Privacy Policy
Version of 23 September 2026.
This policy explains what we do with personal data — and, just as importantly, what we deliberately do not do with it.
1. Controller
Thalassa Consulting Kft., Dózsa György út 37, 1188 Budapest, Hungary
Company registration number (cégjegyzékszám) 13 09 200621,
tax number (adószám) 23892543-2-43,
represented by Patrik Talasi, Founder and CEO.
All privacy requests: info@thalassa-consulting.com. We have not appointed a data protection officer, as none is legally required for our size and activity.
2. The short version
Your meeting audio is not stored. It is streamed for transcription and discarded. We do not keep recordings, we do not build a transcript archive, and we do not use your conversations to train any model.
Your documents are searched on your device. The knowledge base you upload is indexed locally on your own computer. The files themselves are never transmitted to us.
Everything we do run, runs in the EU.
3. What we process, why, and on what basis
3.1 Account data
E-mail address, password hash, subscription status, usage counters. Purpose: providing the service and billing. Legal basis: Art. 6(1)(b) GDPR — performance of a contract. Retention: for the life of the account, then deleted; invoicing records are kept for eight years — the period required by § 169(2) of the Hungarian Accounting Act (Act C of 2000).
3.2 Meeting audio and transcripts
Audio from conversations you run through the application is transmitted to our speech-recognition processor, converted to text, and used to generate answers. That processor is Deepgram, Inc., and we use its European endpoint, so the audio stream is processed in the EU. Legal basis: Art. 6(1)(b) GDPR.
Retention: none. Audio is processed in transit and not written to durable storage by us. Transcripts exist in the application's memory during the session and are gone when it closes, unless you yourself save a report locally.
Conversations may contain personal data of other participants. You are responsible for having a legal basis to record or transcribe them — see section 2 of our Terms of Service.
3.3 Rehearsal (practice conversations)
Rehearsal is a practice conversation against a language model that plays the other side — an interviewer, a client, an investor. It is included in every paid plan and ticket, and draws on the same meeting-hours as a real conversation; it is not sold separately.
What is processed: the questions the model generates, the answers you type or dictate, and the coaching debrief at the end. Dictation uses the same path as section 3.2 — the audio goes to Deepgram, Inc. through its European endpoint, using a short-lived token issued per recording. Your answers and the debrief go to the same language model described in section 3.4. If you attach documents from your own knowledge base, they are used as the source for questions or as the yardstick for your answers.
Unlike section 3.2, no one else is involved. A rehearsal has no other participants, so it raises none of the third-party questions a recorded meeting does. Legal basis: Art. 6(1)(b) GDPR. Retention: none — rehearsal content has no database table.
3.4 Prompts sent to language models
To generate an answer, the relevant part of the transcript is sent to a language model acting as our processor. We use Claude models from Anthropic, run on Amazon Bedrock in the EU, operated by Amazon Web Services EMEA SARL. Bedrock does not use the content to train models, and neither do we. The permitted regions are enforced in our source code: a deployment outside them fails rather than quietly falling back elsewhere.
3.5 Answers that use a web search
Most answers come from the documents in your own knowledge base, which are searched on your device (see 3.7 for the one exception at ingest).
Where an answer cannot be supported from them and web search is switched on, a search query derived from your question is sent to a search provider. This is the one processing step that leaves the European path, and it is the reason we name it here rather than in a footnote. The query contains what is needed to search, not your documents and not the transcript. You can switch web search off, and the application marks which answers used it.
Since 6 September 2026 the same applies when you prepare a briefing: there you switch web search on per briefing, not globally. What is searched are organisations — companies, authorities, associations. Searching for people is ruled out; the individuals you are meeting are not researched. That restriction is a binding instruction to the model that formulates the query. In the conversation types legal advice and compliance web search is blocked and cannot be switched on: a client's matter or an audit's subject does not belong in a search query. That block is not an instruction but a condition in the program — it holds even when the switch is set. When web search is on for a briefing, the document says so at its head, and every item taken from the web carries the mark [Web] with the date it was retrieved.
The search provider is Anthropic PBC (USA), through its web search tool. We name it rather than write "a search provider", because an unnamed recipient in a third country is precisely the detail this page exists to give you. Amazon Bedrock cannot run a web search, which is why this is the one step for which we call the Anthropic interface directly. Legal basis: Art. 6(1)(b) GDPR — web search is part of the service you request, and it stays switchable. The transfer to the USA is covered by the European Commission's Standard Contractual Clauses together with supplementary technical measures.
3.6 Live translation
Live translation is an optional, separately paid feature.
It is off unless you switch it on. When it is on, what the other side says is sent to DeepL SE for translation while the meeting runs. This is the second processing step that can leave the European path, and it is the reason we name it here rather than in a footnote: DeepL is a German company, but guaranteed processing inside the EU is a contractual feature of its Team, Business and Enterprise plans, not a property of the product as such. Switch translation off and the promise that nothing leaves the European path holds without exception.
Legal basis: Art. 6(1)(b) GDPR — translation is the service you separately ordered. Where the plan means processing leaves the EU, the transfer is covered by the European Commission's Standard Contractual Clauses.
3.7 Text recognition for scanned documents
Your knowledge base is read, indexed and searched on your device.
A scanned PDF is the one exception, and it happens at ingest, not during a conversation: such a file contains pictures of text rather than text, so each page is sent as an image to our backend in Frankfurt, where it is passed to Anthropic's model for text recognition. The recognised text then returns to your device, and everything after that step — indexing, searching, answering — is local again.
This step stays inside the European path; unlike web search and live translation it does not leave it. It is named here because part of your knowledge base leaves your machine here, and because someone working with client files should decide it consciously rather than discover it. The second such step is enrichment at ingest, see 3.8. Legal basis: Art. 6(1)(b) GDPR, performance of the contract. A cache keyed to the file and page prevents the same page being sent twice. Page images are not retained after recognition and are not used to train any model.
Text recognition can be switched off. With it off, a scanned file is reported as an image without a text layer instead of silently producing nothing. With text recognition and enrichment (3.8) both off, no part of your knowledge base leaves your device at any point.
3.8 Enrichment at ingest
So that searching your knowledge base still finds the right passage when you ask in different words than the document uses, every section is given a short summary, typical questions and keywords as it is ingested.
These additions feed the search only, never the answers. To produce them, the text of that section is sent to our backend in Frankfurt and passed to a model by Anthropic. The result returns to your device; embedding, searching and answering are local again.
This step, too, stays inside the European path. Unlike 3.7 it concerns not only scanned files but every document you ingest — which is why it is a section of its own rather than a clause. Legal basis: Art. 6(1)(b) GDPR, performance of the contract. A cache on your device, keyed to the content of the section, prevents the same section being sent twice; re-ingesting an unchanged document costs no further transmission. Section texts and results are not stored on the server and are not used to train any model.
Enrichment can be switched off (KB_ENRICH=0). Your
sections are then made searchable without these additions — search
hits slightly less often, and no section text leaves your device.
Supplying your own Anthropic key achieves the same by another route:
enrichment then runs directly from your device, without passing
through our backend.
3.9 Compliance module: jurisdiction selection, your own documents, and the debrief
The Compliance module processes two things that may touch professional secrecy and banking secrecy: the documents you store as your own knowledge base — internal policies, contracts, the outsourcing register — and the question that arises during the call.
Both run on the same EU-isolated path as the legal module: processing in the EU, pseudonymisation before any transfer to a language model, no training on your content.
Retrieving a public legal source is not, in itself, processing of personal data — a statute contains none. The search query may contain some, however, for instance when a name or a contract reference ends up in a search term. The connectors therefore receive only individual, length-limited search terms and never conversation content; terms that look like running text are rejected. They are transmitted to the official body concerned (EUR-Lex, eCFR, dfs.ny.gov). Legal basis: Article 6(1)(b) GDPR.
The debrief — the list of provisions named during the call, with citation and version date — is stored in your account so that you can present it to an examiner. It is deleted after 24 months, earlier on your request. It contains citations, not the content of the conversation.
MCP connections to your own sources. The additional connector retrieves approved text resources from compatible MCP servers via Streamable HTTP and can call tools that a provider you connect offers; every tool call is shown to you for confirmation beforehand and may, depending on the provider, read or change information in that system. Connections you configure yourself; data goes to the destination you choose. The desktop app connects directly to that server and indexes and searches the retrieved text on your device. Selected excerpts for answers and briefings follow the existing request path through Thalassa's backend and the configured model service; the connector does not create a server-side document store. Supported connections and setup.
3.10 Website and analytics
Server logs (IP address, time, page) for security and troubleshooting on the basis of Art. 6(1)(f) GDPR.
There is currently no product analytics on this website. No analytics or counting script is loaded, no tracking pixel is fetched, and no cookie is set for that purpose. This paragraph used to say the opposite; it described an intention, not the state of the site. If measurement is added, the provider will be named here before its first script loads.
3.11 The chat assistant on this website
If you open the chat window and ask a question, we process the text of that question, the messages exchanged in that conversation, the language of the page, your IP address and a session identifier your browser generates. Legal basis: Art. 6(1)(f) GDPR — answering questions about our product, and protecting the service from abuse.
The question is answered by a Claude model from Anthropic, run on Amazon Bedrock in the EU by Amazon Web Services EMEA SARL. This is the same path, under the same rules, as described in 3.4: Bedrock does not use the content to train models and does not retain it. The chat runs under the same privacy rules as the rest of the product — it is not a separate, laxer service.
So that the chat also understands questions worded differently from our pages, Amazon Titan Text Embeddings additionally turns the text of your question into a sequence of numbers (a so-called vector). This also runs on Amazon Bedrock, in Frankfurt am Main (AWS region eu-central-1), by the same processor and under the same rules: the question is not stored there and is not used for training. The vector serves only to find the matching passages of our pages and is discarded afterwards.
We do not store your conversation. The content of your questions and of the answers is not written to any log of ours. Your IP address and session identifier are held in the memory of the chat service alone, solely to limit how many questions can be asked in a given period; they drop out of that count after 24 hours at the latest and are lost whenever the service restarts. The chat service is hosted by Vercel with its function in Frankfurt; Vercel keeps technical request data (time, address, status) as server logs, without the content of your messages.
The chat window keeps two values in your browser: an identifier for the current conversation and a note that the window has been opened once. Both are strictly necessary for the chat you asked for, both stay on your device, and both are gone when you close the tab. No cookies are set.
4. Payments
Purchases are handled by Stripe. We never see or store your card or bank details: they are entered on Stripe's own payment page and stay with Stripe.
We sell through Stripe Managed Payments. Stripe, not Thalassa Consulting Kft., is the merchant of record. The seller shown on your receipt and on your card statement is Link, and the transaction is acquired by Stripe Payments Company or, for customers in Europe, by Stripe Technology Europe, Limited (Ireland). Stripe calculates, collects and remits VAT, sends your invoice and receipt, and handles payment- and subscription-related support. You can view your order history, cancel or change a subscription and update your payment method at link.com.
What we pass to Stripe when you buy: an internal account reference, the product and billing period you selected, and your email address. What Stripe collects directly from you: your name, billing address, payment details, and anything you share with its support. What we receive back: that a payment happened, the amount and currency, customer and transaction identifiers, and subscription status. We do not receive payment details.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and, for the retention of billing records, Art. 6(1)(c) (legal obligation). Because Stripe operates globally, the transfer safeguards described in the next section apply.
5. Where the data is
Our infrastructure runs in the European Union. Our backend is in eu-central-1 (Frankfurt); answer generation is routed inside the EU. This is not merely a policy statement: the permitted regions are enforced in our source code, and a deployment outside them fails.
Not every processor sits in the EU. So here is who they are, where they sit, and what carries the transfer — we would rather name them than make you ask:
- speech recognition by Deepgram, Inc. (USA), through its EU endpoint
- answer generation by Anthropic Claude models on Amazon Bedrock (EU-Regionen), operated by Amazon Web Services EMEA SARL
- hosting and operations by Amazon Web Services (eu-central-1) and Vercel (Frankfurt)
- payments by Stripe
- e-mail delivery and mailboxes by Proton AG (Switzerland) — messages from the contact form and correspondence with our addresses run through it
- translation — only when you switch it on — by DeepL SE (Germany)
- web search — only for answers and briefings that use it, and only for organisations — by Anthropic PBC (USA)
Transfers to the USA are covered by the European Commission's Standard Contractual Clauses together with supplementary technical measures. Switzerland does not need them: the European Commission has found that Switzerland provides an adequate level of data protection, so the transfer rests on Art. 45 GDPR rather than on contractual clauses. If that list changes, this page changes with it.
6. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw consent at any time with effect for the future.
Write to info@thalassa-consulting.com. We answer within one month. Account deletion is also available directly in the application and removes your data without us needing to act.
One thing deletion cannot do is end a running paid subscription. The purchase contract is with Stripe, not with us (see section 4), and we cannot cancel it there. A button that claimed otherwise would leave you with a deleted account and a live charge. So cancel first at link.com; deletion is available immediately afterwards. A free or promotional access does not block it.
7. Right to complain
You may lodge a complaint with a supervisory authority, in particular in the Member State of your residence or workplace. The authority competent for us is:
Hungarian National Authority for Data Protection and Freedom of Information
(Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH))
Falk Miksa utca 9-11, 1055 Budapest, Hungary
https://naih.hu ·
ugyfelszolgalat@naih.hu
8. Security
Transport encryption throughout, encryption at rest for stored account data, access on a need-to-know basis, and a screen-capture exclusion so the assistant window does not appear in shared screens. No system is perfectly secure, and we will not claim otherwise.
9. Changes
We will publish changes here and notify registered users of material changes by e-mail.