Crowther builds sovereign AI: systems that run on infrastructure our customers control, governed by keys they hold. We apply the same principle to your personal information. We collect little, we keep it only as long as we need it, we do not sell it, and we do not use it to train AI models.
This policy explains what we collect through our websites and the AI Strategy Audit, why, and the choices you have. It is issued by Crowther (“Crowther”, “we”, “us”), part of THCO. We are the data controller for the processing described here.
Information you give us
Information collected automatically
We do not ask for, and you should not submit, special category data (such as health information), payment card details, or personal information about other identifiable individuals.
We do not use your information for automated decisions that produce legal or similarly significant effects about you.
Your audit answers are processed by a large language model to assemble your Roadmap. Three commitments apply:
We do not sell personal information. We do not share it with data brokers. We do not run third-party advertising on our websites. We do not use your data to profile you beyond the purposes listed above.
We keep personal information only as long as needed for the purposes above, then delete or anonymise it. As a guide: audit records and Roadmaps are retained for up to 24 months so we can support you on the results; contact messages for up to 24 months; verification codes for minutes; server logs for up to 90 days. Where law requires longer retention, we comply.
We share personal information only with service providers who process it on our instructions, under contracts that protect it:
We may also share information within THCO for administration of the business, with professional advisers under confidentiality, and where required by law, regulation or legal process. If Crowther is involved in a merger, acquisition or asset sale, personal information may transfer as part of that transaction, under this policy’s protections.
Our providers may process data outside your country. Where personal information is transferred internationally, we use recognised safeguards such as adequacy decisions or standard contractual clauses, and we limit transfers to what the services require.
We use strictly necessary cookies to run the websites (for example, remembering which side of our homepage you chose, and session security). Analytics or preference cookies are used only with your consent, which you can give or withdraw through the cookie settings on the site. We honour the choices you make there.
We protect personal information with technical and organisational measures aligned with how we build everything: access is denied by default and granted on need, data is encrypted in transit, verification codes are short-lived, and administrative access is restricted and logged. No system is perfectly secure, and we encourage you to report any concern to hello@thcohq.com.
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict or object to our processing of your personal information, to receive a copy in a portable format, and to withdraw consent where processing is based on consent. You also have the right to complain to your data protection authority.
To exercise any right, contact hello@thcohq.com. We will respond within the time required by applicable law, and we do not charge for reasonable requests.
Our services are for business users and are not directed at anyone under 18. We do not knowingly collect information from children, and we delete any we discover.
We may update this policy from time to time. The date at the top shows the current version, and material changes will be announced on the website or by email before they take effect.
Privacy questions and requests: hello@thcohq.com.