Privacy policy
At DigitalBye we take privacy very seriously — it is, after all, our business. This policy explains what data we process, why, and what rights you have, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable local law.
1. Data controller
Controller: the DigitalBye brand, email [email protected]. The controller’s full identification details are provided in writing before any service is contracted.
2. What data we collect and why
We only collect the data you provide in our forms: name, phone number, email, country and a description of your case. We process it for the following purposes:
— To respond to your enquiry or diagnosis request (Article 6(1)(a) GDPR: consent).
— To provide the contracted service (Article 6(1)(b) GDPR: contract performance).
— To comply with legal obligations (Article 6(1)(c) GDPR).
We do not use your data for any other purpose and we do not share it with third parties, except where required by law or necessary to provide the service (for example, email tools). Where third-party providers are involved, we limit access to what is strictly necessary and, for transfers outside the EEA, we apply the appropriate GDPR safeguards (for example, standard contractual clauses).
3. Retention
We keep your data only for as long as necessary for the purposes described and, in any case, for the applicable legal limitation periods. Lead data is kept for commercial management and deleted once no longer needed. Case documentation is encrypted in transit and at rest, and is automatically purged once the engagement ends or the legal retention period expires.
4. Cookies and analytics
This website uses GoatCounter, an analytics tool that does not use cookies and does not identify users: it only collects aggregated visit data (page views, browser, approximate country). You can read its policy at goatcounter.com.
5. Your rights
You may exercise at any time your rights of access, rectification, erasure, objection, restriction of processing and data portability, by writing to [email protected]. You also have the right to complain to your national data protection authority (for example, AEPD in Spain, CNPD in Portugal, ICO in the UK).
6. Security
All information is transmitted encrypted (TLS) and stored encrypted at rest, on servers with restricted access. Access to case information is limited to the people involved in processing it, under confidentiality obligations. Providers with access to data are limited to those strictly necessary to provide the service. When the engagement ends, documentation is deleted or anonymised in accordance with the retention period in section 3.