OAS is a one-person studio. There are no accounts on this site, no database behind it, and no advertising trackers in it. The only personal data we hold is what you type into the contact form and send us, plus the ordinary technical records any web server keeps. This page explains both.
Who we are
OAS ("we", "us") operates this website at byoas.com and is the data controller for the personal data described here. We are based in Albania and can be reached at contact@byoas.com for anything on this page, including a request to see or delete your data.
Albanian law no. 124/2024 on personal data protection applies to us, and it mirrors the EU General Data Protection Regulation. If you are in the EU or EEA, the GDPR applies to you as well. The two say substantially the same thing, and this policy is written to satisfy both.
What we collect
What you send us
The contact form asks for your name and email address, and optionally your phone number, company, which services you are interested in, and when you are looking to start. The message box is yours to fill however you like.
Only name, email, and a message are required. Everything else is optional and the form works without it. Whatever you put in the message box is up to you, so please do not send us anything sensitive, confidential, or belonging to someone else who has not agreed to it.
The form also carries two anti-spam checks: a hidden field that people never see and bots tend to fill, and a timestamp of when the page loaded, used to reject submissions that arrive faster than a human could type. Neither is stored, and neither identifies you.
What the server records
Our host, Vercel, keeps short-lived request logs the way every web server does. Those include your IP address, the page requested, your browser's user-agent string, and a timestamp. We do not use them to identify anyone. They exist so the site can be kept online and abuse can be traced, and they age out on Vercel's own schedule.
Aggregate analytics
We use Vercel Web Analytics to see which pages get read. It sets no cookies, assigns no persistent identifier, and cannot follow you to another site. Visits are counted into aggregate numbers, and the raw hash it uses to tell one visit from another is discarded within 24 hours. There is nothing in it we could tie back to you if we tried. More on this in the cookie policy.
What we do not do
- No advertising or tracking cookies. No Meta pixel, no Google Analytics, no retargeting, no third-party ad network.
- No selling or sharing. Your details are not sold, rented, or passed to anyone except the service providers listed below, who process data on our instructions.
- No profiling, no automated decisions. Nothing on this site scores you, segments you, or decides anything about you automatically.
- No accounts, no database. The site stores nothing about visitors. A form submission becomes an email and lives in our inbox, nowhere else.
- No newsletter you did not ask for. Sending an enquiry does not add you to a mailing list.
Why we are allowed to hold it
| What | Why we process it | Legal basis |
|---|---|---|
| Contact form details | To read your enquiry and reply to it | Steps taken at your request before entering a contract, and our legitimate interest in answering people who write to us |
| Server logs | To keep the site available, secure, and free of abuse | Legitimate interest |
| Aggregate analytics | To understand which pages are useful | Legitimate interest — the measurement is anonymous, so no consent is required |
| Correspondence after an enquiry | To quote, deliver, and support work you have asked for | Performance of a contract |
Where we rely on legitimate interest, we have weighed it against your privacy and concluded the processing is limited, expected, and not something a visitor would object to. If you disagree, you can object — see your rights below.
Who else touches it
We keep the list of third parties as short as the site's dependency list. Each of these processes data on our instructions and is bound by its own contract to do nothing else with it.
| Provider | What it does | What it sees |
|---|---|---|
| Vercel | Hosts and serves the site, and runs the cookieless analytics | Request logs, including IP address and user-agent |
| Resend | Delivers your contact form submission to us as an email | Everything you entered in the form |
| Our email provider | Holds the resulting message in our inbox | Everything you entered in the form, plus any later correspondence |
These providers are established in the United States, so sending an enquiry means your details are transferred outside Albania and the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses, which the providers incorporate into their data processing agreements with us.
How long we keep it
- Enquiries that go nowhere: kept for up to 24 months, then deleted. Conversations restart, and it helps to have the earlier one.
- Enquiries that become work: kept for the length of the engagement and for as long afterwards as accounting and tax rules require.
- Server logs: retained by Vercel on its own schedule, typically weeks rather than months.
- Analytics: aggregate counts only, with nothing personal left to delete.
You do not have to wait for any of that. Ask us to delete your data and we will, unless a law requires us to keep a specific record.
Your rights
Under Albanian law no. 124/2024 and the GDPR you can ask us to do any of the following, free of charge:
- See it. Get a copy of the personal data we hold about you.
- Fix it. Have anything inaccurate corrected.
- Delete it. Have it erased, where no legal obligation requires us to keep it.
- Restrict it. Have us pause processing while a dispute about it is resolved.
- Object to it. Object to processing we base on legitimate interest.
- Take it with you. Receive it in a portable, machine-readable format.
Email contact@byoas.com and we will respond within 30 days. We may ask a question or two to confirm it is really you, which is a safeguard for you rather than an obstacle.
If you are unhappy with how we handled it, you can complain to Albania's Information and Data Protection Commissioner at idp.al, or to the supervisory authority in your EU or EEA country of residence. We would rather you came to us first, but the right is yours either way.
Security
The site is served over HTTPS everywhere. The contact form posts to a server action that validates and length-limits every field before it goes anywhere. API credentials live in environment variables, never in the code or the browser. There is no database to breach because there is no database. No system is perfect, and we do not claim otherwise, but there is very little here to lose.
Work we do for clients
When we build a website or a CRM for a client, any data their customers enter belongs to that client. In that arrangement they are the controller and we are a processor acting on their instructions, governed by the agreement between us rather than by this policy. This page covers byoas.com and the people who contact us through it.
Children
This site sells services to businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has sent us something, tell us and we will delete it.
Changes to this policy
If this policy changes, the date at the top of the page changes with it, and we will not quietly broaden what we do with data already collected. There is no version history to browse, so if the date matters to you, keep a copy.
Contact
Questions, requests, or complaints about anything here go to contact@byoas.com. If you would rather use the form for it, the contact page reaches the same inbox.
This page is written to be clear and accurate, not to serve as legal advice. If your situation turns on a clause here, take advice on it.
