Privacy Policy

www.thcatherapeutics.com

Privacy Policy

1. Overview

This Privacy Policy explains how personal data is processed when you visit thcatherapeutics.com, communicate with us or make choices through our cookie-consent system.

Personal data means information relating to an identified or identifiable individual.

2. Controller

The controller responsible for processing personal data through this website is:

Farbod Parvin
Sole proprietor operating under the business name THCA Therapeutics

Wildenrother Str. 15
81245 Munich
Germany

Email: info@thcatherapeutics.com
Telephone: ‭+49 174 6617652‬

THCA Therapeutics is operated by Farbod Parvin as a sole proprietorship.

3. Data protection officer

A data protection officer has not been appointed because we currently understand that there is no legal obligation to appoint one.

Questions concerning data protection may be sent to:

info@thcatherapeutics.com

This statement must be reviewed if the scale or nature of our processing activities changes.

4. Hosting and delivery of the website

This website is hosted by:

IONOS SE
Elgendorfer Straße 57, 56410 Montabaur
Germany

When you access the website, the hosting provider may process technical information required to deliver the website and maintain its security. This may include:

  • IP address;

  • date and time of access;

  • requested page or file;

  • browser type and version;

  • operating system;

  • referring website;

  • amount of data transferred;

  • access status or HTTP status code; and

  • technical error and security information.

The processing is necessary to provide a stable and secure website, identify technical errors, prevent misuse and protect our systems.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and technically functional operation of the website.

Server-log data is generally retained for 14 days, unless longer retention is necessary to investigate a security incident, prevent misuse or comply with a legal obligation.

Where the hosting provider processes personal data on our behalf, we will enter into an appropriate data-processing agreement as required by Article 28 GDPR.

5. Contacting us

When you contact us by email, telephone or another communication channel, we process the information you provide. This may include:

  • your name;

  • your contact details;

  • your organization and professional role;

  • the content of your message;

  • attached documents; and

  • related correspondence.

We process this information to respond to your inquiry, communicate with you and manage potential scientific, commercial, investment, advisory or partnership discussions.

Depending on the context, the legal basis is:

  • Article 6(1)(b) GDPR, where processing is necessary to take steps at your request before entering into a contract;

  • Article 6(1)(f) GDPR, where we have a legitimate interest in managing professional communications and responding to inquiries;

  • Article 6(1)(a) GDPR, where you have expressly consented to a particular use; or

  • Article 6(1)(c) GDPR, where processing is required to comply with a legal obligation.

Correspondence is retained only for as long as reasonably necessary for the relevant purpose. It may be retained longer where required by statutory retention duties, to establish or defend legal claims, or to document important business communications.

6. Sensitive information

Please do not send us medical records, health information, genetic data or other sensitive personal information through the website or by ordinary email unless we have specifically requested it and established an appropriate secure process.

This website is not intended to provide individual medical advice, recruit participants for a clinical trial or collect adverse-event reports.

If these functions are introduced in the future, this Privacy Policy and the relevant data-collection procedures will be updated before such processing begins.

7. Cookies and similar technologies

This website may use cookies and comparable technologies, including local storage, tags, pixels or similar identifiers.

Cookies are small data files stored on or accessed from your device. They may be used to provide essential website functions, remember privacy choices and, with your consent, measure website usage.

Essential technologies

Technologies that are strictly necessary to provide a service requested by you or to operate essential website functions may be used without consent where legally permitted.

These may include technologies used to:

  • store your privacy preferences;

  • maintain website security;

  • distribute network traffic;

  • prevent fraudulent or abusive activity; and

  • provide functions specifically requested by you.

The legal basis for accessing or storing information on your device is Section 25(2) TDDDG where applicable. Any subsequent processing of personal data is based on Article 6(1)(f) GDPR, unless another legal basis applies.

Our legitimate interest is the secure and functional operation of the website.

Optional technologies

Analytics, advertising or other non-essential technologies are activated only after you provide consent through the cookie banner.

The legal basis for storing or accessing information on your device is Section 25(1) TDDDG. The legal basis for the associated processing of personal data is Article 6(1)(a) GDPR.

You may refuse optional cookies without losing access to the essential functions of the website.

8. Consent-management platform

We use the following consent-management service:

Google Analytics
Provider: Google Ireland Limited
Address: Gordon House, Barrow Street, Dublin 4, D04 E5W5
Privacy information: [link]

The service records and manages your cookie choices. Depending on its configuration, it may process:

  • consent or refusal status;

  • date and time of the decision;

  • a consent identifier;

  • browser and device information;

  • abbreviated or complete IP address; and

  • the version of the consent notice displayed.

The legal bases are Section 25(2) TDDDG and Article 6(1)(c) GDPR, insofar as processing is necessary to demonstrate compliance with consent requirements. Where applicable, we also rely on Article 6(1)(f) GDPR and our legitimate interest in documenting and administering legally valid privacy choices.

Consent records are retained for 2 months or as otherwise required to demonstrate compliance.

You can revise or withdraw your choices at any time by selecting “Cookie Settings” in the website footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

9. Website analytics

Subject to your prior consent, we use:

Google analytics
Provider: Google Ireland Limited
Address: Gordon House, Barrow Street, Dublin 4, D04 E5W5
Country: Ireland

The analytics service helps us understand how visitors use the website and improve its content, structure and technical performance.

Depending on the selected service and configuration, the following information may be processed:

  • IP address;

  • device and browser information;

  • approximate location;

  • visited pages;

  • time and duration of visits;

  • referring source;

  • interactions with website elements;

  • technical performance information; and

  • pseudonymous online identifiers.

The service is not activated unless you consent to the Analytics category in the cookie banner.

The legal bases are Section 25(1) TDDDG and Article 6(1)(a) GDPR.

Analytics data is retained for [retention period].

You may withdraw your consent at any time through the Cookie Settings link. Withdrawal applies prospectively.

Analytics configuration

Where supported by the selected provider, we configure analytics in a privacy-conscious manner. Measures may include:

  • activation only after consent;

  • shortened retention periods;

  • IP-address truncation or anonymization;

  • disabling advertising functions;

  • disabling cross-service data sharing;

  • avoiding user-ID tracking; and

  • entering into a data-processing agreement with the provider.

The exact wording of this section must be updated after the analytics provider and technical configuration have been selected.

10. Recipients of personal data

Personal data may be disclosed to service providers that assist us with:

  • website hosting;

  • domain and email services;

  • website maintenance;

  • consent management;

  • analytics;

  • cybersecurity;

  • professional advice; and

  • legal or regulatory compliance.

Service providers acting on our instructions are permitted to process personal data only for the agreed purposes and in accordance with applicable data-protection requirements.

We may also disclose information where required by law, a court, a competent authority or where necessary to establish, exercise or defend legal claims.

11. International data transfers

Some service providers may be established outside the European Economic Area or may process data in countries outside the European Economic Area.

Where personal data is transferred internationally, we use an appropriate transfer mechanism where required, such as:

  • an adequacy decision adopted by the European Commission;

  • the European Commission’s Standard Contractual Clauses;

  • supplementary technical and organizational safeguards; or

  • another legally recognized transfer mechanism.

Where a provider participates in the EU–US Data Privacy Framework and is validly certified for the relevant processing, a transfer may be based on the applicable adequacy decision.

The final version of this section must identify any actual international transfers made by the hosting, consent or analytics providers.

12. Retention

We retain personal data only for as long as necessary for the purpose for which it was collected.

The applicable period depends on:

  • the nature and purpose of the processing;

  • whether an inquiry or business relationship remains active;

  • applicable statutory retention obligations;

  • limitation periods;

  • security requirements; and

  • whether consent has been withdrawn.

After the applicable retention period expires, personal data is deleted or anonymized unless continued storage is legally required.

13. Your rights

Subject to the conditions of the GDPR, you may have the right to:

  • obtain information about personal data processed concerning you;

  • request correction of inaccurate or incomplete data;

  • request deletion of your data;

  • request restriction of processing;

  • receive data you provided in a structured, commonly used and machine-readable format;

  • object to processing based on legitimate interests;

  • withdraw consent at any time with future effect; and

  • lodge a complaint with a competent data-protection supervisory authority.

Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.

We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.

Where personal data is processed for direct marketing, you may object at any time without stating a reason.

To exercise your rights, contact:

info@thcatherapeutics.com

We may request reasonable information to verify your identity before responding.

14. Right to complain

You have the right to lodge a complaint with a data-protection supervisory authority.

Where the business is operated from Bavaria by a private-sector controller, the authority expected to be competent is:

Bavarian State Office for Data Protection Supervision
Bayerisches Landesamt für Datenschutzaufsicht – BayLDA
Promenade 18
91522 Ansbach
Germany

You may also contact the supervisory authority responsible for your habitual residence, place of work or the place of the alleged infringement.

15. Automated decision-making

We do not currently use personal data collected through this website for automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals.

16. Data security

We use reasonable technical and organizational measures intended to protect personal data against unauthorized access, loss, alteration, disclosure or destruction.

These measures may include encrypted transmission, access controls, secure hosting, software updates, backups and restricted administrative access.

No method of internet transmission or electronic storage can provide absolute security.

17. External links

This website may contain links to third-party websites. When you follow an external link, the relevant third party is responsible for its own processing activities.

Please review the privacy information of the relevant third-party provider.

18. Social-media links

If this website displays ordinary links to social-media profiles, no data is intentionally transmitted to the relevant platform merely because the link is displayed.

Data may be transmitted when you select the link and visit the third-party platform. The platform’s own privacy terms then apply.

This section must be revised if embedded social-media feeds, tracking pixels, share buttons or platform plugins are introduced.

19. Changes to this Privacy Policy

We may update this Privacy Policy when the website, our processing activities, service providers or legal requirements change.

The version published on this website at the relevant time applies.

Last updated: July 2026