Skip to main content

Boclet Method

Privacy Policy

This privacy policy and terms of use is intended to inform you about how we collect, use, and protect your information when you visit our website.

Article 1 – Scope of this policy

Purpose of the policy

The purpose of this privacy policy is to inform users of the website www.methodeboclet.com and its subdomains (including go.methodeboclet.com) in a clear, transparent and understandable manner about the conditions under which Limitless Learning LLC collects and processes their personal data, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and French law no. 78-17 of 6 January 1978 as amended.

Services concerned

This policy applies to all data processing implemented within the framework of: 

  • navigation on the site and its subdomains;
  • of the creation and management of a user account / member area;
  • ordering and payment for online training courses;
  • access to training content and educational support;
  • customer relationship management (assistance, complaints, exercising rights);
  • sending informational and commercial prospecting communications (emails, newsletters, offers);
  • audience measurement and website traffic statistics;
  • managing cookies and other trackers placed on the user's device;
  • managing any potential disputes.

Article 2 – Identity of the data controller and representative in the European Union

2.1 Data controller

The data controller for the personal data processing described in this policy is:

Limitless Learning LLC
American company
Address: 1209 Mountain Rd Pl NE, Suite R, Albuquerque, NM 87110, USA
EIN: 35-2872157 

The data controller can be contacted at the following email address: contact@methodeboclet.com

Limitless Learning LLC determines the purposes and means of the processing of personal data carried out via the website www.methodeboclet.com.

2.2 Representative in the European Union

In accordance with Article 27 of the GDPR, Limitless Learning LLC, as a data controller not established in the European Union but offering goods and services to persons located in the Union, is in the process of appointing a representative established in the European Union.

The contact details of this representative will be provided as soon as he or she is appointed.

Article 3 - Data collected

3.1 Categories of data processed

The categories of data that may be collected and processed are as follows:

Identification and contact details :

  • name, first name;
  • e-mail address ;
  • postal address (billing);
  • Telephone number (optional, if provided)
 

Data relating to professional life or training project (if provided by the user):

  • profession, professional situation, information on training objectives (optional)
 

Order and billing information :

  • products / training courses purchased;
  • amount, date and time of the order;
  • billing address;
  • transaction number and payment method (bank card data is processed directly by the payment provider and is not retained by Limitless Learning LLC, except for partial data necessary to prove the transaction).
 

Account and member area data :

  • login ID (email) and password (hashed);
  • history of training courses taken, progress, results of any quizzes or exercises;
  • exchanges with the teaching support team (messages, tickets).
 

Connection and browsing data :

  • IP address, connection logs, date and time of connection;
  • pages viewed, navigation path, time spent, clicks;
  • Terminal identifier, operating system, browser used.
 

Data relating to communications :

  • newsletter subscription;
  • email opens, link clicks (campaign statistics);
  • responses to emails and requests addressed to support.
 

3.2 Mandatory or optional nature of the data

During data collection (online forms, account creation, order), mandatory fields are marked as such. Failure to provide this information will make it impossible to: 

  • creating an account;
  • the placing or execution of an order;
  • access to purchased training courses.
 

The other data is optional; not providing it may limit the personalization of support or the receipt of certain information, without affecting the provision of the main service.

Article 4 – Purposes and legal basis of processing

In accordance with Article 6 of the GDPR, all data processing must be based on a specific legal basis and be pursued for specified, explicit and legitimate purposes.

4.1 Site, Account and Order Management

  • Purposes:
    • user account and member area management;
    • processing of online training orders;
    • execution of training services (access to videos, educational monitoring, assistance);
    • billing and accounting management.
  • Legal basis:
    • performance of the contract concluded with the user (Article 6, §1, b, GDPR);
    • compliance with legal obligations in accounting and tax matters (Article 6, §1, c, GDPR).

4.2 Customer relationship management, support and complaints

  • Purposes:
    • response to information requests;
    • technical or educational assistance;
    • handling of complaints and potential disputes.
  • Legal basis:
    • performance of the contract (Article 6, §1, b, GDPR);
    • Limitless Learning LLC's legitimate interest in ensuring the quality of its services and defending its rights (Article 6, §1, f, GDPR).

4.3 Sales prospecting and information communications

  • Purposes:
    • sending informational emails related to training courses, news, and promotional offers;
    • abandoned cart reminder, invitation to webinars or online events;
    • segmentation and personalization of communications based on training courses purchased or viewed.
  • Legal basis:
    • user consent for email marketing to prospects (Article 6, §1, a, GDPR);
    • Limitless Learning LLC's legitimate interest in prospecting its customers, in compliance with applicable rules (Article 6, §1, f, GDPR).

The user may withdraw their consent or object at any time to receiving such communications (unsubscribe link present in each email, or request addressed according to the terms of Article 10 below).

4.4 Statistics, audience measurement and service improvement

  • Purposes:
    • website audience measurement (number of visits, page views, user journeys);
    • analysis of the use of training to improve content and user experience;
    • testing and optimization of website functionalities.
  • Legal basis:
    • Limitless Learning LLC's legitimate interest in improving its services (Article 6, §1, f, GDPR) for strictly necessary trackers or those exempt from consent;
    • user consent for cookies and trackers subject to consent (see article 9).

4.5 Site security and fraud prevention

  • Purposes:
    • securing the site and user accounts;
    • detection of suspicious or fraudulent activities (abnormal increase in connections, unauthorized access attempts);
    • security incident management.
  • Legal basis:
    • Limitless Learning LLC has a legitimate interest in ensuring the security of its information systems and protecting its business (Article 6, §1, f, GDPR).

4.6 Management of individuals' rights and legal obligations

  • Purposes:
    • management of requests to exercise rights (access, rectification, erasure, limitation, objection, portability, post-mortem directives);
    • compliance with legal and regulatory obligations, particularly in the areas of data protection and fraud prevention.
  • Legal basis:
    • compliance with a legal obligation to which the data controller is subject (Article 6, §1, c, GDPR).

Article 5 – Data Recipients and Subcontractors

The data collected is intended for:

  • to the internal departments of Limitless Learning LLC responsible for site management, customer relations, billing and support;
  • to technical service providers acting as subcontractors within the meaning of Article 28 of the GDPR (hosting provider, payment provider, video hosting platform, email campaign management tool, customer support provider, audience analysis tool, etc.), acting on the instructions of Limitless Learning LLC and subject to a contractual obligation of confidentiality and security;
  • where appropriate, to external advisors (lawyers, accountants) and to administrative or judicial authorities, when necessary to defend the rights of Limitless Learning LLC or to comply with a legal obligation.

No data is transferred to third parties for independent commercial purposes without the user's prior consent. [to be verified]

Article 6 – Data transfers outside the European Union

User data may be transferred to countries outside the European Union, and in particular to the United States, where Limitless Learning LLC and some of its service providers (hosting, marketing or support tools) are located.

In accordance with Articles 44 et seq. of the GDPR, these transfers are governed by one of the following mechanisms:

  • when the recipient is located in a country benefiting from a suitability decision of the European Commission, the data are transferred on this basis (Article 45 GDPR);
  • when the American service provider is certified under the EU‑US Data Privacy Framework, the transfer is carried out on the basis of this specific suitability decision;
  • Failing that, transfers are governed by the conclusion of standard contractual clauses of the European Commission, possibly supplemented by additional technical and organisational measures, in order to guarantee a level of protection substantially equivalent to that of the European Union (Article 46 GDPR).

Limitless Learning LLC assesses, on a case-by-case basis, the level of protection offered in the third country concerned and, where appropriate, implements additional measures (encryption, pseudonymization, access restrictions) or, if necessary, suspends the transfer.

The user is informed that, despite these measures, the existence of foreign legislation (particularly regarding access by public authorities) may lead to residual risks to the confidentiality of their data.

Further information regarding transfers and safeguards in place can be obtained by contacting Limitless Learning LLC in accordance with the terms of Article 10.

Article 7 – Data retention periods

Personal data is kept for limited periods, proportionate to the purposes pursued and, where applicable, increased by the legal limitation periods.

The personal data collected by Limitless Learning LLC is kept only for the period strictly necessary to achieve the purposes for which it is processed, plus, where applicable, the statutory limitation periods or archiving obligations imposed on the company.

Data relating to the management of user accounts and the member area (identification data, contact information, account settings, training history) is retained for the entire duration of the user's account use. From the date of the last activity on the account or the last contact initiated by the user (login, purchase, click on an email, support request), this data may be kept in the active database for a maximum of three (3) years for the purposes of managing the business relationship and marketing, unless the user objects or requests its deletion. Beyond this period, the data is either deleted or archived in an intermediate manner when its retention remains necessary for the establishment, exercise, or defense of legal claims.

Order and billing data (purchase information, invoices, non-bank payment data, transaction history) are kept for the duration of the contractual relationship, then archived for a period of ten (10) years from the end of the accounting period in which the transaction took place, in accordance with legal and regulatory obligations in accounting and tax matters.

Data used for marketing purposes (email address, campaign participation history, communication preferences) is retained for a maximum of three (3) years from the last contact initiated by the user (e.g., opening an email, clicking on a link, requesting information, logging into the member area), unless the user has withdrawn their consent or objected to its processing beforehand. After this period, the data is deleted or anonymized, or the user may be contacted again to obtain their consent for a further retention period.

Browsing and audience measurement data collected through cookies and other tracking technologies are stored for no longer than is necessary for the purposes for which they were collected. The lifespan of cookies requiring consent does not, in principle, exceed thirteen (13) months, while information relating to user cookie preferences (consent, refusal) is stored for a maximum of six (6) to thirteen (13) months, in accordance with the recommendations of the CNIL (French Data Protection Authority). Beyond this period, the data may be aggregated or anonymized for purely statistical purposes.

The data collected and processed in the context of the management of requests to exercise rights (access, rectification, erasure, limitation, objection, portability, post-mortem directives) are kept for the time necessary to process the request, then archived for a period of three (3) to six (6) years, depending on the nature of the request, for the purpose of proving compliance with its obligations by Limitless Learning LLC.

Data relating to claims and disputes (information on the dispute, documents exchanged, correspondence with counsel and authorities) are kept for the duration of the procedure and until the expiry of all avenues of appeal and applicable limitation periods, in order to allow Limitless Learning LLC to establish, exercise or defend its rights in court.

At the end of the retention periods thus defined, the data are either deleted, irreversibly anonymized, or, when a legal obligation or a serious legitimate interest justifies it, kept in intermediate archiving with restricted access and enhanced security measures.

Article 8 – Rights of the persons concerned

In accordance with Articles 15 to 22 of the GDPR and the French Data Protection Act, the user has the following rights regarding their personal data:

  • Permission to access : to obtain confirmation as to whether or not data concerning him/her is being processed, and, where it is, access to that data as well as various information (purposes, categories of data, recipients, retention period, existence of transfers outside the EU, appropriate safeguards, etc.).
  • Right of rectification : to obtain the rectification of inaccurate data or the completion of incomplete data.
  • Right to erasure (“right to be forgotten”): to obtain the erasure of one’s data in the cases provided for by the GDPR (for example when the data are no longer necessary for the purposes, withdrawal of consent for processing based on that consent, justified objection, unlawful processing, etc.).
  • Right to restriction of processing : to obtain the restriction of processing in the cases provided for by the GDPR (contestation of the accuracy of the data, unlawful processing, data necessary for the establishment, exercise or defence of legal claims, etc.).
  • Right of opposition : to object, for reasons relating to their particular situation, to processing based on the legitimate interest of Limitless Learning LLC; to object, at any time and without reason, to the processing of their data for commercial prospecting purposes.
  • Right to portability : receive the data he has provided to Limitless Learning LLC, in a structured, commonly used and machine-readable format, and transmit it to another data controller, where the processing is based on consent or the performance of a contract and carried out by automated means.
  • Right to withdraw consent : when processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing based on consent carried out before such withdrawal.
  • Right to define post-mortem directives : to define guidelines regarding the fate of one's data after death (retention, erasure, communication to a third party), general or specific guidelines, which can be modified or revoked at any time.

Exercising these rights is free of charge, unless the requests are manifestly unfounded or excessive (particularly due to their repetitive nature), in which case Limitless Learning LLC may require payment of reasonable fees or refuse to comply.

When data is transferred to a third country that is not subject to an adequacy decision, the user has the right to obtain information on the appropriate safeguards governing that transfer.

Article 9 – Cookies and other trackers

9.1 Definition

Cookies are small text files or trackers placed on the user's device (computer, tablet, smartphone) when browsing the website. They allow, in particular, the website to remember certain information and track website usage.

9.2 Types of cookies used and purposes

The cookies and trackers used on the site can be classified as follows:

Cookies strictly necessary for the operation of the site 

  • Purpose: to ensure the technical operation of the site, security, navigation, shopping cart and order management, access to the member area;
  • Legal basis: Limitless Learning LLC's legitimate interest in providing a functional and secure site;
  • These cookies do not require the user's prior consent.
 

Audience measurement and statistics cookies 

  • purpose: to measure site traffic, analyze navigation paths, improve content and ergonomics;
  • legal basis:
    • either legitimate interest when the tools implemented comply with the conditions for exemption from consent defined by the CNIL (limitation of purpose, limited lifespan, absence of cross-referencing, etc.);
    • either user consent, collected via the cookie banner, when these conditions are not met or when the tool involves a transfer outside the EU.
 

Personalization and marketing cookies 

  • Purpose: personalization of content and offers, tracking of marketing emails, advertising retargeting, improvement of prospecting campaigns;
  • Legal basis: user consent, collected via the cookie banner and/or appropriate forms.

9.3 Cookie lifespan

The lifespan of cookies is limited to what is strictly necessary for the purpose pursued and cannot exceed, for cookies subject to consent, a maximum duration in accordance with the recommendations of the CNIL (in principle 13 months for audience measurement and targeted advertising trackers).

The user's choices (consent, refusal) are kept for a maximum period of 6 to 13 months, after which a new request for consent may be submitted.

9.4 Obtaining consent and setting parameters

On their first visit to the site, users are informed about the use of cookies and other tracking technologies via an information banner. They are offered the following options:

  • to accept all cookies;
  • to refuse all non-essential cookies;
  • to configure your choices by purpose (audience measurement, personalization, advertising, etc.).

The user can change their cookie preferences at any time by using: 

  • the cookie management module accessible from the website;
  • your browser settings (deleting or blocking cookies).

Refusing certain cookies may degrade the user experience but will not prevent access to the main features of the site (viewing pages, ordering training courses).

Article 10 – Procedures for exercising rights and contact

For any questions relating to this privacy policy or to exercise your rights, you can contact Limitless Learning LLC or its representative in the European Union at the following email address: [you will need to create a dedicated email address for data protection – to be completed]

Or to the representative in the European Union at the contact details indicated in Article 2.2.

In order to process the request, Limitless Learning LLC or its representative may need to verify the identity of the requester, particularly in cases of reasonable doubt (for example, by requesting a copy of an identity document).

A response will be provided within one month of receipt of the request, a period which may be extended by two months taking into account the complexity and number of requests, in accordance with Article 12 of the GDPR.

Article 11 – Right to lodge a complaint with the CNIL

If the user believes, after contacting Limitless Learning LLC, that their rights are not being respected or that the processing of their data is not in compliance with the GDPR, they can lodge a complaint with the competent supervisory authority, in particular with the Commission Nationale de l'Informatique et des Libertés (CNIL) in France.

The contact details for the CNIL are available on its website : www.cnil.fr.

Article 12 – Security Measures

Limitless Learning LLC and its subcontractors implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in order to protect data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access.

These measures may include, in particular: 

  • securing access to the site and the member area (HTTPS, hashed passwords, authorization management);
  • the logging of access and significant actions;
  • the use of hosting and service providers that comply with the GDPR and are subject to contractual obligations of security and confidentiality;
  • internal procedures for managing security incidents and regular backups.

In the event of a data breach likely to result in a high risk to the rights and freedoms of individuals, Limitless Learning LLC will inform the individuals concerned under the conditions provided for by the GDPR.

Article 13 – Link with the general terms and conditions of sale

This privacy policy supplements the information contained in the general terms and conditions of sale of the website www.methodeboclet.com . In the event of any conflict between the provisions of the general terms and conditions of sale and those of this privacy policy regarding the protection of personal data, this policy shall prevail.

The provisions relating to personal data contained in the General Terms and Conditions refer to this policy for details of processing, the rights of individuals and the methods of implementation.

Article 14 – Update to the Privacy Policy

This privacy policy may be modified at any time, in particular to take into account legislative and regulatory developments, recommendations from supervisory authorities or changes to the processing implemented.

In the event of a substantial change, users will be informed by any appropriate means (information banner on the site, email, etc.).

The applicable version is the one in effect at the time of browsing the site or placing the order.

You can not copy content of this page