welcome@bytelake.com
byteLAKE s.c. Plac Solny 14 lok. 3, 50-062 Wrocław, Poland
Get Quote
Privacy Policy
HomePrivacy Policy

Privacy Policy and Cookie Policy

Last updated: August 28, 2026

byteLAKE

Privacy Policy and Cookie Policy

Websites: bytelake.com and bytelake.pl

Last updated: August 28, 2026  ·  Version 2.0

This document describes how byteLAKE collects, uses, shares, and protects personal data of visitors, prospective clients, partners, and other users of the websites bytelake.com and bytelake.pl (together, the “Websites”), and how we use cookies and similar technologies. It also explains our transparency practices for artificial intelligence under the EU AI Act and applicable U.S. rules.

This Policy is intended to meet the requirements of the EU General Data Protection Regulation (GDPR), the Polish Personal Data Protection Act, the Polish Electronic Communications Law (Prawo komunikacji elektronicznej) implementing the ePrivacy rules, Regulation (EU) 2024/1689 (the EU AI Act), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the California Online Privacy Protection Act (CalOPPA), California’s bot-disclosure rules, the U.S. CAN-SPAM Act, and — where relevant — the U.S. Children’s Online Privacy Protection Act (COPPA).

This Policy is a website notice, not legal advice to third parties. If you are entering into a commercial contract with byteLAKE, processing of client data under that contract is governed by the contract and, where applicable, a data processing agreement — not solely by this Policy.

1. Who we are (data controller)

The controller of personal data processed in connection with the Websites is the civil partnership:

“byteLAKE” M. Kolanko, M. Rojek spółka cywilna (byteLAKE s.c.)

    Partners: Mariusz Kolanko, conducting business as Mariusz Kolanko Consulting, and Marcin Rojek, conducting business as Marcin Rojek Consulting.

    Registered address: Plac Solny 14 lok. 3, 50-062 Wrocław, Poland

    NIP (tax ID): 8971829142

    REGON: 365510178

    General email: welcome@bytelake.com

    Privacy email: gdpr@bytelake.com

    Phone: +48 508 091 885 / +48 505 322 282

We have not appointed a Data Protection Officer. For GDPR purposes, the partners of the civil partnership jointly determine the purposes and means of processing related to the Websites. Privacy requests should be sent to gdpr@bytelake.com.

 

 

2. Scope of this Policy

This Policy applies to:

    visits to bytelake.com and bytelake.pl and their subpages (including blog, product, contact, and download pages);

    messages sent through Website contact forms and email addresses published on the Websites;

    cookies, pixels, tags, local storage, and similar technologies on the Websites;

    Google Analytics and Google reCAPTCHA / Google Cloud Fraud Defense;

    links and plugins relating to X (Twitter), LinkedIn, Facebook, YouTube, Medium, and Substack;

    any Website chatbot, assistant or AI Agent based on one or more of: OpenAI; Microsoft Azure OpenAI; Google Cloud / Vertex AI (including Gemini on Vertex AI, Vertex AI Agent Builder / Agent Engine, and other managed models from Vertex AI Model Garden);

    website content that may be created by a human, by AI, or by a human with AI assistance;

    the pricing page (bytelake.com/pricing and any counterpart on bytelake.pl i.e. bytelake.pl/pricing) — prices are indicative and are not a binding offer; a binding commercial offer is issued only after written confirmation by byteLAKE;

    third-party embeds on the Websites, in particular X (Twitter) posts and YouTube videos;

    the interactive company-location map in the Website footer (a Google Maps component with an “Open in Maps” control).

This Policy does not govern processing that occurs solely inside a client’s own IT environment under a separate professional-services or software agreement (for example, on-premise or private-AI deployments of Cognitive Services).

3. Personal data we collect

3.1 Data you provide to us

When you use a contact form, write to us, call us, or request materials, we may collect:

    identification and contact data: first name, last name, business email, phone number, company name, job title, country;

    the content of your message and any attachments you choose to send;

    marketing preferences (if you opt in to receive communications);

    any other information you voluntarily include.

3.2 Data collected automatically

When you visit the Websites we may collect, depending on your cookie choices:

    technical data: IP address, approximate location derived from IP, browser type and version, device type, operating system, language, screen resolution, referring URL, pages viewed, date and time, and clickstream;

    cookie identifiers and similar IDs (see Part II);

    security and abuse-prevention signals used by Google Cloud Fraud Defense / reCAPTCHA (for example, IP address, user-agent, interaction patterns, and a risk score) when you submit a form;

    if an embedded X post, YouTube video, or interactive Google Map is loaded: IP address, user-agent, referring URL, and identifiers or cookies set by that platform (Google or X). We load those scripts only after CookieAdmin consent or after you click a placeholder (“show map / play video / show post”).

3.3 Data from AI chatbot interactions (if enabled)

If we enable a Website chatbot, we may process the text (and, if you upload them, files) you submit, conversation metadata, session identifiers, timestamp, language, and technical logs needed to operate, secure, and improve the assistant. Do not submit special-category data (health, biometric data, political opinions, trade-union membership, etc.), secrets, or personal data of third parties unless it is strictly necessary and lawful.

3.4 Data we do not seek

The Websites are directed at business users. We do not intentionally collect special categories of personal data or data of children. We do not sell personal information.


 

4. Purposes and legal bases (GDPR / Polish law)

Under Article 6 GDPR we rely on the legal bases below. For cookies and similar technologies that are not strictly necessary, Polish and EU ePrivacy rules additionally require prior consent. We do not treat analytics cookies as “strictly necessary,” and we do not rely on legitimate interest to store non-essential cookies on your device.

 

Purpose

Typical data

Legal basis

Responding to inquiries from contact forms, email, and phone

Identity, contact, message content

Art. 6(1)(b) GDPR (steps prior to a contract) and/or Art. 6(1)(f) (responding to a business inquiry). Consent Art. 6(1)(a) where a form checkbox is used.

Operating and securing the Websites (hosting, backups, logs, abuse prevention)

IP, logs, security signals

Art. 6(1)(f) GDPR — legitimate interest in a secure, functioning website. Necessary cookies: ePrivacy exemption for transmission / service expressly requested.

Spam and bot protection via Google Cloud Fraud Defense (formerly Google reCAPTCHA)

IP, device/browser signals, interaction patterns, token

Art. 6(1)(f) GDPR and, where the component sets non-essential cookies or equivalent storage, Art. 6(1)(a) plus ePrivacy consent.

Audience measurement (Google Analytics 4), loaded only after consent

Online identifiers, usage data

Art. 6(1)(a) GDPR — consent. No analytics cookies are set before you accept them in CookieAdmin.

Remembering cookie choices (CookieAdmin)

Consent state

Art. 6(1)(c) / 6(1)(f) and ePrivacy necessity — storing your choice is required to respect it.

Website chatbot / virtual assistant (if enabled)

Prompts, conversation, technical metadata (OpenAI / Azure OpenAI / Vertex AI)

Art. 6(1)(a) consent and/or Art. 6(1)(b) if used to pre-contract, and Art. 6(1)(f) for security and quality.

B2B marketing emails or newsletters, if you opt in

Email, name, company, preferences

Art. 6(1)(a) GDPR and Polish electronic-communications / anti-spam rules. CAN-SPAM for U.S. recipients.

Establishing, exercising, or defending legal claims; accounting and tax

Correspondence, identifiers

Art. 6(1)(c) legal obligation and Art. 6(1)(f) legitimate interest.

Displaying indicative pricing packages (FAST AI / ENTERPRISE AI) and handling pre-contract discussions

form / email data if an inquiry starts from the pricing page

Art. 6(1)(b) and/or (f) GDPR; the page is not a binding offer

Embedding Google Maps, YouTube videos, and X posts

IP, technical data, platform cookies

Art. 6(1)(a) GDPR plus ePrivacy / Polish Electronic Communications Law consent. Without consent we show a placeholder or a plain link

 

5. Recipients and processors

We share personal data only with:

    Hosting and website operators — providers that host the Websites, email, and backups, acting on our instructions.

    CookieAdmin — the consent-management platform displayed on the Websites (cookieadmin.net), used to collect and store cookie choices.

    Google LLC / Google Cloud — Google Analytics 4 (audience measurement, only after consent) and Google Cloud Fraud Defense, which includes the visual bot-defense feature formerly branded solely as Google reCAPTCHA. Effective April 2, 2026, Google processes reCAPTCHA / Fraud Defense customer data as a data processor under the Google Cloud Data Processing Addendum (https://cloud.google.com/terms/data-processing-addendum), not as an independent controller of that service data. Existing site keys and API calls continue to work. The service brand in Google Cloud Console, documentation, and billing is “Google Cloud Fraud Defense.” We use it only to distinguish legitimate users from automated abuse on forms.

    OpenAI, L.L.C.; Microsoft (Azure OpenAI); Google Cloud / Google LLC (Vertex AI, Gemini on Vertex AI, Vertex AI Agent Builder / Agent Engine) — if and when a Website chatbot or AI Agent is enabled. The chosen provider processes prompts, replies and technical metadata as a processor under its data-processing terms (for Google: the Google Cloud Data Processing Addendum and the Vertex AI Service Specific Terms). We will use the enterprise / API / Vertex AI setup so that Website conversations are not used to train publicly available foundation models, to the extent the provider’s then-current terms allow. We will not connect the consumer Gemini app (gemini.google.com), whose data uses differ from Google Cloud. If we select a third-party model from Vertex AI Model Garden (for example Anthropic, Meta or Mistral), that vendor is a Google sub-processor under Vertex AI terms — we will provide the sub-processor list on request (gdpr@bytelake.com). Google may log prompts for a limited time for abuse monitoring, unless we enable an available limited / zero data retention option for the chosen model.

    Professional advisers — accountants, lawyers, and insurers, where needed.

    Public authorities — only where required by law.

    Google LLC (Google Maps Embed / Google Maps Platform and YouTube) — if the footer map or a YouTube video is actually loaded. Google then receives at least the IP address and browser technical data. For that traffic Google acts in part as an independent controller under its own Google / YouTube privacy policy, and in part as our provider of the embed. Transfers to the United States rely on an adequacy decision (EU–U.S. Data Privacy Framework, where Google is certified) and/or Standard Contractual Clauses.

    X Corp. (formerly Twitter) — if an embedded X post is actually loaded. X then receives at least the IP address and browser technical data and is an independent controller on its own platform.

    Cloudflare, Inc. – CDN, WAF and bot protection (__cf_bm).

A plain “Open in Maps” text link that only opens maps.google.com after a click does not load an embed on our site. The interactive footer map does.

Social-media platforms (X, LinkedIn, Facebook/Meta, YouTube/Google, Medium, Substack) are independent controllers of data collected on their own properties. If you click a social link or load an embedded player, that platform may process data under its own policy. We do not operate those platforms.

We do not sell personal information and we do not share it for cross-context behavioral advertising of the type that would require a “Do Not Sell or Share” sale under CPRA for our current Website stack. If that changes, we will update this Policy and provide a conspicuous opt-out.


 

6. International transfers

Some recipients (notably Google, Microsoft, and OpenAI) are established in the United States or process data there. Where GDPR Chapter V applies, we rely on one or more of: (i) an adequacy decision, including the EU–U.S. Data Privacy Framework for certified organizations; (ii) the European Commission’s Standard Contractual Clauses together with transfer impact assessments and supplementary measures offered by the provider; and/or (iii) the provider’s data-processing addendum. A copy of the relevant safeguards can be requested at gdpr@bytelake.com, subject to confidentiality.

The same applies to Google Cloud / Vertex AI: we will set the processing region in the Google Cloud project (EEA regions preferred where the model and feature allow); remaining U.S. transfers rely on the Data Privacy Framework (if Google is certified) and/or the SCCs in the Google Cloud DPA.

Chatbot / AI Agent: we aim to run the chosen model in an EEA region the provider offers. Some operations (including security and failover) may still occur outside the EEA; in that case we use the Chapter V GDPR tools described above.

7. Retention

    Contact and pre-contract correspondence: for the time needed to handle the inquiry and then up to 3 years after the last meaningful contact, unless a longer period is required for claims or a contract is concluded.

    Accounting and tax records: for the periods required by Polish tax and accounting law (typically 5 years from the end of the relevant year).

    Marketing contacts: until you withdraw consent or unsubscribe, plus a short suppression record so we can honor the opt-out.

    Server and security logs: typically up to 12 months, longer if needed to investigate an incident.

    Analytics data: according to the Google Analytics retention setting we configure, not longer than 26 months, and only if you consented.

    Cookie consent records: for the life of the consent proof plus a period needed to demonstrate compliance (up to 3 years).

    Chatbot transcripts (if enabled): up to 12 months unless you ask us to delete them earlier or a longer period is needed to handle a follow-up inquiry.

When the purpose expires we delete or irreversibly anonymize the data.

8. Your rights (EEA / UK / Poland)

You may request: access; rectification; erasure; restriction; portability; and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time, without affecting lawfulness before withdrawal. You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO), ul. Stawki 2, 00-193 Warszawa, Poland, https://uodo.gov.pl, or with another EEA supervisory authority of your habitual residence or place of work.

To exercise rights, email gdpr@bytelake.com. We may need to verify your identity. We will respond within one month, extendable by two months for complex requests as permitted by Article 12 GDPR.

9. Security

We use HTTPS/TLS on the Websites, access control, least-privilege administration, and contractual security obligations for processors. No method of transmission or storage is perfectly secure. Please do not send passwords, payment-card data, or highly confidential trade secrets through a public contact form or a Website chatbot.

10. Children

The Websites are not directed to children. We do not knowingly collect personal data from anyone under 16 (GDPR) or under 13 (COPPA). If you believe a child has submitted data, contact gdpr@bytelake.com and we will delete it.

11. Automated decision-making

We do not use Website data to make solely automated decisions that produce legal or similarly significant effects on you (Article 22 GDPR). Fraud Defense / reCAPTCHA may produce a risk score that helps us accept or challenge a form submission; a human can review false positives if you contact us. A chatbot does not bind byteLAKE and does not make formal contractual decisions.

12. Artificial intelligence transparency (EU AI Act and related rules)

12.1 Interaction with an AI system (chatbot)

We may deploy a chatbot, assistant or AI Agent on the Websites using models from OpenAI, Microsoft Azure OpenAI and/or Google Cloud Vertex AI (Gemini or another Vertex AI managed model, including Agent Builder / Agent Engine). Under Article 50(1) of the EU AI Act, and under California bot-disclosure rules, we inform you that:

    you would be interacting with an artificial-intelligence system, not a human, unless a member of our team later joins the conversation;

    answers can be incomplete, outdated, or incorrect and are not legal, financial, medical, or engineering advice;

    the chatbot does not create a contract and does not replace a written quotation;

    prompts and replies may be processed by our subprocessors outside Poland, as described in Sections 5 and 6;

    you should not paste confidential client data, personal data of third parties, or special-category data into the chatbot.

If a chatbot is live, a clear notice will also appear in the chat window itself (for example: “You are chatting with an AI assistant”). That on-interface notice is the primary Article 50(1) disclosure; this Policy is supporting documentation.

12.2 Website content created with AI

Some texts, images, or other materials on the Websites may be created by a human, generated by AI, or produced by a human using AI tools and then edited. byteLAKE remains editorially responsible for content we publish on the Websites. Where Article 50 of the AI Act requires labeling of AI-generated or manipulated content (for example, certain deepfakes or AI-generated text published to inform the public on matters of public interest without human review), we will label that content in a manner appropriate to the medium. Marketing and product pages that have undergone human review and for which byteLAKE holds editorial responsibility are treated accordingly.

12.3 Our products versus this Website

byteLAKE designs industrial and enterprise AI (Cognitive Services, explainable models, intelligent agents, private and edge deployments). Those systems are provided to clients under separate contracts, technical documentation, and — where the AI Act requires it — instructions for use, transparency information, and risk measures. This Policy covers only the public Websites, not the classification or conformity of client-deployed systems.

13. California and other U.S. privacy notices

This Section is provided under the CCPA/CPRA and CalOPPA. In the last 12 months we may have collected the following categories of personal information from Website visitors: identifiers (name, email, IP, cookie ID); commercial information (inquiries about products); internet or electronic-network activity (browsing on our Websites); and geolocation at a coarse IP level. We collect it from you and from your device/browser. We use it for the business purposes in Section 4. We disclose it to service providers / contractors listed in Section 5. We do not sell personal information and we do not share it for cross-context behavioral advertising in the current configuration of the Websites. We do not use or disclose sensitive personal information for purposes that would require a CPRA right to limit.

California residents may request: (1) to know the categories and specific pieces of personal information we collected, sources, purposes, and categories of recipients; (2) deletion; (3) correction; (4) opt-out of sale or sharing (we do not sell or share, but you may still send an opt-out request); and (5) non-discrimination for exercising CPRA rights. Authorized agents may submit requests with proof of authorization. We will verify requests using information we already hold (for example, the email used to contact us). Email gdpr@bytelake.com with the subject line “California Privacy Request.” You may also use a Global Privacy Control (GPC) signal; we will treat a recognized GPC signal as a request to opt out of sale/sharing for that browser.

Shine the Light / CalOPPA: we do not disclose personal information to third parties for their own direct marketing in a way that triggers a separate annual “Shine the Light” catalog. Our Websites identify the operator and include a link to this Policy. CAN-SPAM: marketing emails include our physical postal address and an unsubscribe mechanism.

14. Marketing communications

We send commercial electronic communications only if you have given a valid consent (or another basis permitted by the law applicable to you). Every marketing email includes an unsubscribe link. You may also write to gdpr@bytelake.com or welcome@bytelake.com.


 

PART II — COOKIE POLICY

This Part explains cookies and similar technologies on bytelake.com and bytelake.pl, in line with the GDPR, the Polish Electronic Communications Law, and the EU ePrivacy framework.

15. What cookies are

Cookies are small text files stored on your device. Similar technologies include pixels, tags, local storage, and SDK identifiers. Some cookies are first-party (set by us); others are third-party (set by a provider such as Google).

16. How we obtain consent

On your first visit a CookieAdmin banner lets you Accept all, Reject all (non-essential), or Customize categories. Non-essential cookies — including Google Analytics — are not set until you opt in. You can change your choice later through the banner or cookie icon. Rejecting non-essential cookies does not block the core Website or the contact form, although bot-protection and some embeds may be limited.

Under Polish law there is no analytics exemption. Legitimate interest is not a substitute for ePrivacy consent to store or read non-essential cookies.

17. Categories we use

Strictly necessary

Required to transmit communications or to provide a service you request: load balancing and security, storing your cookie choice, keeping a form session, and similar. These do not require opt-in consent.

Analytics (consent required)

Google Analytics 4 helps us understand aggregate traffic (pages viewed, approximate geography, device class, referral source). We aim to use IP masking / Consent Mode so that tags respect the banner. Analytics cookies are first-party on our domain but the resulting data is processed by Google.

Functional / security (consent where not strictly necessary)

Google Cloud Fraud Defense / reCAPTCHA helps prevent automated abuse of forms. Depending on configuration it may set cookies or use other storage. Where storage is not strictly necessary for the form you requested, we treat it as consent-based. WordPress / theme preferences may store display settings.

Social and embedded media (consent required if they set cookies)

Links to X, LinkedIn, Facebook, YouTube, Medium, and Substack. A simple hyperlink does not by itself set a third-party cookie. If we embed a player or a social plugin that contacts those platforms before you click through, that embed is gated by consent.

The Websites may embed an interactive Google Map in the footer, YouTube videos, and X posts. A plain hyperlink (for example “Open in Maps” opening a new tab) does not set cookies on our site. Loading an embed iframe or script connects the browser directly to Google or X, transmits the IP address, and may set their cookies (including Google’s NID). Embeds therefore load only after CookieAdmin consent (media / functional / social category, as configured in the banner) or after a click on a placeholder. Until then we should show a static image or a “Show map / Play video / Show post” button.

Chatbot (consent required if enabled)

Session or preference cookies used only to run a Website AI assistant.

18. Cookie inventory (typical)

Exact names can change when providers update their products. The live list in the CookieAdmin panel prevails if it differs. Typical items:

 

Name

Provider

Category

Typical life

Purpose

cookieadmin / consent cookies

CookieAdmin / byteLAKE

Necessary

up to 12 months

Stores your accept / reject / customize choice

WordPress session / csrf (e.g. wordpress_test_cookie, PHPSESSID)

byteLAKE (first party)

Necessary

session

Site and form operation

_ga

Google Analytics 4

Analytics

up to 13–24 months

Distinguishes unique visitors (client ID)

_ga_<container>

Google Analytics 4

Analytics

up to 13–24 months

Session and engagement state for the GA4 property

_gid

Google Analytics (if present)

Analytics

24 hours

Short-lived visitor distinction

reCAPTCHA / Fraud Defense cookies (e.g. _GRECAPTCHA) and related storage

Google Cloud Fraud Defense

Security / functional

session to 6 months

Bot and abuse protection on forms

__cf_bm

Cloudflarenecessarysessionbot protection

NID and other Google-domain cookies on Maps / YouTube

Google LLC

Embedded media (consent)

up to 6 months (NID may last longer)

Map / player function; Google may link this to a Google account if the visitor is signed in

YouTube player cookies (e.g. VISITOR_INFO1_LIVE, YSC, PREF)

Google / YouTube

Embedded media (consent)

session to ~6 months

Playback, measurement, YouTube-side abuse protection

X embed cookies / storage (x.com / twitter.com)

X Corp.

Embedded media (consent)

session or per X

Render the post, counters, identification on X

__wpdm_client

WordPress Download Manager

necessary

session

guest download session for brochures and case studies

cookieadmin_consent

CookieAdmin

necessary

session / up to 180 days

stores consent

Chatbot / Agent widget cookies or storage (if enabled)

byteLAKE and the chosen provider: OpenAI, Microsoft or Google Cloud / Vertex AI

Chatbot (consent)

session or short-lived

Keeps the Website conversation thread

 

19. Google Cloud Fraud Defense (reCAPTCHA) — what changed

Google notified Website administrators that, effective April 23, 2026, Google reCAPTCHA is presented as part of Google Cloud Fraud Defense. “Google reCAPTCHA” now refers specifically to the visual bot-defense feature inside that platform. There is no change to existing site keys, secret keys, API calls, service levels, or pricing solely because of the rebrand.

Separately, effective April 2, 2026, Google confirmed that it processes customer data for this service as a data processor under the Google Cloud Data Processing Addendum (https://cloud.google.com/terms/data-processing-addendum), not as a controller of that service data. Accordingly, this Policy no longer treats Google’s consumer Privacy Policy as the document that governs Fraud Defense / reCAPTCHA processing performed for us. Google processes that data on our documented instructions to protect forms. Background reading from Google: “Switching Google’s role with reCAPTCHA from Data Controller to Data Processor.”

Our affected Google Cloud project identifier (as stated in Google’s notice) includes: bytelake-1753369126948.

20. How to control cookies

    Use the CookieAdmin banner / icon on the Websites.

    Use your browser settings to block or delete cookies. Blocking necessary cookies may break the form or consent tool.

    Google Analytics opt-out add-on: https://tools.google.com/dlpage/gaoptout

    Industry opt-out pages and your device advertising-ID settings, if advertising cookies ever appear.

    Email gdpr@bytelake.com if the banner does not work.

21. Changes

We may update this Policy when our stack, providers, or the law changes (including further AI Act guidance). The “Last updated” date will change. Material changes will be highlighted on the Websites or, if we hold your email for that purpose, notified to you.


 

22. Contact

byteLAKE s.c.

Plac Solny 14 lok. 3, 50-062 Wrocław, Poland

Privacy: gdpr@bytelake.com    General: welcome@bytelake.com

Phone: +48 508 091 885 / +48 505 322 282

Supervisory authority (Poland): Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl. California Privacy Protection Agency: https://cppa.ca.gov.