MazeByte

Legal

Privacy Policy

Last updated: 1 March 2026

1. Who We Are

MazeByte is an autonomous AI platform that transforms raw, unstructured data into meaningful insights and fully generated, analytics-ready pipelines, without requiring data engineering teams.

We are incorporated in the United Kingdom and operate globally. When you use MazeByte, the entity responsible for your personal data is:

MazeByte Ltd
124 City Road
London, EC1V 2NX
United Kingdom
Company number: 16860301

This Privacy Policy applies to our website at mazebyte.com and our platform services (together, the “Services”). It explains what personal data we collect, why we collect it, how we use it, and what rights you have over it.

2. The Short Version

We built MazeByte on a foundation of trust. The same principles that govern how MazeByte handles your business data govern how we handle your personal data:

  • We collect only what we need.
  • We use your data only for the purposes we tell you about.
  • We do not sell your data. We do not use it for advertising.
  • Your data is yours. We are processors, not owners.
  • We are transparent about what we do and why.

The sections below set out the full detail.

3. Data We Collect

3.1 Account Data

When you register or sign in to MazeByte, we collect your name, email address, and profile picture. If you authenticate via Google or Microsoft SSO, we receive only the data those providers share with us under your authorisation: typically your name, email address, and profile picture.

3.2 Usage Data

We collect information about how you interact with the Services: pages visited, features used, actions taken within the platform, and session activity. We use this data to improve the product, diagnose technical issues, and understand how customers derive value from the platform.

3.3 Contact and Enquiry Data

If you submit a contact form, request a demo, or otherwise get in touch, we collect your name, email address, company name, and the content of your message.

3.4 Technical Data

We automatically collect IP address, browser type, operating system, referring URLs, and device identifiers for the purposes of security monitoring, fraud prevention, and platform performance.

3.5 Customer Data You Upload or Connect

When you upload data files or connect data sources to the MazeByte platform, we process that data solely to provide the Services you have requested. This is your data. We do not use it to train our models. We do not share it with third parties. We do not analyse it for any purpose beyond delivering the pipeline and insight outputs you have asked for.

This distinction matters: MazeByte is a data processor with respect to your business data. You remain the data controller. Data rights do not transfer to MazeByte at any point.

4. How We Use Your Data

We use personal data for the following purposes:

PurposeData Used
Creating and managing your accountAccount data
Providing, operating, and improving the ServicesAccount data, usage data, technical data
Sending transactional communications (account verification, password reset, invitation notifications, billing)Account data
Responding to enquiries and support requestsContact and enquiry data
Security monitoring, fraud detection, and abuse preventionTechnical data, account data
Complying with legal and regulatory obligationsAs required
Anonymised product analytics and improvementUsage data (anonymised or aggregated)

We do not sell your personal data. We do not use your personal data for advertising purposes. We do not use your uploaded business data for model training or secondary analysis.

5. Legal Basis for Processing

MazeByte is established in the UK and the UK GDPR is our primary compliance framework. Where the EU GDPR applies to users in the European Economic Area, we comply with it on equivalent terms.

Processing ActivityLegal Basis
Providing the Services you have signed up forContract performance (Article 6(1)(b))
Security monitoring, fraud prevention, product improvementLegitimate interests (Article 6(1)(f)), where these do not override your rights
Complying with applicable lawLegal obligation (Article 6(1)(c))
Marketing communicationsConsent (Article 6(1)(a)), where you have opted in

Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms. You may object to this processing at any time (see Section 8).

For users in other jurisdictions, we apply equivalent or stronger protections as required by local law, including CCPA for California residents (see Section 12).

6. Data Sharing and Third Parties

We share personal data with third parties only where strictly necessary to operate the Services. All third-party processors are bound by data processing agreements and are required to handle your data in accordance with applicable data protection law.

Categories of third-party processors we use:

  • Identity and authentication: Auth0 (Okta)
  • Cloud infrastructure and storage: data is processed within the UK or EEA, or under appropriate transfer safeguards
  • Transactional email delivery: for account and platform notifications
  • Analytics and error monitoring: anonymised or pseudonymised data only

We do not sell, rent, or trade personal data. We will disclose personal data if required to do so by applicable law or in response to a valid legal request from a competent authority, and will notify affected users where we are legally permitted to do so.

7. International Transfers

MazeByte is incorporated in the UK and serves customers globally. Where personal data is transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions recognised under UK or EU law
  • Equivalent mechanisms as required by applicable law

For transfers to the United States and other non-adequate countries, we rely on Standard Contractual Clauses supplemented by appropriate technical and organisational measures.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data. We honour these rights for all users globally, not only those in jurisdictions that legally require us to do so.

RightWhat It Means
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
ErasureRequest deletion of your personal data (“right to be forgotten”)
RestrictionRequest that we limit processing of your data in certain circumstances
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests
Withdraw consentWhere processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at [email protected]. We will acknowledge your request within five working days and respond fully within 30 days. You will not be charged for making a rights request.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with a supervisory authority. Our lead authority is the UK Information Commissioner's Office (ICO) at ico.org.uk. Users in the EEA may also contact their local data protection authority.

9. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Services.

Data TypeRetention Period
Account dataDuration of account plus 30 days after closure
Usage and technical data12 months on a rolling basis
Contact and enquiry data12 months from the date of submission
Customer uploaded dataDeleted upon account closure or earlier on request
Legal and financial recordsAs required by applicable law (typically 6–7 years)

If you close your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it by law.

10. Data Security

MazeByte implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, or disclosure.

Our measures include:

  • Encrypted data transmission (TLS 1.2+) in transit
  • Encryption at rest for data stored on our infrastructure
  • Role-based access controls limiting internal access to personal data
  • Regular security reviews and vulnerability assessments
  • Incident response procedures aligned with ICO breach notification requirements

No method of transmission over the internet is completely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by UK GDPR Article 33–34.

11. Cookies

We use cookies on mazebyte.com for two purposes: to keep the site and platform functioning (strictly necessary cookies), and to understand how visitors use our website so we can improve it (analytics cookies, placed only with your consent).

Full details of every cookie we use, how to manage your preferences, and how to withdraw consent at any time are set out in our Cookie Policy.

12. California Residents (CCPA / CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

  • The right to know what personal information we collect, use, and share
  • The right to delete your personal information
  • The right to opt out of the sale or sharing of personal information (note: MazeByte does not sell or share personal information)
  • The right to correct inaccurate personal information
  • The right to limit use of sensitive personal information
  • The right to non-discrimination for exercising your privacy rights

To exercise your CCPA rights, contact us at [email protected]. We will respond within 45 days.

13. Children

The Services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected] and we will delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last updated” date at the top of this page
  • Notify registered users by email where the changes are significant
  • Where required by law, seek renewed consent

Your continued use of the Services after the effective date of any changes constitutes your acknowledgement of the updated policy. We encourage you to review this page periodically.

15. Contact

For any questions about this Privacy Policy or how we handle your personal data, or to exercise your rights, please contact us:

MazeByte Ltd
[email protected]

We aim to respond to all enquiries within five working days.

This Privacy Policy should be read alongside our Terms and Conditions and, where applicable, our Data Processing Agreement.