Privacy Policy
This page is an English translation for your convenience. The German-language original is the legally binding version.
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.
Data Collection on This Website
Data processing on this website is carried out by the website operator. Your data is collected in part by you providing it to us (e.g. by filling out the contact form). Other data is automatically collected or collected with your consent when you visit the website by our IT systems. This is primarily technical data (e.g. internet browser, operating system or time of page access).
What Do We Use Your Data For?
Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior, for contract processing or to answer inquiries.
What Rights Do You Have Regarding Your Data?
You have the right at any time to obtain free information about the origin, recipient and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data as well as the right to lodge a complaint with a supervisory authority.
2. Hosting
We host the contents of our website with Namecheap (Namecheap, Inc., 4600 East Washington Street, Suite 305, Phoenix, AZ 85034, USA). Our mailboxes for receiving and answering enquiries from this website are hosted there as well. The personal data collected on this website is stored on the host’s servers. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses and other data generated via a website. As Namecheap is based in the USA, a transfer there cannot be ruled out; this is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
The use of the host is for the purpose of fulfilling contracts with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast and efficient provision of our online services by a professional provider (Art. 6 para. 1 lit. f GDPR). The host processes your data only on our instructions and to fulfill its service obligations.
Content Delivery Network (Cloudflare)
This website uses the content delivery network and security infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA ("Cloudflare"). Cloudflare acts as a reverse proxy between your browser and our hosting server: all requests to our domain pass through Cloudflare’s edge servers. In doing so, technical connection data (IP address, user agent, requested URL, HTTP status code, timestamp) is processed.
Cloudflare does not set any cookies on this website because Bot Fight Mode and Web Analytics are disabled. In the event of network errors, the browser transmits anonymized error reports to cloudflare.com via the NEL standard (Network Error Logging), solely to ensure availability.
The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in fast, secure and resilient delivery of the website as well as protection against DDoS and bot attacks). Cloudflare is certified under the EU-US Data Privacy Framework; a data processing agreement (Art. 28 GDPR) including EU standard contractual clauses is in place. Details: cloudflare.com/privacypolicy.
Data Backups
We create daily backups of the systems we operate ourselves. These are encrypted before transfer and then kept in three mutually independent locations: Cloudflare R2 (Cloudflare, Inc., USA), Backblaze B2 (Backblaze, Inc., San Mateo, California, USA) and Google Cloud Storage (Google Cloud EMEA Limited, Dublin, Ireland; data centre Frankfurt am Main). The decryption keys remain exclusively with us, so the providers cannot access the contents of the backups. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest in recoverable, resilient operation). Transfers to the USA are based on the EU Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR).
3. General Information and Mandatory Disclosures
Data Protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. Please note that data transmission over the Internet may have security vulnerabilities.
Responsible Entity
Jakob SerfözöBalduin-Helm-Straße 71b
82256 Fürstenfeldbruck
Telefon: +49 8141 5098988
E-Mail: hello@bytebrise.com
Storage Duration
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent for data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data.
Legal Basis
The processing of personal data is based on:
- Art. 6 para. 1 lit. a GDPR: consent
- Art. 6 para. 1 lit. b GDPR: contract or pre-contractual measures
- Art. 6 para. 1 lit. c GDPR: legal obligation
- Art. 6 para. 1 lit. f GDPR: legitimate interest
SSL / TLS Encryption
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock icon in your browser bar.
Objection to Promotional Emails
The use of contact data published as part of the imprint obligation for sending unsolicited advertising and information materials is hereby objected to. The operators of these pages expressly reserve the right to take legal action in the event of unsolicited promotional information, such as spam emails.
4. Data Collection on This Website
Cookies and Local Storage
This website itself sets no identifying cookies and no third-party trackers. One exception applies to the Meta pixel (see section 5): if you select "Allow stats" in the banner, it sets the cookies _fbp and, where applicable, _fbc. Otherwise, storage in your browser takes place exclusively via localStorage/sessionStorage for the following purposes:
- Language preference (
bb_lang, localStorage): stores the chosen language (DE/EN) for future visits. - Consent status (
bb_consent_v1, localStorage): remembers your choice from the privacy banner (allow statistics / essential only). - Session ID for our own statistics (
bb_sess, sessionStorage): only set upon consent to "Allow statistics"; a random identifier that is deleted when the tab is closed. Links a series of visits without any identifying features. - Referral code (
bb_refandbb_ref_t, localStorage): only set if you reach our site via a referral link (with the URL parameter?ref=) and have consented to statistics. Storage period 30 days. Purpose: crediting the referrer with your sign-up as a completed referral (see the Referral Program section on the homepage). You can delete this value at any time by clearing the domain's local storage in your browser. Legal basis: Art. 6 para. 1 lit. a GDPR (consent via the banner).
Cloudflare (CDN, see section 2) sets a technically necessary security cookie
(__cf_bm) for bot detection with a short lifespan (30 min). This cookie
is set by the CDN itself; consent is not required for this under Art. 6 para. 1 lit. f GDPR
and § 25(2) TDDDG, as it serves security purposes.
You can delete all entries at any time in your browser's developer tools.
You can reset your choice from the privacy banner by removing
bb_consent_v1 from localStorage; the banner will reappear
the next time you load the page.
In-House Reach Analytics (Only With Consent)
If you select "Allow statistics" in the privacy banner, we record
on our own servers (no third party) the following events:
page view (visit), time on page/scroll depth (engage),
PDF downloads (audit_download), CTA clicks (cta_click),
form submissions (contact_form). Each event contains the
session ID (bb_sess), the URL path accessed and a
salted SHA-256 hash of your IP address (pseudonymised, not
reversible). The original IP address is not stored. Purpose: understanding which
pages/content are relevant to visitors without being able to identify them
individually. Legal basis: Art. 6 para. 1 lit. a GDPR (your consent) in conjunction with
§ 25(1) TDDDG. Data is stored for 90 days and then aggregated/deleted.
Recipients: none beyond the processors named in section 2,
servers in Germany (Hetzner, Falkenstein).
Sie können sämtliche Einträge jederzeit in den Browser-Entwicklertools löschen.
Die Wahl im Datenschutz-Banner können Sie zurücksetzen, indem Sie
bb_consent_v1 aus dem localStorage entfernen, beim nächsten Seitenaufruf
erscheint das Banner erneut.
Matomo (Self-Hosted, Cookieless)
In addition to our in-house reach analytics, we use Matomo, an open-source analytics software that we operate on our own servers (Hetzner, Falkenstein, Germany). Third-party providers: none. External data transfer: none.
Cookieless: Matomo sets no cookies on this website
(configuration disableCookies). Recognition is session-based via a
short-lived heuristic hash (IP + user-agent tag, generated server-side, max. 30 min).
IP anonymisation: The last two octets of your
IP address are discarded before any processing
(configuration ipAddressMaskLength = 2). The full IP is
never stored.
Do Not Track: If your browser sends a DNT header (Do-Not-Track), Matomo is automatically deactivated and no tracking takes place.
Data collected: page view, referrer, approximate location
(country/region derived from the anonymised IP), screen resolution, browser/OS type.
No personal profiles, no cross-site tracking,
no fingerprinting across websites
(enable_fingerprinting_across_websites = 0).
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in measuring reach). A consent banner for Matomo is not required, as we forgo any access to cookies/local storage (§ 25(2) No. 2 TDDDG) and anonymise IP addresses before processing.
Storage period: raw data 90 days, aggregated statistics permanently. Objection: You can object to the collection at any time by enabling the DNT header in your browser (Settings → Privacy → "Send Do Not Track requests").
Manufacturer: InnoCraft Ltd, 7 Waterloo Quay PO625, 6140 Wellington, New Zealand. A self-hosted instance runs on bytebrise.com; no data is transferred to InnoCraft.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an Reichweitenmessung). Ein Consent-Banner für Matomo ist nicht erforderlich, da wir auf Cookies/Local-Storage-Zugriff verzichten (§ 25 Abs. 2 Nr. 2 TDDDG) und IP-Adressen vor Verarbeitung anonymisieren.
Speicherdauer: Roh-Daten 90 Tage, aggregierte Statistiken dauerhaft. Widerspruch: Sie können der Erfassung jederzeit widersprechen, indem Sie in Ihrem Browser den DNT-Header aktivieren (Einstellungen → Datenschutz → "Do Not Track senden").
Hersteller: InnoCraft Ltd, 7 Waterloo Quay PO625, 6140 Wellington, Neuseeland. Auf bytebrise.com läuft eine self-hosted Instanz, es findet keine Datenübertragung an InnoCraft statt.
Contact Form
If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this data without your consent.
The processing of this data is based on Art. 6 para. 1 lit. b GDPR if your request is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective processing of inquiries addressed to us (Art. 6 para. 1 lit. f GDPR) or on your consent (Art. 6 para. 1 lit. a GDPR) if this has been requested. The data you enter in the contact form will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies. Mandatory statutory provisions remain unaffected.
Inquiry by Email or Phone
If you contact us by email or telephone, your inquiry including all resulting personal data (name, inquiry) will be stored and processed by us for the purpose of processing your request. We do not share this data without your consent. Legal bases are Art. 6 para. 1 lit. b, f and, if applicable, a GDPR.
5. Plugins and Tools
No Third-Party Integrations
This website embeds <strong>no external services</strong>. In particular:
- Fonts: We host all typefaces (Manrope, Syne, Dystopian) on our own server. No connection is made to Google Fonts or any other font CDN.
- Maps: No Google Maps, OpenStreetMap, or other mapping service is embedded.
- Analytics: No Google Analytics, Matomo, Plausible, Hotjar, or comparable tracking tool is installed.
- Social media plugins: No like buttons, Twitter widgets, or comparable social plugins other than the Meta pixel described below. Links to our profiles (LinkedIn, Facebook) are plain links without any tracking component.
- Ad networks: No advertising is served and no profiling for advertising purposes takes place.
What We Embed (Complete List)
- Cloudflare (CDN, reverse proxy, DDoS protection): Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. When you access a page, your IP address is temporarily transmitted to Cloudflare so that content can be delivered quickly (legal basis Art. 6 para. 1 lit. f GDPR). Sets a technically necessary bot-detection cookie
__cf_bmwith a lifetime of 30 minutes. Privacy policy: cloudflare.com/privacypolicy - Cloudflare Turnstile (Spam-Schutz der Formulare, siehe Abschnitt 4): Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Beim Aufruf einer Seite mit Formular wird ein Skript von
challenges.cloudflare.comgeladen; Ihre IP-Adresse und technische Browser-Merkmale werden an Cloudflare übertragen (Rechtsgrundlage Art. 6 Abs. 1 lit. f DSGVO). Datenschutzerklärung: cloudflare.com/privacypolicy - websitecarbon.com (CO2 footprint badge in the footer): just a linked reference, NO script is embedded. The third-party page only loads when you click the link. No data transfer happens in the background.
- api.allorigins.win (CORS proxy): used exclusively when you enter a URL on the /quick-check.html page and click "Check". The URL you enter is transmitted to allorigins.win so that the target page’s HTML can be retrieved. Provider: gnuns <allorigins@gnuns.com> (Brazil). Data: only the URL you entered. No transmission of any other personal data. Only happens on your explicit action (click). If you do not want to use this feature, simply do not start the quick check.
- hello.bytebrise.com (our own server for reach analytics): see section 4. Only contacted with active consent.
- matomo.bytebrise.com (self-hosted Matomo analytics): see section 4. Server in Germany (Hetzner, Falkenstein). Cookieless, IP anonymized before processing, DNT respected. No data transfer to third parties.
- Google Ads conversion tracking (gtag.js, conversion ID AW-18125103490): Provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Measures whether a website visit via one of our Google Ads ads led to a contact. The Google Ads script only loads once you select "Allow stats" in the cookie banner (legal basis Art. 6 para. 1 lit. a GDPR, consent); before your decision no connection to Google is made, and neither cookies nor any data (including cookieless pings) are transmitted to Google. We additionally use Google Consent Mode v2 so that Google correctly respects your consent choice. Your consent can be withdrawn at any time via the "Cookie settings" link in the footer. Processing in the USA cannot be ruled out; Google LLC is certified under the EU-US Data Privacy Framework. Provider’s privacy policy: policies.google.com/privacy
- Meta Ads Pixel + Conversions API (Meta Pixel ID 2115831946000676): Provider Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Measures whether a website visit via one of our Meta ads (Facebook/Instagram) led to a contact. Unlike the Google Ads tag described above, Meta has no cookieless mode: the pixel only loads once you select "Allow stats" in the banner (legal basis Art. 6 para. 1 lit. a GDPR, consent). It then sets the cookie _fbp and, if you click an ad, _fbc. In addition, upon a successful contact we transmit a server-side Conversions API event with a SHA-256-hashed email address or phone number as a matching key, again only with your consent. Processing in the USA cannot be ruled out; Meta Platforms Ireland is certified under the EU-US Data Privacy Framework. You can withdraw your consent at any time via the "Cookie settings" link in the footer. Provider’s privacy policy: facebook.com/privacy/policy
When you access this site, your IP address is transmitted exclusively to our own web server (see section 2 “Hosting”). This is technically required to deliver the site to you (Art. 6 para. 1 lit. f GDPR, legitimate interest in operating the website).
6. Your Rights
You have the following rights with respect to us:
- Access (Art. 15 GDPR) to the personal data stored about you
- Rectification (Art. 16 GDPR) of inaccurate or incomplete data
- Erasure (Art. 17 GDPR) of your personal data
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) in a machine-readable format
- Objection (Art. 21 GDPR) to the processing of your data
To exercise these rights, please contact: hello@bytebrise.com
You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data by us.
7. Online Appointment Booking
Via a personal invitation link (/t/…) we offer you the option of booking a phone consultation with us online. For this we process the following data you provide in the booking form:
- Name
- Email address (for the booking confirmation)
- Phone number (for the call-back at the booked time)
- Your request / topic
- The preferred time slot
Legal basis: Processing is based on Art. 6 para. 1 lit. b GDPR for the performance of pre-contractual measures at your request.
Purpose: Arranging and conducting the initial phone consultation and confirming the appointment by email (including an optional calendar file in .ics format).
Storage period: Your booking data is deleted after the initial consultation if no contractual relationship is established. If an engagement is agreed, the data is further processed to fulfil contractual obligations and statutory retention periods.
Storage location & transfer: The booking data is stored on our web server in a password-protected file and is additionally transferred over an encrypted HTTPS connection to our customer management system (CRM). We operate the CRM on our own server in Germany (Hetzner, see the Hosting section); access is password-protected and limited to us. Deletion follows the retention periods stated above.
Invitation link: The invitation link contains a cryptographically signed token with an expiry date. The booking page cannot be used without a valid link. The link can be invalidated when it expires or at your request.
No disclosure to third parties: Your data is not transmitted to external appointment-booking providers (e.g. Calendly, Cal.com). Bookings are handled exclusively by our own systems.
8. Business Outreach and Lead Processing
As part of our business development we research publicly available information about companies that might be interested in our services (e.g. company name, address, phone, website URL, contact persons publicly listed on the company website). We store this information in an internal customer management system (CRM) that we operate on our own server in Germany (Hetzner, see the Hosting section). Access is password-protected and limited to us.
Legal basis: Art. 6 para. 1 lit. f GDPR. Our legitimate interest is acquiring new business customers through targeted outreach. Only business contact data is processed, no data from private contexts.
Preview drafts: In individual cases we create a non-binding website draft for illustration purposes that uses publicly available content from the company website (company name, logo, texts, images). The draft is stored under a non-indexed address (/preview/{slug}/), blocked for search engines (robots.txt, X-Robots-Tag: noindex) and shared exclusively with the company concerned via a link. It does not imply any existing business relationship.
Objection and deletion: You can object to the processing of your business data for outreach purposes at any time, informally, at hello@bytebrise.com. We will then delete the data from the CRM without delay and remove any preview draft within three working days.
Storage period: Outreach data is deleted no later than three months after the last communication if no business relationship is established. Preview drafts are removed from the server by the same time at the latest. If a contract is concluded, the data is transferred to our customer records.
9. Newsletter
You can subscribe to a newsletter on our blog. For this we process your email address as well as the time and IP address of the registration and confirmation. Registration uses the double-opt-in procedure: you first receive a confirmation email, and you are only subscribed once you click the confirmation link.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent). Logging of the double-opt-in is based on Art. 6 para. 1 lit. f GDPR in order to be able to prove the registration.
Processing and dispatch: Subscribers are managed via self-hosted newsletter software (Listmonk) on our server in Germany (Hetzner, see the Hosting section). For the technical dispatch of the emails we use Brevo (Brevo GmbH, formerly Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin) as a processor; a data processing agreement is in place with Brevo.
Withdrawal and storage period: You can unsubscribe from the newsletter at any time via the unsubscribe link in every email or informally by message to hello@bytebrise.com. After unsubscribing we delete your data from the mailing list; we retain the log data of the previous consent for evidence purposes.
10. Payment Processing via Stripe
For billing paid services (e.g. monthly subscriptions, AI add-ons and payments via the customer portal) we use the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe").
When you make a payment via Stripe, the data required for this is transmitted to Stripe: name, email address, billing address, payment details (e.g. card number or IBAN), amount, currency and time of the transaction. You enter your payment details directly into Stripe’s payment forms; complete card data never reaches our systems. We only receive a confirmation of the payment from Stripe along with the details needed for invoicing.
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of a contract or pre-contractual measures). Where Stripe processes data for its own purposes such as fraud prevention, Stripe is itself responsible for that processing under data protection law.
Third-country transfer: Stripe may transfer data to affiliated companies in the USA (Stripe, Inc.). This is based on the EU standard contractual clauses (Art. 46 para. 2 lit. c GDPR); Stripe is also certified under the EU-US Data Privacy Framework.
Storage duration: We retain payment and invoicing data within the statutory retention periods (Section 147 AO, Section 257 HGB). Details on data processing by Stripe: stripe.com/privacy.
11. AI-Assisted Text Features (Anthropic)
For the optional AI add-ons Humanize (revision of your own texts) and AI Copywriter (creation of blog texts, see Terms of Use) we use AI models from Anthropic (Anthropic, PBC, San Francisco, California, USA).
When you use one of these tools, the texts you enter are transmitted to Anthropic via an API for processing. Other data from your account (name, email address, payment details) is not sent along. Please do not enter any particularly sensitive data or third-party secrets into the tools (see Terms of Use).
Anthropic processes the input on our behalf and according to our instructions; a data processing agreement (Art. 28 GDPR) is in place. According to the provider’s terms for API use, your input is not used to train the AI models.
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of the contract for the booked add-on).
Third-country transfer: Processing may take place on servers in the USA. This is based on the EU standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Details: anthropic.com/legal/privacy.
12. Free Website Audit
On quick-check.html and free-audit.php we offer a free automated website check. We crawl the URL you provide (up to 20 pages) and evaluate technical factors, content quality and meta data. The checked URL itself is not personal data about you unless it happens to contain your name.
Email address (optional): Only if you voluntarily provide your email and consent to the processing via checkbox do we send you the full audit report as a PDF and create a lead record in our internal CRM (company domain, email, audit score). Without consent you only see the result directly on the page; no email is stored.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent via checkbox) for the email processing and PDF delivery; Art. 6 para. 1 lit. f GDPR (legitimate interest in technically performing the check) for the URL analysis itself. The PDF is sent technically via Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin) as a data processor, see section 9 (Newsletter).
Storage duration: The lead record (incl. audit score) is deleted at the latest 90 days after the request, unless it leads to a further business relationship. The generated PDF itself is not stored permanently; it is only kept briefly for delivery and then automatically removed.
Objection and deletion: You can object to this processing at any time, informally, at hello@bytebrise.com; we will then delete the lead record without delay.
13. AI Chatbot (Knowledge Assistant)
On selected pages we offer an AI-powered chat assistant (visible in the bottom right as a speech-bubble icon). The assistant answers questions based on the public content of this website (services, blog, FAQ) and runs on a server we operate ourselves in Germany (Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen; data centre in Germany).
Data processed: Your chat messages are transmitted for processing to the AI model of the provider Anthropic (Anthropic, PBC, San Francisco, California, USA) (see section 11 on third-country transfer and data processing agreements; the same conditions apply). Your IP address is not stored in plain text, but is used exclusively in hashed form for abuse prevention (rate limiting). The conversation history is stored on our server to enable multi-part conversations and to monitor the quality of responses.
Voluntary contact details: If, during the conversation, you voluntarily express interest in personal contact and provide your name and email address, the assistant may store this information as an inquiry in our internal CRM so that we can get back to you (compare section 8). This only happens when interest is explicitly expressed, never automatically or without a recognisable reason.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in a user-friendly, direct answering of questions) for the chat itself; Art. 6 para. 1 lit. a GDPR (implied consent through voluntary disclosure) for a contact request made during the conversation.
Third-country transfer: As described in section 11, the processing of the chat messages themselves may take place on servers in the USA (Anthropic). This is based on the EU standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Details: anthropic.com/legal/privacy. The conversation history itself is stored exclusively on our own server in the EU.
Storage period: Conversation histories are automatically deleted no later than 90 days after the last message.
Objection: You can close the chat at any time without giving reasons; this results in no disadvantage to you. For a contact request stored during the conversation, section 8 (Objection and Deletion) applies.
14. Phone AI Agent (sipgate)
For telephone availability we use an AI-powered phone assistant. It answers incoming calls, records your request and, where needed, arranges an appointment or a call-back from us.
Service used: The assistant runs on the telephony platform of sipgate GmbH, Düsseldorf. sipgate processes the data as a processor on our behalf and according to our instructions; a data processing agreement (Art. 28 GDPR) is in place. Processing takes place in the EU.
Data processed: Your phone number, the content of the call as a transcript, and an automatically generated summary of the call. In addition, we process the details mentioned during the call, such as name, request and desired appointment time.
Notice of digital assistance: At the start of every call we let you know that you are speaking with a digital assistant. If you do not want this, you can hang up at any time and reach us instead by email at hello@bytebrise.com or request a call-back via the contact form.
Legal basis: Art. 6 para. 1 lit. b GDPR, insofar as the call serves to arrange an appointment or initiate a contract; otherwise Art. 6 para. 1 lit. f GDPR (legitimate interest in prompt telephone availability).
Storage period: With the provider sipgate, transcripts are retained for up to 30 days. In our own systems we automatically delete the raw transcript data after 90 days. For appointment and contact data taken over from the call, the storage periods of sections 7 (Online Appointment Booking) and 8 (Business Outreach and Lead Processing) apply.
Your rights: For access, rectification, erasure and the further rights of data subjects, section 6 applies.
15. Lead Magnets (Checklists and Guides)
Download via Forms and Exit Popups
On selected pages (e.g. checkliste.html) and via exit popups on
our landing pages, we offer free checklists and guides as PDFs for
download. If you enter your email address in the form, we transmit it,
together with an identifier for the requested content and an identifier for the
page via which you accessed the form, in encrypted form to our customer
management system (CRM), which we operate on our own server in Germany
(crm.bytebrise.com, Hetzner, see the Hosting section).
Purpose and legal basis: The processing serves the one-time delivery of the PDF you requested by email as well as the management of the resulting lead. The legal basis is Art. 6 para. 1 lit. b GDPR (fulfilment of your request to have the content sent to you).
Storage period and deletion: Your data remains in the CRM until you object to the processing. Deletion follows the same process as described in section 8: informally by email to hello@bytebrise.com, deletion without delay.
Contact Sync with Brevo
For some of our existing lead magnets, the email address you provided is additionally transferred via an automated connection into our contact list with the email service provider Brevo (see section 9) in order to manage the contact centrally there. Not every lead magnet uses this sync. The legal basis is our legitimate interest in an organised, central management of contacts (Art. 6 para. 1 lit. f GDPR). A data processing agreement is in place with Brevo (see section 9).
16. Email Series "AI Visibility for Trade Businesses"
In addition to the one-time guide (see section 15), we offer on selected pages the option to sign up for a four-part information series on the topic of AI visibility for trade businesses. Registration takes place exclusively via a separate, explicit consent checkbox.
Legal basis: Art. 6 para. 1 lit. a GDPR (your consent). As with the newsletter (section 9), we complete registration using the double-opt-in procedure: you first receive a confirmation email, and you are only registered for the series once you click the confirmation link. The logging of registration and confirmation is based on Art. 6 para. 1 lit. f GDPR, in order to be able to prove consent.
Management and dispatch: Registrations are managed, as with the newsletter, via our self-hosted newsletter software (Listmonk) on our own server in Germany (see section 9). For the technical dispatch of the individual series emails we also use Brevo (see section 9) as a processor.
Withdrawal and storage period: You can unsubscribe from the series at any time via the unsubscribe link (one-click) in every email or informally by message to hello@bytebrise.com. After you unsubscribe, you will receive no further series emails. We log registration, confirmation and unsubscription for evidence purposes; we delete the remaining data from the active distribution list after unsubscription.
17. Origin Identification in Demo Templates (Install Ping)
Our free demo templates, offer previews and website kits contain a lightweight script that sends a one-time notification to our server only when the template is accessed on a third-party domain (i.e. not on bytebrise.com or a subdomain thereof). This origin identification helps us detect when a copied template is put live without a licence or completed purchase.
Data transmitted: When accessed on a third-party domain, the
script transmits, via navigator.sendBeacon, only the hostname of the
calling page, an identifier for the template used, a version string and the time
of the call to install.bytebrise.com.
What explicitly does not happen: The script sets no cookies and does not access local storage (local storage, session storage or similar) on your device, nor does it store anything there. There is therefore no access within the meaning of § 25 TDDDG. No visitor identification takes place, no referrer is recorded, and no user agent is stored.
IP address: During the technically required connection setup, our upstream service provider Cloudflare briefly processes the IP address (see section 2, Content Delivery Network). We ourselves do not store the IP address anywhere.
Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in protecting our copyright and usage rights to the templates).
Frequency and storage period: At most one notification per hostname is counted per day (deduplication); multiple calls to the same domain on the same day do not trigger a further transmission. We delete the stored hostname entries after 24 months at the latest.
Our own domains: On bytebrise.com and all our subdomains the script is technically present but does not trigger a notification: before every transmission it checks whether the calling hostname belongs to bytebrise.com, and aborts in that case.
18. Last Updated
15.08.2026