Legal
Privacy Policy
Last reviewed: 1 July 2026. This policy explains how thread handles personal data under UK GDPR and the Data Protection Act 2018.
1. Who we are
thread is the data controller for personal data collected through this website and for the administration of customer accounts. For content within a customer workspace, the customer organisation is the controller and thread acts as processor on its instructions.
You can contact our data protection lead at privacy@thread.example.
2. The personal data we collect
Website and enquiry data: name, work email, company, job title, organisation size, telephone number where provided, the content of your message and your consent record.
Account data: administrator and user names, work email addresses, role and workspace permissions.
Workspace content: conversation records and the context derived from them, processed on behalf of the customer organisation.
Technical data: IP address, device and browser information, and cookie identifiers described in section 8.
3. How we use personal data and our lawful bases
To respond to demo requests and enquiries — consent, and our legitimate interest in responding to business enquiries.
To provide, secure and support the platform — performance of a contract.
To meet accounting, tax and regulatory obligations — legal obligation.
To improve the service and understand website use — legitimate interests, balanced against your rights and subject to your cookie preferences.
4. Who we share personal data with
We share data with vetted processors who help us run the service, including cloud hosting, communication and support tooling. Each is bound by written terms that restrict use to our instructions.
We do not sell personal data and we do not share it for third-party advertising.
5. International transfers
Where personal data is transferred outside the UK, we rely on adequacy regulations or the UK International Data Transfer Addendum together with appropriate supplementary measures. UK-only data residency is available on Momentum and Network plans.
6. How long we keep personal data
Enquiry data is retained for 24 months from your last contact with us unless you ask us to delete it sooner. Account data is retained for the life of the contract plus the period required for legal and accounting purposes. Workspace content is retained according to the retention policy configured by the customer organisation.
7. Your rights
Under UK GDPR you have the right to access your data, to have inaccurate data corrected, to request erasure, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting prior processing.
To exercise a right, contact privacy@thread.example. We respond within one month. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
8. Cookies
We use essential cookies to operate this website and optional analytics cookies to understand how it is used. Optional cookies are only set with your consent, which you give or decline through our cookie banner and can change at any time by clearing your site data.
9. Security
We apply technical and organisational measures appropriate to the sensitivity of the information we hold, including encryption in transit and at rest, role-based access control, audit logging and regular review of supplier security.
10. Automated processing
thread uses automated processing to connect conversations, commitments, projects and objectives. It does not make decisions about individuals, does not score or rank people, and does not produce legal or similarly significant effects. Conclusions are always drawn by people.
11. Changes to this policy
We review this policy at least annually. Material changes will be notified to account administrators and reflected in the review date above.
See also our Terms & Conditions.
