Your Privacy Matters

Privacy Policy

Last updated: September 29, 2026

1. Introduction

ThryvHQ ("Company," "we," "us," or "our") operates AI-powered automation platforms for businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services. This policy applies to all visitors, users, and customers worldwide, including those protected under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws. By accessing or using our services, you agree to this Privacy Policy.

2. Information We Collect

Personal Information You Provide

We may collect personally identifiable information that you voluntarily provide, including:

  • Name, email address, phone number, and business name
  • Billing and payment information
  • Business details such as industry, number of employees, and service area
  • Communications you send to us (support requests, feedback)

Information Collected Through AI Services

When you use our AI automation platform, we may process:

  • Call recordings and transcripts handled by AI voice agents
  • Customer interaction data (scheduling requests, inquiries, follow-ups)
  • Workflow automation data and business process information
  • Integration data from connected third-party services (CRM, calendars, payment systems)

Automatically Collected Information

When you visit our website, we automatically collect:

  • Device and browser information (type, operating system, IP address, anonymized where possible)
  • Usage data (pages visited, time spent, referring URLs)
  • Cookies and similar tracking technologies (see Section 9 for details)

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we process your personal data only when we have a valid legal basis. Our legal bases include:

  • Consent: When you opt in to analytics cookies, marketing communications, or other optional processing. You may withdraw consent at any time through our cookie settings or by contacting us.
  • Contractual Necessity: Processing required to fulfill our service agreement with you, such as providing AI automation services, billing, and support.
  • Legitimate Interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, security, service improvement), provided these do not override your fundamental rights. You may object to processing based on legitimate interests by contacting us.
  • Legal Obligation: Processing required to comply with applicable laws, regulations, or legal proceedings.

4. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our AI automation services
  • Train and improve our AI models to deliver better call handling, scheduling, and workflow automation
  • Process transactions and send billing-related communications
  • Respond to your inquiries and provide customer support
  • Send marketing communications (only with your explicit consent, where required)
  • Monitor usage patterns to improve service performance and reliability
  • Detect, prevent, and address security issues and fraud
  • Comply with legal obligations
  • Conduct analytics to understand website traffic and user experience (consent-gated)

5. AI Data Processing

Our AI services process voice calls, messages, and business data on your behalf. We want you to understand how this works:

  • Call Processing: AI voice agents process inbound and outbound calls in real-time. Call data may be temporarily stored for quality assurance and service improvement.
  • Data Minimization: We only process the data necessary to provide the requested service. We do not collect or retain data beyond what is required.
  • AI Training: We do not use your data to train general AI models. Our AI service providers are contractually limited to using your data to provide the specific service. We may review de-identified interaction summaries to improve how your own assistant is configured.
  • Human Review: In limited cases, our team may review AI interactions for quality assurance purposes, subject to strict confidentiality obligations.
  • Automated Decision-Making: Our AI systems may make automated decisions (e.g., routing calls, scheduling appointments). These decisions are designed to assist human judgment without replacing it. You may request human review of any automated decision by contacting us.

6. Sharing Your Information

We may share your information with:

  • Service Providers: Third-party vendors who assist in operating our platform (cloud hosting, payment processing, analytics, telephony providers). These providers are contractually bound to process data only on our behalf and in accordance with our instructions.
  • Integration Partners: When you connect third-party services (e.g., Google Calendar, QuickBooks, Salesforce), data is shared as necessary to enable those integrations
  • Legal Requirements: When required by law, regulation, or legal process
  • Business Transfers: In connection with a merger, acquisition, or sale of assets. You will be notified of any such change in ownership or control.

Third-Party Services We Use

Our website and platform rely on the following third-party services that may receive or process your data:

  • Google Analytics 4 (GA4): Website analytics with anonymized IP addresses. Only activated with your analytics consent. Data is processed in accordance with Google's privacy policy.
  • Google reCAPTCHA v3: Bot and spam protection on forms. Processes device and interaction data to generate a risk score. Loaded only when you interact with a form. Subject to Google's Privacy Policy and Terms of Service.
  • Customer relationship and appointment provider: When you book an appointment or submit a contact form, your name, email, phone number, and message content are transmitted to our service provider for processing under its privacy and data-protection terms.

Our platform provider is based in the United States and may use affiliates and service providers in other countries, including India, to operate and support the service, under data-processing agreements.

We do not sell your personal information to third parties. We do not share your personal information for cross-context behavioral advertising.

7. Data Retention and Deletion

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law. Specific retention periods include:

  • Account Data: There is no automatic per-customer retention schedule.
  • Call Recordings & Transcripts: If you request deletion, data is deleted from active systems within 30 days of a verified request; backup copies roll off within 90 days.
  • Billing Records: Retained for 7 years to comply with tax and accounting obligations.
  • Website Analytics: Anonymized analytics data is retained for up to 26 months. Raw IP data is not stored.
  • Support Communications: Retained for up to 3 years after your last interaction for quality assurance and reference.
  • Cookie Data: Consent preferences are stored locally on your device. Analytics cookies expire per Google Analytics defaults (up to 2 years).

Deletion Procedures

When data is no longer needed or you request deletion:

  • We will permanently delete or anonymize your personal data from our active systems within 30 days of a verified deletion request.
  • Backup copies may persist for up to 90 days before being overwritten through our regular backup rotation cycle.
  • Certain data may be retained where we have a legal obligation to do so (e.g., billing records, fraud prevention data).
  • To request deletion, email hello@thryvhq.com with the subject line "Data Deletion Request." We will verify your identity before processing.

8. Data Security

We implement industry-standard security measures to protect your information, including:

  • Industry-standard encryption in transit and at rest
  • Role-based access controls with the principle of least privilege
  • Regular security assessments and penetration testing
  • Secure cloud infrastructure with access controls and regular security reviews
  • Incident response procedures with breach notification within 72 hours (as required by GDPR)

Security practices reduce risk but cannot eliminate every security threat. If you become aware of a security incident, please contact us immediately.

9. Cookies and Tracking Technologies

We use cookies and similar technologies on our website. You can manage your preferences at any time through our cookie consent banner or by clicking "Cookie Settings" in the footer.

Types of Cookies We Use

  • Strictly Necessary Cookies: Required for basic site functionality, including security features, session management, and accessibility preferences. These cookies cannot be disabled. They do not collect personally identifiable information for marketing purposes.
  • Analytics Cookies (Consent Required): We use Google Analytics 4 with anonymized IP addresses to understand how visitors interact with our website, which pages are most visited, and how we can improve the experience. These cookies are only activated when you grant analytics consent. No personal data is sold or shared with advertisers.
  • Marketing Cookies (Consent Required): If enabled, these cookies allow us to measure advertising effectiveness and deliver more relevant content. Data may be shared with advertising partners as described in this policy. You can opt out at any time.

Managing Your Cookie Preferences

  • Use our on-site cookie consent banner when you first visit to choose your preferences.
  • Change your preferences at any time via the "Cookie Settings" link in the website footer.
  • You can also control cookies through your browser settings, though this may affect site functionality.
  • We honor the Global Privacy Control (GPC) signal. When detected, we treat it as an opt-out of analytics and marketing cookies.

10. Your Rights

Regardless of your location, you have the following rights regarding your personal data:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal retention requirements).
  • Portability: Request your data in a structured, machine-readable format (CSV or JSON).
  • Opt-Out of Marketing: Unsubscribe from marketing communications at any time via the link in any email or by contacting us.
  • Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Restrict Processing: Request that we limit how we use your data in certain circumstances.

To exercise any right, email hello@thryvhq.com. We will respond within 30 days (or 45 days for CCPA requests, with notice). We will not discriminate against you for exercising your rights.

11. GDPR Compliance (EEA, UK & Switzerland)

If you are in the European Economic Area, United Kingdom, or Switzerland, the following additional rights and protections apply:

  • Right to Object: You may object to processing based on legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to Restrict Processing: You may request restriction while we verify the accuracy of your data or assess an objection.
  • Right Regarding Automated Decisions: You have the right not to be subject to decisions based solely on automated processing that produce legal or significant effects. You may request human review of any such decision.
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.

International Data Transfers

Our services are operated from the United States. If you are located outside the U.S., your personal data may be transferred to and processed in the U.S. We ensure appropriate safeguards for international transfers through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements (DPAs) with all sub-processors
  • Supplementary security measures including encryption and access controls

To request a copy of the safeguards in place, contact hello@thryvhq.com.

12. CCPA/CPRA Compliance (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA):

Categories of Personal Information Collected

  • Identifiers: Name, email, phone number, IP address
  • Commercial Information: Records of services purchased, payment history
  • Internet Activity: Browsing history on our site, interactions with our service
  • Professional Information: Business name, industry, job title
  • Inferences: Preferences or characteristics derived from the above categories
  • Sensitive Personal Information: We do not intentionally collect sensitive personal information as defined by the CPRA

Your California Privacy Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the third parties with whom we share it.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive PI: Not applicable, as we do not intentionally collect sensitive personal information.
  • Non-Discrimination: We will not deny you services, charge different prices, or provide a different quality of service because you exercise your CCPA/CPRA rights.

To submit a CCPA request, email hello@thryvhq.com or call (866) 579-7790. We will verify your identity before processing and respond within 45 days. You may designate an authorized agent to submit requests on your behalf.

13. Children's Privacy

Our services are not directed to individuals under the age of 16 (or 13 in the U.S.). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at hello@thryvhq.com and we will promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website, updating the "Last updated" date, and, where appropriate, sending you a notification by email. Your continued use of our services after changes constitutes acceptance of the revised policy. Previous versions of this policy are available upon request.

15. Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or have a data protection concern, please contact us:

ThryvHQ — Data Protection

Email: hello@thryvhq.com

Phone: (866) 579-7790

Location: Vienna, VA 22180

For GDPR-related inquiries, you may also contact your local supervisory authority. For CCPA requests, you may use the phone number above or email as a toll-free contact method.