Home / Privacy policy
Privacy policy.
What we collect, why we collect it, how long we keep it, and how to exercise your rights.
This Privacy Policy explains how Gysho Limited ("Gysho," "we," "us," or "our") collects, uses, shares, and protects your personal data when you use our website at https://www.gysho.com (the "Website") and our related services (collectively the "Services"). It also explains your privacy rights and how to exercise them.
Gysho is the "data controller" for the personal data described in this policy, meaning we decide why and how it is processed. Our AI Transparency & Disclaimer Notice explains how our AI features work and their limitations; that notice describes AI transparency, while this policy covers data protection.
01 · Who we are and how to reach us
| Controller | Gysho Limited, registered in England and Wales, company number 11262484 |
| Registered office | Sussex Innovation Centre, Science Park Square, Brighton, East Sussex, England, BN1 9SB, United Kingdom |
| VAT number | GB 500 4861 27 |
| EU representative (GDPR Article 27) | Thomas Wink, Hortensiastraat 27, 2681CD Monster, Zuid Holland, The Netherlands Email: winkitnl@winkit.nl Appointed as our representative in the European Union under Article 27 of the GDPR. Individuals in the EU and EEA may contact our representative about any aspect of our processing of their personal data. |
| All enquiries, including privacy questions and rights requests | alert@gysho.com, or https://www.gysho.com/contact. We aim to respond within 1 business day. |
We do not have a separately appointed Data Protection Officer.
Because Gysho Limited is established in the United Kingdom, outside of the European Union, we have designated Thomas Wink as our representative in the European Union under Article 27 of the GDPR.
Our representative can be contacted at winkitnl@winkit.nl, by individuals in the EU and EEA and by supervisory authorities, on any matter relating to our processing of personal data. Contacting our representative does not affect your right to contact us directly at alert@gysho.com, or to complain to a supervisory authority as described in Section 8.
02 · The personal data we collect, why, and our legal basis
The GDPR requires us to have a lawful basis (a valid legal reason) for each way we use your personal data. This Website sets no cookies and uses no third-party analytics. We measure how the Website is used with our own self-hosted, cookieless analytics, described below, alongside standard web server logs.
| What we collect | Why we use it | Legal basis |
|---|---|---|
| Website server logs. When your browser requests a page, our web server records that request in standard log files. These include your IP address, the page requested, the date and time, and your browser's user-agent string, which identifies browser type and version and operating system. | To keep the Website secure and available, prevent fraud and abuse, and fix problems. | Legitimate interest (security and operation of our Website) |
| Website analytics, self-hosted and cookieless. We measure Website usage with our own analytics service running on our own infrastructure. No cookies are set and no identifier is stored on your device. For each page view we record the page path (without query strings), the host name of a referring website if you arrived from another site (never the full referring URL), your screen and browser window dimensions, your browser language, a two-letter country code, and an approximate time on page and scroll depth. Your IP address is used only at the moment the request arrives, to derive the country code and a temporary visitor reference, and is never written to disk or logged. That visitor reference is generated using a random value that changes every day and is never stored, so visits cannot be traced back to you or linked across days. | To understand which content is useful and to improve the Website. | Legitimate interest (understanding and improving our Website) |
| Contact and support data. Your name, email address, the content of your message, and our correspondence, when you contact us at alert@gysho.com or via https://www.gysho.com/contact. We do not retain email addresses for newsletters or mailing lists. | To respond to your enquiry, resolve your issue, and keep a record so we can help you in the future. | Legitimate interest (responding to you). Where your message relates to a contract, contractual necessity. |
| Account data. Login credentials and associated details for the various Gysho applications you use. | To create and manage your accounts and give you access to the applications you use. | Contractual necessity |
| AI interaction data (only if and when AI features are active in Gysho applications): your prompts and inputs to our AI, the AI's outputs, data the AI retrieves in response (which may include web search results), and technical logs of those interactions. Please do not enter sensitive personal data (for example health, financial, or government ID numbers) into AI features. | To provide the AI feature you are using, including maintaining and correcting your specific interaction; and to maintain the security of the feature. | Performance of a contract, for providing and maintaining the feature you are using. Legitimate interests, for security monitoring of the feature. We do not use your AI interaction data to train or improve our underlying AI models, and our AI provider does not have direct access to your data for this purpose. |
Special categories and children's data. We do not intentionally collect special categories of personal data (such as health, racial or ethnic origin, political opinions, or biometric data). None of our applications is aimed at, or designed for, children of any age, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at alert@gysho.com and we will delete it.
Automated decision-making. We do not make solely automated decisions about you that produce legal or similarly significant effects within the meaning of GDPR Article 22.
03 · Cookies and tracking technologies
We do not use cookies or similar tracking technologies on this Website. We do not use third-party analytics, advertising, or social media trackers, and we do not track you across other websites. Because no cookies or trackers are placed, no cookie consent banner is required. If we ever introduce cookies or tracking technologies, we will update this policy and obtain your consent where the law requires it.
04 · How long we keep your data (retention)
We keep personal data only as long as needed for the purposes above, or as required by law:
| Data type | Typical retention |
|---|---|
| Website server logs | 3 months |
| Cookieless analytics records | 3600 days, then deleted automatically by a daily retention sweep |
| Contact and support correspondence | 2 to 5 years, to handle follow-ups and legal claims |
| Account data | For the life of the account, deleted within 180 days of closure |
| AI interaction data | The data retention depends on the applications used and is available by request. Our typical retention period is 1 year. |
When retention ends, we delete or irreversibly anonymise the data. We do not maintain mailing lists, so no marketing data is retained.
05 · Who we share your data with
We share personal data only as needed, and under appropriate safeguards:
- Service providers (processors). Companies that host our systems, deliver our emails, or run our customer support tooling on our behalf. They process data only on our instructions under a contract (a "data processing agreement"). A current list of our processors and subprocessors, including their role, the categories of data they handle, their data locations, and the safeguards applied to any international transfers, is maintained at https://www.gysho.com/subprocessors.
- Legal and safety. Where required by law, regulation, legal process, or to protect the rights, safety, or property of Gysho, our users, or others.
- Business transfers. If Gysho is involved in a merger, acquisition, or sale of assets, your data may be transferred, with notice where required.
We do not sell your personal data.
06 · International transfers
Gysho Limited is established in the United Kingdom (company number 11262484, VAT number GB 500 4861 27).
Where any of our service providers are located in other countries outside the EEA or UK, we rely on a lawful transfer mechanism, such as an adequacy decision for that country or Standard Contractual Clauses, plus supplementary measures where needed. You may request a copy of the relevant safeguards by contacting alert@gysho.com.
07 · Your rights under data protection law
Depending on the circumstances and subject to legal limits, you have the right to:
- Access your personal data and receive a copy;
- Rectification of inaccurate or incomplete data;
- Erasure ("right to be forgotten") in certain cases;
- Restriction of processing in certain cases;
- Object to processing based on legitimate interest, and object at any time to direct marketing;
- Data portability for data you provided, processed based on consent or contract by automated means;
- Withdraw consent at any time where processing is based on consent (this does not affect processing already done);
- Lodge a complaint with a supervisory authority (see Section 8).
To exercise any of these rights, contact us at alert@gysho.com or via https://www.gysho.com/contact. We respond within one month, as the GDPR requires, and can extend by up to two further months for complex requests, with notice. We may need to verify your identity first.
08 · How to complain
If you believe we have handled your personal data unlawfully, please contact us first at alert@gysho.com so we can try to resolve it. You also have the right to complain to your supervisory authority:
- United Kingdom: the Information Commissioner's Office (ICO), via https://ico.org.uk/make-a-complaint/ or by phone on 0303 123 1113 (Monday to Friday, 9am to 5pm, excluding bank holidays).
- European Union: your national data protection authority. A list is available from the European Data Protection Board at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
If you are in the EU or EEA, you may also raise the matter with our EU representative, whose details are in Section 1. Our representative is mandated to be addressed on all issues relating to our processing of personal data. This is in addition to, and does not replace, your right to complain to your supervisory authority.
09 · How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration, including encryption in transit (TLS), access controls, and staff awareness measures. No method of transmission or storage is fully secure, so we cannot guarantee absolute security.
10 · Changes to this policy
We may update this policy from time to time. We will post the updated version with a new version number and effective date and, where changes are significant, provide additional notice (for example on the Website).
11 · Accessibility and languages
This policy is provided in a clear, accessible format and is available in English and Dutch. For an alternative accessible format, contact alert@gysho.com.