Legal
Privacy notice
How Byte Craftpoint handles personal data when providing German migration guidance.
Last updated: 15 August 2026
Controller and contact
Byte Craftpoint, Level 11, 45 Türkenstraße, Munich 80799, is controller for data described here. Questions and rights requests can be sent to info@byte-craftpoint.digital or +49 89 5551 2180.
Data and purposes
We process contact details, enquiry text, appointment information, billing records, and engagement correspondence to answer requests and perform agreed advisory work. We ask clients not to send passport copies, financial account numbers, health records, or other unnecessary sensitive data through the contact form. Technical server logs may record IP address, device information, requested page, and time for security and reliable delivery.
Legal bases include steps requested before a contract and contract performance (GDPR Art. 6(1)(b)), compliance with legal obligations such as accounting (Art. 6(1)(c)), legitimate interests in secure communication and service improvement (Art. 6(1)(f)), and consent where specifically requested (Art. 6(1)(a)). Consent can be withdrawn prospectively.
Recipients and transfers
Hosting, email, bookkeeping, and professional advisers may receive the minimum data needed under contractual safeguards. Public images and font files can cause a request to providers outside Germany; safeguards may include an adequacy decision or Standard Contractual Clauses. We do not sell personal data. Authority disclosure occurs only where legally required or directed by you.
Retention
Unconverted enquiries are normally deleted after 12 months. Engagement files are normally retained for three years after completion to address contractual questions. Invoices and tax records are kept for statutory German retention periods, commonly eight or ten years depending on record type and current law. Security logs are normally removed within 30 days. Data is deleted or anonymised when no longer required, subject to legal holds.
Your rights
Subject to legal conditions, you may request access, correction, deletion, restriction, portability, or objection to legitimate-interest processing. You may withdraw consent and complain to a data-protection supervisory authority, including the Bavarian State Office for Data Protection Supervision where competent. Identity verification may be needed before fulfilling a request.
Automated decisions and security
We do not make solely automated decisions producing legal or similarly significant effects. We use access controls, minimum-data practices, encrypted transport where supported, and redaction requests. No internet transmission can be guaranteed completely secure.
Read the cookie notice for browser storage and third-party resources.