Legal
Privacy Policy
Vanaheim SRL, a Romanian limited-liability company (CUI 52324484, registered with the Trade Register under J2025060779002, with its registered office in Râmnicu Vâlcea, Romania — full address available on written request to hi@vanaheim.io), is the data controller for the Thren product (“Thren,” “we,” “us”). This Privacy Policy explains what personal data we collect, why we collect it, the legal basis for processing, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation 2016/679, “GDPR”).
1. What we collect
We collect only the personal data we need to run the platform.
- Account data — your name and email address, supplied when you sign up.
- Learning progress — courses you enroll in, lessons you complete, quiz answers, sandbox submissions, and the certificates you earn.
- Payment metadata — Stripe processes payments. Stripe holds your card number; we store only a Stripe customer ID, the last four digits of your card, and the status of your subscription or one-time purchase.
- Technical data — IP address (truncated where possible), browser user-agent, device type, and pages visited. We use this to keep the site working, detect abuse, and measure aggregate traffic patterns.
- Support correspondence — the content of any email you send to hello@thren.io.
2. Why we process it, and on what legal basis
Under Article 6(1) GDPR, we rely on the following legal bases:
We do not sell your personal data. We do not run third-party ad networks on the site, and we do not share your learning data with advertisers.
3. Who we share it with (sub-processors)
We share the minimum personal data needed to operate the Service with a small number of trusted sub-processors, under Data Processing Agreements:
- Microsoft Azure — hosts the website, learner app, application data, and operational logs. Data is stored in the EU region (West Europe / North Europe).
- Azure Communication Services — delivers transactional and product email.
- Azure Application Insights — receives pseudonymised page-view and event telemetry for product analytics.
- Stripe Payments Europe, Ltd. — processes payments and stores card details. Stripe acts as a controller for the data it processes; see stripe.com/privacy.
We may also disclose information when required by law, court order, or when necessary to protect Vanaheim SRL, our users, or the public from fraud, abuse, or safety threats.
4. International transfers
Your data is primarily stored in EU Azure regions. Where a sub-processor is established outside the EEA (for example, certain Stripe components), transfers rely on the European Commission’s Standard Contractual Clauses (Commission Decision 2021/914) and any applicable adequacy decision. You can request a copy of the relevant transfer mechanism by emailing the data protection contact below.
5. Retention
We keep your account and learning records for as long as your account is open. If you delete your account, we erase the associated personal data within thirty (30) days, except for records we are legally required to retain (for example, invoices and payment records, kept for the statutory period under Romanian / EU tax law, typically 10 years). Backups expire on a rolling 90-day cycle.
6. Your rights under the GDPR
Subject to the conditions in the GDPR, you have the right to:
- Access — get a copy of the personal data we hold about you. (Art. 15)
- Rectify — correct inaccurate or incomplete personal data. (Art. 16)
- Erase — request that we delete your personal data. (Art. 17)
- Restrict — ask us to limit how we process your data. (Art. 18)
- Portability — receive your data in a structured, commonly used, machine-readable format. (Art. 20)
- Object — object to processing based on legitimate interests, including direct marketing. (Art. 21)
- Withdraw consent — where processing is based on your consent, withdraw it at any time. (Art. 7)
To exercise any of these rights, email hi@vanaheim.io from the address on your account. We respond within thirty (30) days. There is no fee unless your request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority — in our case the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro — or with the supervisory authority in the EU member state where you live or work.
7. Cookies & similar technologies
We use a small number of strictly necessary cookies and local-storage entries to keep you signed in, remember your quiz answers between pages, and preserve form state. We do not use third-party advertising or cross-site tracking cookies. Where analytics cookies are not strictly necessary, we limit them to pseudonymised event tracking that does not identify you.
8. Security
We use TLS in transit, encrypted storage at rest, role-scoped staff access, and short-lived session tokens. No system is bulletproof, but we treat your data the way we would want ours treated. If we ever become aware of a personal-data breach likely to result in risk to your rights, we will notify the supervisory authority within 72 hours and, where required, notify you without undue delay.
9. Children
Thren is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has created an account, please contact us and we will remove the account.
10. Changes to this policy
If we make a material change we will notify active account holders by email at least seven (7) days before it takes effect. The “Last updated” date above always reflects the current version.
11. Contact & data protection
CUI 52324484 · Trade Register J2025060779002 · EUID ROONRC.J2025060779002
Data protection & GDPR requests: hi@vanaheim.io
Product support: hello@thren.io
We have not formally designated a Data Protection Officer because our processing does not meet the thresholds in Article 37 GDPR; the contact above is the responsible point for all data-protection matters.