Use coupon WELCOME10 for 10% off your first orderShop now →
Legal

Privacy Policy

Effective May 22, 2026. Governed by Spanish and EU law.

Last updated: May 22, 2026

1. Data controller

Auerswald Marketing S.L., Ctra. del Cap de la Nau Pla, 126-1-18, 03730 Xàbia (Alicante), Spain (VAT ESB09946799), operates the website bytedocks.io and the Bytedocks dashboard. We are the controller of the personal data described in this policy under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

You can contact us about any data-protection matter at [email protected] or by post at the address above. We reply within 30 days, usually within 5 business days.

2. Categories of data we collect

We collect three categories of personal data:

  • Account data — name, work email, company, billing address, VAT/NIF and authentication credentials when you create an account.
  • Usage data — request counts, bandwidth, latency, error rates, lease IDs and the geographic regions you target. We do not retain the URLs or payloads of the requests you proxy through our network.
  • Communications — what you write to support, sales and partnerships and what we write back.

We do not collect, log or sell the content of the requests routed through our proxy network. Traffic is seen only long enough to route it.

3. Purposes and legal bases

We process personal data for the following purposes:

  • To provide the service, manage your account and bill you accurately — legal basis: performance of the contract (GDPR Art. 6(1)(b)).
  • To comply with our tax, accounting and anti-fraud obligations under Spanish law — legal basis: legal obligation (GDPR Art. 6(1)(c)).
  • To detect and prevent abuse, fraud and violations of our Terms — legal basis: legitimate interest (GDPR Art. 6(1)(f)).
  • To send you service announcements and respond to your enquiries — legal basis: performance of the contract or legitimate interest.
  • To send commercial communications about products similar to those you have purchased — legal basis: legitimate interest under Art. 21.2 of the LSSI-CE; you can object at any time.

We do not carry out automated decision-making with legal effects and we do not perform behavioural profiling for advertising.

4. Cookies and similar technologies

Our marketing site uses only strictly necessary cookies plus one anonymised analytics cookie that you can refuse without breaking the site. The dashboard uses session cookies needed to keep you logged in. Detailed information is provided in the cookie banner shown on your first visit, in compliance with Art. 22.2 of the LSSI-CE.

5. Processors and sub-processors

To operate the service we rely on the following categories of processors: payment processing (Stripe, PayPal), cloud hosting (within the EEA by default), edge networking (Cloudflare) and transactional email. A current list, including the location of each processor and the categories of data shared, is available on request at [email protected].

All processors are bound by written data-processing agreements meeting the requirements of GDPR Art. 28.

6. International transfers

Personal data is processed within the European Economic Area (EEA) wherever possible. Where a transfer outside the EEA is necessary (for example to a US-based payment processor) we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) together with appropriate supplementary technical and organisational measures.

7. Retention

We keep personal data only for as long as necessary for the purposes set out above:

  • Invoices and accounting records: 6 years (Article 30 of the Spanish Commercial Code) and 4 years for tax purposes (Article 66 of the General Tax Law).
  • Account data: for the duration of your account plus 30 days after closure for recovery, then deleted or anonymised.
  • Usage events: 90 days at request granularity, then aggregated.
  • Support communications: 2 years for quality assurance, unless a longer period is required to resolve a legal claim.

8. Your rights

Under GDPR and the LOPDGDD you have the right to: access your personal data, rectify it, erase it, restrict or object to its processing, request portability (in a structured, machine-readable format), and withdraw any consent you have given. You also have the right not to be subject to a decision based solely on automated processing.

You can exercise these rights by writing to [email protected]. We may need to verify your identity before responding. If you believe your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es), the lead supervisory authority for processing carried out by Auerswald Marketing S.L..

9. Security

We apply the technical and organisational measures required by Article 32 GDPR, including encryption in transit (TLS), encryption at rest for credentials and tokens, role-based access control, audit logging, and regular backup and restoration testing. No system is 100% secure; we will notify you and the Spanish supervisory authority of any personal-data breach affecting your data within the deadlines required by Articles 33 and 34 GDPR.

10. Changes to this policy

We will notify account owners by email of material changes at least 30 days before they take effect. Minor or cosmetic changes are recorded in our internal changelog and reflected in the date at the top of this policy.