Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal data.
Effective Date: January 2, 2026
Last Updated: January 2, 2026
Table of Contents
1. Introduction
Welcome to Caramel ("we," "us," "our"). We are committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how React Motion Technologies SAS (the "Company"), located at 73 Allée Kléber, 34000 Montpellier, Hérault, France, collects, uses, shares, and protects your personal information when you visit our website at https://joincaramel.com/ (the "Service").
This Privacy Policy is designed to comply with applicable data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR) - European Union
- Lei Geral de Proteção de Dados (LGPD) - Brazil
- Personal Information Protection and Electronic Documents Act (PIPEDA) - Canada
- California Consumer Privacy Act (CCPA) - United States
- Children's Online Privacy Protection Act (COPPA) - United States
- Privacy Act 1988 - Australia
- Personal Data Protection Act (PDPA) - Singapore
By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Service.
2. Data Controller Information
- Company Name:
- React Motion Technologies SAS
- Address:
- 73 Allée Kléber, 34000 Montpellier, Hérault, France
- Email:
- contact@joincaramel.com
- Data Protection Officer:
- dpo@joincaramel.com
3. Information We Collect
3.1 Personal Information You Provide
We collect information you voluntarily provide when you:
- Register for an account
- Subscribe to our newsletter
- Fill out contact forms
- Request customer support
- Participate in surveys or promotions
This may include:
- Identity Data: First name, last name, username, title
- Contact Data: Email address, telephone numbers, postal address
- Professional Data: Company name, job title, work address
- Account Data: Username, password, account preferences
- Financial Data: Payment card details, billing address (processed through secure payment processors)
- Communication Data: Your correspondence with us, feedback, survey responses
3.2 Information Automatically Collected
When you visit our Service, we automatically collect:
- Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform
- Usage Data: Information about how you use our website, products, and services
- Location Data: Geographic location based on IP address (country/city level only)
- Cookie Data: As detailed in our Cookie Policy
3.3 Information from Third Parties
We may receive information about you from:
- Analytics providers
- Technical service providers (e.g., Cloudflare)
- Social media platforms (when you interact with our social media pages)
- Business partners
- Public databases
3.4 Special Categories of Data
We do not intentionally collect special categories of personal data (revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation).
4. Legal Basis for Processing (GDPR/LGPD)
We process your personal data based on the following legal grounds:
4.1 Consent (Article 6(1)(a) GDPR / Article 7, I LGPD)
Where you have given clear consent for us to process your personal data for specific purposes.
4.2 Contract (Article 6(1)(b) GDPR / Article 7, V LGPD)
Processing necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
4.3 Legal Obligation (Article 6(1)(c) GDPR / Article 7, II LGPD)
Processing necessary to comply with legal obligations, such as tax laws, data retention requirements, or court orders.
4.4 Vital Interests (Article 6(1)(d) GDPR / Article 7, VII LGPD)
Processing necessary to protect vital interests of you or another person.
4.5 Legitimate Interests (Article 6(1)(f) GDPR / Article 7, IX LGPD)
Processing necessary for our legitimate interests or those of third parties, provided your interests and fundamental rights do not override those interests.
5. How We Use Your Information
5.1 Service Delivery
- Provide, maintain, and improve our Service
- Process transactions and send related information
- Manage your account and provide customer support
- Send service-related notices and updates
5.2 Communication
- Respond to your inquiries and requests
- Send newsletters and marketing communications (with your consent)
- Provide customer support
- Send administrative messages and legal notices
5.3 Business Operations
- Analyze usage patterns and improve user experience
- Conduct research and analytics
- Detect, prevent, and address technical issues
- Prevent fraud and enhance security
- Comply with legal obligations
5.4 Marketing (with consent where required)
- Send promotional materials about our products and services
- Personalize your experience
- Conduct market research
- Manage our loyalty programs
6. Data Sharing and Disclosure
6.1 Service Providers
We share data with third-party service providers who assist us in operating our Service:
- Hosting: Netlify (San Francisco, CA, USA)
- Security/CDN: Cloudflare (San Francisco, CA, USA)
- Customer Communication: Intercom (San Francisco, CA, USA)
- Consent Management: Adopt (Orlando, FL, USA)
All service providers are bound by data processing agreements and must protect your data in accordance with applicable laws.
6.2 Legal Requirements
We may disclose your information when required by law, including:
- To comply with legal obligations
- To respond to lawful requests from public authorities
- To protect our rights, privacy, safety, or property
- To enforce our terms and conditions
6.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity.
6.4 Consent-Based Sharing
We will share your personal data with other third parties only with your explicit consent.
6.5 Aggregated Data
We may share aggregated, anonymized data that cannot identify you personally.
7. International Data Transfers
Your information may be transferred to and processed in countries outside your country of residence, including the United States and other countries that may have different data protection laws.
7.1 Safeguards
We implement appropriate safeguards for international transfers:
- EU-US Data Privacy Framework: For transfers to US companies certified under the DPF
- Standard Contractual Clauses (SCCs): EU Commission-approved contractual clauses
- Binding Corporate Rules (BCRs): Where applicable
- Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
7.2 Your Rights Regarding Transfers
You have the right to:
- Be informed about international transfers
- Request information about safeguards in place
- Object to transfers in certain circumstances
8. Data Retention
8.1 Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Account Data: Duration of account activity plus 7 years
- Transaction Data: 10 years (tax and accounting requirements)
- Marketing Data: Until consent is withdrawn or 3 years of inactivity
- Cookie Data: As specified in our Cookie Policy
- Legal Claims: Data may be retained longer if necessary for legal proceedings
8.2 Deletion
When retention periods expire, we will securely delete or anonymize your personal data, unless we are legally required to retain it longer.
9. Your Privacy Rights
Depending on your location and applicable laws, you have the following rights:
9.1 Universal Rights
- Access: Request access to your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request restriction of processing
- Data Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent at any time
- Complaint: Lodge a complaint with supervisory authorities
9.2 CCPA Rights (California Residents)
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to non-discrimination for exercising privacy rights
- Right to correct inaccurate personal information
9.3 LGPD Rights (Brazilian Residents)
- Right to confirmation of processing
- Right to anonymization, blocking, or deletion of unnecessary data
- Right to information about sharing with third parties
- Right to revoke consent
- Right to review automated decisions
9.4 PIPEDA Rights (Canadian Residents)
- Right to know why personal information is collected
- Right to expect reasonable security safeguards
- Right to access personal information
- Right to challenge compliance
9.5 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@joincaramel.com
- Data Subject Request Form: Privacy Request Portal
- Mail: React Motion Technologies SAS, Attn: Privacy Rights, 73 Allée Kléber, 34000 Montpellier, France
We will respond to your request within the timeframe required by applicable law (typically within 30 days).
10. Data Security
10.1 Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: SSL/TLS encryption for data in transit
- Access Controls: Role-based access controls and authentication
- Regular Audits: Security assessments and vulnerability testing
- Employee Training: Regular privacy and security training
- Incident Response: Established breach notification procedures
- Data Minimization: We only collect data necessary for specified purposes
10.2 Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify relevant supervisory authorities within 72 hours (GDPR requirement)
- Notify affected individuals without undue delay
- Document the breach and actions taken
10.3 Your Responsibilities
While we implement robust security measures, no system is 100% secure. Please:
- Keep your account credentials confidential
- Use strong passwords
- Notify us immediately of any unauthorized access
11. Children's Privacy
11.1 Age Restrictions
Our Service is not directed to individuals under the age of 16 (or applicable age of consent in your jurisdiction). We do not knowingly collect personal data from children.
11.2 Parental Rights
If you believe we have collected information from a child, please contact us immediately at privacy@joincaramel.com. We will promptly delete such information.
13. Third-Party Links and Services
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
14. Marketing Communications
14.1 Opt-In/Opt-Out
- We will only send marketing communications with your explicit consent
- You can opt-out at any time by:
- Clicking "unsubscribe" in any marketing email
14.2 Do Not Track
We respect Do Not Track browser settings where technically feasible.
15. Automated Decision-Making
15.1 Profiling
We may use automated profiling for:
- Personalization of content
- Marketing segmentation
- Fraud prevention
15.2 Your Rights
You have the right to:
- Request human intervention
- Express your point of view
- Contest automated decisions
- Opt-out of profiling for marketing purposes
16. Updates to This Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our practices
- New legal requirements
- Technological developments
16.1 Notification of Changes
We will notify you of material changes by:
- Email notification
- Prominent notice on our website
- Requiring renewed consent where appropriate
16.2 Version History
- Current Version: 2.0
- Last Updated: January 2, 2026
- Previous versions available upon request
17. Contact Information
17.1 Data Protection Officer
For privacy-related inquiries, contact our Data Protection Officer:
- Email: dpo@joincaramel.com
- Mail: DPO, React Motion Technologies SAS, 73 Allée Kléber, 34000 Montpellier, France
17.2 General Inquiries
- Company: React Motion Technologies SAS
- Email: contact@joincaramel.com
- Address: 73 Allée Kléber, 34000 Montpellier, Hérault, France
17.3 Supervisory Authorities
You have the right to lodge a complaint with your local data protection authority:
European Union:
France: CNIL (Commission Nationale de l'Informatique et des Libertés)
Website: https://www.cnil.fr
Brazil:
ANPD (Autoridade Nacional de Proteção de Dados)
Website: https://www.gov.br/anpd
Canada:
Office of the Privacy Commissioner of Canada
Website: https://www.priv.gc.ca
United States (California):
California Privacy Protection Agency
Website: https://cppa.ca.gov
18. Jurisdiction-Specific Provisions
18.1 European Union Residents
- Legal basis required for all processing
- Right to data portability
- Right to restrict processing
- 72-hour breach notification to authorities
18.2 Brazilian Residents (LGPD)
- Right to anonymization of unnecessary data
- Right to information about public and private entities with which data is shared
- National Data Protection Authority: ANPD
18.3 California Residents (CCPA/CPRA)
- Right to opt-out of sale of personal information
- Right to limit use of sensitive personal information
- Right to correct inaccurate information
- No discrimination for exercising rights
18.4 Canadian Residents (PIPEDA)
- Consent required for collection, use, and disclosure
- Right to access and challenge accuracy
- Reasonable purposes limitation
Acknowledgment
By using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Language
This Privacy Policy is available in multiple languages. In case of discrepancies, the English version shall prevail.
© 2024 React Motion Technologies SAS. All rights reserved.