Privacy Policy

Irish and EU website policy | Effective 7 September 2026 · version 1.1.0

Our approach. BYE is designed to collect less, explain more and keep sensitive career and financial information optional. We do not require your employer name, manager name or workplace contact details.


1. Who controls your personal data

The controller for personal data handled through Build Your Exit is:

Controller: Ronaldo Pavic trading as Build Your Exit

Address: 57 Cypress Drive, Cypress Downs, Templeogue, D6W R859, Ireland

Privacy email: hello@buildyourexitnow.com

Telephone: +353 83 899 2912

This Policy applies to buildyourexitnow.com, BYE accounts, assessments, products, workshops, support and related communications.


2. Personal data we collect

Website and security data

We may collect IP address, browser and device information, pages requested, approximate location derived from IP, timestamps, sign in events, security logs, cookie choices and similar technical information.

Account and identity data

We collect your name, email address, sign in and verification information, account settings, language, time zone and optional business details.

Assessment, profile and planning data

Depending on what you choose to use, we may collect assessment answers, current work situation, goals, skills, experience, relationships, household or dependant responsibilities, available weekly capacity, constraints, risk tolerance, chosen business idea, customer problem, action plan, notes, progress and evidence you record.

The Exit Number and related tools may process income targets, expenses, savings, runway assumptions, tax assumptions, scenario values and outputs. You may be able to calculate without saving. We do not send sensitive calculator values to general analytics tools.

Purchases and billing

We collect order reference, products purchased, price, currency, tax, billing name and address, optional business name and tax number, payment status, invoice, subscription, cancellation, refund and dispute information. The payment provider handles card or bank details. BYE normally receives transaction identifiers and limited payment method information rather than a full card number.

Communications and support

We collect transactional message status, marketing permissions, subscription preferences, reminder choices, support messages, attachments, complaint details and records of how an issue was resolved. Email delivery systems may record delivery, bounce, complaint, open or link activity where enabled and lawful.

Workshops, programmes and community

We may collect registrations, attendance, preparation, submissions, feedback, chat contributions and, where clearly disclosed, audio or video recording information. Community features may display the profile name and content you choose to post to other members.

Personalisation and derived data

BYE may derive an assessment result, current stage, recommended next action, evidence gap, reminder timing and relevant product recommendation from your answers and activity. The reasoning should be understandable and editable.


3. Data we ask you not to provide

Do not provide employer trade secrets, confidential workplace files, manager or colleague contact details, client personal data, passwords, payment card numbers in notes, or special category data unless BYE specifically asks for it and explains why. Special category data includes health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetics, biometrics used for identification, sex life or sexual orientation.

If sensitive or third party data is provided unexpectedly, we may restrict, delete or redact it where appropriate.


4. Why we use personal data and our legal bases

We use personal data only where a lawful basis applies.

Contract and steps requested before a contract

We use this basis to create and secure your account, provide a requested assessment or product, save work, process an order, deliver access, administer a subscription or event, send essential service messages and resolve support issues connected to the service.

Legal obligation

We use this basis for tax, accounting, consumer rights, fraud reporting, legal requests and other records the law requires us to keep or disclose.

Legitimate interests

We may use limited data to secure the service, prevent abuse, investigate errors, defend legal claims, measure basic service performance, improve accessibility and understand whether BYE features lead to useful customer action. We consider the impact on you and do not use this basis where your rights and interests override ours.

Consent

We use consent for The Exit Note and other optional electronic marketing, non essential cookies or tracking, and any other processing presented as optional. You can withdraw consent at any time without affecting earlier lawful processing.


5. Essential and optional messages

Essential messages may cover secure sign in, account changes, payment, access, invoice, refund, subscription, registration, event changes and support acknowledgements. They are separate from promotional messages.

The Exit Note, educational sequences, progress prompts and product education are optional unless a specific message is strictly needed to provide a feature you requested. Unsubscribing from optional messages will not block essential account or purchase messages. Every marketing email will include a valid way to opt out.


6. Cookies and similar technologies

Essential cookies and local storage may be used for sign in, security, fraud prevention, checkout, accessibility, language, session continuity and recording your privacy choices. Where they are strictly necessary for a service you requested, consent may not be required.

BYE does not currently use non essential product analytics, advertising or session replay technologies. If any are introduced later, they will not be used before the required consent. Sensitive assessment or calculator values will not be recorded in general analytics. You will be able to reject non essential technologies as easily as accepting them and change your choice later.

The cookie controls will identify each live technology, provider, purpose and duration.


7. Automated personalisation and artificial intelligence

BYE uses rules to calculate assessment results and recommend a next action. BYE does not currently send personal data to a separate artificial intelligence provider. If this changes, we will update this Policy, apply data minimisation and use suitable provider terms before the feature is introduced. Do not enter confidential employer, client or third party information into any future artificial intelligence feature.

BYE does not use solely automated processing to make decisions that produce legal effects, or similarly significant effects, about you. A result does not determine employment, credit, insurance, tax, investment or legal eligibility. You may ask for an explanation or correction of a result.


8. Who receives personal data

We share personal data only where needed with providers supporting website hosting, database services, payment, billing, tax, invoicing and transactional email. They may act as processors under written terms or, for some payment and legal functions, as independent controllers.

Current providers: Vercel for website hosting and deployment, Neon for database hosting in Frankfurt, Stripe for payments, billing and tax, and Postmark for transactional email.

We may also disclose data to professional advisers, insurers, auditors, regulators, courts, law enforcement or a buyer or successor where reasonably necessary and lawful. We do not sell personal data.


9. International transfers

We aim to use European Economic Area processing where practical. Some providers or their support teams may process data outside the European Economic Area. Where required, we rely on an adequacy decision, approved Standard Contractual Clauses and appropriate supplementary safeguards. You may contact us for information about the relevant transfer safeguard.


10. How long we keep data

We keep personal data only for as long as needed for the purpose, legal obligations, security and the establishment, exercise or defence of legal claims. The following periods are the proposed operational schedule and must match the implemented deletion jobs before publication.

Temporary unfinished assessment data not saved to an account: up to 7 days.

Account, profile, plans and saved work: while the account is active, then normally deleted or anonymised within 30 days after a verified deletion request, subject to backup expiry and records that must be retained.

Backups: overwritten or deleted on the implemented backup cycle, proposed maximum 90 days, unless isolated for a security or legal reason.

Orders, invoices, payments, refunds and tax records: 6 years from the end of the relevant accounting period, or longer where a dispute, inquiry or law requires it.

Support cases and complaints: proposed 24 months after closure, unless linked to a transaction, dispute or legal claim requiring longer retention.

Security and access logs: proposed 12 months, with longer retention only for an active investigation.

Marketing consent and suppression records: for as long as messages are sent, then enough evidence to respect the opt out and address legal claims, proposed 6 years.

Workshop recordings: for the access period stated on the event page, then deleted or archived only where a separate lawful purpose applies.

Completed assessment results that were not saved to an account: up to 90 days from completion, then deleted or anonymised. This is separate from the seven day period above, which applies to unfinished work.

After a refund: assessment data, generated results and other account content that is no longer required are normally deleted or anonymised within seven days. Payment, refund, transaction, tax and accounting records are excluded from that period and are retained for as long as legal, tax or accounting obligations require.


11. Security

We use measures appropriate to the risk, including encrypted connections, protected storage, access controls, strong administrator authentication, audit records, verified payment and email events, restricted support views, signed download links, backups, monitoring and incident response. No online service can guarantee absolute security. Support staff see only what is needed to resolve an issue. Private financial inputs, assessment answers and notes are masked by default, and administrative access requires a reason and an audit record.


12. Your data protection rights

Depending on the circumstances, you may have the right to access, correct, erase or restrict personal data, receive portable data, object to processing, withdraw consent and complain to a supervisory authority. You may also object at any time to direct marketing.

Where account settings are available, they should allow correction, export, communication choices and deletion. You may also contact hello@buildyourexitnow.com. We may verify identity and normally respond within one month, subject to lawful extensions.

You may complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland, at dataprotection.ie, or to the supervisory authority where you live or work.


13. Children, links, changes and contact

BYE is for adults aged 18 or over and does not knowingly offer accounts or paid services to children. Contact us if you believe a child has provided personal data. Linked services control their own privacy practices, so please read their notices. We may update this Policy for legal, provider or product changes, publish the updated date and give appropriate notice of a material change. A new incompatible purpose will receive the information and consent required by law before use. Send privacy questions and rights requests to hello@buildyourexitnow.com or the controller address in section 1.


Questions about this policy can go to hello@buildyourexitnow.com.