Privacy

What we hold, why, and for how long.

This notice is written in plain English for a small company and should be reviewed by a solicitor before you rely on it. It is not legal advice. Subject to that, it describes honestly how Echobyt handles personal data: we collect little, we keep it only while it is useful, and we tell you where in the world it is accessed from.

01

Who we are, and where the work happens

Echobyt is the controller for the personal data described in this notice. The controlling entity is the UK company, based in London, England, and it is the counterparty on any contract you sign with us. Our engineering and delivery team is located in Dhaka, Bangladesh. That means personal data you send us, and personal data inside systems we are engaged to work on, may be accessed by our delivery team outside the United Kingdom. We treat those transfers as restricted transfers and rely on appropriate safeguards, including the UK International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses, together with access controls that limit personal data to the people who need it for the engagement. Bangladesh is not covered by UK adequacy regulations, so we do not rely on adequacy. If you would like detail on the safeguards in place for a specific engagement, write to hello@echobyt.com and we will describe them.

02

The data we collect

From enquiries: your name, email address, company name where you give it, and whatever you write in the message, including any description of your business or workflow. From calls and correspondence: notes we take about your requirements, the people involved, and what was agreed. From engagements: contact details for the people we work with, plus billing and contract information. From the website: aggregate, privacy-respecting usage measurement as described in section 07. We do not ask for special category data, and we ask you not to send it in an enquiry. We do not buy contact lists and we do not enrich your record from third-party data brokers.

03

Why we hold it, and our lawful basis

To reply to your enquiry and assess whether we are a fit: legitimate interests, in responding to someone who contacted us about our services. To carry out a diagnostic or a build: performance of a contract, or steps taken at your request before entering one. To send invoices and keep accounting records: legal obligation, and legitimate interests in running the business. To keep security and delivery logs: legitimate interests in operating reliable systems. To publish a case study: your consent, given separately and in writing, which you may withdraw. We do not use your enquiry as the basis for a marketing sequence. If you receive anything from us that is not a direct reply, tell us and it will stop.

04

Personal data inside client systems

A diagnostic and a build usually involve access to a client's inbox, CRM or documents, which contain personal data about that client's own customers and staff. For that data the client is the controller and Echobyt acts as a processor, working only on the client's documented instructions under a written processing agreement covering scope of access, confidentiality, security measures, sub-processors, the location of the delivery team, breach notification, and deletion or return at the end of the engagement. We take read-only access where read-only access is enough. We do not copy client datasets onto local machines when we can work in place, and we do not use client data to train models.

05

How long we keep it

Enquiries that do not lead to a call: deleted within twelve months. Enquiries that lead to a call but not an engagement: kept for up to twenty-four months, so we can pick up the conversation if you return, then deleted. Engagement records, contracts and correspondence: kept for the duration of the engagement and then for six years, to meet UK statutory and tax retention requirements. Access to client systems: revoked at the end of the engagement, and any working copies of client data deleted, with a written confirmation on request. Where something must be kept for legal reasons we keep only what the obligation requires.

06

Who we share it with

We use a small number of service providers to run the business: email and document hosting, a website host, an error and uptime monitoring service, an accounting provider, and payment processing for invoices. Each acts under contract and processes data only for the purpose we set. We do not sell personal data, we do not share it with advertising networks, and we do not disclose client information to anyone outside these arrangements except where we are legally required to. A current list of our processors is available on request from hello@echobyt.com.

07

Website measurement

We want to know which pages are read, not who reads them. Our analytics posture is deliberately minimal: aggregate page and referrer counts, no advertising or cross-site tracking pixels, no profiles built about individual visitors, and no selling of usage data. We do not set non-essential cookies for advertising. The cookie notice explains in detail what is and is not set, and how any choice available to you is presented.

08

Security

Access to systems holding personal data is restricted to the people who need it, protected by strong authentication, and reviewed when someone's role changes or an engagement ends. Devices used for delivery are encrypted. Credentials for client systems are held in a managed secret store rather than in documents or messages, and are rotated or revoked at handover. We log administrative access. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the Information Commissioner's Office within seventy-two hours where required, and tell you without undue delay where the risk is high.

09

Your rights

Under UK data protection law you may ask for a copy of the personal data we hold about you, ask us to correct it if it is wrong, ask us to delete it, ask us to restrict how we use it, object to processing we carry out on the basis of legitimate interests, ask us to transfer it to you or another provider in a portable form, and withdraw any consent you have given. Write to hello@echobyt.com and we will respond within one month. There is no charge. Where the request concerns data inside a client's systems, we will pass it to that client as the controller and support them in answering it.

10

Complaints, and changes to this notice

If you are unhappy with how we have handled your personal data, tell us first at hello@echobyt.com so we have a chance to put it right. You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk. We update this notice when our processing changes, and the revision date below always reflects the current version. Material changes affecting people we already hold data about will be communicated directly.

Last updated · July 2026