Data Protection Policy
Last updated: 26 June 2026
We Are Thryve is committed to protecting the personal data we handle on behalf of our clients and their people. This policy sets out how we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Our principles
We process personal data in line with the data-protection principles:
- lawfully, fairly and transparently;
- only for specified, explicit and legitimate purposes;
- limited to what is necessary (data minimisation);
- kept accurate and up to date;
- retained no longer than necessary;
- kept secure with appropriate technical and organisational measures.
2. Roles
For our own business contacts we act as a data controller. When we host and process HR data inside the portal on behalf of a client organisation, we act as a data processor, processing that data only on the client’s documented instructions.
3. Lawful basis
We rely on the lawful bases of contract, legal obligation and legitimate interests. Where special category data (such as health or absence information) is handled within HR records, it is processed only where an appropriate condition under UK GDPR applies and on behalf of the controlling client organisation.
4. Security and storage
Data is hosted with reputable infrastructure providers within the UK or European Economic Area. We apply role-based access controls, encryption in transit, secure authentication and the principle of least privilege so that people can access only the data relevant to their role and organisation.
5. Sub-processors
We use a limited number of vetted sub-processors (for hosting, database, file storage and email delivery). Each is bound by a written agreement requiring equivalent data-protection and confidentiality standards.
6. International transfers
Where any transfer outside the UK or EEA is necessary, we ensure an appropriate safeguard is in place, such as an adequacy decision or standard contractual clauses.
7. Retention and deletion
Personal data is retained for the duration of the client relationship and any period required by law, then securely deleted or anonymised. Clients may request export or deletion of their data on termination of services.
8. Data breaches
We maintain procedures to detect, report and investigate personal-data breaches. Where a breach is likely to result in a risk to individuals, we will notify the relevant controller and, where required, the ICO without undue delay and within 72 hours of becoming aware of it.
9. Contact
For data-protection queries or to make a request, contact hello@wearethryve.co.uk. You also have the right to complain to the Information Commissioner’s Office (ICO).
