Privacy Policy
Last updated: April 2, 2026
RenderThink respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use and protect your information in accordance with the General Data Protection Regulation (GDPR).
1. Data controller
RenderThink - SAS RENDERTHINK, registered in France under SIRET number 102 977 147 00010, specialized in AI image transformation services for professionals.
Data protection contact: contact@renderthink.com. In the absence of a designated Data Protection Officer (DPO), any data protection request may be addressed to this email.
2. Data collected
Account data
- Name, first name, professional title
- Email address, phone number (optional)
- Encrypted password, authentication preferences
- Profile picture, company information
Usage data
- Created projects, file metadata
- Uploaded and transformed images (temporarily)
- Activity history, user preferences
- Interface settings, language, notifications
Technical data
- IP address, approximate geolocation
- Device type, browser, operating system
- Pages visited, session time, actions performed
- Performance and error logs
Billing data
- Credit purchase and subscription history
- Billing information and addresses
- Payment data processed by Stripe (not stored by us)
3. Processing purposes
- Providing and improving image transformation services
- User account management and authentication
- Subscription management, billing and commercial support
- Technical support and customer assistance
- Usage analysis to improve the platform
- Platform security and fraud prevention
- Compliance with legal and regulatory obligations
- Transactional and marketing communications (with consent)
4. Legal basis for processing
Contract execution: Providing RenderThink services according to our ToS
Legitimate interest: Improving our services, security, usage analysis
Legal obligation: Accounting, invoice retention, fraud prevention
Consent: Marketing communications
5. Data sharing
Processors
- Hosting on secure European infrastructure (OVHcloud)
- Cloudflare - File storage and content delivery (R2)
- Stripe - Secure payment processing (PCI DSS certified)
- AI technologies - AI processing via secure API, data not used for third-party model training
- Monitoring services - Performance monitoring and error detection
Authorities
We may have to communicate your data to competent authorities in case of legal obligation or judicial request.
No data sale
We do not sell, rent, or trade your personal data with third parties for commercial purposes.
Right to object to sub-processors
In accordance with GDPR Article 28(4), you have the right to object to the engagement of new sub-processors. In the event of a new sub-processor being added, you will be notified by email with 30 days' notice. You have 15 days from notification to object. In case of justified objection, you may terminate your contract at no cost or request additional compliance measures.
6. Data security
- Secure connections: HTTPS/TLS for all communications, encryption of sensitive data at rest
- Secure authentication: hashed passwords, JWT sessions, login attempt limits, access logging
- Monitoring: rate limiting, automatic blocking after repeated failed attempts
- Backups: regular data backups, hosting on secure European infrastructure
- In case of security incident: CNIL notification within 72h as per GDPR, affected client notification, corrective measures
7. Retention period
Account data: During contract duration + 3 years after termination
Projects and files: During contract duration + 30 days after termination
Billing data: 10 years for accounting and tax obligations
Technical logs: 6 months maximum for security and optimization
8. International transfers
Some of our processors may process your data outside the EU. These transfers are governed by:
- European Commission adequacy decisions
- Standard contractual clauses for data protection
9. Your rights
Right of access
Obtain a copy of your personal data
Right to rectification
Correct inaccurate or incomplete data
Right to erasure
Request deletion of your data
Right to restriction
Restrict processing of your data
Right to portability
Retrieve your data in a structured format
Right to object
Object to processing for legitimate reasons
To exercise your GDPR rights, contact us at contact@renderthink.com contact@renderthink.com . We will respond within a maximum of 30 days. For any request, please specify your identity and the right you wish to exercise.
10. Cookies and similar technologies
RenderThink uses cookies strictly necessary for the operation of the service (authentication, language preferences) and, subject to your explicit consent, a PostHog analytics solution (hosted in the European Union) to measure platform usage and improve the service. No advertising or third-party tracking cookies are used. You can change your preferences at any time via the 'Cookie preferences' link in the footer.
For more details, see our cookie policy.
11. Complaints
If you believe your rights are not being respected, you can file a complaint with your national data protection authority.
12. Policy updates
This policy may be updated to reflect changes in our practices or regulations. We will notify you of significant changes.
13. Contact
For any questions regarding this privacy policy:
RenderThink - Data Protection
Contact: contact@renderthink.com
Technical support: support@renderthink.com
Subject: Personal data protection