BENICODE / RGPD

Privacy and personal data

Updated: 19 September 2026.

Controller and contact

Pixel Mint, trading as Benicode — 12 Rue de Oberhausen, 29270 Carhaix-Plouguer, France.

For a question or to exercise your rights, write to this postal address.

Data and purposes

When the form is enabled, we receive your name, email address, requested service and message. Your company is optional. If you arrive from an audit, its URL, device type and scores may accompany your enquiry. We use this information to reply and discuss a possible project. Fields marked with an asterisk are needed to handle the enquiry. Do not include sensitive personal information in your message.

Legal bases

Quote and project enquiries are processed to take steps at your request before entering a contract (GDPR Article 6(1)(b)). Other correspondence and protection against abuse rely on our legitimate interests in responding to visitors and keeping the service secure (Article 6(1)(f)). Requested audits are processed to provide that service at your request. Reading this notice does not give consent to marketing.

Website audits

The audit is optional and starts only when you request it. Our server sends the submitted URL to Google PageSpeed Insights and Chrome UX Report. The report contains technical measurements and recommendations. No account or email is required to view it. Use only public URLs, without passwords, access tokens or personal information. Cancelling stops the browser from waiting; an analysis already sent to the provider may continue.

Audit history and email delivery

We keep a private history of successful audits: origin, date, device and scores, without URL query parameters. This history helps us understand service use and expressed needs; a domain alone does not identify the visitor. If you request your report by email, we use the supplied address for that delivery. Follow-up permission is optional, separate, unchecked by default and only becomes active after confirmation from the email. You can withdraw it using the provided link. Results remain accessible without email or follow-up permission.

Retention

In our application database: report cache 24 hours; analysis jobs one hour; domain history 180 days; delivery metadata 30 days; unconfirmed permission seven days; confirmed permission 12 months; contact enquiries 180 days. Withdrawal immediately disables follow-up and removes the address from the permission record. A minimal hash may remain for 12 months to respect withdrawal. Expired records are deleted in hourly batches. Active-project correspondence may be retained separately according to applicable obligations. Provider backups, logs, messages and execution state follow their own retention periods: application deletion does not guarantee their immediate erasure.

Recipients and providers

Enquiries are intended for authorised people at Benicode. Cloudflare Turnstile checks report-email and contact requests for bots using technical browser signals. Cloudflare provides hosting, functions, background execution and the database. Resend sends reports and notifications when email is enabled. The configured Gmail mailbox receives contact enquiries. Google receives the URLs needed for analysis. Providers also process technical data, including IP addresses. Our abuse limits use a temporary hash of the IP address. During a demonstration through ngrok, that provider routes requests.

Processing outside the European Economic Area

Some providers may process data outside the European Economic Area, including in the United States. Our office location therefore does not guarantee exclusively European hosting. Processing agreements, locations and applicable transfer safeguards must be verified when production is configured. Provider privacy information is linked below.

Cookies and analytics

This version of the site does not integrate advertising trackers, audience analytics or session recording. Fonts are hosted with the site. Mentioning PostHog in a case study describes a client project and does not mean it is installed here. If non-essential trackers are added, they must remain disabled until you choose, with rejection as easy as acceptance and a way to change that choice.

Your rights

Depending on the processing, you may request access, correction, deletion or restriction, object to processing based on legitimate interests, and request portability where its conditions apply. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. We normally respond within one month; a justified extension is possible in the cases allowed by the GDPR. Proportionate identity verification may be needed if there is reasonable doubt.

You may also lodge a complaint with the CNIL, or the competent supervisory authority in your country.

Provider information