Privacy and Confidentiality

Your information and project ideas are treated with care.

This policy explains how Byte Craft Enterprises collects, uses, protects and retains information when you visit our website, contact us, request a quotation or work with us.

Effective: 15 July 2026 Version 1.0 Website privacy notice
This policy covers the Byte Craft Enterprises corporate website.

Individual mobile apps, websites, education services or products published by Byte Craft Enterprises may have separate privacy policies describing the information processed by that specific product.

01

Organisation

Who we are and when this policy applies

Byte Craft Enterprises is a technology business providing website development, mobile application development, WordPress solutions, software support, digital design and connected technology services.

For personal information collected through this corporate website, Byte Craft Enterprises normally acts as the organisation deciding why and how that information is processed.

When we build or maintain a system for a client, the client may be the organisation controlling personal information within that system. In that situation, Byte Craft Enterprises may process information only on the client’s documented instructions and according to the agreed project arrangements.

In this policy

“Personal information” means information that identifies, relates to or can reasonably be connected with an individual. “Processing” includes collecting, viewing, storing, organising, transmitting, updating and deleting information.

02

Data categories

Information we may collect

Contact information

Your name, email address, telephone or WhatsApp number, country, preferred contact method and business or organisation name.

Project information

Project descriptions, intended users, goals, requested features, budget range, schedule, website links, app links, reference examples and technical requirements.

Communications

Emails, form submissions, support messages, quotation discussions, meeting notes and other communications relating to an enquiry or project.

Client and transaction records

Quotations, contracts, invoices, payment status, deliverables, approvals, revision records and support history.

Technical website information

Internet Protocol address, browser type, device type, operating system, timestamps, requested pages, referral information and server or security logs.

Voluntarily supplied files

Images, documents, designs, datasets, specifications or other files that you choose to provide for evaluation or project delivery.

Please do not submit passwords, private encryption keys, complete payment-card details, highly sensitive personal records or information that you are not authorised to share.

03

Collection

How we receive information

We normally receive information directly from you when you:

  • submit a contact form or quotation request;
  • contact us by email, telephone, WhatsApp or live chat;
  • discuss, approve or enter into a project;
  • provide files, links, credentials or technical information;
  • request maintenance, publishing or product support; or
  • use and navigate the website.

We may also receive limited information from a person acting on behalf of your organisation, a public business website, an app store listing or another source that you have asked us to review.

04

Purposes

How and why we use information

Purpose Reason for processing
Responding to enquiries To communicate with you and provide requested information.
Preparing quotations To understand your requirements and take steps before entering into a contract.
Delivering projects To perform agreed development, design, publishing, maintenance or support services.
Managing business records To maintain contracts, invoices, approvals, accounting records and project history.
Website security To detect abuse, investigate suspicious activity, prevent unauthorised access and maintain service reliability.
Website improvement To understand general website use and improve navigation, content, accessibility and performance.
Legal compliance To meet applicable legal, taxation, accounting, regulatory and dispute-resolution obligations.

Depending on the circumstances and applicable law, processing may be based on your consent, steps requested before a contract, performance of a contract, compliance with a legal obligation or our legitimate interest in operating and protecting the business.

We do not use contact or project information to make decisions about you that produce legal or similarly significant effects solely through automated processing.

06

Recipients

When information may be shared

Byte Craft Enterprises does not sell or rent personal information. Information may be shared only as reasonably necessary with:

  • website hosting, server, backup and security providers;
  • email, form-delivery and business communication providers;
  • analytics, performance or security services where enabled;
  • app stores, domain providers, hosting providers or platform services when you request related support;
  • authorised contractors or specialists assisting with a project;
  • accountants, legal advisers, insurers or professional advisers;
  • authorities where disclosure is legally required; or
  • a successor organisation if the business is lawfully sold, reorganised or transferred.

Service providers are expected to use relevant information only to perform the service for which they were engaged and to protect it appropriately.

07

Website technologies

Cookies, logs and analytics

Cookies are small files or browser-storage records used to support website functions, remember settings, maintain security or understand general website use.

You can use your browser settings to remove or block cookies. Blocking essential technologies may prevent some website functions from operating correctly.

08

Interactive assistance

Live chat and AI-assisted tools

The website may display live-chat, automated-support or AI-assisted features. Information entered into those tools may be processed by the technology provider used to operate the feature.

Automated responses are provided for general assistance and should not be treated as a final quotation, contractual commitment, legal advice, security instruction or confirmation that a project has been accepted.

Do not enter account passwords, access tokens, private keys, full payment-card details or highly confidential project files into a public chat or AI-support window.

09

Global services

International processing and storage

Byte Craft Enterprises serves customers internationally. Website hosting, email, cloud storage, communication platforms, analytics, app-store services and project tools may process or store information in countries other than the country where you live.

Where required, we take reasonable steps to use reputable service providers, appropriate contractual arrangements and other safeguards intended to protect information during international processing.

10

Safeguards

How we protect information

We use reasonable technical and organisational measures suitable for a small technology business. Depending on the system and project, these measures may include:

  • encrypted HTTPS connections;
  • password-protected and access-controlled accounts;
  • limiting access to persons who need the information;
  • software, plugin and server maintenance;
  • backups and recovery measures where appropriate;
  • spam, abuse and suspicious-login protection;
  • secure transfer methods for sensitive project material; and
  • deletion or anonymisation when information is no longer needed.

No website, electronic transmission or storage system can be guaranteed to be completely secure. You are responsible for using secure communication methods and protecting any credentials or accounts under your control.

11

Storage period

How long information is retained

We retain information only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, security or dispute-resolution requirements.

General enquiries

Normally retained for up to 24 months after the last meaningful communication, unless a longer period is reasonably required.

Unsuccessful quotations

Normally retained for up to 24 months so that we can respond to follow-up enquiries and maintain quotation history.

Client and project records

Retained during the relationship and normally for up to seven years afterwards where needed for accounting, contractual, warranty, legal or dispute purposes.

Security and server logs

Normally retained for a shorter operational period, commonly between 30 and 180 days, unless needed to investigate an incident.

Marketing preferences

Retained until you withdraw consent, unsubscribe or the information is no longer required.

Backups

Deleted information may remain temporarily in protected backups until the normal backup cycle removes or overwrites it.

12

Individual choices

Your privacy rights

Depending on your location and the law that applies, you may have the right to:

Request access to your personal information Ask us to correct inaccurate or incomplete information Request deletion where there is no valid reason to retain it Request restriction of certain processing Object to processing based on legitimate interests Withdraw consent where processing relies on consent Request a portable copy where the right applies Complain to an appropriate data-protection authority

We may need to confirm your identity before responding. Rights may be limited where information must be retained for legal, contractual, security, accounting or dispute purposes, or where disclosure would affect another person’s rights.

13

Young users

Children’s privacy

This corporate website and its quotation services are intended primarily for adults, businesses, organisations and authorised project representatives.

We do not knowingly request personal information from a child who is not legally able to provide it without parental or guardian authorisation. A parent or guardian who believes that a child has submitted information through this website may contact us to request review or deletion.

Education products or child-accessible applications may provide separate, product-specific privacy information.

14

Other websites

External links, stores and third-party services

This website may link to app stores, social-media platforms, payment providers, client websites, videos, hosting services or other third-party websites.

Third-party services operate under their own terms and privacy policies. Byte Craft Enterprises does not control how an external website or platform processes information after you leave this website.

15

Revisions

Changes to this policy

We may update this policy when our website, services, suppliers, security practices or legal obligations change.

The revised policy will be published on this page with a new effective date. Where a change significantly affects how existing personal information is used, we will take reasonable steps to provide additional notice where required.

16

Privacy contact

Questions, requests and complaints

Contact us if you have a question about this policy, want to exercise a privacy right or believe your information has been handled incorrectly.

Organisation Byte Craft Enterprises
Business location Sri Lanka — serving clients internationally

Please include enough information for us to identify the relevant enquiry or project. Do not send identity documents unless we specifically request an appropriate verification method.

Regulatory complaints

You may have the right to complain to the data-protection authority responsible for your location. In Sri Lanka, privacy matters are regulated by the Data Protection Authority of Sri Lanka.

Visit the Data Protection Authority