Privacy Policy
Last updated: July 26, 2026
1. Data controller
The controller of personal data processing is THXU OÜ, a company incorporated in the Republic of Estonia (the "THXU"). You can contact us through the support channels published on the Service.
2. Scope
This Policy applies to the site and the XHR — Knowledge HR platform. Within the SaaS service, THXU acts as processor regarding the data that client companies upload (documents, users, queries) and as controller regarding data related to the contractual relationship.
3. Data we process
- Account: name, email, company, role and login provider identifier (e.g., Google).
- Billing: legal name, tax ID, address and billing contact details. Payment data is processed by Stripe; we do not store full card numbers.
- Customer Content: documents and texts uploaded by companies, and queries made to the assistant.
- Usage and technical data: logs, IP addresses, session identifiers, browser information and usage metrics.
- Connectors: OAuth tokens (e.g., Google Drive) stored encrypted.
4. Purposes and legal basis
- Providing the Service (contract performance).
- Billing and tax compliance (legal obligation).
- Security, fraud prevention and audit (legitimate interest).
- Customer support and operational communications (contract performance).
- Improving the Service with aggregated metrics (legitimate interest).
- Marketing communications only with your consent; you can withdraw it at any time.
We do not use Customer Content to train third-party models or our own base models. Content is processed exclusively to generate assistant responses within the customer's account.
5. Processors and third parties
We work with providers that act as sub-processors under contract:
- Infrastructure and database (platform hosting).
- AI model providers for generating embeddings and responses.
- Stripe for payment processing.
- Google for authentication and optional Google Drive sync.
- Transactional email services for notifications.
6. International transfers
Some providers may process data outside the European Economic Area. In such cases we apply adequate safeguards under the GDPR, such as the Standard Contractual Clauses (SCC) approved by the European Commission.
7. Retention
- Account and billing data: for as long as the contractual relationship exists and applicable legal periods (usually 7 years for tax matters).
- Customer Content: for as long as the client company keeps the service or until deletion is requested.
- Technical and audit logs: for limited periods according to operational and security needs.
8. Your rights
You have the right to access, rectify, delete, object to, restrict the processing of, and request portability of your personal data, as well as to withdraw your consent when the processing is based on it. You can exercise these rights by writing to us through the Service's support channels. You also have the right to file a complaint with the competent supervisory authority (in Estonia, the Andmekaitse Inspektsioon).
9. Security
We apply reasonable technical and organizational measures, including encryption in transit (TLS), data isolation per company through Row Level Security, role-based access control, encrypted token storage and audit logging.
10. Cookies
We use strictly necessary cookies for functioning (e.g., session and authentication). If we use analytics or marketing cookies, we will request your prior consent.
11. Minors
The Service is not directed at minors under 16 years old. If you become aware that a minor has provided us with data without authorization, contact us to have it deleted.
12. Changes to this Policy
We may update this Policy. We will notify substantial changes by email or within the Service before they take effect.
13. Contact
Privacy inquiries: THXU OÜ, Republic of Estonia, through the support channels published on the Service.