THaiva THaiva
EN PL TH
Open app
  • Home
  • Features
  • Pricing
  • FAQ
  • Support
  • Privacy Notice
  • Cookies and browser storage
EN PL TH
Open app

Legal information

Privacy Notice for the THaiva Public Website

This Notice explains how personal data is handled when the THaiva public website is used. It applies only to the informational website at thaiva.com. The THaiva web and mobile applications are governed by a separate privacy notice.

Version 1.1 · Effective and last revised:18 July 2026

1. Data controller and contact details

The data controller is n8.software Piotr Gnyp, Jędrzychowska 20D, 65-385 Zielona Góra, Poland, Polish tax identification number (NIP): 9292070264, REGON business register number: 521530737 (the “Controller” or “N8 Software”).

THaiva is a product name used by the Controller. It is not a separate legal entity.

Questions concerning privacy or the exercise of data protection rights may be sent to privacy@thaiva.com. Technical support enquiries should be sent to support@thaiva.com.

The Controller has not appointed a data protection officer. Having regard to the current nature and scale of the processing carried out through the public website, the Controller has not identified a legal requirement to make such an appointment. If the circumstances change, the relevant information will be published in this Notice.

2. What this Notice covers

This Notice covers the Polish, English and Thai versions of the THaiva public website, its public guides and the other informational pages made available at thaiva.com.

It does not cover the processing carried out through the THaiva application, including account registration, authentication, profiles, passport or visa information, addresses, journeys, generated documents, notifications or other application features. Those activities are described in the separate privacy notice available within the application.

The public website does not currently provide a contact form, registration form or any field intended for submitting identity, immigration or document data. Links to the THaiva application lead to a separate service governed by its own privacy arrangements.

3. Categories of data processed

3.1. Technical data used to deliver and protect the website

When a visitor connects to the website, the supporting infrastructure may process information required to deliver the requested content, maintain security and investigate technical faults. This may include:

  • the visitor’s IP address and basic network information;
  • the date and time of the request;
  • the requested URL, response code and basic HTTP request metadata;
  • browser, device and operating-system information transmitted in HTTP headers;
  • security signals used to identify abuse, attacks or service failures.

The Controller does not use this information to build advertising profiles.

3.2. Privacy preference stored in the browser

To remember the visitor’s choice regarding optional analytics, the website stores a record in the browser’s localStorage under the key thaiva.landing.consent.v2. The record contains the consent mechanism version, the analytics choice, the time of the most recent update and the interface through which the choice was made.

This record remains on the visitor’s device and is not, by itself, transmitted to the Controller. Its sole purpose is to restore and apply the selected privacy setting on subsequent visits.

3.3. Data collected through Microsoft Clarity after consent

Once prior consent has been obtained, the Controller may activate Microsoft Clarity. The service is used to assess how visitors use the public website and to improve its content, navigation and usability.

Depending on the visitor’s activity and the service configuration, Clarity may process information such as:

  • pages viewed, the referring page and the general navigation path;
  • clicks, taps, scrolling, pointer movements and interaction timing;
  • browser, device, operating-system and screen characteristics;
  • approximate location inferred from network information;
  • pseudonymous browser or session identifiers;
  • data used to generate heatmaps and technical session replays.

A session replay is not a camera recording or a recording of the visitor’s device screen. It is a technical reconstruction generated from page-rendering and interaction data. The Controller uses the content-masking controls made available by the service, and the public website does not provide fields intended for submitting confidential information.

The Clarity script is neither downloaded nor activated before analytics consent has been given.

3.4. Email correspondence

If a visitor contacts the Controller by email, the Controller may process the sender’s details, the contents and metadata of the correspondence, and any information reasonably required to answer the enquiry or handle the request.

Visitors should not send passport scans, visa or residence documents, or other confidential or otherwise sensitive information in an enquiry concerning the public website unless the Controller has specifically requested it and the information is necessary to deal with the matter.

4. Purposes and lawful bases

The Controller processes personal data for the following purposes and on the following lawful bases:

  • delivering the website, maintaining security, preventing abuse and diagnosing incidents – the Controller’s legitimate interests in operating a secure and reliable website under Article 6(1)(f) GDPR and, where a legal duty applies, Article 6(1)(c) GDPR;
  • remembering and applying privacy preferences – providing the setting requested by the visitor; where the locally stored record constitutes personal data, the Controller relies on its legitimate interest in respecting and evidencing the visitor’s choice under Article 6(1)(f) GDPR;
  • Microsoft Clarity analytics – consent under Article 6(1)(a) GDPR and the consent required by Article 399 of the Polish Electronic Communications Law of 12 July 2024 for non-essential storage of, or access to, information on terminal equipment;
  • handling enquiries and correspondence – Article 6(1)(b), (c) or (f) GDPR, depending on the subject of the enquiry;
  • responding to data protection requests and demonstrating compliance – Article 6(1)(c) and (f) GDPR.

Where the law of another jurisdiction applies to a particular person or processing activity, the Controller will use the corresponding lawful basis and safeguards required by that law.

5. Whether providing data is required

Technical information needed to establish the connection is transmitted automatically by the browser and network infrastructure. Without that processing, the website may not be delivered or protected effectively.

Consent to Microsoft Clarity is optional. Refusing or later withdrawing consent does not restrict access to the public website.

Providing information in an email is voluntary. The Controller may nevertheless be unable to give a complete response if information necessary to understand the request is omitted.

6. Recipients of personal data

Personal data may be disclosed only where necessary for the purposes described in this Notice, in particular to:

  • Cloudflare, for hosting, content delivery, network protection and technical logging associated with the public website;
  • Microsoft, in connection with Microsoft Clarity and only after consent has been given; Microsoft states that it acts as a data controller in connection with Clarity;
  • OVHcloud and Google, in connection with domain services and the routing and storage of email sent to addresses within the thaiva.com domain;
  • technical service providers, legal advisers and other professional advisers, to the extent required to provide services to the Controller;
  • public authorities, courts or other authorised bodies where disclosure is required by law or is necessary to establish, exercise or defend legal claims.

The Controller does not sell personal data and does not use data from the public website for its own behavioural advertising.

7. Transfers outside the European Economic Area

Cloudflare, Microsoft and Google operate internationally. Depending on service architecture, routing and support arrangements, personal data may be processed outside Poland or the European Economic Area.

Where the GDPR applies to a transfer, the transfer is made on the basis of an adequacy decision or subject to appropriate safeguards under Chapter V GDPR, such as standard contractual clauses, supplemented where necessary by additional protective measures.

8. Retention periods

  • The privacy preference stored in localStorage remains on the device until the visitor changes the choice, clears the website data in the browser or a materially revised consent mechanism replaces the current version.
  • Technical and security logs are kept only for as long as is reasonably required for website operation, incident detection and investigation, the relevant provider configuration and applicable legal requirements.
  • According to Microsoft’s current documentation, Clarity playback data is retained for 30 days. Click data, heatmap data, and labelled or favourited sessions may be retained for 9 months.
  • Correspondence is retained for the time required to deal with the matter and, where justified, for a further period needed to demonstrate compliance, meet legal obligations or protect against claims.

9. Data protection rights

Subject to the conditions laid down by applicable law, a data subject may request access to, rectification or erasure of personal data, restriction of processing, or data portability, and may object to processing based on the Controller’s legitimate interests.

Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Requests may be sent to privacy@thaiva.com. Where necessary to prevent unauthorised disclosure, the Controller may ask for information reasonably required to verify the requester’s identity.

A complaint may also be lodged with the President of the Polish Personal Data Protection Office (UODO) or, where applicable, another competent supervisory authority. A complaint may be submitted without first contacting the Controller.

10. Managing analytics consent

On a first visit, where no preference has been stored, the website displays controls allowing the visitor to reject optional analytics, accept it or review the detailed settings.

After a choice has been made, the Privacy settings button remains available on the website. It can be used to reopen the panel and change the selection. Withdrawing consent is intended to be as straightforward as giving it.

When analytics consent is withdrawn, the website records the updated choice, notifies Clarity that analytics consent has been denied, removes Clarity cookies accessible to the website on the current domain and reloads the page so that the script is not activated again. Cookies stored exclusively on Microsoft domains cannot be deleted directly by the THaiva website; they can be managed through the browser or Microsoft’s privacy controls.

Further details are provided in the separate Cookies and Browser Storage Notice.

11. Automated decision-making

The Controller does not use the public website to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects for a visitor.

12. Security and external links

The Controller applies technical and organisational measures appropriate to the limited processing carried out through the public website. These include encryption in transit, restricted deployment access, security headers and network-level protection. No method of transmission or storage over the internet can, however, be guaranteed to be completely secure.

The website may contain links to the THaiva application or to websites operated by third parties. Once a visitor follows such a link, the destination service processes personal data under its own privacy information and settings.

13. Changes and language versions

This Notice may be revised when the website, service providers or legal requirements change. A material change affecting optional analytics or the validity of an earlier choice may result in the website requesting consent again.

The Notice is available in Polish, English and Thai. Each version has been drafted using legal and technical terminology appropriate to the relevant language and is not intended as a word-for-word translation. In the event of an interpretative inconsistency, the Polish version serves as the reference version. This does not limit any rights arising under mandatory law.

This Notice applies only to the THaiva public website. Processing carried out through the THaiva application is covered by the separate privacy notice available in the application.

THaiva THaiva

Public information website for the THaiva product.

© 2026 N8 Software. THaiva is a product of N8 Software. All rights reserved.

Home Features Guides Support Privacy Notice Cookies and browser storage

Privacy settings

We store a necessary privacy preference in your browser. With your consent, Microsoft Clarity may help us understand how the public website is used and improve its usability. Privacy Notice · Cookies and browser storage.

THaiva

Privacy preferences

Choose whether Microsoft Clarity may be used for optional analytics. A necessary local preference remains stored so that the website can apply your choice on later visits.

Necessary

Always active

Stores only the privacy setting required to apply your choice on later visits. It does not measure website activity and cannot be disabled in this panel.

Analytics

Microsoft Clarity may analyse navigation, clicks, scrolling and other session interactions to help improve the public website. Its script is not loaded before consent.

Privacy NoticeCookies and browser storage