Legal

Website Privacy Policy

Last Updated: 17 September 2026

This Privacy Policy explains how TastyBytes Oy ("we", "us", "our") collects and processes personal data when you visit and interact with the bonapp.recipes website ("Site"). We comply with the General Data Protection Regulation (GDPR), the Finnish Data Protection Act, and the EU Digital Services Act (DSA).


1. Data Controller

TastyBytes Oy
Tyyneläntie 19
03100 Nummela
Finland
Business ID: 3472941-4
Email: [email protected]

2. Information Collected on the Website

2.1 Server Log Data

When you request pages on the Site, our web servers and edge networks automatically log basic technical metrics: your IP address, browser type, operating system, HTTP status code, and referring page URL. This data is used solely for system security, DDoS defense, and infrastructure performance monitoring.

2.2 Local Storage & Essential Browser Cookies

We use essential browser local storage and cookies to record your preferences (such as dark mode settings, metric vs. imperial measurements) and maintain technical session states.

2.3 Web Analytics

We process aggregated, privacy-focused website analytics to understand page popularity, search query trends, and site load performance.

3. Legal Basis for Processing

  • Legitimate Interest: Ensuring network security, DDoS mitigation, optimizing web performance, and improving content indexing efficiency.
  • Legal Obligation: Complying with applicable statutory laws, regulatory obligations, content moderation requests under the EU Digital Services Act (DSA), and fulfilling data subject rights requests under GDPR.
  • Consent: Storing non-essential browser cookies or processing analytics where explicit user consent is requested and provided.

4. Data Sharing, Infrastructure & Media Hosting

We utilize trusted third-party infrastructure providers to serve web content, optimize asset delivery, and ensure site security under strict Data Processing Agreements (DPAs):

  • Cloudflare Inc. — Edge CDN distribution, SSL encryption, security routing, rate limiting, and DDoS protection.
  • Vercel Inc. — Next.js web application hosting, static asset delivery, and serverless execution.

4.1 Image & Media Asset Handling

Recipe photographs and media assets displayed on the Site are served via external Content Delivery Networks (CDNs) or referenced via remote URL links. We do not host, store, or process raw user image files or EXIF metadata directly on our origin web application servers.

5. International Data Transfers

Where infrastructure providers process web requests outside the EU/EEA, data transfers are protected under EU Standard Contractual Clauses (SCCs) or applicable adequacy decisions.

6. Your GDPR Rights

Under GDPR you have full rights regarding your personal data:

  • Right of access and data portability
  • Right to rectification or erasure ("right to be forgotten")
  • Right to restrict or object to data processing
  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority

To exercise any of these rights, contact us at: [email protected]

As a company established in Finland, our lead supervisory authority under GDPR is the Office of the Data Protection Ombudsman (tietosuoja.fi). EU/EEA users may also contact their local data protection authority.

7. Terms of Service

Your use of the Site is also subject to our Terms of Service.

8. Contact Us

For privacy questions or data subject requests related to the website:
[email protected]