2026-09-11

Privacy Policy

The short version

We collect very little. If you fill in the contact form or book a call, we get your name, your email address, your company if you type one, and what you wrote. We use it to reply to you and to hold the call. That is all.

We count page views, and if you accept our cookie banner, we also use Google and Meta to see which ad or search result actually brought someone here. That tracking stays off until you say yes, and you can change your mind at any time from the footer. We do not sell or rent your data to anyone.

The rest of this page is the detail, because the law asks for it and because you should be able to check what we say.

Who is responsible for your data

The controller is Bycause.ai, operated by Matvey Bykovskiy.

Email: matvey@bycause.ai Website: https://bycause.ai

We have not appointed a Data Protection Officer. Given our size and the small amount of personal data we handle, we do not believe Article 37 GDPR requires one.

Anything about privacy goes to matvey@bycause.ai.

What we collect, and when

Contact form, on the contact page. Your name, your email address, your company name if you choose to enter one, and the message you write.

Booking form, on the booking page. Your name, your email address, your company name if you choose to enter one, the date and time slot you pick, and the timezone your browser reports, for example Europe/Madrid. We store the timezone so nobody turns up an hour late.

Email you send us directly. If you write to matvey@bycause.ai we hold your address and whatever you sent.

Technical data. Our host writes standard server logs when a page or a function is requested. These normally include the IP address, the time, what was requested, and the browser user agent. We do not connect this to form submissions and we do not use it to identify anyone.

Audience measurement. We use Vercel Web Analytics to see which pages actually get read. It records the page you opened, the site you arrived from, your country, and your browser and device type. It stores nothing on your device and it does not keep your IP address. To count a repeat visit within the same day it builds a one-way hash from your request and a value that changes every 24 hours, then discards it. It cannot be reversed and it cannot follow you across days or onto other sites.

Analytics and advertising cookies, only for whichever category you accept. The cookie banner offers Accept all, Reject all, or Manage preferences to choose each category separately. Accepting Analytics loads Google Analytics (GA4), setting _ga and _ga_*. Accepting Advertising loads a Google Ads conversion tag and the Meta Pixel, setting _gcl_au, _fbp and _fbc, so we can see which ad or search result led to a booked call, and so Google and Meta can show our ads again to people who visited without booking. Rejecting a category, or not answering, means nothing for it loads and none of its cookies are set. Google's Consent Mode still receives an anonymised, cookieless signal either way, which it uses to estimate aggregate results without identifying anyone.

Cookie preference. Your choice for each category is saved in your browser's local storage so we do not ask again on every visit. Change it any time from "Cookie preferences" in the footer.

WhatsApp button. When you tap a WhatsApp button on this site we record that a tap happened: the time, the page, which button, the site language and, if you arrived from one of our ads, which ad brought you, read from the address of the page you landed on. We keep no IP address, no browser details and no identifier with it, and it cannot be linked to you or to the message you then write to us. It is a count, so we know which ads lead to conversations.

That is the complete list. There is no account to create, no password, and no payment information collected anywhere on this site. Beyond the analytics and advertising cookies above, which run only for whichever category you accept, we use no heatmaps, no session recording and no profiling.

Prospect data — how we find you before you contact us

Everything above describes data you give us directly, through the contact form, the booking form, or an email to us. This section is different: it covers business contact details we collect about a company and the person we believe leads it, before that person has ever contacted us.

We research businesses that might want the kind of work we do, using their own public presence: their website, their Google Business listing, and general web search. What we hold is a company name, a contact name, a work email address if we can find one, a phone number if it is published, a LinkedIn profile URL if there is one, and a short written note about why we think this company might need automation work.

The basis is Article 6(1)(f) GDPR: our legitimate interest in reaching businesses that could plausibly become a client, using information they have already made public. We do not use this to build a profile of you as an individual; it is about the company, and you as a plausible point of contact for it.

Article 14 GDPR requires that, because we did not get this from you, we tell you about it within one month, or by the time we first contact you if that is sooner. If you receive an outreach message from us, it links to this page. If you have not heard from us and want to know whether we hold anything about your company, email matvey@bycause.ai.

You can object to this at any time (Article 21), the same as anything else on this page based on legitimate interest. If you object, or if we contact you and you are not interested, we delete what we held rather than keep trying.

We have not yet fixed a hard retention period for prospects we never reach or never hear back from. Until we do, ask and we will tell you what we hold, and delete it on request.

Why we are allowed to use it

For the contact form and the booking form, the basis is Article 6(1)(b) GDPR: steps taken at your request before entering into a contract. You are asking about work we might do for you, and we cannot answer or hold a slot without your details.

If your message is not about possible work together, the basis is Article 6(1)(f) GDPR: our legitimate interest in answering people who write to us. You can object to that at any time and we will stop.

The confirmation email you receive, and the notification we receive ourselves, sit on the same basis. Both are part of handling your enquiry, not separate marketing.

For server logs, the basis is Article 6(1)(f) GDPR: our legitimate interest in keeping the site running and protecting it from abuse.

For counting WhatsApp taps, the basis is Article 6(1)(f) GDPR: our legitimate interest in knowing which pages and ads lead to a conversation. It identifies nobody and you can object to it at any time.

For audience measurement, the basis is Article 6(1)(f) GDPR: our legitimate interest in knowing which pages are worth keeping. It is aggregate, it identifies nobody, and you can object to it at any time.

For the advertising and analytics cookies, the basis is Article 6(1)(a) GDPR: your consent, given through the cookie banner. Withdrawing it is exactly as easy as giving it, from "Cookie preferences" in the footer, and withdrawing does not undo anything that already happened while consent was in effect.

We do not send marketing newsletters from this site and there is no mailing list to join.

We do not use your data for automated decision-making or profiling in the sense of Article 22 GDPR. A person reads every enquiry.

Giving us your details is voluntary. If you would rather not, we simply cannot reply or book you in.

Who else handles your data

The list is short on purpose. Supabase, Vercel, and Resend act as processors on our instructions under Article 28 GDPR. Telegram, Google, and Meta are different cases and we explain each below.

Supabase, for the database. Your form entry is written into our database directly from your browser, which means Supabase also receives your IP address at that moment.

Vercel, for hosting the site, running the small function that sends the notifications, and measuring audience. Vercel Inc. is a United States company.

Resend, for email. It sends the notification to us and the confirmation to you. Resend is a United States company.

Telegram, for notifications. We get a Telegram message when someone submits a form so nothing is missed. For a contact form the message currently contains your name, email address, company, and the text you wrote. For a booking it contains your name, email address, company, and the slot and timezone you picked. Telegram is a messaging service we use, not a processor we hold an Article 28 contract with, and it is operated outside the EU.

Google, for analytics and ad measurement, only if you accept the cookie banner. Google LLC is a United States company.

Meta, for ad measurement, only if you accept the cookie banner. Meta Platforms Ireland Limited is based in the EU; its US parent, Meta Platforms, Inc., also processes this data.

Where a provider is outside the EU or the EEA, the transfer relies on the European Commission Standard Contractual Clauses, or on an adequacy decision where one applies.

We do not sell your data. Beyond Google and Meta above, who receive anything only if you accept the cookie banner, we do not share your data with advertisers, and we do not pass it to anyone else unless the law requires it.

How long we keep it

Enquiries and bookings that do not lead to work together: 12 months, then we delete them.

If we do end up working together, your details become part of the client file. We keep those for as long as the contract runs, then for the period commercial and tax law requires.

Telegram notifications sit in a chat history until that chat is cleared.

Server logs are kept by our host for a short period as part of normal operation.

You can ask us to delete your data sooner. The next section says how.

Your rights

Under the GDPR you can:

Ask what we hold about you and get a copy of it (Article 15). Have anything wrong or incomplete corrected (Article 16). Have your data deleted (Article 17). Ask us to pause processing while a question is being sorted out (Article 18). Receive your data in a structured, commonly used, machine readable format, or have it sent to another provider (Article 20). Object to anything we base on legitimate interest (Article 21). If you object, we stop, unless we have compelling grounds that override yours.

Email matvey@bycause.ai and say which one you want. We reply within one month, as Article 12(3) requires. There is no charge.

You can also complain to a data protection authority, either where you live or work, or where you think something went wrong. We operate from Spain, so our lead authority is:

Agencia Española de Protección de Datos (AEPD), Spain. www.aepd.es

If you are in Luxembourg, you can raise it with your own authority instead: Commission nationale pour la protection des données (CNPD). www.cnpd.lu

Cookies and local storage

Three cookie-setting tags run on this site, in two categories: Analytics (Google Analytics, GA4) and Advertising (a Google Ads conversion tag and the Meta Pixel). Both default to off. A banner asks once, with three choices: accept all, reject all, or manage preferences to choose each category on its own. Accepting a category sets the cookies listed under what we collect, above; rejecting it, or not answering, loads nothing for it.

We store one thing in your browser's local storage: your choice for each category, so we do not ask again on every visit. Your language is part of the address you are on, so there is nothing to remember there.

Our audience measurement (Vercel Web Analytics) stays cookieless by design regardless of what you choose on the banner, which is why it appears above under what we collect rather than behind it.

You can change your choices at any time from "Cookie preferences" in the footer, on any page.

How we keep it safe

Traffic between your browser and the site runs over HTTPS. Access to the database, the email tool, and the notification channel is limited to Matvey.

Automated workflows run parts of our business, and we say so openly elsewhere on this site. They do not read website enquiries. Enquiries go to a person.

No system is perfect. If something goes wrong that puts your data at risk, we notify the supervisory authority within 72 hours as Article 33 requires, and we tell you directly if the risk to you is high.

Changes to this page

If we change how any of this works, we update this page and change the date at the top. We will not quietly widen what we do with data you have already given us.

Contact

Matvey Bykovskiy matvey@bycause.ai