Privacy Policy

86 bytes CommV (“86 bytes”, “we”), registered in Belgium [registered office address], operates the 86bytes website (86bytes.com) and the 86 bytes application (your workspace on 86bytes.com) — an invoice follow-up service for small and medium-sized businesses. This policy explains what personal data we process, why, and the rights you have. For privacy questions or requests, contact privacy@86bytes.com.

Our two roles

We process personal data in two distinct capacities, and your rights route differently depending on which applies:

What we process, and why

Legal bases

Where we act as controller: performance of a contract (providing the service), legitimate interest (service security, preventing abuse, improving the service), and consent where required (e.g. the waitlist). Where we act as processor, the controller — our customer — determines the legal basis; for payment reminders this is typically their legitimate interest in collecting what they are owed, exercised within the limits of applicable debt-collection law (in Belgium, Book XIX of the Code of Economic Law).

Who we share data with (subprocessors)

We do not sell personal data, and we do not use it for advertising.

International transfers

Our infrastructure runs in the European Union. AI processing may involve providers or model endpoints outside the EU depending on the models in use; where that is the case, transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

Security

Each customer’s data lives in its own isolated database. Data is encrypted in transit and at rest; particularly sensitive fields are additionally encrypted at the application level. Credentials and integration tokens are held in a managed secrets store, never in application configuration. Access to sensitive data is logged.

Retention and deletion

Data is retained per data type under configurable retention policies and deleted by automated processes when the retention period lapses. Customers can request erasure of a person’s data; where a legal obligation requires retaining specific records (for example, evidence of a sent reminder), that exception is recorded and justified, never silent. When a customer leaves the service, their data is exported on request and then deleted.

Cookies

The application uses a single session cookie required for sign-in. On the application’s billing page, our payment provider Adyen loads its checkout component, which may set cookies strictly for payment processing and fraud prevention. We use no advertising or cross-site tracking cookies, and no third-party analytics on this website.

Your rights

Under the GDPR you can request access to, rectification or erasure of your personal data, restriction of or objection to its processing, and a portable copy. Write to privacy@86bytes.com; we respond within one month. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, dataprotectionauthority.be) or your local supervisory authority.

Changes

We will update this policy as the service evolves and note the date of the latest revision above. Material changes affecting our customers are announced to them directly.