GDPR, we must have a lawful basis for each processing activity. The table below sets out how we use your personal data and the lawful basis we rely on under Article 6(1) of UK GDPR.

Processing Activity

Personal Data Used

Lawful Basis (Article 6)

Responding to your enquiries submitted via the contact form

Name, email address, message content

Article 6(1)(f) — legitimate interests (responding to and managing enquiries from prospective and existing customers)

Website analytics via Google Analytics to understand and improve how our homepage is used

Analytics data collected via cookies

Article 6(1)(a) — consent (given via our cookie consent banner)

Operating basic, essential website functions (session and functional cookies)

Cookie data

PECR Regulation 6(4) exemption; Article 6(1)(f) — legitimate interests (ensuring our website functions correctly and securely)

Where we rely on legitimate interests as the lawful basis, we have considered your interests, rights, and freedoms, and are satisfied that our legitimate interests do not override them. You have the right to object to processing based on legitimate interests at any time (see Section 6).

Where we rely on consent for non-essential cookies, you may withdraw your consent at any time (see Sections 5 and 6).

  1. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We share your personal data only with the following third-party service providers who process data on our behalf

Service Provider

Purpose

Location

Transfer Safeguard

Google (Google Analytics)

Website analytics and usage tracking

United States

UK-US Data Bridge (Google LLC is a certified participant under the UK Extension to the EU-US Data Privacy Framework)

Tilda

Website building and hosting

Distributed infrastructure (EU-based servers); Tilda is a Russian-owned company

UK International Data Transfer Agreement (IDTA) and/or Standard Contractual Clauses (SCCs), together with a transfer risk assessment and supplementary measures. We keep the appropriateness of these safeguards under active review (see Section 4A)

Each of these providers acts as a data processor and processes your data only on our instructions and in accordance with UK data protection law. We have appropriate contractual arrangements in place with each provider.

We may also disclose your personal data where required to do so by law, regulation, or court order, or to protect our rights or the rights of third parties.

4A. Note on Tilda and Ongoing Review

Tilda is a website building and hosting provider that is Russian-owned but operates using EU-based infrastructure. We recognise that the ownership of our hosting provider is a relevant factor in assessing the risk to your personal data when it is transferred or processed outside the UK. Accordingly, we rely on the UK IDTA and/or SCCs, supported by a transfer risk assessment and appropriate supplementary technical and organisational measures. We keep these arrangements, and the suitability of this provider generally, under active and ongoing review, and we will take further steps (including changing provider where necessary) if we consider that the protection of your personal data requires it.

  1. International Data Transfers

Some of the third-party service providers we use are based, or process data, outside the United Kingdom. When we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place to protect your data, in compliance with UK GDPR Articles 44 to 49.

The safeguards we rely on include:

  1. UK-US Data Bridge — for transfers to US-based organisations that are certified participants under the UK Extension to the EU-US Data Privacy Framework (including Google). The UK-US Data Bridge has been recognised by the UK Government as providing an adequate level of protection for personal data.
  2. UK International Data Transfer Agreement (IDTA) and Standard Contractual Clauses (SCCs) — for transfers that are not covered by the UK-US Data Bridge (including transfers connected with our hosting provider, Tilda), we use the UK IDTA approved by the Information Commissioner's Office and/or Standard Contractual Clauses with the UK Addendum, together with a transfer risk assessment.
  3. Supplementary measures — where necessary, we implement additional technical and organisational measures to ensure that the level of protection required by UK GDPR is maintained.

You may request a copy of the safeguards we have put in place by contacting us using the details in Section 1.

  1. Cookies

Our homepage uses cookies to ensure it functions correctly and to help us understand how visitors use the site.

What are cookies? Cookies are small text files placed on your device (computer, tablet, or smartphone) when you visit a website. They are widely used to make websites work efficiently and to provide information to website owners.

Types of cookies we use:

Cookie Type

Purpose

Duration

Consent Required

Strictly necessary / functional cookies

Essential for the website to function properly, including maintaining your session, remembering your preferences, and enabling core website features

Session (deleted when you close your browser) or up to 12 months

No — these are exempt under PECR Regulation 6(4) as they are strictly necessary for the service you have requested

Google Analytics cookies (_ga, _gid, _gat)

Used to collect information about how visitors use our homepage, including which pages are visited most often and how visitors navigate the site. This information helps us improve the website

_ga: 14 months; _gid: 24 hours; _gat: 1 minute

Yes — we obtain your consent before setting analytics cookies, in accordance with PECR Regulation 6

Managing your cookie preferences: When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies (including Google Analytics cookies). You can change your cookie preferences at any time by clearing your cookies and revisiting the site, or by adjusting your browser settings.

Browser settings: Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all cookies, accept only certain cookies, or notify you when a cookie is being placed. Please note that disabling cookies may affect the functionality of our website.

For more information about cookies and how to manage them, visit www.allaboutcookies.org.

  1. How Long We Keep Your Data

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by law. Our specific retention periods are as follows:

Data Category

Retention Period

Reason

Contact form enquiries (name, email, message content)

12 months from the date of last correspondence

Responding to and managing your enquiry, and dealing with any related follow-up.

Website analytics data (Google Analytics)

14 months

Google Analytics default retention period for user and event data

When your personal data is no longer required, we will securely delete or anonymise it.

  1. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  1. Right of access — you have the right to request a copy of the personal data we hold about you (a "data subject access request" or "DSAR").
  2. Right to rectification — you have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
  3. Right to erasure — you have the right to request that we delete your personal data in certain circumstances (for example, where it is no longer necessary for the purpose for which it was collected).
  4. Right to restriction of processing — you have the right to request that we restrict the processing of your personal data in certain circumstances (for example, where you contest the accuracy of the data).
  5. Right to data portability — you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller, where the processing is based on consent or contract performance and is carried out by automated means.
  6. Right to object — you have the right to object to processing of your personal data where we rely on legitimate interests as the lawful basis. Where you object, we will stop processing your data for that purpose unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  7. Right to withdraw consent — where we process your personal data on the basis of your consent (for example, analytics cookies), you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  8. Rights relating to automated decision-making — you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you. We confirm that we do not carry out any automated decision-making or profiling using your personal data (see Section 11).
  1. How to Exercise Your Rights

To exercise any of your data protection rights, please contact us:

Email: hello@thryve3.com

Post: Michael Chalmers, Thryve Pro Academy, 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE

What to include in your request: Please provide your full name, email address (or other details we can use to identify you), and a clear description of the right you wish to exercise.

Identity verification: To protect your data, we may need to verify your identity before responding to your request. We will ask you to provide sufficient information to confirm you are the person whose data the request relates to.

Response timeframe: We will respond to your request within one calendar month of receiving it. If your request is complex or we receive a large number of requests, we may extend this period by a further two months. If so, we will inform you within the first month and explain the reason for the extension.

Cost: We will not normally charge a fee for handling your request. However, if your request is manifestly unfounded or excessive (for example, if you make repetitive requests), we may charge a reasonable administrative fee or refuse the request.

Complaints: If you are not satisfied with our response, or if you believe we are processing your personal data in a way that is not compliant with UK data protection law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Telephone: 0303 123 1113

Website: https://ico.org.uk

Email: icocasework@ico.org.uk

We encourage you to contact us first so that we can try to resolve any concerns before you escalate to the ICO.

  1. Data Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include:

  1. Using secure, encrypted connections (HTTPS/TLS) for data transmitted through our website.
  2. Restricting access to personal data to authorised personnel who need it to perform their duties.
  3. Regularly reviewing our data processing practices and security measures.

While we take all reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal data.

  1. Data Breach Notification

In the event of a personal data breach:

  1. Notification to the ICO — where a breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, as required by UK GDPR Article 33.
  2. Notification to you — where a breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by UK GDPR Article 34. We will inform you of the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address it.
  1. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making (making decisions by automated means without any human involvement) or profiling (automated processing of personal data to evaluate certain personal aspects) that produces legal effects or similarly significantly affects you.

  1. Children's Data

Our services are designed for individuals aged 18 and over. We do not knowingly collect or process personal data from anyone under the age of 18 through our homepage.

If you are under 18, please do not use our contact form or provide any personal data to us.

If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data as soon as reasonably practicable. If you believe we may hold data about a child under 18, please contact us using the details in Section 1.

  1. Other Pages and Services

This Privacy Policy covers only our homepage. Other pages and services on our website — including our retreats pages, where you can book and pay for our online wellbeing retreats — are governed by their own separate privacy policy and terms of use. Those services involve different processing activities (such as taking bookings, processing payments, delivering sessions via video conferencing, and handling any health information you choose to share), which are explained in the separate retreats privacy policy.

When you follow a link from our homepage to those pages, or use any of those services, please review the separate privacy policy and terms of use that apply to them. This Privacy Policy does not apply to your use of those pages or services.

Our website may also contain links to other third-party websites (including Google and social media platforms). We are not responsible for the privacy practices or content of those websites, and we encourage you to read the privacy policy of any website you visit.

  1. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes, we will post the updated Privacy Policy on our website with a revised "Last updated" date.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

  1. Contact Us

If you have any questions about this Privacy Policy, your personal data, or our data protection practices, please contact us:

Thryve Pro Academy

Data protection contact: Michael Chalmers

Email: hello@thryve3.com

Post: 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE

Company number: 16573922

ICO registration number: ZC019699