Privacy Policy
THRIVE GLOBAL PRIVACY POLICY
Last Updated: August 20, 2026
At Thrive, we are committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how Thrive Operations, LLC and its affiliates worldwide (“Thrive,” “we,” “us,” or “our”) collect, use, share, and protect your personal information. This policy applies to information collected through our websites, customer portals, managed IT services, cybersecurity services, managed AI services, and all other services we provide.
We operate globally with entities and clients in the United States, United Kingdom, European Union, Canada, Singapore, Hong Kong, Philippines, and Australia. Depending on where you are located, different sections of this policy may apply to you, and we have included region-specific information where applicable.
This Privacy Policy applies to personal information that Thrive collects and processes, including:
- Visitors to our websites where this policy is posted;
- Individuals who apply for a job to work at Thrive;
- Current, former, and prospective customers, vendors, and partners;
- Individuals who subscribe to receive news, marketing communications, or event invitations from us; and
- Individuals who communicate with us or engage with us through any channel.
1. INFORMATION WE COLLECT AND SOURCES OF INFORMATION
We collect different types of information depending on how you interact with us, which include the following:
- Contact information, such as name, email address, mailing address, and telephone number; including business contact records
- Account information, such as username, password, and account preferences.
- Business information, such as company name, business address, industry type, and billing information.
- Technical information, such as IP addresses, hostnames, geographical location, browser type, device identifiers, operating system, and information about how you use our websites and services.
- Service-related information, which is information necessary to provide our managed IT services, cloud hosting services, cybersecurity services, consulting and advisory services, and managed AI services, which may include system access credentials, log files, network traffic data, configuration data, and system settings.
- Employment information. If you apply for a job with us, we collect resume/CV information, employment history including prior job titles and dates of employment, educational background, right to work information such as visa or citizenship status (only where required and permitted by law), and any other information you provide in your application. Where permitted by law and with your consent, we may collect information through pre-employment background checks conducted by authorized third-party vendors. This may include verification of employment history, educational credentials, criminal records (where legally permitted), and professional references.
- Information submitted to us, such as if you email or call us, we collect the information you provide to us in the message or phone call.
We collect information from you in the following ways:
- Directly from you: When you fill out forms on our website, create an account, contact us by phone, email, or chat, attend our events, or otherwise provide information to us. For clarity, with respect to current and former clients, this includes information entered into a support case, incident, or request.
- Automatically: Through cookies, web beacons, log files, and similar technologies when you visit our websites or use our online services.
- From third parties: Including marketing partners (including within legitimately purchased marketing lists), data providers, social media platforms (such as LinkedIn), recruiting platforms (such as Indeed, LinkedIn, or Glassdoor), event co-sponsors, and publicly available sources.
- From your employer or organization: If you interact with us on behalf of a business customer, your employer may provide us with your business contact information.
- From Thrive affiliates: Our affiliated companies may share information with us to provide coordinated services.
2. HOW WE USE YOUR INFORMATION
We use your personal information for the following purposes:
- Performance of a Contract: To carry out our contractual obligations including delivering our managed IT services, cybersecurity services, managed AI services, and to provide customer support. Contractual obligations may also include processing and filling orders for products and services, and invoicing for products and services.
- To Communicate with You: To respond to inquiries from you, send order statues and service updates, circulate newsletters/blog updates/other marketing communications, and send notices about your account.
- To Improve Our Services: To evaluate and improve our business, such as by performing data analytics such as research, trend analysis, and website enhancement; developing and improving our product and service offerings; and performing accounting, auditing, billing, and other financial activities. We do not use your personal information to build, develop, or train artificial intelligence or machine learning models.
- For Marketing and Advertising: To market, advertise, and sell our products and services including by sending promotional materials, generating and pursuing leads, managing our brand, launching campaigns, running events or programs, and sending out surveys.
- To Consider You for Employment: If you apply for a job with us, to evaluate your application, review your qualification, to verify information, to conduct interviews or assessments, and to prepare employment documents for you.
- For Security: To protect our system, detect and prevent fraud, and to ensure the security of our services and your data.
- For Legal Compliance: To comply with legal obligations, regulatory requirements, applicable industry standards, and our internal policies.
We only process your personal information when we have a valid legal basis to do so. Depending on the circumstances and your location, this may include: your consent, performance of a contract with you or an applicable third-party, compliance with legal obligations, protection of vital interests, exercise or defense of a legal claim, or our legitimate business interests (where not overridden by your rights).
3. HOW WE SHARE YOUR INFORMATION
We may share your personal information in the following circumstances:
- With Our Employees and Personnel: We share information with our internal employees and personnel to the extent necessary to perform services, respond to any contact by you, or review your job application.
- With Service Providers: We share information with companies that help us operate our business, such as cloud hosting providers, payment processors, and customer support platforms. These providers are contractually obligated to protect your information and may only use it to provide services to us.
- With Subprocessors: We engage third-party subprocessors to assist in providing our services. A list of our current subprocessors, including their names, functions, and locations, is available upon request by contacting privacy@thrivenextgen.com. We require that all subprocessors enter into data processing agreements that impose confidentiality and security obligations consistent with this Privacy Policy and applicable law.
- With Our Subsidiaries: We may share information with Thrive’s subsidiaries worldwide to provide coordinated services and support.
- For Business Transfers: If Thrive is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and your choices.
- For Legal Reasons: We may disclose your information when required by law, in response to valid legal requests by public authorities (including national security or law enforcement requirements), to protect our rights or property, or in emergencies involving potential threats to safety.
- With Your Consent: We may share your information with third parties when you give us permission to do so.
We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes without your explicit consent.
4. INTERNATIONAL DATA TRANSFERS
Because we operate globally, your personal information may be transferred to and processed in countries other than where you live. These countries may have different data protection laws than your country of residence.
Thrive may transfer personal data to countries that benefit from an adequacy decision by the European Commission or the UK Secretary of State. For transfers to countries not covered by an adequacy decision, we use appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or other legally recognized mechanisms to ensure your data is protected.
5. YOUR PRIVACY RIGHTS
Depending on where you live, you may have certain rights regarding your personal information that we process. Please refer to the region-specific privacy information in Section 11 below for further information.
To exercise any of these rights, please contact us at privacy@thrivenextgen.com. We will acknowledge your request and respond fully within the timeframe required by applicable law (typically within 30 to 45 days, depending on your jurisdiction).
To protect your personal information and prevent unauthorized access, we must verify your identity before processing your request. We may ask you to provide two or three pieces of identifying information (such as your name, email address, copies of government issued identification documents, and account details) that we can match against our records. For sensitive requests such as deletion, we may require additional verification steps. If we cannot verify your identity, we will explain why and what additional information is needed. Information collected for verification purposes will only be used for that purpose.
You may designate an authorized agent to submit privacy requests on your behalf. Authorized agents must provide: (1) written permission signed by you authorizing the agent to act on your behalf, or (2) a valid Power of Attorney under applicable law. We may require you to verify your identity directly and confirm that you authorized the agent to act on your behalf. To submit a request through an authorized agent, please contact us at privacy@thrivenextgen.com with the subject line “Authorized Agent Request.”
6. DATA SECURITY
We take the security of your personal information seriously. We implement appropriate technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit using industry-standard protocols, access controls, regular security assessments, and employee training.
Thrive maintains SOC 2 Type 2 and ISO 27001 certifications and undergoes regular internal and external security audits. While we strive to protect your personal information, no method of transmission over the internet or electronic storage is completely secure or error-free, and these safeguards and processes could be subject to compromise. Thrive cannot guarantee against any loss; misuse; unauthorized disclosure, alteration, or destruction of data or personal information. Accordingly, Thrive cannot be held responsible for unauthorized or unintended access that is beyond our control.
7. DATA RETENTION
We retain your personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy. Retention periods vary depending on the nature of the information, the purposes for which it was collected, and our legal and operational requirements. In determining how long to retain information, we consider factors including:
- The purposes for which we collected the information and whether those purposes have been fulfilled;
- Our legal, regulatory, accounting, and tax obligations, which may require retention for specified minimum periods;
- Whether the information is needed to establish, exercise, or defend legal claims or to resolve disputes;
- Legitimate business needs, including maintaining appropriate records for audit, compliance, and operational purposes; and
- Any applicable contractual obligations or industry-specific requirements.
When personal information is no longer needed for any of the above purposes, we will securely delete or anonymize it in accordance with our data retention policies and applicable law.
8. COOKIES AND TRACKING TECHNOLOGIES
Our websites use cookies and similar technologies to enhance your experience, analyze usage, and support our marketing efforts. Cookies are small text files stored on your device when you visit a website.
Types of Cookies We Use: The following table describes the cookies we use:
- Essential Cookies: These cookies are necessary for our website to function properly and cannot be disabled. They enable core functionality such as security, network management, and accessibility. Examples include session cookies that remember your login status and cookies that remember your cookie consent preferences.
- Analytics/Performance Cookies: These cookies help us understand how visitors interact with our website by collecting information anonymously. For visitors in the United Kingdom, the DUAA permits analytics cookies that do not identify individual users to be placed without consent.
- We use Google Analytics, which places cookies (ga, _gid) to track visitor behavior. The _ga cookie expires after 2 years; the _gid cookie expires after 24 hours. This data helps us improve website performance and user experience. To learn more about Google Analytics cookies, visit https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage.
- We also use Cookie Consent plugin, which places cookies (viewed_cookie_policy, wordpress_test_cookie) to record that you accept the fact that our website uses cookies. These cookies expire after 1 year unless you manually clear your cache.
- Marketing/Advertising Cookies: These cookies are used to deliver advertisements relevant to your interests and to measure the effectiveness of our advertising campaigns. They may be placed by us or by third-party advertising partners. These cookies track your browsing activity across websites and may be used to build a profile of your interests. You can disable or opt out of these cookies through our Cookie Preference Manager.
- Functional Cookies: These cookies enable enhanced functionality and personalization, such as remembering your language preference, location, or customized settings. You have the right to disable or opt-out of these cookies. If you disable these cookies, some features may not work properly.
You can control the use of cookies at the individual browser level by choosing to have your computer warn you each time a cookie is being sent or turning off all cookies via your browser settings. Like most websites, if you turn your cookies off, some of our website features or services may not function properly.
UK Cookie Consent: For visitors in the United Kingdom, the Data (Use and Access) Act 2025 amended the Privacy and Electronic Communications Regulations to provide exemptions from consent requirements for certain cookies. Analytics cookies that do not identify individual users and cookies strictly necessary for website functionality may be placed without consent. Marketing and advertising cookies continue to require your consent.
Do Not Track Signals: Some web browsers offer a “Do Not Track” (DNT) setting. Because there is no industry standard for DNT signals, our website does not currently respond to DNT browser signals. However, we do honor Global Privacy Control (GPC) signals as described above.
9. CHILDREN’S PRIVACY
Our services are not intended for or directed at children under the age of 16 (or such younger age as may be permitted under applicable law). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@thrivenextgen.com, and we will take steps to delete such information.
10. THIRD-PARTY WEBSITES AND SOCIAL MEDIA
Thrive maintains official company pages on third-party social media platforms, including X (formerly Twitter), Facebook, LinkedIn, Instagram, and YouTube. Thrive does not host or operate social media features (such as “Like” buttons, share widgets, or embedded feeds) directly on its website. Instead, our website provides links to our official social media pages. When you click on a link to one of our social media pages, you will be directed to a third-party platform that is owned and operated by that social media company. Thrive may collect and use information you make publicly available on social media platforms, such as your name, profile picture, and comments, in accordance with this Privacy Policy and applicable law. Your interactions on those platforms (including any information you view, post, share, or otherwise provide) are governed solely by the privacy policy and terms of service of that social media company, not by this Privacy Policy. The social media company may collect information about you, including your IP address, browser type, device identifiers, pages visited, and your interactions with content. We have no control over and assume no responsibility for the data collection, use, or sharing practices of these third-party platforms. We encourage you to review the privacy policies of these platforms before interacting with our social media pages.
We may use third-party chat services to provide real-time customer support. If you use our online chat function, we may record and retain the contents of your chat session. This information is used to respond to your inquiries, improve our services, and may be shared with our chat service provider solely to enable the service.
11. REGION-SPECIFIC INFORMATION
For California Residents (CCPA/CPRA):
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). These include the right to know what personal information we collect and how we use it, the right to delete your personal information, the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information (we do not sell personal information), and the right to limit the use of sensitive personal information. We do not use or disclose sensitive personal information for purposes beyond what is necessary to provide our services. You may designate an authorized agent to make a request on your behalf.
Categories of Personal Information We Collect (CCPA Disclosures): Under the California Consumer Privacy Act, we are required to disclose the categories of personal information we collect. The personal information we collect and process varies depending on the nature of our relationship with you. In the preceding 12 months, we may have collected the following categories of personal data about California residents:
- Identifiers (such as name, email address, IP address, account name);
- Personal information as defined in California Civil Code Section 1798.80(e) (such as name, address, telephone number, financial information);
- Commercial information (such as records of products or services purchased);
- Internet or other electronic network activity information (such as browsing history, search history, website interactions);
- Geolocation data (such as city, state, or country derived from IP address);
- Professional or employment-related information (such as job title, employer); and
- Inferences drawn from the above categories.
We collect this information from you directly, automatically through your use of our services, and from third-party sources such as marketing partners and publicly available sources. We use this information for the business and commercial purposes described in Section 2 above.
Categories of Personal Information Disclosed for Business Purposes: We may disclose the above categories of personal information to service providers, affiliates, business partners (with your consent), and as required by law. We do not sell personal information as traditionally defined. We may share identifiers and internet activity information with advertising partners through cookies, which may constitute “sharing” under CPRA.
- Right to Know/Access: You can request information about the personal data we hold about you and receive a copy of that data.
- Right to Correct: You can request that we correct inaccurate personal information we hold about you.
- Right to Delete: You can request that we delete your personal information, subject to certain exceptions required by law.
- Right to Opt-Out: You can opt out of the sale or sharing of your personal information (note: we do not sell personal information), and you can opt out of certain uses such as direct marketing at any time.
- Right to Limit Use of Sensitive Information: You can request that we limit our use of your sensitive personal information to what is necessary for providing services.
- Right to Data Portability: Where technically feasible, you can request a copy of your personal data in a structured, commonly used format.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Sensitive Personal Information: We may collect certain categories of sensitive personal information, including account login credentials (username and password) and payment card information for processing transactions. We do not use or disclose sensitive personal information for purposes other than those permitted under CPRA, such as providing the services you request. You have the right to limit our use of sensitive personal information.
For European Economic Area, United Kingdom, and Switzerland Residents:
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and equivalent local laws. Subject to the conditions and limitations set forth in applicable data protection laws, you have the following rights:
- Right to access: to request access to and receive a copy your personal information we hold about you.
- Right to Rectification: to request correction of inaccurate or incomplete data.
- Right to Erasure: to request deletion of your data where there is no longer a lawful basis for processing.
- Right to Restriction of Processing: to request that we limit how we use your data in certain circumstances.
- Right to Object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw: to withdraw your consent to the processing and use of your personal information completely or partially.
- Right to Portability: to obtain a copy of your personal information in a format that is portable to a technically reasonable extent, readily usable to a practical extent, and enables you to transmit the personal information to another entity reasonably easily if the processing is carried out by automated means.
- Right to Complain: to complain to the responsible supervisory authority if you believe that the processing of your personal information is in violation of applicable law. You may submit a complaint by contacting us at privacy@thrivenextgen.com. We will acknowledge your complaint within 30 days and aim to provide a final outcome within three months, unless exceptional circumstances apply. Decisions will be communicated in plain, accessible language. If your complaint remains unresolved, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at https://ico.org.uk/.
To exercise your privacy rights under the GDPR, please email privacy@thrivenextgen.com. You may be subject to a reasonable fee to meet our costs related to providing details of personal information we hold about you. Before responding to a request for your personal information under applicable data protection laws, we must verify the request and may ask for identifying information to reasonably verify your identity.
Data Processing Agreements
For clients who require formal data processing terms, Thrive offers Data Processing Agreements that address GDPR, UK GDPR, and other applicable data protection requirements. To request a Data Processing Agreement, please contact privacy@thrivenextgen.com or your Thrive account representative.
UK Data (Use and Access) Act 2025 Compliance
Thrive complies with the UK Data (Use and Access) Act 2025 (DUAA), which amends the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and Privacy and Electronic Communications Regulations. Under the DUAA:
- Recognized Legitimate Interests: The DUAA introduces a “recognised legitimate interests” lawful basis for certain processing activities, including safeguarding vulnerable individuals, security and defense, crime prevention, and emergencies. Where Thrive relies on recognised legitimate interests for processing, no separate balancing assessment is required under UK law.
- Automated Decision-Making: Under the DUAA, Thrive may rely on a broader range of lawful bases when using personal information to make automated decisions, provided appropriate safeguards are in place. Thrive does not engage in fully automated decision-making that produces legal or similarly significant effects on individuals without meaningful human involvement.
For more information about your rights to submit a data subject access request (DSAR), please refer to the region-specific privacy information in this Section 11. The DUAA introduces a “stop the clock” provision that allows Thrive to pause the statutory response period for a DSAR if we need to request clarification or additional information from you to identify you or locate the requested data. The response period resumes once we receive the necessary information, and any time already spent responding will count toward the applicable deadline.
For Canadian Residents:
If you are a Canadian resident, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. You have the right to access your personal information, request corrections, and withdraw consent at any time (subject to legal or contractual restrictions). Personal information collected by Thrive Canada may be stored and processed in the United States, United Kingdom, Philippines, or other countries where Thrive or its service providers operate.
Ontario AI Disclosure: For job postings advertised in Ontario, Canada, Thrive discloses when artificial intelligence is used to screen, assess, or select applicants, as required under Ontario’s Employment Standards Act, 2000 (as amended).
For Australia Residents:
If you are an Australian resident, you have rights under the Privacy Act 1988 and the Australian Privacy Principles. You can request access to and correction of your personal information. If you believe we have not handled your personal information in accordance with the Australian Privacy Principles, you may file a complaint with the Office of the Australian Information Commissioner.
For Singapore Residents:
If you are a Singapore resident, you have rights under the Personal Data Protection Act 2012 (PDPA). You can request access to and correction of your personal data held by us. You may also withdraw your consent to the collection, use, or disclosure of your personal data at any time by contacting us using privacy@thrivenextgen.com.
For Hong Kong Residents:
If you are a Hong Kong resident, you have rights under the Personal Data (Privacy) Ordinance (PDPO). You can request access to and correction of your personal data. For inquiries, please contact us using the information below.
For Philippines Residents:
If you are a Philippines resident, you have rights under the Data Privacy Act of 2012. You have the right to be informed, the right to access, the right to rectification, the right to erasure or blocking, and the right to data portability. You may also file a complaint with the National Privacy Commission.
12. HEALTH INFORMATION (HIPAA)
If we receive protected health information (PHI) subject to the Health Insurance Portability and Accountability Act (HIPAA) in connection with our services to healthcare clients, we handle such information in accordance with applicable Business Associate Agreements and HIPAA requirements. Our use and disclosure of PHI is limited to the purposes specified in our service agreements and as permitted or required by HIPAA.
13. AUTOMATED DECISION-MAKING AND ARTIFICIAL INTELLIGENCE
Thrive is committed to using artificial intelligence (AI) responsibly and transparently to protect your privacy. This section describes how Thrive uses AI in its services and internal operations, our AI governance principles, and the disclosures required under applicable international AI regulations, including the EU AI Act (Regulation (EU) 2024/1689).
Our AI Governance Principles
Thrive’s approach to AI is guided by the following principles:
- Human Oversight: AI systems assist human decision-makers but do not replace them.
- Transparency: We inform individuals when they are interacting with AI systems and provide information about our AI capabilities and uses.
- Security: AI systems are subject to the same security controls and safeguards as other Thrive systems.
- Accountability: We maintain governance structures and processes to oversee AI deployment and address concerns.
Thrive’s Use of Artificial Intelligence
Thrive does not own or operate its own large language model (LLM) or foundational AI model. AI capabilities are embedded in certain third-party platforms and tools that Thrive licenses or subscribes to in order to deliver services and conduct internal operations. Thrive requires its AI technology vendors to maintain appropriate security, privacy, and compliance standards. The primary ways Thrive uses AI-enabled tools include:
- IT Service Management: Thrive uses a ticketing system with embedded AI functionality to support its managed IT services. This AI assists Thrive’s engineers by summarizing support incidents, providing intelligent routing of tickets to appropriate teams, and generating standard operating procedures and playbooks. These AI tools are used to improve operational efficiency and service delivery; they do not make automated decisions that produce legal or similarly significant effects on individuals without human involvement.
- Applicant Tracking: Thrive uses an applicant tracking system (ATS) that includes AI functionality to assist with recruitment processes, such as identifying suitable candidates and supporting the review of applications. However, Thrive does not use the AI within this system to make automated employment decisions. All decisions regarding whether to advance, interview, or reject candidates involve meaningful human review by Thrive’s recruiting and hiring personnel. The AI functions as an assistive tool only and does not autonomously determine employment outcomes.
- Cybersecurity and Threat Detection: Thrive uses AI-enabled tools to enhance its cybersecurity services, including for security monitoring, anomaly detection, threat intelligence analysis, and fraud prevention. These tools analyze patterns in network traffic and system behavior to identify potential security threats. AI-assisted security monitoring is subject to human review for significant findings and does not make automated decisions about individuals.
- Other Operational Uses: Thrive may also use AI-enabled tools for website analytics and performance optimization, marketing campaign analysis, and customer service improvements (including chatbot functionality). Where chatbots or virtual assistants are deployed, individuals will be informed that they are interacting with an AI system.
No Fully Automated Decision-Making
Thrive does not engage in fully automated decision-making, including profiling, that produces legal or similarly significant effects on individuals without meaningful human involvement. Where AI tools are used to assist with decisions that may affect individuals (such as in recruitment or service delivery), a qualified human reviewer is involved in the decision-making process. Individuals have the right under applicable law to request human intervention, express their point of view, and contest any decision that significantly affects them.
EU AI Act Compliance
For individuals located in the European Union, Thrive complies with the EU AI Act (Regulation (EU) 2024/1689), which establishes a risk-based regulatory framework for AI systems. The following disclosures are provided pursuant to the transparency requirements under Article 50 of the EU AI Act:
- Transparency Disclosures: Where Thrive deploys AI systems that interact directly with individuals (such as chatbots or virtual assistants), individuals will be informed that they are interacting with an AI system before or at the time of first interaction, in accordance with Article 50(1) of the EU AI Act. Any AI-generated content is marked or labeled as such where required by applicable law.
- High-Risk AI Systems in Employment: Under Annex III of the EU AI Act, AI systems used in employment, worker management, and access to self-employment are classified as “high-risk” when they materially influence decisions about recruitment, selection, hiring, promotion, termination, or task allocation. Thrive’s use of AI in its applicant tracking system is designed to assist—not replace—human decision-makers. All decisions about whether to advance, interview, or reject candidates are made by qualified human reviewers. Thrive does not use AI to automatically advance or reject candidates without human review.
- AI Literacy: Thrive provides AI literacy training to personnel who work with AI systems to provide staff with sufficient knowledge to understand the capabilities, limitations, and appropriate use of AI technologies.
- Your Rights Under the EU AI Act: Where AI systems are used in decisions that significantly affect you, you have the right to: (1) be informed that you are interacting with an AI system; (2) receive meaningful information about the AI system’s role in decision-making; (3) request human intervention in decisions that significantly affect you; and (4) where applicable, contest decisions and express your point of view. To exercise these rights, please contact us at privacy@thrivenextgen.com.
Other International AI Frameworks
Thrive also adheres to applicable AI governance principles in other jurisdictions where it operates:
United Kingdom: Thrive follows the UK’s principles-based approach to AI governance, including guidance from UK regulators. The UK does not currently have a standalone AI statute, but Thrive complies with AI-related requirements under UK data protection law (including the UK GDPR and DUAA) and sector-specific guidance.
Canada: Thrive complies with applicable Canadian privacy laws (including PIPEDA and provincial privacy legislation) as they apply to the use of AI. For job postings in Ontario, Thrive discloses when AI is used to screen, assess, or select candidates as required under Ontario’s Employment Standards Act, 2000.
Singapore: Thrive adheres to Singapore’s Model AI Governance Framework and the ASEAN Guide on AI Governance and Ethics, which promote principles of transparency, explainability, fairness, security, and accountability in AI deployment.
Hong Kong: Thrive complies with guidance from the Office of the Privacy Commissioner for Personal Data (PCPD) on AI governance, including requirements for privacy impact assessments, staff training, and incident-response plans where AI is deployed.
Australia: Thrive follows the Australian Government’s AI Guidelines for Business and complies with the Privacy Act 1988 and Australian Privacy Principles as they apply to AI systems.
Our Commitment to Responsible AI
Thrive regularly reviews its use of AI tools to ensure they are deployed ethically and in compliance with applicable laws. Data processed by AI systems is retained only as long as necessary for the purposes described in this Privacy Policy and our Data Retention practices (Section 7). Thrive does not use your personal information to build, develop, or train AI models. If you have questions about our use of AI or wish to exercise any rights under applicable AI regulations, please contact us at privacy@thrivenextgen.com.
14. COMPLAINTS AND DISPUTE RESOLUTION
We take privacy concerns seriously and are committed to resolving any complaints you may have. If you have a complaint about how we handle your personal information, please contact our privacy team at privacy@thrivenextgen.com. We will acknowledge your complaint within 10 business days and work to resolve it within 45 days or sooner if required by applicable law.
If your complaint remains unresolved, you have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction. For EU residents, you can find your local authority at https://edpb.europa.eu/about-edpb/board/members_en. For UK residents, contact the Information Commissioner’s Office at https://ico.org.uk/. The services of data protection authorities are provided at no cost to you.
15. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will notify you by posting the updated policy on our website with a new effective date. For significant changes, we may also notify you by email or through a prominent notice on our website. We encourage you to review this policy periodically.
16. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us.
United States:
Thrive Operations, LLC
25 Forbes Boulevard, Suite 3
Foxborough, MA 02035
Email: privacy@thrivenextgen.com
United Kingdom:
Thrive Operations Limited
16-22 Crawley Green Road
Luton, LU2 0QX
United Kingdom
Email: privacy@thrivenextgen.com
Canada:
Thrive Operations Canada, Ltd
3080 Yonge Street, Suite 6000
Toronto, Ontario M4N 3N1
Canada
Email: privacy@thrivenextgen.com
Philippines:
Thrive Operations Philippines Corp.
Unit 1W-701, One West Aeropark Building
Clark Global City, Clark Freeport Zone, Pampanga, 2023
Email: privacy@thrivenextgen.com
Singapore:
Thrive Operations Singapore Pte. Ltd.
150 Cecil Street, #07-01,
Singapore, 069543
Email: privacy@thrivenextgen.com
Hong Kong:
Thrive Operations Hong Kong Limited
7/F, 69 Jervois Street
Sheung Wan, Hong Kong
Email: privacy@thrivenextgen.com
Australia:
Thrive Operations – Australia Pty Ltd
Level 61, Governor Phillip Tower
1 Farrer Place
Sydney, NSW 2000
Email: privacy@thrivenextgen.com