Privacy notice
Last update: 2 October 2026
We provide dis translation make e easy for you. Na di English version be di one wey bind.
Dis notice dey explain di personal data wey AddToThese dey collect, why we dey collect am, how long we dey keep am and di rights wey you get. Na Nordic Byte LTD dey run AddToThese. Na company wey register for England and Wales (company number 16978110), wey im registered office dey 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Nordic Byte LTD na di data controller. Contact: info@nordicbyte.co.uk.
Wetin we dey collect
| Data | Why | Lawful basis |
|---|---|---|
| Email address, name, password hash (Argon2id) | To create and secure your account and to send service email like password reset | Contract |
| Google or GitHub account ID and verified email, if you sign in with dem | To log you in | Contract |
| Two-factor secret and recovery codes wey we hash, if you on 2FA | To protect your account | Contract |
| Activity log: sign-ins and account changes, with IP address and browser user agent | Security and to investigate abuse; we dey show am to you for di Security page | Legitimate interests |
| Team membership: if you join team, di owner go see your name and email address; if you invite person, we go keep im email for 7 days to send di invitation | To run di Team plan | Contract; legitimate interests for di people wey we invite |
| Endpoints, custom domains, API token names and di last time wey you use dem | To run di service wey you configure | Contract |
| Usage counters: bytes wey you transfer and how many requests every month | To apply di plan limits and show you your usage | Contract |
| Stripe customer and subscription IDs and status | To bill di paid plans | Contract; legal obligation for accounting records |
| Session cookie and CSRF cookie | To keep you logged in and protect forms. Di two of dem strictly necessary; we no dey use analytics or advertising cookies | Legitimate interests |
| Emails of people wey visit URLs wey email codes protect, plus the one-time codes wey we send to dem | To allow only the people wey the URL owner allow. We dey process dis for the URL owner side, na dem dey decide who fit enter. | Legitimate interests (security of the URL owner); we dey delete codes within one day |
Traffic wey pass through your tunnels
Requests wey come your public URLs dey pass through our servers go your machine. We no dey store request or response bodies. Our proxy and web server dey keep technical logs wey no dey last long (time, host, path, status, client IP) to run di service and handle abuse reports. Na you get responsibility for any personal data wey your own service dey handle.
Who we dey share am with
We no dey sell personal data. We dey use dis processors:
- Stripe for payments. Card details dey go straight to Stripe and dem no dey ever reach our servers.
- Bunny.net (BunnyWay d.o.o., Slovenia) for DNS and di content delivery network wey dey in front of dis website.
- Our hosting provider for di server wey dey run AddToThese, wey dey inside di European Economic Area.
- Google and GitHub, only if you choose to sign in with dem.
- Let's Encrypt, wey dey record di domain names wey we request certificates for, including your custom domains.
Where data comot from UK or EEA (for example go Stripe or GitHub for United States), di transfer dey rely on di UK International Data Transfer Addendum or di EU Standard Contractual Clauses wey dat providers dey offer.
How long we dey keep am
- Account data: as long as your account dey. After you ask us make we delete am, inside 30 days, except wetin di next points require.
- Activity log entries: 12 months, then we go delete dem automatically.
- Sessions wey don expire and password reset links: we dey delete dem automatically.
- Billing records: 6 years, as UK accounting law require.
- Database backups: 30 days, wey dey roll.
Your rights
Under UK GDPR, and EU GDPR where e apply to you, you fit ask for copy of your data, ask us make we correct or delete am, object to or restrict processing wey base on legitimate interests, and ask for your data for format wey you fit carry go anywhere. Write to info@nordicbyte.co.uk from di email address wey dey your account and we go reply inside one month. If our answer no satisfy you, you fit complain to di UK Information Commissioner's Office for ico.org.uk, or to di data protection authority for where you dey live.
Security
We dey hash passwords with Argon2id, we dey store API tokens hashed, all traffic to our site dey use HTTPS, and two-factor authentication dey for every plan.
Changes
If we change dis notice for way wey matter, we go email account holders before di change start to work.