Privacy Policy

Last updated

This notice explains what personal data ThriveCore Technologies collects when you use ThriveSurvey, why we collect it, and the rights you have over it. It covers both people who hold a ThriveSurvey account and people who answer a survey built with it.

1. Who we are

ThriveSurvey is operated by ThriveCore Technologies ("we", "us"), registered at [registered address], [country]. For questions about this notice or your data, contact privacy@thrivecoretech.com.

Where the Nigeria Data Protection Act 2023 ("NDPA") applies, we act as a data controller for account data and as a data processor for survey responses. Where the UK or EU GDPR applies, the same split holds: controller for our own customers, processor for the response data our customers collect through us. Our EU/UK representative, where one is required, is [representative].

2. The two kinds of data on this platform

This distinction decides who is answerable to you, so it is worth being precise about.

Account data — we decide how it is used

If you sign up for ThriveSurvey, we hold your name, email address, organization, encrypted password, billing records, and a log of significant actions taken in your workspace. We determine the purposes of this processing, so we are the controller and this notice governs it directly.

Survey response data — our customer decides how it is used

When you answer a survey built with ThriveSurvey, the organization that created that survey decides what to ask, why, and how long to keep it. They are the controller; we only store and process it on their written instructions. If you want your responses corrected or deleted, that request belongs with them — contact them directly. If you cannot identify or reach them, write to us and we will pass it on.

3. What we collect and why

DataWhyLawful basis
Name, email, password, organization Create and secure your account Performance of a contract
Billing details and invoices Take payment and meet tax obligations Contract; legal obligation
Survey responses and any contact lists you upload Provide the service to the customer who collected them Processed on the customer's instructions
IP address, browser, pages visited, timestamps Keep the service secure, diagnose faults, prevent abuse Legitimate interests
Support correspondence Answer your questions and keep a record Legitimate interests
Marketing email address Send product news you asked for Consent, withdrawable at any time

We do not sell personal data, and we do not use survey responses to train machine-learning models except where the customer who owns them explicitly enables an AI feature on their own data.

4. Sensitive data

A survey can ask anything, including questions touching health, beliefs, or other sensitive categories. Where a customer collects such data through ThriveSurvey, they are responsible for having a valid basis for it — explicit consent under NDPA section 30 or GDPR Article 9 as applicable. We provide the tools; we do not choose the questions.

5. Who we share it with

We use a small number of processors, each under contract and each only for the purpose listed:

  • Hosting and database — [provider], [region]
  • Email delivery — Amazon SES and Brevo, for invitations, reminders and account email
  • Payments — Paystack. Card details go to them directly; we never see or store a full card number
  • AI features — [provider], where a customer enables AI survey authoring or analysis

We also disclose data where the law requires it, and to a buyer if the business is sold — in which case this notice travels with it.

6. Sending data abroad

Some of these providers operate outside Nigeria and outside the UK/EEA. Where we transfer personal data internationally we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses (GDPR Article 46) together with the safeguards NDPA section 41 requires. You can request a copy of the mechanism we rely on for a particular transfer.

7. How long we keep it

  • Account data — while your account is open, then up to 12 months after closure
  • Billing records — [6] years, to satisfy tax and accounting law
  • Survey responses — for as long as the customer who collected them keeps them; deleting a workspace removes them on our documented purge schedule
  • Security logs — [12] months

8. Your rights

Under the NDPA and the GDPR you may request access to your data, correction of it, deletion of it, restriction of or objection to processing, and a portable copy. Where we rely on consent you may withdraw it at any time without affecting what came before.

Write to privacy@thrivecoretech.com. We respond within 30 days under the NDPA and one month under the GDPR. Exercising these rights is free, and we will not treat you differently for doing so.

If you are unhappy with our response you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng), to the UK Information Commissioner's Office (ico.org.uk), or to your local EU supervisory authority.

9. Security

Traffic is encrypted in transit with TLS. Passwords are hashed with Argon2id and are never recoverable, by us or anyone else. Workspaces are isolated at the database level by row-level security, so one organization's queries cannot reach another's data. Two-factor authentication is available on every account and we recommend turning it on. No system is perfectly secure, and we will notify you and the relevant regulator of a qualifying breach within 72 hours of becoming aware of it.

10. Children

ThriveSurvey is not intended for children under 18, and we do not knowingly create accounts for them. A customer surveying minors is responsible for obtaining the consent the NDPA and GDPR require.

11. Changes

We will post any change here and update the date below. If a change materially affects your rights we will tell account holders by email before it takes effect.