GDPR Compliance
Last updated: 2025
BytesCrafter is committed to protecting the personal data of every visitor and client, including those located in the European Economic Area (EEA) and the United Kingdom. This GDPR Compliance statement explains how we meet our obligations under the EU General Data Protection Regulation (GDPR) and the UK GDPR, and the rights those regulations give you over your personal data.
Scope of this statement
The GDPR applies whenever we process the personal data of individuals in the EEA or the UK, regardless of where BytesCrafter is located. Where the GDPR applies, it supplements — and does not replace — the protections described in our Privacy Policy.
Data controller
For personal data collected through this website, BytesCrafter IT Solutions acts as the data controller. If you have any questions about this statement or how we handle your data, you can reach us at [email protected].
Lawful bases for processing
We only process personal data where we have a lawful basis to do so. Depending on the context, we rely on one or more of the following:
- Consent — for example, when you opt in to marketing emails or accept non-essential cookies. You may withdraw consent at any time.
- Contract — where processing is necessary to provide a service you have requested or to take steps at your request before entering into a contract.
- Legitimate interests — to operate, secure, and improve our website and services, provided your rights do not override those interests.
- Legal obligation — where we must process data to comply with applicable law.
Your rights under the GDPR
If you are located in the EEA or the UK, you have the following rights over your personal data:
- The right to be informed about how your data is collected and used.
- The right of access to the personal data we hold about you.
- The right to rectification of inaccurate or incomplete data.
- The right to erasure (the “right to be forgotten”) where there is no overriding reason to keep it.
- The right to restrict processing in certain circumstances.
- The right to data portability — to receive your data in a structured, machine-readable format.
- The right to object to processing based on legitimate interests or direct marketing.
- Rights related to automated decision-making and profiling.
How to exercise your rights
You can exercise any of these rights by contacting us at [email protected]. We will respond to your request within one month, as required by the GDPR. We will not charge a fee unless your request is manifestly unfounded or excessive.
International data transfers
BytesCrafter operates from the Philippines, so personal data collected from EEA or UK visitors may be transferred outside the EEA/UK. Where we make such transfers, we put appropriate safeguards in place — such as Standard Contractual Clauses — to ensure your data continues to receive an adequate level of protection.
Data retention
We keep personal data only for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements. When data is no longer needed, we securely delete or anonymise it.
Cookies and consent
We use cookies and similar technologies as described in our Privacy Policy. Non-essential cookies are only set with your consent, which you can manage or withdraw at any time through your browser settings or our cookie controls.
Right to lodge a complaint
If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with your local supervisory authority. We would, however, appreciate the chance to address your concerns first — please contact us at [email protected].
Empowering Businesses with Customized Software Solutions
Tell us what you need — we typically reply within the day. Let’s build something that drives your business forward.