Privacy Policy
Learn about our data protection and privacy practices. We handle your information with care and security.
Beyond The Brackets holds data protection to the same standard as the code we write. This policy explains what personal data we collect when you use this website or our services, why we process it, how long we keep it and how to exercise your rights, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
Data controller
The controller of your personal data is:
- BEYOND THE BRACKETS — Simplified joint-stock company with a sole shareholder (SASU), share capital €2,000.00
- Paris Trade Register B 852 264 035 — SIRET 852 264 035 00035
- Registered office: 66 avenue des Champs-Élysées, 75008 Paris, France
- Legal representative and publication director: Mr Loïc Guillebeau
- Data protection contact: contact@beyond-the-brackets.com
Given its size and the nature of its activities, Beyond The Brackets is not required to appoint a Data Protection Officer. Any question about your data is handled directly by management, at the address above.
Data we collect
We only collect the data required for the purposes described below. We never ask for special categories of data within the meaning of Article 9 GDPR.
Data you provide
- Contact form: first and last name, email address, phone number, company, request type and the content of your message.
- Project simulator and online diagnostic: email address and questionnaire answers (project type, expected budget, maturity).
- Client area: login credentials, hashed password, project information, documents, tickets and messages exchanged.
- Marketplace: billing information required to process your order.
Data collected automatically
- Connection data and technical logs: IP address, request date and time, pages viewed, browser and device type.
- Audience measurement: page views, traffic source and browsing path, only if you have consented.
- Security data: anti-spam signals produced by Google reCAPTCHA when you submit one of our forms.
Purposes, legal bases and retention periods
Each processing activity relies on a specific legal basis and a limited retention period. Once that period ends, the data is deleted or anonymised.
| Purpose | Data involved | Legal basis | Retention |
|---|---|---|---|
| Answer your enquiries and prepare a quote | Identity, contact details, message content | Pre-contractual steps (Art. 6(1)(b)) | 3 years after last contact |
| Deliver simulator and diagnostic results | Email, questionnaire answers | Consent (Art. 6(1)(a)) | 3 years after last contact |
| Deliver our services and run the client area | Account, project data, documents, exchanges | Performance of a contract (Art. 6(1)(b)) | Term of the contract, then 5 years |
| Invoicing and accounting obligations | Billing and order data | Legal obligation (Art. 6(1)(c)) | 10 years (Art. L123-22 French Commercial Code) |
| Send our communications and B2B outreach | Email, open and click statistics | Consent or legitimate interest (Art. 6(1)(a) / 6(1)(f)) | 3 years after last interaction |
| Measure audience and improve the site | Browsing identifiers, page views | Consent (Art. 6(1)(a)) | 13 months (cookies), 25 months (statistics) |
| Secure the site and prevent abuse | IP address, technical logs, reCAPTCHA signals | Legitimate interest (Art. 6(1)(f)) | 12 months |
Recipients and processors
Your data is accessible to the Beyond The Brackets team on a need-to-know basis, and to the technical providers listed below, which act as processors and are bound by contract under Article 28 GDPR. We never sell or rent your data to third parties.
| Provider | Role | Location |
|---|---|---|
| Vercel Inc. | Website hosting and technical logs | United States / EU |
| Prisma Data Platform | Managed PostgreSQL database | European Union |
| Resend | Transactional email delivery | United States |
| Google (Analytics, Tag Manager, reCAPTCHA) | Audience measurement and anti-spam protection | United States / EU |
| Stripe | Marketplace payment processing | United States / EU |
Card details never pass through our servers and are never stored by Beyond The Brackets: they are handled directly by Stripe, a PCI-DSS Level 1 certified provider.
Your data may also be shared with our advisers (accountant, lawyer) or with administrative and judicial authorities where the law requires it.
Transfers outside the European Union
Some of our processors are established in the United States. These transfers are covered by the appropriate safeguards set out in Chapter V GDPR: certification under the EU-U.S. Data Privacy Framework and, failing that, the European Commission's standard contractual clauses supplemented by technical measures (encryption in transit and at rest). A copy of these safeguards is available on request.
Data security
We implement technical and organisational measures proportionate to the risk:
- HTTPS/TLS encryption across the entire site.
- Passwords stored as irreversible hashes, never in plain text.
- Data access restricted to the people who need it, with individual authentication.
- Regular, encrypted database backups.
- Anti-spam protection and rate limiting on public forms.
- In the event of a data breach likely to result in a high risk to your rights, you would be informed without undue delay, in accordance with Article 34 GDPR.
Cookies and trackers
The site sets cookies that are strictly necessary for it to work, plus audience measurement and marketing cookies that require your prior consent. You can change your choice at any time.
Read the cookie policy →Your rights
Under Articles 15 to 22 GDPR, you have the following rights over your personal data:
Access
Confirm whether your data is being processed and obtain a copy of it.
Rectification
Have inaccurate or incomplete data corrected.
Erasure
Request deletion of your data, subject to our legal retention obligations.
Restriction
Ask us to temporarily freeze processing you are contesting.
Portability
Receive the data you provided to us in a structured, machine-readable format.
Objection
Object to processing based on our legitimate interest, and at any time to direct marketing.
Withdrawal of consent
Withdraw your consent at any time, without affecting the lawfulness of processing already carried out.
Post-mortem instructions
Set out what should happen to your data after your death, under Article 85 of the French Data Protection Act.
To exercise these rights, write to contact@beyond-the-brackets.com or by post to 66 avenue des Champs-Élysées, 75008 Paris, France. We reply within one month of receiving your request. Proof of identity may be requested where there is reasonable doubt about who you are.
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French supervisory authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.
Automated decision-making
The online simulator and diagnostic produce an indicative estimate based on your answers. These tools do not constitute automated decision-making producing legal effects concerning you within the meaning of Article 22 GDPR: every commercial proposal goes through a human conversation.
Minors
Our services are aimed at professionals and are not intended for people under 15. We do not knowingly collect data about minors. If you believe a minor has provided us with data, contact us and it will be deleted.
Changes to this policy
This policy may be updated to reflect changes in our services or in the applicable regulations. The date of the latest update appears at the top of this page. If a material change affects your rights, we will notify you by email or through a notice on the site.
Contact us
A question about this policy or about how we handle your data?
Email: contact@beyond-the-brackets.com
Address: 66 avenue des Champs-Élysées, 75008 Paris, France
