Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how ByteTech OÜ ("ByteTech", "we", "us") collects, uses, stores, and protects your personal data when you visit our website or use our services. We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.
1. Who we are
ByteTech OÜ ("ByteTech", "we", "us", or "the Company") is a software studio registered in Tallinn, Estonia, acting as the data controller for personal data processed through this website. You can reach our Data Protection contact at support@bytetech.ee.
2. What personal data we collect
We only collect data that is necessary for the purposes described in this policy. This may include: (a) contact details you provide voluntarily — name, email address, company, and message — when you use our contact form or email us; (b) communications data, such as the content of your enquiries and our responses; (c) technical data collected automatically, including IP address, browser type and version, device information, pages visited, referring URLs, and timestamps; and (d) consent and preference data, such as your cookie choices.
3. How we collect your data
We collect data in three ways: directly when you submit information via our forms or email us; automatically when you browse the site (through cookies and similar technologies); and from third parties where necessary to deliver our services, such as analytics or hosting providers acting as data processors on our behalf.
4. Why we use your data (purposes)
We process your data to: respond to your enquiries and provide the services you request; operate, maintain, and improve our website; analyze usage and measure performance; ensure security and prevent fraud; meet our legal, accounting, and reporting obligations; and where you have consented, send you marketing or newsletter communications. You can withdraw marketing consent at any time using the unsubscribe link or by contacting us.
5. Legal basis for processing (GDPR Art. 6)
We rely on the following legal bases: (a) your consent, for cookies, analytics, and marketing; (b) performance of a contract or pre-contractual steps, when you request a service or quote; (c) our legitimate interests, to respond to enquiries, operate and improve our business, and ensure security, balanced against your rights; and (d) compliance with legal obligations, such as tax and record-keeping requirements.
6. Cookies and similar technologies
We use cookies and similar technologies to operate the site and, with your consent, to understand how it is used. Essential cookies are required for the site to function and cannot be disabled. Analytics and optional cookies are only set after you accept them via the cookie banner. You can change your choice at any time through the banner or your browser settings. Most browsers let you refuse or delete cookies; doing so may affect some site features.
7. Analytics
If you accept analytics cookies, we may use third-party analytics tools to collect aggregated, pseudonymized, or anonymized usage data. These providers process data as our data processors under written agreements and do not use the data for their own purposes without your consent. Where a provider is based outside the EEA, we rely on a valid transfer mechanism (see Section 10).
8. Sharing your data
We do not sell your personal data. We may share data with: (a) trusted service providers acting as processors — such as hosting, email, analytics, and payment providers — under written agreements and only for specified purposes; (b) competent authorities or third parties where required by law, court order, or to protect our rights, safety, or property; and (c) successors in the event of a merger, acquisition, or sale of our business assets, subject to confidentiality.
9. International data transfers
Because we and our providers may operate internationally, your data may be processed in countries outside the European Economic Area. Where this occurs, we ensure an adequate level of protection through an adequacy decision by the European Commission, Standard Contractual Clauses (SCCs), or another valid transfer mechanism under Chapter V of the GDPR, and we apply additional safeguards where required.
10. Data retention
We keep personal data only as long as necessary for the purposes set out in this policy or as required by law. Contact and enquiry data is typically retained for the duration of the relationship plus a reasonable period for record-keeping. Analytics and cookie data is kept in anonymized, pseudonymized, or aggregated form. You can request early deletion of your data subject to legal retention obligations.
11. Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), access controls, regular reviews, and secure hosting. No method of transmission or storage is completely secure, but we take reasonable steps to safeguard your information against unauthorized access, loss, misuse, or alteration.
12. Data breaches
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where the risk is high, communicate the breach to affected individuals as required by Articles 33 and 34 of the GDPR.
13. Automated decision-making and profiling
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not engage in profiling for such purposes.
14. Children's privacy
Our website and services are intended for businesses and professionals and are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.
15. Your rights under the GDPR
Subject to applicable conditions, you have the right to: access your personal data; rectify inaccurate data; erase your data (the right to be forgotten); restrict processing; data portability; object to processing based on legitimate interests or for direct marketing; withdraw consent at any time without affecting prior lawful processing; and lodge a complaint with the Estonian Data Protection Inspectorate (andmeinspektsioon, aki.ee) or your local supervisory authority. To exercise these rights, contact us at support@bytetech.ee. We will respond within one month, extendable by two months for complex requests.
16. Links to third-party websites
Our site may contain links to third-party websites that we do not control. We are not responsible for the privacy practices or content of those sites and encourage you to review their privacy policies.
17. Updates to this policy
We may update this policy from time to time to reflect changes in our practices, technologies, or legal requirements. We will post the updated version on this page and revise the 'Last updated' date. Where changes are significant, we may provide a more prominent notice. We encourage you to review this page periodically.
18. Contact
For any questions, requests, or complaints regarding your personal data or this policy, contact ByteTech OÜ at support@bytetech.ee, or by post at the address listed on our website. The supervisory authority in Estonia is the Data Protection Inspectorate (aki.ee).
