Thesr Thesr
FR EN

Privacy Policy

This English version is a translation, provided for convenience. The French version is the authoritative one.

Version 2.3 — in force from 27 September 2026.

1. Who we are, and who this policy is for

THESR SAS (“THESR”), a French simplified joint-stock company with a share capital of €1,000, registered with the Paris Trade and Companies Register under number 988 273 421, whose registered office is at 200 rue de la Croix Nivert, 75015 Paris, France, publishes Thesr (the “Platform”), a document management and search service reserved for professionals: law firms, legal departments, companies and other organisations. It is not offered to consumers.

This policy explains which personal data we process, why, for how long, with whom we share it and how to exercise your rights. It is addressed to visitors of our websites, to our prospects and customers, and to users of the Platform.

For any question or request about your data: [email protected] (subject: “Personal data”), or THESR SAS, 200 rue de la Croix Nivert, 75015 Paris, France.

2. Two different roles

2.1. THESR as a processor for its customers

The documents, notes, tasks and other content that our customers place in the Platform, and the data of their users processed in the use of the service, are processed on behalf of each customer, which is the controller, and on its instructions only, under the terms of the Data Processing Agreement. If you are mentioned in the documents of a THESR customer, or if you use the Platform within a customer organisation, please address your requests to that organisation first; we forward to it those we receive.

2.2. THESR as a controller

THESR is the controller of the processing it carries out on its own behalf: running its websites, managing its prospects and customers, invoicing, support and the security of the Platform. The rest of this policy describes that processing.

3. What we process, why, and on what basis

PurposeDataLegal basis
Answering contact and demonstration requests, opening and following demonstration spacesName, position, organisation, professional contact details, message, stated needs, use of the demonstration spacePre-contractual measures and our legitimate interest in developing our business
Business prospecting aimed at professionalsName, position, organisation, professional email address, history of exchangesLegitimate interest (you may object at any time)
Creating and administering accounts, enabling sign-inName, professional email address, role, language, organisation, account security settingsPerformance of the contract concluded with the customer
Managing subscriptions, invoicing, collecting paymentsBilling details, VAT number, payment history (card data is processed by our payment provider, never by THESR)Performance of the contract; legal accounting and tax obligations
Supporting usersExchanges with support and the files sentPerformance of the contract
Securing the Platform, preventing fraud and unauthorised access, evidencing accessConnection and usage data: IP addresses, devices, dates and times, actions performedLegitimate interest in protecting the Platform and our customers’ data; performance of the contract
Keeping the service working properlyResponse times and errors, without the content of documentsLegitimate interest
Complying with our legal obligations and defending our rightsData needed for evidence and for answering the authoritiesLegal obligation; legitimate interest

THESR neither sells nor rents any data. It does not consult the content of its customers’ documents on its own behalf, does not analyse it for commercial purposes and never uses it to train artificial intelligence models. Our security tools analyse connection and usage data only, never the content of documents or searches.

The Platform takes no decision producing legal effects concerning you based solely on automated processing. Automatic protective measures, such as closing a suspicious session, aim to protect a threatened account; they are reported and can be lifted by an administrator.

4. Connectors and AI assistants

When a customer or one of its users connects the Platform to a connector (Google Drive, Microsoft OneDrive or SharePoint, the Thesr Sync desktop application), THESR receives, with their authorisation, the files of the folders chosen, their metadata and a read-only access authorisation, which is stored encrypted. These files become the customer’s content (section 2.1).

When a customer allows its users to connect an AI assistant (for example Claude, ChatGPT, Copilot or Le Chat), the Platform sends that assistant, at its request and within the rights of the user who connected it, extracts and the text of documents, notes, tasks and, for assigning tasks, the names of the members of their organisation. The assistant then processes them under the terms of its publisher, which the customer has chosen; depending on the publisher, this processing may take place outside the European Union. Each exchange is logged (date, items consulted, assistant and user), without recording the questions asked of the assistant or the text sent.

5. Recipients

Your data is only accessible to those who need it:

  • authorised THESR staff, bound by confidentiality, within the limits of their duties;
  • the administrators of your organisation, for your account data and the activity attached to it;
  • our service providers, within the limits of their task and bound by contract to confidentiality and security: OVH SAS (hosting, in France), Cloudflare (protection of the site and of exchanges), Sendinblue SAS — Brevo (sending the Platform’s emails), Google (Google Workspace: our email, including support) and, for subscription payments, our payment provider. The sub-processors processing data on behalf of our customers are listed in the Data Processing Agreement;
  • the third-party services your organisation chose to connect to the Platform (section 4), on its instruction;
  • administrative or judicial authorities, where the law requires it.

6. Where your data is

The Platform, the data it holds and its backups are hosted in France, by OVHcloud.

To protect the site against attacks, exchanges between your browser and the Platform pass through the network of our security provider, Cloudflare. They are encrypted all the way. Cloudflare processes them automatically, for the sole purpose of routing them and keeping out malicious traffic: it does not exploit them on its own behalf and does not keep the content of the pages or documents viewed. As Cloudflare, Inc. is established in the United States, any resulting transfers are governed by the EU–US Data Privacy Framework, under which it is certified, and by the European Commission’s standard contractual clauses.

Emails exchanged with THESR, including with support, are hosted by Google (Google Workspace), under the same transfer safeguards. The same applies to our payment provider.

Data that a customer chooses to send to an AI assistant (section 4) is processed wherever its publisher processes it, under that customer’s responsibility.

7. Retention periods

DataPeriod
Customers’ content and their users’ accountsFor the duration of the subscription, then at most ninety days after it ends
Deleted documents, notes and workspacesThirty days in the trash, where they can be restored, then erased
Account deleted by its organisation’s administratorDeleted at once, with its personal documents; the documents it had added to its organisation’s libraries remain there, attributed to “Removed user”
Demonstration spacesDeleted, with their content, within hours of expiring
Connection, access and activity logs, including those of AI assistants; security dataTwelve months at most
Usage patterns established to detect unusual accessAs long as the account exists, and at most twelve months after its last activity
Search history; previous versions of notesThirty days
Prospects, contact and demonstration requestsThree years from your last contact
Billing data and accounting recordsTen years (legal obligation)
Data needed to evidence a contractFive years after it ends (limitation period)

8. Backups

To be able to restore the service after an incident, we back up the Platform’s database and files every day, in France. Each backup is kept fourteen days, then erased, and we regularly check that it can be restored.

Backups serve only for that restoration: they are neither consulted nor exploited. Data erased from the Platform — on leaving the trash, for a document, a note or a workspace — may therefore remain in them until they are erased, that is fourteen days at most.

9. Security

We protect data with technical and organisational measures suited to its confidential nature, including encryption of exchanges, strong authentication, separation of each customer’s data, access logging, continuous monitoring and daily backups. Our commitments to our customers are set out in the Data Processing Agreement.

In the event of a data breach, we take the necessary measures without delay. For the processing we control, we notify the CNIL and, where it presents a high risk, the persons concerned; for data processed on behalf of a customer, we notify the customer within forty-eight hours so that it can do so.

10. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, the right to withdraw your consent where the processing depends on it, and the right to give instructions on what happens to your data after your death. You may object to business prospecting at any time, through the unsubscribe link each of our messages carries, by replying to it or by writing to us.

To exercise them, write to [email protected]. We answer within one month, which may be extended by two months for complex requests, and may ask you to prove your identity where there is reasonable doubt. For data processed on behalf of a customer (section 2.1), we forward your request to it.

You may lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.

11. Cookies

Our websites and the Platform only use cookies necessary for their operation and security (session, form protection, language, remembering a trusted device), which do not require your consent. No audience measurement tool or advertising cookie is used at this time. The details are in our cookie policy.

12. Changes

We may change this policy to reflect changes to the Platform or to the regulations. The date of the version in force appears at the top of the document; any significant change is announced on the Platform or by email. In the event of a discrepancy between a translation and the French version, the French version prevails.

Thesr
© 2026 THESR SAS
200, rue de la Croix Nivert - 75015 Paris
Société par actions simplifiée registered under number 988 273 421 (RCS Paris)
Privacy Policy Cookies Data processing (GDPR) Legal notice Contact us
Thesr Sync