Privacy Policy

Dytto BV · Version 1.1 · Effective 19 August 2026 · Replaces version 1.0 (23 February 2026)

At Dytto, we are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, and safeguard your information when you interact with our website, software, and related services.

By accessing or using Dytto, you acknowledge that you have read and understood this Privacy Policy. Our processing of personal data is governed by the General Data Protection Regulation (GDPR) and other applicable European data protection laws.

1. Who We Are

Dytto BV is registered with the Crossroads Bank for Enterprises (Kruispuntbank van Ondernemingen) under number 1030.588.178.

Registered address: Kliniekstraat 27a, 9050 Ghent, Belgium

Data Protection Contact: Niels Van Driessche, niels@dytto.ai

2. What Data We Collect

Website visitors (dytto.ai)

  • Basic analytics data such as page views, referral source, browser type, and approximate location, collected through Google Analytics (loaded via Google Tag Manager) after you give consent via our cookie banner. Our website is hosted on Framer, which sets strictly necessary cookies for hosting and security.

  • Information voluntarily provided through contact forms, newsletter sign-ups, or demo requests (name, email, company name).

Software users (Dytto platform)

  • Account information: name, email address, company details, and login credentials.

  • Usage data: features used, session duration, and interaction logs for service improvement, collected through PostHog on an EU-hosted instance (Frankfurt, Germany). This usage data never includes the content of emails, documents, or accounting records.

  • Client data: financial and accounting records, documents, business-contact details, and professional activity information. We process client data exclusively as a data processor on behalf of your firm (see Section 6).

3. Purpose and Legal Basis for Processing

Processing purposes and legal bases under Article 6 GDPR:

Purpose

Legal Basis

Example Data

Providing Dytto platform services

Contractual necessity

Account details, client accounting data

Account creation/authentication

Contractual necessity

Name, email, login credentials

Customer support

Contractual necessity

Contact details, support correspondence

Security, fraud prevention, abuse detection

Legitimate interest

IP addresses, access logs, usage patterns

Product improvement and analytics

Legitimate interest

Aggregated usage data, feature interaction logs

Website analytics

Consent

Page views, referral source, browser type

Marketing communications

Consent

Email address, name

Legal and regulatory compliance

Legal obligation

Financial records, tax-related data

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal applies only to the period following the withdrawal and does not affect the lawfulness of prior processing.

4. AI Processing

  • Data input into the Dytto platform may be processed by AI models for insights and suggestions.

  • AI processing is carried out through third-party large language model (LLM) providers bound by data processing agreements.

  • Data minimisation principles are applied; only necessary data is sent to AI providers.

  • We do not use your data or your clients' data to train AI models, unless explicitly agreed separately.

  • AI-generated outputs are intended as assistance and should be reviewed by qualified professionals before reliance.

5. Automated Decision-Making

Dytto does not make decisions that produce legal effects or similarly significant effects on you based solely on automated processing within the meaning of GDPR Article 22. AI features are assistive; human professionals retain decision responsibility.

6. Data Controller and Data Processor

As data controller: Dytto determines purposes and means of processing for website visitors, platform account holders, and prospective customers, including the product usage analytics described in Section 2.

As data processor: When accountants use Dytto to process client data, the accounting firm is the data controller; Dytto processes that data solely on documented instructions. For those data, the privacy notice of your accounting firm applies.

A Data Processing Agreement (DPA) is included as part of our customer agreements. Contact niels@dytto.ai for a standalone copy.

7. Data Sharing and Transfers

We do not sell your personal data.

Dytto may share data with external processors, including cloud hosting providers, AI/LLM service providers, product analytics providers, IT service providers, auditors, and legal advisors, all bound by data processing agreements.

Where processors are established outside the EEA, appropriate safeguards under GDPR Article 46 are applied, such as Standard Contractual Clauses (SCCs) or transfers to countries or organisations covered by an EU adequacy decision (including the EU-U.S. Data Privacy Framework).

The current list of our sub-processors is set out in our Data Processing Agreement and is available upon request at niels@dytto.ai. We will notify customers of any new or replacement sub-processor with a 14-day prior notice period.

8. Data Retention

Data is not kept longer than necessary, on servers at established cloud and hosting providers that comply with GDPR legislation.

  • Website visitor data (analytics) is retained for a maximum of 14 months.

  • Account and usage data is retained for the duration of your contract and deleted within 90 days after termination, unless a longer retention period is required by law.

  • Client accounting data is deleted or returned in accordance with the Data Processing Agreement: active data within 30 days after the end of services, encrypted backups within 90 days.

9. Data Security

We are committed to ensuring the confidentiality, integrity, and availability of your data. Measures include:

  • Encryption at rest and in transit

  • Multi-factor authentication for administrative access

  • Role-based access controls with least-privilege principle

  • Secure logging and monitoring of access to personal data

  • Secure data storage and encrypted backups

  • Regular security reviews, vulnerability remediation, and periodic penetration testing by an independent third party

10. Data Breach Notification

Upon a personal data breach likely to result in a risk to rights and freedoms, Dytto will:

  • Notify the relevant supervisory authority (the Belgian Data Protection Authority) without undue delay and, where feasible, within 72 hours, in accordance with GDPR Article 33.

  • Notify affected individuals without undue delay where the breach is likely to result in a high risk, in accordance with GDPR Article 34.

  • For customers with a Data Processing Agreement: notify the data controller within 48 hours of becoming aware of the breach.

11. Cookies and Tracking

Our website and platform use cookies:

  • Strictly necessary cookies for website hosting, security, and storing your cookie preference. These cannot be disabled.

  • Analytics cookies on the website (Google Analytics, loaded via Google Tag Manager), placed only with your consent via the cookie banner.

  • Platform analytics cookies on app.dytto.ai (PostHog, EU-hosted), used to understand feature usage and improve the service.

The full list of cookies, their duration, and how to manage or withdraw your preferences can be found in our Cookie Policy at dytto.ai/cookie-policy.

12. Your Rights

Under the GDPR, you can exercise the following rights by contacting niels@dytto.ai:

  • Right of access: You have the right to access the personal data Dytto processes about you and obtain additional information regarding this processing.

  • Right to rectification: Request correction of inaccurate or incomplete data.

  • Right to erasure: In certain cases, you may request the deletion of your personal data.

  • Right to restrict processing: In certain cases, you may request to restrict the processing of your personal data.

  • Right to data portability: In certain cases, you have the right to have the personal data you provided transferred to another controller, provided this is technically possible.

  • Right to object: You may object to the processing of your personal data for direct marketing purposes at any time.

Identity verification may be required.

Supervisory Authority: If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority.

Belgian Data Protection Authority (Gegevensbeschermingsautoriteit):

13. Children's Privacy

Dytto's services are designed for business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we discover inadvertent collection, we delete the data promptly.

14. Third-Party Links

Our platform may contain links to third-party websites or services. We are not responsible for their content or privacy practices.

15. Changes to This Policy

This policy is reviewed at least annually, or upon significant changes to our services or applicable law. The latest version will always be available at dytto.ai/privacy-policy with the effective date and version number clearly stated. We will inform you of material changes by email or through the platform.

Contact