Last updated: October 9, 2026
/
Legal

Privacy Policy

1. Introduction

THINKPOL SAS ("we," "our," or "us") is incorporated in France and acts as data controller responsible for the personal data described in this policy. Our registered address is 59 rue de Ponthieu, Bureau 326, 75008 Paris, France. SIRET: 102 449 683 00014. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

2. Information We Collect

We may collect personal information that you voluntarily provide to us, including but not limited to:

  • Name, email address, and contact information
  • Company name and job title
  • Information provided through our contact forms
  • Usage data and analytics information

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Respond to your inquiries and fulfill your requests
  • Send administrative information and service updates
  • Analyze usage patterns to enhance user experience
  • Comply with legal obligations

4. Newsletter and Service Emails

Newsletter. We send at most one newsletter email per month about our investigations, tool updates and events. We send it to:

  • People who subscribed through the form on our website (legal basis: consent, Art. 6(1)(a) GDPR).
  • Current and former users of our services, about services similar to the ones they used (Article L34-5 of the French Post and Electronic Communications Code; legitimate interest, Art. 6(1)(f) GDPR).
  • Professional contacts, only for content related to their professional activity (legitimate interest, Art. 6(1)(f) GDPR).

Every newsletter contains an unsubscribe link. Unsubscribing is free, takes one click and is effective immediately. We keep the address on a suppression list only to make sure we never email it again. To measure how a newsletter performs, we count opens and link clicks per campaign, as anonymous totals only (a small image and redirected links served from mail.think-pol.com). We never record who opened or clicked, nor your IP address.

Service emails. If you hold a THINKPOL API account, we send you service notifications such as key delivery and low-quota alerts (legal basis: performance of the contract, Art. 6(1)(b) GDPR). These are not marketing and contain no promotion; you can ask us to send them to a different address at any time.

Providers. The website is delivered by BunnyWay d.o.o. (Bunny.net, Slovenia). Newsletter sign-ups, forms and the newsletter list are stored on THINKPOL infrastructure hosted by Scaleway SAS in France, and emails are delivered by Scaleway SAS (France). No personal data from these features is stored outside the European Union.

Retention. Newsletter addresses are kept until you unsubscribe, and deleted 3 years after our last contact with you (sign-up, reply or account activity) unless you confirm you want to keep receiving it. Suppression list entries are kept as long as needed to honour the opt-out.

5. Free Tools

Usage limits. Our free tools have a daily allowance. To enforce it we keep a counter per visitor, keyed by your IP address passed through a one-way cryptographic hash with a secret key, so the address itself is never stored. The counter resets every day and is deleted after 30 days at most (legal basis: legitimate interest in preventing abuse and protecting the service, Art. 6(1)(f) GDPR).

Extended access. To unlock more lookups you enter your work email and confirm it with a code we send to it. We record the address, with the tool you were using, to grant access, to follow up about professional use of THINKPOL and to send you our monthly newsletter, which relates to your professional activity (legitimate interest for business contacts, Art. 6(1)(f) GDPR and Article L34-5 of the French Post and Electronic Communications Code). You are told about the newsletter before you confirm, and every issue has a one-click unsubscribe. Your browser keeps an access pass for 30 days; you can ask us to delete your email at any time at dpo@think-pol.com. These records are stored in France (Scaleway).

6. Data Sharing & Disclosure

We do not sell your personal information. We may share your information with trusted third-party service providers who assist us in operating our platform, conducting our business, or servicing you, provided they agree to keep this information confidential.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet is 100% secure.

8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal obligations, resolve disputes, and enforce our agreements.

9. Your Rights

Under applicable data protection laws (including GDPR), you have the following rights in relation to your personal data:

  • Access (Art. 15): Request a copy of the personal data we hold about you.
  • Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Erasure (Art. 17): Request deletion of your personal data where there is no legitimate ground for continued processing.
  • Restriction (Art. 18): Request that we limit processing of your data in certain circumstances.
  • Object (Art. 21): Object at any time to processing based on our legitimate interests, including processing of publicly available data collected from third-party platforms. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
  • Portability (Art. 20): Receive your personal data in a structured, machine-readable format where processing is based on consent or contract.

To exercise any of these rights, contact us at dpo@think-pol.com. We will respond within 30 days. You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) at cnil.fr if you believe our processing does not comply with applicable law.

10. Third-Party Platform Data: Article 14 Notice

This section constitutes our transparency notice under GDPR Article 14 for data subjects whose publicly available content is processed through our intelligence platform.

Categories of data processed: Publicly posted text content (posts, comments, usernames), associated metadata (timestamps, community identifiers, engagement signals), and derived analytical signals. We do not process data from behind login walls, and we do not collect content that requires authentication to access.

Source: Publicly accessible third-party platforms, including social media and community platforms. THINKPOL is not affiliated with, endorsed by, or sponsored by any such platform. We do not circumvent technical access controls deployed by third-party platforms.

Purpose: Providing threat intelligence, fraud detection, brand protection, law enforcement support, and security research capabilities to authorized professional customers.

Legal basis: Article 6(1)(f) GDPR — legitimate interests. Our legitimate interests are: enabling professional customers (law enforcement, government agencies, corporate security teams) to identify threats, detect fraud, and conduct lawful security investigations using publicly available open-source intelligence. These interests are balanced against data subjects' rights given that only publicly posted content is processed and no individual profiling for commercial purposes takes place.

Retention: Publicly available content is retained for as long as operationally necessary to provide intelligence services. Content removal requests are processed in accordance with the erasure rights described in Section 7.

Restrictions on use: Data processed through our platform is used solely to generate analytical intelligence for authorized professional customers (such as law enforcement, government agencies and corporate security teams) in the context of their lawful investigations, and never for advertising, commercial profiling or automated decisions producing legal effects. Our analysis is limited to content that individuals have made public. Where such content itself reveals information that may relate to special categories of data under GDPR Article 9 (for example where an individual has manifestly made such information public), any processing is confined to the professional security and law-enforcement purpose described above, and remains subject to the objection right set out in Section 7 and below.

How to object: If you are a data subject whose publicly available content is processed through our platform and wish to object to this processing under Article 21 GDPR, you may submit a request at dpo@think-pol.com. Include sufficient information to identify the content in question. We will review your objection and respond within 30 days.

Legitimate interest assessment: Before relying on Article 6(1)(f), we carried out and documented a balancing test. Our purpose (enabling competent authorities and vetted security professionals to detect threats, fraud and serious crime using publicly available open-source intelligence) is legitimate; the processing is necessary because this capability cannot reasonably be achieved by less intrusive means; and the impact on data subjects is limited because we process only content the individual made public, apply no advertising or commercial profiling, and restrict access to vetted professional customers under contract. We keep this assessment under review and reassess it against any objection received.

Objections, removal requests and restriction of processing: When we receive an objection or removal request, we immediately cease the most intrusive processing by removing public access to the account through our free tools. Any residual records are then restricted under Article 18 (stored but not otherwise processed) and retained only where a compelling legitimate ground applies, namely support for competent authorities' investigations into serious crime and threats to public security, and the establishment, exercise or defence of legal claims, in each case under strict safeguards: no public exposure, access limited to vetted competent authorities, EU hosting and data minimisation. Where no such ground applies, we erase the data. We give particular weight to, and act on with priority, requests that concern a minor, special categories of data under Article 9, or content that is non-consensual.

Customers who access our services are independently responsible for ensuring their use of derived intelligence complies with applicable data protection law, including the GDPR, and any relevant third-party platform policies in their jurisdiction.

11. Contact

For questions about this Privacy Policy, or to exercise any of the rights described above, write to our data protection contact at dpo@think-pol.com or at THINKPOL SAS, 59 rue de Ponthieu, Bureau 326, 75008 Paris, France.