Last updated — 2 September 2026
Privacy policy
How BEBRANDED collects, uses and protects personal data on this website and in the Dashly application, under the General Data Protection Regulation (EU) 2016/679 and the French Data Protection Act.
01Who is responsible
BEBRANDED, 34 avenue Chanzy, 93250 Villemomble, France, registered under SIREN 984 530 212, publishes and operates Dashly. For any question about this policy or to exercise your rights, write to legal@usedashly.com.
We have not appointed a Data Protection Officer, which our size and activity do not require. Requests are handled by the publication director.
02Two different roles
This distinction governs everything below. Dashly is sold to agencies, and an agency uses it to hold information about its own clients.
- We are the controller for the data of the agencies that subscribe: their members' accounts, billing, support exchanges, and the technical logs of the site and the application. This policy describes that processing.
- We are a processor for everything an agency puts into Dashly about its clients and prospects — contacts, deals, tickets, time entries, documents, messages. The agency decides why and how that data is used; we only process it on the agency's instructions, to run the service. If you are the client of an agency that uses Dashly and want to exercise your rights, contact that agency: they hold the answers, and we will assist them.
03What we collect
| Context | Data | Origin |
|---|---|---|
| Visiting this website | Technical connection logs only: IP address, date and time, page requested, user agent. No cookies, no analytics, no profiling. | Automatic |
| Creating an account | First and last name, professional email address, password (stored hashed, never in clear text), agency name, language. | You |
| Using the application | Your activity within your agency's workspace: what you create and modify, timestamps, and technical logs needed for security and diagnosis. | Automatic |
| Subscribing | Billing details, plan, number of seats, invoices. Card details are entered on our payment provider's pages and never reach our servers. | You, and our payment provider |
| Contacting us | Your email address and the content of your message. | You |
04Why, and on what legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Providing the service, managing accounts and access | Performance of the contract | Duration of the contract, then 3 years |
| Billing, collection, accounting | Legal obligation | 10 years for accounting records |
| Security, fraud prevention, abuse detection, diagnosing incidents | Legitimate interest in a service that stays available and safe | 12 months for connection logs, 90 days for error reports |
| Answering your messages and providing support | Performance of the contract, or legitimate interest before a contract exists | 3 years from the last contact |
| Sending service emails (invitations, alerts, password resets) | Performance of the contract | Duration of the contract |
| Sending commercial emails about our product | Legitimate interest towards professionals, with an unsubscribe link in every message | 3 years from the last contact, or until you unsubscribe |
We do not sell personal data, we do not rent mailing lists, and we take no automated decision producing legal effects concerning you.
05Who else processes the data
Running the service requires a small set of providers. Each is bound by a data processing agreement, processes data only on our instructions, and appears here so you can see exactly who is involved.
| Provider | Role | Where the data sits |
|---|---|---|
| Vercel Inc. (United States) | Hosting the site and the application, connection logs | Stockholm, Sweden (EU) |
| Supabase Inc. (United States) | Database and file storage | Stockholm, Sweden (EU) |
| Resend (United States) | Sending transactional email | United States |
| Stripe Payments Europe Ltd (Ireland) | Subscription payments and invoicing | European Union, with transfers to the United States |
| Functional Software Inc. — Sentry (United States) | Error monitoring | United States |
| Cloudflare Inc. (United States) | DNS, email routing, website crawling for the SEO tool | Global network |
Some services are only involved if an agency chooses to connect them — Google, Slack, WhatsApp, Webflow, Ahrefs, Fathom and the other integrations offered in Dashly. Nothing is sent to them unless that connection is made, and it can be revoked at any time from the application.
06Data obtained from Google APIs
An agency can connect a Google account to Dashly. That connection is optional, it is granted account by account, and each feature asks separately for the access it needs — connecting Gmail does not open Drive, and refusing one does not disable the others. Every authorisation below is read-only but one: sending an email. That one is never automatic — a message leaves your address only when someone presses send in Dashly. Nothing else in your Google account is created, modified or deleted.
| Access requested | What it is used for |
|---|---|
| Gmail, read-only | Reading the messages exchanged with a contact, so that the thread appears on the lead, the deal or the client it belongs to — and so that a deal nobody has answered in weeks can be seen for what it is. |
| Gmail, sending | Sending a reply or a follow-up from your own address, when you write it in Dashly. Nothing is ever sent without that action. |
| Google Drive, read-only | Browsing and opening the folders and documents an agency attaches to a client or a project. |
| Search Console, read-only | The weekly snapshot of impressions, clicks and positions shown in the SEO reports. |
| Google Analytics 4, read-only | The weekly snapshot of audience metrics shown on the dashboards and in the client reports. |
| Google Ads, read-only | The weekly snapshot of advertising spend, shown next to the other acquisition channels. |
| Google Calendar, read-only | Displaying the day's meetings on the dashboard and in the activity view. |
| Email address and basic profile | Identifying which Google account a connection belongs to, and signing you in if you choose Google as your sign-in method. |
Dashly's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely:
- The data is used only to provide or improve the features described above — the features you can see in the application.
- It is never sold, and never transferred to anyone other than the providers listed in the previous section, and only so that the service can run — unless you ask us to, or the law compels us.
- It is never used for advertising, and never to build advertising profiles.
- No human reads it, except with your explicit consent, for security purposes such as investigating an abuse, to comply with the law, or once aggregated and anonymised for internal operations.
- It is never used to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models.
A connection is revocable at any time from the integrations settings in Dashly, and from your Google account at myaccount.google.com/permissions. Revoking deletes the stored access tokens and stops any further collection.
07How long we keep data
Two regimes, and the distinction follows from the two roles described above. What we collect as a controller expires on the schedule below, enforced automatically every night. What an agency stores about its own clients is on no countdown of ours: that data is theirs, we process it on their instructions, and it goes when they delete it or delete their agency.
| Data | Period | Why |
|---|---|---|
| Action log (who changed what) | 2 years | It is what answers a dispute, and disputes surface late. Beyond that it is neither useful to the agency nor proportionate. |
| Sent-email log | 1 year | Long enough to prove an invitation or a reset link was sent, across a full billing cycle. |
| Read notifications | 6 months | An unread notification is work still waiting for someone: it does not expire. |
| Automation run logs | 3 months | They exist to debug a rule that misfired, which is noticed in days. |
| Expired sessions and verification tokens | 30 days past expiry | An expired session grants no access, but the row still names a person and an IP address. |
| Recognised devices | 1 year since last use | A device unseen for a year is not a known device any more. |
| Account and billing | Term of the contract, then 3 years | Accounting obligations and the commercial limitation period. |
Two deliberate exceptions. SEO audience measurements kept for an agency are retained without limit: their whole value is the year-over-year comparison, and a rolling window would destroy the only data that gets more valuable with age. And an unsubscribe request is kept indefinitely — letting one expire would mean writing again to someone who asked us not to.
08Transfers outside the European Union
The application and its database run in the European Union. Some of the providers listed above are established in the United States, which means personal data may be transferred there.
Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU–US Data Privacy Framework, together with additional technical measures such as encryption in transit and at rest.
09How the data is protected
- Traffic is encrypted in transit (HTTPS) and data is encrypted at rest by our host.
- The database is backed up daily by our host, in the same European region as production, and the backups are encrypted at rest.
- Passwords are stored as salted hashes and are never readable by us. Two-factor authentication is available on every account.
- Access tokens for third-party integrations are encrypted before being written to the database.
- Each agency's workspace is isolated: a query carrying one agency's identity cannot reach another's rows.
- Access to production is limited to the people who need it, and administrative actions are logged.
Should a personal data breach be likely to result in a risk to your rights, we will notify the CNIL within 72 hours and inform you where the regulation requires it.
10Your rights
You may ask for access to your data, its rectification, its erasure or the restriction of its processing; you may object to processing based on our legitimate interest; and you may request portability of the data you provided.
Write to legal@usedashly.com. We answer within one month, extendable by two months for complex requests. We may ask for proof of identity where there is reasonable doubt.
If you consider your rights are not respected, you may lodge a complaint with the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
11Changes to this policy
This policy may change as the service evolves. The date at the top of the page always reflects the version in force, and any substantial change is announced to account holders by email before it takes effect.