Last updated: August 2026
1. Our commitment
Byto X is committed to protecting personal data and processing it lawfully, fairly and transparently. This page explains how we comply with the EU/UK General Data Protection Regulation (GDPR) and comparable data-protection laws, and how you can exercise your rights. It complements our Privacy Policy.
2. Data controller
For personal data processed through this website, the data controller is Byto X (Business Bay, Dubai, United Arab Emirates). You can reach us for any data-protection matter at [email protected].
3. What we process and why
- Contact enquiries — name, email, company (optional) and your message, used only to respond to you and to scope requested work.
- Technical data — limited, mostly aggregated information used to keep the site secure and reliable.
4. Lawful bases
- Consent — when you contact us voluntarily, or where we ask for it (e.g. future non-essential cookies).
- Legitimate interests — to respond to enquiries, secure and improve the site, and manage a potential or existing business relationship, balanced against your rights.
- Legal obligation — where we must retain or disclose data to comply with the law.
5. Your rights
Subject to applicable law, you have the right to:
- Be informed about how your data is used;
- Access the personal data we hold about you;
- Request rectification of inaccurate data;
- Request erasure ("right to be forgotten");
- Restrict or object to processing;
- Data portability, where applicable;
- Withdraw consent at any time;
- Lodge a complaint with your data-protection authority.
To exercise any of these rights, email [email protected]. We will respond within the timeframes required by law (generally within one month).
6. International transfers
Our infrastructure and service providers may process data outside your country. Where personal data is transferred internationally, we rely on appropriate safeguards (such as adequacy decisions or standard contractual clauses) as required by law.
7. Data retention
We keep personal data only for as long as necessary for the purposes described here and to meet legal or record-keeping obligations, after which it is deleted or anonymised.
8. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or misuse. No system is perfectly secure, but we work to keep risk low.
9. Contact
For any data-protection request or question, contact [email protected].
Questions about this page? Email us at [email protected].