Last updated: August 12, 2026

Privacy Policy

Learn about our data protection and privacy practices. We handle your information with care and security.

Beyond The Brackets holds data protection to the same standard as the code we write. This policy explains what personal data we collect when you use this website or our services, why we process it, how long we keep it and how to exercise your rights, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.

Data controller

The controller of your personal data is:

  • BEYOND THE BRACKETS — Simplified joint-stock company with a sole shareholder (SASU), share capital €2,000.00
  • Paris Trade Register B 852 264 035 — SIRET 852 264 035 00035
  • Registered office: 66 avenue des Champs-Élysées, 75008 Paris, France
  • Legal representative and publication director: Mr Loïc Guillebeau
  • Data protection contact: contact@beyond-the-brackets.com

Given its size and the nature of its activities, Beyond The Brackets is not required to appoint a Data Protection Officer. Any question about your data is handled directly by management, at the address above.

Data we collect

We only collect the data required for the purposes described below. We never ask for special categories of data within the meaning of Article 9 GDPR.

Data you provide

  • Contact form: first and last name, email address, phone number, company, request type and the content of your message.
  • Project simulator and online diagnostic: email address and questionnaire answers (project type, expected budget, maturity).
  • Client area: login credentials, hashed password, project information, documents, tickets and messages exchanged.
  • Marketplace: billing information required to process your order.

Data collected automatically

  • Connection data and technical logs: IP address, request date and time, pages viewed, browser and device type.
  • Audience measurement: page views, traffic source and browsing path, only if you have consented.
  • Security data: anti-spam signals produced by Google reCAPTCHA when you submit one of our forms.

Purposes, legal bases and retention periods

Each processing activity relies on a specific legal basis and a limited retention period. Once that period ends, the data is deleted or anonymised.

PurposeData involvedLegal basisRetention
Answer your enquiries and prepare a quoteIdentity, contact details, message contentPre-contractual steps (Art. 6(1)(b))3 years after last contact
Deliver simulator and diagnostic resultsEmail, questionnaire answersConsent (Art. 6(1)(a))3 years after last contact
Deliver our services and run the client areaAccount, project data, documents, exchangesPerformance of a contract (Art. 6(1)(b))Term of the contract, then 5 years
Invoicing and accounting obligationsBilling and order dataLegal obligation (Art. 6(1)(c))10 years (Art. L123-22 French Commercial Code)
Send our communications and B2B outreachEmail, open and click statisticsConsent or legitimate interest (Art. 6(1)(a) / 6(1)(f))3 years after last interaction
Measure audience and improve the siteBrowsing identifiers, page viewsConsent (Art. 6(1)(a))13 months (cookies), 25 months (statistics)
Secure the site and prevent abuseIP address, technical logs, reCAPTCHA signalsLegitimate interest (Art. 6(1)(f))12 months

Recipients and processors

Your data is accessible to the Beyond The Brackets team on a need-to-know basis, and to the technical providers listed below, which act as processors and are bound by contract under Article 28 GDPR. We never sell or rent your data to third parties.

ProviderRoleLocation
Vercel Inc.Website hosting and technical logsUnited States / EU
Prisma Data PlatformManaged PostgreSQL databaseEuropean Union
ResendTransactional email deliveryUnited States
Google (Analytics, Tag Manager, reCAPTCHA)Audience measurement and anti-spam protectionUnited States / EU
StripeMarketplace payment processingUnited States / EU

Card details never pass through our servers and are never stored by Beyond The Brackets: they are handled directly by Stripe, a PCI-DSS Level 1 certified provider.

Your data may also be shared with our advisers (accountant, lawyer) or with administrative and judicial authorities where the law requires it.

Transfers outside the European Union

Some of our processors are established in the United States. These transfers are covered by the appropriate safeguards set out in Chapter V GDPR: certification under the EU-U.S. Data Privacy Framework and, failing that, the European Commission's standard contractual clauses supplemented by technical measures (encryption in transit and at rest). A copy of these safeguards is available on request.

Data security

We implement technical and organisational measures proportionate to the risk:

  • HTTPS/TLS encryption across the entire site.
  • Passwords stored as irreversible hashes, never in plain text.
  • Data access restricted to the people who need it, with individual authentication.
  • Regular, encrypted database backups.
  • Anti-spam protection and rate limiting on public forms.
  • In the event of a data breach likely to result in a high risk to your rights, you would be informed without undue delay, in accordance with Article 34 GDPR.

Cookies and trackers

The site sets cookies that are strictly necessary for it to work, plus audience measurement and marketing cookies that require your prior consent. You can change your choice at any time.

Read the cookie policy

Your rights

Under Articles 15 to 22 GDPR, you have the following rights over your personal data:

Access

Confirm whether your data is being processed and obtain a copy of it.

Rectification

Have inaccurate or incomplete data corrected.

Erasure

Request deletion of your data, subject to our legal retention obligations.

Restriction

Ask us to temporarily freeze processing you are contesting.

Portability

Receive the data you provided to us in a structured, machine-readable format.

Objection

Object to processing based on our legitimate interest, and at any time to direct marketing.

Withdrawal of consent

Withdraw your consent at any time, without affecting the lawfulness of processing already carried out.

Post-mortem instructions

Set out what should happen to your data after your death, under Article 85 of the French Data Protection Act.

To exercise these rights, write to contact@beyond-the-brackets.com or by post to 66 avenue des Champs-Élysées, 75008 Paris, France. We reply within one month of receiving your request. Proof of identity may be requested where there is reasonable doubt about who you are.

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French supervisory authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.

Automated decision-making

The online simulator and diagnostic produce an indicative estimate based on your answers. These tools do not constitute automated decision-making producing legal effects concerning you within the meaning of Article 22 GDPR: every commercial proposal goes through a human conversation.

Minors

Our services are aimed at professionals and are not intended for people under 15. We do not knowingly collect data about minors. If you believe a minor has provided us with data, contact us and it will be deleted.

Changes to this policy

This policy may be updated to reflect changes in our services or in the applicable regulations. The date of the latest update appears at the top of this page. If a material change affects your rights, we will notify you by email or through a notice on the site.

Contact us

A question about this policy or about how we handle your data?

Email: contact@beyond-the-brackets.com

Address: 66 avenue des Champs-Élysées, 75008 Paris, France