Privacy Policy
Last updated August 6, 2026
This Privacy Policy explains how Bytecode d.o.o. ("Bytecode", "we", "us"), the provider of the SayTrue platform ("SayTrue", the "Service"), collects, uses and protects personal data. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Croatian data-protection law.
1. Who we are
Bytecode d.o.o., Zagreb, Croatia, is the data controller for the account and login information of the people who administer SayTrue. For the end-customer conversations that businesses handle through SayTrue, Bytecode acts as a data processor on behalf of that business (our customer), who remains the controller of that content.
Contact: support@bytecode.hr.
2. Data we collect
- Account & login data — your name, email address and profile picture. If you sign in with Google, we receive only your basic Google profile and email address (see section 3).
- Workspace configuration — the agents, knowledge base, documents and settings you create in SayTrue.
- Conversation data — messages, transcripts and any personal data contained in the customer conversations your agents handle, processed on your behalf.
- Technical & usage data — log data, device/browser information and diagnostic events needed to run and secure the Service.
3. Signing in with Google
When you choose "Sign in with Google", we use Google OAuth solely to authenticate you. We request only your email address and basic profile (name and profile picture). We do not access your Gmail, Drive, contacts or any other Google data, and we do not use this information for advertising. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke access at any time in your Google account settings.
4. How we use data and our legal bases
- To provide, secure and operate the Service (performance of a contract).
- To authenticate users and prevent abuse (legitimate interest / legal obligation).
- To process customer conversations strictly on the documented instructions of the business customer (processor role).
- To communicate about the Service and provide support (legitimate interest / contract).
5. Subprocessors
We rely on a limited set of vetted subprocessors to deliver the Service, including cloud hosting, large-language-model and voice providers, and transactional email. They act under data-processing agreements and only process data as needed to provide their function. A current list is available on request at support@bytecode.hr.
6. Retention
Account data is retained while your account is active. Conversation transcripts and related personal data are retained according to the retention period configured by the business customer — 90 days by default — after which a scheduled nightly job deletes or anonymizes them. We delete or return customer data on termination, subject to any legal retention obligations.
7. Security
We apply appropriate technical and organizational measures, including encryption in transit, encryption of sensitive credentials at rest, access controls and tenant isolation, to protect personal data.
8. Hosting and international transfers
SayTrue is built and operated from Croatia by Bytecode d.o.o. We are formally verifying the hosting region of our application servers, database and backups, and we will state it here once that verification is documented — we would rather leave this open than claim a location we have not confirmed. Prospective customers receive the current subprocessor list, including each provider's role and processing location, before signing. Where a subprocessor processes data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Your rights
Subject to the GDPR, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. To exercise these rights, contact support@bytecode.hr. If your data is handled by a business using SayTrue, please contact that business directly, as they control that content. You may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).
10. Cookies
We use strictly necessary cookies to keep you signed in and to secure the Service. We do not use advertising cookies.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above.
12. Contact
Bytecode d.o.o., Zagreb, Croatia — support@bytecode.hr.