BYQ SUPPLY – PRIVACY POLICY
Last updated: 20 June 2025
Please read this Privacy Policy (“Policy”) carefully. It explains how BYQ Supply (“Company,” “we,” “our,” “us”) collects, uses, and safeguards your personal data when you access or use the BYQ Supply platform (the “Platform”).
1. Introduction
1.1 This Policy applies to the BYQ Supply website, dashboard, and related applications or services operated by Marcin Chmielowski UX Design, ul. Marcina Kasprzaka 29/1042, 01-234 Warszawa, Poland (NIP/VAT: PL7551941386).
1.2 It describes the personal data we collect, the reasons for processing, and your rights under the EU General Data Protection Regulation (“GDPR”) and other applicable laws.
2. Data We Collect
We collect the following categories of personal data:
- Account Information: name, email address, password, company name (optional), subscription details.
- Payment Information: transaction IDs and limited card details (last four digits) processed by our payment provider — we never store full card numbers.
- Usage Data: IP address, browser type, device identifiers, pages visited, time spent, and actions taken.
- Cookies & Tracking Technologies: small files that authenticate sessions, remember preferences, and gather analytics (see Section 6).
- Third-Party Sources: data from services you connect (e.g., social login) or public sources, subject to their privacy settings.
3. How We Use Your Data
- Create and maintain your account, providing access to our section library.
- Process payments and manage billing.
- Monitor performance, analyse usage, and improve the Platform (see Section 5).
- Communicate with you about updates, support, marketing (with consent), and security.
- Protect the Platform, prevent fraud, and enforce our Terms & Conditions.
- Comply with legal obligations or respond to lawful requests.
4. Legal Bases for Processing
- Contractual Necessity – to deliver the services you request.
- Legitimate Interests – to maintain and enhance the Platform, ensure security, and market similar services (you may object at any time).
- Consent – for non-essential cookies or direct marketing; you can withdraw consent at any time.
- Legal Obligation – to satisfy tax, bookkeeping, or compliance requirements.
5. Google Analytics
5.1 We use Google Analytics 4 (“GA4”) to obtain aggregated statistics on Platform usage.
5.2 GA4 places cookies that transmit anonymised data (including truncated IP addresses) to Google servers. Google acts as our processor under Standard Contractual Clauses.
5.3 We enable IP anonymisation and disable advertising features. You can opt out via the Google Analytics Opt-out Browser Add-on or through our cookie settings.
6. Cookies & Similar Technologies
We use three main types of cookies and similar technologies:
- Essential cookies: required for login, security, and core functionality.
- Analytics cookies: help us understand usage patterns and are set only with your consent.
- Preference cookies: store language and interface choices.
You can manage cookies via our banner or your browser settings. Disabling cookies may reduce functionality.
7. Sharing of Data
We share data only when necessary:
- Service Providers – hosting, payment, analytics, and support partners processing data on our instructions.
- Business Transfers – in connection with a merger, acquisition, or asset sale, subject to confidentiality.
- Legal Requirements – to comply with law or protect our rights, property, or safety.
8. International Transfers
When data is transferred outside the European Economic Area, we rely on adequacy decisions, Standard Contractual Clauses, or other lawful mechanisms to protect it.
9. Data Retention
We retain personal data only as long as needed for the purposes described in this Policy, to resolve disputes, and to enforce agreements. Usage data is typically anonymised or deleted within 26 months.
10. Security
We employ technical and organisational measures—such as encryption in transit, access controls, and regular backups—to protect your data. No system is completely secure, but we strive to mitigate risks.
11. Your Rights
Under the GDPR, you have the right to:
- Access your data.
- Rectify inaccurate or incomplete data.
- Erase data in certain circumstances.
- Restrict processing.
- Port data to another provider.
- Object to processing based on legitimate interests.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority (e.g., the Polish Data Protection Office — UODO).
12. Children’s Privacy
The Platform is not directed to children under 16. We do not knowingly collect data from children; if we discover such collection, we will delete the data promptly.
13. Third-Party Links
Our Platform may link to external sites. We do not control and are not responsible for their privacy practices.
14. Changes to This Policy
We may update this Policy periodically. Material changes will be announced via email or a prominent notice on the Platform. Continued use after changes means you accept the revised Policy.
15. Contact
For any privacy-related questions, please contact us:
- Email: hi@byq.studio
- Address: Marcin Chmielowski UX Design, ul. Marcina Kasprzaka 29/1042, 01-234 Warszawa, Poland
Effective date: 20 June 2025