Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your personal data.

Effective Date: July 31, 2026
Last Updated: July 31, 2026
Version: 2.1

⚖️ LEGAL JURISDICTION

ONLY Paris Courts, France have exclusive jurisdiction over disputes. EU consumers may alternatively use their local courts. See Section 18 for details.

1. Introduction

Welcome to Caramel ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws worldwide. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services.

Caramel is a business-to-business platform. Businesses use it to build and publish forms, collect and manage their own customer records, and run marketing campaigns across email, SMS, messaging apps, and push notifications, together with the integrations and premium advisory services that support that work.

Our Commitment to EU Data Residency: We prioritize data sovereignty by processing and storing your data primarily within the European Union using EU-based infrastructure providers.

This policy applies to:

  • Our website and web applications
  • Our mobile applications (iOS and Android)
  • Our API services
  • All related services we provide

2. Data Controller Information

Company Name:
React Motion Technologies SAS (SAS)
SIRET / SIREN / VAT:
94861223900012 / 948 612 239 / FR95948612239
Address:
73 Allée Kléber, 34000 Montpellier, France
Data Protection Officer (DPO):
To be appointed if required. Reach the privacy team at dpo@joincaramel.com
EU / UK Representative:
Not required (established in the EU). A UK representative will be appointed if UK operations commence.

For GDPR purposes, we act as:

  • Data Controller for platform users and business accounts
  • Data Processor for the end-customer data our business customers upload, collect, or send messages to through the platform

3. Information We Collect

3.1 Information You Provide Directly

Account Information:

  • Full name and title
  • Email address (verified)
  • Phone number (for 2FA and notifications)
  • Business name and registration details (for business accounts)
  • VAT/Tax identification numbers
  • Password (bcrypt hashed, never stored in plain text)

Payment Information:

  • Payment card details (tokenized through Stripe EU servers)
  • IBAN/Bank account details (for SEPA payments)
  • Billing address
  • Transaction history
  • Invoice preferences

End-Customer Data (processed on behalf of businesses):

Where a business uses Caramel to reach its own customers, we process the data that business supplies or collects. We act as processor for all of it:

  • Contact details (name, email address, phone number)
  • Responses submitted through forms the business publishes
  • Marketing consent status and communication preferences
  • Message delivery, open, click, and unsubscribe records
  • Segment membership and campaign history
  • Language and locale, where provided

3.2 Information Collected Automatically

Technical Data:

  • IP address (anonymized after 7 days)
  • Device type and identifiers (hashed)
  • Browser type and version
  • Operating system
  • Time zone and locale settings
  • Language preferences

Usage Data:

  • Pages visited and features used
  • Click patterns and navigation paths
  • Search queries within the platform
  • Performance metrics
  • Error logs (PII scrubbed)
  • Session duration

Cookie Data: Essential cookies for functionality, and analytics/marketing cookies where you have given consent — see our Cookie Policy.

3.3 Information from Third Parties

  • Payment verification from Stripe (EU servers)
  • Message delivery and engagement events from our sending providers
  • Analytics data from PostHog (EU cloud)

3.4 Special Categories of Data

We do NOT collect special categories of personal data (health, biometric, racial/ethnic origin, political opinions, religious beliefs, etc.) unless:

  • Required for legal compliance
  • Explicitly provided with separate consent
  • Necessary for employment law compliance (business accounts)

5. How We Use Your Information

5.1 Primary Purposes

Purpose Legal Basis Data Categories
Account Management Contract Identity, Contact
Payment Processing Contract Financial, Transaction
Form Publishing & Response Capture Contract End-customer, Communication
Campaign Delivery Contract End-customer, Communication, Consent
Customer Support Contract/Legitimate Interest All relevant
Security & Fraud Legitimate Interest Technical, Behavioral
Marketing Consent/Legitimate Interest Contact, Preferences
Legal Compliance Legal Obligation All required
Analytics Legitimate Interest Usage, Technical

5.2 Automated Decision-Making and Profiling

We use limited automated decision-making for:

  • Fraud Detection: Transaction risk scoring
  • Marketing Segmentation: Customer categorization
  • Service Personalization: Feature recommendations

Your Rights:

  • Request human review of automated decisions
  • Object to profiling for marketing
  • Opt-out of automated decision-making
  • Request explanation of logic involved

6. Data Sharing and Disclosure

6.1 EU-Based Service Providers (Data Processors)

All our primary processors maintain EU data residency:

Processor Purpose Location DPA Status
Hetzner Infrastructure hosting Germany (EU) ✅ Signed
Supabase Database & Auth EU Region (Frankfurt) ✅ Signed
Stripe Payment processing EU Data Center ✅ Signed
PostHog Analytics EU Cloud (Frankfurt) ✅ Signed
Sentry Error monitoring EU Region ✅ Signed

6.2 Communication Services

Service Purpose Data Location Safeguards
AWS SES Transactional email EU-WEST-1 (Ireland) SCCs + Encryption
AWS SNS SMS delivery EU-WEST-1 (Ireland) SCCs + Encryption
Internal System Marketing automation EU (Our servers) Internal control

6.3 Recipients Categories

  • Business Partners: Only their own customer data
  • Professional Advisors: Lawyers, accountants (under NDA)
  • Regulatory Authorities: When legally required
  • Law Enforcement: With valid legal basis only
  • Potential Acquirers: During M&A (under NDA)

6.4 We Never Share Data With

  • Data brokers or advertisers
  • Third parties for their own marketing
  • Anyone without legal basis
  • Non-EU countries without safeguards

7. International Data Transfers

7.1 EU Data Residency First

Primary Processing: All data is processed and stored within the EU:

  • Database: Germany (Hetzner)
  • Application: EU regions
  • Analytics: EU servers
  • Backups: EU locations

7.2 Limited Third-Country Transfers

When transfers outside the EU are necessary:

Country Processor Mechanism Additional Safeguards
USA Stripe (payments only) SCCs + DPF Encryption, Minimization

7.3 Transfer Safeguards

  • Standard Contractual Clauses (SCCs): Module 2 (Controller to Processor)
  • Supplementary Measures: End-to-end encryption, pseudonymization, data minimization, access restrictions
  • Transfer Impact Assessments (TIAs): Completed for each transfer
  • Your Rights: Request copies of safeguards documentation

8. Data Security

8.1 Technical Measures (ISO 27001 Aligned)

Encryption:

  • At rest: AES-256-GCM
  • In transit: TLS 1.3 (TLS 1.2 minimum)
  • Database: Transparent Data Encryption (TDE)
  • Backups: Encrypted with separate keys

Access Control:

  • Multi-factor authentication (MFA) mandatory
  • Role-Based Access Control (RBAC)
  • Principle of least privilege
  • Just-in-time access for elevated privileges
  • API rate limiting and authentication

Infrastructure Security:

  • Web Application Firewall (WAF)
  • DDoS protection (Cloudflare EU)
  • Intrusion Detection System (IDS)
  • Container security scanning
  • Vulnerability management program

Monitoring:

  • 24/7 security monitoring
  • Anomaly detection
  • Security Information and Event Management (SIEM)
  • Incident response team

8.2 Organizational Measures

Policies & Procedures:

  • Information Security Management System (ISMS)
  • Data Protection Impact Assessments (DPIAs)
  • Regular security audits (quarterly)
  • Penetration testing (annually)
  • Employee security training (mandatory)

Compliance:

  • ISO 27001 certification (in progress)
  • SOC 2 Type II (planned 2026)
  • PCI DSS compliance (via Stripe)
  • GDPR compliance program

8.3 Breach Response

Detection & Response Timeline:

  1. 0-1 hours: Incident detection and containment
  2. 1-24 hours: Impact assessment and mitigation
  3. 24-72 hours: Regulatory notification (if required)
  4. 72+ hours: User notification (if high risk)

Breach Register: Maintained per Article 33(5) GDPR.

9. Data Retention

9.1 Retention Schedule

Data Category Active Retention Post-Deletion Legal Basis
Account Data Duration of account 30 days Recovery period
Transaction Data Active account 10 years Tax law (France)
End-Customer Records Duration of business account 30 days Controller instruction
Form Responses Duration of business account 30 days Controller instruction
Campaign & Delivery Logs 24 months Immediate Deliverability, abuse prevention
Payment Data Active account 7 years Accounting law
Marketing Consent Until withdrawn 3 years proof Evidence
Analytics 24 months Immediate anonymization Legitimate interest
Security Logs 1 year 5 years (incidents only) Security
Support Tickets 2 years 3 years Service improvement
Cookies Per Cookie Policy

9.2 Retention Principles

  • Data Minimization: Only retain what's necessary
  • Purpose Limitation: Delete when purpose fulfilled
  • Legal Requirements: Comply with mandatory retention
  • Automated Deletion: Systematic purging schedules
  • Backup Rotation: 90-day backup retention

10. Your Privacy Rights (GDPR Chapter III)

10.1 Your Rights Summary

Right Description Response Time
Access (Art. 15) Get a copy of your data 30 days
Rectification (Art. 16) Correct inaccurate data 30 days
Erasure (Art. 17) Delete your data 30 days
Restrict (Art. 18) Limit processing 30 days
Portability (Art. 20) Export your data 30 days
Object (Art. 21) Stop certain processing Immediate (marketing)
Not to be profiled (Art. 22) No automated decisions 30 days
Withdraw consent (Art. 7) Revoke given consent Immediate

10.2 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

We will respond to your request within the timeframe required by applicable law (typically within 30 days).

10.3 Identity Verification

For your security, we require:

  • Account email verification
  • Two-factor authentication
  • Government ID (for sensitive requests, redacted)
  • Security questions

10.4 Complaints

Internal Process: Contact our DPO first, escalation to management, resolution within 30 days.

Supervisory Authority

France (Lead): CNIL — www.cnil.fr
EU Directory: edpb.europa.eu/about-edpb/board/members

11. International Privacy Rights

11.1 California (CCPA/CPRA)

  • Know what personal information we collect
  • Delete your personal information
  • Opt-out of sale/sharing (we don't sell)
  • Non-discrimination
  • Correct inaccurate information
  • Limit use of sensitive information

Shine the Light: Request info about disclosures to third parties.

11.2 Canada (PIPEDA)

  • Access and challenge accuracy
  • Withdraw consent
  • File complaints with the Privacy Commissioner

11.3 Brazil (LGPD)

  • Similar rights to GDPR
  • National Data Protection Authority (ANPD) complaints

11.4 United Kingdom

  • Rights equivalent to GDPR
  • ICO complaints: ico.org.uk

11.5 Other Jurisdictions

We respect privacy rights in all jurisdictions where we operate.

12. Children's Privacy

Age Restrictions:

  • Minimum age: 18 years (general)
  • EU/EEA: 16 years with parental consent
  • Other regions: Age of majority

If we discover underage users:

  1. Immediate account suspension
  2. Parental notification attempt
  3. Data deletion within 48 hours

13. Marketing Communications

13.1 Opt-In/Opt-Out

Consent-Based (EU):

  • Explicit opt-in required
  • Granular preferences
  • Easy withdrawal

Legitimate Interest (Existing Customers):

  • Soft opt-in for similar products
  • Clear opt-out in every message

13.2 Unsubscribe Methods

14. Third-Party Links and Services

Our platform may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies before providing personal data.

Integrated Services Privacy Policies:

15. Data Processing for Businesses

When we process data on behalf of businesses:

  • Our Role: Data Processor
  • Business Role: Data Controller
  • Governance: Data Processing Agreement (DPA)
  • Compliance: GDPR Article 28 requirements

See our DPA Generator for details.

16. Changes to This Policy

Notification of Changes:

  • Email: 30 days advance notice for material changes
  • Platform: Banner notification
  • Previous versions available upon request at privacy@joincaramel.com

Review Schedule: Quarterly review, annual update minimum.

17. Accessibility

This Privacy Policy is available in:

  • Languages: English, French, German, Spanish, Italian
  • Accessibility: WCAG 2.1 AA compliant
  • Alternative formats: Available upon request

18. Jurisdiction and Dispute Resolution

18.1 EXCLUSIVE JURISDICTION - PARIS COURTS

For any disputes arising from this Privacy Policy or your use of our services:

  • ONLY the Courts of Paris, France have exclusive jurisdiction
  • Tribunal de Commerce de Paris for business matters
  • Tribunal Judiciaire de Paris for other matters
  • No other courts may hear disputes related to our services

Exception for EU Consumers: EU consumers retain their right to bring proceedings in their local courts. This is a mandatory right under EU Regulation 1215/2012 (Brussels I).

Governing Law: This Privacy Policy is governed exclusively by French law. Data protection matters are subject to GDPR as implemented in France (Loi Informatique et Libertés).

18.2 Contact Before Legal Action

Before initiating any legal proceedings:

  1. Submit a request to privacy@joincaramel.com or the Privacy Request Portal
  2. Allow 30 days for resolution
  3. Consider mediation through appropriate French authorities

By using our services, you explicitly accept that ONLY Paris courts have jurisdiction, except where EU law provides mandatory consumer protections.

Contact Us

Privacy Team

Email: privacy@joincaramel.com
Response: 48 hours acknowledgment, 30 days resolution

Data Protection Officer

Email: dpo@joincaramel.com
Status: To be appointed if required

Postal Address

React Motion Technologies SAS
Attn: Privacy Department
73 Allée Kléber
34000 Montpellier
France

Acknowledgment
By using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

Language
This Privacy Policy is available in multiple languages. In case of discrepancies, the English version shall prevail.

© 2026 React Motion Technologies SAS. All rights reserved.