Last updated: 17 August 2026
This policy explains how BeRelevant.ai collects and uses personal data through berelevant.ai, business communications, and client relationships. It also explains your rights under the General Data Protection Regulation (GDPR) and Portuguese law.
1. Who is responsible for your data?
BeRelevant.ai controls the personal data described in this policy.
Privacy contact: privacy@berelevant.ai
We use “BeRelevant.ai,” “we,” “us,” and “our” below to refer to the controller.
2. When this policy applies
This policy applies when you:
- visit berelevant.ai
- contact us, book a call, or request a proposal
- receive business communications from us
- represent a client, prospect, supplier, or partner
- attend a meeting, webinar, or event we organize
This policy covers personal data we control for our business purposes.
When a client gives us access to website data, analytics, search data, server logs, content systems, code, or other systems, the client normally controls that data. BeRelevant.ai processes it on the client’s instructions. The client agreement and data processing agreement govern that work.
3. What data we collect
Data you give us
We may collect:
- your name, job title, organization, business email, phone number, and location
- information you submit by email, message, meeting, or scheduling form
- your website, priorities, budget, requested services, and project requirements
- proposal, contract, billing, payment, and transaction records
- preferences and records of your marketing consent or objection
Do not send special-category personal data, passwords, access tokens, or confidential client data through a public channel.
Data collected when you use the website
The website and its infrastructure providers process technical request data needed to deliver and protect the site. This may include:
- IP address
- browser, device, operating system, and language
- requested URL, referring page, timestamp, and response status
- security and diagnostic records
The homepage and content pages do not set first-party cookies. The scheduling page embeds Cal.com and sets the cookies listed in section 6.
Data from other sources
We may receive business contact data from:
- a colleague, client, or referral partner who introduces you
- public company websites and professional profiles
- event organizers and business partners
When GDPR Article 14 requires us to notify you about data obtained elsewhere, we will do so within the applicable period unless an exemption applies.
Data processed during client work
Depending on the signed scope, client systems may contain:
- public URLs, page content, metadata, structured data, and crawl responses
- Google Search Console and analytics data
- search queries, rankings, backlinks, and AI citation observations
- server logs and technical identifiers
- code, templates, content-management data, and implementation records
- names, business contact details, or identifiers contained in those systems
We process this data only for the agreed work, under the client’s instructions and the applicable agreement.
4. Why we use personal data
To respond and prepare an engagement
We use your contact details and request information to answer questions, book meetings, assess fit, and prepare a proposal.
Legal basis: steps requested before entering a contract under GDPR Article 6(1)(b), and our legitimate interest in managing business enquiries under Article 6(1)(f).
To deliver and manage contracted work
We use client and project data to provide services, communicate with project owners, manage access, invoice, receive payment, and keep engagement records.
Legal basis: performance of a contract under Article 6(1)(b), or our legitimate interest in administering a contract with the organization you represent under Article 6(1)(f).
To operate and protect the website
We use technical and security data to deliver pages, prevent abuse, investigate faults, maintain availability, and protect our systems.
Legal basis: our legitimate interests in operating and securing the website under Article 6(1)(f).
To schedule meetings
We use the details you submit through Cal.com to offer available times, create a booking, send meeting information, and manage changes or cancellations.
Legal basis: steps requested before entering a contract under Article 6(1)(b), or our legitimate interest in administering a requested meeting under Article 6(1)(f).
To send marketing communications
We may send relevant service updates, research, or event invitations where you have consented or where applicable law permits the communication subject to an opt-out.
Legal basis: consent under Article 6(1)(a), or our legitimate interest in relevant business-to-business marketing under Article 6(1)(f), together with applicable electronic communications rules. You can unsubscribe or object to direct marketing at any time.
To meet legal duties and handle claims
We retain and disclose data when required for accounting, tax, fraud prevention, legal claims, regulatory requests, or enforcement of agreements.
Legal basis: compliance with a legal obligation under Article 6(1)(c), and our legitimate interests in establishing, exercising, or defending legal claims under Article 6(1)(f).
5. When providing data is required
You choose whether to contact us or book a meeting. We cannot answer a request without the contact information needed to reply. A signed engagement may require additional contact, billing, access, and project data. We identify information required by contract or law when we request it.
6. Cookies and similar technology
BeRelevant.ai does not use analytics, advertising, or personalization cookies. It does not provide a cookie-settings control because there are no optional cookies to enable or disable.
The scheduling page at /talk/ embeds Cal.com. Loading that page causes Cal.com to set the following third-party cookies for the requested scheduling service:
__cf_bm: Cloudflare bot-management and abuse-prevention cookie used by Cal.com. It expires after about 30 minutes.__Secure-next-auth.csrf-token: session cookie used to protect the scheduling flow from cross-site request forgery. It expires when the browser session ends.__Secure-next-auth.callback-url: session cookie used to return the browser to the scheduling service after an authentication step. It expires when the browser session ends.
Cal.com may change its service and necessary-cookie names. We review this inventory when the scheduling integration changes. Cal.com’s own privacy policy explains how it processes scheduling data.
The site also requests fonts from Google Fonts and public images from Cloudflare-hosted storage. Those requests did not set cookies in our browser audit on 17 August 2026, but the providers receive technical request data such as your IP address and browser headers.
If we add analytics, advertising, personalization, or another non-essential technology, we will update this policy and obtain any consent required before enabling it.
7. Who receives personal data
We share only the data needed for a defined purpose. Current website providers include:
- Railway Corporation, which hosts and delivers the website and may process IP addresses, request data, and service logs
- Cloudflare, Inc., which stores and delivers public images and may process IP addresses and request data
- Google LLC, which delivers the website fonts and receives technical request data
- Cal.com, Inc., which provides the embedded scheduling service and processes booking details and technical request data
Other recipients may include email, video-call, accounting, payment, banking, legal, insurance, and professional service providers used for a requested interaction or contracted engagement. Contractors and delivery partners receive data only where needed and are bound by appropriate confidentiality and data-protection terms.
We may disclose data to courts, regulators, law enforcement, and public authorities where required or legally justified. We may also disclose data in a proposed business transaction subject to appropriate safeguards.
We do not sell personal data.
8. International transfers
Railway Corporation, Cloudflare, Inc., Google LLC, and Cal.com, Inc. are based in the United States or operate infrastructure there. Personal data may therefore be processed outside Portugal and the European Economic Area.
Where a destination is not covered by a European Commission adequacy decision, we rely on the transfer safeguards provided by the relevant service agreement, such as the European Commission’s Standard Contractual Clauses, and assess whether supplementary safeguards are required.
You may request information about the safeguard used for a transfer by emailing privacy@berelevant.ai.
9. How long we keep personal data
We keep personal data only for its stated purpose and any period required by law.
- Enquiries and proposal records: while we handle the request and for up to 24 months after the last substantive contact, unless a contract begins or the record is needed for a claim.
- Client and supplier records: for the engagement and the applicable legal, tax, accounting, warranty, and limitation periods.
- Marketing contacts: until you withdraw consent, object, or the data is no longer useful for the stated purpose. We may retain a minimal suppression record to respect an opt-out.
- Website security and diagnostic records: for the shortest period needed to secure and troubleshoot the website, according to the hosting provider’s service settings and retention rules.
- Cal.com booking data: while needed to arrange and document the meeting, then according to our Cal.com account settings and any period needed for follow-up, contracts, or legal claims.
- Client data processed on a client’s behalf: for the period in the client agreement and data processing agreement, then returned or deleted as instructed, subject to legal retention duties.
We may retain data longer to establish, exercise, or defend a legal claim, respond to an authority, or comply with a preservation duty.
10. How we protect personal data
We use measures appropriate to the nature of the data and the risk. These include access controls, secure transfer methods, controlled credentials, service-provider review, backups where required, and procedures for security incidents and data-subject requests.
No internet transmission or storage system removes every risk. We review safeguards when our systems, providers, or work change.
11. Your rights
Subject to the GDPR’s conditions, you may:
- ask whether we process your personal data and obtain a copy
- correct incomplete or inaccurate data
- ask us to erase data
- ask us to restrict processing
- object to processing based on legitimate interests
- object to direct marketing at any time
- receive data you provided in a structured, commonly used, machine-readable format and have it transmitted where technically feasible
- withdraw consent at any time for future processing
- lodge a complaint with a supervisory authority
To exercise a right, email privacy@berelevant.ai. Tell us which right you want to use and provide enough information to identify the relevant record. We may ask for proportionate proof of identity. We normally respond within one month. The GDPR permits an extension of up to two further months for complex or numerous requests. If an extension is needed, we will explain it within the first month.
You may complain to the Portuguese supervisory authority:
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1.º
1200-651 Lisboa, Portugal
cnpd.pt
You may also complain to the data-protection authority where you live, work, or believe an infringement occurred.
12. Automated decisions
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects for website visitors, prospects, or client contacts.
13. Children’s data
The website and our services are intended for organizations and professionals, not children. We do not knowingly request personal data from children through the website. If you believe a child has submitted personal data, email privacy@berelevant.ai.
14. Other websites
Our website may link to websites and services operated by others. Their privacy practices are governed by their notices, not this policy.
15. Changes to this policy
We may update this policy when our services, providers, or legal duties change. We will publish the revised version here and change the “Last updated” date. If a change materially affects how we use data already collected, we will provide any additional notice required by law.
16. Contact
Send privacy questions, objections, and rights requests to privacy@berelevant.ai.
