Version: 1.3
Last updated: 5 August 2026
Governing language: Dutch. In case of conflict, the Dutch privacy statement prevails.

Thalassa Cloud Services B.V. (“Thalassa”, “we”), established in the Netherlands, respects your privacy. This policy explains how we process personal data when we act as controller, for which purposes, on which legal basis, and what rights you have.

Thalassa Cloud Services B.V.
Meander 251, 6825 MC Arnhem, the Netherlands
Chamber of Commerce (KvK): 99309769 · VAT: NL868926966B01

Contact: privacy@thalassa.cloud
Website: https://thalassa.cloud

1. Our roles

Controller

Thalassa is the controller for personal data relating to:

  • services / platform — Account Data: organisation and billing data, (service) accounts, support tickets, platform telemetry and resource metadata;
  • website and marketing — visitor data, contact forms and (where applicable) newsletter subscriptions.

That processing is covered by this privacy policy.

Processor

For Customer Content (data you or your users place on the platform or that is directly derived therefrom), Thalassa is the processor. In that case, you in principle determine the purpose and means of the processing and are the controller. That processing is governed by our Data Processing Agreement (DPA). Requests from end users about those personal data should therefore primarily be addressed to you; Thalassa assists you under the DPA.

Thalassa has no access to Customer Content, unless the customer explicitly grants it (for example for support).

2. Services (platform)

2.1 Information you provide

  1. Account registration. Contact and organisation details such as name, company name, address, email address and phone number.
  2. Payments. Payment data via Mollie (independent controller). We do not store full payment card details; we do have access to subscriber and invoice data via Mollie.
  3. Support and contact. Via the service desk or contact channels: name, email, message content and account reference.
  4. Assessment of new organisations. When an organisation is created, we assess whether it is legitimate and complies with the terms. We automatically determine a risk score and may consult external sources, such as business registries and credit information. An organisation is never refused or blocked solely by automated means: an elevated risk score triggers manual review.

2.2 Use of the platform

When you use our cloud services we process Account Data needed to operate and secure the platform and provide support, including:

  • platform telemetry (availability, usage intensity, errors);
  • audit and access-related logs;
  • resource metadata (such as resource names and sizing);
  • technical metadata associated with API/console traffic (where relevant including IP addresses).
PurposeData (summary)Legal basis
Account and service deliveryAccount and organisation data, technical metadataContract
Payments and billingInvoice and contact detailsContract / legal obligation
SupportTickets, communications, account reference, technical logsLegitimate interest (service delivery)
Security (WAF/DNS)IP addresses, technical metadataLegitimate interest (security)
Platform notificationsEmail, account and security noticesContract
Offsite backup of platform metadataEncrypted account/platform metadataLegitimate interest (continuity)
Business emailCorrespondence and attachmentsLegitimate interest (operations)
Assessment of new organisationsOrganisation and contact details, risk score, external sources (business registries, credit information)Legitimate interest (fraud prevention and platform security)

3. Website and marketing

3.1 Website

  1. We set only essential, functional cookies (technical operation and session preferences such as language). No cookies for tracking, profiling or advertising.
  2. Analytics via Plausible (self-hosted) uses no tracking cookies and aggregated statistics. Raw IP addresses are not stored for that purpose.
  3. Bunny Shield may set temporary security tokens/cookies. For availability, abuse detection and security, we also process IP addresses in the website access logs.

3.2 Marketing and newsletter

For the newsletter we process name and email address based on consent. You may withdraw consent at any time (unsubscribe).

PurposeData (summary)Legal basis
Operate the websiteEssential cookies / session preferencesLegitimate interest (technical operation)
Website analyticsAggregated visit statistics (Plausible)Legitimate interest (usage insight)
Website securityIP / security tokens (Bunny Shield)Legitimate interest (security)
NewsletterName, emailConsent

4. Sharing with third parties

PartyRole / context
AhaSend B.V.Platform and security emails
BunnyWay d.o.o. (bunny.net)WAF/Shield, DNS and website security
Scaleway S.A.S.Encrypted offsite backup of platform metadata
Mollie B.V.Payments (independent controller)
AccountantBookkeeping and tax

Sub-processors for Customer Content are listed only in the DPA, Annex B.

We may share data where legally required or needed to defend our rights.

5. Transfers outside the EEA

Processing within the EEA is the default. For Customer Content, 100% EU applies under the DPA. If a transfer is still needed for Account Data or operations, we use appropriate safeguards (adequacy decision or standard contractual clauses).

6. Retention

We do not keep personal data longer than needed for the purpose or a legal duty.

  • Erasure or account/organisation termination: handled within 30 days, where reasonably possible, unless a legal retention duty requires longer storage.
  • Financial / bookkeeping / business email: up to 7 years where applicable.
  • Support tickets: 2 years after closure; invoice- and contract-related correspondence up to 7 years (statutory retention duty).
  • WAF logs: about 3 days; platform emails: about 14 days; offsite backup metadata: about 28 days.
  • Newsletter: until withdrawal of consent.

7. Security

We treat personal data as confidential and apply appropriate technical and organisational measures (access, encryption, logging, incidents). See Platform security.

8. Your rights

The GDPR applies to the processing of personal data by Thalassa. You have the right of access, rectification, erasure, restriction of processing and data portability. Where processing is based on consent, you may withdraw that consent at any time; this does not affect the lawfulness of processing before the withdrawal.

Right to object. Where we process personal data on the basis of a legitimate interest, you have the right to object at any time, on grounds relating to your particular situation, to that processing. We will then cease the processing unless compelling legitimate grounds override, or the processing is needed for legal claims.

You may contact us via privacy@thalassa.cloud with questions or requests about your personal data.

We handle questions, requests and complaints carefully and aim to resolve them within 30 days, unless a statutory deadline or the nature of the request requires a different handling period.

You may also lodge a complaint with the Dutch Data Protection Authority.

9. Changes

We may update this privacy policy from time to time. We communicate material changes via the website or by email (and, where applicable, via platform notification).