Privacy Policy

Last updated: April 2, 2026

RenderThink respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use and protect your information in accordance with the General Data Protection Regulation (GDPR).

1. Data controller

RenderThink - SAS RENDERTHINK, registered in France under SIRET number 102 977 147 00010, specialized in AI image transformation services for professionals.

Data protection contact: contact@renderthink.com. In the absence of a designated Data Protection Officer (DPO), any data protection request may be addressed to this email.

2. Data collected

Account data

  • Name, first name, professional title
  • Email address, phone number (optional)
  • Encrypted password, authentication preferences
  • Profile picture, company information

Usage data

  • Created projects, file metadata
  • Uploaded and transformed images (temporarily)
  • Activity history, user preferences
  • Interface settings, language, notifications

Technical data

  • IP address, approximate geolocation
  • Device type, browser, operating system
  • Pages visited, session time, actions performed
  • Performance and error logs

Billing data

  • Credit purchase and subscription history
  • Billing information and addresses
  • Payment data processed by Stripe (not stored by us)

3. Processing purposes

  • Providing and improving image transformation services
  • User account management and authentication
  • Subscription management, billing and commercial support
  • Technical support and customer assistance
  • Usage analysis to improve the platform
  • Platform security and fraud prevention
  • Compliance with legal and regulatory obligations
  • Transactional and marketing communications (with consent)

4. Legal basis for processing

Contract execution: Providing RenderThink services according to our ToS

Legitimate interest: Improving our services, security, usage analysis

Legal obligation: Accounting, invoice retention, fraud prevention

Consent: Marketing communications

5. Data sharing

Processors

  • Hosting on secure European infrastructure (OVHcloud)
  • Cloudflare - File storage and content delivery (R2)
  • Stripe - Secure payment processing (PCI DSS certified)
  • AI technologies - AI processing via secure API, data not used for third-party model training
  • Monitoring services - Performance monitoring and error detection

Authorities

We may have to communicate your data to competent authorities in case of legal obligation or judicial request.

No data sale

We do not sell, rent, or trade your personal data with third parties for commercial purposes.

Right to object to sub-processors

In accordance with GDPR Article 28(4), you have the right to object to the engagement of new sub-processors. In the event of a new sub-processor being added, you will be notified by email with 30 days' notice. You have 15 days from notification to object. In case of justified objection, you may terminate your contract at no cost or request additional compliance measures.

6. Data security

  • Secure connections: HTTPS/TLS for all communications, encryption of sensitive data at rest
  • Secure authentication: hashed passwords, JWT sessions, login attempt limits, access logging
  • Monitoring: rate limiting, automatic blocking after repeated failed attempts
  • Backups: regular data backups, hosting on secure European infrastructure
  • In case of security incident: CNIL notification within 72h as per GDPR, affected client notification, corrective measures

7. Retention period

Account data: During contract duration + 3 years after termination

Projects and files: During contract duration + 30 days after termination

Billing data: 10 years for accounting and tax obligations

Technical logs: 6 months maximum for security and optimization

8. International transfers

Some of our processors may process your data outside the EU. These transfers are governed by:

  • European Commission adequacy decisions
  • Standard contractual clauses for data protection

9. Your rights

Right of access

Obtain a copy of your personal data

Right to rectification

Correct inaccurate or incomplete data

Right to erasure

Request deletion of your data

Right to restriction

Restrict processing of your data

Right to portability

Retrieve your data in a structured format

Right to object

Object to processing for legitimate reasons

To exercise your GDPR rights, contact us at contact@renderthink.com contact@renderthink.com . We will respond within a maximum of 30 days. For any request, please specify your identity and the right you wish to exercise.

10. Cookies and similar technologies

RenderThink uses cookies strictly necessary for the operation of the service (authentication, language preferences) and, subject to your explicit consent, a PostHog analytics solution (hosted in the European Union) to measure platform usage and improve the service. No advertising or third-party tracking cookies are used. You can change your preferences at any time via the 'Cookie preferences' link in the footer.

For more details, see our cookie policy.

11. Complaints

If you believe your rights are not being respected, you can file a complaint with your national data protection authority.

12. Policy updates

This policy may be updated to reflect changes in our practices or regulations. We will notify you of significant changes.

13. Contact

For any questions regarding this privacy policy:

RenderThink - Data Protection

Contact: contact@renderthink.com

Technical support: support@renderthink.com

Subject: Personal data protection