Privacy Policy
Last updated: 2 September 2026 · Effective: 2 September 2026 · Previous version: 1 September 2026
This policy describes what personal data Thalamus processes, on what legal basis, who it is shared with, how long it is kept and how you can control it. We do not sell data, show ads or run third-party analytics.
IN SHORT
We collect what the service needs to work: account sign-in, profile, provider listing and requests. We take no payments, so we hold no payment data. Data is stored in the European Union. There are no advertising or analytics trackers. You can delete your account yourself in profile settings. What you publish yourself — a provider listing, a question in the Parents section, a reaction under an answer — is readable by everyone; you choose the signature on the question and on the reaction.
1. WHO IS RESPONSIBLE FOR YOUR DATA
1.1 Controller
The data controller is Ilona Golman, Barcelona, Spain. Tax number (NIF/NIE): to be published upon registration as autónomo. Postal address: to be published upon registration as autónomo. Email: hello@thalamus.community.
1.2 Scope
This policy covers the site thalamus.community, all of its sections, and the Studio tool (studio.thalamus.community) embedded into the Studio page.
1.3 Data protection officer
The law does not require us to appoint a data protection officer: we do not monitor people systematically on a large scale and do not process special categories of data on a large scale. All questions go to the contacts in Section 14.
1.4 Applicable law
Processing is governed by Regulation (EU) 2016/679 (GDPR) and the Spanish law LOPDGDD 3/2018.
2. WHAT DATA WE COLLECT
2.1 Data you provide
- Account: email address, password as a hash or a one-time sign-in code, interface language.
- Telegram sign-in, if you used it: your Telegram account number, name, username and a link to your photo. Such an account starts without an email address — until you add one yourself in your profile.
- Two-factor authentication: the authenticator secret and the factor status, if you enabled it.
- Profile: name, city, origin and destination countries, languages, avatar.
- Activity in the service: relocation goals, favourite listings, votes for future features.
- Contact preference: which channel we use for notifications — Telegram, email, or “do not write”.
- Provider listing: name, phone, email, website, description, services, prices, geography, extra blocks and events.
- Provider verification: the type of proof and the document file.
- Requests and deals: your contact details, the text of the enquiry, the chosen provider, the status and related notes and tasks.
- Support messages: whatever you write to us by email.
- A question to the Parents section: the text of the question, the child’s age band and sex, the topic, and whether you asked anonymously.
- A reaction under a library answer: the kind — agree, disagree or addition — the text explaining why, and whether you signed it with your name.
- An application to answer in the Parents section, if you sent one: the name shown under your answer, your credentials, a link confirming them, and the topics you are ready to answer on.
- Community membership: which community you belong to, your role and your status — including a request the owner has not reviewed yet. If you invited someone with an invite link, we keep the link code and the fact that you created it.
- What you write in a community: the text of your posts and comments and your name next to them. In a public community they are visible to everyone, including people who are not signed in.
- The course you teach: its title, description, lesson texts, checklist items and module names, with your name and credential next to them. A published course is visible to everyone, including people who are not signed in; an unpublished one is visible to you, to the moderators of your club and to the service administrator.
2.2 Data collected automatically
- Hosting technical logs: IP address, browser type, request time. Needed for security and troubleshooting.
- Visit counter: the address of the page you opened, the host you came from and the time. No cookies, no IP address, no identifier — such a record cannot tell who you are.
- Rate limit on open forms: a fingerprint of your address — a one-way hash with a secret salt. The address itself is never stored. It exists so feedback and enquiry forms cannot be flooded by a script; the record lives one hour and is deleted.
- Studio access: the date it was first opened and the access status. There are no payment identifiers — we take no payments.
2.3 Data from third-party sources
If you sign in with Telegram, your name, username and photo link come to us from Telegram itself — by your decision and only at the moment you press the button. We have no access to your messages and cannot have any.
Sometimes a third party gives us a provider's or a client's contact details — for example, you were recommended to us. In that case, on first contact we tell you where your data came from, as Article 14 of the GDPR requires.
2.4 Other people's data
If you enter other people's data into the service — for example an employee's contact in a provider listing — you are responsible for the lawfulness of publishing it and for making sure the person knows about it.
2.5 Cookies and local storage
We use strictly necessary cookies only: the sign-in session and the chosen language. There are no analytics or advertising cookies, hence no consent banner. The full map is in the Cookie Policy.
2.6 What we do not collect
- special categories of data: health, religion, political views, biometrics;
- children's data: the service is for people 18 and older;
- data for advertising profiles and cross-site tracking;
- bank card details: we take no payments and never ask for a card.
3. PURPOSES AND LEGAL BASES
Each purpose of processing, the data involved, the legal basis under Article 6 of the GDPR and the retention period:
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Registration and sign-in | Email, password hash, sign-in codes, language, 2FA factors | Contract, Art. 6(1)(b) | Until the account is deleted |
| Profile and matching services to your route | Name, city, countries, languages, avatar, goals, favourites | Contract, Art. 6(1)(b) | Until the account is deleted |
| Publishing a provider listing in the catalog | Name, contacts, services, prices, geography, blocks, events | Contract, Art. 6(1)(b) | While the listing is published |
| Verifying a provider | Type of proof, document file | Legitimate interest, Art. 6(1)(f): the catalog needs verified providers | File — up to 30 days after the decision; the verification mark — while the listing exists |
| Passing a request to a provider and following the deal | Contact details, enquiry text, status, notes, tasks | Contract and legitimate interest, Art. 6(1)(f) | 24 months without activity, then automatic deletion |
| Telling you about your request | The channel you chose, the request number and the name of the provider it went to; your Telegram account number or email address — whichever you picked | Contract, Art. 6(1)(b) | The delivery record — until the account is deleted |
| Transactional email: sign-in codes, request statuses | Email, event | Contract, Art. 6(1)(b) | Until the account is deleted; delivery logs per the email provider |
| Telling you that your question has an answer | The channel you chose, the text of your question and a link to the answer; your Telegram account number or email address, depending on that choice | Contract, Art. 6(1)(b) | Delivery record until the account is deleted |
| Introducing a job seeker and an employer in the Jobs section | Your “looking for work” card: craft, city, work format, availability, right to work; languages from your profile; introductions, their statuses and recommendations | Contract, Art. 6(1)(b) | While the card exists; “hidden” takes it out of results, and the “Delete the card” button erases it. Introductions and recommendations go when the account is deleted |
| Telling you about a matching position and about an introduction moving | The channel you chose, the position number and the introduction status; your Telegram account number or email address, depending on that choice | Contract, Art. 6(1)(b) | Delivery record until the account is deleted |
| Studio access during the test launch | User identifier, date access was opened, status | Contract, Art. 6(1)(b) | Until the account is deleted |
| Answering a question in the Parents section | Question text, the child’s age band and sex, topic, anonymity flag | Contract, Art. 6(1)(b) | Until the account is deleted; an answered question stays in the library without its author |
| Publishing a reaction under a library answer | Kind of reaction, the text explaining why, the “no name” flag | Contract, Art. 6(1)(b) | Until the account is deleted |
| Admitting a specialist to answer in the Parents section | Name shown under the answer, credentials, confirmation link, topics; for an application also the decision and the reason for refusal | Contract, Art. 6(1)(b): you ask to be admitted yourself | Application — 6 months after the decision; an admitted specialist's card — while the role lasts |
| Security and troubleshooting | Technical logs: IP, browser, time | Legitimate interest, Art. 6(1)(f) | Per the hosting provider's policy |
| Protecting open forms from flooding | Address fingerprint (one-way hash), form name, counter — never the address itself | Legitimate interest, Art. 6(1)(f) | 1 hour, then deleted automatically |
| Understanding which pages are read | Page address, referrer host, time — no IP, no identifiers | Legitimate interest, Art. 6(1)(f) | 12 months, then deleted automatically |
| Moderation and handling complaints | The report, the disputed material, correspondence | Legal obligation, Art. 6(1)(c): Regulation (EU) 2022/2065 | 3 years from the decision |
3.1 Notifications
When your question has an answer, we send one message: the question itself, a link to the page with the answer, and a reminder that this is not a doctor’s appointment. You choose the channel in your profile — Telegram, email, or “do not write”. The choice is followed literally: if you chose email, we will not write to you on Telegram. “Do not write” switches notifications off entirely; the answer still stays on the question’s page.
3.2 Marketing
A marketing mailing, separate from transactional email, covers topics like relocation and residency permits. Signing up is voluntary: a separate form with an explicit, not pre-checked consent box. The mailing list is kept apart from accounts — it has no effect on sign-in emails or other transactional messages. Unsubscribe with one click from any mailing.
3.3 Matching in the Jobs section
The section compares your card with open positions on five points: craft, place, work format, language and the right to work. A match is a suggestion, not a decision: every position is open to you without it, and a person decides whom to invite. The language a position requires is printed on its card, so you can see which condition did not match.
Your card is visible to exactly the audience you choose in its settings, down to “hidden”. Messages about matches go to the channel you chose in your profile; “do not write” switches them off entirely, and every message carries a link to switch them off.
3.4 New purposes
If we need data for a purpose not listed here, we will tell you before the processing starts and ask for consent where required.
4. WHO WE SHARE DATA WITH
Data is not sold and is not passed to advertising networks. Processing is carried out by contractors, each under a data processing agreement (DPA):
| Recipient | Role | What it receives | Where data sits | Transfer mechanism |
|---|---|---|---|---|
| Supabase | Processor | Database, authentication, verification files | EU, region eu-west-3 (Paris) | DPA and EU Standard Contractual Clauses |
| Vercel | Processor | Site hosting, technical logs | US and edge nodes | EU-US Data Privacy Framework |
| Brevo | Processor | Sending transactional email and notifications, plus the voluntary marketing mailing — under separate consent | France, EU | Data stays in the EU |
| Cloudflare | Processor | DNS and domain email routing | US and global network | EU-US Data Privacy Framework |
| The provider you sent a request to | Independent controller | Your contact details and the enquiry text | The provider's country | Transfer on your instruction |
| Telegram | Not our processor | The fact of signing in: Telegram learns that you are signing in to Thalamus. If you chose Telegram as your notification channel, also the text of the message: your question and a link to the answer. Separately from that, service signals go to the site owner’s working chat: a new request, and a sign-up that was never completed. The email address in such a signal is shortened to its first three characters and the domain | Telegram Messenger countries | Transferred by your decision: when you press the sign-in button, and when you choose Telegram as your notification channel. Service signals to the site owner rest on legitimate interest: to learn about a request and about a broken sign-up, so we can answer and fix it |
| Google Maps | Not our processor | IP address — only after you press “Show map” | US | Loaded at your decision |
4.1 Authorities
Data is disclosed to public authorities only on a lawful request and only to the extent necessary.
4.2 Business transfer
If the service is sold or reorganised, data may pass to the successor. We will tell you in advance and you will keep the right to delete your account.
4.3 What is public
Publicly visible: the provider listing with the contacts stated in it, the level and type of verification, and events with the status “published”. User profiles, requests, goals and verification files are not public.
The Parents section is public as well: an answered question, the answers under it and the reactions to them can be read by anyone, including people who are not signed in. You choose the signature on your own reaction when you send it — your profile name or “no name”; in the second case the page shows neither your name nor any identifier of yours. A reaction that breaks the rules of the section is removed from the page: it stops being shown, but stays with us as a record of the measure taken.
For an admitted specialist, the name, the credentials and the confirmation link are public: they sit under every answer they give. The application itself never becomes public — neither before the decision nor after a refusal.
5. THE STUDIO AND ITS TOOL
5.1 What we store
On our side we store only Studio access: the user identifier, the date access was opened and its status. There is no payment data: we take no payments and have connected no payment provider.
5.2 What stays in your browser
Scripts, notes and materials in the Studio tool stay on your device in browser storage. We do not receive them and keep no copies. Clearing browser data deletes them permanently.
5.3 Token passed to the embedded frame
The Studio tool opens in an embedded frame from studio.thalamus.community. Only a temporary access token for your session is passed to it, so the tool can recognise you. The token lives about an hour, the exchange is restricted to the Thalamus and Studio domains, and the long-lived session refresh key is never passed.
5.4 Your own language-model key
If you connect a language-model key in the Studio tool, it is stored in your browser and never reaches our servers. The prompt text goes directly to the model provider you chose and is processed under their policy: in that part we are neither controller nor processor.
6. HOW LONG WE KEEP DATA
| Category | Retention |
|---|---|
| Account and profile | Until the account is deleted |
| Provider listing | While published; deleted immediately after removal |
| Verification file | No more than 30 days after the verification decision |
| Requests and deals | 24 months without activity, then deleted automatically on a schedule |
| Studio access | Until the account is deleted |
| Visit counter rows | 12 months, deleted on schedule |
| Infrastructure backups | Up to 30 days |
| Questions in the Parents section | Until the account is deleted; an answered question stays in the library without its author |
| Applications to answer in the Parents section | 6 months after the decision, then deleted |
| An admitted specialist's card | While the role lasts; deleting the account erases it at once |
| Reactions under library answers | Until the account is deleted; removed ones as moderation records |
| Complaint and moderation records | 3 years from the decision |
6.1 After you delete your account
Profile, goals, favourites, requests and memberships are deleted immediately. A provider listing where you are the only member is deleted together with its verification files; a listing with other members stays with the team. Infrastructure backups hold deleted data for no more than 30 days.
6.2 What we must keep
Some data is kept longer where the law requires it: accounting and tax documents, and records about disputes and complaints.
7. TRANSFERS OUTSIDE THE EEA
7.1 Where data is stored
The primary storage — the database and files — is in the European Union, in the Paris region.
7.2 Residual transfers
Some contractors — hosting and domain email routing — operate from the United States. Those transfers rely on certification under the EU-US Data Privacy Framework and, where there is none, on the European Commission's Standard Contractual Clauses.
7.3 Copy of the safeguards
You can request a copy of the contractual safeguards by writing to hello@thalamus.community.
8. SECURITY
8.1 Measures
- row-level access control in the database: a user sees only their own records;
- verification files in private storage, accessible to the administrator only;
- passwords stored only as hashes, sign-in codes single-use;
- two-factor authentication for access to other people's data;
- traffic encrypted over HTTPS;
- rotation of access keys whenever compromise is suspected.
8.2 Data breach
If a breach creates a risk to your rights, we notify the Spanish supervisory authority AEPD within 72 hours of becoming aware of it. Where the risk is high we also tell you: what happened, what we did and what you should do.
8.3 Your part
Use a strong password, do not share access to your mailbox, and enable two-factor authentication if you work with client data.
9. YOUR RIGHTS
9.1 The rights
- access: find out what data we process and get a copy;
- rectification: correct inaccurate data;
- erasure: ask us to delete data;
- restriction of processing;
- objection to processing based on legitimate interest;
- portability: receive your data in a machine-readable format;
- withdrawal of consent where processing is based on it; withdrawal does not affect the lawfulness of processing before it.
9.2 How to exercise them
Write to hello@thalamus.community from the address on your account. If we have reasonable doubts about who is asking, we will ask you to confirm your identity — and will request no more than needed for that check.
9.3 Response time
We answer within one month. That period may be extended by two further months for complex requests — we will tell you about the extension and its reason within the first month.
9.4 Deleting your account
You can delete your account yourself in profile settings. No payment obligations remain: we take no payments.
9.5 Complaints
If you believe we handle data improperly, you can lodge a complaint with the Spanish data protection agency AEPD (aepd.es) or with the supervisory authority of your country of residence.
10. CHILDREN
10.1 Age
The service is for adults: you must be 18 or older to use it. We do not create accounts for children and do not collect anything by which a child could be identified. One exception we state plainly: when you ask a question in the Parents section you give the child’s age band and sex — with no name, date of birth or anything else about them. Without it the answer would be wrong: an infant and a seven-year-old are not answered the same way.
10.2 If a child's data reaches us
Write to hello@thalamus.community and we will delete such data without delay.
11. AUTOMATED DECISIONS AND ARTIFICIAL INTELLIGENCE
11.1 No decisions without a human
We take no decisions producing legal or similarly significant effects on you by automated means alone. Verification, moderation and blocking are decided by a human.
11.2 No profiling
We build no advertising profiles and do not score people algorithmically.
11.3 Where a model is used
A language model is used only in the Studio tool, with a key you connect yourself. Catalog, request and profile data is not used to train models and is not passed to model providers.
12. COOKIES
12.1 What is set
Strictly necessary cookies only: the sign-in session and the chosen language. Your decision to load maps is stored separately in your browser. The full map is in the Cookie Policy.
12.2 Consent
Under AEPD rules technical cookies need no consent, so there is no banner. If analytics with identifiers appears, an honest banner with equally weighted accept and reject buttons will come first.
13. CHANGES TO THIS POLICY
13.1 How we announce them
We announce material changes on the site or by email at least 30 days before they take effect.
13.2 Previous versions
The dates of the current version and of its entry into force are in the page header, along with a link to the previous version.
14. CONTACT
14.1 Where to write
- Data questions and requests to exercise rights: hello@thalamus.community
- Postal address: to be published upon registration as autónomo
- Supervisory authority: Agencia Española de Protección de Datos, aepd.es
Last updated: 2 September 2026 · Effective: 2 September 2026