This Data Sharing Agreement applies to the use of Personal Data which belongs to Thrive4 Users and Client Members that is collected, shared and initially used (Processed) for the purposes of the accessing of Thrive4’s Services and of facilitating the business relationship between Thrive4 and the Client.
PARTIES
Supplier is Pay Here Limited of Studio 4, The Boardwalk, Brighton Marina, Brighton, East Sussex, England BN2 5ZB trading as Thrive4, including services marketed under Thrive4 and any sector-specific, programme-specific or product-specific brands operated by Pay Here Limited from time to time.
Client, is an Organiser or Organisation as described in Pay Here Ltd.’s terms and conditions.
DEFINITIONS
The following terms shall have the meanings set out below and apply to this document as well as Thrive4’s terms and conditions.
Data Controller or Controller – as defined by the Data Protection Laws.
Data Protection Laws – the General Data Protection Regulation EU 2016/679 as adopted by the UK and written into the Data Protection Act 2018 (also known as the UK GDPR).
Member / Membership – the relationship between the Client and a User.
Personal Data – the data/information held about any User / member – as defined by the Data Protection Laws.
Personal Data Breach – a security incident where personal data is compromised, either accidentally or unlawfully.
Supervisory Authority – data protection regulatory body such as the UK’s ICO.
Services – the products and services provided by Thrive4, including software, payment services, learning resources, AI-powered services, consultancy, mentoring, workshops and other support services.
User – an individual who uses, accesses or interacts with the Services provided by Thrive4.
PARTIES AS DATA CONTROLLERS
- Client is acting as a Controller in relation to Personal Data that is received from Supplier.
- Supplier is acting as a Controller in relation to Personal Data that is received from Client.
- The relationship between the Client and the Supplier is a Controller-to-Controller relationship.
- Both Parties agree to use shared Personal Data to:
- manage the relationship between the Parties;
- manage relationships with Users and Members;
- deliver and improve Services;
- provide support, learning resources, recommendations and related services; and
- fulfil their respective contractual and legal obligations.
AI SERVICES
- Both Parties acknowledge that certain Services may utilise AI-powered tools and recommendation systems.
- Information provided through such Services may be processed, analysed, summarised and stored for the purpose of delivering recommendations, improving Services, maintaining records of interactions and supporting service delivery.
- Shared Personal Data, including conversation transcripts, summaries, assessments and recommendations generated through AI-powered Services, may be stored within customer relationship management systems and other business systems used by either Party for the delivery, management and administration of Services.
- Both Parties shall continue to comply with their respective obligations under Data Protection Laws when using or receiving information generated through such Services.
EACH PARTY SHALL:
- Comply with its obligations under the Data Protection Laws including but not limited to the issuing of Privacy Notices to Users / Members.
- Maintain the security and confidentiality of all shared Personal Data, sufficient to protect the rights and freedoms of Users.
- Co-operate and provide mutual support in instances where Users invoke their rights under Data Protection Laws.
- Inform the other Party without undue delay of any Personal Data Breach irrespective of whether there is a requirement to notify any Supervisory Authority.
- At the end of the relationship between Supplier and Client, retain and delete shared Personal Data in accordance with their respective retention policies and applicable Data Protection Laws.
This Data Sharing Agreement was last updated June 2026.