Privacy Policy
1. Who we are and what this covers
This Privacy Policy explains how Sebastien Vautier (professionally known as Sebastien Ricci), a sole proprietor trading as Beyond the Edge Studio, Las Vegas, Nevada, USA ("we", "us"), handles personal information in connection with the Beyond the Edge Lead Engine (the "Service"). It covers visitors to our public pages, the people who hold accounts ("users"), and the business contact information our customers process through the Service. For customer organizations subject to data protection law, the Data Processing Agreement at /legal/dpa also applies and controls for Customer Data. Contact: sebastien@beyondtheedgestudio.com, 4375 N Las Vegas Blvd, Suite 7, PMB 5028, Las Vegas, NV 89115, USA.
2. Two roles: controller and processor
For account, billing, and usage information about our customers and their users, we act as the data controller. For the business contact data our customers bring into or gather through the Service (their leads, messages, notes, and related records, together "Customer Data"), the customer is the controller and we act as their processor: we handle that data only on the customer's instructions as described in the Data Processing Agreement. If you were contacted by one of our customers, that customer, not us, decided to contact you. See Section 14.
3. Information we collect
We collect the following categories.
- Account information: name, work email address, password (stored only as a salted hash, never in readable form), optional profile photo, role, office, language preference, and two-factor enrollment status.
- Organization information: company name, physical postal address (required by law in outreach email), plan, and billing status.
- Billing information: handled by Stripe. We store Stripe identifiers and invoice metadata. We never see or store full card numbers.
- Usage and log information: entries in the audit log such as sends, blocks, sign-ins and administrative changes; technical error logs; and the approximate network address used for security purposes including sign-in throttling and the durable record of terms acceptance.
- Customer Data: the business contacts, outreach messages, replies, tasks, generated pages, and client contracts your organization manages in the Service.
- Connected-account credentials: OAuth tokens, SMTP credentials, and provider API keys you choose to connect. These are encrypted before storage and are never returned to any browser, including yours.
4. Cookies and similar technologies
The Service sets two first-party cookies and no advertising or analytics trackers. There is no third-party advertising cookie, no cross-site tracking pixel, and no product analytics SDK in the application. The Service also uses no browser localStorage or sessionStorage.
- bte_session - strictly necessary. Keeps you signed in. Contains only an opaque random token; the session record itself stays on our servers. httpOnly, SameSite=Lax, Secure over HTTPS, lifetime 7 days.
- bte_gate - strictly necessary during the private beta. Records that a visitor entered the beta access code. Contains a fixed token and never the code itself. httpOnly, SameSite=Lax, Secure over HTTPS, lifetime 30 days.
- Web fonts: our application shell and pricing page load fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). Your browser's request to Google discloses your IP address and user agent to Google. No cookie is set by us for this. The pages under /legal use system fonts only and make no third-party request.
5. How we use information
We use information to provide and operate the Service (including sending your approved messages through your own connected inboxes), to secure it (authentication, abuse and fraud prevention, audit records), to bill for it, to support you, to comply with law, and to improve reliability. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train general-purpose models or to advertise to anyone.
6. Legal bases (where GDPR or similar law applies)
We process account and billing information to perform our contract with your organization. Security, abuse prevention, and product reliability rest on our legitimate interests in operating a safe service. Processing required by law, such as tax records, rests on legal obligation. Customer Data is processed on the customer's documented instructions under the Data Processing Agreement. Where we rely on legitimate interests we have considered the impact on the people concerned and you may object as described in Section 11.
7. Providers we share information with
We share information only with the providers needed to run the Service, under contracts that restrict their use of it. The current list, what each one handles, and where it processes data is published and dated at /legal/subprocessors. We update that page before adding a provider that handles personal data. We may also disclose information where required by law, to protect the Service and its users, or in connection with a merger or acquisition, in which case we will give notice. Note that some providers are connected by you rather than by us: your email inboxes, and any provider key you supply yourself. Where you connect a provider, your agreement with that provider governs it.
8. International transfers
The Service is operated from the United States on infrastructure that may process data in multiple regions. Where personal data is transferred out of the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's 2021 Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK transfers and the Swiss adaptations recognized by the Federal Data Protection and Information Commissioner for Swiss transfers, and on the transfer mechanisms our providers publish. You may request a copy of the relevant mechanism by contacting us.
9. Security
The measures below are implemented today, not aspirations. No system is perfectly secure; if a breach affecting Customer Data occurs we will notify affected customers without undue delay, and within 72 hours of becoming aware, as set out in the Data Processing Agreement.
- Tenant isolation: every organization's data is separated at a single audited data-access layer that injects the organization identifier into every query and refuses any caller-supplied one.
- Encryption in transit: TLS on every connection.
- Encryption at rest for secrets: stored provider keys and inbox credentials are encrypted with AES-256-GCM using a random initialization vector per value, under a key held only as a deployment secret.
- Password storage: PBKDF2-SHA256 with 100,000 iterations, a random 128-bit salt per password, and constant-time comparison on verification.
- Sessions: opaque 256-bit random tokens held server-side; the browser receives only an httpOnly cookie. Optional TOTP two-factor authentication and an additional workspace passcode are available.
- Access control: three roles enforced on the server, never in the browser, plus a cross-site request forgery guard on every state-changing request.
- Rate limiting: sign-in failures are limited per address and per account, and password-reset and signup requests are limited per network address.
- Integrity: webhooks are rejected unless their cryptographic signature verifies. The audit log is append-only.
- Outreach safeguards that operators cannot disable: per-inbox volume caps, enforced intervals, permanent suppression of opt-outs, and unsubscribe headers on every message.
10. Retention
We are deliberately plain about this because vague retention language is usually untrue. Account and Customer Data are kept while your organization's account is active. THERE IS NO AUTOMATIC AGE-BASED DELETION: contacts, messages, sends, calls, generated pages and audit records inside an active workspace are kept indefinitely until your organization is deleted. Short-lived security records expire automatically on the schedules below. When an administrator deletes the organization, the deletion is comprehensive rather than selective: every organization-scoped record is removed, including billing history, the record of terms acceptance, and the suppression list, and we do not currently hold anything back from that erasure. If you need particular records preserved for your own compliance purposes, export or record them before deleting.
- Sign-in sessions: 7 days, then expire automatically.
- Pending two-factor login state and two-factor enrollment state: 10 minutes.
- Password-reset links: 30 minutes, single use.
- Email-confirmation links: 24 hours, single use.
- Sign-in failure, password-reset and signup rate-limit counters: 15 minutes to 1 hour. Some of these counters include an email address or network address in the record while they exist.
- Organization deletion: an administrator can permanently delete the organization in-app after typing the organization name to confirm. This removes the organization's records and stored files from live systems immediately.
11. Your rights and how to exercise them
Depending on where you live you may have the right to access, correct, delete, or receive a portable copy of your personal information, to object to or restrict certain processing, to withdraw consent where processing relies on it, and to complain to a supervisory authority. Users can edit their own profile in the app, and an administrator can permanently delete the whole organization in the app. The Service does not yet provide a self-service export or a way to delete one individual contact record; while that is the case we handle both manually, and you can obtain an export or a specific deletion by emailing us. To make any request, email sebastien@beyondtheedgestudio.com. We will verify your request by confirming control of the email address on the account, or for a person who is not an account holder, by asking for enough information to locate the records reliably and no more. An authorized agent may act for you with written authorization and we may still verify with you directly. We respond within 30 days, and where the law allows an extension for complex requests we may extend by a further 45 days and will tell you why. If we decline a request you may appeal by replying to our decision with the word APPEAL, and we will review and respond; you may also complain to your supervisory authority or state attorney general. We do not discriminate against anyone for exercising these rights. We do not make decisions producing legal or similarly significant effects about you by automated means alone.
12. United States state privacy rights
California: under the CCPA as amended by the CPRA, in the preceding 12 months we collected the categories of personal information described in Section 3 (identifiers, commercial information, internet and network activity, professional or employment-related information, and the contents of communications you create in the Service), for the business purposes described in Section 5, from you and from your organization, and disclosed them for business purposes only to the providers listed at /legal/subprocessors. WE HAVE NOT SOLD PERSONAL INFORMATION AND HAVE NOT SHARED IT FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING IN THE PRECEDING 12 MONTHS, AND WE DO NOT DO SO TODAY. We do not knowingly sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes requiring a limitation notice. You have rights to know, delete, correct, and to limit use of sensitive information, exercised as described in Section 11. Nevada: under NRS 603A we do not sell covered information as that chapter defines it; Nevada residents may still submit a verified opt-out request to the contact address above. Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws: you have equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling with legal effects, together with the appeal right described in Section 11. We do not conduct targeted advertising, sale, or such profiling.
13. Other jurisdictions
Brazil: under the LGPD you have rights of confirmation, access, correction, anonymization or deletion, portability, information about sharing, and revocation of consent, exercised through the contact above. Canada: under PIPEDA you may access and correct your personal information and challenge our handling of it with our contact above, and ultimately with the Office of the Privacy Commissioner of Canada. Where local law grants rights beyond those described here, we honor them.
14. A note for people contacted by our customers
Our customers use the Service to contact businesses. If a customer contacted you, that customer is the sender and is responsible for that outreach; we process the data on their behalf. Every outreach email carries a working one-click unsubscribe link, and using it suppresses your address for that customer permanently and cannot be undone by that customer. You may also write to sebastien@beyondtheedgestudio.com. We will pass a verified request to the responsible customer, and where the request is to stop contact we will apply suppression ourselves. Because we act as processor for that data, a request to delete records held by a customer is ultimately the customer's decision to make, and we will identify them to you where we lawfully can so that you can exercise your rights against the controller.
15. Children
The Service is for business use by adults. It is not directed to children, we do not knowingly collect personal information from anyone under 16, and we will delete such information promptly if we learn we have it.
16. Changes and contact
When this policy materially changes, the version identifier changes and we notify account administrators. Questions, requests, and complaints: sebastien@beyondtheedgestudio.com, or Sebastien Vautier, trading as Beyond the Edge Studio, 4375 N Las Vegas Blvd, Suite 7, PMB 5028, Las Vegas, NV 89115, USA. We have not appointed a representative in the European Union or United Kingdom; if you are in those regions and wish to raise a matter, write to the address above and we will respond directly.