Privacy policy
How BytecodeHS handles information across its public website, business communications, authorized security research, and custom web, mobile, and API development.
Last updated: 25 September 2026
Who this covers
BytecodeHS is a business operated by Stiv Chachashvili, an individual business owner based in Be’er Sheva, Israel. He is responsible for the personal information collected directly through bytecodehs.net, including its /security/ section, the separate contact API, and business communications. This policy also describes our handling of information during authorized security research and custom web, mobile, and API development. A signed client agreement may set additional, project-specific rules.
When we handle information on behalf of a client in a system we develop or operate, that client may determine the purpose and instructions for processing. Requests about that information may need to be handled with the client.
Questions or privacy requests can be sent to privacy@bytecodehs.net. Security-related requests can also be sent to security@bytecodehs.net.
Information we receive
- Contact form details: name, email address, company if supplied, enquiry topic, and message.
- Business communications and records needed to discuss, quote, perform, and document an engagement.
- Technical material a client chooses to provide within an agreed project scope. Please do not send vulnerability details or secrets through the public form.
- Basic server and security logs, which may include IP address, request time, URL, and browser information.
You are not legally required to provide information through the form. Its name, email, topic, and message fields are required to submit it; without them, we cannot receive and answer the enquiry through the form. You may email us instead, but we will still need contact details and enough information to respond.
Why we use it
- Respond to enquiries and prepare proposals.
- Perform and administer agreed security research or software development work.
- Protect our systems, investigate misuse, and maintain operational records.
- Meet applicable legal, accounting, and contractual obligations.
We do not use the contact form to sign you up for marketing messages, and we do not sell personal information.
How long we keep it
Our retention period for enquiries that do not become customer records is 12 months in the contact-ticket database. A daily job deletes contact tickets older than one year from that database. If an enquiry becomes an engagement, necessary customer and project records may be kept separately under the signed agreement and applicable legal or accounting requirements. Direct email correspondence, security logs, and Vultr's automated backups may follow different retention periods.
A deletion request may be limited where a record must be kept for a legal obligation, an active agreement, or a dispute.
Your choices and requests
Under Israeli law, you may ask to access personal information about you in a database and request correction or deletion of information that is inaccurate, incomplete, unclear, or outdated. You may also ask us to delete other information; we will assess that request under the law that applies to the information. Email privacy@bytecodehs.net with enough detail to identify it. We may verify your identity before releasing or changing records. See our Data deletion page for the process.
Security
Please arrange a secure channel with us before sending sensitive research material.
Changes and contact
We will update the date on this page when the policy changes. Handling of existing client data remains subject to the applicable signed agreement and law. For privacy questions, email privacy@bytecodehs.net.