Thren ← Back to home

Legal

Privacy Policy

Last updated: May 22, 2026 · Data controller: Vanaheim SRL (Romania).

Vanaheim SRL, a Romanian limited-liability company (CUI 52324484, registered with the Trade Register under J2025060779002, with its registered office in Râmnicu Vâlcea, Romania — full address available on written request to hi@vanaheim.io), is the data controller for the Thren product (“Thren,” “we,” “us”). This Privacy Policy explains what personal data we collect, why we collect it, the legal basis for processing, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation 2016/679, “GDPR”).

1. What we collect

We collect only the personal data we need to run the platform.

2. Why we process it, and on what legal basis

Under Article 6(1) GDPR, we rely on the following legal bases:

Operating the Service
Performance of a contract — we cannot deliver lessons, grade quizzes, or issue certificates without your account data and learning progress. Art. 6(1)(b).
Processing payments
Performance of a contract and compliance with tax / accounting law. Art. 6(1)(b), 6(1)(c).
Transactional email
Performance of a contract — receipts, password resets, certificate notifications. Art. 6(1)(b).
Product email (cohort openings, new programs)
Legitimate interest in informing existing customers about related offerings. You can unsubscribe at any time. Art. 6(1)(f).
Aggregate analytics
Legitimate interest in keeping the product reliable and detecting abuse. Pseudonymised. Art. 6(1)(f).
Tax / accounting records
Legal obligation under Romanian / EU bookkeeping rules. Art. 6(1)(c).

We do not sell your personal data. We do not run third-party ad networks on the site, and we do not share your learning data with advertisers.

3. Who we share it with (sub-processors)

We share the minimum personal data needed to operate the Service with a small number of trusted sub-processors, under Data Processing Agreements:

We may also disclose information when required by law, court order, or when necessary to protect Vanaheim SRL, our users, or the public from fraud, abuse, or safety threats.

4. International transfers

Your data is primarily stored in EU Azure regions. Where a sub-processor is established outside the EEA (for example, certain Stripe components), transfers rely on the European Commission’s Standard Contractual Clauses (Commission Decision 2021/914) and any applicable adequacy decision. You can request a copy of the relevant transfer mechanism by emailing the data protection contact below.

5. Retention

We keep your account and learning records for as long as your account is open. If you delete your account, we erase the associated personal data within thirty (30) days, except for records we are legally required to retain (for example, invoices and payment records, kept for the statutory period under Romanian / EU tax law, typically 10 years). Backups expire on a rolling 90-day cycle.

6. Your rights under the GDPR

Subject to the conditions in the GDPR, you have the right to:

To exercise any of these rights, email hi@vanaheim.io from the address on your account. We respond within thirty (30) days. There is no fee unless your request is manifestly unfounded or excessive.

You also have the right to lodge a complaint with a supervisory authority — in our case the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro — or with the supervisory authority in the EU member state where you live or work.

7. Cookies & similar technologies

We use a small number of strictly necessary cookies and local-storage entries to keep you signed in, remember your quiz answers between pages, and preserve form state. We do not use third-party advertising or cross-site tracking cookies. Where analytics cookies are not strictly necessary, we limit them to pseudonymised event tracking that does not identify you.

8. Security

We use TLS in transit, encrypted storage at rest, role-scoped staff access, and short-lived session tokens. No system is bulletproof, but we treat your data the way we would want ours treated. If we ever become aware of a personal-data breach likely to result in risk to your rights, we will notify the supervisory authority within 72 hours and, where required, notify you without undue delay.

9. Children

Thren is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has created an account, please contact us and we will remove the account.

10. Changes to this policy

If we make a material change we will notify active account holders by email at least seven (7) days before it takes effect. The “Last updated” date above always reflects the current version.

11. Contact & data protection

Vanaheim SRL (data controller) Râmnicu Vâlcea, Romania · full address on written request to hi@vanaheim.io
CUI 52324484 · Trade Register J2025060779002 · EUID ROONRC.J2025060779002
Data protection & GDPR requests: hi@vanaheim.io
Product support: hello@thren.io

We have not formally designated a Data Protection Officer because our processing does not meet the thresholds in Article 37 GDPR; the contact above is the responsible point for all data-protection matters.