Privacy Policy
This document explains what personal data we process when operating the Bytero service, on what legal basis, to whom we disclose it, and what rights you have as a data subject under Regulation (EU) 2016/679 (the "GDPR") and Slovak Act No. 18/2018 Coll. on personal data protection.
1. Controller
Andreja Trúchleho Sytnianskeho 1179/6
969 01 Banská Štiavnica, Slovak Republic
Company ID (IČO): 57 463 069 | Tax ID (DIČ): 2122775303
Registered in the Commercial Register of the District Court Banská Bystrica, section: Sro, insert no. 55164/S
The controller's contact details are available on the Contact page. The controller is not obliged to appoint a data protection officer (DPO) under Art. 37 GDPR.
2. What data we process
2.1 Registration and profile data
- E-mail address, name, optionally a profile picture (when signing in via a federated identity provider).
- Password - stored exclusively as a one-way hash, never in plain form.
- Security tokens (e.g. for e-mail verification or password reset) with a short validity period.
2.2 Usage data
- Saved filters, favourites and account settings.
- Data the User voluntarily enters within their plan.
- Technical logs - IP address, user agent, timestamp, endpoint and response code.
2.3 Payment data
- Billing details (name, address, company/tax ID for businesses) needed to issue a tax document.
- Payment details (amount, currency, date, transaction identifier). We do not store the payment card number or CVV - these are processed exclusively by the payment gateway provider.
2.4 Automated technologies
- Cookies and similar technologies for functional, analytical and possibly marketing purposes (see section 8).
- Anonymized traffic analytics and performance metrics.
3. Purposes and legal bases of processing
- Providing the Service and performing the contract (Art. 6(1)(b) GDPR) - creating and managing the account, authentication, providing plan features.
- Legal obligations (Art. 6(1)(c) GDPR) - accounting, archiving tax documents, responding to requests from public authorities.
- The controller's legitimate interests (Art. 6(1)(f) GDPR) - security, abuse prevention, debugging, direct marketing to existing clients, developing and improving the Service.
- Consent (Art. 6(1)(a) GDPR) - marketing communication to persons who are not clients, non-essential cookies, newsletter. Consent can be withdrawn at any time.
4. Retention periods
- Registration data and account content - for the duration of the active account and a reasonable period after its deletion, in case of restoration or dispute resolution.
- Billing documents - for the period required by accounting legislation.
- Technical logs - for a reasonable period necessary to secure operations, then deletion or anonymization.
- Consent-based marketing - until you withdraw consent or the purpose of processing ends.
- Security tokens - only for their short validity period, deleted immediately after use.
After the period expires, the data is deleted or anonymized so that a specific person can no longer be identified.
5. Recipients and processors
Personal data is accessible only to the controller's authorized staff and to processors who process data on our behalf and are bound by a data processing agreement under Art. 28 GDPR. These are mainly the following categories:
- cloud hosting and data infrastructure providers,
- e-mail service providers (transactional messages such as e-mail verification or password reset),
- traffic analytics providers (deployed only to the extent permitted by the selected cookie settings),
- payment service providers - for paid plans.
The controller will provide the current list of specific processors to the data subject on request. We do not provide personal data to third parties for marketing purposes, nor do we sell it. We may disclose it only to public authorities on the basis of a legal obligation.
6. Transfers outside the EU
To the extent that some processors operate outside the European Economic Area, transfers take place in accordance with Art. 44-46 GDPR - in particular on the basis of Commission adequacy decisions, Standard Contractual Clauses and appropriate technical and organizational measures.
7. Your rights
As a data subject, under the GDPR and Act No. 18/2018 Coll. you have in particular the following rights:
- Right of access (Art. 15) - confirmation of processing and a copy of your data.
- Right to rectification (Art. 16) - correction of inaccurate or incomplete data.
- Right to erasure / "to be forgotten" (Art. 17) - deletion of data that is no longer needed or where you withdraw consent.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) - obtaining your data in a structured, machine-readable format.
- Right to object (Art. 21) - to processing based on legitimate interest or direct marketing.
- Right to withdraw consent (Art. 7(3)) - at any time, without affecting the lawfulness of processing before the withdrawal.
- Right not to be subject to automated decision-making (Art. 22), including profiling with legal or similarly significant effects. The Service's analytical outputs are informational and are not decisions with legal effects on the User.
- Right to lodge a complaint with the supervisory authority - Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.
You can exercise your rights via the contact listed on the Contact page. We will handle the request within the period set by the GDPR. Identity verification may be part of processing the request.
8. Cookies and similar technologies
Bytero uses the following categories of cookies:
- Essential - for the basic functioning of the Service (sign-in, language preference). Legal basis: legitimate interest or performance of the contract.
- Analytical - for traffic measurement. Deployed only on the basis of consent.
- Marketing - only with consent; they let us evaluate campaign effectiveness.
You can adjust or withdraw consent to non-essential cookies at any time via your browser settings or by contacting the controller.
9. Security
We have adopted appropriate technical and organizational measures to protect personal data:
- encryption of data in transit (HTTPS/TLS),
- passwords stored exclusively as one-way hashes,
- account abuse prevention mechanisms,
- data minimization and pseudonymization where possible,
- access control on a need-to-know basis,
- regular monitoring of security vulnerabilities.
In the event of a personal data breach that could lead to a high risk to the rights of data subjects, we proceed in accordance with Art. 33 and 34 GDPR.
10. Children
The Service is not intended for persons under 16 years of age. We do not knowingly process children's personal data. If we discover that we have obtained such data, we delete it without delay.
11. Changes to this document
We may update this document. In the event of material changes we inform users in an appropriate manner, reasonably in advance. The current version is always available on the Privacy page.
12. Contact
Questions or a request? Contact details are available on the Contact page.






