Legal · privacyPublished 2026-09-18 · last change 2026-09-22TermsPrivacyRefunds

What this site collects, and what it does not.

No cookies for visitors, no analytics, no tracking scripts. Personal data reaches us when you send a form, write to us, open an account or subscribe. This page names every party that sees a request from your browser and everything an account stores, and changes only by a dated entry in the list at the end.

Requests about your data, including deletion: [email protected].

01Who is responsible #

The controller of personal data processed through debyko.com is MB „Blynai“, company code 308115000, Girulių g. 10, LT-12112 Vilnius, Lithuania, [email protected].

02What is collected #

Just by visiting: nothing. The site sets no cookies, stores nothing in your browser, and runs no analytics or tracking scripts.

When you send a form: the Contact sales and Join the waitlist forms send what you type — your email address, and for a sales request the organisation, the engagement and the venues, instruments and period; for the waitlist the product you are interested in — to a function on this site, which passes it on by email to [email protected] through Mailjet. The notification also carries your IP address and country, so that abuse can be recognised; they are not stored anywhere else. To limit abuse the function counts requests per IP address in Cloudflare’s key-value store; each count expires by itself after ten minutes.

When you write to us directly: the Subscribe buttons, and the address shown if a form cannot send, open your own email app. What you send is your email address, your name if your email app includes it, and what you write.

When you open an account: your email address and the time the account was opened. Signing in works by a link sent to that address; the link is valid for fifteen minutes and is stored as a hash until then. The account keeps, for each API key, its first twelve characters and a hash of the rest — never the key itself — plus the plan, the dates it was issued, expires or was revoked, and a label you give it. A session cookie is set only after you sign in, only on your account pages, and only to keep you signed in.

When you use a key: the API counts requests per key, per hour and per endpoint class, and the seconds a live stream stayed open. These counts enforce your plan’s limits and are the basis of usage shown in your account. The API does not keep a per-request log tied to your key. Your IP address is used only for short-lived rate counts that expire within an hour.

When you subscribe: the checkout is Paddle’s. We receive from Paddle your name, email address, country, the plan, the subscription’s status and dates, and the identifiers Paddle uses for the subscription and its invoices. We never receive your card number.

At the providers the pages use: the technical data of each request your browser makes — IP address, time, requested address and browser details — as described in section 04.

03Why, and on what basis #

  • A sales request is used to answer it and to prepare a scope — steps taken at your request before a contract (GDPR Art. 6(1)(b)).
  • A waitlist address is used for one message when the chosen product opens — your consent (Art. 6(1)(a)), which you can withdraw at any time by writing to us.
  • Request data at the hosting and delivery providers is processed to deliver the pages and keep them secure — legitimate interest (Art. 6(1)(f)).
  • Account, key and usage data are processed to provide the service you signed up for and enforce its limits — performance of a contract (Art. 6(1)(b)).
  • Subscription and invoice records are kept because accounting law requires it — a legal obligation (Art. 6(1)(c)).

Nothing is sold, and nothing is shared for advertising.

04Who else sees a request #

  • Cloudflare, Inc. hosts debyko.com (Cloudflare Pages), runs the function that sends the forms, and sits in front of the market-data API. It processes the technical data of every request, and receives network-error reports from browsers that support them, under its own retention rules.
  • Google serves the two typefaces the pages use (Google Fonts). When your browser fetches them it sends Google its IP address and browser details.
  • The market-data API at cryptosmithx.blynai.eu, operated by MB „Blynai“, answers the pages’ requests for figures. It keeps no access log of visitors. If a request fails with a server error, a technical error report without your IP address is sent to Sentry (Functional Software, Inc., EU region).
  • Mailjet (Sinch, EU) delivers the Contact sales and waitlist forms to [email protected]: the form’s content, your email address as the reply-to, and your IP address and country. If a delivery fails, Mailjet’s error message is written to the function’s log at Cloudflare.
  • Apple hosts the [email protected] mailbox (iCloud Mail); messages you send us, and the form notifications, are stored there.
  • Paddle.com Market Ltd (Paddle) handles checkout, payment, tax and invoicing as our merchant of record. MB „Blynai“ operates the service and holds the Paddle account; Paddle sells the subscription to you and is the seller on your receipt. For the payment itself Paddle is an independent controller under its own privacy notice; it sends us the subscription data listed in section 02.
  • Mailjet (Sinch, EU) also delivers sign-in links and subscription emails.
  • The account and API at api.debyko.com and studio.debyko.com, operated by MB „Blynai“ on infrastructure rented from Microsoft (Azure, EU region), store account, key and usage data as described in section 02.

Cloudflare, Google and Apple may process data outside the European Economic Area under their own safeguards for such transfers.

05How long it is kept #

  • A waitlist address: until the one message is sent when the product opens, then deleted.
  • A sales request and the correspondence that follows: for as long as the conversation or the engagement lasts, and afterwards only as long as the law requires records to be kept.
  • Your IP address in the form’s request count: ten minutes, in Cloudflare’s key-value store, then it expires.
  • Request data at Cloudflare and Google, and delivery records at Mailjet: for the periods those providers set.
  • Account, key and plan data: for as long as the account exists, then deleted within thirty days of closure.
  • Usage counts per key: twelve months, then deleted.
  • Subscription and invoice records received from Paddle: for as long as accounting law requires, currently ten years.
  • Sign-in link hashes: fifteen minutes, then deleted; session cookie: until you sign out or thirty days.

06Your rights #

You can ask for access to, correction or deletion of your data, restriction of its processing or a copy of it, object to its processing, and withdraw a consent you gave — by writing to [email protected]. You can also complain to the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija).

Changes to this page #

  • 2026-09-18First publication of this page.
  • 2026-09-18The Contact sales and waitlist forms send through a function on this site and Mailjet instead of opening your email app; Mailjet added as a processor, with the IP address and country the notification carries. The request count per IP address is kept in Cloudflare’s key-value store for ten minutes.
  • 2026-09-22Accounts, API keys, usage counts and subscriptions added; Paddle added as merchant of record; Microsoft Azure added as hosting for the account and API; Mailjet now also delivers sign-in links; the session cookie set after sign-in described.

Each later change is added here with its date.