Back to BEYOND
Privacy

Privacy Notice

How the BEYOND Research Platform collects, uses, shares, retains, and deletes personal information, and what rights you have over it. This notice covers survey.beyondinsights.com, which is where research studies are programmed, fielded, processed, and stored.

Effective August 6, 2026

Contents
  1. 1. Who and what this covers
  2. 2. Information we collect
  3. 3. How we use information
  4. 4. Legal basis for processing
  5. 5. Advertising measurement in research studies
  6. 6. Cookies and similar technologies
  7. 7. How long we keep information
  8. 8. How we share information
  9. 9. We do not sell or share personal information
  10. 10. Where information is processed
  11. 11. Your rights and how to exercise them
  12. 12. Children's privacy
  13. 13. Security
  14. 14. Breach notification
  15. 15. Changes to this notice
  16. 16. Contact us
Section 1

Who and what this covers

BEYOND Insights, LLC ("BEYOND", "we") is a market research firm. This notice applies to the BEYOND Research Platform at survey.beyondinsights.com, which is where we program and host surveys, collect and process respondent data, run analysis, and store study records.

It covers three groups of people:

  • Research respondents, who take a survey or participate in a qualitative session on the platform.
  • Client users, who hold an account to design studies and review results.
  • Visitors to the platform's public pages.

Our corporate marketing site, www.beyondinsights.com, is a separate property that hosts no study and stores no respondent data. It carries its own notice.

For most studies, BEYOND acts as a processor or service provider on behalf of a client, who determines the purpose of the research. Where BEYOND designs and fields research on its own behalf, we act as the controller. The applicable data processing agreement governs which role applies to a given study.

Section 2

Information we collect

From research respondents

  • Survey responses, including answers to closed and open-ended questions.
  • Research demographics collected for analysis and weighting, such as age band, gender, region, household composition, and category behaviors.
  • Participation metadata: the study and page a response belongs to, timestamps, time spent, device and browser type, and quality signals used to detect fraud, speeding, and inattentive responding.
  • Consent records, including the timestamp at which consent was given.
  • Where a study is fielded through a panel provider, a pseudonymous participant identifier supplied by that provider so completion can be credited and duplicates prevented.

We do not ask respondents for names, contact details, government identifiers, or payment information as part of a survey. Where a client supplies a customer list for a study, it is provided in pseudonymized or encrypted form.

From client users

  • Account information: name, work email address, organization, and role.
  • Authentication data, including credentials stored in hashed form and two-factor authentication settings.
  • Audit records of actions taken in the platform.

From visitors

Standard server logs, and cookies described in section 6. We do not run advertising or cross-site analytics trackers on pages where respondents answer surveys.

Section 3

How we use information

  • To conduct the research study a respondent has agreed to take part in.
  • To produce aggregate analysis, tables, reports, and dashboards for the client who commissioned the study.
  • To weight and validate data so results are statistically sound.
  • To detect and prevent fraud, duplicate participation, and low-quality responses.
  • To operate, secure, and support the platform, including error monitoring.
  • To build aggregated, de-identified benchmarks and norms across studies. These never identify a respondent, a client, or a sponsor.
  • To meet legal and regulatory obligations.

We do not use respondent data to train third-party AI models. Where AI assists analysis, it operates on data scoped to the individual study, is not pooled across clients, and is not used for provider model training. This is described at how we use AI.

We do not use respondent data for advertising, audience building, or targeting, and we do not make automated decisions that produce legal or similarly significant effects.

Section 4

Legal basis for processing

Where the GDPR or UK GDPR applies, we rely on the following bases:

  • Consent, for participation in research and for non-essential cookies. Consent is given before a survey begins and can be withdrawn at any time.
  • Legitimate interests, for securing the platform, preventing fraud, and maintaining data quality, balanced against the rights of the people concerned.
  • Contract, for providing the platform to client users.
  • Legal obligation, where retention or disclosure is required by law.
Section 5

Advertising measurement in research studies

Some studies measure whether a campaign changed brand perception. To do that we need to know whether a research panelist was exposed to the campaign, which is established with a measurement tag placed alongside the advertising creative by the publisher.

The tag records campaign metadata only: a timestamp, campaign and placement identifiers, and the browser and device type from the request. It does not receive names, email addresses, account or user identifiers, mobile advertising identifiers, or any other person-level identifier from the publisher, and we will reject an implementation that sends one.

Matching happens on the research panel side, against people who have already opted in to that panel, using the panel's own identifier. It is not an advertising tag: it builds no audience segments, drives no targeting or media buying, and writes nothing into any advertising system. Results returned to the publisher are aggregate only, with no respondent-level record.

Section 6

Cookies and similar technologies

We use cookies that are strictly necessary to run a survey session, keep it secure, and stop the same person completing a study twice. These do not require consent because the service cannot function without them.

Any non-essential cookie is set only with consent, and consent can be changed at any time through your browser settings or the controls presented on the page. We do not place advertising cookies on survey pages, and we do not sell or share cookie data.

Section 7

How long we keep information

Retention periods run from the delivery of the final study output.

  • Survey response data: five years from final delivery, unless the client requests earlier deletion or a longer period in writing. This period supports longitudinal trending and cross-study benchmarking.
  • Raw advertising exposure logs for measurement studies: purged 90 days after campaign flight end. After that point only the derived exposed or control indicator remains, joined to the survey record.
  • Client account and audit records: for the life of the account and a reasonable period afterwards for security and legal purposes.
  • Backups: retained per the configured recovery window and then overwritten.

Data is securely destroyed at the end of the applicable period. Deletion on request is described in section 11, and can be actioned per individual respondent or in bulk for a study.

Section 8

How we share information

We share personal information only in these circumstances:

  • With the client who commissioned the study, in aggregate form. Respondent-level data is provided only where the study design requires it and the applicable agreement permits it.
  • With service providers acting on our instructions under contract: cloud database and storage hosting, application hosting, panel and sample providers, incentive fulfillment, error monitoring, and, where invoked, AI text analysis. They may use the data only to provide their service to us.
  • Where required by law, or to establish, exercise, or defend legal claims.
  • In a business transfer, where personal information may be part of the assets transferred, subject to this notice.

Our subprocessors are named individually, with their role, vetting, and access scope, in the InfoSec questionnaire at security and compliance. We provide written notice before adding or replacing a subprocessor on a client engagement.

Section 9

We do not sell or share personal information

BEYOND does not sell personal information, and does not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act. We have not done so in the preceding twelve months.

Because we do not sell or share personal information, there is nothing to opt out of. Should that ever change, we would update this notice and provide a clear opt-out mechanism before doing so, and we would honor opt-out preference signals such as Global Privacy Control.

We do not use or disclose sensitive personal information for any purpose beyond those permitted without a right to limit.

Section 10

Where information is processed

BEYOND operates from the United States, and platform data is stored and processed in US regions. Studies in our current scope are US market and English language.

Where a study involves personal data originating in the European Economic Area, the United Kingdom, or another jurisdiction restricting international transfers, appropriate transfer safeguards, including standard contractual clauses, will be put in place under the data processing agreement for that study before the data is collected.

Section 11

Your rights and how to exercise them

Everyone

  • Request access to the personal information we hold about you, and information about how it is used.
  • Request correction of inaccurate information.
  • Request deletion of your information.
  • Withdraw consent to research participation at any time, without penalty.

Under GDPR and UK GDPR

  • Restrict or object to processing, including processing based on legitimate interests.
  • Receive your data in a portable format.
  • Lodge a complaint with your supervisory authority.

Under CCPA and CPRA

  • Know what personal information is collected, used, and disclosed, and the categories of recipients.
  • Delete personal information, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of sale or sharing. As stated in section 9, we do not sell or share personal information.
  • Limit use of sensitive personal information, which we do not use beyond permitted purposes.
  • Non-discrimination: not be discriminated against for exercising any of these rights. We will not deny service, charge a different price or rate, provide a different level or quality of service, or suggest that you will receive any of those, because you exercised a right.

How to make a request

Email privacy@beyondinsights.com or write to us at the address in section 16. We will verify your request, usually by confirming details already associated with your participation, and we will not use the information you provide for verification for any other purpose.

We respond within 45 days of a verifiable request under CCPA, and will tell you if we need a further 45 days. Under GDPR we respond within one month, extendable by two further months for complex requests. An authorized agent may make a request on your behalf with proof of authority.

Where BEYOND processes data on behalf of a client, we will refer your request to that client and act on their instructions, and we will tell you when we have done so.

Section 12

Children's privacy

The platform is not directed to children. Research participation requires respondents to be 18 or older unless a study is specifically designed to include minors, in which case verifiable parental consent is obtained in line with the Children's Online Privacy Protection Act and applicable law. We do not knowingly collect personal information from a child under 13. If we learn that we have, we delete it.

Section 13

Security

Data is stored with infrastructure providers holding SOC 2 Type II certification, encrypted at rest with AES-256 and in transit with TLS 1.2 or above. Access is role-based and limited to personnel who need it, with mandatory two-factor authentication on administrative accounts and audit trails across sensitive actions. Automated backups and point-in-time recovery are in place.

No system is perfectly secure, and we do not claim otherwise. Our full security posture, including network security, vulnerability management, access control, and business continuity, is documented at security and compliance.

Section 14

Breach notification

If we confirm a breach affecting personal information, we notify the affected client without undue delay and within 24 hours of confirmation. Where the GDPR applies, we notify the relevant supervisory authority within 72 hours, and affected individuals where the breach is likely to result in a high risk to their rights. Our incident response process covers detection, containment, investigation, notification, and remediation.

Section 15

Changes to this notice

We update this notice as our practices or the law change. The effective date at the top shows when it last changed. Where a change materially affects how we handle personal information already collected, we will provide notice before it takes effect.

Section 16

Contact us

Privacy questions and rights requests: privacy@beyondinsights.com

General enquiries: info@beyondinsights.com

BEYOND Insights, LLC
Woodsboro, Maryland, United States