Privacy Policy

Last updated: July 30, 2026

Only the French version of this document is legally binding. This English text is provided for information purposes.

This policy describes how RenderThink processes personal data within the Sudothink platform, in accordance with the General Data Protection Regulation (GDPR) and the amended French Data Protection Act.

1. Data controller

RENDERTHINK, a simplified joint-stock company with a share capital of 2 EUR, registered office at 17 rue Pasteur, 38400 Saint-Martin-d'Heres (SIRET 102 977 147 00010), is the controller of the data described in section 3.

No data protection officer (DPO) has been appointed to date. Any request regarding your data may be sent to: contact@sudothink.com.

2. Scope and roles: two distinct situations

Sudothink processes personal data in two different legal contexts.

a. You, the platform user. When you create an account and use the dashboard, RenderThink acts as a data controller. This is the subject of this policy.

b. The people whose computers are managed. When a customer uses Sudothink to administer the Windows computers of its own employees or end users, RenderThink acts as a processor, on behalf of the customer, who is then the data controller. This context is governed by the Data Processing Agreement (DPA), not by this policy.

3. Data collected

Within the context of point 2.a, we collect:

  • Account data: first name, last name, email address, password (hashed), OAuth login identifiers, interface and language preferences.
  • Usage data: actions performed in the platform, deployment and configuration logs, organisations and roles.
  • Technical data: connection IP addresses, browser, operating system, error logs.
  • Billing data: subscribed plan, transaction history, billing details. Card data is processed directly by Stripe and is never stored by RenderThink.
  • Comment data: when you post a comment on a blog article (signed-in users only), we keep the comment content, the name associated with your account, and the publication date. Comments are subject to moderation before they are displayed.
  • Blog audience measurement: we count article views in an aggregated, anonymous way. An ephemeral technical fingerprint derived from the IP address is used solely to avoid counting the same visit several times, then is not retained.

We do not collect sensitive data within the meaning of Article 9 of the GDPR.

4. Purposes and legal bases

Purpose Legal basis
Provision of the service and account management Performance of the contract
Billing and accounting obligations Legal obligation
Security, fraud prevention, service improvement Legitimate interest
Product usage measurement and internal operational notifications Legitimate interest
Service-related communications (maintenance, updates) Performance of the contract
Marketing communications (news, newsletter) Consent

5. Artificial intelligence assistant

The platform offers an AI-based help assistant. When you query it, your question and the context required to answer it (for example results from your organisation, such as device names or technical information) are transmitted to our processor OpenAI, whose processing may take place in the United States.

This transfer is governed by standard contractual clauses. We limit the data transmitted to the strict minimum and have enabled the option excluding the use of your data for model training. Conversations with the assistant are kept for 365 days, then automatically deleted.

6. Recipients and processors

Your data is processed by RenderThink and by the following processors, strictly for the provision of the service:

Processor Role Location Safeguard
OVHcloud Hosting of the application and databases France (EU) No transfer outside the EU
Stripe Payments Europe Payment processing Ireland (EU) European Union
Cloudflare, Inc. Website hosting (Pages), CDN, DNS, storage of deployed software United States Standard contractual clauses
OpenAI Artificial intelligence assistant United States Standard contractual clauses
PostHog Audience measurement and product analytics European Union European Union
Resend, Inc. Sending of transactional emails (account, notifications, invitations) United States (sent from the European Union) Standard contractual clauses

We never sell your data and do not share it with any third party for advertising purposes. We may disclose it to the competent authorities where required by law.

7. Transfers outside the European Union

The main hosting (application and databases) is located in the European Union. Some processors (Cloudflare, OpenAI, Resend) may process data in the United States; these transfers are governed by standard contractual clauses adopted by the European Commission, together with appropriate safeguards.

8. Retention periods

  • Organisation operational data (fleet, configurations): deleted after a grace period of approximately 37 days following subscription termination.
  • Account data: kept for the duration of the relationship. You may request anonymisation of your account at any time (see section 9).
  • Technical logs: 12 months.
  • AI assistant conversations: 365 days.
  • Billing data: 10 years, in accordance with French accounting and tax obligations.

9. Your rights

In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability.

Two of these rights are available in self-service from your account:

  • Portability: you can export all your personal data in a structured file.
  • Erasure: you can request anonymisation of your account. To preserve the integrity of logs and accounting references, erasure is carried out by anonymisation (your identifying data is erased and the account is neutralised) rather than by physical deletion of linked records.

For other rights, or in case of difficulty, contact contact@sudothink.com. You may also lodge a complaint with the CNIL (www.cnil.fr).

10. Cookies

The use of cookies and trackers is described in our Cookie Policy.

11. Security

We implement appropriate technical and organisational measures: encryption of communications (HTTPS/TLS), hashed passwords, authentication tokens stored in HTTP-only cookies (Secure, SameSite=Strict), an encrypted vault for secrets (AES-256-GCM, Argon2id derivation), strict isolation of data between organisations, and automatic masking of personal data and secrets in application logs.

12. Changes

This policy may be updated. The date of last modification appears at the top of this page. In the event of a substantial change, you will be informed by email or via the platform.