Privacy policy
Last updated 6 October 2026
This policy explains what personal data ThinkCheck AI collects through thinkcheckai.co.uk, why, who it's shared with and the rights you have under the UK GDPR, the Data Protection Act 2018 and the EU GDPR.
1. Who we are
ThinkCheck AI is run by Stroy Grup Soft 1 EOOD, a company registered in Bulgaria (UIC 207575913), registered office zh.k. Lyulin-5, bl. 524, vh. A, et. 1, ap. 4, 1359 Sofia, Bulgaria. We are the data controller for the data described here.
Contact for anything about your data: hello@thinkcheckai.co.uk.
2. What we collect
- When you register: first name, email address, mobile number, the country code you chose, and the date and time you agreed to be contacted.
- How you found us: the page you signed up on, the advert and campaign tags in the link (UTM parameters), the Facebook click ID (
fbclid) if you came from a Facebook or Instagram ad and, only if you accept marketing cookies, the Meta Pixel browser identifiers. - Technical data: your country (worked out from your IP address; we don't store your IP address or precise location) and your browser type.
- If you get course access: your login email, which course tracks you can open and which lessons you've completed.
- If you email us: your message and email address.
We don't collect payment details, and we don't ask for or want information about your finances, trading accounts or balances.
3. Why we use it, and our lawful basis
- To review your registration and contact you about the course by email, phone or SMS: your consent (the tick box on the form). You can withdraw it at any time.
- To give you course access, send login links and save your progress: performance of a contract (our terms).
- To measure which adverts work: marketing cookies and the Meta Pixel run only with your consent. We also tell Meta, server-to-server, that a sign-up happened so it can match it to an advert, using your email, phone and name converted into irreversible codes (hashed) before they're sent. We do this on the basis of our legitimate interests in knowing which adverts work and not paying for ones that don't. You can object at any time (see section 8) and we will stop.
- To stop spam, bots and fake registrations: legitimate interests.
- To keep records and meet legal obligations: legal obligation and legitimate interests.
Course access is decided by a person reviewing registrations, not by an automated system. We don't make decisions about you based solely on automated processing.
4. Who we share it with
We never sell your data, and we never pass it to brokers, trading platforms or any provider of financial products. We use these service providers, who process data on our instructions:
- Supabase: database and login (data stored in London, UK).
- Cloudflare: website hosting, security, bot protection (Turnstile) and email forwarding.
- Resend: sends our login and course-access emails (EU, Ireland).
- Telegram: internal alerts to our team when someone registers, containing only first name, country and which page or advert they came from.
- Meta Platforms (Facebook, Instagram): advert measurement, as described in section 3. For data collected by the Meta Pixel, Meta and we can be joint controllers; Meta's role is explained in its privacy policy.
We may also disclose data if the law requires it, or to professional advisers under a duty of confidentiality.
5. International transfers
We are based in the EU (Bulgaria), and some of our providers process data in the US or elsewhere outside the UK and EEA. Where that happens we rely on an adequacy decision (for example the UK–US Data Bridge, for certified companies) or on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. Ask us for a copy of the relevant safeguards.
6. How long we keep it
- Registrations that don't get course access: 12 months from sign-up, then deleted.
- Students: while you have access and for 24 months after your last login, then deleted.
- If you ask us to delete your data or withdraw consent, we delete it within 30 days. We keep only a short note that you opted out, so we don't contact you again.
7. Cookies
Essential cookies run the site and keep you logged in. Marketing cookies (the Meta Pixel) are used only if you click Accept. Full details are in the cookie policy, and you can change your choice at any time via .
8. Your rights
You have the right to access your data, have it corrected or deleted, restrict or object to its use (including the advert matching in section 3), receive it in a portable format, and withdraw consent at any time without affecting what happened before. To use any of these rights, email hello@thinkcheckai.co.uk. We reply within one month.
To stop course contact, reply "stop" to any message or email us.
If you're unhappy with how we've handled your data, please tell us first. You can also complain to the UK Information Commissioner's Office or to the Bulgarian Commission for Personal Data Protection.
9. Age
The course is for adults aged 18 or over. We don't knowingly collect data from anyone younger. If you think we have, contact us and we'll delete it.
10. Security
Data is encrypted in transit. Access to registrations is limited to our team, using password-less login, and course pages are only available to approved students.
11. Changes
If we change this policy we'll update the date at the top. If a change is significant and we have your email, we'll tell you.