Last updated: September 23, 2026

Privacy Policy

What data we collect, why, for how long, who we share it with — and your rights, depending on where you live.

Beyond The Brackets holds the protection of your data to the same standard as the code we write. This policy explains what personal data we collect when you use this site or our services, why we process it, how long we keep it and how to exercise your rights. It is built on the General Data Protection Regulation (GDPR) and the French Data Protection Act, which we apply as the baseline for every visitor wherever they are; a dedicated section then sets out the additional rights you have depending on where you live — in particular in the United States, the United Kingdom, Switzerland, Canada, Brazil and Australia.

Data controller

The controller of your personal data is the company that publishes this site, whose full identity appears in our legal notice:

  • Company : BEYOND THE BRACKETS — SASU
  • Registration : RCS Paris B 852 264 035 — SIRET 852 264 035 00035
  • Registered office : 66 avenue des Champs-Élysées, 75008 Paris, France
  • Legal representative and publication director : Loïc Guillebeau
  • Data protection contact : contact@beyond-the-brackets.com

Given its size and the nature of its activities, Beyond The Brackets is not required to appoint a Data Protection Officer. Any question about your data is handled directly by management, at the address above.

Data we collect

We only collect the data required for the purposes described below. We never ask for special categories of data within the meaning of Article 9 GDPR.

Data you provide

  • Contact form: first and last name, email address, phone number, company, request type and the content of your message.
  • Site chat: what you write in the conversation and any contact details you leave in it, passed to our sales pipeline (Pipedrive).
  • Project simulator and online diagnostic: email address and questionnaire answers (project type, expected budget, maturity).
  • Client area: login credentials, hashed password, project information, documents, tickets and messages exchanged.
  • Marketplace: billing information required to process your order.

Data collected automatically

  • Connection data and technical logs: IP address, request date and time, pages viewed, browser and device type.
  • Audience measurement: page views, traffic source and browsing path, only if you have consented.
  • Security data: anti-spam signals produced by Google reCAPTCHA when you submit one of our forms.

Purposes, legal bases and retention periods

Each processing activity relies on a specific legal basis and a limited retention period. Once that period ends, the data is deleted or anonymised.

PurposeData involvedLegal basisRetention
Answer your enquiries and prepare a quoteIdentity, contact details, message contentPre-contractual steps (Art. 6(1)(b))3 years after last contact
Deliver simulator and diagnostic resultsEmail, questionnaire answersConsent (Art. 6(1)(a))3 years after last contact
Deliver our services and run the client areaAccount, project data, documents, exchangesPerformance of a contract (Art. 6(1)(b))Term of the contract, then 5 years
Invoicing and accounting obligationsBilling and order dataLegal obligation (Art. 6(1)(c))10 years (Art. L123-22 French Commercial Code)
Send our communications and B2B outreachEmail, open and click statisticsConsent or legitimate interest (Art. 6(1)(a) / 6(1)(f))3 years after last interaction
Measure audience and improve the siteBrowsing identifiers, page viewsConsent (Art. 6(1)(a))13 months (cookies), 25 months (statistics)
Secure the site and prevent abuseIP address, technical logs, reCAPTCHA signalsLegitimate interest (Art. 6(1)(f))12 months

Recipients and processors

Your data is accessible to the Beyond The Brackets team, on a need-to-know basis, and to the technical providers below, who act as processors and are bound by contract under article 28 of the GDPR. We do not sell or rent your data. The one exception worth naming concerns advertising trackers: when you accept them, browsing identifiers are passed to Google, to OpenAI and to Meta, which California law calls "sharing" — the section for US residents sets that out in detail.

ProviderRoleLocation
Vercel Inc.Site hosting, technical logs and load-time measurement (Speed Insights, cookieless)European Union (servers) / United States (head office)
Prisma Data PlatformManaged PostgreSQL databaseEuropean Union
ResendTransactional email and our email sequencesUnited States
Google Ireland Ltd / Google LLCTag Manager, Google Ads and reCAPTCHA (anti-spam protection)European Union / United States
OpenAI, L.L.C.OpenAI Ads measurement pixel, loaded only once advertising is acceptedUnited States
Meta Platforms Ireland LtdMeta pixel (Facebook, Instagram), loaded only once advertising is acceptedEuropean Union / United States
Pipedrive OÜSite chat and sales follow-up of the requests made in it, loaded only once advertising is acceptedEuropean Union / United States
StripeMarketplace payment processingEuropean Union / United States

Card details never pass through our servers and are never stored by Beyond The Brackets: they are handled directly by Stripe, a PCI-DSS Level 1 certified provider.

Your data may also be shared with our advisers (accountant, lawyer) or with administrative and judicial authorities where the law requires it.

International transfers

Several of our processors are established in the United States, and Beyond The Brackets operates from Paris and New York. Every transfer outside the European Economic Area therefore relies on one of the safeguards in Chapter V of the GDPR: the recipient's certification under the EU-U.S. Data Privacy Framework where it exists, and otherwise the European Commission's standard contractual clauses of 4 June 2021. Those clauses are backed by technical measures — encryption in transit and at rest, minimising what is transmitted — and by a transfer impact assessment where the recipient is subject to surveillance legislation. For the United Kingdom, the UK International Data Transfer Addendum is added to the standard clauses; for Switzerland, the clauses are used in the version recognised by the FDPIC. A copy of these safeguards is available on request.

Your rights, depending on where you live

Data protection does not follow the same rules everywhere. Rather than applying the lowest common denominator, we grant every visitor the GDPR baseline — access, rectification, erasure, objection — and add the specific rights your local law provides. The purposes table above applies in every case.

European Economic Area, United Kingdom and Switzerland

The GDPR, the UK GDPR and the Swiss Federal Act on Data Protection give you the rights detailed in the "Your rights" section below. You may lodge a complaint with your supervisory authority: the CNIL in France, the Information Commissioner's Office in the United Kingdom, the Federal Data Protection and Information Commissioner in Switzerland. As our main establishment is in France, the CNIL is our lead authority.

Canada

Under PIPEDA you may access the personal information we hold, ask for it to be corrected and challenge our compliance with the Office of the Privacy Commissioner of Canada. If you live in Quebec, Law 25 additionally gives you the right to portability, the right to be informed of any decision based exclusively on automated processing — we make none — and the right to de-indexing. The person responsible for the protection of personal information is our legal representative, reachable at the address at the foot of this page.

Brazil

The LGPD gives you the right to confirm that processing exists, to access it, to correct it, to request anonymisation, blocking or deletion, to obtain portability, to know the entities your data is shared with, and to withdraw consent. You may refer a matter to the Autoridade Nacional de Proteção de Dados.

Australia and New Zealand

The Australian Privacy Principles and the New Zealand Privacy Act let you access your personal information and ask for corrections. You may complain to the Office of the Australian Information Commissioner or to the New Zealand Privacy Commissioner once you have contacted us first.

Everywhere else

If your local law provides no equivalent regime, we apply the GDPR baseline anyway: you can ask for access, rectification or erasure, and object to marketing, at the same address and within the same deadlines.

United States residents (California and comparable states)

Beyond The Brackets does not currently meet the thresholds that make the California Consumer Privacy Act apply. We have nonetheless chosen to extend the rights below to all US residents, whether they live in California, Colorado, Connecticut, Virginia, Utah, Texas or elsewhere. What follows therefore describes a commitment, not an obligation we are under.

Categories of personal information collected in the last twelve months

Category (CCPA)ExamplesShared for advertising
IdentifiersName, email, phone, IP address, browsing identifiersYes, if you accept advertising
Customer records (Cal. Civ. Code § 1798.80)Company, job title, billing detailsNo
Commercial informationServices ordered, marketplace order historyNo
Internet or network activityPages viewed, traffic source, navigation pathYes, if you accept advertising
Approximate geolocationCountry and region inferred from the IP addressNo
Professional informationCV and background, if you apply for a roleNo
InferencesScore and verdict produced by the simulator and diagnosticNo

Sensitive personal information

We collect no category of sensitive personal information within the meaning of the CPRA — no social security number, no health data, no biometrics, no contents of private communications, no sexual orientation, and no racial, ethnic or religious background. The right to limit the use of sensitive personal information therefore has nothing to apply to here.

Sale and sharing

We do not sell personal information and never have — including the personal information of anyone under sixteen. However, when you accept advertising cookies, our Google Ads tags, the OpenAI Ads pixel and the Meta pixel pass identifiers and browsing data to those partners: California law calls that "sharing" for cross-context behavioural advertising. We would rather say so than hide behind a bare "we do not sell your data".

Opting out of sale or sharing

Two ways, both free and immediate. Turn on the Global Privacy Control signal in your browser: we honour it automatically, with nothing for you to send us. Or use the "Manage cookies" control in the footer to switch the Advertising category off. No sign-up and no account are required.

Your rights

  • Know which categories of information we collect, where they come from, why we process them and who we share them with.
  • Obtain a copy of the specific pieces of information we hold about you.
  • Ask us to correct inaccurate information.
  • Ask us to delete your information, subject to the exceptions the law allows — our accounting obligations in particular.
  • Opt out of the sharing of your information for cross-context behavioural advertising.
  • Suffer no discrimination for exercising any of these rights: no different price, no degraded service, no refusal to answer.

How to exercise these rights

Write to contact@beyond-the-brackets.com stating the state you live in and what you are asking for. We acknowledge within ten business days and answer within forty-five days, extendable once by a further forty-five days if your request is complex — we would tell you if so. We must be able to verify your identity to a reasonable degree before releasing data: we do that by matching the information you give us against what we already hold, and we never ask for identity documents by email.

Authorised agent

You may appoint an authorised agent to act for you. We will ask the agent for written proof of authority and, unless there is a power of attorney, for direct confirmation from you.

California Shine the Light

Section 1798.83 of the California Civil Code lets you request the list of personal information disclosed to third parties for their direct marketing purposes. We disclose none for that purpose, so there is nothing to report — and we will confirm that to you in writing on request.

Data security

We implement technical and organisational measures proportionate to the risk:

  • HTTPS/TLS encryption across the entire site.
  • Passwords stored as irreversible hashes, never in plain text.
  • Data access restricted to the people who need it, with individual authentication.
  • Regular, encrypted database backups.
  • Anti-spam protection and rate limiting on public forms.
  • In the event of a data breach likely to result in a high risk to your rights, you would be informed without undue delay, in accordance with Article 34 GDPR.

Cookies and trackers

The site sets cookies that are strictly necessary for it to work, plus audience measurement and marketing cookies that require your prior consent. You can change your choice at any time.

Read the cookie policy →

Your rights

Under Articles 15 to 22 GDPR, you have the following rights over your personal data:

Access

Confirm whether your data is being processed and obtain a copy of it.

Rectification

Have inaccurate or incomplete data corrected.

Erasure

Request deletion of your data, subject to our legal retention obligations.

Restriction

Ask us to temporarily freeze processing you are contesting.

Portability

Receive the data you provided to us in a structured, machine-readable format.

Objection

Object to processing based on our legitimate interest, and at any time to direct marketing.

Withdrawal of consent

Withdraw your consent at any time, without affecting the lawfulness of processing already carried out.

Post-mortem instructions

Set out what should happen to your data after your death, under Article 85 of the French Data Protection Act.

To exercise these rights, write to contact@beyond-the-brackets.com or by post to 66 avenue des Champs-Élysées, 75008 Paris, France. We reply within one month of receiving your request. Proof of identity may be requested where there is reasonable doubt about who you are.

If, after contacting us, you believe your rights have not been respected, you may refer the matter to the competent supervisory authority: the CNIL in France (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr), the Information Commissioner's Office in the United Kingdom, the FDPIC in Switzerland, the Office of the Privacy Commissioner in Canada, the ANPD in Brazil, or the authority in your country of residence. In the United States the route depends on your state: in California, the California Privacy Protection Agency and the State Attorney General.

Automated decision-making

The online simulator and diagnostic produce an indicative estimate based on your answers. These tools do not constitute automated decision-making producing legal effects concerning you within the meaning of Article 22 GDPR: every commercial proposal goes through a human conversation.

Minors

Our services are aimed at professionals and are not intended for minors. We do not knowingly collect data about anyone under fifteen in France — raised to sixteen in some EU member states — or under thirteen in the United States, where the Children's Online Privacy Protection Act applies. If you find that a minor has given us data, tell us: it will be deleted without delay and without condition.

Changes to this policy

This policy may be updated to reflect changes in our services or in the applicable regulations. The date of the latest update appears at the top of this page. If a material change affects your rights, we will notify you by email or through a notice on the site.

Contact us

A question about this policy or about how we handle your data?

contact@beyond-the-brackets.com

BEYOND THE BRACKETS, 66 avenue des Champs-Élysées, 75008 Paris, France

Privacy Policy | Beyond The Brackets