Privacy Policy
Last Updated: 21 September 2026
HYTO Consult (“HYTO”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit or use www.hytoconsult.com (the “Website”), communicate with us, enquire about our services, engage us for consulting services, or otherwise interact with HYTO.
This Privacy Policy is intended to apply to users, visitors, prospects and clients globally, subject to applicable local laws. Where the law of your jurisdiction provides you with rights or protections that are greater than those described here, those rights will continue to apply.
By using the Website or providing personal information to us, you acknowledge that you have read and understood this Privacy Policy.
1. Who We Are
HYTO Consult is a consulting collective focused on helping D2C, ecommerce and consumer brands with growth strategy, brand building, marketing, operations, profitability, scaling and exit readiness.
For privacy-related questions or requests, please contact us using the contact details provided at the end of this Policy.
2. Information We Collect
Depending on how you interact with HYTO, we may collect the following categories of information:
A. Information You Provide Directly
This may include:
-
Full name
-
Business or company name
-
Job title or role
-
Email address
-
Telephone or mobile number
-
Country, city or general business location
-
Website, social media or marketplace information you voluntarily provide
-
Information contained in enquiry forms
-
Information provided during consultations, calls, meetings or correspondence
-
Business, operational, marketing or financial information provided in connection with our consulting services
-
Billing and transaction information where applicable
-
Any other information you voluntarily provide to us
Please do not provide sensitive personal information unless it is reasonably necessary for the services we are providing and you are authorised to share it.
B. Information Collected Automatically
When you access our Website, certain information may be collected automatically, including:
-
IP address
-
Browser type and version
-
Device type
-
Operating system
-
Approximate geographic location
-
Referring website or source
-
Pages visited
-
Time spent on pages
-
Date and time of access
-
Website interactions and technical information
-
Cookies and similar technologies
C. Information Received from Third Parties
We may receive information from third parties where permitted by law, including:
-
Business partners
-
Professional advisers
-
Analytics and advertising providers
-
Social media or digital platforms
-
Referral partners
-
Publicly available business sources
-
Companies or clients that engage HYTO and provide information about their personnel or representatives
Where you provide us with information about another individual, you should ensure that you have the necessary authority or lawful basis to do so.
3. How We Use Personal Information
We may use personal information for purposes including:
-
Responding to enquiries and requests
-
Providing and managing consulting services
-
Communicating with prospective and existing clients
-
Preparing proposals, audits, assessments and recommendations
-
Managing client relationships
-
Scheduling meetings and consultations
-
Processing payments and maintaining business records
-
Improving our Website, services and user experience
-
Understanding Website usage and performance
-
Marketing our services, where permitted by applicable law
-
Sending relevant business communications
-
Preventing fraud, abuse and security incidents
-
Protecting our legal rights and interests
-
Complying with applicable laws, regulations, court orders and governmental requests
-
Establishing, exercising or defending legal claims
-
Maintaining business continuity and security
-
Any other purpose disclosed to you at the time information is collected
We will not use personal information for materially incompatible purposes without an appropriate lawful basis or notice where required by law.
4. Legal Bases for Processing
Where applicable data protection laws require a lawful basis for processing, we may rely on one or more of the following:
-
Your consent
-
Performance of a contract or steps taken at your request before entering into a contract
-
Compliance with a legal obligation
-
Our legitimate interests, where those interests are not overridden by your rights and interests
-
Protection of vital interests
-
Performance of a task carried out in the public interest, where applicable
-
Any other lawful basis available under applicable law
Where we rely on consent, you may generally withdraw that consent at any time, subject to legal or contractual limitations.
Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
5. Cookies and Similar Technologies
Our Website may use cookies, pixels, tags, analytics tools and similar technologies.
These technologies may be used to:
-
Keep the Website functioning properly
-
Remember preferences
-
Understand Website traffic and usage
-
Measure advertising performance
-
Improve Website functionality
-
Detect fraud or security issues
-
Deliver or measure relevant advertising where legally permitted
Where required by applicable law, we will obtain consent before placing non-essential cookies or similar technologies.
You may be able to manage cookies through your browser or through any cookie-management tools made available on the Website.
Disabling certain cookies may affect Website functionality.
6. Analytics and Advertising
We may use third-party analytics, advertising or measurement services to understand how visitors use our Website and to measure the effectiveness of our marketing.
These providers may process information such as device information, IP address, browsing activity, approximate location and interaction data, subject to their own privacy policies and applicable law.
Where required, we will obtain appropriate consent or provide applicable opt-out mechanisms.
7. How We Share Personal Information
We do not sell personal information as a general business practice.
We may share personal information with:
-
Employees, consultants and contractors who need the information to perform their functions
-
Technology and hosting providers
-
Website and analytics providers
-
Email and communications providers
-
Payment processors
-
Professional advisers such as lawyers, accountants and auditors
-
Business partners where necessary to provide services
-
Government authorities, regulators or law-enforcement bodies where legally required
-
Potential buyers, investors or advisers in connection with a business transaction, merger, acquisition, restructuring or sale of assets
-
Other parties where you have instructed or authorised us to share the information
-
Other recipients where disclosure is permitted or required by applicable law
Where we engage third-party service providers to process personal information on our behalf, we will take reasonable steps to require appropriate confidentiality and data-protection safeguards.
8. International Data Transfers
HYTO may use service providers or work with clients and partners located in countries different from your own.
As a result, personal information may be transferred to, stored in, or accessed from another country.
Where applicable law imposes requirements on international transfers, we will use an appropriate lawful transfer mechanism or safeguard, such as an adequacy decision, approved contractual safeguards, standard contractual clauses, consent where legally valid, or another mechanism recognised by applicable law.
International transfer requirements can differ between jurisdictions, and HYTO will apply the requirements relevant to the particular processing activity.
9. Data Security
We use reasonable administrative, technical and organisational safeguards designed to protect personal information against unauthorised access, disclosure, alteration, loss, misuse or destruction.
However, no electronic transmission, storage system or security measure can be guaranteed to be completely secure.
Accordingly, while we take reasonable precautions, we cannot guarantee absolute security of personal information.
10. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including:
-
Providing services
-
Maintaining business and financial records
-
Managing client relationships
-
Resolving disputes
-
Establishing or defending legal claims
-
Complying with legal, tax, accounting or regulatory requirements
-
Enforcing agreements
-
Maintaining security and preventing abuse
Retention periods may vary depending on the type of information and applicable legal requirements.
When information is no longer required, we will take reasonable steps to delete, anonymise or securely dispose of it, subject to applicable law.
11. Your Privacy Rights
Depending on your jurisdiction and the circumstances of processing, you may have rights including:
-
The right to know what personal information we hold about you
-
The right to request access to your personal information
-
The right to request correction of inaccurate or incomplete information
-
The right to request deletion of personal information
-
The right to restrict or object to certain processing
-
The right to withdraw consent where processing is based on consent
-
The right to data portability, where applicable
-
The right to opt out of certain marketing communications
-
The right to opt out of certain sales or sharing activities where applicable
-
The right to limit certain uses of sensitive personal information where applicable
-
The right to lodge a complaint with a relevant data protection authority
-
The right not to be discriminated against for exercising applicable privacy rights
These rights are not absolute and may be subject to exceptions, limitations and verification requirements under applicable law.
12. California Privacy Rights
If you are a California resident and applicable California privacy law applies to our processing of your information, you may have additional rights, including rights to know, access, correct and delete personal information and to opt out of certain forms of sale or sharing, subject to statutory exceptions.
We will not unlawfully discriminate against you for exercising privacy rights available to you under California law.
Where applicable, requests relating to California privacy rights may be submitted using the contact details provided below.
13. European Economic Area and United Kingdom
If applicable data protection law in the European Economic Area or United Kingdom applies to you, you may have additional rights under the GDPR or UK GDPR, including rights of access, rectification, erasure, restriction, objection, portability and rights relating to automated decision-making, subject to applicable legal conditions and exceptions.
Where required, we will provide information regarding our lawful basis for processing, recipients, international transfers, retention and other matters required by applicable law.
You may also have the right to lodge a complaint with your relevant supervisory authority.
14. Children's Privacy
Our Website and consulting services are intended primarily for businesses and adults.
We do not knowingly seek to collect personal information from children where doing so would be prohibited by applicable law.
If you believe that a child has provided personal information to us without appropriate authorisation, please contact us so that we can review and, where appropriate, delete the information.
15. Third-Party Websites
Our Website may contain links to third-party websites, platforms or services.
We are not responsible for the privacy practices, security or content of third-party websites.
You should review the privacy policies of those third parties before providing them with personal information.
16. Business and Client Information
As a consulting business, HYTO may receive confidential business information from clients, including commercial, operational, financial, marketing, customer and strategic information.
Such information may be subject to separate contractual confidentiality obligations and agreements between HYTO and the relevant client.
This Privacy Policy does not replace or override a separate client agreement, data-processing agreement, confidentiality agreement or other contractual arrangement.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, technology, legal requirements or privacy practices.
When we make changes, we will update the “Last Updated” date at the beginning of this Policy.
Where required by law, we will provide additional notice or obtain consent.
18. Contact Us
If you have questions, concerns or requests regarding this Privacy Policy or your personal information, please contact HYTO Consult through the contact details published on our Website.
Privacy requests should include sufficient information for us to identify you and understand your request.
We may need to verify your identity before fulfilling certain requests.
19. Governing Rights and Local Law
This Privacy Policy is intended to operate alongside, and not exclude or restrict, any mandatory privacy rights or protections applicable to you under the laws of your jurisdiction.
Where mandatory local privacy law provides rights or remedies that conflict with this Policy, the mandatory local law will prevail to the extent required.
By using the HYTO Website or providing personal information to HYTO, you acknowledge that you have had an opportunity to review this Privacy Policy.