Last updated: July 26, 2026
EYTAK LIMITED is committed to protecting the personal data of our users in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page outlines our compliance practices, your rights as a data subject, and how we safeguard your data.
Our commitment: Eytak processes personal data lawfully, fairly, and transparently. We collect only what is necessary, keep it accurate, store it securely, and retain it no longer than needed.
Entity: EYTAK LIMITED
Address: 82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
Privacy Contact: privacy@eytak.com
Supervisory Authority: Information Commissioner's Office (ICO)
Processing necessary to provide our hosting services to you (account management, server provisioning, billing) and to handle the support requests you raise, including by our AI support agent.
Processing for fraud prevention, security monitoring and service improvement — balanced against your rights. Website analytics is not covered by this basis; we rely on your consent for it instead.
Analytics cookies on our public website, and marketing communications you have opted in to. Both are off unless you actively agree, and you can withdraw at any time — for analytics, through "Cookie settings" in the footer of any page.
Processing required to comply with tax laws, financial regulations, and law enforcement requests.
You have the right to request a copy of all personal data we hold about you. We will provide this in a structured, commonly used, machine-readable format within 30 days of your request.
You can request correction of any inaccurate or incomplete personal data. You can also update most of your information directly through the panel settings.
You can delete your account from Account → Danger zone in the panel. Deletion is scheduled 28 days ahead and can be cancelled until then, after which your data is erased — completing inside the 30 days this notice promises — except where retention is required by law (e.g., billing records), which are kept with your identifying details removed.
You can request that we limit the processing of your personal data under certain conditions, such as when you contest the accuracy of your data or object to processing.
You can download your personal data in a structured, commonly used, machine-readable format (JSON) from Account → Your data in the panel, and transfer it to another service provider.
You can object to the processing of your personal data for direct marketing, profiling, or processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds.
Where processing is based on consent, you can withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
An AI agent reads and answers support tickets, and its replies are labelled AI in the panel. It cannot decide account termination, refunds, billing disputes or complaints — a person always does — so it makes no decision producing legal or similarly significant effects on you. You can pass any ticket to a human with the Request human review button, or by sending "Human review requested" as your whole message. What the agent processes, and where, is set out in section 3 of the Privacy Policy.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority, particularly in the EU/EEA member state of your habitual residence.
TLS on all traffic. Passwords and one-time codes stored as Argon2 hashes; API and session tokens stored hashed. Staff second-factor secrets encrypted with AES-256-GCM. Databases, backups and object storage are encrypted at rest by the providers hosting them.
Staff permissions are granted per role rather than per person. Access to our internal tools requires multi-factor authentication, with a fresh challenge before sensitive operations.
We collect and process the minimum needed for each purpose. In practice: IP addresses are stripped from server logs before the AI support agent reads them, and deleted accounts are anonymised rather than kept where records must be retained for tax.
We have not yet obtained an independent security audit, penetration test or certification. We would rather say so than imply one. When we have, it will be named here.
Where a personal data breach is reportable, we will notify the supervisory authority within 72 hours of becoming aware of it and tell affected users without undue delay, as Articles 33 and 34 require.
Our privacy contact coordinates data protection requests and can be reached at privacy@eytak.com.
Our infrastructure may process data in the United Kingdom, the EEA and other locations described in our Privacy Policy. Where required, international transfers are protected through:
To exercise any of your GDPR rights, you can:
Panel: Account → Your data (export) and Account → Danger zone (deletion)
Email: privacy@eytak.com — include "GDPR Request" in the subject line
Response Time: We will respond within 30 days. Complex requests may be extended by an additional 60 days with prior notice.