Privacy Policy
BitByte Factory
Last Updated: February 14, 2026
Effective Date: February 14, 2026
Introduction
BitByte Factory (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our automation services, visit our website at https://bitbytefactory.com, or engage with us in any way.
We provide specialized automation solutions using workflow technology, integrating with various platforms including Meta (Facebook, Instagram), Google services, and other third-party APIs to streamline your business processes.
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
1. Information We Collect
1.1 Information You Provide to Us
When you register for our services or engage with us, we collect:
- Account Information: Name, email address, company name, business address, phone number
- Payment Information: Billing address, payment method details (processed securely by our payment processor)
- Communication Data: Information you provide when contacting our support team, attending events, or participating in our community
- Professional Information: Job title, company details, industry sector
1.2 Platform Integration Data
When you connect third-party services to our automation platform, we may access and process:
- Meta Platform Data: Facebook Page IDs, Instagram Business Account IDs, access tokens, page posts, comments, messages, media content, user engagement metrics, and related metadata accessed through Meta Graph API
- Google Services Data: Google Sheets data, Google Drive files, Gmail messages, Calendar events (only data you explicitly authorize via OAuth)
- Other API Data: Data from any third-party platforms you choose to integrate with our automation workflows
- Authentication Tokens: API keys, OAuth tokens, and access credentials required for platform integrations
1.3 Workflow and Usage Data
We automatically collect information about how you use our services:
- Workflow Metadata: Workflow configurations, node connections, execution logs, timestamps, success/failure status
- Technical Data: IP address, browser type, operating system, device information, referring URLs
- Usage Analytics: Features used, frequency of access, performance metrics, error reports
- Cookies and Tracking: We use cookies and similar technologies to analyze website usage and improve user experience (see our Cookie Policy)
1.4 Information We Do Not Collect
- We do not collect sensitive personal information such as racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data unless explicitly required for a specific workflow you create
- We do not access your platform data beyond what you explicitly authorize through OAuth permissions
- We do not store credit card information directly (handled by our payment processor)
2. How We Use Your Information
We use the collected information for the following purposes:
2.1 Service Provision and Execution
- To create, maintain, and provide access to your automation workflows
- To execute automated tasks across connected platforms (Meta, Google, and other APIs)
- To process data according to your workflow configurations
- To monitor workflow execution, performance, and error handling
- To provide customer support and respond to your inquiries
2.2 Service Improvement and Analytics
- To analyze usage patterns and improve our platform functionality
- To develop new features and optimize user experience
- To identify and fix technical issues, bugs, and security vulnerabilities
- To conduct research and development for service enhancements
2.3 Communication and Marketing
- To send service-related notifications, updates, and announcements
- To provide technical support and respond to your requests
- To send newsletters and marketing communications (with your consent, where required)
- To inform you about new features, promotions, and events
2.4 Legal and Security
- To comply with legal obligations and regulatory requirements
- To protect against fraud, unauthorized access, and security threats
- To enforce our Terms of Service and other agreements
- To protect the rights, property, and safety of our users and the public
2.5 Important Limitations
- We do not use any personal data, including data received through third-party services, for developing, improving, or training AI and/or ML models
- We do not sell, rent, or trade your personal information to third parties for their marketing purposes
- We do not share your data with third parties except as described in this Privacy Policy
3. How We Share Your Information
We may share your information in the following circumstances:
3.1 Third-Party Service Providers
We work with trusted service providers who assist us in operating our platform:
- Payment Processors: To handle billing and payment transactions securely
- Cloud Hosting Providers: To store data and host our infrastructure (EU-based servers)
- Analytics Services: To understand user behavior and improve our services
- Customer Support Tools: To provide efficient support services
- Email Service Providers: To send service-related and marketing communications
These service providers are contractually obligated to protect your data and use it only for the purposes we specify.
3.2 Platform APIs
When you create workflows, data is transmitted to the third-party platforms you connect:
- Meta Platforms: Data sent to Facebook and Instagram through Meta Graph API according to your workflow logic
- Google Services: Data sent to Google Sheets, Drive, Gmail, or other Google services you integrate
- Other APIs: Data shared with any third-party platforms included in your workflows
These platforms operate under their own privacy policies, which we encourage you to review.
3.3 Legal Requirements
We may disclose your information when required by law or in response to:
- Valid legal processes (subpoenas, court orders, government requests)
- Enforcement of our Terms of Service or other agreements
- Protection of our rights, property, safety, or that of our users
- Prevention of fraud, security threats, or illegal activities
3.4 Business Transfers
If BitByte Factory is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred to the acquiring entity. We will notify you of any such change and the choices you may have regarding your information.
3.5 With Your Consent
We may share your information with third parties when you provide explicit consent for specific purposes.
4. Data Storage and Security
4.1 Data Location
- We store your data primarily in the European Union (EU) to ensure compliance with GDPR
- Data may be processed in other jurisdictions where our service providers operate
- When transferring data outside the EU, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs)
4.2 Security Measures
We implement industry-standard security measures to protect your data:
- Encryption: Data encryption in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Role-based access controls and multi-factor authentication
- API Security: Secure storage of API keys and tokens with encryption
- Monitoring: Continuous security monitoring and threat detection
- Regular Audits: Periodic security assessments and vulnerability testing
- Employee Training: Regular security awareness training for our team
4.3 Your Responsibility
You are responsible for:
- Maintaining the security of your account credentials
- Ensuring authorized access to your account and workflows
- Properly configuring your workflows to comply with applicable privacy laws
- Safeguarding API keys and access tokens for third-party integrations
5. Data Retention
5.1 Retention Periods
We retain your personal information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal, regulatory, and reporting requirements
- Resolve disputes and enforce our agreements
- Support legitimate business interests
5.2 Specific Retention Guidelines
| Data Type | Retention Period |
| Account Information | Duration of account + 30 days after closure |
| Workflow Data | Duration of account + 30 days after closure |
| Execution Logs | 90 days from execution date |
| Payment Records | 7 years (legal requirement) |
| Support Communications | 3 years from last interaction |
| Marketing Data | Until consent withdrawal + 30 days |
Table 1: Data retention periods by category
5.3 Data Deletion
When retention periods expire or when you request deletion:
- We securely delete or anonymize your personal data
- Anonymized data may be retained indefinitely for analytics and research
- Backups containing your data are deleted according to our backup retention schedule (maximum 90 days)
- Some data may be retained longer if required by law or for legitimate legal purposes
6. Your Rights Under Data Protection Laws
6.1 GDPR Rights (EU/EEA Users)
If you are located in the European Union or European Economic Area, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data (“right to be forgotten”)
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Data Portability: Request transfer of your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent for data processing at any time
- Right to Lodge a Complaint: File a complaint with your local supervisory authority
6.2 Other Jurisdictions
Users in other jurisdictions may have similar rights under applicable data protection laws, including:
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- UK Data Protection Act
- Brazil’s Lei Geral de Proteção de Dados (LGPD)
- India’s Digital Personal Data Protection Act (DPDPA)
6.3 Exercising Your Rights
To exercise any of these rights:
- Email us at: privacy@bitbytefactory.com
- Access your account settings to update certain information directly
- Contact our Data Protection Officer (DPO) for complex requests
We will respond to your request within 30 days (or as required by applicable law). We may need to verify your identity before processing your request.
7. Third-Party Platforms and Services
7.1 Platform Responsibilities
When you integrate third-party platforms (Meta, Google, etc.) with our automation services:
- Each platform operates under its own privacy policy and terms of service
- We are not responsible for the privacy practices of these platforms
- You grant us permission to access and process data from these platforms as necessary to execute your workflows
- You are responsible for ensuring your workflows comply with each platform’s policies
7.2 Key Platform Policies
We recommend reviewing the privacy policies of platforms you integrate:
- Meta Privacy Policy: https://www.facebook.com/privacy/policy/
- Google Privacy Policy: https://policies.google.com/privacy
- Other platforms: Refer to their respective privacy documentation
7.3 OAuth and Permissions
- We use OAuth 2.0 for secure authentication with third-party platforms
- You explicitly authorize the specific permissions we request
- You can revoke access permissions at any time through the respective platform’s settings
- We only access data covered by the permissions you grant
8. Cookies and Tracking Technologies
8.1 Types of Cookies We Use
- Essential Cookies: Required for basic website functionality and security
- Analytics Cookies: Help us understand how visitors use our website (Google Analytics)
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Track your activity for advertising purposes (with consent)
8.2 Cookie Management
You can control cookies through:
- Your browser settings (most browsers allow you to refuse cookies)
- Our cookie consent banner (for non-essential cookies)
- Opting out of third-party analytics services
Note that disabling essential cookies may impact website functionality.
9. Children’s Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@bitbytefactory.com, and we will delete such information promptly.
10. International Data Transfers
10.1 Cross-Border Transfers
If you access our services from outside the EU, your information may be transferred to and processed in the EU or other countries where our service providers operate.
10.2 Transfer Safeguards
We implement appropriate safeguards for international transfers:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Other legally approved transfer mechanisms
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
11.1 Notification of Changes
- We will post the updated Privacy Policy on our website with a new “Last Updated” date
- For material changes, we will notify you via email (if you have an account) or through a prominent notice on our website
- We may also announce updates through in-app notifications
11.2 Your Acceptance
Continued use of our services after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated policy, you should discontinue using our services and may request account deletion.
12. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
BitByte Factory
Email: privacy@bitbytefactory.com
Support: support@bitbytefactory.com
Website: https://bitbytefactory.com
Address: Pune, Maharashtra, India
Data Protection Officer (DPO):
For GDPR-related inquiries, you may contact our Data Protection Officer at: dpo@bitbytefactory.com
Supervisory Authority:
EU/EEA users have the right to lodge a complaint with their local data protection authority. You can find your supervisory authority at: https://edpb.europa.eu/about-edpb/board/members_en
13. Additional Information for Specific Users
13.1 California Residents (CCPA/CPRA)
California residents have additional rights including:
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to deletion of personal information
- Right to non-discrimination for exercising privacy rights
We do not sell your personal information.
To exercise your California privacy rights, contact us at privacy@bitbytefactory.com.
13.2 UK Residents
UK residents have similar rights to EU residents under the UK Data Protection Act 2018 and UK GDPR. Contact us at privacy@bitbytefactory.com to exercise your rights.
13.3 Indian Users (DPDPA)
Indian users have rights under the Digital Personal Data Protection Act, including rights to access, correction, deletion, and data portability. Contact us at privacy@bitbytefactory.com.
14. Data Processing Agreement (DPA)
For enterprise customers or users processing personal data on behalf of others (acting as data processors), we offer a separate Data Processing Agreement (DPA) that includes:
- Detailed processing terms and obligations
- Security measures and incident response procedures
- Sub-processor information
- International data transfer provisions
- Audit rights and compliance requirements
Contact us at legal@bitbytefactory.com to request our DPA.
15. Your Consent
By using our services, you consent to this Privacy Policy and agree to its terms. If you do not agree, please do not use our services.
Thank you for trusting BitByte Factory with your automation needs. We are committed to protecting your privacy and handling your data responsibly.