Bayto Privacy Policy
1. About this Policy
This Policy explains how Bayto collects, uses, stores, shares and protects personal data when you:
- visit the Bayto website;
- submit a request for a 7-day Trial, Demo or plan purchase;
- create and use a Bayto account;
- use the CRM, Telegram booking, the customer web booking form and other Bayto features;
- contact support; or
- communicate with us about commercial, contractual or legal matters.
It applies to representatives of prospective and current Bayto business customers, users on their teams and, to the extent described below, individuals whose data a business customer enters into Bayto.
2. Who is responsible for the data
For website visitor, lead, business contact, account, Trial, Demo, billing, security and service data, the controller is:
Individual Entrepreneur Shavnia Leonid Serhiiovych Ukrainian taxpayer number: 3504612110 Place of state registration: Ukraine. The full registration address is not published for owner safety and is disclosed where and to the extent required by law. Privacy and support email: support.bayto.io@gmail.com Telegram: @Bayto_io
“Bayto”, “we”, “us” and “our” mean the entrepreneur identified above.
Business customer CRM data
Where a business customer uses Bayto to manage its customers, vehicles, bookings, work orders, notes, service history or messages:
- the business customer is preliminarily the controller and decides why and how that data is used;
- Bayto preliminarily acts as processor and processes it on the business customer's documented instructions; and
- the final allocation of roles must be set out in the customer agreement and DPA.
If you are a customer of a car wash or detailing business, please contact that business first. We will assist it with a valid request to the extent required of us.
3. Data we process
Depending on your interaction with Bayto, we may process the following categories.
3.1. Landing-page requests and commercial communications
- name;
- business name;
- phone number;
- email;
- Telegram contact;
- city;
- comment;
- request type: Trial, Demo or plan purchase;
- selected plan;
- interface language;
- request source; and
- date, time, version and other evidence of legal-document acceptance.
Submitting a sales form is only a request to be contacted. A customer web booking form sends a booking request to the selected business and does not make Bayto the seller of that business's services.
3.2. Accounts and access
- name, phone and email;
- Telegram identifiers;
- organisation, branch and role membership;
- session and access-token data;
- login, action and change logs; and
- theme, navigation and organisation preferences.
3.3. Data entered into the CRM by a business customer
- customer contact details, including phone and Telegram identifier;
- vehicles and registration plates;
- bookings submitted through Telegram or the customer web form, services and service history;
- work orders/receipts, status, amounts and notes;
- employee details, roles, schedules and actions; and
- inventory-operation data.
Bayto does not claim that VIN is collected as a standard field in the current configuration.
3.4. Contracts, plans and billing
- plan, service status and term;
- invoices, amounts and information about manual bank payments; and
- contracts, completion documents, correspondence and legally required accounting records.
Bayto does not currently use an integrated payment provider. Following commercial agreement, the contract, invoice and bank transfer are handled separately.
3.5. Technical and security data
- IP address;
- browser type, operating system and user agent;
- session identifiers;
- security, audit, rate-limit and reverse-proxy logs; and
- time, source and result of a technical interaction.
3.6. Support
- message content;
- contact metadata; and
- attachments and technical information that you provide or that is required for troubleshooting.
Do not send real customer data through support or a Demo unless this has been agreed and is necessary for the specific support request.
3.7. Data Subject categories
The data may concern:
- website visitors and people who submit a request;
- business owners, individual entrepreneurs, managers and business contacts;
- employees, contractors and authorised users of a business customer;
- customers and prospective customers of a car wash or detailing business; and
- representatives of providers, partners or authorities interacting with Bayto or a business customer.
4. How we obtain data
We obtain data:
- directly from you through forms, correspondence, Telegram, a Trial or a Demo;
- from your employer or business when it gives you access;
- from a business customer when it enters its own customers' and employees' data into the CRM;
- automatically from the browser, server and security controls; and
- from Telegram through Bot API or WebApp functionality activated by you or the business customer; and
- through a customer web booking form activated by the relevant business as a permanent alternative to Telegram.
5. Why and on what basis we process data
We process data only for defined purposes and on a basis permitted by applicable law.
| Purpose | Data | Main legal basis |
|---|---|---|
| Respond to a request and arrange a Trial, Demo or plan | Contact, business and request data | Steps requested before entering a contract; other statutory permission and, where required, consent |
| Provide Bayto and administer accounts | Account, CRM and technical data | Performance of a contract and the business customer's documented instructions |
| Support and service communications | Contact, request content and technical data | Contract performance, responding to a request, service operation and protection of rights |
| Security, abuse prevention and audit | IP, user agent, sessions and logs | Legitimate interests in protecting the service and users; compliance with legal obligations |
| Invoicing, payment records, accounting and tax | Contract and billing data | Contract performance and legal obligations |
| Legal requests and disputes | Data necessary for the request | Compliance with law and establishment, exercise or defence of legal claims |
Where the GDPR applies, relevant bases may include Articles 6(1)(b), 6(1)(c), 6(1)(f) and, where necessary, 6(1)(a). We do not rely on consent where processing is required for a contract or by law. Consent may be withdrawn prospectively, but withdrawal does not affect previous lawful processing or another valid basis.
6. Telegram and other external services
Telegram
Telegram is a third-party communications service. If you use a bot, Mini App/WebApp or Bayto contact, Telegram may receive and process technical and profile data under its own terms. Bayto receives only information needed for the selected function, including minimum Telegram identifiers and booking/notification data.
This Policy must be accessible to bot/Mini App users. Personal data obtained through Telegram Bot Platform must be encrypted at rest, with the encryption key stored separately, before real-data production. Each Telegram flow requires separate legal and technical classification; this text does not conclusively classify Telegram as a processor, independent controller or Subprocessor. The role is determined from the actual flow, provider terms and applicable law.
Google/Gmail email
support.bayto.io@gmail.com is a standard consumer Gmail account. Google may process message content and contact metadata under the applicable consumer Google terms. CRM exports or bulk Customer Data must not be transferred through this channel without a separately approved secure procedure.
7. Who receives data
We do not sell personal data. To the extent necessary, access may be given to:
- authorised Bayto staff and contractors on a need-to-know basis;
- the business customer whose organisation is linked to the account or request;
- Hostinger International Ltd., 61 Lordou Vironos Street, Larnaca 6023, Cyprus, VAT Reg #: CY10301365E, for VPS infrastructure whose region is confirmed as Germany;
- Telegram for functions used by the user or business customer;
- Google/Gmail for receiving and sending email; and
- public authorities, courts, auditors or professional advisers where required by law or necessary to protect rights.
In the current scope, Bayto does not claim to use a payment provider, automated email-marketing service, marketing pixels, external CRM, Sentry or third-party object storage.
8. International transfers
Bayto's primary VPS is located in Germany. Hostinger, Telegram and Google/Gmail may involve access to or transfers outside Ukraine or the user's country.
Before this Policy is launched, Bayto must confirm:
- the applicable accepted Hostinger DPA version, provider Subprocessors and transfer terms;
- locations and roles for the separate Telegram and consumer Gmail flows; and
- whether the GDPR or another regime applies to the specific activity.
International-transfer safeguards are selected from the actual provider, role, destination and applicable law. We do not claim that Standard Contractual Clauses or another transfer mechanism is in place until supported by documentation. Hosting the VPS in Germany does not mean that all data remains in the EU.
9. Retention
The table below is the target retention policy. It becomes effective only after technical or controlled manual enforcement is confirmed for production.
| Data | Target period |
|---|---|
| Unconverted leads | 12 months after the last substantive contact |
| Minimum legal-acceptance evidence for a closed lead | 3 years after lead closure |
| Security and reverse-proxy logs | Up to 90 days by default; longer only for a documented incident, legal hold or legal requirement |
| Expired sessions and password-reset tokens | Delete no later than 30 days after expiry |
| CRM data | Contract term; 30-day export window after termination, followed by operational deletion |
| Encrypted backups | Rolling 30-day period |
| Contracts, invoices, payments and accounting | The period required by applicable law |
| Data-subject request register | 3 years after request completion |
We may retain specific information longer where required by law, an active dispute, protection of rights or a valid legal hold. Once that basis ends, the data should be deleted or anonymised.
10. Cookies and local storage
Bayto uses only necessary and functional storage, including:
- refresh cookies and other means of maintaining an authenticated session;
- isolated Demo cookies or tokens;
- theme, organisation and navigation preferences; and
- security tokens and abuse-prevention controls.
Bayto does not currently use analytics or marketing cookies/pixels. A separate marketing cookie banner is therefore not planned for the present scope. If optional tracking is added, the Policy will be updated and an appropriate choice/consent mechanism introduced before activation.
Blocking necessary cookies may prevent authentication or other functions from working.
11. Security
Bayto applies organisational and technical measures appropriate to risk, including:
- encryption in transit;
- access control and authentication/session protection;
- data isolation by organisation, role and branch;
- security monitoring and audit;
- protected encrypted backups; and
- organisational access, response and recovery controls.
Specific measures are reviewed and improved according to risk. No system is absolutely secure. This section does not claim full-disk or database encryption at rest, geographically redundant backups, certification or a fixed incident-notification SLA.
12. Your rights
Depending on applicable law, you may have the right to:
- know the source, location, purpose and recipients of data;
- obtain confirmation and access;
- correct inaccurate or incomplete data;
- object to processing or request restriction where the law provides;
- request deletion where no valid retention basis remains;
- withdraw consent prospectively;
- obtain a copy or, where the GDPR applies, portability;
- complain to the Ukrainian Parliament Commissioner for Human Rights or another competent authority; and
- seek a judicial remedy.
These rights are not absolute. We may retain minimum data required by law, accounting, security or the defence of rights.
13. How to make a data request
Email support.bayto.io@gmail.com with “Personal Data Request” or “Data Request” in the subject line.
Please provide:
- your name and reply contact;
- your relationship with Bayto or the relevant business customer;
- the request; and
- information that will help locate the record.
We may request minimum additional information to verify identity and protect data from unauthorised disclosure. For an access request governed by Ukrainian law, the target control is to review the request and notify the requester within 10 working days and fulfil it within 30 calendar days unless the law provides otherwise. The overall operational target is no later than one month. The applicable deadline is determined from the request, Bayto's role and mandatory law. There is no automated DSAR portal.
If the request concerns data controlled by a car wash or detailing business through Bayto, we may refer it to that business and assist as processor.
14. Automated decisions
Bayto does not claim to make decisions producing legal or similarly significant effects on an individual solely through automated processing. Analytics are intended to support business operations.
15. Children
Bayto is a B2B service for business owners and authorised representatives aged 18 or over. It is not intended for independent use by children. Do not submit children's data without a proper legal basis and any necessary authorisation.
16. Policy changes
We may update this Policy when the product, providers or law changes. Each published version must have:
- a human- and machine-readable version;
- an effective date;
- its language and paired UA/EN version;
- an immutable content hash; and
- a change log.
If a change materially affects rights or processing purposes, Bayto will provide prominent notice and, where required, obtain renewed acceptance before continuing the affected processing.
The Ukrainian version is primary for interpretation under Ukrainian law. The English version is a functionally equivalent translation. If they conflict, the Ukrainian version prevails to the extent permitted by law.
17. Contact and complaints
For questions about this Policy:
Individual Entrepreneur Shavnia Leonid Serhiiovych support.bayto.io@gmail.com @Bayto_io
You may also contact the Ukrainian Parliament Commissioner for Human Rights or another competent supervisory authority with jurisdiction.