---
url: https://byoxon.com/data-protection-policy/
title: "Data Privacy / Data Protection Policy - Byoxon (BoB)"
description: "Byoxon / TATEEDA Data Protection Policy outlining GDPR-aligned principles, lawful processing, data subject rights, international transfers, and cookie usage."
type: policy
published: 2026-01-21
modified: 2026-01-21
---

# Data Privacy

## Aim of the Data Protection Policy

We are always working to stay compliant – we encourage audits, certifications, and provide industry-standard contractual protections.

This Data Protection Policy ensures the level of data protection prescribed by the European Union Data Protection Regulations and provides one of the necessary framework conditions for cross-border data transmission.

This Data Protection Policy applies to all companies of TATEEDA and BYOXON, affiliated companies, and their employees, and is based on globally accepted, basic principles of data protection. The latest version can be accessed at www.tateeda.com.

## Principles of Personal Data Processing

We collect and use certain types of Personal Data that relate to the people (Data Subjects) with whom we come into contact in order to carry out our business. Personal data shall be:
(a) processed lawfully, fairly, and transparently ('lawfulness, fairness and transparency');
(b) collected for specified, explicit, and legitimate purposes ('purpose limitation');
(c) adequate, relevant and limited to what is necessary ('data minimisation');
(d) accurate and kept up to date ('accuracy');
(e) kept in a form which permits identification of data subjects no longer than necessary ('storage limitation');
(f) processed in a manner that ensures appropriate security ('integrity and confidentiality').

## Lawfulness of Processing

According to Article 6(1) of EU Regulation No 2016/679 (GDPR), lawful reasons could be: the data subject has given consent; processing is necessary for the performance of a contract; or processing is necessary for the legitimate interests pursued by the controller or a third party (except where overridden by the data subject's interests or fundamental rights, particularly where the data subject is a child).

## How Do We Collect Your Personal Information

- You contact us directly via our website to request information about our services.
- You reply to our direct marketing campaigns.
- We acquired your personal data from other sources, such as social media sites.

If you are under 16, please do not provide us with any of your information unless you have the permission of your parent or guardian. You may request rectification or erasure ("right to be forgotten") under Article 17(1) by contacting tateeda@tateeda.com.

## What Personal Data May Be Collected
Name, address, phone numbers, e-mail address. When you visit our website, web servers automatically recognize your domain name and IP address, the referring site's IP, OS version, and browser. This does not identify you directly and is not treated as personal data.

## How Do We Keep Personal Data Safe
Technical and organizational security measures, including encryption and authentication tools. Main measures:
- restricted access on a "need to know" basis
- transfer of data only in encrypted form
- firewalled IT systems to prohibit unauthorized access
- permanently monitored access to IT systems to detect and stop misuse.

## Your Rights
- Right of Access by the Data Subject
- Right to Rectification
- Right to Erasure (Art. 17 GDPR)
- Right to Restriction of Processing (Art. 18 GDPR)
- Right to Object
- Right to Data Portability
- Right of Revocation (withdraw consent at any time, free of charge, via tateeda@tateeda.com)
- Right to Complain to a government supervisory authority

## International Transfers
TATEEDA has offices in many countries. Your Personal Data may be processed on a server in a country different from your residence. Appropriate safeguards are in place, including the European Commission's Standard Contractual Clauses for transfers of Personal Data between group companies, requiring protection equivalent to EU data protection law.

## Cookies

### Use of Cookies
The TATEEDA website may use cookies to personalize your online experience. Cookies cannot run programs or deliver viruses; they are uniquely assigned to you and can only be read by the issuing domain's web server. TATEEDA uses cookies to collect your IP address and browsing information, placed only with consent. To record and analyze visits and improve experience, TATEEDA/BYOXON uses Google Analytics and the Yandex.Metrika counter, which place cookies to track traffic and interaction. You can accept or decline cookies via your browser; declining may limit interactive features.

### Data Protection Standards
We proactively ask third parties to review our services against international standards, like ISO standards, so your business and personal data are handled responsibly.

### Data Processing Agreement
During contractual relations, there might be a necessity to process Personal Data previously collected by your company. In such cases, we would act as a processor or sub-processor, keep all Personal Data strictly confidential, and fully comply with EU Regulations, providing a special Data Protection Agreement and Standard Contractual Clauses recommended by the European Commission.

### Personal Data Protection Clause (Direct Marketing)
The processing of personal data for direct marketing is carried out according to point (f) of Article 6(1) (Legitimate Interests) of the GDPR. In accordance with Article 47 of the GDPR Preamble, processing for direct marketing is considered to serve a legitimate interest. Personal data is acquired from open sources such as social media sites. Types collected: name, address, phone numbers, e-mail address. You retain rights to rectification and erasure ("right to be forgotten") via tateeda@tateeda.com.
