Privacy Policy
Last updated: June 15, 2026
Effective June 15, 2026
This Privacy Policy explains how ThinkingDBx Pvt. Ltd. ("ThinkingDBx", "we", "us") collects, uses, and protects personal data when you use ThinkingMemoryCloud (the "Service"). We act as a data controller / data fiduciary for account and usage data, and as a data processor / data processor on behalf of a fiduciary for the content you store ("Your Data"). This Policy is published under the EU/UK GDPR and India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. Data we collect
- Account data — name, email, hashed password, tenant identifier, and login timestamps.
- Usage data — API requests, operation counts, and audit entries used for security, quotas, and billing.
- Content ("Your Data") — the memories and metadata you send to the Service. You decide what to send; please do not store special-category or unnecessary personal data.
- Payment data — handled by our Merchant of Record (Paddle.com Market Ltd.); we do not store full card details.
2. Purposes & legal bases
We process personal data for the following purposes, on these legal bases (GDPR Art. 6 / DPDP lawful uses):
- Provide & secure the Service — performance of our contract with you.
- Enforce plan limits, prevent abuse, meter usage — our legitimate interests and contract.
- Process payments & send transactional email (verification, sign-in, billing) — contract and legal obligation.
- Comply with law and maintain audit records — legal obligation and legitimate interests.
We do not sell your personal data, and we do not use Your Data to train models.
3. Processors & sub-processors
We use a short list of vetted sub-processors, published and kept current at /legal/subprocessors. By default, embeddings are computed locally on our infrastructure, so the content of your memories is not sent to any third-party model provider.
4. International transfers
ThinkingDBx is established in India. Your Data is stored in a managed PostgreSQL database hosted in the United Kingdom (Supabase, on AWS, London region), and our application/compute runs on Contabo GmbH infrastructure in the United Kingdom; our payment provider processes limited account/billing data in the UK/EU. Where personal data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent measures, consistent with the GDPR and the DPDP Act. (Transfers to the United Kingdom benefit from a UK–EU adequacy decision, and are permitted under the DPDP Act.)
5. Retention
We retain account data for as long as your account is active. Content (Your Data) is retained per your plan's retention window; on plans with a finite window, memory that has not been accessed (recalled) within that window is automatically and permanently deleted, while actively-used memories are kept. You can erase your data at any time (Section 6). After account closure we delete or anonymise personal data within a reasonable period, unless a longer period is required by law. Append-only audit records of administrative actions (including deletions) are retained as our compliance trail.
6. Your rights & how to exercise them
Subject to applicable law (GDPR and the DPDP Act) you may request access, correction, deletion, export/portability, restriction, or object to certain processing. The Service provides self-serve tooling for the core rights:
- Access & portability — export everything we store for your account as JSON (
GET /me/export), or per agent (GET /v1/export/agent/{id}). - Erasure — delete all your data (
DELETE /me/data?hard=true) or a single project (DELETE /v1/forget/agent/{id}?hard=true).
You can also email dpo@thinkingdbx.com. We respond within the timeframes required by law. You may withdraw consent where processing relies on consent.
7. Grievance Officer (India DPDP Act)
If you are in India, you may raise any grievance about the processing of your personal data with our Grievance Officer, who will respond within the statutory timeframe:
Mallesh Madapathi
ThinkingDBx Pvt. Ltd., Survey No. 6, 2/91/20, Leeway MR Prime, Kondapur, Serilingampally, Hyderabad – 500084, Telangana, India
Email: grievance@thinkingdbx.com
If your grievance is not resolved, you may complain to the Data Protection Board of India. EU/UK users may lodge a complaint with their local supervisory authority.
8. Security
We apply technical and organisational measures including per-tenant isolation enforced at the database (PostgreSQL row-level security), hashed credentials and API keys, encryption in transit (TLS), encryption at rest on the managed database (AES-256), append-only audit logging, rate limiting, and access controls. No method of transmission or storage is completely secure.
9. Cookies
We use a strictly necessary, httpOnly session/refresh cookie to keep you signed in. We do not use advertising or third-party tracking cookies in the console.
10. Children
The Service is not directed to children under 18 and we do not knowingly collect their data.
11. Changes
We may update this Policy; material changes will be notified via the Service or email.
12. Contact
ThinkingDBx Pvt. Ltd., Survey No. 6, 2/91/20, Leeway MR Prime, Kondapur, Serilingampally, Hyderabad – 500084, Telangana, India · CIN U62011TS2025PTC206211. Privacy enquiries: dpo@thinkingdbx.com. See also our Data Processing Agreement and Sub-processors.