01Data Controller
Beyonds World OÜ
Registration number: 17507571
Registered address: Vesivärava tn 50-301, 10152 Tallinn, Estonia
Office: Tornimäe 5, 2nd floor, 10145 Tallinn, Estonia
Email: privacy@beyonds.world
We are established in Estonia, so the GDPR applies to everything we do with personal data — including when you write to us from outside the European Union.
02What data we collect
When you use a diagnostic tool
Beyonds publishes six free tools: the Collapse Risk Check, the Funding Navigator, and four audits inside the Deep Guides — Signal vs Pull, Real Moat, Premature Marketing and The Feature Trap.
How a tool starts differs. The Collapse Risk Check and the Funding Navigator begin with a short form. The four audits inside the Deep Guides ask for nothing up front: you can work through one in full and, at the end, decide whether to have the result emailed to you. If you decide not to, we receive nothing at all.
Where you do give us something, we receive:
- Your name and email address. A phone number and a LinkedIn address are optional — you do not have to provide them, and the tool works without them.
- Your answers to the questions, including free-text descriptions of your project, your product, your customers and the stage you are at.
- The result the tool calculates from those answers.
- Which language version you used and which country the request came from. We do not store your IP address with the submission.
- Whether you ticked the optional box asking us to keep your answers for tailored messages, together with the time and the wording you were shown, and when you confirmed it by email — the box takes effect only once you do.
The free-text fields are yours to fill as you wish. Please do not enter anything you would not want us to read — for example other people's personal data, or information covered by a confidentiality agreement.
Your unfinished answers are also kept in your own browser so you do not lose your progress if you close the page. That copy stays on your device, and clearing your browser data removes it.
When you ask to be told when a tool is ready
Some tools are announced before they are released. If you leave your email address to be told when one opens, we receive that address, the language version you used and the page you signed up from. We send you one message when the tool is ready and nothing else, and then delete the address.
When you apply to Beyonds Incubator
The application form runs on Tally. We receive the name, contact details and project information you enter there.
When you apply for a Strategic Reframe Session
We receive the name, contact details and the description of your project, your current stage and the question you want to work on.
If the session goes ahead, follow-up emails and materials are written and sent by hand from our own mailbox. Where an applicant prefers Russian, that correspondence may take place in Telegram instead. There is no automated sequence, no bot and no mailing platform behind it.
The session is not recorded.
When you contact us
By email, WhatsApp or Telegram: the content of your message and the contact details you write from. WhatsApp and Telegram run on their own infrastructure under their own privacy policies.
When you read the website
- Cloudflare Web Analytics counts page views, visits, pages, referrers and country. It sets no cookies, stores no identifier on your device, does not fingerprint your browser and does not follow you across other sites. We use it only to measure how this site is read: the figures are aggregated, they are ours alone, they are never combined with any other processing and never shared for anyone's advertising. On that basis — audience measurement confined to our own site — it runs without asking you first. If you would rather it did not run at all, switching Analytics off in Privacy settings stops it as well.
- Microsoft Clarity records how pages are used — scrolling, clicks, and a replay of the session. It does not load at all until you turn on Analytics. Not in a reduced mode, not without cookies: the script is simply not requested. Microsoft is not our supplier here: its own terms say that Microsoft and we are independent controllers, so it decides for itself what it does with what Clarity collects. Microsoft's terms allow it to use that data for its own purposes as well, including Microsoft Advertising. We pass your Advertising choice on to it: unless you have also turned on Advertising, Clarity is told not to store advertising-related data. If you would rather Microsoft received nothing at all, leave Analytics off.
- The Meta Pixel loads only after you turn on Advertising, and is not
set otherwise. Once it loads, Meta receives your IP address, browser and
device data, the page address, the fact of the visit and the
_fbpadvertising cookie, so that Beyonds ads can be shown to you and their results measured.
Analytics and Advertising are independent. You may turn on one and leave the other off, and you can change either at any time through Privacy settings in the footer of every page. Withdrawing does not affect the lawfulness of what was processed beforehand.
Because neither Clarity nor the Meta Pixel can be unloaded from a page that is already open, turning one off reloads the page so that it genuinely stops.
On the six diagnostic tools, session replay runs in strict masking mode: the result screen shows an analysis built from what you wrote about your own project, and strict mode keeps that text out of the recording.
Audio in the Deep Guides
The spoken versions of the guides are served from Cloudflare R2. Playing one means your browser requests the file from Cloudflare, which sees your IP address and browser data as part of delivering it.
03Why we process data
| Purpose | Legal basis |
|---|---|
| Sending you the result of a tool you completed | Steps at your request, Art. 6(1)(b) |
| Keeping your submission for a short period for support, troubleshooting and defence against claims | Legitimate interests, Art. 6(1)(f) |
| Keeping your answers and writing to you with tailored messages | Consent, Art. 6(1)(a) |
| Reviewing applications to the Incubator and to the Strategic Reframe Session | Steps at your request prior to a contract, Art. 6(1)(b) |
| Correspondence about a session, by email or Telegram | Steps at your request, Art. 6(1)(b) |
| Aggregated traffic measurement that stores nothing on your device | Legitimate interests, Art. 6(1)(f) |
| Telling you once when a tool you asked about is released | Consent, Art. 6(1)(a) |
| Session replay and behavioural analytics (Microsoft Clarity) | Consent, Art. 6(1)(a) |
| Advertising measurement and retargeting (Meta Pixel) | Consent, Art. 6(1)(a) |
| Keeping a record of the consents given, with timestamps and the wording shown | Legal obligation, Art. 6(1)(c), read with Art. 5(2) and 7(1) |
| Keeping the website available, and protecting it from abuse | Legitimate interests, Art. 6(1)(f) |
Where we rely on legitimate interests we have weighed them against your rights, and you may object at any time — see section 06.
04Who we share data with
Each service receives only what it needs for its own function. We do not sell personal data, and we do not share it for anyone else's marketing.
| Service | Function | Data location |
|---|---|---|
| Netlify | Website hosting and the function that receives tool submissions | US * |
| Supabase | Database of tool submissions | EU |
| Resend | Sending you the result of a tool by email | US * |
| HubSpot | Contact details, the tools you used and your results — only if you consented to tailored messages; deleted when you withdraw | EU hosting; support access from the US * |
| Tally | Application forms | EU |
| Cloudflare | Audio delivery for the Deep Guides, and aggregated traffic measurement | US * |
| Microsoft (Clarity) | Session replay — only after Analytics consent | US *, **** |
| Meta Platforms Ireland Ltd | Meta Pixel — only after Advertising consent | EU / US *, ** |
| Telegram FZ-LLC | Correspondence with applicants who prefer Russian | UAE / global *** |
| Google (Workspace) | Our mailbox — correspondence about applications and sessions | US * |
* Transfers to the United States are made under the EU–US Data Privacy Framework where the recipient is certified, and otherwise under Standard Contractual Clauses, with supplementary measures where required.
** For data collected through the Meta Pixel and passed to Meta, we and Meta Platforms Ireland Ltd act as joint controllers within the meaning of Art. 26 GDPR. The allocation of responsibilities is set out in Meta's Controller Addendum. Meta is independently responsible for any further processing on its side under its own Privacy Policy.
*** Telegram FZ-LLC acts as an independent controller on its own distributed infrastructure, under its own Privacy Policy.
**** Microsoft is an independent controller for Clarity, not our processor. Its own terms state that Microsoft and the customer are independent controllers and that neither party is a processor, so there is no processing agreement between us for this, and Microsoft answers for its own use of the data under its own Privacy Statement.
A full record of our processing activities and international transfers is maintained separately under Art. 30 GDPR and is available to supervisory authorities on request.
05Data retention periods
| Data | Retained for |
|---|---|
| Tool submission, where you did not ask us to keep your answers, or ticked the box but did not confirm it by email | 90 days, then deleted automatically |
| Address left to be told when a tool is ready | Until that one message is sent, and no longer than 12 months |
| Tool submission, where you did ask us to keep your answers and confirmed it by email | Until you withdraw, or 24 months after you last confirmed — whichever comes first. Then deleted straight away |
| Record of the consent you gave (the wording shown, the time, the version) | Stored with the submission itself, and deleted together with it |
| Record that a withdrawal or erasure was carried out — a pseudonymous identifier derived from your address with a secret key, the date and the route; the address itself is not kept once the request is complete | 36 months |
| Incubator and Strategic Reframe Session applications | 24 months from submission |
| Correspondence by email or Telegram, and the notice our team receives once you have confirmed your consent (your contact details and the short result — not your answers) | 24 months from the last message |
| Unfinished answers held in your own browser | Until you clear your browser data |
| Microsoft Clarity recordings | Per Clarity's own retention, currently 30 days |
Meta _fbp advertising cookie |
Up to 90 days in your browser; removed when you withdraw Advertising consent or clear site data |
| Aggregated traffic figures | Kept as aggregates only; they identify nobody |
Deletion of tool submissions is enforced by the database itself and a daily automated sweep, not by someone remembering to do it. After the period expires, data is deleted or anonymised. Erasure requests are completed within 30 days.
06Your rights
Under the GDPR you have the right to:
- access your data and receive a copy;
- rectify data that is inaccurate or incomplete;
- erasure — have your data deleted;
- restrict processing while a dispute is resolved;
- data portability — receive your data in a machine-readable form;
- object to processing based on legitimate interests, including profiling;
- withdraw consent at any time, as easily as you gave it, without affecting the lawfulness of processing before withdrawal.
You are never required to consent to tailored messages in order to receive the result of a tool you completed. The result is sent either way.
07How to exercise your rights
Write to privacy@beyonds.world. We reply within 30 days.
You can also act directly:
- Analytics and Advertising — the Privacy settings link in the footer of every page, at any time.
- Tailored messages — the withdrawal link at the end of every message we send you, or one line to privacy@beyonds.world. We then stop writing, delete the answers you asked us to keep and remove you from our CRM. Anything you sent without that box keeps its own 90-day period.
- Erasure — one line to privacy@beyonds.world naming the email address you used. We remove the submissions held against it.
08Right to lodge a complaint
If you believe we have handled your data unlawfully you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn — aki.ee — or to the supervisory authority of the EU country where you live or work.
09Data security
Submissions travel over HTTPS and are stored in a database that is not reachable from the browser: the keys that can read it exist only on the server. Access is limited to the people who need it. The site sets strict transport security and content-type headers, and loads no third-party script other than the analytics named above — the code that runs the pages is served from our own domain.
No system is perfectly secure. If a personal data breach occurs, we notify the supervisory authority within 72 hours unless the breach is unlikely to result in a risk to your rights (Art. 33 GDPR). If it is likely to result in a high risk to your rights, we also tell you directly, without undue delay (Art. 34 GDPR).
10Age restrictions
Our services are intended for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has sent us personal data, write to privacy@beyonds.world and we will delete it.
11Changes to this Policy
We update this policy when what we actually do changes — not the other way round. The current version is always at this address, with its version number and date at the top. Material changes affecting data already collected will be notified to you directly where we hold a contact address for you.