Privacy Policy
The short version
We collect very little. If you fill in the contact form or book a call, we get your name, your email address, your company if you type one, and what you wrote. We use it to reply to you and to hold the call. That is all.
We run no analytics on this site. No advertising pixels, no tracking cookies, no session recording, no profiling. We do not sell or rent your data to anyone.
The rest of this page is the detail, because the law asks for it and because you should be able to check what we say.
Who is responsible for your data
The controller is Bycause.ai, operated by Matvey Bykovskiy.
Email: matvey@bycause.ai Website: https://bycause.ai
We have not appointed a Data Protection Officer. Given our size and the small amount of personal data we handle, we do not believe Article 37 GDPR requires one.
Anything about privacy goes to matvey@bycause.ai.
What we collect, and when
Contact form, on the contact page. Your name, your email address, your company name if you choose to enter one, and the message you write.
Booking form, on the booking page. Your name, your email address, your company name if you choose to enter one, the date and time slot you pick, and the timezone your browser reports, for example Europe/Madrid. We store the timezone so nobody turns up an hour late.
Email you send us directly. If you write to matvey@bycause.ai we hold your address and whatever you sent.
Technical data. Our host writes standard server logs when a page or a function is requested. These normally include the IP address, the time, what was requested, and the browser user agent. We do not connect this to form submissions and we do not use it to identify anyone.
That is the complete list. There is no account to create, no password, and no payment information collected anywhere on this site. We do not run analytics, advertising pixels, heatmaps, session recording, or any other tracker. We checked the site code before writing this page to make sure that is true.
Why we are allowed to use it
For the contact form and the booking form, the basis is Article 6(1)(b) GDPR: steps taken at your request before entering into a contract. You are asking about work we might do for you, and we cannot answer or hold a slot without your details.
If your message is not about possible work together, the basis is Article 6(1)(f) GDPR: our legitimate interest in answering people who write to us. You can object to that at any time and we will stop.
The confirmation email you receive, and the notification we receive ourselves, sit on the same basis. Both are part of handling your enquiry, not separate marketing.
For server logs, the basis is Article 6(1)(f) GDPR: our legitimate interest in keeping the site running and protecting it from abuse.
For the fonts loaded from Google, see that section further down. The basis there is Article 6(1)(f) GDPR, and there is a decision for us to make about it.
We do not send marketing newsletters from this site and there is no mailing list to join.
We do not use your data for automated decision-making or profiling in the sense of Article 22 GDPR. A person reads every enquiry.
Giving us your details is voluntary. If you would rather not, we simply cannot reply or book you in.
Who else handles your data
The list is short on purpose. Supabase, Vercel, and Resend act as processors on our instructions under Article 28 GDPR. Telegram is a different case and we explain that below.
Supabase, for the database. Your form entry is written into our database directly from your browser, which means Supabase also receives your IP address at that moment.
Vercel, for hosting the site and running the small function that sends the notifications. Vercel Inc. is a United States company.
Resend, for email. It sends the notification to us and the confirmation to you. Resend is a United States company.
Telegram, for notifications. We get a Telegram message when someone submits a form so nothing is missed. For a contact form the message currently contains your name, email address, company, and the text you wrote. For a booking it contains your name, email address, company, and the slot and timezone you picked. Telegram is a messaging service we use, not a processor we hold an Article 28 contract with, and it is operated outside the EU.
Where a provider is outside the EU or the EEA, the transfer relies on the European Commission Standard Contractual Clauses, or on an adequacy decision where one applies.
We do not sell your data, we do not share it with advertisers, and we do not pass it to anyone else unless the law requires it.
How long we keep it
Enquiries and bookings that do not lead to work together: 12 months, then we delete them.
If we do end up working together, your details become part of the client file. We keep those for as long as the contract runs, then for the period commercial and tax law requires.
Telegram notifications sit in a chat history until that chat is cleared.
Server logs are kept by our host for a short period as part of normal operation.
You can ask us to delete your data sooner. The next section says how.
Your rights
Under the GDPR you can:
Ask what we hold about you and get a copy of it (Article 15). Have anything wrong or incomplete corrected (Article 16). Have your data deleted (Article 17). Ask us to pause processing while a question is being sorted out (Article 18). Receive your data in a structured, commonly used, machine readable format, or have it sent to another provider (Article 20). Object to anything we base on legitimate interest (Article 21). If you object, we stop, unless we have compelling grounds that override yours.
Email matvey@bycause.ai and say which one you want. We reply within one month, as Article 12(3) requires. There is no charge.
You can also complain to a data protection authority, either where you live or work, or where you think something went wrong. Two that are relevant to us:
Commission nationale pour la protection des données (CNPD), Luxembourg. www.cnpd.lu Agencia Española de Protección de Datos (AEPD), Spain. www.aepd.es
Cookies and local storage
This site sets no cookies. Not ours, not anyone else's. No analytics cookies, no advertising cookies, and therefore no consent banner, because there is nothing to consent to.
We store exactly one thing in your browser local storage: a key called lang holding your language choice, for example en or es. It stays until you clear your browser data. It is there so the site opens in the language you picked last time. It holds no identifier, it is not shared, and it never leaves your browser.
If we ever add analytics, we will ask you first and rewrite this section.
Fonts are loaded from Google
The site uses three typefaces, Plus Jakarta Sans, DM Sans, and JetBrains Mono, served from Google Fonts. Your browser fetches them from Google servers when a page loads. That request carries your IP address to Google, along with your browser and operating system details, and it happens before you have clicked anything.
We are telling you because it is easy to miss and because a German court has treated it as a problem when it happens without a proper basis.
Our basis for it is Article 6(1)(f) GDPR: our legitimate interest in the site rendering consistently across devices.
Google explains its own handling here: policies.google.com/privacy
How we keep it safe
Traffic between your browser and the site runs over HTTPS. Access to the database, the email tool, and the notification channel is limited to Matvey.
Automated workflows run parts of our business, and we say so openly elsewhere on this site. They do not read website enquiries. Enquiries go to a person.
No system is perfect. If something goes wrong that puts your data at risk, we notify the supervisory authority within 72 hours as Article 33 requires, and we tell you directly if the risk to you is high.
Changes to this page
If we change how any of this works, we update this page and change the date at the top. We will not quietly widen what we do with data you have already given us.
Contact
Matvey Bykovskiy matvey@bycause.ai
Write in English, Spanish, French, or German. Any of them is fine.