GDPR Policy

Last updated: March 2026

1. Our Commitment to GDPR

Byebyte is committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take data protection seriously — both the personal data of our clients and the data stored on the IT equipment we process.

2. Data Controller

Byebyte acts as the data controller for personal information collected through our website, contact forms, and business communications. For equipment containing third-party data, we act as a data processor on behalf of our clients, destroying all data in accordance with agreed standards.

3. Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: Processing necessary to fulfil our collection and disposal services.
  • Legitimate interest: Communication about our services and improving our operations.
  • Legal obligation: Record-keeping for WEEE compliance and waste transfer regulations.
  • Consent: Marketing communications, which you can opt out of at any time.

4. Data Destruction & NIST 800-88

All data-bearing devices collected by Byebyte undergo secure data sanitisation following NIST 800-88 guidelines. This includes software-based erasure with verification, or physical destruction where necessary. Every drive is individually logged with its serial number and erasure status. Certificates of destruction are issued as proof of compliance.

5. Zero to Landfill Commitment

Our zero-to-landfill policy ensures that no equipment or materials are sent to landfill. This includes data-bearing media, which is either securely wiped and reused, or physically destroyed with the resulting materials sent to certified recycling facilities. This approach supports both data protection and environmental sustainability — ensuring your old IT is handled responsibly at every stage.

6. Data Protection Measures

We implement the following security measures:

  • Secure chain-of-custody from collection to processing
  • Access controls on all systems containing client data
  • Encrypted communications for sensitive information
  • Regular review of security procedures
  • Staff training on data protection responsibilities

7. Data Subject Rights

Under UK GDPR, individuals have the following rights regarding their personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data where there is no compelling reason for continued processing.
  • Right to restrict processing: Request limitation of how we use your data.
  • Right to data portability: Receive your data in a structured, commonly-used format.
  • Right to object: Object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, please contact us using the details below. We will respond within one month.

8. Data Breach Procedures

In the unlikely event of a personal data breach, we will notify the Information Commissioner's Office (ICO) within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms. Affected individuals will be notified directly where the breach poses a high risk.

9. International Transfers

We do not transfer personal data outside the United Kingdom. All data processing and equipment handling takes place within the UK.

10. Contact & Complaints

For any GDPR-related queries, contact us at office@byebyte.co.uk.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.