Privacy Policy
Effective Date: October 2026
At Thriving Berries Ltd (“we”, “us”, or “our”), we respect your privacy and are committed to protecting the personal data of our website visitors and subscribers. This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Company Details & Data Controller:
- Company Name: Thriving Berries Ltd
- Registered Office: Unit 2, 2 Bridge Street, Athlone, Westmeath, Ireland
- Company Number: 800282
- Data Protection Contact: hello@thrivingberries.ie
1. Information We Collect
- We collect only the personal data necessary to deliver our educational activity packs, fulfill physical shipments, process payments, and communicate with you:
- Subscriber & Contact Information — your name and email address when you sign up for our Free Tier, purchase a paid subscription, or contact us.
- Delivery Information (Digital + Physical Pack subscribers, Ireland only) — full recipient name, street address, town/city, county, and Eircode, for fulfilling and dispatching physical activity packs by post.
- Payment Data — payment transactions are processed securely by Stripe. We do not store or process full credit or debit card numbers on our servers.
- Children's Data — our products are designed for children aged 2–5 and are always purchased or subscribed to by a parent or guardian. We do not knowingly collect personal data directly from children.
- Cookies, Security and Analytics — our site uses Cloudflare Turnstile for essential bot protection, and a self-hosted analytics system that records page views, button clicks, and the country a visit originates from, in order to measure performance. This analytics system does not use cookies, does not follow you across other websites, and does not collect personal information. We do not use advertising or third-party tracking cookies.
2. How We Use Your Information & Legal Basis for Processing
- Under the GDPR, we process your personal data on the following lawful bases:
- Contractual necessity — to deliver your bi-monthly digital activity packs by email, package and post your physical packs to your delivery address, process subscription payments, and manage your account. Without this data we cannot provide the service.
- Consent — to send you Free Tier activity packs and our newsletter or seasonal announcements via EmailOctopus. You can withdraw your consent at any time by clicking the unsubscribe link at the bottom of any email, or by contacting us.
- Legitimate interest — for site security (Cloudflare Turnstile), basic analytics, and improving our service. We do not use this basis for marketing.
- Legal obligation — to comply with tax, accounting, and consumer protection reporting requirements under Irish and EU law.
4. Data Security
- We implement appropriate technical and organisational security measures to safeguard your personal data against unauthorised access, loss, or misuse. All electronic communications, mailing lists managed in EmailOctopus, and billing credentials handled by Stripe are protected using standard encryption protocols.
- No method of transmission over the Internet or electronic storage is completely secure, but we take reasonable measures to protect your personal information.
5. How Long We Retain Your Data
- We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected:
- Active subscribers — we retain your contact and shipping details for as long as your subscription remains active.
- Cancelled subscriptions — your contact and shipping details are retained for 30 days after cancellation and then deleted, excluding records we are required to keep by law.
- Unsubscribed users — if you unsubscribe from our mailing list, your details are removed from our active EmailOctopus lists so that you no longer receive communications from us.
- Transaction and payment records — retained for up to 6 years as required by Irish tax law (Revenue Commissioners).
6. Your Legal Data Rights Under GDPR
- If you are located in Ireland or the European Union, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete personal details, such as an updated delivery address.
- Erasure ("right to be forgotten") — request deletion of your personal data, subject to statutory record-keeping exceptions.
- Restriction — request that we limit how we process your data.
- Portability — request a copy of your data in a structured, commonly used, machine-readable format.
- Objection — object to processing we carry out on the basis of legitimate interests.
- Withdraw consent — unsubscribe from our mailing list at any time using the link in every email, or withdraw consent for any other processing by contacting us. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
- To exercise any of these rights, contact us at hello@thrivingberries.ie. We will respond within 30 days.
- Right to Complain: If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Irish Data Protection Commission (DPC) at www.dataprotection.ie.
7. Changes to This Privacy Policy
- We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. When we do, we will revise the "Effective Date" at the top of this document. For significant updates affecting active subscribers, we will notify you by email.
8. Contact Us
- If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please contact us at:
- hello@thrivingberries.ie