Privacy policy
What data we process, why, for how long, and how to exercise your rights.
In short
We collect strictly what the service needs to work. We sell no data, we display no advertising and we train no artificial intelligence model on your data. Your information is hosted in France.
Controller
For the marketing website and workspace requests, the controller is Thiris — contact@thiris.com.
For the data you subsequently enter into your HubPlace workspace, you are the controller and Thiris acts as processor within the meaning of Article 28 of the GDPR.
Data collected by this site
When you request a workspace, we collect:
- your organisation's name;
- your first and last name;
- your work email address;
- your country and the approximate size of your estate;
- the date of the request and the sending IP address, solely to prevent abuse.
Data processed in the service
Once your workspace is created, HubPlace processes the data you put into it:
- user accounts: name, email address, group, permissions;
- IT estate: technical characteristics of endpoints and devices, and any link to a person;
- support and projects: the content of the tickets, tasks and attachments you create;
- technical logs: sign-ins, administration actions, agent check-ins.
What we do not collect
The agent installed on your endpoints transmits no file contents, no documents, no screenshots, no keystrokes and no browsing history. It reports technical characteristics and status indicators only.
Legal bases
Processing rests on the performance of our contract (delivery of the service), on your consent (workspace request, sending of information) and on our legitimate interest in securing the platform and preventing abuse.
AI analysis
Endpoint health analysis sends technical indicators to an artificial intelligence model: disk usage, memory, pending patches, hardware status. No user name, no address and no file content is transmitted. The data sent is not used to train the model.
Recipients
Your data is accessible only to members of your organisation, according to their permissions, and to Thiris technical administrators for operations and support. We use sub-processors for hosting, email and SMS delivery and AI analysis; an up-to-date list is available on request.
Transfers outside the European Union
Hosting and the database are located in France. Where the use of a provider involves a transfer outside the European Union, it is covered by the European Commission's standard contractual clauses.
Retention periods
Unconverted workspace requests are deleted after twelve months. Monitoring data is kept for the period you configure, up to twelve months by default. Deleting your workspace permanently erases all of your data within thirty days.
Cookies
The marketing website sets no advertising cookie and no third-party analytics tracker. Only local storage keeps the language you selected. The HubPlace application uses a session cookie that is strictly necessary for authentication.
Your rights
You have the right of access, rectification, erasure, restriction, objection and portability. To exercise them, write to contact@thiris.com. We respond within thirty days. You may also lodge a complaint with your country's supervisory authority — in France, the CNIL.
Security
HTTPS/TLS encryption in transit, passwords hashed with bcrypt, prepared statements, anti-CSRF tokens, strict per-organisation isolation, regular backups. Full details of the technical and organisational measures are available on request.
Changes
This policy may change. Any substantial modification is notified by email to the administrators of the workspaces concerned, at least thirty days before it takes effect.
Last updated: August 2026.