Privacy Policy

Last updated: 24.09.2026

We are committed to protecting your personal data and handling it responsibly. This policy explains what information we collect, how we use it, with whom we may share it, and the rights you have under the GDPR. We only collect information necessary to operate our website and deliver our AI-powered medical image analysis services, and we handle all data with strict security and confidentiality.

1. Introduction

This Privacy Policy explains how Thirona B.V. (“Thirona”, “we”, “our”, or “us”) collects, uses, stores, and protects your personal data when you visit thirona.eu or interact with our products and services.

We are committed to handling your information responsibly, transparently, and in accordance with applicable privacy laws, including the EU General Data Protection Regulation (“GDPR”) and relevant national legislation.

By using our website or providing your information, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

The data controller responsible for your personal data is:

Thirona B.V.
Toernooiveld 300, 6525 EC Nijmegen
The Netherlands
Email: privacy@thirona.eu
Website: https://thirona.eu

For certain processing operations, we may act as a data processor on behalf of healthcare institutions, research partners, or clients. In those cases, our processing is governed by a data processing agreement.

3. What Personal Data We Collect

We collect personal data in several ways, depending on how you interact with our website and services.

3.1 Data You Provide Directly

  • Contact information, including your name, email address and phone number
  • Company information, including organisation name, role and department
  • Form submissions, including demo requests, enquiries, partnership forms and downloads
  • Communication content, including email correspondence and customer-support messages

Depending on the context, we process this information based on your consent, the need to take steps at your request before entering into a contract, the performance of a contract, or our legitimate interest in responding to enquiries and maintaining business relationships.

3.2 Data Collected Automatically

When you visit our website, we may collect:

  • IP address
  • Browser type and version
  • Device information
  • Pages viewed and time spent on the website
  • Referral source
  • Cookie identifiers
  • Approximate geolocation information, such as city-level location and not precise GPS location

We process strictly necessary technical information based on our legitimate interests in operating, securing and improving our website. Where consent is legally required for analytics, marketing or visitor-identification technologies, the relevant processing takes place only after you have provided consent.

3.3 Cookies and Tracking Technologies

See Section 4 for details. Strictly necessary technologies may be used without consent where legally permitted. We rely on your consent for non-essential functional, analytics, marketing and visitor-identification technologies where consent is required by law.

3.4 Data from Third Parties

We may receive data from:

  • Analytics providers
  • Lead-generation and visitor-identification providers
  • Publicly available business sources, such as LinkedIn company-page data
  • Integration partners, if you use interoperable solutions with Thirona services

3.5 Special Categories of Data

Thirona provides AI-powered medical image analysis.

When processing medical images or health-related data through our professional services, we act as a data processor, rather than a controller, as defined under the GDPR.

Such data is handled strictly under contractual agreements, data-minimisation principles, and medical-grade security measures and standards where applicable.

No health data is processed through the public website thirona.eu.

3.6 Children’s Data

Our website and services are not intended for children under 16. We do not intend to collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@thirona.eu.

4. Cookies & Tracking Technologies

We use cookies and similar technologies to ensure website functionality, remember visitor preferences, analyse website performance and, with your consent, support marketing and visitor insights.

4.1 Types of Cookies and Technologies We Use

Type Purpose Examples of services that may be used
Strictly necessary Ensure the basic functioning, security and accessibility of our website, protect forms against spam and remember cookie-consent choices. WordPress/Elementor, Cloudflare, CookieYes and Google reCAPTCHA
Analytics and performance Help us understand how visitors use our website and improve its performance. These technologies are used only with consent where required. Google Analytics and Microsoft Clarity
Functional Enable additional features, embedded content and visitor or service preferences. YouTube and certain LinkedIn service functionality
Marketing, advertising and visitor insights Help us measure campaigns and understand interactions with our website. These technologies are used only with consent where required. LinkedIn Insight Tag, Microsoft/Bing, YouTube/Google and Lead Forensics using Demandbase infrastructure

Google Tag Manager may be used to manage and deploy website technologies. Google Tag Manager does not itself determine the purposes for which personal data is processed, but it enables the relevant website tags to be managed.

4.2 Legal Basis for Cookies and Similar Technologies

  • Strictly necessary technologies may be used without consent where they are required to provide or secure the website. Where personal data is processed, we rely on our legitimate interests in operating and protecting the website.
  • Non-essential functional, analytics, marketing, advertising and visitor-insight technologies are used on the basis of consent where required by law.

4.3 Managing Cookies

You can manage or disable cookies and similar technologies through:

  • The CookieYes banner and cookie-preference settings on our website
  • Your browser settings
  • “Do Not Track” or similar browser preferences where supported

The CookieYes preference settings provide information about the cookies detected on our website, including their categories, providers, purposes and retention periods.

You can change or withdraw your consent at any time through the cookie-preference settings. Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

5. Data Storage & Retention

We store personal data only as long as needed for the purposes described in this policy or as required by law.

Typical retention periods include:

  • Form submissions stored in WordPress: 30 days
  • Related correspondence: as long as necessary to respond to the enquiry or maintain the relevant business relationship
  • Contract and customer data: 7 years for legal and accounting purposes
  • Newsletter data: until you unsubscribe
  • Google Analytics data: 14 months
  • Other analytics, marketing and visitor-insight data: according to the applicable provider settings and no longer than necessary for the stated purposes
  • Technical logs: up to 12 months for security and diagnostic purposes

If legal obligations, including tax, medical-device or clinical-research laws, require longer retention, we retain the relevant information for the legally required period.

6. Data Security

We take appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted connections using HTTPS/TLS
  • Secure data centres and access controls
  • Firewalls and intrusion detection
  • Data access limited to authorised personnel
  • Staff confidentiality agreements
  • Regular system and security audits
  • Data-minimisation principles in all services
  • Medical-grade security standards and strict access governance for medical-imaging services

7. Data Sharing

We do not sell personal data.

We may share data with trusted third parties when necessary.

7.1 Categories of Recipients

  • Hosting and infrastructure providers
  • Consent-management providers
  • Analytics and performance providers
  • Embedded-content and video providers
  • Marketing and visitor-identification providers
  • Email and communication tools
  • CRM and customer-support systems
  • Legal and regulatory authorities when required
  • Professional service providers, such as accounting, legal and compliance advisers

7.2 Purpose of Sharing

We may share information where necessary for:

  • Operating our website
  • Responding to your requests
  • Ensuring security and performance
  • Analysing website use
  • Supporting marketing and visitor insights with your consent where required
  • Providing contracted services
  • Meeting legal obligations

7.3 Service Providers and Data Processing Agreements

Where a third party processes personal data on our behalf, the processing is governed by an appropriate agreement where required under the GDPR.

Service providers supporting our website and marketing activities include:

  • Adwell: online marketing and website services
  • Sciential B.V.: life-sciences digital marketing services

The website also uses the technology providers identified in Section 4. Depending on the service and processing activity, these providers may act as processors, independent controllers or joint controllers.

8. International Transfers

If we transfer personal data outside the EU/EEA, we ensure that appropriate safeguards are used as required by the GDPR, including:

  • European Commission adequacy decisions
  • Standard Contractual Clauses
  • Additional security measures where required

You may request information about the applicable transfer mechanism by contacting privacy@thirona.eu.

9. Your Rights (GDPR)

You may have the following rights regarding your personal data:

  • Access – request a copy of your personal data
  • Rectification – correct inaccurate or incomplete personal data
  • Erasure – request deletion of your personal data where applicable
  • Restriction of processing
  • Data portability
  • Objection, including objection to direct marketing
  • Withdrawal of consent at any time
  • Lodging a complaint with a data-protection authority

How to Exercise Your Rights

Email: privacy@thirona.eu

We may request additional information to verify your identity before processing your request. We will respond within one month of receiving your request, subject to the exceptions permitted under the GDPR.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work or place of the alleged infringement.

For complaints regarding Thirona’s processing, the competent supervisory authority is:

Autoriteit Persoonsgegevens
Dutch Data Protection Authority
Website: https://autoriteitpersoonsgegevens.nl

10. Questions or Requests

If you have questions about this Privacy Policy or how we process your data, please contact:

Thirona B.V.
Toernooiveld 300, 6525 EC Nijmegen
The Netherlands
Email: privacy@thirona.eu

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies or legal obligations. The “Last updated” date at the top of this policy indicates when it was most recently revised.