Version 2026-09-05
This Privacy Policy describes how Bytloop ("Bytloop", "we", "us") collects, uses, discloses, and protects personal information in connection with Bytloop Mail (the "Service"). It applies to visitors to our marketing site, account owners and end users of the Service ("Customers"), and to individuals whose personal data our Customers process through the Service ("End Recipients").
Under GDPR and similar frameworks, we act as Controller for personal data of our Customers (account owners, teammates, billing contacts, marketing-site visitors) and as Processor for personal data our Customers upload, send, or receive through the Service. When we act as Processor, our Data Processing Agreement applies.
Account & billing: name, email address, hashed password, organisation name, country, IP address, and payment metadata (last-four digits of the card, billing address; full card details go to our Merchant of Record and are never stored by us).
Usage & product: log data (IP, user agent, timestamps, request paths), audit events, mailbox and campaign metadata, feature-usage counters, deliverability metrics, error diagnostics.
Customer Content: the email content, contact lists, templates, and related metadata Customers push into the Service. We handle this as Processor under the DPA.
Marketing site: cookies (see § 8), form submissions, analytics events.
We use personal information to (a) provide, secure, and improve the Service; (b) authenticate users and enforce access controls; (c) bill and support Customers; (d) monitor deliverability and abuse; (e) send transactional and — with consent — marketing communications; (f) comply with legal obligations. We do not sell personal information and we do not use Customer Content to train machine-learning models without explicit opt-in.
We rely on the following legal bases: performance of a contract (running your account and providing the Service); legitimate interests (securing the platform, preventing abuse, product analytics, direct B2B marketing to Customers); legal obligations (tax, KYC where required); consent (marketing emails to non-Customers, optional analytics cookies). You may withdraw consent at any time; see § 9.
We rely on the following categories of sub-processors to provide the Service. Data may be processed in the United States, United Kingdom, European Economic Area, and elsewhere depending on the vendor.
A machine-readable, up-to-date sub-processor list is available on request at hello@bytloop.com. Customers who have signed our DPA will be notified before we add or replace a sub-processor in a way that materially affects the processing of their data.
We share personal information (a) with sub-processors as above; (b) with professional advisers under confidentiality obligations; (c) when required by law, subpoena, or court order (we will notify the affected Customer unless legally prohibited); (d) in connection with a merger, acquisition, or asset sale, in which case we will require the acquiring party to honour this Policy.
We are headquartered in Bangladesh. Data is transferred internationally to and from our sub-processors. For transfers of EEA / UK personal data to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) or, for UK transfers, the UK IDTA. Copies of the executed SCCs are available on request.
Our marketing site and dashboard use strictly necessary cookies (session, CSRF, load balancing) which do not require consent, and optional analytics cookies which we set only after opt-in where required. You can control cookies through your browser settings.
Depending on your location you may have the right to (a) access personal data we hold about you; (b) correct or update it; (c) request deletion; (d) request a portable export; (e) object to or restrict certain processing; (f) withdraw consent where processing is based on consent; (g) lodge a complaint with a supervisory authority (e.g. the ICO in the UK, or your local EU DPA). To exercise a right, email hello@bytloop.com. For End Recipients whose data is in a Customer's account, please contact that Customer first; we will assist them in fulfilling your request.
We do not "sell" or "share" personal information as defined by the CCPA / CPRA. California residents have the right to know, delete, correct, and opt-out of profiling in narrow cases. Requests may be made to hello@bytloop.com. We will not discriminate against you for exercising these rights.
We retain personal information for as long as your account is active and afterwards for as long as reasonably necessary to comply with legal obligations, resolve disputes, and enforce agreements. Customer Content is retained per the Customer's instructions and per the DPA. After account closure, we make Customer Data available for export for at least thirty (30) days, then delete it from active systems within an additional ninety (90) days, subject to backup rotation.
We use administrative, technical, and physical safeguards to protect personal information: encryption in transit (TLS 1.2+) and at rest for the primary database and attachment storage; per-tenant logical isolation; least-privilege access; audit logging; automated dependency and code scanning; incident-response procedures. No system is perfectly secure — if you discover a vulnerability, please report it to security@bytloop.com.
The Service is intended for use by businesses and adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us and we will delete it.
We may update this Policy. Material changes will be announced at least fourteen (14) days in advance by dashboard notice or email to account owners.
Bytloop
Dhaka, Bangladesh
Data protection queries: hello@bytloop.com