Privacy policy
Last updated: August 12, 2026.
Who we are, and what this policy covers
Bytefactory LLC (“bytefactory”, “we”, “us”) is a limited liability company registered in Wyoming, United States. This policy explains how we handle personal data collected through bytefactory.cc — our website and the contact form on it.
It does not cover personal data we process during a client engagement. When we build, modernize, or operate systems for a client, that client decides what data is collected and why. We act on their documented instructions as a processor (a “service provider” under US state privacy laws), and the master services agreement and data processing addendum we sign with them govern that work instead of this page. If you are an end user of a system we built for someone else, their privacy policy is the one that applies to you.
Controller for the purposes of this policy:
Bytefactory LLC, 1000 Brickell Avenue, Suite #715 PMB 153, Miami, FL 33131, United States
hello@bytefactory.cc
What we collect, why, and on what legal basis
Contact form submissions
What: your name, email address, company name, and the content of your message.
Why: to read and respond to your enquiry, and — if it leads to work — to set up and manage the engagement.
Legal basis (where the GDPR or UK GDPR applies): where your message is a request to take steps toward a contract, Article 6(1)(b). Otherwise, our legitimate interest under Article 6(1)(f) in receiving and responding to business enquiries about our services. You can object to processing based on legitimate interest at any time — see Your rights.
Retention: 24 months after our last exchange with you. If the enquiry becomes an engagement, we keep the correspondence for the duration of that engagement and for 7 years afterwards, where we need it for tax, contractual, professional-records, or legal-claim purposes.
Server logs
What: IP address, browser user-agent string, the URL requested, timestamp, and referring page.
Why: to keep the site available, diagnose faults, and detect and investigate abuse.
Legal basis (where the GDPR or UK GDPR applies): our legitimate interest under Article 6(1)(f) in the security and reliable operation of our own website. We do not use these logs to build profiles of visitors or to target advertising.
Retention: generally retained for up to 90 days, after which they are deleted.
What we do not do
We do not sell or share personal data, as those terms are defined under US state privacy laws — including “sharing” for cross-context behavioural advertising. We do not use personal data collected through this site for advertising, profiling, or automated decision-making that produces legal or similarly significant effects.
Please don’t send us sensitive information through the form
The contact form is for initial enquiries, and it reaches us by ordinary email. Please don’t put health or patient information, customer records, credentials, API keys, financial account numbers, or other sensitive material into it.
If your project involves data like that — and much of the work we do does — describe the problem in general terms and say so. We will set up an appropriate channel and put the necessary agreements in place before anything sensitive changes hands.
Cookies and analytics
This site sets no cookies, which is why you see no cookie banner.
We measure traffic with Umami, a privacy-focused analytics tool loaded from Umami Cloud. It uses no cookies and stores nothing on your device. It records page views, the referring page, browser and operating system, device type, and country. Your IP address is used transiently to derive that country and a salted daily hash, and is not stored; the hash cannot be linked back to you and expires within a day. We use these aggregated statistics — on the legal basis of our legitimate interest in understanding how the site is used — and nothing in them identifies you.
Beyond that, the site loads no third-party scripts or fonts; the only other request it makes to a third party is delivering your message to Formspree when you submit the contact form. If any of this changes, we will update this policy before deploying the change, name the tool and what it collects, and — where consent is legally required — ask for your consent before it runs rather than after.
Who else your data reaches
We use a small number of service providers to run this site and our email:
| Provider | What they handle | Location |
|---|---|---|
| DigitalOcean | Website hosting and server logs | United States |
| Formspree | Contact form delivery and storage of submissions | United States |
| ImprovMX | Inbound routing for our @bytefactory.cc email addresses | France |
| Google (Gmail) | Where our correspondence is stored and read | United States |
| Umami Cloud | Cookieless, aggregated website analytics | United States |
Each of them processes personal data only on our documented instructions, under a data processing agreement we have entered into with them.
We do not disclose personal data to anyone else, except where we are legally required to, or where we need to establish, exercise, or defend a legal claim. If we are ever compelled to disclose your data, we will tell you unless we are legally prohibited from doing so. If we are ever party to a merger, acquisition, or sale of the business, personal data may transfer as part of it, and we will note that on this page before it takes effect.
International transfers
Our website hosting and our mailbox are located in the United States; ImprovMX routes our inbound email through datacenters in France. If you contact us from the EEA, the United Kingdom, or Switzerland, your personal data is transferred to the United States and processed there.
For those transfers we rely on the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where the UK GDPR applies), or on a provider’s certification under the EU–US Data Privacy Framework where they hold one. You can request a copy of the relevant safeguards by writing to hello@bytefactory.cc.
How we protect your data
- The site is served over HTTPS using TLS 1.2 or above, with HSTS enabled.
- Contact form submissions are encrypted in transit between your browser and Formspree.
- Data held by our providers is encrypted at rest using their platform encryption.
- Access to our mailbox and to provider dashboards is limited to the people who need it, and is protected by multi-factor authentication.
- We review what we hold and delete correspondence that has passed its retention period.
One honest limitation: email between mail servers uses opportunistic TLS, which we cannot guarantee from end to end. That is a property of email itself rather than of our setup, and it is the main reason we ask you not to send sensitive material through the contact form.
No system is completely secure, and we cannot guarantee absolute security — but if a breach affecting your personal data occurs, we will notify you and the relevant authorities where the law requires it.
Your rights
Subject to the law that applies to you, you can ask us to:
- Access the personal data we hold about you, and get a copy of it
- Correct anything inaccurate or incomplete
- Delete it
- Export it in a portable, machine-readable format
- Restrict how we process it
- Object to processing we carry out on the basis of legitimate interest
If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your data protection supervisory authority. In the EEA you can find yours through the European Data Protection Board at edpb.europa.eu; in the UK it is the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you are not required to.
If you are in a US state with a comprehensive privacy law, you have rights to know, delete, and correct, and to opt out of the sale or sharing of your data and of targeted advertising — we do none of those things. You may use an authorized agent to make a request, and we will not treat you differently for exercising any of these rights. If we decline a request, you can appeal by replying to our decision with “appeal” in the subject line; we will respond to an appeal within 45 days.
How to exercise any of this: email hello@bytefactory.cc. We will acknowledge your request promptly and respond within one month. If the request is complex, we may extend that by up to two further months, and we will tell you within the first month if we do. There is no charge, unless a request is manifestly unfounded or excessive. We may ask you for enough information to confirm your identity, and we will use whatever you provide for that purpose only.
Children
This site is aimed at businesses, not children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States). If you believe a child has sent us personal data, write to hello@bytefactory.cc and we will delete it.
EU and UK representative
We have no establishment in the EEA or the United Kingdom. Our processing of data belonging to people there is occasional, does not involve special category data on any significant scale, and is unlikely to result in a risk to their rights and freedoms, so we rely on the exemption in Article 27(2) GDPR and have not appointed a representative. For any GDPR or UK GDPR matter, write to hello@bytefactory.cc.
Changes to this policy
We will post any changes on this page and update the date at the top. Where a change materially affects how we handle your personal data, we will say so prominently rather than relying on you to notice the date.
Contact
Bytefactory LLC
1000 Brickell Avenue, Suite #715 PMB 153, Miami, FL 33131, United States
hello@bytefactory.cc