Thanex Data Protection and Data Management Policy

Last Updated: 21 July 2026

1. Policy Status and Purpose

1.1 The Data Protection and Data Management Policy, referred to as the “Policy,” establishes the principles, governance requirements, technical controls, organisational measures, and operational procedures applied by Thanex Ltd to personal data and other information processed through the Thanex Service.

1.2 Thanex Ltd, referred to as “Thanex,” “we,” “us,” or “our,” is a private limited company incorporated in England and Wales under company number 16426957. Its registered office is at Flat 11, Mill Pond Place, 1 Mill Lane, Maidstone, England, ME14 1GL, United Kingdom.

1.3 The Policy supports the Thanex Privacy Policy, Terms and Conditions, applicable Data Processing Agreements, provider contracts, and internal security procedures. Where a written Business-Customer agreement imposes a higher data-protection standard, the higher standard will apply to the relevant processing.

1.4 The Policy is intended to:

(a) establish responsibility for personal data and Business Workspace records;

(b) describe the data-management lifecycle applied by Thanex;

(c) define access, storage, retention, downloading, data-copy requests, deletion, security, and incident-management requirements;

(d) explain the relationship between Thanex and its Business Customers;

(e) maintain the confidentiality, integrity, availability, and resilience of the Service; and

(f) demonstrate compliance with applicable data-protection legislation.

1.5 Questions concerning the Policy may be sent to support@thanex.uk.

 

2. Scope

2.1 The Policy applies to personal data, Project Content, Business Workspace records, technical data, and confidential information processed through:

(a) https://thanex.uk;

(b) the Thanex mobile applications;

(c) the Thanex web and cloud applications;

(d) free, Pro, and Business Accounts;

(e) Organisations, Business Workspaces, Projects, and team-management functions;

(f) cloud storage, databases, authentication services, analytics, email, marketing, billing, and notification systems;

(g) customer-support and complaint-management processes; and

(h) backups, audit records, downloads, rights-request disclosures, and deletion procedures.

2.2 Directors, employees, contractors, advisers, and suppliers with authorised access to Thanex information must comply with the parts of the Policy relevant to their functions.

2.3 Business Customers remain responsible for their own internal data-protection procedures, lawful bases, privacy notices, staff instructions, workplace-monitoring decisions, and record-retention requirements.

 

3. Legal Framework

3.1 Thanex manages personal data in accordance with:

(a) the United Kingdom General Data Protection Regulation, referred to as the “UK GDPR”;

(b) the Data Protection Act 2018;

(c) the Privacy and Electronic Communications (EC Directive) Regulations 2003, referred to as “PECR”;

(d) the Data (Use and Access) Act 2025, where its relevant provisions have commenced;

(e) Regulation (EU) 2016/679, referred to as the “EU GDPR,” where applicable to persons in the European Economic Area; and

(f) other applicable confidentiality, employment, communications, consumer, and electronic-commerce requirements.

3.2 Article 5 of the UK GDPR establishes the governing data-protection principles. Thanex must process personal data lawfully, fairly, and transparently; collect it for specified and legitimate purposes; limit collection to what is adequate and necessary; maintain accuracy; restrict retention; apply appropriate security; and demonstrate accountability.

3.3 Personal data must not be processed merely because it is technically possible to collect or retain it. Every material processing activity must have an identified purpose, lawful basis, responsible owner, retention approach, and security classification.

 

4. Definitions

4.1 The following definitions apply:

Business Customer: An organisation, employer, contractor, partnership, sole trader, or other legal or commercial person that controls a Thanex Organisation or Business Workspace.

Business Workspace: The controlled environment through which authorised Users create Projects, assign roles, capture records, manage members, and access Project Content.

Controller: The person that determines the purposes and means of processing personal data.

Data Subject: An identified or identifiable living individual to whom personal data relates.

Personal Data: Information relating to an identified or identifiable living individual, including names, email addresses, photographs, job titles, online identifiers, timestamps, notes, and location data.

Personal-Data Breach: A security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

Processor: A person that processes personal data on behalf of a controller.

Project Content: Photographs, supported documents, Project names, company names, Users, roles, timestamps, notes, tags, descriptions, user-defined locations, GPS coordinates, and associated Business Workspace records.

Special-Category Data: Personal data described in Article 9 of the UK GDPR, including information concerning health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric identification, sex life, or sexual orientation.

Subprocessor: A supplier appointed by Thanex to process personal data on behalf of a Business Customer.

 

5. Governance and Responsibility

5.1 Thanex’s directors retain ultimate responsibility for data-protection governance, adequate resources, legal compliance, risk management, and approval of material changes to processing activities.

5.2 A responsible member of Thanex management will supervise:

(a) privacy and data-protection enquiries;

(b) data-subject requests;

(c) provider assessments;

(d) data-protection impact assessments;

(e) security-incident escalation;

(f) retention and deletion reviews;

(g) processing records; and

(h) updates to privacy and contractual documentation.

5.3 A statutory Data Protection Officer has not presently been appointed because Thanex’s current core activities do not, on the information available, involve large-scale special-category processing or large-scale regular and systematic monitoring requiring an appointment under Article 37 of the UK GDPR.

5.4 The need for a Data Protection Officer will be reviewed where the nature, volume, sensitivity, territorial reach, or regularity of processing changes.

5.5 Personnel may access personal data only where access is necessary for an authorised business function. Access for personal curiosity, unrelated commercial purposes, or unauthorised disclosure is prohibited.

 

6. Allocation of Controller and Processor Roles

6.1 Thanex generally acts as controller for:

(a) Account creation and administration;

(b) authentication management;

(c) subscription and billing administration;

(d) customer support and complaints;

(e) Service-security records;

(f) Thanex marketing and communication preferences;

(g) website analytics configuration;

(h) corporate, tax, and accounting records; and

(i) Thanex’s own legal and operational requirements.

6.2 A Business Customer ordinarily acts as controller for Project Content processed within its Business Workspace. The Business Customer decides:

(a) which Projects are created;

(b) which Users are invited;

(c) which roles and permissions are assigned;

(d) what may be photographed or documented;

(e) whether GPS location should be collected;

(f) how Project Content may be used;

(g) who may view, download, or receive a copy of Project Content; and

(h) how long its business records should be retained.

6.3 Thanex ordinarily acts as processor when it stores, organises, displays, transmits, makes available for authorised viewing or downloading, backs up, or deletes Project Content on the documented instructions of a Business Customer.

6.4 Processing undertaken for a Business Customer must be governed by Article 28 of the UK GDPR or EU GDPR. The applicable terms must address the subject matter, duration, nature, purpose, personal-data categories, data-subject categories, confidentiality, security, subprocessors, rights assistance, breach assistance, deletion, audit information, and termination procedures.

6.5 Thanex may act as an independent controller for limited processing required to protect the Service, investigate unlawful activity, comply with a binding legal requirement, or establish, exercise, or defend legal claims.

 

7. Data Inventory and Records of Processing

7.1 Thanex will maintain records appropriate to the nature and scale of its processing.

7.2 Records of Processing Activities maintained under Article 30 will identify, where applicable:

(a) the controller or processor role;

(b) the responsible business function;

(c) the purpose and lawful basis;

(d) categories of personal data and Data Subjects;

(e) recipients and subprocessors;

(f) international-transfer locations and safeguards;

(g) retention periods or criteria;

(h) security measures; and

(i) links to relevant contracts, assessments, and notices.

7.3 New systems, providers, data fields, integrations, and material product features must be entered into the relevant processing inventory before, or as part of, production implementation.

7.4 Data-flow mapping may be used to record how information moves from capture or registration through authentication, databases, cloud storage, web display, mobile access, downloading, rights-request disclosure, backup, and deletion.

 

8. Data Classification

8.1 Information must be handled according to its sensitivity and operational significance.

Public Information: Information lawfully intended for public release, including general website content and published product information.

Internal Information: Routine operational information not intended for public distribution but unlikely to cause material harm if disclosed.

Confidential Information: Customer information, commercial records, support correspondence, internal documentation, contracts, and non-public product information.

Restricted Information: Personal data, authentication records, payment references, security configurations, GPS coordinates, Project photographs, sensitive workplace records, and any special-category or criminal-offence data.

8.2 Restricted Information requires controlled access, appropriate transmission protection, limited disclosure, and documented deletion or retention arrangements.

8.3 Classification must account for context. A photograph that appears routine may become highly sensitive when combined with a precise location, timestamp, worker name, access credential, safety incident, or confidential Project description.

 

9. Data Collection and Minimisation

9.1 Collection must be limited to information reasonably required for a defined Service or legal purpose.

9.2 Account registration ordinarily requires a name, email address, authentication information, and any Organisation details necessary to establish access.

9.3 Project capture may involve photographs, notes, categories, timestamps, job titles, user-defined locations, and GPS coordinates. Business Customers should configure Project practices so that unnecessary personal information is not included.

9.4 Users should avoid capturing:

(a) persons unrelated to the work activity;

(b) private residential areas without authority;

(c) identification documents unless operationally required;

(d) payment-card information;

(e) passwords, access codes, or security credentials;

(f) health or medical information unless a lawful condition has been established; and

(g) information unrelated to the stated Project purpose.

9.5 A new mandatory field must not be introduced without assessing its purpose, necessity, lawful basis, retention effect, and impact on Data Subjects.

 

10. Lawful Processing and Purpose Control

10.1 Thanex must identify a lawful basis under Article 6 before processing personal data as controller.

10.2 Depending on the activity, the basis may be:

(a) performance of a contract;

(b) compliance with a legal obligation;

(c) consent;

(d) protection of vital interests in exceptional circumstances;

(e) performance of a qualifying public task, where applicable; or

(f) legitimate interests following an appropriate balancing assessment.

10.3 Special-category data requires both an Article 6 basis and a condition under Article 9. Where United Kingdom law requires an additional condition or Appropriate Policy Document under Schedule 1 to the Data Protection Act 2018, the relevant controller must satisfy that requirement.

10.4 Personal data collected for one purpose must not be used for a materially incompatible purpose without completing a compatibility assessment, identifying a new lawful basis where required, and updating the relevant privacy information.

10.5 Business Customers may not instruct Thanex to process Project Content unlawfully. Where an instruction appears to breach data-protection law, Thanex may suspend the affected processing while seeking clarification.

 

11. Privacy by Design and Data Protection Impact Assessments

11.1 Data-protection considerations must be incorporated into material product, infrastructure, and provider decisions from the design stage.

11.2 Product reviews should consider:

(a) the minimum data required;

(b) default visibility and permissions;

(c) location-data controls;

(d) role-based access;

(e) download, data-access, and deletion functions;

(f) retention settings;

(g) security and authentication;

(h) transparency to affected persons; and

(i) risks created by combining data fields.

11.3 A Data Protection Impact Assessment, referred to as a “DPIA,” must be undertaken where proposed processing is likely to result in a high risk to individuals, as required by Article 35.

11.4 A DPIA may be required for systematic workplace monitoring, extensive location tracking, new uses of sensitive photographic information, large-scale special-category processing, significant automated evaluation, or the combination of datasets in a manner creating high risk.

11.5 The assessment must describe the processing, examine necessity and proportionality, identify risks, record intended controls, and determine whether residual high risk remains.

11.6 Where high risk cannot be sufficiently reduced, the competent supervisory authority must be consulted before processing begins, as required by Article 36.

 

12. Access Control and Authentication

12.1 Access must follow the least-privilege principle. Each person should receive only the permissions required for authorised duties.

12.2 Thanex may support Owner, Administrator, and Member roles. Available permissions may include Project creation, content access, member administration, viewing and downloading Project Content, invalidation, deletion, billing management, and ownership transfer.

12.3 Account credentials must be personal and must not be shared. Passwords managed directly by Thanex must be stored using suitable protected methods rather than readable plain text.

12.4 Social sign-in may be provided through Apple, Google, or Microsoft. Tokens and provider identifiers must be handled according to applicable security requirements.

12.5 Access rights should be reviewed following role changes, suspected compromise, termination of employment, contractor departure, or an Organisation’s request.

12.6 Administrative access by Thanex personnel must be limited, recorded where appropriate, and used only for support, security, maintenance, legal compliance, or another authorised purpose.

 

13. Storage, Hosting, and Transmission

13.1 Project photographs and supported documents may be stored through Amazon Web Services, including Amazon S3. Associated structured information may be stored in databases used to support search, filtering, display, attribution, permissions, authorised access, and data-subject requests.

13.2 Network transmission must use appropriate encrypted communication methods where supported by the applicable system.

13.3 Storage configurations must be reviewed with regard to public-access prevention, identity and access management, credential protection, logging, backup, deletion, and region selection.

13.4 Project Content must not be intentionally exposed through publicly accessible storage unless the controlling Organisation has authorised public disclosure and appropriate safeguards have been applied.

13.5 Production personal data should not be copied into test or development environments unless the use is necessary, authorised, protected, and proportionate. Synthetic, anonymised, or appropriately de-identified data should be used where practicable.

 

14. Accuracy and Record Integrity

14.1 Thanex must take reasonable measures to maintain accurate Account, billing, and operational information.

14.2 Users and Business Customers are responsible for checking names, Project assignments, job titles, notes, categories, manually entered locations, and other information they supply.

14.3 Information stamped into a photograph may form part of the image and may not be independently editable after capture. Corrections may therefore require an explanatory record, a replacement capture, or invalidation of the earlier record rather than alteration of the original file.

14.4 Audit and attribution information should not be altered merely to remove evidence of an authorised action. Corrections must preserve record integrity where the Business Customer requires an accurate work history.

 

15. Data Retention

15.1 Retention must be based on purpose, legal obligations, contractual needs, security requirements, limitation periods, and the controlling Organisation’s documented instructions.

15.2 Retention categories include:

Active Account Data: Retained while the Account remains active. Following final confirmation of Account deletion, access is revoked immediately, and relevant Account data is removed or irreversibly anonymised from active systems within 30 days, except where continued retention is legally required or permitted.

Organisation-Controlled Project Content: Retained while the relevant Organisation or Project remains active and according to the Business Customer’s lawful retention instructions. Deletion of an individual Account does not delete Project Content controlled by an Organisation.

Deleted Account, Pro-Project, and Organisation Data: Operational data subject to confirmed permanent deletion may remain in a controlled active-system deletion queue for up to 30 days.

Backup Copies: Residual copies may remain in routine backups until the relevant backup is overwritten, expires, or is securely destroyed under the applicable backup cycle. Deleted data retained solely in backups must be placed beyond ordinary use and must not be restored except where required for a genuine disaster-recovery process.

Billing and Tax Records: Retained for up to six years after the relevant accounting period, or for a longer period where required by law, audit, or legal proceedings.

Security Records: Retained for a period proportionate to detecting abuse, investigating incidents, and protecting Accounts and systems.

Support and Complaint Records: Retained for the time required to resolve the matter and establish an appropriate record of the response.

Marketing Records: Retained until consent is withdrawn, an objection is received, or the information is no longer required. A minimal suppression record may be kept to honour an unsubscribe request.

15.3 Records must not be retained indefinitely without an identified reason. Periodic reviews should identify obsolete, duplicated, expired, or unsupported information.

15.4 A legal hold, regulatory investigation, payment dispute, fraud enquiry, or anticipated claim may suspend ordinary deletion until the relevant requirement ends.

 

16. Download, Portability, and Business Continuity

16.1 Thanex does not presently provide a bulk Project-export function. Authorised Users may view and download photographs through the available web or mobile functions and may download any other files expressly made available by the Service.

16.2 Business Customers should download and retain any required photographs or other available files before closing a Project, deleting an Organisation, or allowing paid access to expire.

16.3 A Data Subject may request access to, or a portable copy of, qualifying personal data by contacting support@thanex.uk. Identity, role, authority, third-party rights, and applicable legal conditions may be verified before a substantial or sensitive copy is released.

16.4 Thanex may maintain backup and recovery arrangements appropriate to the Service’s risk profile. Backups are intended for operational recovery and are not a substitute for a Business Customer’s own records-management obligations.

16.5 Recovery procedures should consider service restoration, data integrity, provider availability, credential recovery, communication responsibilities, and the order in which critical systems are restored.

 

17. Deletion and Disposal

17.1 Account and Organisation deletion must be initiated only by an authorised person through an approved function or documented process. Thanex may require reauthentication, a one-time confirmation code, or proportionate evidence of authority.

17.2 Deletion may involve:

(a) revocation of Account, Organisation, and Project access;

(b) removal from active databases;

(c) deletion of stored photographs, supported documents, and structured records;

(d) irreversible anonymisation where appropriate;

(e) cancellation of authentication tokens and active sessions;

(f) expiry from backup systems; and(g) removal of provider-held copies according to contractual instructions.

17.3 Following final confirmation of individual Account deletion, access to all Organisations and Projects must be revoked immediately. Account information controlled by Thanex must be deleted or irreversibly anonymised from active systems within 30 days, except where retention is legally required or permitted. Any personal Subscription must be cancelled, and Project Content controlled solely through an individual Pro Account must enter the applicable deletion process.

17.4 Deletion of an individual Account does not delete Project Content controlled by an Organisation. Names, roles, timestamps, locations, notes, and attribution may remain where incorporated into a photograph or required to preserve a lawful Organisation record.

17.5 An Owner must not be permitted to delete an individual Account while remaining the Owner of an Organisation. Ownership must first be transferred to another eligible Member, or the Owner must permanently delete the Organisation.

17.6 Organisation deletion must be initiated by the Owner and must remove the Organisation, its Projects, photographs, supported documents, records, settings, memberships, and operational data. Every Member’s access to that Organisation must be removed, but the Member’s individual Thanex Account must not be deleted solely because the Organisation is deleted.

17.7 Account and Organisation deletion becomes irreversible for the User after final confirmation. Operational data may remain in a controlled deletion queue for up to 30 days. Residual backup copies may remain until overwritten or deleted under the established backup cycle and must be placed beyond ordinary use.

17.8 Data required for billing, tax, accounting, security, fraud prevention, complaints, disputes, regulatory compliance, or legal claims may be retained notwithstanding an Account or Organisation deletion request.

17.9 Physical media containing Restricted Information must be securely destroyed or rendered unreadable before disposal.

 

18. Suppliers and Subprocessors

18.1 Providers may support hosting, storage, databases, authentication, payments, analytics, marketing, email, and notifications.

18.2 Relevant providers may include:

(a) Amazon Web Services, including Amazon S3;

(b) Apple, Google, and Microsoft for authentication;

(c) Stripe for Subscription payments, renewals, refunds, billing administration, and payment-security checks;

(d) Google Analytics for consent-based measurement;

(e) Mailchimp for authorised marketing communications; and

(f) contracted transactional-email and push-notification providers.

18.3 Before appointing a provider that will process personal data, Thanex should assess:

(a) the service and data involved;

(b) the provider’s security information;

(c) processing and storage locations;

(d) confidentiality commitments;

(e) breach-notification terms;

(f) deletion and return obligations;

(g) international-transfer arrangements;

(h) subprocessor controls; and

(i) audit or assurance information.

18.4 Subprocessors processing Project Content must be appointed under written terms consistent with Article 28. Thanex remains responsible to the Business Customer for the subprocessor’s performance of applicable data-protection obligations.

 

19. International Data Transfers

19.1 Personal data may be processed outside the United Kingdom where a provider, support function, or infrastructure location is situated abroad.

19.2 Restricted transfers must use a lawful mechanism, which may include:

(a) United Kingdom adequacy regulations;

(b) an adequacy decision under the EU GDPR;

(c) the United Kingdom International Data Transfer Agreement;

 

(d) the United Kingdom Addendum to the European Commission’s Standard Contractual Clauses;

(e) the European Commission’s Standard Contractual Clauses;

(f) the UK Extension to the EU-US Data Privacy Framework for an eligible certified recipient; or

(g) a limited statutory derogation where its conditions are met.

19.3 Transfer-risk assessments and supplementary safeguards must be considered where required by applicable law and the nature of the data.

19.4 Government or law-enforcement requests for personal data must be reviewed for legal validity, scope, jurisdiction, and disclosure restrictions before information is released, unless law prohibits such review or notice.

 

20. Data-Subject Rights

20.1 Requests for access, correction, erasure, restriction, portability, objection, consent withdrawal, or review of qualifying automated decisions may be sent to support@thanex.uk.

20.2 Thanex must:

(a) record the date and scope of the request;

(b) verify identity and authority proportionately;

(c) determine whether Thanex acts as controller or processor;

(d) search relevant systems;

(e) consult the controlling Business Customer where required;

(f) review third-party rights and legal exemptions;

(g) respond within the statutory period; and

(h) document the outcome.

20.3 Controller requests will ordinarily be completed without undue delay and within one month. A lawful extension may be applied where a request is complex or numerous, with notice to the requester.

20.4 Where Thanex acts as processor, the request must be referred to the relevant Business Customer, and Thanex will provide reasonable assistance according to Article 28 and the applicable Data Processing Agreement.

 

 

21. Personal-Data Breach Management

21.1 Any suspected loss, unauthorised access, disclosure, alteration, mistaken transmission, credential compromise, malicious activity, or unlawful deletion must be reported internally without delay.

21.2 Incident response must include, as appropriate:

(a) containment of the event;

(b) preservation of relevant evidence;

(c) identification of affected systems and records;

(d) assessment of the categories and volume of data;

(e) evaluation of consequences for individuals;

(f) remediation and recovery;

(g) notification to controllers, authorities, or individuals; and

(h) documentation of decisions and lessons identified.

21.3 Where Thanex acts as processor, the affected Business Customer must be notified without undue delay after Thanex becomes aware of a personal-data breach affecting that Customer’s Project Content.

21.4 Where Thanex acts as controller, a notifiable breach must be reported to the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of awareness.

21.5 Affected individuals must be notified without undue delay where the breach is likely to create a high risk to their rights and freedoms, unless a lawful exception applies.

21.6 Every personal-data breach must be recorded, including facts, effects, remedial action, notification decisions, and reasons supporting those decisions.

 

22. Complaints

22.1 Data-protection complaints may be submitted to support@thanex.uk.

22.2 A qualifying complaint will be acknowledged within 30 days, investigated appropriately, and answered without undue delay in accordance with section 164A of the Data Protection Act 2018, as inserted by section 103 of the Data (Use and Access) Act 2025.

22.3 Complainants may also contact the Information Commissioner’s Office:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113.

 

23. Training, Confidentiality, and Compliance

23.1 Personnel with access to personal data must receive instructions proportionate to their responsibilities.

23.2 Confidentiality obligations continue after employment, engagement, or authorised access ends.

23.3 Material non-compliance may result in access removal, contractual action, disciplinary measures where applicable, termination of engagement, or notification to competent authorities.

23.4 Thanex may conduct periodic reviews of provider arrangements, access permissions, retention records, security incidents, processing inventories, and legal documentation.

 

24. Policy Review and Approval

24.1 The Policy will be reviewed following a material Service change, significant security incident, new processing activity, provider change, regulatory development, or change in applicable law.

24.2 Amendments require approval from Thanex’s responsible management.

24.3 The current version will display its latest revision date. Superseded versions may be retained where necessary to demonstrate historical compliance.

 

25. Contact Details

Data-protection enquiries, rights requests, security reports, and complaints should be directed to:

Thanex Ltd
Flat 11, Mill Pond Place
1 Mill Lane
Maidstone
England
ME14 1GL
United Kingdom

Email: support@thanex.uk
Website: https://thanex.uk
Company number: 16426957.

Ready to See the Bigger Picture?

Every project tells a story. Make sure yours is organised, searchable, and ready whenever you need it. Download Thanex today and start building better project records from the very first photo.

Download Now

Live on the App Store and Google Play. Free to download and start capturing work photos in under a minute.

Scan to download.