Privacy and Confidentiality
Your information and project ideas are treated with care.
This policy explains how Byte Craft Enterprises collects, uses, protects and retains information when you visit our website, contact us, request a quotation or work with us.
Individual mobile apps, websites, education services or products published by Byte Craft Enterprises may have separate privacy policies describing the information processed by that specific product.
Organisation
Who we are and when this policy applies
Byte Craft Enterprises is a technology business providing website development, mobile application development, WordPress solutions, software support, digital design and connected technology services.
For personal information collected through this corporate website, Byte Craft Enterprises normally acts as the organisation deciding why and how that information is processed.
When we build or maintain a system for a client, the client may be the organisation controlling personal information within that system. In that situation, Byte Craft Enterprises may process information only on the client’s documented instructions and according to the agreed project arrangements.
“Personal information” means information that identifies, relates to or can reasonably be connected with an individual. “Processing” includes collecting, viewing, storing, organising, transmitting, updating and deleting information.
Data categories
Information we may collect
Contact information
Your name, email address, telephone or WhatsApp number, country, preferred contact method and business or organisation name.
Project information
Project descriptions, intended users, goals, requested features, budget range, schedule, website links, app links, reference examples and technical requirements.
Communications
Emails, form submissions, support messages, quotation discussions, meeting notes and other communications relating to an enquiry or project.
Client and transaction records
Quotations, contracts, invoices, payment status, deliverables, approvals, revision records and support history.
Technical website information
Internet Protocol address, browser type, device type, operating system, timestamps, requested pages, referral information and server or security logs.
Voluntarily supplied files
Images, documents, designs, datasets, specifications or other files that you choose to provide for evaluation or project delivery.
Please do not submit passwords, private encryption keys, complete payment-card details, highly sensitive personal records or information that you are not authorised to share.
Collection
How we receive information
We normally receive information directly from you when you:
- submit a contact form or quotation request;
- contact us by email, telephone, WhatsApp or live chat;
- discuss, approve or enter into a project;
- provide files, links, credentials or technical information;
- request maintenance, publishing or product support; or
- use and navigate the website.
We may also receive limited information from a person acting on behalf of your organisation, a public business website, an app store listing or another source that you have asked us to review.
Purposes
How and why we use information
Depending on the circumstances and applicable law, processing may be based on your consent, steps requested before a contract, performance of a contract, compliance with a legal obligation or our legitimate interest in operating and protecting the business.
We do not use contact or project information to make decisions about you that produce legal or similarly significant effects solely through automated processing.
Client protection
Confidentiality of client projects and business ideas
We recognise that a project enquiry may contain private business information, an unpublished product concept, technical details or commercially valuable material.
We do not disclose one client’s private project information to another client.
We do not provide private project material to competitors, advertisers or unrelated third parties.
We do not publish a client’s name, screenshots, source code, designs or project details in our portfolio without appropriate permission.
Access to project information is limited to persons who reasonably need it to evaluate, develop, test, maintain or support the project.
Approved subcontractors or specialist providers must handle relevant information confidentially and only for the agreed purpose.
A separate non-disclosure agreement may be considered where a project requires additional written confidentiality terms.
Information may be disclosed when you authorise it, when it is necessary to use an approved service provider for the project, when required to protect legal rights or security, or when disclosure is required by applicable law or a valid legal process.
Recipients
When information may be shared
Byte Craft Enterprises does not sell or rent personal information. Information may be shared only as reasonably necessary with:
- website hosting, server, backup and security providers;
- email, form-delivery and business communication providers;
- analytics, performance or security services where enabled;
- app stores, domain providers, hosting providers or platform services when you request related support;
- authorised contractors or specialists assisting with a project;
- accountants, legal advisers, insurers or professional advisers;
- authorities where disclosure is legally required; or
- a successor organisation if the business is lawfully sold, reorganised or transferred.
Service providers are expected to use relevant information only to perform the service for which they were engaged and to protect it appropriately.
Website technologies
Cookies, logs and analytics
Cookies are small files or browser-storage records used to support website functions, remember settings, maintain security or understand general website use.
Essential technologies
These may be needed for website operation, form security, accessibility, session management, fraud prevention or administrative functionality.
Analytics technologies
Where analytics are enabled, they may collect information about visited pages, approximate location, device type, referral source, interactions and website performance.
Third-party content
Embedded videos, live chat, social links or external services may use their own cookies or similar technologies when loaded or activated.
You can use your browser settings to remove or block cookies. Blocking essential technologies may prevent some website functions from operating correctly.
Interactive assistance
Live chat and AI-assisted tools
The website may display live-chat, automated-support or AI-assisted features. Information entered into those tools may be processed by the technology provider used to operate the feature.
Automated responses are provided for general assistance and should not be treated as a final quotation, contractual commitment, legal advice, security instruction or confirmation that a project has been accepted.
Do not enter account passwords, access tokens, private keys, full payment-card details or highly confidential project files into a public chat or AI-support window.
Global services
International processing and storage
Byte Craft Enterprises serves customers internationally. Website hosting, email, cloud storage, communication platforms, analytics, app-store services and project tools may process or store information in countries other than the country where you live.
Where required, we take reasonable steps to use reputable service providers, appropriate contractual arrangements and other safeguards intended to protect information during international processing.
Safeguards
How we protect information
We use reasonable technical and organisational measures suitable for a small technology business. Depending on the system and project, these measures may include:
- encrypted HTTPS connections;
- password-protected and access-controlled accounts;
- limiting access to persons who need the information;
- software, plugin and server maintenance;
- backups and recovery measures where appropriate;
- spam, abuse and suspicious-login protection;
- secure transfer methods for sensitive project material; and
- deletion or anonymisation when information is no longer needed.
No website, electronic transmission or storage system can be guaranteed to be completely secure. You are responsible for using secure communication methods and protecting any credentials or accounts under your control.
Storage period
How long information is retained
We retain information only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, security or dispute-resolution requirements.
Normally retained for up to 24 months after the last meaningful communication, unless a longer period is reasonably required.
Normally retained for up to 24 months so that we can respond to follow-up enquiries and maintain quotation history.
Retained during the relationship and normally for up to seven years afterwards where needed for accounting, contractual, warranty, legal or dispute purposes.
Normally retained for a shorter operational period, commonly between 30 and 180 days, unless needed to investigate an incident.
Retained until you withdraw consent, unsubscribe or the information is no longer required.
Deleted information may remain temporarily in protected backups until the normal backup cycle removes or overwrites it.
Individual choices
Your privacy rights
Depending on your location and the law that applies, you may have the right to:
We may need to confirm your identity before responding. Rights may be limited where information must be retained for legal, contractual, security, accounting or dispute purposes, or where disclosure would affect another person’s rights.
Young users
Children’s privacy
This corporate website and its quotation services are intended primarily for adults, businesses, organisations and authorised project representatives.
We do not knowingly request personal information from a child who is not legally able to provide it without parental or guardian authorisation. A parent or guardian who believes that a child has submitted information through this website may contact us to request review or deletion.
Education products or child-accessible applications may provide separate, product-specific privacy information.
Other websites
External links, stores and third-party services
This website may link to app stores, social-media platforms, payment providers, client websites, videos, hosting services or other third-party websites.
Third-party services operate under their own terms and privacy policies. Byte Craft Enterprises does not control how an external website or platform processes information after you leave this website.
Revisions
Changes to this policy
We may update this policy when our website, services, suppliers, security practices or legal obligations change.
The revised policy will be published on this page with a new effective date. Where a change significantly affects how existing personal information is used, we will take reasonable steps to provide additional notice where required.
Privacy contact
Questions, requests and complaints
Contact us if you have a question about this policy, want to exercise a privacy right or believe your information has been handled incorrectly.
Please include enough information for us to identify the relevant enquiry or project. Do not send identity documents unless we specifically request an appropriate verification method.
You may have the right to complain to the data-protection authority responsible for your location. In Sri Lanka, privacy matters are regulated by the Data Protection Authority of Sri Lanka.
Visit the Data Protection Authority ↗