1. Data controller
The data controller for personal data processed through Jawwws Bytes is Jawwws Ltd, a company registered in England and Wales with registered address at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
For data protection enquiries, you can contact us at dpo@jawwws.com.
2. Scope
This policy applies to:
- Visitors to the Jawwws Bytes website
- Users who register for an account
- Workspace owners, administrators and team members
- People who interact with short links, QR codes, or offline engagement assets created through the platform
- People who contact us for support or other business communications
3. Data we collect
Account and profile data
Name, email address, password (stored in hashed form), account preferences and settings.
Workspace and billing data
Workspace name, plan type, team member details, and billing or invoicing contact information where applicable.
Link and engagement data
Short link configurations, destination URLs, link metadata, QR code settings, offline engagement details, and associated assets.
Analytics and usage data
Click counts, scan counts, unique visitor estimates, referrer sources, geographic data (country/region level), device types, browser types, operating systems, and timestamps associated with link interactions.
Jawwws Bytes logs information about link visits and interactions for analytics, security, fraud prevention and service performance purposes.
Technical and device data
IP addresses, browser user-agent strings, device identifiers, screen resolution, referring URLs, and other technical metadata collected automatically during website and application usage.
Bot protection and form security
When you submit selected public forms, such as the contact form, we may use Cloudflare Turnstile to help prevent spam, automated abuse and malicious submissions. This may involve Cloudflare processing technical information about your browser, device and request so that it can assess whether the submission is likely to be legitimate. We use this for security and abuse prevention.
Cookie and consent data
Information about cookie preferences and consent choices stored in your browser or device, such as optional analytics consent. These choices are currently browser-level preferences and are not silently synced with your account settings. See our Cookie Policy for full details.
Communications and support data
Messages, emails, support requests and any content you provide when communicating with us.
4. How we collect data
- Directly from you - when you register, create content, configure links, update your profile or contact support.
- Automatically - through your use of the website, application, and API, including technical data collected via cookies and similar technologies.
- From link interactions - when someone clicks a short link, scans a QR code, or interacts with an offline engagement asset, we collect technical and analytics data about that interaction.
- From third parties - where applicable, from integration partners, identity providers, or analytics services.
5. Purposes of processing
- Providing the service - operating short links, redirects, QR codes, analytics, workspaces and offline engagement features.
- Account security and authentication - protecting your account, verifying identity, and managing sessions.
- Analytics and reporting - generating usage insights and performance reports for workspace owners and authorised users.
- Customer support - responding to enquiries and resolving issues.
- Product improvement - understanding how the platform is used to improve features and reliability.
- Fraud and abuse prevention - detecting and preventing misuse, spam, phishing and other harmful activity.
- Legal and compliance - meeting our legal obligations and responding to lawful requests.
- Service communications - sending transactional messages such as verification emails, security alerts and service updates.
- Marketing - only where you have given consent or where we have a legitimate interest, and always with an easy opt-out.
6. Lawful bases
We process personal data under the UK General Data Protection Regulation (UK GDPR) using the following lawful bases:
- Contract - processing necessary to provide the service you have signed up for, including account management, link creation, and analytics delivery.
- Legitimate interests - processing necessary for our legitimate business interests, such as improving the platform, preventing fraud, ensuring security, and understanding usage patterns. We balance these interests against your rights.
- Legal obligation - processing necessary to comply with applicable law, regulation or lawful requests.
- Consent - where we rely on your consent (for example, for optional marketing communications or non-essential cookies), you can withdraw it at any time. Cookie consent choices are currently managed per browser or device.
8. International transfers
Some of our service providers may process data outside the United Kingdom. Where this occurs, we ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the relevant authority, or transfers to jurisdictions with an adequate level of data protection as recognised by the UK government.
9. Data retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, or as required by law. As a general guide:
- Account data is retained while your account remains active and for a reasonable period after closure.
- Analytics and interaction data is retained in accordance with your workspace plan's retention period.
- Support correspondence is retained for a reasonable period for quality and compliance purposes.
- Where data is anonymised, it may be retained indefinitely for statistical analysis.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration. These measures include encrypted storage, secure authentication, access controls, and regular review of our security practices.
No system is completely secure. We encourage you to use a strong, unique password and to keep your account credentials confidential.
11. Your rights
Under UK data protection law, you have the right to:
- Access - request a copy of the personal data we hold about you.
- Correction - ask us to correct inaccurate or incomplete data.
- Deletion - ask us to delete your personal data in certain circumstances.
- Restriction - ask us to restrict how we process your data in certain circumstances.
- Objection - object to processing based on legitimate interests.
- Portability - request your data in a structured, machine-readable format.
- Withdraw consent - where processing is based on consent, withdraw it at any time.
- Complain - lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise any of these rights, please contact us at dpo@jawwws.com.
12. Children
Jawwws Bytes is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
13. Changes to this policy
We may update this policy from time to time. Where changes are material, we will notify account holders by email or through the platform. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
14. Contact
If you have any questions about this policy or our data practices, please contact:
Jawwws Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
General enquiries: bytes@jawwws.com
Privacy enquiries: dpo@jawwws.com