Privacy Policy & Data Protection Framework
1. Data Controller & Scope
Sukrano oy ("Company", "we", "us", "our") acts as the Data Controller under the General Data Protection Regulation (EU GDPR 2016/679), the UK Data Protection Act, and the Estonian Personal Data Protection Act for personal data processed through thru.capital and terminal.thru.capital.
2. Principles of Data Minimization
We operate under strict privacy-by-design and data minimization protocols:
- Zero Data Monetization: We never sell, rent, monetize, or trade your personal data with third-party advertisers or data brokers.
- Zero Payment Card Exposure: Raw credit/debit card numbers and CVVs are transmitted directly to Stripe under PCI-DSS Level 1 certification. We never store or view raw card data.
- Non-Custodial Crypto: On-chain USDC settlements are push-based. We never request, collect, or store your private cryptographic keys or seed phrases.
3. Categories of Data Collected
- Account Identifiers: Email address collected upon authentication via email OTP, paired with a pseudonymous Supabase UUID (
user_id). - Billing & Invoicing: Stripe customer identifiers, blockchain transaction hashes (TXIDs), deposit addresses, and payment timestamps required for entitlement provisioning and tax accounting.
- Edge Diagnostics: IP addresses, browser user-agents, and request timestamps captured transiently by edge gateways for DDoS mitigation and rate-limiting.
- Market Inquiries: Inquiry text submitted to the market investigation engine for telemetry synthesis, together with your account email and tier, is also logged to our private operator notification channel (Telegram) for service monitoring. Inquiries are not used to train generalized LLMs.
- Usage Quotas: A daily investigation counter keyed by your account ID, or for guests by a salted one-way hash of your IP address (the raw IP is not stored), expiring after 24 hours.
- Usage Analytics (thru.capital only): Google Analytics 4 records pages viewed, referrer, approximate location, device type, and a pseudonymous client identifier. Visitors in the EU/EEA, the United Kingdom and Switzerland are asked first; elsewhere it runs by default and can be switched off under Manage Preferences. terminal.thru.capital does not use analytics.
4. Lawful Bases for Processing (GDPR Art. 6)
- Consent (Art. 6(1)(a)): Analytics cookies on thru.capital for visitors in the EU/EEA, the United Kingdom and Switzerland, requested before any analytics script loads and withdrawable at any time under Manage Preferences.
- Contractual Necessity (Art. 6(1)(b)): Processing email auth, session tokens, and subscription entitlements to deliver the SaaS service.
- Legal Obligation (Art. 6(1)(c)): Retaining financial transaction records for statutory compliance with Estonian commercial accounting and VAT directives.
- Legitimate Interests (Art. 6(1)(f)): Protecting edge infrastructure against cyberattacks, automated scraping, and unauthorized service exploitation; enforcing fair-use quotas; operator monitoring of inquiries.
5. Authorized Sub-Processors
We work exclusively with enterprise sub-processors maintaining SOC 2 Type II / ISO 27001 certifications and Standard Contractual Clauses (SCCs):
- Supabase Inc. (Authentication & Session State)
- Stripe Inc. (Payment Processing & Invoicing)
- Cloudflare Inc. (Edge CDN, DDoS Shield, Encrypted R2 Archival Storage)
- Google Cloud / DeepMind (Gemini Model API for Telemetry Synthesis — zero customer prompt training)
- Google LLC (Google Analytics 4 on thru.capital: opt-in in the EU/EEA, UK and Switzerland, on by default elsewhere with an opt-out)
- Telegram FZ-LLC (Private operator notifications: inquiry logs and contact requests)
- Vercel Inc. (Edge Web Application Hosting)
6. Data Retention & Erasure
- Account Identifiers: Retained while your account remains active. Deleted within 30 days of a verified erasure request.
- Financial Audit Records: Retained for up to 7 years in compliance with the statutory requirements of the Estonian Accounting Act and EU tax directives.
- Network Edge Logs: IP and security logs are automatically rotated and purged after 90 days.
7. Your Data Protection Rights
Under GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data.
To exercise your rights, submit a written request to support@thru.capital. We verify identity and respond within 30 days without charge. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).
8. Cookies, Local Storage & Analytics
terminal.thru.capital uses no analytics, advertising, or behavioral tracking cookies. It uses strictly necessary storage only: your Supabase session, stored only in this site's LocalStorage (it is not shared with thru.capital or any other site), your theme (thru_theme), and your local inquiry history.
On thru.capital, Google Analytics 4 cookies (_ga, _ga_<container-id>) are set only after you select “Accept” if you are in the EU/EEA, the United Kingdom or Switzerland; elsewhere analytics runs by default and can be switched off under Manage Preferences. See the thru.capital Cookie & Analytics Policy.