Last updated: August 25, 2026
CloudThinker (“we”, “us”, or “our”) respects your privacy and is committed to protecting your data. This Privacy Policy explains how we handle information when you visit cloudthinker.io, use our AgenticOps platform at app.cloudthinker.io, or engage our professional and managed services (together, the “Service”).
CloudThinker provides AI agents that connect to customers’ cloud and operational systems to investigate, recommend, and — under customer-controlled approval gates — act. This means we process two distinct categories of information, and it matters which one you are asking about:
Sections 3 to 9 concern data we control. Section 10 concerns Customer Data we process on our customers’ behalf. If you are an individual whose personal data appears inside a CloudThinker customer’s environment, that customer is the controller and you should direct requests to them; we will assist them in responding.
Our Terms of Service govern all use of the Service and, together with this Privacy Policy and our Cookie Policy, constitute your agreement with us.
Information you provide. Full name, work email address, phone number, company name and role, billing and payment information (processed by our payment provider, not stored by us), support and sales correspondence, event and webinar registrations, community and affiliate programme participation, and any content you submit through forms or chat.
Account and authentication data. User identifiers, authentication events, SSO/SCIM attributes supplied by your identity provider, roles and permissions within your workspace, and multi-factor authentication metadata.
Usage data. IP address, browser type and version, device identifiers, operating system, pages and features accessed, timestamps, session duration, referring URLs, and diagnostic data including error and crash reports.
Platform activity metadata. Records of which agents, Skills, and Connections were invoked, credit consumption, approval decisions taken by named users, and the immutable audit trail of actions proposed and executed — which we maintain both to provide the Service and to meet our own security and compliance obligations.
We do not seek special-category personal data and ask that you do not submit it through our website forms.
We use personal data to:
Where GDPR or comparable law applies, our legal bases are: performance of a contract (providing the Service and billing); legitimate interests (securing the Service, preventing fraud, improving our products, and direct marketing to business contacts); consent (marketing where consent is required, and non-essential cookies); and legal obligation (tax, accounting, and lawful requests).
You may opt out of marketing at any time by using the unsubscribe link in any email or by writing to biz@cloudthinker.io. Opting out of marketing does not stop transactional and service messages such as billing notices, security alerts, incident notifications, and changes to these policies, which are necessary to provide the Service.
We retain personal data only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. In practice:
Customer Data retention is described in Section 10 and, for enterprise customers, in the applicable Data Processing Addendum.
We may disclose personal data:
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Where we receive a government or law enforcement request for Customer Data, we will, unless legally prohibited, notify the affected customer and direct the requester to them so they can respond directly.
We apply defense-in-depth across our cloud foundation, our multi-tenant application, and the AI agent layer. Our controls include brokered identity and scoped credentials for Connections, isolated sandbox execution of agent actions, deterministic tokenization of sensitive values, encryption in transit and at rest, role-based access control with least privilege, tamper-evident audit logging, and continuous monitoring. CloudThinker maintains SOC 2 Type II compliance; current reports and control documentation are available through our Trust Center at trust.cloudthinker.io.
Enterprise customers may reduce exposure further through private connectivity (VPN, AWS PrivateLink, VPC peering), fully managed BYOC deployment in their own cloud account, or use of their own LLM provider.
No security measure is perfect. We cannot guarantee absolute security, and you transmit information to us at your own risk. Please use a strong, unique password and enable multi-factor authentication.
To report a security concern, a suspected breach, or a vulnerability, contact security@cloudthinker.io. We will acknowledge reports promptly and will notify affected customers and, where required, regulators, of a personal data breach within the timeframes mandated by applicable law and by our contractual commitments.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal data; to receive a portable copy; to withdraw consent; and to lodge a complaint with a supervisory authority. These rights are recognized under Vietnam’s Decree 13/2023/ND-CP on Personal Data Protection, Singapore’s Personal Data Protection Act, the EU and UK GDPR, and other applicable laws.
To exercise a right relating to data we control, contact privacy@cloudthinker.io. We may need to verify your identity before responding, and we will respond within the period required by applicable law. Note that we may be unable to provide the Service without certain data.
If your request concerns personal data held inside a CloudThinker customer’s environment, please contact that customer; we will support them in responding to you.
Scope. When a customer connects their systems, the platform ingests operational data necessary for agents to reason and act. This is predominantly machine data rather than personal data, but it may incidentally include identifiers such as usernames, IP addresses, email addresses in configuration or code, and names in ticket and incident records.
Instructions. We process Customer Data only to provide the Service and on the customer’s documented instructions, including the autonomy levels, guardrails, and permission scopes the customer configures.
No training on Customer Data. We do not use Customer Data to train, fine-tune, or otherwise improve foundation models, whether ours or a third party’s. Our agreements with model providers prohibit them from training on data submitted through our Service and require zero data retention or short-term retention limited to abuse monitoring.
Minimization. Connections are established with read-only scopes by default, and customers control what is connected. Sensitive values are tokenized before agent processing where technically feasible. Customers should scope Connections to the minimum access required and exclude systems they do not want processed.
Isolation. Customer Data is logically segregated by tenant and workspace. Agent execution occurs in isolated sandboxes. Enterprise BYOC deployments keep Customer Data within the customer’s own cloud account.
Retention and deletion. Customer Data is retained for the subscription term and for a limited post-termination window during which the customer may export it, after which it is deleted or de-identified in accordance with the applicable Data Processing Addendum, subject to backup cycles and legal retention obligations. Customers may delete data and revoke Connections at any time from within the platform.
Data Processing Addendum. Business customers may request our standard DPA, which incorporates the EU Standard Contractual Clauses and UK Addendum where relevant, by contacting legal@cloudthinker.io.
We engage third parties to help deliver the Service. Each is bound by written contract to process data only on our instructions, to maintain appropriate security, and not to use data for their own purposes. Categories include:
Our public repositories at github.com/cloudthinker-ai are used for open-source distribution and community contribution only; they do not process Customer Data or account personal data.
A current list of sub-processors is available on request from privacy@cloudthinker.io and, for enterprise customers, is maintained under the DPA with advance notice of changes.
We use analytics to understand how visitors find and use our website and platform, and we may use remarketing to advertise to people who have visited our site. These technologies rely on cookies and similar identifiers; see our Cookie Policy for details and controls. Where required by law, non-essential cookies are set only after you consent, and you may withdraw consent at any time.
CloudThinker’s operations span Vietnam and Singapore, and our sub-processors operate in multiple jurisdictions. Your information may therefore be transferred to and processed in countries other than your own, including countries whose data protection laws differ from those of your jurisdiction.
The multi-tenant platform is hosted on Amazon Web Services in the Asia Pacific (Singapore) region, ap-southeast-1. Customer Data for SaaS customers is stored at rest in that region unless otherwise agreed in an Order Form.
Where personal data originating in Vietnam is transferred outside Vietnam, we do so in accordance with Decree 13/2023/ND-CP, including maintaining a cross-border transfer impact assessment dossier and filing it with the competent authority where required.
Where we transfer personal data internationally, we implement appropriate safeguards, including Standard Contractual Clauses, transfer risk assessments, and contractual security commitments. Customers with data residency requirements should discuss BYOC or regional deployment options with us — a fully managed BYOC deployment keeps Customer Data within the customer’s own AWS account and chosen region.
The Service is a business product and is not directed at, or intended for use by, anyone under eighteen (18). We do not knowingly collect personal data from anyone under eighteen. If you believe a minor has provided us with personal data, contact privacy@cloudthinker.io and we will delete it.
We may update this Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. For material changes, we will notify you by email or a prominent notice in the Service before the change takes effect. Please review this Policy periodically.
CloudThinker
114 Lavender Street, #11-83, CT Hub 2, Singapore 338729