Privacy Policy

Our privacy policy and how we use your data

Last updated: August 25, 2026

1. Introduction

CloudThinker (“we”, “us”, or “our”) respects your privacy and is committed to protecting your data. This Privacy Policy explains how we handle information when you visit cloudthinker.io, use our AgenticOps platform at app.cloudthinker.io, or engage our professional and managed services (together, the “Service”).

CloudThinker provides AI agents that connect to customers’ cloud and operational systems to investigate, recommend, and — under customer-controlled approval gates — act. This means we process two distinct categories of information, and it matters which one you are asking about:

  • Account and website data, where CloudThinker acts as a controller. This is information about you as a visitor, prospect, or user — your name, work email, and how you interact with our site and platform.
  • Customer Data, where CloudThinker acts as a processor on behalf of our business customers. This is the operational data flowing from a customer’s connected systems — logs, metrics, traces, configurations, schemas, infrastructure metadata, tickets, and source code — which may incidentally contain personal data such as usernames in an audit log or an email address in a commit message.

Sections 3 to 9 concern data we control. Section 10 concerns Customer Data we process on our customers’ behalf. If you are an individual whose personal data appears inside a CloudThinker customer’s environment, that customer is the controller and you should direct requests to them; we will assist them in responding.

Our Terms of Service govern all use of the Service and, together with this Privacy Policy and our Cookie Policy, constitute your agreement with us.

2. Definitions

  • PERSONAL DATA means information relating to an identified or identifiable individual.
  • USAGE DATA means data collected automatically through use of the Service or its infrastructure, such as page duration or feature interaction.
  • CUSTOMER DATA means data, telemetry, and content that a customer or a customer’s Connections make available to the platform, together with output generated from it.
  • CONNECTION means an authorized integration between the platform and a customer system.
  • COOKIES are small files stored on your device.
  • CONTROLLER means the party that determines the purposes and means of processing.
  • PROCESSOR means a party that processes personal data on a controller’s behalf and on its instructions.
  • SUB-PROCESSOR means a third party engaged by a processor to process personal data.

3. Personal Data We Collect as Controller

Information you provide. Full name, work email address, phone number, company name and role, billing and payment information (processed by our payment provider, not stored by us), support and sales correspondence, event and webinar registrations, community and affiliate programme participation, and any content you submit through forms or chat.

Account and authentication data. User identifiers, authentication events, SSO/SCIM attributes supplied by your identity provider, roles and permissions within your workspace, and multi-factor authentication metadata.

Usage data. IP address, browser type and version, device identifiers, operating system, pages and features accessed, timestamps, session duration, referring URLs, and diagnostic data including error and crash reports.

Platform activity metadata. Records of which agents, Skills, and Connections were invoked, credit consumption, approval decisions taken by named users, and the immutable audit trail of actions proposed and executed — which we maintain both to provide the Service and to meet our own security and compliance obligations.

We do not seek special-category personal data and ask that you do not submit it through our website forms.

4. How We Use Personal Data

We use personal data to:

  • Provide, operate, secure, and maintain the Service;
  • Authenticate users, provision seats, and enforce permissions;
  • Meter usage, allocate credits, invoice, and collect payment;
  • Provide customer support and respond to enquiries;
  • Detect, investigate, and prevent security incidents, fraud, abuse, and technical faults;
  • Maintain audit trails required for our own SOC 2 and contractual compliance;
  • Notify you about changes to the Service, your account, or your subscription;
  • Improve the Service through analysis of aggregated usage patterns;
  • Send newsletters, product updates, and marketing about goods and services similar to those you have purchased or enquired about, where permitted and subject to your right to opt out;
  • Comply with legal obligations and enforce our agreements.

Where GDPR or comparable law applies, our legal bases are: performance of a contract (providing the Service and billing); legitimate interests (securing the Service, preventing fraud, improving our products, and direct marketing to business contacts); consent (marketing where consent is required, and non-essential cookies); and legal obligation (tax, accounting, and lawful requests).

5. Marketing and Your Choices

You may opt out of marketing at any time by using the unsubscribe link in any email or by writing to biz@cloudthinker.io. Opting out of marketing does not stop transactional and service messages such as billing notices, security alerts, incident notifications, and changes to these policies, which are necessary to provide the Service.

6. Retention

We retain personal data only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. In practice:

  • Account data is retained for the life of the account and for a limited period afterwards to handle disputes and reactivation requests.
  • Billing and tax records are retained for the period required by applicable accounting and tax law.
  • Security and audit logs are retained for the period required by our compliance framework and contractual commitments.
  • Usage and analytics data is generally retained for a shorter period, except where needed to strengthen security or improve functionality.
  • Marketing data is retained until you opt out or the contact becomes inactive.

Customer Data retention is described in Section 10 and, for enterprise customers, in the applicable Data Processing Addendum.

7. Disclosure of Personal Data

We may disclose personal data:

  • To sub-processors and service providers who perform functions on our behalf under written contract (see Section 11);
  • To professional advisers such as auditors, lawyers, and accountants under duties of confidentiality;
  • In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy continuing to apply;
  • To comply with a legal obligation or valid lawful request;
  • To protect and defend our rights or property;
  • To investigate possible wrongdoing in connection with the Service;
  • To protect the personal safety of users or the public, or to protect against legal liability.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Where we receive a government or law enforcement request for Customer Data, we will, unless legally prohibited, notify the affected customer and direct the requester to them so they can respond directly.

8. Security

We apply defense-in-depth across our cloud foundation, our multi-tenant application, and the AI agent layer. Our controls include brokered identity and scoped credentials for Connections, isolated sandbox execution of agent actions, deterministic tokenization of sensitive values, encryption in transit and at rest, role-based access control with least privilege, tamper-evident audit logging, and continuous monitoring. CloudThinker maintains SOC 2 Type II compliance; current reports and control documentation are available through our Trust Center at trust.cloudthinker.io.

Enterprise customers may reduce exposure further through private connectivity (VPN, AWS PrivateLink, VPC peering), fully managed BYOC deployment in their own cloud account, or use of their own LLM provider.

No security measure is perfect. We cannot guarantee absolute security, and you transmit information to us at your own risk. Please use a strong, unique password and enable multi-factor authentication.

To report a security concern, a suspected breach, or a vulnerability, contact security@cloudthinker.io. We will acknowledge reports promptly and will notify affected customers and, where required, regulators, of a personal data breach within the timeframes mandated by applicable law and by our contractual commitments.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data; to receive a portable copy; to withdraw consent; and to lodge a complaint with a supervisory authority. These rights are recognized under Vietnam’s Decree 13/2023/ND-CP on Personal Data Protection, Singapore’s Personal Data Protection Act, the EU and UK GDPR, and other applicable laws.

To exercise a right relating to data we control, contact privacy@cloudthinker.io. We may need to verify your identity before responding, and we will respond within the period required by applicable law. Note that we may be unable to provide the Service without certain data.

If your request concerns personal data held inside a CloudThinker customer’s environment, please contact that customer; we will support them in responding to you.

10. Customer Data — Our Role as Processor

Scope. When a customer connects their systems, the platform ingests operational data necessary for agents to reason and act. This is predominantly machine data rather than personal data, but it may incidentally include identifiers such as usernames, IP addresses, email addresses in configuration or code, and names in ticket and incident records.

Instructions. We process Customer Data only to provide the Service and on the customer’s documented instructions, including the autonomy levels, guardrails, and permission scopes the customer configures.

No training on Customer Data. We do not use Customer Data to train, fine-tune, or otherwise improve foundation models, whether ours or a third party’s. Our agreements with model providers prohibit them from training on data submitted through our Service and require zero data retention or short-term retention limited to abuse monitoring.

Minimization. Connections are established with read-only scopes by default, and customers control what is connected. Sensitive values are tokenized before agent processing where technically feasible. Customers should scope Connections to the minimum access required and exclude systems they do not want processed.

Isolation. Customer Data is logically segregated by tenant and workspace. Agent execution occurs in isolated sandboxes. Enterprise BYOC deployments keep Customer Data within the customer’s own cloud account.

Retention and deletion. Customer Data is retained for the subscription term and for a limited post-termination window during which the customer may export it, after which it is deleted or de-identified in accordance with the applicable Data Processing Addendum, subject to backup cycles and legal retention obligations. Customers may delete data and revoke Connections at any time from within the platform.

Data Processing Addendum. Business customers may request our standard DPA, which incorporates the EU Standard Contractual Clauses and UK Addendum where relevant, by contacting legal@cloudthinker.io.

11. Sub-Processors and Service Providers

We engage third parties to help deliver the Service. Each is bound by written contract to process data only on our instructions, to maintain appropriate security, and not to use data for their own purposes. Categories include:

  • Cloud infrastructure and hosting — Amazon Web Services (AWS), which hosts the platform and stores Customer Data at rest. AWS’s privacy notice: https://aws.amazon.com/privacy/;
  • Large language model providers — for agent reasoning, under contractual terms prohibiting training on submitted data. Enterprise customers may substitute their own model provider;
  • Payment processing — Stripe. We do not store payment card details; card data is provided directly to the processor, which maintains PCI-DSS compliance. Stripe’s privacy policy: https://stripe.com/privacy;
  • Analytics — Google Analytics, to understand website and platform usage. Google’s privacy policy: https://policies.google.com/privacy;
  • Business productivity and communication — Google Workspace, for email, calendaring, document collaboration, and sales and support correspondence. Google’s privacy policy: https://policies.google.com/privacy;
  • Development, source control, and CI/CD — GitLab.com (GitLab Inc., SaaS), for source control, build, test, and deployment of the Service. GitLab’s privacy policy: https://about.gitlab.com/privacy/;
  • In-product messaging and support ticketing — for support requests and product notifications;
  • Business operations — CRM, billing, and identity management platforms.

Our public repositories at github.com/cloudthinker-ai are used for open-source distribution and community contribution only; they do not process Customer Data or account personal data.

A current list of sub-processors is available on request from privacy@cloudthinker.io and, for enterprise customers, is maintained under the DPA with advance notice of changes.

12. Analytics and Advertising

We use analytics to understand how visitors find and use our website and platform, and we may use remarketing to advertise to people who have visited our site. These technologies rely on cookies and similar identifiers; see our Cookie Policy for details and controls. Where required by law, non-essential cookies are set only after you consent, and you may withdraw consent at any time.

13. International Transfers

CloudThinker’s operations span Vietnam and Singapore, and our sub-processors operate in multiple jurisdictions. Your information may therefore be transferred to and processed in countries other than your own, including countries whose data protection laws differ from those of your jurisdiction.

The multi-tenant platform is hosted on Amazon Web Services in the Asia Pacific (Singapore) region, ap-southeast-1. Customer Data for SaaS customers is stored at rest in that region unless otherwise agreed in an Order Form.

Where personal data originating in Vietnam is transferred outside Vietnam, we do so in accordance with Decree 13/2023/ND-CP, including maintaining a cross-border transfer impact assessment dossier and filing it with the competent authority where required.

Where we transfer personal data internationally, we implement appropriate safeguards, including Standard Contractual Clauses, transfer risk assessments, and contractual security commitments. Customers with data residency requirements should discuss BYOC or regional deployment options with us — a fully managed BYOC deployment keeps Customer Data within the customer’s own AWS account and chosen region.

14. Children’s Privacy

The Service is a business product and is not directed at, or intended for use by, anyone under eighteen (18). We do not knowingly collect personal data from anyone under eighteen. If you believe a minor has provided us with personal data, contact privacy@cloudthinker.io and we will delete it.

15. Changes to This Privacy Policy

We may update this Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we will notify you by email or a prominent notice in the Service before the change takes effect. Please review this Policy periodically.

Contact Us

CloudThinker
114 Lavender Street, #11-83, CT Hub 2, Singapore 338729