Privacy Policy
Last updated: July 30, 2026
Only the French version of this document is legally binding. This English text is provided for information purposes.
This policy describes how RenderThink processes personal data within the Sudothink platform, in accordance with the General Data Protection Regulation (GDPR) and the amended French Data Protection Act.
1. Data controller
RENDERTHINK, a simplified joint-stock company with a share capital of 2 EUR, registered office at 17 rue Pasteur, 38400 Saint-Martin-d'Heres (SIRET 102 977 147 00010), is the controller of the data described in section 3.
No data protection officer (DPO) has been appointed to date. Any request regarding your data may be sent to: contact@sudothink.com.
2. Scope and roles: two distinct situations
Sudothink processes personal data in two different legal contexts.
a. You, the platform user. When you create an account and use the dashboard, RenderThink acts as a data controller. This is the subject of this policy.
b. The people whose computers are managed. When a customer uses Sudothink to administer the Windows computers of its own employees or end users, RenderThink acts as a processor, on behalf of the customer, who is then the data controller. This context is governed by the Data Processing Agreement (DPA), not by this policy.
3. Data collected
Within the context of point 2.a, we collect:
- Account data: first name, last name, email address, password (hashed), OAuth login identifiers, interface and language preferences.
- Usage data: actions performed in the platform, deployment and configuration logs, organisations and roles.
- Technical data: connection IP addresses, browser, operating system, error logs.
- Billing data: subscribed plan, transaction history, billing details. Card data is processed directly by Stripe and is never stored by RenderThink.
- Comment data: when you post a comment on a blog article (signed-in users only), we keep the comment content, the name associated with your account, and the publication date. Comments are subject to moderation before they are displayed.
- Blog audience measurement: we count article views in an aggregated, anonymous way. An ephemeral technical fingerprint derived from the IP address is used solely to avoid counting the same visit several times, then is not retained.
We do not collect sensitive data within the meaning of Article 9 of the GDPR.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provision of the service and account management | Performance of the contract |
| Billing and accounting obligations | Legal obligation |
| Security, fraud prevention, service improvement | Legitimate interest |
| Product usage measurement and internal operational notifications | Legitimate interest |
| Service-related communications (maintenance, updates) | Performance of the contract |
| Marketing communications (news, newsletter) | Consent |
5. Artificial intelligence assistant
The platform offers an AI-based help assistant. When you query it, your question and the context required to answer it (for example results from your organisation, such as device names or technical information) are transmitted to our processor OpenAI, whose processing may take place in the United States.
This transfer is governed by standard contractual clauses. We limit the data transmitted to the strict minimum and have enabled the option excluding the use of your data for model training. Conversations with the assistant are kept for 365 days, then automatically deleted.
6. Recipients and processors
Your data is processed by RenderThink and by the following processors, strictly for the provision of the service:
| Processor | Role | Location | Safeguard |
|---|---|---|---|
| OVHcloud | Hosting of the application and databases | France (EU) | No transfer outside the EU |
| Stripe Payments Europe | Payment processing | Ireland (EU) | European Union |
| Cloudflare, Inc. | Website hosting (Pages), CDN, DNS, storage of deployed software | United States | Standard contractual clauses |
| OpenAI | Artificial intelligence assistant | United States | Standard contractual clauses |
| PostHog | Audience measurement and product analytics | European Union | European Union |
| Resend, Inc. | Sending of transactional emails (account, notifications, invitations) | United States (sent from the European Union) | Standard contractual clauses |
We never sell your data and do not share it with any third party for advertising purposes. We may disclose it to the competent authorities where required by law.
7. Transfers outside the European Union
The main hosting (application and databases) is located in the European Union. Some processors (Cloudflare, OpenAI, Resend) may process data in the United States; these transfers are governed by standard contractual clauses adopted by the European Commission, together with appropriate safeguards.
8. Retention periods
- Organisation operational data (fleet, configurations): deleted after a grace period of approximately 37 days following subscription termination.
- Account data: kept for the duration of the relationship. You may request anonymisation of your account at any time (see section 9).
- Technical logs: 12 months.
- AI assistant conversations: 365 days.
- Billing data: 10 years, in accordance with French accounting and tax obligations.
9. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability.
Two of these rights are available in self-service from your account:
- Portability: you can export all your personal data in a structured file.
- Erasure: you can request anonymisation of your account. To preserve the integrity of logs and accounting references, erasure is carried out by anonymisation (your identifying data is erased and the account is neutralised) rather than by physical deletion of linked records.
For other rights, or in case of difficulty, contact contact@sudothink.com. You may also lodge a complaint with the CNIL (www.cnil.fr).
10. Cookies
The use of cookies and trackers is described in our Cookie Policy.
11. Security
We implement appropriate technical and organisational measures: encryption of communications (HTTPS/TLS), hashed passwords, authentication tokens stored in HTTP-only cookies (Secure, SameSite=Strict), an encrypted vault for secrets (AES-256-GCM, Argon2id derivation), strict isolation of data between organisations, and automatic masking of personal data and secrets in application logs.
12. Changes
This policy may be updated. The date of last modification appears at the top of this page. In the event of a substantial change, you will be informed by email or via the platform.