ThingsBoard License Portal - Privacy Policy

Revision Date: September 15, 2026

1. Introduction and Scope

This Privacy Policy (“Policy”) governs the collection, processing, use, disclosure, and protection of personal data by ThingsBoard, Inc. (“ThingsBoard,” “we,” “us,” or “our”) across all our operational touchpoints, including our corporate website (thingsboard.io), the ThingsBoard License Portal (https://license.thingsboard.io, hereinafter the “Portal”), our cloud services, IoT software ecosystem, customer support channels, and administrative infrastructure.

Our role depends on the data. ThingsBoard, Inc. acts as the data controller for the personal data described in this Policy — Portal accounts, licensing, billing and customer records, website and support interactions, and the system and license data described in Section 2.3 — under applicable global data protection laws, including the EU General Data Protection Regulation (GDPR) and applicable US state privacy legislation.

Where we process personal data contained in a customer’s own ThingsBoard deployment on that customer’s instructions — including data held in our cloud services and data sent to our hosted AI service as described in Section 2.5 — we act as a data processor on behalf of that customer, who is the controller of it. That processing is governed by our agreement with the customer, including any data processing agreement, rather than by this Policy.

This Policy applies to visitors, account holders, customers, developers, and representatives of Organizations utilizing ThingsBoard products, services, or web platforms. Our products, website, and Portal are intended for business and professional use and are not directed to children under 16; we do not knowingly collect personal data from children.

2. Information We Collect

We collect information directly from you, automatically through your interactions with our platforms, and from third-party services.

2.1 Information Provided Directly by You

2.2 Payment and Billing Data

What Stripe handles. We do not collect, process or store payment instruments — card numbers, bank credentials or equivalent. All card transactions made through the Portal or our website are collected, processed and secured by our payment processor, Stripe, Inc. (“Stripe”), under its own privacy policy. Stripe returns to us only transaction confirmations, billing addresses, Tax/VAT IDs and payment status.

What we hold ourselves. We maintain our own billing and customer records, in our accounting system (Intuit Inc., QuickBooks) and our customer relationship management system (Pipedrive). These records include your legal entity name and billing address, Tax/VAT ID, the name, business email address and telephone number of your billing and account contacts, purchase order numbers, invoices and credit notes, amounts, currency, dates, payment status and payment history, and correspondence relating to your purchases and account.

We keep these records to perform our contract with you, to meet our accounting and tax obligations, and to manage our relationship with your organization. Retention is described in Section 6.

2.3 System, License Check, and Instance Check Data

When you utilize our Software, license keys, or the Portal, we collect technical operational data:

2.4 Website Usage, Cookies, and Tracking Technologies

When visiting our websites or Portal, we automatically collect log data and technical information, including your IP address, browser type, operating system, referring URLs, access times, pages viewed, and device parameters. We utilize essential cookies for authentication and platform security, as well as analytics cookies (where consented to) to measure platform usage and performance.

2.5 ThingsBoard AI Feature Interactions

When users interact with ThingsBoard AI capabilities:

2.6 Business Contact and Prospect Data

We also hold business contact records for people who have not purchased from us — for example, someone who requests a demonstration or a quotation, registers for a webinar or event, subscribes to updates, or otherwise contacts our sales team. These records are kept in our customer relationship management system (Pipedrive) and typically comprise name, business email address, telephone number, employer, role, country, the source of the enquiry, and our correspondence about it.

We process this data on the basis of our legitimate interests in developing and managing business relationships. You may object at any time under Section 8, and every marketing email carries an unsubscribe link. Where we rely on consent for electronic marketing, you may withdraw it at any time, without affecting processing carried out before withdrawal.

We process personal data only where we have a valid legal basis under applicable law:

Processing Purpose Category of Data Legal Basis (GDPR / Global Equivalent)
Account Creation & Service Delivery: Administering accounts, issuing license keys, facilitating Portal access, sending system notifications. Account information, credentials, organization details. Performance of a Contract (Art. 6(1)(b) GDPR).
License Compliance & Grant Evaluation: Verifying key validity, evaluating Community Grant eligibility, and ensuring adherence to device caps and License Agreement terms. License usage data, Instance Check Reports, commercial declarations. Legitimate Interests (Art. 6(1)(f) GDPR) in enforcing IP rights; Performance of Contract (Art. 6(1)(b) GDPR).
Fraud Prevention & Abuse Mitigation: Detecting manipulated declarations, illegal key sharing, unauthorized access, or breach of software terms. Deployment and cluster identifiers, account log data, hashed identifiers. Legitimate Interests (Art. 6(1)(f) GDPR) in mitigating legal and commercial risk.
Payment & Billing Administration: Facilitating Stripe billing, issuing invoices, maintaining accounting records, processing tax liabilities. Transaction logs, Tax/VAT ID, billing address, legal entity name, billing contact details, invoices and payment history. Performance of Contract (Art. 6(1)(b) GDPR) & Legal Obligation (Art. 6(1)(c) GDPR).
Product Analytics & Improvement: Producing statistical and analytical reports on use of the Software to guide product development, prioritisation and improvement. Usage snapshot statistics only (aggregate, platform-wide counters, pseudonymous and attributable to a licensed account rather than to an individual). Legitimate Interests (Art. 6(1)(f) GDPR) in understanding and improving our own product. The usage snapshot can be disabled in the Software’s configuration at any time, without affecting platform functionality, license validity or support entitlements.
Communications & Consent-Based Activities: Sending direct newsletters, product updates, or voluntary feedback collection. Contact details, communication preferences. Consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time.
Anti-Abuse & License Enforcement: Validating online licenses, verifying deployment scale, detecting duplicate license usage across isolated instances, and logging connecting network addresses. Source IP address; for offline licenses: customer and subscription identifiers, software version, packaging type; for online licenses: license secret, instance and cluster identifiers. Legitimate Interests (Art. 6(1)(f) GDPR) in protecting intellectual property rights, enforcing license terms, and preventing unauthorized duplication.
AI Feature Delivery: Processing user messages, maintaining conversation history, retrieving platform data requested by the AI model, and generating requested content (dashboards, IoT solutions, and other configurations). User messages, conversation history, platform data retrieved via tool calls, UI screen context, time zone, browser language. Performance of Contract (Art. 6(1)(b) GDPR).
AI Quality Assurance & Observability: Debugging AI features, evaluating answer quality and improving AI responses, and maintaining AI audit records; accounting for AI credit usage. AI audit records containing the full conversation content (user messages, AI responses, model reasoning, tool call arguments and results), user and tenant identifiers, user email; aggregated per-tenant usage counters. Legitimate Interests (Art. 6(1)(f) GDPR) in operational quality and service security; Performance of a Contract (Art. 6(1)(b) GDPR) for credit accounting.
Customer Relationship Management: Maintaining records of your organization, its contacts, purchases and correspondence in order to administer your account, respond to requests and manage renewals. Company name, contact name, business email address and telephone number, purchase and payment history, correspondence. Performance of Contract (Art. 6(1)(b) GDPR) & Legitimate Interests (Art. 6(1)(f) GDPR) in administering and developing our customer relationships.
Sales and Business Development: Responding to enquiries, preparing quotations, and maintaining prospect records in our CRM. Name, business email address and telephone number, employer, role, country, enquiry source, correspondence. Legitimate Interests (Art. 6(1)(f) GDPR) in developing business relationships, and Consent (Art. 6(1)(a) GDPR) where required for electronic marketing.

4. Third-Party Data Sharing and Processing

ThingsBoard does not sell, rent, or trade your personal data. We share personal and technical data strictly as necessary for administrative and legal purposes:

5. International Data Transfers

ThingsBoard, Inc. is a United States corporation. Personal data collected from users located outside the US (including the European Economic Area (EEA), the United Kingdom, and Switzerland) is transferred to, stored, and processed in the United States and other regions where ThingsBoard or its subprocessors operate.

To protect cross-border transfers of personal data originating from the EEA, UK, or Switzerland, ThingsBoard relies on legally recognized transfer mechanisms, including:

6. Retention, Account Deletion, and Post-Deletion Evidentiary Rules

6.1 Standard Account Retention

We retain personal data associated with active user or Organization accounts for as long as the account remains open, as needed to fulfill contractual obligations, or as required by applicable tax, accounting, and legal recordkeeping regulations.

6.2 Voluntary Account Deletion

You may request or execute the deletion of your user or Organization account at any time within the Portal settings or by contacting privacy operations. Upon execution of an account deletion request, ThingsBoard permanently deletes your personal identity data—including your name, personal email address, login credentials, and direct links connecting your identity to system records.

If your Organization operates the Software under an offline (air-gapped) license, our automated cloud systems cannot detect when a user is deleted locally within your infrastructure. Consequently, local deletions do not automatically trigger a deletion of associated account data held centrally by ThingsBoard. To exercise a deletion of data held by ThingsBoard, the user or Organization representative must manually submit a deletion request to privacy@thingsboard.io, providing information sufficient for us to locate the data, such as an account or subscription ID.

6.3 Technical Data and License Evidence Retained After Account Deletion

Pursuant to Article 17(3)(e) of the GDPR (and equivalent statutory exemptions permitting retention necessary for the establishment, exercise, or defense of legal claims):

6.4 Suspected Violation & Integrity Retention

Where an account or deployment is linked to an ongoing investigation or suspected violation of our LICENSE terms, License Agreement, Community Grant License Agreement, or Portal Terms at the time of account deletion, ThingsBoard reserves the right to retain a minimal, privacy-preserving cryptographic record (a one-way hashed identifier) tied to the historical deployment or identity. This hashed record is retained strictly for the purpose of establishing, exercising, or defending against legal claims, preventing fraudulent re-registration, and enforcing retroactive commercial license compliance under GDPR Article 17(3)(e).

6.5 AI Feature Data

Conversation history and AI audit records created by the AI features (see Section 2.5) are retained while the user account remains active, as part of service delivery, security, and AI credit accounting. Users may delete individual conversations at any time; deleted conversations are immediately and permanently erased. Upon account deletion, all remaining records are permanently deleted or de-identified in the manner described below for Improvement Records within 90 days, alongside the deletion described in Section 6.2.

6.6 Business Contact and Prospect Data

Where an enquiry does not lead to a purchase, we keep the contact record described in Section 2.6 for as long as the enquiry remains a realistic business prospect. We judge that by whether there has been meaningful interaction — a reply, a meeting, a quotation, or a renewed enquiry — and we delete or anonymize records that no longer meet it when we review our records. You may ask us to delete your record, or object to the processing, at any time under Section 8, and we will act on that request.

7. Data Security

ThingsBoard maintains appropriate administrative, physical, and technical safeguards designed to protect personal data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access.

8. Your Data Subject Rights

Depending on your jurisdiction (including the EEA, UK, Canada, and various US states), you may hold statutory rights regarding your personal data:

AI Features: AI data processing occurs only when users actively invoke AI features. Administrators can disable AI features system-wide, per tenant, or per user role; when disabled, no AI-related data is collected or sent.

To exercise any applicable right, please submit a written request to privacy@thingsboard.io. We will respond within statutory timeframes upon verifying your identity and legal authority.

9. Amendments to This Privacy Policy

ThingsBoard reserves the right to modify or update this Privacy Policy periodically to reflect technological changes, legal requirements, or adjustments to our business practices. The updated Policy will be published on our website and Portal with a revised “Revision Date”. In the event of material structural or legal changes, registered account holders will be notified via email to the primary address associated with their Organization account prior to the effective date.

10. Contact Information

For inquiries, legal notices, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer at: privacy@thingsboard.io