Legal

Privacy policy

Version 2026-09-18.2 · Last updated 2026-09-18

Who we are

PeakBeyond™ (peakbeyond.ai, and peakbeyond.com, which now redirects here) is operated by Peak Beyond, LLC, 435 Merchant Walk Square, Suite 300-132, Charlottesville, VA 22902. We are the data controller (the “business”, under US state laws) for the personal data described here: what visitors give us on this website, and the accounts of people who use our client portal.

Where we process data inside the portal on a client's behalf — information about that client's own websites and systems — we act as the client's processor (“service provider”), under our agreement with them.

Visiting our website

When you contact us

The contact form asks for your name and email address, and optionally your company, phone number and what you'd like help with, plus your message. We use it only to reply to you and to arrange any conversation you ask for. When you send it, we email you a short confirmation that we received it; that email contains only your first name and the topic you chose, never your message. We check that your email address's domain exists (a public DNS lookup) so we can reply, and to keep spam out we briefly keep one-way codes made from your IP address and your email address (never the addresses themselves) to limit how many messages one network or one address can send.

Visit statistics

Our own server counts page views, time on each page, the referring website, links you follow to other websites, and your device type, operating system, browser, screen size, language and approximate location (country, region and city, which our hosting provider derives from your IP address). Visitors are told apart by a code made from a random value that we replace every day, your IP address and your browser details. The IP address itself is never stored and the daily value is deleted after two days, so the code can't be traced back to you or linked across days. Nothing is stored on your device (unless you switch the statistics off, when your browser remembers that choice) and nothing is shared with anyone else. You can switch this off below.

Client case studies and testimonials

Our case studies describe work we have done for our clients, with their agreement. Where we quote someone from a client, we publish their name, their organization and what they said, only with their permission. Pictures on a case study come from the client's own website. To have a quote or picture removed, contact us and we will take it down.

Privacy requests

If you make a privacy request we keep what you send (your name, email address, where you live and the details of the request) to handle it and to show we answered it.

Using the client portal

The portal is used by our clients' staff to see what has changed on their own websites. It is not a consumer product and is not open to public sign-up.

Your account

Your name, work email address, the date you created the account, the date you last signed in, your display preferences and the time zone your browser reports (so our emails show times in your own zone). If you register a passkey we store its public key and the name you give it — never a private key, and never biometric data, which stays on your own device. When you create an account we link it to your organization if your email address is one of its contacts or on its email domain; otherwise one of our administrators reviews it before it can be used.

Sign-in activity

Single-use sign-in codes (stored hashed, deleted after use or after fifteen minutes), active session identifiers, and a record of administrative actions affecting your account — including any occasion on which an administrator viewed the portal as you.

Monitoring data

Information about your organization's websites: code changes and their authors as reported by your source control, theme changes, page performance measurements, website audits, error logs and traffic totals you connect, and a record of the emails we send about them. Where this includes a person's name — the author of a commit, for instance — it comes from your organization's systems and is processed because your organization instructed us to monitor them. We mask email addresses, card-like numbers and tokens in error logs before storing them.

Why we use it and our legal bases

  • To answer your inquiry — replying to a contact-form message. (Steps you ask for before any contract, and our legitimate interest in responding to people who contact us.)
  • To provide the portal — signing you in, showing your organization's data, and sending the reports and alerts it has asked for. (Performance of a contract.)
  • To keep the site and portal secure — spam and abuse prevention, rate limiting, session management and the audit trail. (Legitimate interests in securing our systems.)
  • To understand how the site is used — the visit statistics above. (Legitimate interests; you can opt out at any time.)
  • To show our work — publishing client case studies and the testimonials of people who agreed to be quoted. (Consent, which you can withdraw at any time.)
  • To meet legal obligations — responding to privacy requests and keeping records of those responses.

We do not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising or profiling, or make automated decisions that produce legal or similarly significant effects. We don't collect sensitive personal data.

Cookies, visit statistics and your choices

We set three cookies, all strictly necessary and first-party, and none used for tracking or measurement, so no consent banner is needed:

  • pb_sess — keeps a portal user signed in. HttpOnly, Secure, SameSite=Lax, thirty days.
  • pb_preview — only while the site is closed for maintenance, to let approved testers past the holding page.
  • pb_admin_door — only for our own administrators, to reach the portal sign-in page. HttpOnly, Secure, ninety days.

There are no advertising or analytics cookies, tag managers, session recorders, embedded fonts, social widgets or third-party scripts of any kind. The site enforces a Content Security Policy that permits requests to our own origin only, so a third-party request cannot be added by accident.

Opting out of visit statistics. We don't count visitors whose browser sends a Global Privacy Control or Do Not Track signal, and we treat Global Privacy Control as a valid opt-out request. You can also switch the statistics off for this browser here:

Who we share it with

We use the following service providers (processors). Each is bound by a contract that limits it to processing data on our instructions and keeping it secure.

ProviderPurposeLocation
VercelHosting and content delivery for peakbeyond.ai; approximate location of visitors from their IP addressUnited States
UpstashAccount, session, visit-statistics and rate-limit storage (Redis)United States
NeonPortal database (Postgres)United States
ResendEmail delivery (sign-in codes, reports, contact-form messages and the confirmation we send when you use the form)United States
Microsoft (Microsoft 365)Our business email: receiving and answering contact-form messages and privacy requestsUnited States
CloudflareSecurity filtering and redirecting our former address, peakbeyond.com, to this siteUnited States
GTmetrixPage performance tests of client website addresses (no visitor data)Canada
Google (PageSpeed Insights)Accessibility and performance audits of client website addresses (no visitor data)United States

Inside the portal, your organization's own people and, with your organization's agreement, the website partners it works with (its developer or hosting company) see the information about its websites. We disclose data to anyone else only where the law requires it, or to protect our rights, or as part of a merger or sale of our business (you would be told first).

International transfers

We and our providers are based mainly in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, transfers of your data rely on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and, where a provider is certified, the EU–US Data Privacy Framework and its UK and Swiss extensions.

How long we keep it

  • Contact-form messages — in our email for as long as we're discussing your inquiry or working together, and no longer than three years after our last contact.
  • Anti-spam codes — up to 24 hours.
  • Visit statistics — 90 days.
  • Your portal account — until you or your organization delete it. Accounts unused for 36 months are deleted automatically.
  • Sign-in codes — fifteen minutes, or immediately once used.
  • Sessions — thirty days from last use.
  • Monitoring data and email records — for the term of your organization's agreement with us, then deleted on request.
  • Privacy requests — 24 months after the request is closed, so we can show we answered it.
  • Audit trail — retained, with identifiers replaced by a one-way hash once the related account is deleted.

Your rights

Depending on where you live, you have the right to:

  • Know and access what personal data we hold about you and get a copy, including in a portable, machine-readable format;
  • Correct data that is inaccurate;
  • Delete your data;
  • Object to or restrict how we use it, including our visit statistics;
  • Opt out of the sale or sharing of personal data, targeted advertising and profiling — we do none of these;
  • Withdraw consent where we rely on it — for a published testimonial, for instance;
  • Not be discriminated against for using any of these rights;
  • Complain to a data protection authority — in the UK the Information Commissioner's Office, in the EU the authority where you live or work.

Portal users can do most of this themselves: My account lets you download everything we hold, correct your name or email address, sign out everywhere, and ask for deletion. Deleting a client organization's account is reviewed by an administrator first, because monitoring data may be covered by an ongoing agreement; we will tell you the outcome either way.

US state privacy notice (including California)

This section adds to the rest of the policy for residents of California (CCPA as amended by the CPRA) and of other states with consumer privacy laws, including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia.

In the past twelve months we have collected the categories of personal information below. We have not sold or shared (for cross-context behavioral advertising) personal information, including of anyone under 16, and we don't use or disclose sensitive personal information.

CategoryWhat we holdSourceWhyDisclosed toKept
IdentifiersName, email address, phone number (if you give it), account ID, a daily visitor codeYou; your organizationReplying to you; providing the portal; securityService providers aboveSee “How long we keep it”
Professional informationCompany name, job role within a client organization; for people quoted in a case study, their name, organization and what they saidYou; your organizationReplying to you; providing the portal; showing our work (with permission)Service providers above; the public, for published testimonialsAs for identifiers; testimonials until permission is withdrawn
Internet or network activityPages viewed on our site, time on page, referring site, links followed, portal sign-ins and actionsYour browser; our serversUnderstanding how the site is used; securityService providers aboveVisit statistics 90 days; audit trail as described
Approximate locationCountry, region and city derived from your IP address (not precise location)Our hosting providerUnderstanding where visitors come fromService providers above90 days
Device informationDevice type, operating system, browser, screen size, languageYour browserUnderstanding how the site is usedService providers above90 days
Content of communicationsWhat you write in the contact form or a privacy requestYouReplying to you; handling your requestService providers aboveSee “How long we keep it”

How we verify requests. We match the email address you give us to the data we hold and may ask you to confirm a code we send there. For deletion or copies of data we may ask for one more detail we already have. We never ask for more than we need.

Authorized agents. Someone you have authorized may make a request for you; we will ask for your signed permission and may confirm your identity with you directly.

Response times. We confirm a request within 10 business days and answer within 30 days (the stricter GDPR deadline; US state laws allow 45), and tell you if we need an extension where the law allows one.

Appeals. If we decline your request, you can appeal by replying to our answer with the word “Appeal”. Someone who wasn't involved in the first decision will review it and reply within 45 days, or sooner where your state requires. If you disagree with the outcome, you can contact your state's Attorney General.

Make a privacy request

Use this form, or email us: . You'll get a reference number and the date we'll answer by.

Children

Our website and portal are for businesses and aren't directed to children. We don't knowingly collect personal data from anyone under 16, and portal accounts are only for people 16 or older. If you believe a child has given us personal data, contact us and we will delete it.

Security

There are no passwords on the portal, so there is none to be stolen or reused. You sign in with a passkey or a single-use emailed code. Session tokens are stored hashed. Sensitive operations require a fresh sign-in. Credentials for the systems we monitor on our clients' behalf are encrypted (AES-256-GCM) before they are stored, with the key held separately from the database. Access to each organization's data is restricted at the query level, not merely hidden in the interface, and all traffic is encrypted in transit.

No service can promise perfect security, but if a breach affects your personal data we will notify you and the relevant regulator as the law requires.

Changes and contact

For questions about this policy or your data, email us: , or use the form above.

If we change this policy we will update the version above and, for changes that affect you materially, tell portal account holders by email before they take effect.