Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal data.
Effective Date: July 31, 2026
Last Updated: July 31, 2026
Version: 2.1
⚖️ LEGAL JURISDICTION
ONLY Paris Courts, France have exclusive jurisdiction over disputes. EU consumers may alternatively use their local courts. See Section 18 for details.
Table of Contents
1. Introduction
Welcome to Caramel ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws worldwide. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services.
Caramel is a business-to-business platform. Businesses use it to build and publish forms, collect and manage their own customer records, and run marketing campaigns across email, SMS, messaging apps, and push notifications, together with the integrations and premium advisory services that support that work.
Our Commitment to EU Data Residency: We prioritize data sovereignty by processing and storing your data primarily within the European Union using EU-based infrastructure providers.
This policy applies to:
- Our website and web applications
- Our mobile applications (iOS and Android)
- Our API services
- All related services we provide
2. Data Controller Information
- Company Name:
- React Motion Technologies SAS (SAS)
- SIRET / SIREN / VAT:
- 94861223900012 / 948 612 239 / FR95948612239
- Address:
- 73 Allée Kléber, 34000 Montpellier, France
- Contact:
- privacy@joincaramel.com
- Data Protection Officer (DPO):
- To be appointed if required. Reach the privacy team at dpo@joincaramel.com
- EU / UK Representative:
- Not required (established in the EU). A UK representative will be appointed if UK operations commence.
For GDPR purposes, we act as:
- Data Controller for platform users and business accounts
- Data Processor for the end-customer data our business customers upload, collect, or send messages to through the platform
3. Information We Collect
3.1 Information You Provide Directly
Account Information:
- Full name and title
- Email address (verified)
- Phone number (for 2FA and notifications)
- Business name and registration details (for business accounts)
- VAT/Tax identification numbers
- Password (bcrypt hashed, never stored in plain text)
Payment Information:
- Payment card details (tokenized through Stripe EU servers)
- IBAN/Bank account details (for SEPA payments)
- Billing address
- Transaction history
- Invoice preferences
End-Customer Data (processed on behalf of businesses):
Where a business uses Caramel to reach its own customers, we process the data that business supplies or collects. We act as processor for all of it:
- Contact details (name, email address, phone number)
- Responses submitted through forms the business publishes
- Marketing consent status and communication preferences
- Message delivery, open, click, and unsubscribe records
- Segment membership and campaign history
- Language and locale, where provided
3.2 Information Collected Automatically
Technical Data:
- IP address (anonymized after 7 days)
- Device type and identifiers (hashed)
- Browser type and version
- Operating system
- Time zone and locale settings
- Language preferences
Usage Data:
- Pages visited and features used
- Click patterns and navigation paths
- Search queries within the platform
- Performance metrics
- Error logs (PII scrubbed)
- Session duration
Cookie Data: Essential cookies for functionality, and analytics/marketing cookies where you have given consent — see our Cookie Policy.
3.3 Information from Third Parties
- Payment verification from Stripe (EU servers)
- Message delivery and engagement events from our sending providers
- Analytics data from PostHog (EU cloud)
3.4 Special Categories of Data
We do NOT collect special categories of personal data (health, biometric, racial/ethnic origin, political opinions, religious beliefs, etc.) unless:
- Required for legal compliance
- Explicitly provided with separate consent
- Necessary for employment law compliance (business accounts)
4. Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds:
4.1 Contract Performance (Art. 6(1)(b))
- Account creation and management
- Delivering the platform features a business has subscribed to, including form publishing, customer records, and campaign sending
- Payment processing and invoicing
- Customer support services
- API access provision
4.2 Legitimate Interests (Art. 6(1)(f))
We've conducted Legitimate Interests Assessments (LIA) for:
- Fraud prevention and platform security
- Service improvement and optimization
- Direct marketing to existing customers (with opt-out)
- Business analytics and reporting
- Network and information security
Balancing Test Results: Our legitimate interests do not override your fundamental rights, and you can object at any time.
4.3 Legal Obligations (Art. 6(1)(c))
- Tax reporting and VAT compliance
- Court orders and legal proceedings
- Consumer protection law compliance
- Data breach notifications
4.4 Consent (Art. 6(1)(a))
- Marketing communications to prospects
- Non-essential cookies and tracking
- Session recordings for UX improvement
- Push notifications
- Location-based services
4.5 Vital Interests (Art. 6(1)(d))
Emergency situations only (extremely rare).
5. How We Use Your Information
5.1 Primary Purposes
| Purpose | Legal Basis | Data Categories |
|---|---|---|
| Account Management | Contract | Identity, Contact |
| Payment Processing | Contract | Financial, Transaction |
| Form Publishing & Response Capture | Contract | End-customer, Communication |
| Campaign Delivery | Contract | End-customer, Communication, Consent |
| Customer Support | Contract/Legitimate Interest | All relevant |
| Security & Fraud | Legitimate Interest | Technical, Behavioral |
| Marketing | Consent/Legitimate Interest | Contact, Preferences |
| Legal Compliance | Legal Obligation | All required |
| Analytics | Legitimate Interest | Usage, Technical |
5.2 Automated Decision-Making and Profiling
We use limited automated decision-making for:
- Fraud Detection: Transaction risk scoring
- Marketing Segmentation: Customer categorization
- Service Personalization: Feature recommendations
Your Rights:
- Request human review of automated decisions
- Object to profiling for marketing
- Opt-out of automated decision-making
- Request explanation of logic involved
6. Data Sharing and Disclosure
6.1 EU-Based Service Providers (Data Processors)
All our primary processors maintain EU data residency:
| Processor | Purpose | Location | DPA Status |
|---|---|---|---|
| Hetzner | Infrastructure hosting | Germany (EU) | ✅ Signed |
| Supabase | Database & Auth | EU Region (Frankfurt) | ✅ Signed |
| Stripe | Payment processing | EU Data Center | ✅ Signed |
| PostHog | Analytics | EU Cloud (Frankfurt) | ✅ Signed |
| Sentry | Error monitoring | EU Region | ✅ Signed |
6.2 Communication Services
| Service | Purpose | Data Location | Safeguards |
|---|---|---|---|
| AWS SES | Transactional email | EU-WEST-1 (Ireland) | SCCs + Encryption |
| AWS SNS | SMS delivery | EU-WEST-1 (Ireland) | SCCs + Encryption |
| Internal System | Marketing automation | EU (Our servers) | Internal control |
6.3 Recipients Categories
- Business Partners: Only their own customer data
- Professional Advisors: Lawyers, accountants (under NDA)
- Regulatory Authorities: When legally required
- Law Enforcement: With valid legal basis only
- Potential Acquirers: During M&A (under NDA)
6.4 We Never Share Data With
- Data brokers or advertisers
- Third parties for their own marketing
- Anyone without legal basis
- Non-EU countries without safeguards
7. International Data Transfers
7.1 EU Data Residency First
Primary Processing: All data is processed and stored within the EU:
- Database: Germany (Hetzner)
- Application: EU regions
- Analytics: EU servers
- Backups: EU locations
7.2 Limited Third-Country Transfers
When transfers outside the EU are necessary:
| Country | Processor | Mechanism | Additional Safeguards |
|---|---|---|---|
| USA | Stripe (payments only) | SCCs + DPF | Encryption, Minimization |
7.3 Transfer Safeguards
- Standard Contractual Clauses (SCCs): Module 2 (Controller to Processor)
- Supplementary Measures: End-to-end encryption, pseudonymization, data minimization, access restrictions
- Transfer Impact Assessments (TIAs): Completed for each transfer
- Your Rights: Request copies of safeguards documentation
8. Data Security
8.1 Technical Measures (ISO 27001 Aligned)
Encryption:
- At rest: AES-256-GCM
- In transit: TLS 1.3 (TLS 1.2 minimum)
- Database: Transparent Data Encryption (TDE)
- Backups: Encrypted with separate keys
Access Control:
- Multi-factor authentication (MFA) mandatory
- Role-Based Access Control (RBAC)
- Principle of least privilege
- Just-in-time access for elevated privileges
- API rate limiting and authentication
Infrastructure Security:
- Web Application Firewall (WAF)
- DDoS protection (Cloudflare EU)
- Intrusion Detection System (IDS)
- Container security scanning
- Vulnerability management program
Monitoring:
- 24/7 security monitoring
- Anomaly detection
- Security Information and Event Management (SIEM)
- Incident response team
8.2 Organizational Measures
Policies & Procedures:
- Information Security Management System (ISMS)
- Data Protection Impact Assessments (DPIAs)
- Regular security audits (quarterly)
- Penetration testing (annually)
- Employee security training (mandatory)
Compliance:
- ISO 27001 certification (in progress)
- SOC 2 Type II (planned 2026)
- PCI DSS compliance (via Stripe)
- GDPR compliance program
8.3 Breach Response
Detection & Response Timeline:
- 0-1 hours: Incident detection and containment
- 1-24 hours: Impact assessment and mitigation
- 24-72 hours: Regulatory notification (if required)
- 72+ hours: User notification (if high risk)
Breach Register: Maintained per Article 33(5) GDPR.
9. Data Retention
9.1 Retention Schedule
| Data Category | Active Retention | Post-Deletion | Legal Basis |
|---|---|---|---|
| Account Data | Duration of account | 30 days | Recovery period |
| Transaction Data | Active account | 10 years | Tax law (France) |
| End-Customer Records | Duration of business account | 30 days | Controller instruction |
| Form Responses | Duration of business account | 30 days | Controller instruction |
| Campaign & Delivery Logs | 24 months | Immediate | Deliverability, abuse prevention |
| Payment Data | Active account | 7 years | Accounting law |
| Marketing Consent | Until withdrawn | 3 years proof | Evidence |
| Analytics | 24 months | Immediate anonymization | Legitimate interest |
| Security Logs | 1 year | 5 years (incidents only) | Security |
| Support Tickets | 2 years | 3 years | Service improvement |
| Cookies | Per Cookie Policy | ||
9.2 Retention Principles
- Data Minimization: Only retain what's necessary
- Purpose Limitation: Delete when purpose fulfilled
- Legal Requirements: Comply with mandatory retention
- Automated Deletion: Systematic purging schedules
- Backup Rotation: 90-day backup retention
10. Your Privacy Rights (GDPR Chapter III)
10.1 Your Rights Summary
| Right | Description | Response Time |
|---|---|---|
| Access (Art. 15) | Get a copy of your data | 30 days |
| Rectification (Art. 16) | Correct inaccurate data | 30 days |
| Erasure (Art. 17) | Delete your data | 30 days |
| Restrict (Art. 18) | Limit processing | 30 days |
| Portability (Art. 20) | Export your data | 30 days |
| Object (Art. 21) | Stop certain processing | Immediate (marketing) |
| Not to be profiled (Art. 22) | No automated decisions | 30 days |
| Withdraw consent (Art. 7) | Revoke given consent | Immediate |
10.2 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@joincaramel.com
- Data Subject Request Form: Privacy Request Portal
- Cookie / consent preferences: Privacy Settings
- Mail: React Motion Technologies SAS, Attn: Privacy Rights, 73 Allée Kléber, 34000 Montpellier, France
We will respond to your request within the timeframe required by applicable law (typically within 30 days).
10.3 Identity Verification
For your security, we require:
- Account email verification
- Two-factor authentication
- Government ID (for sensitive requests, redacted)
- Security questions
10.4 Complaints
Internal Process: Contact our DPO first, escalation to management, resolution within 30 days.
Supervisory Authority
France (Lead): CNIL — www.cnil.fr
EU Directory: edpb.europa.eu/about-edpb/board/members
11. International Privacy Rights
11.1 California (CCPA/CPRA)
- Know what personal information we collect
- Delete your personal information
- Opt-out of sale/sharing (we don't sell)
- Non-discrimination
- Correct inaccurate information
- Limit use of sensitive information
Shine the Light: Request info about disclosures to third parties.
11.2 Canada (PIPEDA)
- Access and challenge accuracy
- Withdraw consent
- File complaints with the Privacy Commissioner
11.3 Brazil (LGPD)
- Similar rights to GDPR
- National Data Protection Authority (ANPD) complaints
11.4 United Kingdom
- Rights equivalent to GDPR
- ICO complaints: ico.org.uk
11.5 Other Jurisdictions
We respect privacy rights in all jurisdictions where we operate.
12. Children's Privacy
Age Restrictions:
- Minimum age: 18 years (general)
- EU/EEA: 16 years with parental consent
- Other regions: Age of majority
If we discover underage users:
- Immediate account suspension
- Parental notification attempt
- Data deletion within 48 hours
13. Marketing Communications
13.1 Opt-In/Opt-Out
Consent-Based (EU):
- Explicit opt-in required
- Granular preferences
- Easy withdrawal
Legitimate Interest (Existing Customers):
- Soft opt-in for similar products
- Clear opt-out in every message
13.2 Unsubscribe Methods
- One-click unsubscribe in emails
- SMS: Reply STOP
- Privacy portal: Granular controls
- Email: privacy@joincaramel.com
14. Third-Party Links and Services
Our platform may contain links to third-party websites. We are not responsible for their privacy practices. Please review their policies before providing personal data.
Integrated Services Privacy Policies:
15. Data Processing for Businesses
When we process data on behalf of businesses:
- Our Role: Data Processor
- Business Role: Data Controller
- Governance: Data Processing Agreement (DPA)
- Compliance: GDPR Article 28 requirements
See our DPA Generator for details.
16. Changes to This Policy
Notification of Changes:
- Email: 30 days advance notice for material changes
- Platform: Banner notification
- Previous versions available upon request at privacy@joincaramel.com
Review Schedule: Quarterly review, annual update minimum.
17. Accessibility
This Privacy Policy is available in:
- Languages: English, French, German, Spanish, Italian
- Accessibility: WCAG 2.1 AA compliant
- Alternative formats: Available upon request
18. Jurisdiction and Dispute Resolution
18.1 EXCLUSIVE JURISDICTION - PARIS COURTS
For any disputes arising from this Privacy Policy or your use of our services:
- ONLY the Courts of Paris, France have exclusive jurisdiction
- Tribunal de Commerce de Paris for business matters
- Tribunal Judiciaire de Paris for other matters
- No other courts may hear disputes related to our services
Exception for EU Consumers: EU consumers retain their right to bring proceedings in their local courts. This is a mandatory right under EU Regulation 1215/2012 (Brussels I).
Governing Law: This Privacy Policy is governed exclusively by French law. Data protection matters are subject to GDPR as implemented in France (Loi Informatique et Libertés).
18.2 Contact Before Legal Action
Before initiating any legal proceedings:
- Submit a request to privacy@joincaramel.com or the Privacy Request Portal
- Allow 30 days for resolution
- Consider mediation through appropriate French authorities
By using our services, you explicitly accept that ONLY Paris courts have jurisdiction, except where EU law provides mandatory consumer protections.
Contact Us
Privacy Team
Email: privacy@joincaramel.com
Response: 48 hours acknowledgment, 30 days resolution
Data Protection Officer
Email: dpo@joincaramel.com
Status: To be appointed if required
Postal Address
React Motion Technologies SAS
Attn: Privacy Department
73 Allée Kléber
34000 Montpellier
France
Acknowledgment
By using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Language
This Privacy Policy is available in multiple languages. In case of discrepancies, the English version shall prevail.
© 2026 React Motion Technologies SAS. All rights reserved.