Privacy Policy
What data we collect, why, for how long, who we share it with — and your rights, depending on where you live.
Beyond The Brackets holds the protection of your data to the same standard as the code we write. This policy explains what personal data we collect when you use this site or our services, why we process it, how long we keep it and how to exercise your rights. It is built on the General Data Protection Regulation (GDPR) and the French Data Protection Act, which we apply as the baseline for every visitor wherever they are; a dedicated section then sets out the additional rights you have depending on where you live — in particular in the United States, the United Kingdom, Switzerland, Canada, Brazil and Australia.
Data controller
The controller of your personal data is the company that publishes this site, whose full identity appears in our legal notice:
- Company : BEYOND THE BRACKETS — SASU
- Registration : RCS Paris B 852 264 035 — SIRET 852 264 035 00035
- Registered office : 66 avenue des Champs-Élysées, 75008 Paris, France
- Legal representative and publication director : Loïc Guillebeau
- Data protection contact : contact@beyond-the-brackets.com
Given its size and the nature of its activities, Beyond The Brackets is not required to appoint a Data Protection Officer. Any question about your data is handled directly by management, at the address above.
Data we collect
We only collect the data required for the purposes described below. We never ask for special categories of data within the meaning of Article 9 GDPR.
Data you provide
- Contact form: first and last name, email address, phone number, company, request type and the content of your message.
- Site chat: what you write in the conversation and any contact details you leave in it, passed to our sales pipeline (Pipedrive).
- Project simulator and online diagnostic: email address and questionnaire answers (project type, expected budget, maturity).
- Client area: login credentials, hashed password, project information, documents, tickets and messages exchanged.
- Marketplace: billing information required to process your order.
Data collected automatically
- Connection data and technical logs: IP address, request date and time, pages viewed, browser and device type.
- Audience measurement: page views, traffic source and browsing path, only if you have consented.
- Security data: anti-spam signals produced by Google reCAPTCHA when you submit one of our forms.
Purposes, legal bases and retention periods
Each processing activity relies on a specific legal basis and a limited retention period. Once that period ends, the data is deleted or anonymised.
| Purpose | Data involved | Legal basis | Retention |
|---|---|---|---|
| Answer your enquiries and prepare a quote | Identity, contact details, message content | Pre-contractual steps (Art. 6(1)(b)) | 3 years after last contact |
| Deliver simulator and diagnostic results | Email, questionnaire answers | Consent (Art. 6(1)(a)) | 3 years after last contact |
| Deliver our services and run the client area | Account, project data, documents, exchanges | Performance of a contract (Art. 6(1)(b)) | Term of the contract, then 5 years |
| Invoicing and accounting obligations | Billing and order data | Legal obligation (Art. 6(1)(c)) | 10 years (Art. L123-22 French Commercial Code) |
| Send our communications and B2B outreach | Email, open and click statistics | Consent or legitimate interest (Art. 6(1)(a) / 6(1)(f)) | 3 years after last interaction |
| Measure audience and improve the site | Browsing identifiers, page views | Consent (Art. 6(1)(a)) | 13 months (cookies), 25 months (statistics) |
| Secure the site and prevent abuse | IP address, technical logs, reCAPTCHA signals | Legitimate interest (Art. 6(1)(f)) | 12 months |
Recipients and processors
Your data is accessible to the Beyond The Brackets team, on a need-to-know basis, and to the technical providers below, who act as processors and are bound by contract under article 28 of the GDPR. We do not sell or rent your data. The one exception worth naming concerns advertising trackers: when you accept them, browsing identifiers are passed to Google, to OpenAI and to Meta, which California law calls "sharing" — the section for US residents sets that out in detail.
| Provider | Role | Location |
|---|---|---|
| Vercel Inc. | Site hosting, technical logs and load-time measurement (Speed Insights, cookieless) | European Union (servers) / United States (head office) |
| Prisma Data Platform | Managed PostgreSQL database | European Union |
| Resend | Transactional email and our email sequences | United States |
| Google Ireland Ltd / Google LLC | Tag Manager, Google Ads and reCAPTCHA (anti-spam protection) | European Union / United States |
| OpenAI, L.L.C. | OpenAI Ads measurement pixel, loaded only once advertising is accepted | United States |
| Meta Platforms Ireland Ltd | Meta pixel (Facebook, Instagram), loaded only once advertising is accepted | European Union / United States |
| Pipedrive OÜ | Site chat and sales follow-up of the requests made in it, loaded only once advertising is accepted | European Union / United States |
| Stripe | Marketplace payment processing | European Union / United States |
Card details never pass through our servers and are never stored by Beyond The Brackets: they are handled directly by Stripe, a PCI-DSS Level 1 certified provider.
Your data may also be shared with our advisers (accountant, lawyer) or with administrative and judicial authorities where the law requires it.
International transfers
Several of our processors are established in the United States, and Beyond The Brackets operates from Paris and New York. Every transfer outside the European Economic Area therefore relies on one of the safeguards in Chapter V of the GDPR: the recipient's certification under the EU-U.S. Data Privacy Framework where it exists, and otherwise the European Commission's standard contractual clauses of 4 June 2021. Those clauses are backed by technical measures — encryption in transit and at rest, minimising what is transmitted — and by a transfer impact assessment where the recipient is subject to surveillance legislation. For the United Kingdom, the UK International Data Transfer Addendum is added to the standard clauses; for Switzerland, the clauses are used in the version recognised by the FDPIC. A copy of these safeguards is available on request.
Your rights, depending on where you live
Data protection does not follow the same rules everywhere. Rather than applying the lowest common denominator, we grant every visitor the GDPR baseline — access, rectification, erasure, objection — and add the specific rights your local law provides. The purposes table above applies in every case.
European Economic Area, United Kingdom and Switzerland
The GDPR, the UK GDPR and the Swiss Federal Act on Data Protection give you the rights detailed in the "Your rights" section below. You may lodge a complaint with your supervisory authority: the CNIL in France, the Information Commissioner's Office in the United Kingdom, the Federal Data Protection and Information Commissioner in Switzerland. As our main establishment is in France, the CNIL is our lead authority.
Canada
Under PIPEDA you may access the personal information we hold, ask for it to be corrected and challenge our compliance with the Office of the Privacy Commissioner of Canada. If you live in Quebec, Law 25 additionally gives you the right to portability, the right to be informed of any decision based exclusively on automated processing — we make none — and the right to de-indexing. The person responsible for the protection of personal information is our legal representative, reachable at the address at the foot of this page.
Brazil
The LGPD gives you the right to confirm that processing exists, to access it, to correct it, to request anonymisation, blocking or deletion, to obtain portability, to know the entities your data is shared with, and to withdraw consent. You may refer a matter to the Autoridade Nacional de Proteção de Dados.
Australia and New Zealand
The Australian Privacy Principles and the New Zealand Privacy Act let you access your personal information and ask for corrections. You may complain to the Office of the Australian Information Commissioner or to the New Zealand Privacy Commissioner once you have contacted us first.
Everywhere else
If your local law provides no equivalent regime, we apply the GDPR baseline anyway: you can ask for access, rectification or erasure, and object to marketing, at the same address and within the same deadlines.
United States residents (California and comparable states)
Beyond The Brackets does not currently meet the thresholds that make the California Consumer Privacy Act apply. We have nonetheless chosen to extend the rights below to all US residents, whether they live in California, Colorado, Connecticut, Virginia, Utah, Texas or elsewhere. What follows therefore describes a commitment, not an obligation we are under.
Categories of personal information collected in the last twelve months
| Category (CCPA) | Examples | Shared for advertising |
|---|---|---|
| Identifiers | Name, email, phone, IP address, browsing identifiers | Yes, if you accept advertising |
| Customer records (Cal. Civ. Code § 1798.80) | Company, job title, billing details | No |
| Commercial information | Services ordered, marketplace order history | No |
| Internet or network activity | Pages viewed, traffic source, navigation path | Yes, if you accept advertising |
| Approximate geolocation | Country and region inferred from the IP address | No |
| Professional information | CV and background, if you apply for a role | No |
| Inferences | Score and verdict produced by the simulator and diagnostic | No |
Sensitive personal information
We collect no category of sensitive personal information within the meaning of the CPRA — no social security number, no health data, no biometrics, no contents of private communications, no sexual orientation, and no racial, ethnic or religious background. The right to limit the use of sensitive personal information therefore has nothing to apply to here.
Sale and sharing
We do not sell personal information and never have — including the personal information of anyone under sixteen. However, when you accept advertising cookies, our Google Ads tags, the OpenAI Ads pixel and the Meta pixel pass identifiers and browsing data to those partners: California law calls that "sharing" for cross-context behavioural advertising. We would rather say so than hide behind a bare "we do not sell your data".
Opting out of sale or sharing
Two ways, both free and immediate. Turn on the Global Privacy Control signal in your browser: we honour it automatically, with nothing for you to send us. Or use the "Manage cookies" control in the footer to switch the Advertising category off. No sign-up and no account are required.
Your rights
- Know which categories of information we collect, where they come from, why we process them and who we share them with.
- Obtain a copy of the specific pieces of information we hold about you.
- Ask us to correct inaccurate information.
- Ask us to delete your information, subject to the exceptions the law allows — our accounting obligations in particular.
- Opt out of the sharing of your information for cross-context behavioural advertising.
- Suffer no discrimination for exercising any of these rights: no different price, no degraded service, no refusal to answer.
How to exercise these rights
Write to contact@beyond-the-brackets.com stating the state you live in and what you are asking for. We acknowledge within ten business days and answer within forty-five days, extendable once by a further forty-five days if your request is complex — we would tell you if so. We must be able to verify your identity to a reasonable degree before releasing data: we do that by matching the information you give us against what we already hold, and we never ask for identity documents by email.
Authorised agent
You may appoint an authorised agent to act for you. We will ask the agent for written proof of authority and, unless there is a power of attorney, for direct confirmation from you.
California Shine the Light
Section 1798.83 of the California Civil Code lets you request the list of personal information disclosed to third parties for their direct marketing purposes. We disclose none for that purpose, so there is nothing to report — and we will confirm that to you in writing on request.
Data security
We implement technical and organisational measures proportionate to the risk:
- HTTPS/TLS encryption across the entire site.
- Passwords stored as irreversible hashes, never in plain text.
- Data access restricted to the people who need it, with individual authentication.
- Regular, encrypted database backups.
- Anti-spam protection and rate limiting on public forms.
- In the event of a data breach likely to result in a high risk to your rights, you would be informed without undue delay, in accordance with Article 34 GDPR.
Cookies and trackers
The site sets cookies that are strictly necessary for it to work, plus audience measurement and marketing cookies that require your prior consent. You can change your choice at any time.
Read the cookie policy →Your rights
Under Articles 15 to 22 GDPR, you have the following rights over your personal data:
Access
Confirm whether your data is being processed and obtain a copy of it.
Rectification
Have inaccurate or incomplete data corrected.
Erasure
Request deletion of your data, subject to our legal retention obligations.
Restriction
Ask us to temporarily freeze processing you are contesting.
Portability
Receive the data you provided to us in a structured, machine-readable format.
Objection
Object to processing based on our legitimate interest, and at any time to direct marketing.
Withdrawal of consent
Withdraw your consent at any time, without affecting the lawfulness of processing already carried out.
Post-mortem instructions
Set out what should happen to your data after your death, under Article 85 of the French Data Protection Act.
To exercise these rights, write to contact@beyond-the-brackets.com or by post to 66 avenue des Champs-Élysées, 75008 Paris, France. We reply within one month of receiving your request. Proof of identity may be requested where there is reasonable doubt about who you are.
If, after contacting us, you believe your rights have not been respected, you may refer the matter to the competent supervisory authority: the CNIL in France (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr), the Information Commissioner's Office in the United Kingdom, the FDPIC in Switzerland, the Office of the Privacy Commissioner in Canada, the ANPD in Brazil, or the authority in your country of residence. In the United States the route depends on your state: in California, the California Privacy Protection Agency and the State Attorney General.
Automated decision-making
The online simulator and diagnostic produce an indicative estimate based on your answers. These tools do not constitute automated decision-making producing legal effects concerning you within the meaning of Article 22 GDPR: every commercial proposal goes through a human conversation.
Minors
Our services are aimed at professionals and are not intended for minors. We do not knowingly collect data about anyone under fifteen in France — raised to sixteen in some EU member states — or under thirteen in the United States, where the Children's Online Privacy Protection Act applies. If you find that a minor has given us data, tell us: it will be deleted without delay and without condition.
Changes to this policy
This policy may be updated to reflect changes in our services or in the applicable regulations. The date of the latest update appears at the top of this page. If a material change affects your rights, we will notify you by email or through a notice on the site.
Contact us
A question about this policy or about how we handle your data?
contact@beyond-the-brackets.com
BEYOND THE BRACKETS, 66 avenue des Champs-Élysées, 75008 Paris, France
