Privacy Policy
Last updated: 23 August 2026
86 bytes CommV (“86 bytes”, “we”), registered in Belgium [registered office address], operates the 86bytes website (86bytes.com) and the 86 bytes application (your workspace on 86bytes.com) — an invoice follow-up service for small and medium-sized businesses. This policy explains what personal data we process, why, and the rights you have. For privacy questions or requests, contact privacy@86bytes.com.
Our two roles
We process personal data in two distinct capacities, and your rights route differently depending on which applies:
- As controller — for data about our own users and prospects: your account details, sign-in data, waitlist registrations, and correspondence with us.
- As processor — for the business data our customers process through the service: their invoices, their customers’ (debtors’) contact and payment details, connected mailbox content, and bank transactions. For that data, our customer — the business using 86 bytes — is the controller, and we act on their instructions under a data processing agreement. If you are a customer of one of our customers (for example, you received a payment reminder), please direct privacy requests to that business; we assist them in fulfilling your rights.
What we process, and why
- Account and waitlist data — name, email address, company name, sign-in credentials (passwords are stored hashed) — to provide access to the service and to contact you about it.
- Connected mailbox data — when a customer connects their own mailbox (Microsoft, Google, or IMAP), we detect invoice emails, send payment reminders from that mailbox, and match replies to those reminders back to the related invoice. We do not provide general inbox management, and we only store what this requires: message metadata, invoice-related messages and attachments, and reminder threads.
- Bank transaction data — read-only account and transaction information, accessed via Ponto Connect (Ibanity, Isabel Group) under PSD2 account-information access, used solely to match incoming payments to invoices. This bank connection is read-only: we cannot move money from a connected account. (Subscription fees for the service itself are a separate, explicit payment relationship handled by our payment provider — see below.)
- Subscription billing data — the billing details a customer provides for their own subscription (legal name, address, VAT number) and records of subscription charges and invoices. Payment credentials (card or bank mandate details) are collected and stored by our payment provider Adyen, never by us; we store only a tokenized reference. No payment method is collected during the free trial.
- Invoice and debtor data — structured data extracted from invoice documents (invoice number, amounts, due dates, payment references) and the linked customer records (name, email, VAT number, IBAN), used to track invoices and send compliant payment reminders.
- AI-assisted processing — we use large language models to extract data from invoice documents, to fill limited personalization into pre-approved reminder templates, and to power the in-app assistant. Every AI interaction is logged (what was processed, when, at what cost) so processing remains reconstructable. Our AI providers are contractually prohibited from training models on this data.
- Operational logs — audit logs of actions taken in the service (including every automated reminder and the authorization behind it) and access logs for sensitive data, kept for security and accountability.
Legal bases
Where we act as controller: performance of a contract (providing the service), legitimate interest (service security, preventing abuse, improving the service), and consent where required (e.g. the waitlist). Where we act as processor, the controller — our customer — determines the legal basis; for payment reminders this is typically their legitimate interest in collecting what they are owed, exercised within the limits of applicable debt-collection law (in Belgium, Book XIX of the Code of Economic Law).
Who we share data with (subprocessors)
- Amazon Web Services — hosting and storage, EU region.
- OpenRouter, Inc. — AI model routing. Requests are restricted to model endpoints that do not retain or train on submitted data.
- Anthropic — AI models, where used directly, under terms that prohibit training on customer data.
- Isabel Group (Ibanity / Ponto Connect) — bank account information access (PSD2).
- Adyen N.V. — payment processing for subscription fees (EU, PCI-DSS certified). Adyen receives the payment details the customer enters at checkout and processes recurring subscription charges.
- Microsoft / Google — only when a customer connects a mailbox hosted there; access is limited to the scopes the customer grants and can be revoked by them at any time.
We do not sell personal data, and we do not use it for advertising.
International transfers
Our infrastructure runs in the European Union. AI processing may involve providers or model endpoints outside the EU depending on the models in use; where that is the case, transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
Security
Each customer’s data lives in its own isolated database. Data is encrypted in transit and at rest; particularly sensitive fields are additionally encrypted at the application level. Credentials and integration tokens are held in a managed secrets store, never in application configuration. Access to sensitive data is logged.
Retention and deletion
Data is retained per data type under configurable retention policies and deleted by automated processes when the retention period lapses. Customers can request erasure of a person’s data; where a legal obligation requires retaining specific records (for example, evidence of a sent reminder), that exception is recorded and justified, never silent. When a customer leaves the service, their data is exported on request and then deleted.
Cookies
The application uses a single session cookie required for sign-in. On the application’s billing page, our payment provider Adyen loads its checkout component, which may set cookies strictly for payment processing and fraud prevention. We use no advertising or cross-site tracking cookies, and no third-party analytics on this website.
Your rights
Under the GDPR you can request access to, rectification or erasure of your personal data, restriction of or objection to its processing, and a portable copy. Write to privacy@86bytes.com; we respond within one month. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, dataprotectionauthority.be) or your local supervisory authority.
Changes
We will update this policy as the service evolves and note the date of the latest revision above. Material changes affecting our customers are announced to them directly.