Legal
Privacy Policy
How Thynex handles personal data when you visit our website, chat with Venus, contact us or use Thynex for your store. Last updated 1 October 2026.
1. Who we are
Thynex is a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KvK) under number 91791987, with its office at Irisstraat 14, 7151 VT Eibergen, the Netherlands. In this policy, “Thynex”, “we” and “us” mean us.
We are responsible (the “controller”) for the personal data described in this policy. Questions or requests: email hello@thynex.ai.
2. Businesses that use Thynex, and their customers
Online stores use Thynex to answer their own customers. For the conversations, contacts and order details in their helpdesk, the store decides what happens with the data and we process it on its behalf, as its processor. Our Data Processing Agreement covers that.
Are you a customer of a store that uses Thynex? Then please contact that store about your data. If you write to us instead, we’ll pass your request on.
3. What we collect and why
- Visiting our website. Our host keeps server logs with your IP address, browser and the pages you open, to run and secure the site. Basis: our legitimate interest in a working, safe website.
- Spam protection. Our pages use Google reCAPTCHA to keep bots away from our forms. It sends your IP address and browser data to Google. Basis: our legitimate interest in preventing abuse. See Google’s privacy policy.
- Chatting with Venus on our website or trying the demo store. We process your messages to answer them. Your chat history is also kept in your own browser (local storage), so the conversation survives a page reload. Chats in the demo store are deleted after six hours. Basis: our legitimate interest in answering your questions.
- Asking us to follow up. If you leave your email address in the chat or our contact form, we use it, with your name and message, to reply about Thynex. Basis: your consent and taking steps at your request before a contract.
- Your Thynex account. Name, email address, company details, your password (stored only as a secure hash) and your plan, to provide the service. Basis: our contract with you.
- Billing. Billing name and address, VAT number and payment status. Payments are handled by Stripe or, if you installed Thynex through Shopify, by Shopify. We never see or store full card numbers. Basis: our contract and our legal duty to keep financial records.
- Service and product emails. We email you about your account, usage and billing. We only send marketing emails if you asked for them, and every one has an unsubscribe link.
- Improving Venus. Only if a business switches on “Let Thynex learn from your conversations” in its settings (off by default) do we keep its AI interactions to improve our models. Email addresses, phone numbers and postcodes are always masked in that data, and switching the setting off deletes what was kept.
4. Who we share data with
We don’t sell personal data. We only share it with providers we need to run Thynex, under agreements that bind them to protect it:
- DigitalOcean, which hosts the Thynex app and its database in Amsterdam, the Netherlands;
- Hostinger, which hosts this website in France;
- an AI model provider based in the European Union, which processes text to write Venus’s answers;
- Titan, which provides our email;
- Stripe and Shopify, for payments;
- Google, for reCAPTCHA.
We may also share data when the law requires it, for example at the request of a court or regulator.
5. Transfers outside the EU
We keep personal data in the European Union where we can: the Thynex app, its database and the AI models we use all run in the EU. Some of our providers belong to groups based outside the EU, such as DigitalOcean, Google and Stripe, and email can pass through servers outside the EU. Where data may leave the EU, we rely on an adequacy decision, such as the EU-US Data Privacy Framework, or on the European Commission’s Standard Contractual Clauses.
6. How long we keep data
- Account data: while your account is active, and 30 days after it ends so you can export your data. Then we delete it.
- Invoices and payment records: seven years, as Dutch tax law requires.
- Emails and contact requests: as long as we need them to help you, and no longer than two years after our last contact.
- Chats with Venus on our website: as long as we need them to answer and follow up your question. Demo store chats: six hours.
- Technical logs of AI requests: 30 days. Usage records of Venus replies: 180 days. Neither contains message text.
- Server logs: kept by our host for a limited period for security.
7. Cookies and local storage
We don’t use analytics or advertising cookies. Google reCAPTCHA may read or set cookies to tell people from bots. Our website chat keeps your conversation in your browser’s local storage, which you can clear at any time. The Thynex app uses cookies that are needed to keep you signed in.
8. Security
We protect personal data with measures that fit the risk: encrypted connections, hosting in the EU, strict separation between customer accounts, two-factor authentication and logging for our own staff access, and redaction of payment card numbers and passwords before any text reaches an AI model. Our Data Processing Agreement describes them in more detail.
9. Your rights
You can ask us to access, correct or delete your personal data, to restrict or object to how we use it, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time. Email hello@thynex.ai and we’ll reply within one month.
You can also file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
10. Changes to this policy
We update this policy when our services or the law change. The date at the top shows the latest version. If a change matters for you, we’ll tell you by email or in the app.