- Privacy Policy →
Thanex Privacy Policy
Last Updated: 21 July 2026
1. Purpose and Scope
1.1 Thanex Ltd, referred to in this Privacy Policy as “Thanex,” “we,” “us,” or “our,” respects the privacy of every person whose personal data is processed through its website, mobile applications, cloud portal, Business Workspaces, Projects, communications, and related services.
1.2 The Policy explains how Thanex collects, receives, records, organises, stores, accesses, uses, discloses, transfers, retains, makes available for download or lawful disclosure, and deletes personal data.
1.3 The Policy applies to:
(a) the website available at https://thanex.uk;
(b) the Thanex mobile applications for compatible devices;
(c) the Thanex cloud and web applications;
(d) free and paid Accounts;
(e) Business Workspaces, Organisations, and Projects;
(f) subscription, support, marketing, and operational communications; and
(g) authorised integrations and third-party sign-in services.
1.4 Use of the Service is also governed by the Thanex Terms and Conditions. A separate Data Processing Agreement may apply where Thanex processes Project Content for a Business Customer.
2. Identity and Contact Details
2.1 Thanex Ltd is a private limited company incorporated in England and Wales under company number 16426957.
2.2 The registered office is:
Thanex Ltd
Flat 11, Mill Pond Place
1 Mill Lane
Maidstone
England
ME14 1GL
United Kingdom
2.3 Questions, rights requests, objections, and data-protection complaints may be sent to support@thanex.uk.
2.4 Thanex has not appointed a statutory Data Protection Officer because its current core activities do not, on the information presently available, require regular and systematic monitoring on a large scale or large-scale processing of special-category data. Privacy matters are supervised by Thanex’s responsible management personnel. The position will be reviewed as the Service, processing scale, and legal obligations develop.
3. Applicable Data-Protection Legislation
3.1 Thanex is established in England and principally complies with:
(a) the United Kingdom General Data Protection Regulation, referred to as the “UK GDPR”;
(b) the Data Protection Act 2018;
(c) the Privacy and Electronic Communications (EC Directive) Regulations 2003, referred to as “PECR”;
(d) the Data (Use and Access) Act 2025, to the extent that its relevant provisions have commenced; and
(e) other applicable United Kingdom privacy, communications, consumer, and electronic-commerce laws.
3.2 Where Thanex offers the Service to persons in the European Economic Area, or monitors their behaviour within the meaning of Article 3(2), Regulation (EU) 2016/679, referred to as the “EU GDPR,” may also apply. The official text is available at https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng.
3.3 Mandatory rights under applicable national law continue to apply even where they provide greater protection than the provisions described in this Policy.
4. Controller and Processor Roles
4.1 Responsibility for personal data depends on the context in which it is processed.
Thanex as Controller: Thanex generally acts as controller for Account registration, authentication administration, subscription management, billing records, website enquiries, customer support, Service security, marketing preferences, analytics configuration, legal compliance, and Thanex’s own operational records. Thanex determines why and how that data is processed.
Business Customer as Controller: A company, employer, contractor, partnership, sole trader, or other organisation ordinarily acts as controller for Project Content created or maintained within its Business Workspace. The Business Customer decides which Projects are created, who may participate, what records may be captured, how long they are required, and how they may be used.
Thanex as Processor: When Thanex stores, displays, organises, transmits, makes available for authorised viewing or downloading, or deletes Project Content according to a Business Customer’s instructions, Thanex ordinarily acts as processor under Article 28 of the UK GDPR or EU GDPR.
Individual or Pro Users: Where an individual creates and controls Projects independently rather than on behalf of another Organisation, Thanex’s role will depend on the circumstances and applicable law. Thanex may act as controller for Service administration while the User remains responsible for establishing lawful authority to capture information about other persons.
4.2 A person seeking access to, correction of, or deletion of Project Content should ordinarily contact the Organisation controlling the relevant Project. Thanex will assist the Organisation as required by law and the applicable Data Processing Agreement.
4.3 Thanex may process limited Project Content as an independent controller where necessary to investigate fraud, respond to a binding legal demand, protect the Service, establish legal claims, or comply with statutory duties. Such processing will be confined to the applicable purpose.
5. Categories of Personal Data Collected
5.1 The categories collected depend on how a person uses the Service.
Account and Identity Data: Full name, email address, Account identifier, profile information, authentication method, password credentials in protected form where email-and-password registration is used, and confirmation of Account status.
Social Sign-In Data: Where Apple, Google, or Microsoft authentication is selected, Thanex may receive a provider identifier, name, email address, authentication token, and other information authorised by the User or supplied by the provider.
Organisation and Employment Data: Company or Organisation name, job title, workplace role, team membership, invitation status, administrative permissions, Project assignments, and the relationship between a User and a Business Workspace.
Project Data: Project name, Project identifier, category, location entered by a User, assigned Users, creation date, archive status, and associated activity.
Photographs and Documents: Images and supported documents captured, submitted, or stored through the Service. Photographs may show people, workplaces, construction sites, property, equipment, vehicles, identification marks, defects, incidents, safety matters, or other information selected by the User.
Stamped and Structured Photo Data: Photographer name, date, time, Project, photograph type, job title, description, notes, tags, user-defined location, GPS coordinates where available, and a Thanex capture mark. Selected details may be permanently incorporated into the image.
Location Data: GPS coordinates supplied by the User’s device when location permission has been enabled, together with locations manually selected or entered by a User. Capture may remain available without GPS where the relevant device and application configuration permit it.
Activity and Audit Data: Account access, invitations, Project activity, captures, uploads, downloads, data-copy requests, deletions, role changes, administrative actions, notification events, and security-related records.
Device and Technical Data: Device type, operating system, application version, browser type, IP address, approximate network-derived location, language, time zone, diagnostic data, error reports, request times, session identifiers, and security logs.
Subscription and Transaction Data: Selected plan, billing period, number of Users, storage allowance, subscription status, renewal date, currency, tax information, payment-provider reference, invoices, payment status, and limited card information such as card type or final digits where supplied by the payment provider. Thanex does not ordinarily receive or store complete payment-card credentials.
Support and Communications Data: Emails, support requests, complaint details, correspondence, attachments, call notes where applicable, survey responses, and information supplied when a person contacts Thanex.
Marketing and Preference Data: Newsletter registration, marketing consent, communication preferences, campaign engagement, unsubscribe status, and records required to respect an objection or withdrawal.
Website and Analytics Data: Pages viewed, referral source, interactions, device information, session information, campaign attribution, and cookie or similar-technology identifiers where analytics consent has been granted.
5.2 Thanex does not intentionally request criminal-offence data or special-category data, including health, biometric, political, religious, trade-union, sexual-orientation, or racial and ethnic information. Project photographs may nevertheless contain such information because of what a User chooses to capture.
5.3 Business Customers must determine whether special-category or criminal-offence information may appear in their Projects and, if so, identify an appropriate legal condition under Article 9 of the UK GDPR, Schedule 1 to the Data Protection Act 2018, or other applicable legislation.
6. Sources of Personal Data
6.1 Personal data may be obtained:
(a) directly from the person who registers, subscribes, contacts Thanex, or uses the Service;
(b) from an Organisation that invites, registers, or administers a User;
(c) from another authorised User who captures or annotates Project Content;
(d) from Apple, Google, or Microsoft when social sign-in is used;
(e) from Stripe in connection with Subscription payments, invoices, refunds, and payment-security checks;
(f) automatically from a device, browser, application, server, cookie, software development kit, or security system;
(g) from analytics, email, hosting, notification, and infrastructure providers; and
(h) from public authorities, professional advisers, counterparties, or public records where required for legal, security, or dispute purposes.
6.2 An Organisation may provide a User’s name, email address, job title, role, or Project assignment before that User has registered. Thanex uses that information to issue the invitation, administer authorised access, and maintain the Organisation’s records.
7. Purposes and Lawful Bases
7.1 Article 6 of the UK GDPR and, where applicable, the EU GDPR requires a lawful basis for processing.
Account Creation and Authentication: Account information is processed to enter into and perform the Service contract, administer registration, verify sign-in attempts, and provide authorised access. Article 6(1)(b) applies. Security-related authentication may also rely on Thanex’s legitimate interests under Article 6(1)(f).
Service Delivery: Names, Projects, photographs, notes, locations, timestamps, roles, and activity information are processed to capture, store, organise, retrieve, display, share, and make Project records available for authorised viewing or downloading. Thanex relies on Article 6(1)(b) for its direct contractual relationship with a User. Where Thanex acts as processor, the Business Customer determines the applicable lawful basis.
Business Workspace Administration: Invitations, membership, permissions, role assignments, and ownership records are processed to operate team access and preserve the Business Customer’s control over its records. The applicable bases are contractual necessity and legitimate interests in administering secure business services.
Location Functions: GPS data is processed to associate a capture with a location when the device supplies the information. Device permission permits technical access but does not, by itself, determine the legal basis under data-protection law. The relevant Organisation must establish its lawful basis for workplace location processing.
Billing and Subscriptions: Plan, transaction, invoice, and payment-reference data is processed to collect fees, administer renewals, prevent payment fraud, maintain accounts, and meet tax obligations. Article 6(1)(b), Article 6(1)(c), and Article 6(1)(f) may apply according to the activity.
Service Notifications: Operational emails and push notifications may be sent for invitations, Project activity, security events, billing, material policy changes, and Account administration. Such communications are based on contractual necessity or legitimate interests. Device-level notification permission may be withdrawn through device settings.
Customer Support: Contact details, correspondence, and diagnostic information are processed to answer enquiries, investigate faults, resolve complaints, and maintain service quality. Contractual necessity and legitimate interests apply.
Security and Abuse Prevention: Technical records, IP addresses, authentication events, and audit logs may be examined to detect unauthorised access, malicious activity, fraud, or Terms violations. Thanex relies on legitimate interests and, where relevant, legal obligations.
Legal and Regulatory Compliance: Information may be processed to comply with tax, accounting, court, law-enforcement, data-protection, consumer, and corporate requirements. Article 6(1)(c) applies. Legal-claim processing may also rely on Article 6(1)(f).
Product Measurement and Analytics: Consent-based analytics may be used to understand website and application usage, measure campaigns, diagnose performance, and guide service development. Non-essential cookies and similar technologies will be activated only where valid consent or another lawful PECR exception applies.
Marketing: Email newsletters and promotional communications may be sent with consent or, where legally permitted, under the existing-customer exception in regulation 22 of PECR. Every marketing email will offer an unsubscribe method. Withdrawal does not affect processing lawfully undertaken before withdrawal.
7.2 Legitimate interests are used only after considering the purpose, necessity, and potential effect on individuals. A person may object to processing based on Article 6(1)(f), as explained in Section 15.
8. Photographs, Notes, Timestamps, and GPS Data
8.1 Photographs may be combined with selected Project information when captured. Where details are stamped into the image, they become part of the stored file and may not be independently editable.
8.2 A structured copy of relevant information may also be stored in the Thanex database to support searching, filtering, display, permissions, attribution, and authorised access.
8.3 Device-camera access is required for core capture functionality. Location permission is optional unless an Organisation makes location collection part of its internal work procedure. Users can alter location permission through device settings.
8.4 Thanex does not ordinarily read or import a User’s existing personal photograph library. Where the application offers a save-to-device function, access may be limited to writing the selected file to the device gallery.
8.5 Responsibility for deciding whether a photograph may lawfully be taken rests with the User and controlling Organisation. Business Customers should inform workers, visitors, contractors, clients, and other affected persons where photography or location recording is undertaken.
9. Automated Decision-Making
9.1 Thanex does not presently make decisions producing legal effects, or similarly significant effects, solely through automated processing within the meaning of Article 22 of the UK GDPR or EU GDPR.
9.2 Analytics, security signals, search tools, categorisation, and automated technical checks may assist human decisions or Service operation. They are not intended to determine employment rights, creditworthiness, legal status, or comparable matters without meaningful human involvement.
10. Sharing and Recipients
10.1 Personal data may be disclosed to the following recipients where necessary:
Organisation Members: Owners, Administrators, and authorised Members may access Project Content according to assigned permissions.
Cloud and Infrastructure Providers: Amazon Web Services, including Amazon S3, may host photographs, documents, databases, backups, logs, or supporting infrastructure according to Thanex’s selected configuration.
Authentication Providers: Apple, Google, and Microsoft support sign-in where selected by the User.
Payment Provider: Stripe processes Subscription payments, renewals, refunds, billing details, payment authentication, and fraud checks for purchases made through the Thanex website or web application. Apple, Google, and Microsoft support authentication only and do not process Thanex Subscription payments.
Analytics Providers: Google Analytics may process consent-based website or application usage information where enabled.
Marketing Providers: Mailchimp may process names, email addresses, consent records, campaign activity, and unsubscribe preferences for authorised marketing communications.
Notification and Communication Providers: Contracted email, transactional-messaging, and push-notification suppliers may process the minimum information required to deliver communications.
Professional Advisers: Lawyers, accountants, auditors, insurers, and consultants may receive information where necessary and subject to professional or contractual confidentiality.
Authorities and Courts: Personal data may be disclosed where required by law, court order, regulatory demand, or a valid law-enforcement request.
Corporate Transactions: Prospective purchasers, investors, lenders, and professional advisers may receive limited information during financing, restructuring, merger, or sale discussions, subject to confidentiality and lawful safeguards.
10.2 Thanex does not sell personal data. Personal data is not disclosed to unrelated third parties for their independent advertising merely in exchange for payment.
10.3 Service providers are appointed under contracts requiring confidentiality, security, purpose limitation, and data-protection compliance where Article 28 applies.
11. International Transfers
11.1 Thanex is established in the United Kingdom, but certain suppliers may process data in the United States, the European Economic Area, or other countries.
11.2 A restricted transfer will be made only where a lawful transfer mechanism is available. Depending on the destination and provider, Thanex may rely on:
(a) United Kingdom adequacy regulations;
(b) an adequacy decision adopted under Article 45 of the EU GDPR;
(c) the United Kingdom International Data Transfer Agreement;
(d) the United Kingdom Addendum to the European Commission’s Standard Contractual Clauses;
(e) the European Commission’s Standard Contractual Clauses;
(f) the UK Extension to the EU-US Data Privacy Framework, where the United States recipient holds a valid certification covering the relevant data; or
(g) a limited statutory derogation where legally permitted.
11.3 Transfer-risk assessments and supplementary contractual, organisational, or technical measures will be applied where required. Further information about a relevant transfer safeguard may be requested through support@thanex.uk, subject to protection of confidential and security-sensitive terms.
12. Retention Periods
12.1 Personal data is retained only for as long as reasonably required for the applicable purpose, contractual obligation, legal duty, security requirement, or legal claim.
Account Data: Account information is normally retained while the Account remains active. Following final confirmation of Account deletion, access is revoked immediately, and relevant Account data is removed or irreversibly anonymised from active Account systems within 30 days, except where continued retention is legally required or permitted.
Organisation-Controlled Project Content: Deletion of an individual Account does not delete Project Content controlled by an Organisation. Such content remains available while the Organisation lawfully retains it or until the Organisation is permanently deleted by its Owner.
Deleted Account, Pro-Project, and Organisation Data: Data subject to confirmed permanent deletion may remain in a controlled active-system deletion queue for up to 30 days. Residual protected copies may remain in routine backups until the relevant backup is overwritten or expires and will not be restored or used for ordinary Service purposes.
Business Attribution Records: A deleted User’s name, role, timestamp, location, note, or activity may remain attached to Organisation records or incorporated into photographs where necessary to preserve the integrity of workplace documentation and where the Organisation has a lawful retention basis.
Billing and Tax Records: Invoices, payment references, and accounting records may be retained for up to six years after the end of the relevant accounting period, or longer where required by tax law, audit, or an active dispute.
Security Logs: Authentication, device, and security-event logs are normally retained for a limited period proportionate to fraud prevention, incident investigation, and system security.
Support Records: Support correspondence may be retained for the period needed to resolve the matter and establish the history of the request, after which it will be deleted or anonymised unless required for a claim.
Marketing Records: Marketing contact data is retained until consent is withdrawn, an objection is made, or the data is no longer required. A minimal suppression record may be retained to ensure that an unsubscribed address is not added again inadvertently.
Analytics Data: Analytics information is retained according to the period configured within the relevant analytics service and disclosed through the Cookie Policy or consent interface.
12.2 Legal holds, litigation, regulatory investigations, fraud enquiries, or binding preservation duties may extend an otherwise applicable retention period.
13. Data Downloads, Account Deletion, and Organisation Deletion
13.1 Thanex does not presently provide a bulk Project-export function. Authorised Users may view and download photographs through the available web or mobile functions and may download any other files expressly made available by the Service. Requests for access to, or portability of, qualifying personal data may be submitted to support@thanex.uk.
13.2 Account deletion may be initiated through the available in-app or web function. Thanex may require reauthentication or a one-time confirmation code sent to the email address associated with the Account.
13.3 Following final confirmation, the User’s access to all Organisations and Projects is revoked immediately. Account information controlled by Thanex will be removed or irreversibly anonymised from active systems within 30 days, except where continued retention is legally permitted or required. Any personal Subscription will be cancelled. Project Content controlled solely by an individual Pro User will enter the applicable deletion process.
13.4 Deleting an individual Account does not delete Project Content controlled by an Organisation. Photographs, notes, timestamps, locations, activity records, and other workplace records previously created by the User may remain available to authorised Organisation members. The User’s name, role, and other attribution may remain where incorporated into a photograph or required to preserve a lawful business record.
13.5 An Owner cannot delete the Owner’s individual Account while the Account remains the Owner of an Organisation. Ownership must first be transferred to another eligible Member, or the Owner must permanently delete the Organisation through the separate Organisation-deletion process.
13.6 Organisation deletion may be initiated only by its Owner and may require a one-time confirmation code. Confirmed deletion removes the Organisation, Projects, photographs, supported documents, notes, settings, memberships, and operational records. Every Member’s access to the Organisation is removed, but individual Member Accounts remain available unless separately deleted.
13.7 Account or Organisation deletion cannot be reversed by the User after final confirmation. Data may remain in a controlled deletion queue for up to 30 days, and residual copies may remain temporarily in backups until overwritten or deleted under the established backup cycle. Limited billing, tax, accounting, fraud-prevention, security, complaint, dispute, and legal-claim records may be retained where required or permitted by law.
14. Security Measures
14.1 Thanex applies technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
14.2 Measures may include encrypted network transmission, cloud-access controls, role-based permissions, protected credentials, logging, provider due diligence, backup controls, software maintenance, access reviews, and incident-response procedures.
14.3 No internet-based service can provide an absolute security guarantee. Users must maintain secure credentials, protect their devices, install relevant updates, use available access controls, and report suspected compromise promptly.
14.4 A personal-data breach will be assessed under Articles 33 and 34 of the UK GDPR or EU GDPR. Where notification is legally required, Thanex will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach. Affected individuals will be informed where the breach is likely to create a high risk to their rights and freedoms.
15. Individual Rights
15.1 Subject to legal conditions and exemptions, individuals may exercise the following rights:
Right of Access: A person may request confirmation of processing and a copy of personal data.
Right to Rectification: Inaccurate personal data may be corrected, and incomplete data may be completed.
Right to Erasure: Deletion may be requested where the data is no longer necessary, consent has been withdrawn, processing is unlawful, or another statutory ground applies.
Right to Restriction: Processing may be restricted while accuracy, lawfulness, an objection, or another qualifying issue is examined.
Right to Data Portability: Data supplied by the individual may be requested in a structured, commonly used, and machine-readable format where processing is automated and based on consent or contract.
Right to Object: A person may object to processing based on legitimate interests. Objections to direct marketing will be honoured without requiring reasons.
Right to Withdraw Consent: Consent may be withdrawn at any time without affecting earlier lawful processing.
Rights Concerning Automated Decisions: A person may request safeguards where a qualifying solely automated decision produces legal or similarly significant effects.
Right to Complain: A person may complain directly to Thanex and may also contact the competent supervisory authority.
15.2 Requests may be sent to support@thanex.uk. Identity and authority may be verified before information is disclosed or changed.
15.3 Thanex will normally respond without undue delay and within one month after receiving a valid request. A lawful extension may be used for complex or numerous requests, with notice explaining the reason.
15.4 Requests are ordinarily free of charge. A reasonable fee may be charged, or action may be refused, where a request is manifestly unfounded or excessive, as permitted by law.
15.5 Rights concerning Project Content should initially be directed to the relevant Organisation. When acting as processor, Thanex will not independently alter the Organisation’s records unless instructed or legally required.
16. Complaints and Supervisory Authorities
16.1 A data-protection complaint may be sent to support@thanex.uk. The complaint should identify the relevant Account, Project, conduct, date, and requested outcome.
16.2 In accordance with section 164A of the Data Protection Act 2018, as inserted by section 103 of the Data (Use and Access) Act 2025, Thanex will acknowledge a qualifying complaint within 30 days, take appropriate steps to investigate it, and communicate the outcome without undue delay.
16.3 United Kingdom complaints may also be submitted to the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113.
16.4 Persons in the European Economic Area may complain to the supervisory authority in the Member State of their habitual residence, place of work, or the alleged infringement.
17. Cookies, Analytics, and Similar Technologies
17.1 Thanex may use cookies, local storage, software development kits, pixels, and comparable technologies for authentication, security, preference storage, analytics, and marketing measurement.
17.2 Strictly necessary technologies may operate without consent where permitted because they are required to provide a requested service, protect an Account, maintain a session, remember privacy choices, or complete a transaction.
17.3 Google Analytics and other non-essential measurement or advertising technologies will not be activated for a United Kingdom or European visitor unless the required consent has been obtained or a specific statutory exception applies.
17.4 Consent may be withdrawn or changed through the cookie-preference tool where available. Browser settings can also block or delete cookies, although doing so may affect Service functionality.
17.5 Further details concerning cookie names, providers, purposes, and durations should be read in the Thanex Cookie Policy.
18. Marketing and Mailchimp
18.1 Thanex may use Mailchimp to manage newsletters, product announcements, early-access communications, and other authorised marketing.
18.2 Marketing records may include a name, email address, consent source, consent time, campaign activity, and unsubscribe status.
18.3 Every recipient may unsubscribe by selecting the link contained in a marketing email or by contacting support@thanex.uk.
18.4 Transactional messages concerning security, billing, Account administration, or material Service changes are not marketing and may continue after a marketing opt-out where necessary to perform the contract or comply with law.
19. Children
19.1 The Service is intended for professional workplace use by persons aged 18 or older. Thanex does not knowingly permit children to create Accounts.
19.2 A parent, guardian, or other person who believes that a child has supplied personal data should contact support@thanex.uk. Appropriate investigation and deletion steps will be taken, subject to any lawful need to preserve evidence or protect the child.
20. Changes to the Privacy Policy
20.1 Thanex may amend the Policy to reflect legal developments, provider changes, new features, revised data practices, or security requirements.
20.2 Material amendments will be notified through the Service, by email, or by another appropriate method before taking effect where required. The date displayed at the beginning identifies the latest revision.
20.3 Earlier versions may be retained for compliance and dispute purposes.
21. Contact
All privacy enquiries, rights requests, withdrawal notices, and complaints should be directed to:
Thanex Ltd
Flat 11, Mill Pond Place
1 Mill Lane
Maidstone
England
ME14 1GL
United Kingdom
Email: support@thanex.uk
Website: https://thanex.uk
Company number: 16426957.