Privacy notice
1. Who is responsible
Thalius AI AB (organisation number 559528-5635, VAT SE559528563501), Stockholm, Sweden, is the controller for the personal data described in this notice.
Privacy contact: [email protected]. We answer privacy requests within one month.
This notice covers:
- visitors to this site;
- people who sign up for or use the Hippocampus cloud service;
- people who join the beta notification list or send the Corporate form;
- partners in our referral programme.
It does not cover the documents customers upload to the Service. For those, the customer is the controller and we are its processor under the data processing agreement.
2. What we collect and why
| Who | Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Every site visitor | Page, day, campaign tags (UTM source and campaign), referral link, and a salted one-way hash of the IP address | Count visits and sign-ups by page and campaign, and brake abuse, without identifying anyone | Legitimate interest |
| Site visitors who allow analytics or marketing | Analytics events and identifiers set by the tools in section 3; the first-touch cookie | Understand which pages and campaigns lead to sign-ups | Consent |
| People who join the beta notification list | Email; name and company if the form asks; the words you agreed to and when; where you first came from (campaign tags, referral link, referrer site, entry page) | Email you when the beta opens | Consent |
| People who send the Corporate form | Work email, organisation, company size, message, where you first came from | Answer and follow up | Legitimate interest; steps before a contract |
| People who create an account from this site | Email and the campaign tag of the sign-up, passed to the application | Create the account; count sign-ups by source | Contract; legitimate interest |
| Account holders | Name, email, organisation, sign-in events, plan, credit usage | Provide and bill the Service, prevent abuse | Contract |
| Users of the Service | Questions asked and answers given, with the signed-in user attached | Conversation history, support, security audit | Contract; legitimate interest (security) |
| Paying customers | Billing contact, invoices, payment records | Billing and accounting | Contract; legal obligation |
| Referral partners | Name, email, referral link, sign-ups attributed to the link, partner portal account | Run the referral programme | Contract |
We do not collect special categories of personal data on purpose, and we do not sell personal data.
Do you have to give us data? No. Without an email address we cannot create an account, add you to the beta list or answer the Corporate form. Declining cookies does not limit the site.
Where data comes from. Most data comes from you. The campaign tag of a sign-up is passed from this site to the application, and the source of a referral comes from the link you followed.
3. Cookies and similar technologies
Without your consent, this site sets no cookies. If Cloudflare Web Analytics is switched on, it measures page loads without cookies and without identifying you (legitimate interest). The site also keeps three things in your browser’s own storage:
- your consent choice (local storage);
- your light or dark theme (local storage);
- where this visit came from, so that a form you send during the same visit carries it (session storage, cleared when you close the tab).
With your consent, given in the banner and changeable at any time from “Cookie settings” in the footer, we may use the tools below. The banner appears only while at least one of them is switched on.
| Tool | Category | What it does |
|---|---|---|
th_ft first-party cookie |
Analytics or marketing | Remembers for 90 days the campaign or referral link that first brought you here, so a later sign-up can be attributed to it. It holds no name or email and is removed when you withdraw consent. |
| PostHog (EU cloud) | Analytics | Page views, events, the path from visit to sign-up, and heatmaps where enabled. Before consent it runs in memory only, with no cookie. |
| Google Analytics 4 | Analytics | Visit and campaign measurement with IP anonymisation and Google Consent Mode. Loads only after consent. |
| Google Tag Manager | Analytics or marketing | Loads measurement or advertising tags only for the categories you allowed, with Google Consent Mode. |
4. Who receives data
- Service providers that process data for us under data processing agreements:
- Cloudflare, which delivers this site and the application;
- our hosting for this site and its content system;
- the analytics tools in section 3;
- the providers listed on the sub-processors page for the Service itself;
- the payment provider named at checkout.
- Authorities, when the law requires it.
- A buyer or successor, if the business is transferred, under the same protections.
Referral partners see only counts of sign-ups attributed to their link, never who signed up.
5. Transfers outside the EU/EEA
Documents and the knowledge structure of the Service are stored in the EU (Finland). Some providers, including Google, Cloudflare and the AI model providers used by default, are based in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses with a transfer risk assessment. Corporate customers can choose EU-hosted or customer-hosted inference. You can ask us for a copy of the safeguards.
6. How long we keep data
| Data | Retention |
|---|---|
| Visit counts with hashed IP | 26 months |
| Analytics tool data | 26 months, or the tool’s shorter setting |
th_ft cookie |
90 days in your browser |
| Beta notification list | Until the beta opens and we have told you, or until you withdraw consent, whichever comes first |
| Corporate enquiries | 2 years from the last contact |
| Account data and conversation logs | While the account exists; deleted within 30 days of account deletion, and from backups within 90 days |
| Invoices and payment records | 7 years (Swedish Bookkeeping Act) |
| Referral partner data | While the partnership lasts, plus 3 years |
After that, data is deleted or anonymised.
7. Security
Data is encrypted in transit and at rest. Documents in the Service are encrypted with per-document keys bound to the tenant. Access to personal data is limited to the people who need it, and security-relevant operations are logged. Details are on the security page.
If a breach is likely to put your rights at risk, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and tell you without undue delay.
8. Your rights
You have the right to:
- access your personal data and get a copy;
- have it corrected;
- have it erased;
- restrict its processing;
- receive it in a portable format;
- object to processing based on legitimate interest, and to direct marketing at any time;
- withdraw consent at any time, without affecting processing before the withdrawal.
Write to [email protected]. We do not charge unless a request is manifestly unfounded or excessive. If your data sits in a customer’s tenant, we forward your request to that customer.
You can also complain to the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, [email protected], www.imy.se, or to the authority where you live or work.
9. Automated decisions
We make no decisions with legal or similarly significant effects on you based solely on automated processing. The AI features of the Service are described in the AI Act disclosure.
10. Children
The site and the Service are for professional use and are not directed at children under 16.
11. Changes
When we change this notice, we update the version and effective date above. Material changes are announced on this site at least 30 days before they apply and, for account holders, by email.