Privacy Policy
Dytto BV · Version 1.1 · Effective 19 August 2026 · Replaces version 1.0 (23 February 2026)
At Dytto, we are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, and safeguard your information when you interact with our website, software, and related services.
By accessing or using Dytto, you acknowledge that you have read and understood this Privacy Policy. Our processing of personal data is governed by the General Data Protection Regulation (GDPR) and other applicable European data protection laws.
1. Who We Are
Dytto BV is registered with the Crossroads Bank for Enterprises (Kruispuntbank van Ondernemingen) under number 1030.588.178.
Registered address: Kliniekstraat 27a, 9050 Ghent, Belgium
Data Protection Contact: Niels Van Driessche, niels@dytto.ai
2. What Data We Collect
Website visitors (dytto.ai)
Basic analytics data such as page views, referral source, browser type, and approximate location, collected through Google Analytics (loaded via Google Tag Manager) after you give consent via our cookie banner. Our website is hosted on Framer, which sets strictly necessary cookies for hosting and security.
Information voluntarily provided through contact forms, newsletter sign-ups, or demo requests (name, email, company name).
Software users (Dytto platform)
Account information: name, email address, company details, and login credentials.
Usage data: features used, session duration, and interaction logs for service improvement, collected through PostHog on an EU-hosted instance (Frankfurt, Germany). This usage data never includes the content of emails, documents, or accounting records.
Client data: financial and accounting records, documents, business-contact details, and professional activity information. We process client data exclusively as a data processor on behalf of your firm (see Section 6).
3. Purpose and Legal Basis for Processing
Processing purposes and legal bases under Article 6 GDPR:
Purpose | Legal Basis | Example Data |
|---|---|---|
Providing Dytto platform services | Contractual necessity | Account details, client accounting data |
Account creation/authentication | Contractual necessity | Name, email, login credentials |
Customer support | Contractual necessity | Contact details, support correspondence |
Security, fraud prevention, abuse detection | Legitimate interest | IP addresses, access logs, usage patterns |
Product improvement and analytics | Legitimate interest | Aggregated usage data, feature interaction logs |
Website analytics | Consent | Page views, referral source, browser type |
Marketing communications | Consent | Email address, name |
Legal and regulatory compliance | Legal obligation | Financial records, tax-related data |
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal applies only to the period following the withdrawal and does not affect the lawfulness of prior processing.
4. AI Processing
Data input into the Dytto platform may be processed by AI models for insights and suggestions.
AI processing is carried out through third-party large language model (LLM) providers bound by data processing agreements.
Data minimisation principles are applied; only necessary data is sent to AI providers.
We do not use your data or your clients' data to train AI models, unless explicitly agreed separately.
AI-generated outputs are intended as assistance and should be reviewed by qualified professionals before reliance.
5. Automated Decision-Making
Dytto does not make decisions that produce legal effects or similarly significant effects on you based solely on automated processing within the meaning of GDPR Article 22. AI features are assistive; human professionals retain decision responsibility.
6. Data Controller and Data Processor
As data controller: Dytto determines purposes and means of processing for website visitors, platform account holders, and prospective customers, including the product usage analytics described in Section 2.
As data processor: When accountants use Dytto to process client data, the accounting firm is the data controller; Dytto processes that data solely on documented instructions. For those data, the privacy notice of your accounting firm applies.
A Data Processing Agreement (DPA) is included as part of our customer agreements. Contact niels@dytto.ai for a standalone copy.
7. Data Sharing and Transfers
We do not sell your personal data.
Dytto may share data with external processors, including cloud hosting providers, AI/LLM service providers, product analytics providers, IT service providers, auditors, and legal advisors, all bound by data processing agreements.
Where processors are established outside the EEA, appropriate safeguards under GDPR Article 46 are applied, such as Standard Contractual Clauses (SCCs) or transfers to countries or organisations covered by an EU adequacy decision (including the EU-U.S. Data Privacy Framework).
The current list of our sub-processors is set out in our Data Processing Agreement and is available upon request at niels@dytto.ai. We will notify customers of any new or replacement sub-processor with a 14-day prior notice period.
8. Data Retention
Data is not kept longer than necessary, on servers at established cloud and hosting providers that comply with GDPR legislation.
Website visitor data (analytics) is retained for a maximum of 14 months.
Account and usage data is retained for the duration of your contract and deleted within 90 days after termination, unless a longer retention period is required by law.
Client accounting data is deleted or returned in accordance with the Data Processing Agreement: active data within 30 days after the end of services, encrypted backups within 90 days.
9. Data Security
We are committed to ensuring the confidentiality, integrity, and availability of your data. Measures include:
Encryption at rest and in transit
Multi-factor authentication for administrative access
Role-based access controls with least-privilege principle
Secure logging and monitoring of access to personal data
Secure data storage and encrypted backups
Regular security reviews, vulnerability remediation, and periodic penetration testing by an independent third party
10. Data Breach Notification
Upon a personal data breach likely to result in a risk to rights and freedoms, Dytto will:
Notify the relevant supervisory authority (the Belgian Data Protection Authority) without undue delay and, where feasible, within 72 hours, in accordance with GDPR Article 33.
Notify affected individuals without undue delay where the breach is likely to result in a high risk, in accordance with GDPR Article 34.
For customers with a Data Processing Agreement: notify the data controller within 48 hours of becoming aware of the breach.
11. Cookies and Tracking
Our website and platform use cookies:
Strictly necessary cookies for website hosting, security, and storing your cookie preference. These cannot be disabled.
Analytics cookies on the website (Google Analytics, loaded via Google Tag Manager), placed only with your consent via the cookie banner.
Platform analytics cookies on app.dytto.ai (PostHog, EU-hosted), used to understand feature usage and improve the service.
The full list of cookies, their duration, and how to manage or withdraw your preferences can be found in our Cookie Policy at dytto.ai/cookie-policy.
12. Your Rights
Under the GDPR, you can exercise the following rights by contacting niels@dytto.ai:
Right of access: You have the right to access the personal data Dytto processes about you and obtain additional information regarding this processing.
Right to rectification: Request correction of inaccurate or incomplete data.
Right to erasure: In certain cases, you may request the deletion of your personal data.
Right to restrict processing: In certain cases, you may request to restrict the processing of your personal data.
Right to data portability: In certain cases, you have the right to have the personal data you provided transferred to another controller, provided this is technically possible.
Right to object: You may object to the processing of your personal data for direct marketing purposes at any time.
Identity verification may be required.
Supervisory Authority: If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority.
Belgian Data Protection Authority (Gegevensbeschermingsautoriteit):
Address: Drukpersstraat 35, 1000 Brussels
Email: contact@apd-gba.be
Phone: +32 2 274 48 00
Website: www.dataprotectionauthority.be
13. Children's Privacy
Dytto's services are designed for business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we discover inadvertent collection, we delete the data promptly.
14. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for their content or privacy practices.
15. Changes to This Policy
This policy is reviewed at least annually, or upon significant changes to our services or applicable law. The latest version will always be available at dytto.ai/privacy-policy with the effective date and version number clearly stated. We will inform you of material changes by email or through the platform.
Contact
Data Protection Contact: Niels Van Driessche, niels@dytto.ai
General contact: contact@dytto.ai
Address: Kliniekstraat 27a, 9050 Ghent, Belgium