Data Processing Agreement (DPA)
Last updated: June 23, 2026
Only the French version of this document is legally binding. This English text is provided for information purposes.
This Data Processing Agreement (the "Agreement") supplements the Sudothink Terms of Sale and Terms of Use. It governs the processing of personal data carried out by RenderThink on behalf of the Customer, in accordance with Article 28 of the General Data Protection Regulation (GDPR). In the event of conflict with the general terms on data protection matters, this Agreement prevails.
1. Subject matter and roles of the parties
When managing its IT fleet through Sudothink, the Customer acts as data controller and RenderThink acts as processor. RenderThink processes the data described in Annex 1 solely to provide the service and on the Customer's instructions.
2. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in Article 4 of the GDPR.
3. Description of the processing
The nature, purposes, categories of data and data subjects, and the duration of the processing are described in Annex 1.
4. Documented instructions
RenderThink processes the data only on the Customer's documented instructions, of which the general terms and the use of the platform constitute the initial expression. RenderThink informs the Customer if, in its opinion, an instruction infringes the GDPR or any other applicable data protection provision.
5. Confidentiality
RenderThink ensures that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
6. Security
RenderThink implements the appropriate technical and organisational measures provided for in Article 32 of the GDPR, described in Annex 3, to ensure a level of security appropriate to the risk.
7. Sub-processors
The Customer authorises RenderThink to use the sub-processors listed in Annex 2. RenderThink imposes on those sub-processors data protection obligations equivalent to those of this Agreement.
RenderThink informs the Customer of any intended addition or replacement of a sub-processor, with 30 days' notice. The Customer has 15 days from such notice to object, on legitimate grounds relating to data protection. Where an objection cannot be resolved, the Customer may terminate the affected part of the service free of charge.
8. Assistance to the Customer
Taking into account the nature of the processing, RenderThink assists the Customer:
- by putting in place appropriate technical and organisational measures to respond to requests from data subjects exercising their rights;
- by notifying the Customer, without undue delay after becoming aware of it, of any data breach affecting the data processed on its behalf, and by providing the information required for the Customer's own obligations;
- by providing reasonable assistance with data protection impact assessments and prior consultations with the supervisory authority.
9. Transfers outside the European Union
Where a sub-processor processes data outside the European Union (see Annex 2), such transfer is governed by standard contractual clauses adopted by the European Commission, together with appropriate safeguards.
10. Fate of the data at the end of the contract
At the end of the service, RenderThink deletes or returns to the Customer, at the latter's choice, all data processed on its behalf, and destroys existing copies, save for any statutory retention obligation. Failing any contrary instruction from the Customer, operational data is deleted upon expiry of the grace period provided for in the general terms.
11. Audits
RenderThink makes available to the Customer the information necessary to demonstrate compliance with the obligations of this Agreement. The Customer may carry out audits, including inspections, on reasonable terms agreed between the parties (reasonable notice, respect for confidentiality and security, proportionate frequency), without disrupting the service or compromising the security of other customers.
12. Liability
The liability of the parties under this Agreement is subject to the limits provided for in the Sudothink general terms, without prejudice to the mandatory provisions of the GDPR.
13. Term
This Agreement takes effect upon acceptance of the general terms and remains in force for as long as RenderThink processes data on behalf of the Customer.
Annex 1: Description of the processing
- Subject matter and purposes: remote configuration, deployment and administration of the Customer's Windows computers, including inventory reporting and the execution of operations requested by the Customer.
- Categories of data: hardware and software inventory of the computers, machine names, local Windows accounts, computer IP addresses, execution and deployment logs.
- Categories of data subjects: end users and employees of the Customer whose computers are managed through Sudothink.
- Duration of processing: the duration of the contractual relationship, plus the applicable grace period before deletion of operational data.
Annex 2: Sub-processors
| Sub-processor | Role | Location | Transfer safeguard |
|---|---|---|---|
| OVHcloud | Hosting of the application and databases | France (EU) | No transfer outside the EU |
| Stripe Payments Europe | Payment processing | Ireland (EU) | European Union |
| Cloudflare, Inc. | CDN, DNS, storage of deployed software | United States | Standard contractual clauses |
| OpenAI | Artificial intelligence assistant | United States | Standard contractual clauses, training opt-out |
| PostHog | Audience measurement and product analytics | European Union | European Union |
Annex 3: Technical and organisational measures
- Encryption of communications in transit (HTTPS/TLS) and of secrets at rest (AES-256-GCM vault, Argon2id derivation).
- Strict isolation of data between organisations (systematic multi-tenant partitioning).
- Role-based access control and available two-factor authentication.
- Logging and traceability of sensitive access; automatic masking of personal data and secrets in logs.
- Hashed passwords; authentication tokens in HTTP-only cookies (Secure, SameSite=Strict).
- Regular backups of the infrastructure hosted in the European Union.