Privacy Policy and Cookie Policy
Cookie Policy - scroll down to Part II
Last updated: August 28, 2026
byteLAKE
Privacy Policy and Cookie Policy
Websites: bytelake.com and
bytelake.pl
Last updated: August 28, 2026 ·
Version 2.0
This document
describes how byteLAKE collects, uses, shares, and protects personal data of
visitors, prospective clients, partners, and other users of the websites
bytelake.com and bytelake.pl (together, the “Websites”), and how we use cookies
and similar technologies. It also explains our transparency practices for
artificial intelligence under the EU AI Act and applicable U.S. rules.
This Policy is
intended to meet the requirements of the EU General Data Protection Regulation
(GDPR), the Polish Personal Data Protection Act, the Polish Electronic
Communications Law (Prawo komunikacji elektronicznej) implementing the ePrivacy
rules, Regulation (EU) 2024/1689 (the EU AI Act), the California Consumer
Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the
California Online Privacy Protection Act (CalOPPA), California’s bot-disclosure
rules, the U.S. CAN-SPAM Act, and — where relevant — the U.S. Children’s Online
Privacy Protection Act (COPPA).
This Policy is a website notice,
not legal advice to third parties. If you are entering into a commercial
contract with byteLAKE, processing of client data under that contract is
governed by the contract and, where applicable, a data processing agreement —
not solely by this Policy.
1. Who we are
(data controller)
The controller
of personal data processed in connection with the Websites is the civil
partnership:
“byteLAKE” M. Kolanko, M. Rojek
spółka cywilna (byteLAKE s.c.)
•
Partners: Mariusz Kolanko, conducting business as
Mariusz Kolanko Consulting, and Marcin Rojek, conducting business as Marcin
Rojek Consulting.
•
Registered address: Plac Solny 14 lok. 3, 50-062 Wrocław, Poland
•
NIP (tax ID): 8971829142
•
REGON: 365510178
•
General email: welcome@bytelake.com
•
Privacy email: gdpr@bytelake.com
•
Phone: +48 508 091 885 / +48 505 322 282
We have not
appointed a Data Protection Officer. For GDPR purposes, the partners of the
civil partnership jointly determine the purposes and means of processing
related to the Websites. Privacy requests should be sent to gdpr@bytelake.com.
2. Scope of
this Policy
This Policy
applies to:
•
visits to bytelake.com and bytelake.pl and their
subpages (including blog, product, contact, and download pages);
•
messages sent through Website contact forms and email
addresses published on the Websites;
•
cookies, pixels, tags, local storage, and similar
technologies on the Websites;
•
Google Analytics and Google reCAPTCHA / Google Cloud
Fraud Defense;
•
links and plugins relating to X (Twitter), LinkedIn,
Facebook, YouTube, Medium, and Substack;
•
• website
content that may be created by a human, by AI, or by a human with AI assistance;
• the pricing page (bytelake.com/pricing and any
counterpart on bytelake.pl i.e. bytelake.pl/pricing) — prices are indicative
and are not a binding offer; a binding commercial offer is issued only after
written confirmation by byteLAKE;
• third-party embeds on the Websites, in particular X
(Twitter) posts and YouTube videos;
• the interactive company-location map in the Website
footer (a Google Maps component with an “Open in Maps” control).
This Policy
does not govern processing that occurs solely inside a client’s own IT
environment under a separate professional-services or software agreement (for
example, on-premise or private-AI deployments of Cognitive Services).
3. Personal
data we collect
3.1 Data you provide to us
When you use a
contact form, write to us, call us, or request materials, we may collect:
•
identification and contact data: first name, last
name, business email, phone number, company name, job title, country;
•
the content of your message and any attachments you
choose to send;
•
marketing preferences (if you opt in to receive
communications);
•
any other information you voluntarily include.
3.2 Data collected automatically
When you visit
the Websites we may collect, depending on your cookie choices:
•
technical data: IP address, approximate location
derived from IP, browser type and version, device type, operating system,
language, screen resolution, referring URL, pages viewed, date and time, and
clickstream;
•
cookie identifiers and similar IDs (see Part II);
•
security and abuse-prevention signals used by Google
Cloud Fraud Defense / reCAPTCHA (for example, IP address, user-agent,
interaction patterns, and a risk score) when you submit a form;
•
if an embedded X post, YouTube video, or interactive
Google Map is loaded: IP address, user-agent, referring URL, and identifiers or
cookies set by that platform (Google or X). We load those scripts only after
CookieAdmin consent or after you click a placeholder (“show map / play video /
show post”).
3.3 Data from AI chatbot
interactions (if enabled)
If we enable a
Website chatbot, we may process the text (and, if you upload them, files) you
submit, conversation metadata, session identifiers, timestamp, language, and
technical logs needed to operate, secure, and improve the assistant. Do not
submit special-category data (health, biometric data, political opinions,
trade-union membership, etc.), secrets, or personal data of third parties
unless it is strictly necessary and lawful.
3.4 Data we do not seek
The Websites
are directed at business users. We do not intentionally collect special
categories of personal data or data of children. We do not sell personal
information.
4. Purposes and
legal bases (GDPR / Polish law)
Under Article 6
GDPR we rely on the legal bases below. For cookies and similar technologies
that are not strictly necessary, Polish and EU ePrivacy rules additionally
require prior consent. We do not treat analytics cookies as “strictly
necessary,” and we do not rely on legitimate interest to store non-essential
cookies on your device.
|
Purpose |
Typical
data |
Legal
basis |
|
Responding to
inquiries from contact forms, email, and phone |
Identity,
contact, message content |
Art. 6(1)(b)
GDPR (steps prior to a contract) and/or Art. 6(1)(f) (responding to a
business inquiry). Consent Art. 6(1)(a) where a form checkbox is used. |
|
Operating and
securing the Websites (hosting, backups, logs, abuse prevention) |
IP, logs,
security signals |
Art. 6(1)(f)
GDPR — legitimate interest in a secure, functioning website. Necessary
cookies: ePrivacy exemption for transmission / service expressly requested. |
|
Spam and bot
protection via Google Cloud Fraud Defense (formerly Google reCAPTCHA) |
IP,
device/browser signals, interaction patterns, token |
Art. 6(1)(f)
GDPR and, where the component sets non-essential cookies or equivalent
storage, Art. 6(1)(a) plus ePrivacy consent. |
|
Audience
measurement (Google Analytics 4), loaded only after consent |
Online
identifiers, usage data |
Art. 6(1)(a)
GDPR — consent. No analytics cookies are set before you accept them in
CookieAdmin. |
|
Remembering
cookie choices (CookieAdmin) |
Consent state |
Art. 6(1)(c)
/ 6(1)(f) and ePrivacy necessity — storing your choice is required to respect
it. |
|
Website
chatbot / virtual assistant (if enabled) |
Prompts,
conversation, technical metadata |
Art. 6(1)(a)
consent and/or Art. 6(1)(b) if used to pre-contract, and Art. 6(1)(f) for
security and quality. |
|
B2B marketing
emails or newsletters, if you opt in |
Email, name,
company, preferences |
Art. 6(1)(a)
GDPR and Polish electronic-communications / anti-spam rules. CAN-SPAM for
U.S. recipients. |
|
Establishing,
exercising, or defending legal claims; accounting and tax |
Correspondence,
identifiers |
Art. 6(1)(c)
legal obligation and Art. 6(1)(f) legitimate interest. |
|
Displaying
indicative pricing packages (FAST AI / ENTERPRISE AI) and handling
pre-contract discussions |
form / email
data if an inquiry starts from the pricing page |
Art. 6(1)(b)
and/or (f) GDPR; the page is not a binding offer |
|
Embedding
Google Maps, YouTube videos, and X posts |
IP, technical
data, platform cookies |
Art. 6(1)(a)
GDPR plus ePrivacy / Polish Electronic Communications Law consent. Without
consent we show a placeholder or a plain link |
5. Recipients
and processors
We share
personal data only with:
•
Hosting and website operators — providers
that host the Websites, email, and backups, acting on our instructions.
•
CookieAdmin — the consent-management platform
displayed on the Websites (cookieadmin.net), used to collect and store cookie
choices.
•
Google LLC / Google Cloud — Google
Analytics 4 (audience measurement, only after consent) and Google Cloud Fraud
Defense, which includes the visual bot-defense feature formerly branded solely
as Google reCAPTCHA. Effective April 2, 2026, Google processes reCAPTCHA /
Fraud Defense customer data as a data processor under the Google Cloud Data
Processing Addendum (https://cloud.google.com/terms/data-processing-addendum),
not as an independent controller of that service data. Existing site keys and
API calls continue to work. The service brand in Google Cloud Console,
documentation, and billing is “Google Cloud Fraud Defense.” We use it only to
distinguish legitimate users from automated abuse on forms.
•
•
Professional advisers — accountants,
lawyers, and insurers, where needed.
•
Public authorities — only where
required by law.
• Google LLC (Google Maps Embed / Google Maps Platform
and YouTube) — if the footer map or
a YouTube video is actually loaded. Google then receives at least the IP
address and browser technical data. For that traffic Google acts in part as an
independent controller under its own Google / YouTube privacy policy, and in part
as our provider of the embed. Transfers to the United States rely on an
adequacy decision (EU–U.S. Data Privacy Framework, where Google is certified)
and/or Standard Contractual Clauses.
• X Corp. (formerly Twitter) — if an embedded X post is actually loaded. X then
receives at least the IP address and browser technical data and is an
independent controller on its own platform.
• Cloudflare, Inc.
– CDN, WAF and bot protection (__cf_bm).
A plain “Open in Maps” text link that only opens
maps.google.com after a click does not load an embed on our site. The
interactive footer map does.
Social-media
platforms (X, LinkedIn, Facebook/Meta, YouTube/Google, Medium, Substack) are
independent controllers of data collected on their own properties. If you click
a social link or load an embedded player, that platform may process data under
its own policy. We do not operate those platforms.
We do not sell
personal information and we do not share it for cross-context behavioral
advertising of the type that would require a “Do Not Sell or Share” sale under
CPRA for our current Website stack. If that changes, we will update this Policy
and provide a conspicuous opt-out.
6.
International transfers
Some recipients
(notably Google, Microsoft, and OpenAI) are established in the United States or
process data there. Where GDPR Chapter V applies, we rely on one or more of:
(i) an adequacy decision, including the EU–U.S. Data Privacy Framework for
certified organizations; (ii) the European Commission’s Standard Contractual
Clauses together with transfer impact assessments and supplementary measures
offered by the provider; and/or (iii) the provider’s data-processing addendum.
A copy of the relevant safeguards can be requested at gdpr@bytelake.com,
subject to confidentiality.
The same applies to Google Cloud / Vertex AI: we will set
the processing region in the Google Cloud project (EEA regions preferred where
the model and feature allow); remaining U.S. transfers rely on the Data Privacy
Framework (if Google is certified) and/or the SCCs in the Google Cloud DPA.
Chatbot / AI Agent: we aim to run the chosen model in an
EEA region the provider offers. Some operations (including security and
failover) may still occur outside the EEA; in that case we use the Chapter V
GDPR tools described above.
7. Retention
•
Contact and pre-contract correspondence: for the
time needed to handle the inquiry and then up to 3 years after the last
meaningful contact, unless a longer period is required for claims or a contract
is concluded.
•
Accounting and tax records: for the
periods required by Polish tax and accounting law (typically 5 years from the
end of the relevant year).
•
Marketing contacts: until you withdraw consent or
unsubscribe, plus a short suppression record so we can honor the opt-out.
•
Server and security logs: typically
up to 12 months, longer if needed to investigate an incident.
•
Analytics data: according to the Google Analytics
retention setting we configure, not longer than 26 months, and only if you
consented.
•
Cookie consent records: for the
life of the consent proof plus a period needed to demonstrate compliance (up to
3 years).
•
Chatbot transcripts (if enabled): up to 12
months unless you ask us to delete them earlier or a longer period is needed to
handle a follow-up inquiry.
When the
purpose expires we delete or irreversibly anonymize the data.
8. Your rights
(EEA / UK / Poland)
You may
request: access; rectification; erasure; restriction; portability; and
objection to processing based on legitimate interests. Where processing is
based on consent, you may withdraw consent at any time, without affecting
lawfulness before withdrawal. You may also lodge a complaint with the President
of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych,
PUODO), ul. Stawki 2, 00-193 Warszawa, Poland, https://uodo.gov.pl, or with
another EEA supervisory authority of your habitual residence or place of work.
To exercise
rights, email gdpr@bytelake.com. We may need to verify your identity. We will
respond within one month, extendable by two months for complex requests as
permitted by Article 12 GDPR.
9. Security
We use
HTTPS/TLS on the Websites, access control, least-privilege administration, and
contractual security obligations for processors. No method of transmission or
storage is perfectly secure. Please do not send passwords, payment-card data,
or highly confidential trade secrets through a public contact form or a Website
chatbot.
10. Children
The Websites
are not directed to children. We do not knowingly collect personal data from
anyone under 16 (GDPR) or under 13 (COPPA). If you believe a child has
submitted data, contact gdpr@bytelake.com and we will delete it.
11. Automated
decision-making
We do not use
Website data to make solely automated decisions that produce legal or similarly
significant effects on you (Article 22 GDPR). Fraud Defense / reCAPTCHA may
produce a risk score that helps us accept or challenge a form submission; a
human can review false positives if you contact us. A chatbot does not bind
byteLAKE and does not make formal contractual decisions.
12. Artificial
intelligence transparency (EU AI Act and related rules)
12.1 Interaction with an AI system
(chatbot)
We may
deploy a chatbot, assistant or AI Agent on the Websites using models from
OpenAI, Microsoft Azure OpenAI and/or Google Cloud Vertex AI (Gemini or another
Vertex AI managed model, including Agent Builder / Agent Engine). Under Article 50(1) of the EU AI Act, and under California
bot-disclosure rules, we inform you that:
•
you would be interacting with an
artificial-intelligence system, not a human, unless a member of our team later
joins the conversation;
•
answers can be incomplete, outdated, or incorrect and
are not legal, financial, medical, or engineering advice;
•
the chatbot does not create a contract and does not
replace a written quotation;
•
prompts and replies may be processed by our
subprocessors outside Poland, as described in Sections 5 and 6;
•
you should not paste confidential client data,
personal data of third parties, or special-category data into the chatbot.
If a chatbot is
live, a clear notice will also appear in the chat window itself (for example:
“You are chatting with an AI assistant”). That on-interface notice is the
primary Article 50(1) disclosure; this Policy is supporting documentation.
12.2 Website content created with
AI
Some texts,
images, or other materials on the Websites may be created by a human, generated
by AI, or produced by a human using AI tools and then edited. byteLAKE remains
editorially responsible for content we publish on the Websites. Where Article
50 of the AI Act requires labeling of AI-generated or manipulated content (for
example, certain deepfakes or AI-generated text published to inform the public
on matters of public interest without human review), we will label that content
in a manner appropriate to the medium. Marketing and product pages that have
undergone human review and for which byteLAKE holds editorial responsibility
are treated accordingly.
12.3 Our products versus this
Website
byteLAKE
designs industrial and enterprise AI (Cognitive Services, explainable models,
intelligent agents, private and edge deployments). Those systems are provided
to clients under separate contracts, technical documentation, and — where the
AI Act requires it — instructions for use, transparency information, and risk
measures. This Policy covers only the public Websites, not the classification
or conformity of client-deployed systems.
13. California
and other U.S. privacy notices
This Section is
provided under the CCPA/CPRA and CalOPPA. In the last 12 months we may have
collected the following categories of personal information from Website
visitors: identifiers (name, email, IP, cookie ID); commercial information
(inquiries about products); internet or electronic-network activity (browsing
on our Websites); and geolocation at a coarse IP level. We collect it from you
and from your device/browser. We use it for the business purposes in Section 4.
We disclose it to service providers / contractors listed in Section 5. We do
not sell personal information and we do not share it for cross-context
behavioral advertising in the current configuration of the Websites. We do not
use or disclose sensitive personal information for purposes that would require
a CPRA right to limit.
California
residents may request: (1) to know the categories and specific pieces of
personal information we collected, sources, purposes, and categories of
recipients; (2) deletion; (3) correction; (4) opt-out of sale or sharing (we do
not sell or share, but you may still send an opt-out request); and (5)
non-discrimination for exercising CPRA rights. Authorized agents may submit
requests with proof of authorization. We will verify requests using information
we already hold (for example, the email used to contact us). Email
gdpr@bytelake.com with the subject line “California Privacy Request.” You may
also use a Global Privacy Control (GPC) signal; we will treat a recognized GPC
signal as a request to opt out of sale/sharing for that browser.
Shine the Light
/ CalOPPA: we do not disclose personal information to third parties for their
own direct marketing in a way that triggers a separate annual “Shine the Light”
catalog. Our Websites identify the operator and include a link to this Policy.
CAN-SPAM: marketing emails include our physical postal address and an
unsubscribe mechanism.
14. Marketing
communications
We send
commercial electronic communications only if you have given a valid consent (or
another basis permitted by the law applicable to you). Every marketing email
includes an unsubscribe link. You may also write to gdpr@bytelake.com or
welcome@bytelake.com.
PART II —
COOKIE POLICY
This Part
explains cookies and similar technologies on bytelake.com and bytelake.pl, in
line with the GDPR, the Polish Electronic Communications Law, and the EU
ePrivacy framework.
15. What cookies are
Cookies are
small text files stored on your device. Similar technologies include pixels,
tags, local storage, and SDK identifiers. Some cookies are first-party (set by
us); others are third-party (set by a provider such as Google).
16. How we obtain consent
On your first
visit a CookieAdmin banner lets you Accept all, Reject all (non-essential), or
Customize categories. Non-essential cookies — including Google Analytics — are
not set until you opt in. You can change your choice later through the banner
or cookie icon. Rejecting non-essential cookies does not block the core Website
or the contact form, although bot-protection and some embeds may be limited.
Under Polish
law there is no analytics exemption. Legitimate interest is not a substitute
for ePrivacy consent to store or read non-essential cookies.
17. Categories we use
Strictly necessary
Required to
transmit communications or to provide a service you request: load balancing and
security, storing your cookie choice, keeping a form session, and similar.
These do not require opt-in consent.
Analytics (consent required)
Google
Analytics 4 helps us understand aggregate traffic (pages viewed, approximate
geography, device class, referral source). We aim to use IP masking / Consent
Mode so that tags respect the banner. Analytics cookies are first-party on our
domain but the resulting data is processed by Google.
Functional / security (consent where not strictly
necessary)
Google Cloud
Fraud Defense / reCAPTCHA helps prevent automated abuse of forms. Depending on
configuration it may set cookies or use other storage. Where storage is not
strictly necessary for the form you requested, we treat it as consent-based.
WordPress / theme preferences may store display settings.
Social and embedded media (consent required if they set
cookies)
Links to X,
LinkedIn, Facebook, YouTube, Medium, and Substack. A simple hyperlink does not
by itself set a third-party cookie. If we embed a player or a social plugin
that contacts those platforms before you click through, that embed is gated by
consent.
The Websites may embed an interactive Google Map in the
footer, YouTube videos, and X posts. A plain hyperlink (for example “Open in
Maps” opening a new tab) does not set cookies on our site. Loading an embed
iframe or script connects the browser directly to Google or X, transmits the IP
address, and may set their cookies (including Google’s NID). Embeds therefore
load only after CookieAdmin consent (media / functional / social category, as
configured in the banner) or after a click on a placeholder. Until then we
should show a static image or a “Show map / Play video / Show post” button.
Chatbot (consent required if enabled)
Session or
preference cookies used only to run a Website AI assistant.
18. Cookie inventory (typical)
Exact names can
change when providers update their products. The live list in the CookieAdmin
panel prevails if it differs. Typical items:
|
Name |
Provider |
Category |
Typical
life |
Purpose |
|
cookieadmin /
consent cookies |
CookieAdmin /
byteLAKE |
Necessary |
up to 12
months |
Stores your
accept / reject / customize choice |
|
WordPress
session / csrf (e.g. wordpress_test_cookie, PHPSESSID) |
byteLAKE
(first party) |
Necessary |
session |
Site and form
operation |
|
_ga |
Google
Analytics 4 |
Analytics |
up to 13–24
months |
Distinguishes
unique visitors (client ID) |
|
_ga_<container> |
Google
Analytics 4 |
Analytics |
up to 13–24
months |
Session and
engagement state for the GA4 property |
|
_gid |
Google
Analytics (if present) |
Analytics |
24 hours |
Short-lived
visitor distinction |
|
reCAPTCHA /
Fraud Defense cookies (e.g. _GRECAPTCHA) and related storage |
Google Cloud
Fraud Defense |
Security /
functional |
session to 6
months |
Bot and abuse
protection on forms |
|
__cf_bm | Cloudflare | necessary | session | bot protection |
|
NID and other
Google-domain cookies on Maps / YouTube |
Google LLC |
Embedded
media (consent) |
up to 6
months (NID may last longer) |
Map / player
function; Google may link this to a Google account if the visitor is signed
in |
|
YouTube
player cookies (e.g. VISITOR_INFO1_LIVE, YSC, PREF) |
Google /
YouTube |
Embedded
media (consent) |
session to ~6
months |
Playback,
measurement, YouTube-side abuse protection |
|
X embed
cookies / storage (x.com / twitter.com) |
X Corp. |
Embedded
media (consent) |
session or
per X |
Render the
post, counters, identification on X |
|
__wpdm_client |
WordPress
Download Manager |
necessary |
session |
guest
download session for brochures and case studies |
|
cookieadmin_consent |
CookieAdmin |
necessary |
session / up
to 180 days |
stores
consent |
|
Chatbot / Agent widget cookies or storage (if enabled) |
byteLAKE and the chosen provider: OpenAI, Microsoft or Google Cloud / Vertex AI |
Chatbot (consent) |
session or short-lived |
Keeps the Website conversation thread |
19. Google Cloud Fraud Defense
(reCAPTCHA) — what changed
Google notified
Website administrators that, effective April 23, 2026, Google reCAPTCHA is
presented as part of Google Cloud Fraud Defense. “Google reCAPTCHA” now refers
specifically to the visual bot-defense feature inside that platform. There is
no change to existing site keys, secret keys, API calls, service levels, or
pricing solely because of the rebrand.
Separately,
effective April 2, 2026, Google confirmed that it processes customer data for
this service as a data processor under the Google Cloud Data Processing
Addendum (https://cloud.google.com/terms/data-processing-addendum), not as a
controller of that service data. Accordingly, this Policy no longer treats
Google’s consumer Privacy Policy as the document that governs Fraud Defense /
reCAPTCHA processing performed for us. Google processes that data on our
documented instructions to protect forms. Background reading from Google:
“Switching Google’s role with reCAPTCHA from Data Controller to Data
Processor.”
Our affected
Google Cloud project identifier (as stated in Google’s notice) includes:
bytelake-1753369126948.
20. How to control cookies
•
Use the CookieAdmin banner / icon on the Websites.
•
Use your browser settings to block or delete cookies.
Blocking necessary cookies may break the form or consent tool.
•
Google Analytics opt-out add-on:
https://tools.google.com/dlpage/gaoptout
•
Industry opt-out pages and your device advertising-ID
settings, if advertising cookies ever appear.
•
Email gdpr@bytelake.com if the banner does not work.
21. Changes
We may update
this Policy when our stack, providers, or the law changes (including further AI
Act guidance). The “Last updated” date will change. Material changes will be
highlighted on the Websites or, if we hold your email for that purpose,
notified to you.
22. Contact
byteLAKE s.c.
Plac Solny 14 lok. 3, 50-062 Wrocław,
Poland
Privacy: gdpr@bytelake.com
General: welcome@bytelake.com
Phone: +48 508 091 885 / +48 505 322
282
Supervisory
authority (Poland): Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa,
https://uodo.gov.pl. California Privacy Protection Agency: https://cppa.ca.gov.