Effective Date: September 25, 2026 • Entity: Sukrano oy (Registered in Republic of Estonia) • Contact:[email protected]
1. Data Controller & Scope
/privacy#controller
Sukrano oy ("Company", "we", "us", "our") acts as the Data Controller under the General Data Protection Regulation (EU GDPR 2016/679), the UK Data Protection Act, and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) for personal data processed through thru.capital and terminal.thru.capital.
2. Principles of Data Minimization
/privacy#minimization
We operate under strict privacy-by-design and data minimization protocols:
Zero Data MonetizationWe never sell, rent, monetize, or trade your personal data with third-party advertisers or data brokers.
Zero Payment Card ExposureRaw credit/debit card numbers and CVVs are transmitted directly to Stripe under PCI-DSS Level 1 certification. We never store or view raw card data.
Non-Custodial CryptoOn-chain USDC settlements are push-based. We never request, collect, or store your private cryptographic keys or seed phrases.
3. Categories of Data Collected
/privacy#data-collected
Account IdentifiersEmail address collected upon authentication via email OTP, paired with a pseudonymous Supabase UUID (user_id).
Billing & InvoicingStripe customer identifiers, blockchain transaction hashes (TXIDs), deposit addresses, and payment timestamps required for entitlement provisioning and tax accounting.
Edge DiagnosticsIP addresses, browser user-agents, and request timestamps captured transiently by edge gateways (Cloudflare/Vercel) for DDoS mitigation and rate-limiting.
Market InquiriesInquiry text submitted to the market investigation engine for telemetry synthesis, together with your account email and tier, is also logged to our private operator notification channel (Telegram) for service monitoring. Inquiries are not used to train generalized LLMs.
Contact RequestsEmail address, institution name, use case, and notes submitted through the API access request form, delivered to our private operator notification channel (Telegram).
Usage Analytics (thru.capital only)When analytics is enabled for you (see section 8), Google Analytics 4 records pages viewed, referrer, approximate location (derived from IP, which Google does not store), device and browser type, and a pseudonymous client identifier.
4. Lawful Bases for Processing (GDPR Art. 6)
/privacy#lawful-basis
Consent (Art. 6(1)(a))Analytics cookies on thru.capital (Google Analytics 4) for visitors in the EU/EEA, the United Kingdom and Switzerland. Consent is optional, requested before any analytics script loads, and can be withdrawn at any time under Manage Preferences.
Contractual Necessity (Art. 6(1)(b))Processing email auth, session tokens, and subscription entitlements to deliver the SaaS service.
Legal Obligation (Art. 6(1)(c))Retaining financial transaction records for statutory compliance with Estonian commercial accounting and VAT directives.
Legitimate Interests (Art. 6(1)(f))Protecting edge infrastructure against cyberattacks, automated scraping, and unauthorized service exploitation; operator monitoring of contact requests and terminal inquiries.
5. Authorized Sub-Processors
/privacy#subprocessors
We work exclusively with enterprise sub-processors maintaining SOC 2 Type II / ISO 27001 certifications and Standard Contractual Clauses (SCCs):
Supabase Inc.Passwordless authentication, JWT bearer management, and session state.
Stripe Inc.PCI-DSS Level 1 fiat payment processing and automated subscription management.
Google Cloud / DeepMindGemini API for real-time market microstructure synthesis (zero customer prompt retention for training).
Google LLC (Google Analytics 4)Website usage analytics on thru.capital, loaded as described in section 8. Transfers to the USA under the EU–US Data Privacy Framework and SCCs.
Telegram FZ-LLCPrivate operator notifications for contact requests and terminal inquiry logs (email, tier, inquiry text). Not used for marketing.
Vercel Inc.Serverless web application deployment and edge API endpoints.
6. Data Retention & Erasure
/privacy#retention
Account IdentifiersRetained while your account remains active. Deleted within 30 days of a verified erasure request.
Financial Audit RecordsRetained for up to 7 years in compliance with the statutory requirements of the Estonian Accounting Act and EU tax directives.
Network Edge LogsIP and security logs are automatically rotated and purged after 90 days.
Analytics DataGoogle Analytics event data is retained for a maximum of 14 months. Analytics cookies expire after at most 2 years, or immediately when you switch analytics off under Manage Preferences.
7. Your Data Protection Rights
/privacy#rights
Under GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data.
To exercise your rights, submit a written request to [email protected]. We verify identity and respond within 30 days without charge. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee).
8. Cookie & Analytics Policy
/privacy#cookies
This policy explains which cookies and browser storage thru.capital uses, why, and how you control them. We do not use advertising, retargeting, or cross-site behavioral tracking cookies, and we never sell analytics data.
8.1 What we store
Strictly Necessary (no consent required)LocalStorage entries that remember your theme and your analytics choice (thru_theme, thru_consent), and a SessionStorage entry that remembers, for the current tab only, whether the consent banner applies in your region (thru_consent_region). Sign-in happens only on terminal.thru.capital, and your session is kept in terminal.thru.capital's own LocalStorage, which thru.capital cannot read; thru.capital stores no session data.
Analytics (optional, thru.capital only)Google Analytics 4 cookies: _ga (distinguishes visitors with a pseudonymous identifier, expires after 2 years) and _ga_<container-id> (keeps session state, expires after 2 years). terminal.thru.capital does not use analytics.
8.2 When analytics runs
EU/EEA, United Kingdom, SwitzerlandOpt-in. A banner asks for your consent on your first visit. The Google Analytics script is not loaded, and no analytics cookie is set, unless you select “Accept”. If you select “Decline”, analytics stays off.
All other regionsNo banner is shown and Google Analytics runs by default. You can switch it off at any time under Manage Preferences.
How your region is determinedFrom the country our edge network (Cloudflare/Vercel) derives from your IP address for each request. The country is used only to decide whether the banner applies and is not stored. If your country cannot be determined, you are treated as being in a consent region.
8.3 Other ways to control cookies
Your choice is stored in this browser only; clearing site data resets it. You can also block or delete cookies in your browser settings, or install Google's Google Analytics opt-out add-on.
9. Manage Preferences
/privacy#manage-preferences
Strictly necessary storage is always on. Analytics is optional, and your choice takes effect immediately in this browser.
Analytics cookies (Google Analytics 4)
Checking your current setting…
We use Google Analytics cookies to understand site usage, only if you allow it.
Cookie & analytics policy