thru.capital REAL-TIME MARKET INTELLIGENCE.
thru.capital REAL-TIME MARKET INTELLIGENCE.
System Active · BTC · 9 Venues

// Legal & Compliance · Privacy Policy

Effective Date: September 25, 2026 • Entity: Sukrano oy (Registered in Republic of Estonia) • Contact: [email protected]

1. Data Controller & Scope

/privacy#controller

Sukrano oy ("Company", "we", "us", "our") acts as the Data Controller under the General Data Protection Regulation (EU GDPR 2016/679), the UK Data Protection Act, and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) for personal data processed through thru.capital and terminal.thru.capital.

2. Principles of Data Minimization

/privacy#minimization

We operate under strict privacy-by-design and data minimization protocols:

Zero Data Monetization We never sell, rent, monetize, or trade your personal data with third-party advertisers or data brokers.
Zero Payment Card Exposure Raw credit/debit card numbers and CVVs are transmitted directly to Stripe under PCI-DSS Level 1 certification. We never store or view raw card data.
Non-Custodial Crypto On-chain USDC settlements are push-based. We never request, collect, or store your private cryptographic keys or seed phrases.

3. Categories of Data Collected

/privacy#data-collected
Account Identifiers Email address collected upon authentication via email OTP, paired with a pseudonymous Supabase UUID (user_id).
Billing & Invoicing Stripe customer identifiers, blockchain transaction hashes (TXIDs), deposit addresses, and payment timestamps required for entitlement provisioning and tax accounting.
Edge Diagnostics IP addresses, browser user-agents, and request timestamps captured transiently by edge gateways (Cloudflare/Vercel) for DDoS mitigation and rate-limiting.
Market Inquiries Inquiry text submitted to the market investigation engine for telemetry synthesis, together with your account email and tier, is also logged to our private operator notification channel (Telegram) for service monitoring. Inquiries are not used to train generalized LLMs.
Contact Requests Email address, institution name, use case, and notes submitted through the API access request form, delivered to our private operator notification channel (Telegram).
Usage Analytics (thru.capital only) When analytics is enabled for you (see section 8), Google Analytics 4 records pages viewed, referrer, approximate location (derived from IP, which Google does not store), device and browser type, and a pseudonymous client identifier.

4. Lawful Bases for Processing (GDPR Art. 6)

/privacy#lawful-basis
Consent (Art. 6(1)(a)) Analytics cookies on thru.capital (Google Analytics 4) for visitors in the EU/EEA, the United Kingdom and Switzerland. Consent is optional, requested before any analytics script loads, and can be withdrawn at any time under Manage Preferences.
Contractual Necessity (Art. 6(1)(b)) Processing email auth, session tokens, and subscription entitlements to deliver the SaaS service.
Legal Obligation (Art. 6(1)(c)) Retaining financial transaction records for statutory compliance with Estonian commercial accounting and VAT directives.
Legitimate Interests (Art. 6(1)(f)) Protecting edge infrastructure against cyberattacks, automated scraping, and unauthorized service exploitation; operator monitoring of contact requests and terminal inquiries.

5. Authorized Sub-Processors

/privacy#subprocessors

We work exclusively with enterprise sub-processors maintaining SOC 2 Type II / ISO 27001 certifications and Standard Contractual Clauses (SCCs):

Supabase Inc. Passwordless authentication, JWT bearer management, and session state.
Stripe Inc. PCI-DSS Level 1 fiat payment processing and automated subscription management.
Cloudflare Inc. Global edge routing, DDoS shielding, and encrypted R2 archival storage.
Google Cloud / DeepMind Gemini API for real-time market microstructure synthesis (zero customer prompt retention for training).
Google LLC (Google Analytics 4) Website usage analytics on thru.capital, loaded as described in section 8. Transfers to the USA under the EU–US Data Privacy Framework and SCCs.
Telegram FZ-LLC Private operator notifications for contact requests and terminal inquiry logs (email, tier, inquiry text). Not used for marketing.
Vercel Inc. Serverless web application deployment and edge API endpoints.

6. Data Retention & Erasure

/privacy#retention
Account Identifiers Retained while your account remains active. Deleted within 30 days of a verified erasure request.
Financial Audit Records Retained for up to 7 years in compliance with the statutory requirements of the Estonian Accounting Act and EU tax directives.
Network Edge Logs IP and security logs are automatically rotated and purged after 90 days.
Analytics Data Google Analytics event data is retained for a maximum of 14 months. Analytics cookies expire after at most 2 years, or immediately when you switch analytics off under Manage Preferences.

7. Your Data Protection Rights

/privacy#rights

Under GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data.

To exercise your rights, submit a written request to [email protected]. We verify identity and respond within 30 days without charge. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).

8. Cookie & Analytics Policy

/privacy#cookies

This policy explains which cookies and browser storage thru.capital uses, why, and how you control them. We do not use advertising, retargeting, or cross-site behavioral tracking cookies, and we never sell analytics data.

8.1 What we store

Strictly Necessary (no consent required) LocalStorage entries that remember your theme and your analytics choice (thru_theme, thru_consent), and a SessionStorage entry that remembers, for the current tab only, whether the consent banner applies in your region (thru_consent_region). Sign-in happens only on terminal.thru.capital, and your session is kept in terminal.thru.capital's own LocalStorage, which thru.capital cannot read; thru.capital stores no session data.
Analytics (optional, thru.capital only) Google Analytics 4 cookies: _ga (distinguishes visitors with a pseudonymous identifier, expires after 2 years) and _ga_<container-id> (keeps session state, expires after 2 years). terminal.thru.capital does not use analytics.

8.2 When analytics runs

EU/EEA, United Kingdom, Switzerland Opt-in. A banner asks for your consent on your first visit. The Google Analytics script is not loaded, and no analytics cookie is set, unless you select “Accept”. If you select “Decline”, analytics stays off.
All other regions No banner is shown and Google Analytics runs by default. You can switch it off at any time under Manage Preferences.
How your region is determined From the country our edge network (Cloudflare/Vercel) derives from your IP address for each request. The country is used only to decide whether the banner applies and is not stored. If your country cannot be determined, you are treated as being in a consent region.

8.3 Other ways to control cookies

Your choice is stored in this browser only; clearing site data resets it. You can also block or delete cookies in your browser settings, or install Google's Google Analytics opt-out add-on.

9. Manage Preferences

/privacy#manage-preferences

Strictly necessary storage is always on. Analytics is optional, and your choice takes effect immediately in this browser.

Analytics cookies (Google Analytics 4)
Checking your current setting…