BYSER PRIVACY AND COOKIE NOTICE
Last updated: 6 August 2026
1. Who We Are
Byser is a pre-launch dataset catalogue operated by Elisabetta Piticco, based in Florence, Italy.
For the personal data described in this Notice, Elisabetta Piticco is the data controller.
- Privacy enquiries: privacy@byser.ai
- General enquiries: contact@byser.ai
- Legal notices: legal@byser.ai
Byser does not currently provide public user registration, public contributor accounts, online checkout, automatic dataset purchases, payment processing, or automatic delivery of paid datasets.
2. Scope of This Notice
This Notice explains how personal data is processed when you:
- visit byser.ai;
- view dataset listings, documentation, or public samples;
- submit or send a dataset enquiry;
- communicate with Byser by email;
- interact with website security features; or
- access a restricted internal administrative area, if you are specifically authorised to do so.
Any future paid dataset transaction, contributor programme, public account system, upload flow, payment service, or custom data collection will be governed by additional or updated terms and privacy information before that activity begins.
3. Personal Data We Collect
3.1 Information You Provide
When you request information about a dataset or contact Byser, we may collect:
- your name;
- professional email address;
- company or organisation;
- professional role;
- dataset of interest;
- intended use case;
- estimated volume, timeline, or indicative budget;
- the content of your enquiry and subsequent communications; and
- any other information you choose to provide.
Do not submit passwords, payment card details, government identifiers, health information, biometric information, confidential third-party information, or other sensitive personal data through a general enquiry form.
3.2 Technical and Security Data
When you access the website, Byser and its infrastructure or security providers may process:
- IP address;
- date and time of access;
- requested page or URL;
- browser, device, and operating-system information;
- referring page;
- request and session identifiers;
- server, application, error, performance, and security logs; and
- signals used to detect automated requests, abuse, fraud, or security threats.
Byser does not use this information for targeted advertising or behavioural profiling.
3.3 Internal Administrative Access
The website has a restricted internal administrative area that is not intended for public registration or public use.
For authorised internal users, Byser may process:
- administrative account email;
- authentication and one-time-password events;
- session and refresh tokens;
- account role and access permissions;
- access timestamps;
- IP address, device, and browser information; and
- administrative actions and security logs.
Public visitors cannot create an administrative account through the website.
4. Purposes and Legal Bases
4.1 Dataset Enquiries and Pre-Contractual Discussions
Byser uses contact and enquiry information to respond to requests, understand business requirements, identify potentially suitable datasets, provide samples or indicative quotations, arrange discussions, and take steps requested before a possible contract.
The legal basis is taking steps at your request before entering into a possible contract.
4.2 Website Operation and Security
Byser uses technical and security data to deliver the website, maintain availability and performance, prevent abuse and unauthorised access, protect forms and internal systems, investigate errors or incidents, and maintain proportionate security records.
The legal basis is Byser's legitimate interest in operating a reliable and secure website and protecting its systems, business information, and visitors.
4.3 Internal Administration
Byser uses authentication and administrative-access data to verify authorised users, manage permissions, protect restricted functions, and investigate unauthorised access.
The legal basis is Byser's legitimate interest in securely administering its website and related systems.
4.4 Legal Compliance and Claims
Byser may process relevant information to comply with legal obligations, respond to lawful requests, preserve evidence, and establish, exercise, or defend legal claims.
The legal basis is compliance with legal obligations and, where applicable, Byser's legitimate interest in protecting its legal rights.
4.5 Marketing
Byser does not currently add enquiry contacts to automated newsletters or unrelated marketing lists.
Byser may send reasonable follow-up communications about the same enquiry. A future newsletter or broader marketing programme will use a separate lawful basis and any consent required by applicable law.
5. Information You Must Provide
Providing enquiry information is voluntary. Byser may be unable to respond effectively without a valid contact address and enough information to understand the request.
Submitting an enquiry does not create an account, purchase contract, reservation, or dataset licence.
6. Service Providers and Recipients
Byser uses service providers to operate and protect the website. Current categories and providers may include:
- Vercel for website hosting and delivery;
- Supabase for database services and restricted internal authentication;
- Cloudflare for domain, network, and security services where enabled;
- business communications providers;
- professional technical, security, accounting, or legal advisers where reasonably necessary; and
- courts, regulators, or public authorities where disclosure is legally required.
Providers may act as processors on Byser's instructions or, for limited activities, as independent controllers under their own privacy notices.
Byser does not sell personal data and does not share personal data for cross-context behavioural advertising.
7. International Transfers
Some providers or their subprocessors may process personal data outside the European Economic Area, including in the United States.
Where required, Byser relies on recognised transfer mechanisms such as an adequacy decision, European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, or another lawful safeguard.
You may contact privacy@byser.ai for further information about safeguards relevant to your data.
8. Retention
Byser uses the following retention criteria and target periods. Automated deletion is not currently enabled for all categories of data:
- enquiries that do not lead to an active commercial discussion: a target review and deletion date of 12 months after the last meaningful communication is recorded;
- active commercial discussions: for the duration of the discussion and up to 24 months after it ends;
- communications needed for legal claims: for the applicable limitation period or while a claim remains active;
- internal administrative account data: while access remains authorised and for up to 12 months after access is removed, unless longer retention is necessary for security or legal claims;
- application, security, access, and infrastructure logs: retained according to the configured retention periods of the relevant provider or system; Byser does not currently operate a separate 90-day application log archive;
- records connected to a security incident: for as long as reasonably necessary to investigate, remediate, and document the incident; and
- information required by law: for the applicable statutory period.
Infrastructure providers may maintain limited backup or platform logs under their configured retention schedules. Data retained solely in protected backups is not used for ordinary business purposes and is deleted or overwritten through the normal backup lifecycle.
9. Cookies and Similar Technologies
9.1 Public Website
At the date of this Notice, the public website does not intentionally use advertising cookies, marketing pixels, behavioural profiling, session-replay tools, or non-essential analytics cookies.
Byser therefore does not currently display an "Accept all cookies" banner. This statement must be reviewed whenever the website's scripts, integrations, or hosting configuration change.
9.2 Strictly Necessary Technologies
Strictly necessary technologies may be used for:
- website delivery and security;
- prevention of spam, abuse, or automated requests;
- protection of enquiry forms;
- restricted internal authentication;
- maintenance of secure administrative sessions; and
- detection and investigation of security incidents.
These technologies are used only where necessary to provide a requested function or protect the website.
9.3 Internal Authentication Cookies
Authorised internal administrators may receive first-party authentication or session cookies when using the restricted administrative login. These cookies may contain or reference access tokens, refresh tokens, session identifiers, or information required to maintain and verify an authenticated session.
They are necessary for internal authentication and are not used for advertising or behavioural tracking. Their duration is controlled by the configured authentication session and may continue until expiry, logout, revocation, or deletion through browser controls.
9.4 Cloudflare Turnstile
Where Cloudflare Turnstile is enabled on a form, Cloudflare may process browser, device, network, and interaction signals to determine whether a request appears to come from a person rather than an automated system.
If Turnstile pre-clearance is enabled, Cloudflare may set a strictly necessary cf_clearance cookie. Byser does not use Turnstile for advertising or retargeting.
9.5 Browser Controls
You can delete or block cookies through your browser settings. Blocking strictly necessary authentication or security technologies may prevent authorised internal login or a protected form from operating correctly.
9.6 Future Changes
Before introducing non-essential analytics, advertising, profiling, or session-replay technologies, Byser will update this Notice, block those technologies until any required consent is obtained, and provide suitable accept, reject, and preference controls.
10. Security
Byser uses reasonable technical and organisational measures designed to protect personal data, including HTTPS, restricted internal authentication, role-based access, database and storage controls, security logging, authentication rate limits, automated-abuse protection, and access-revocation procedures where appropriate.
No internet service or storage system can be guaranteed to be completely secure. Do not transmit sensitive or confidential information through a general enquiry form.
11. Automated Decision-Making
Byser does not currently use personal data collected through the public website to make decisions based solely on automated processing that produce legal or similarly significant effects.
Automated security systems may identify or block suspected spam, bots, abuse, or unauthorised access. These controls do not determine eligibility to purchase a dataset.
12. Children
The website is directed to business and professional users and is not intended for children. Do not submit an enquiry if you are under 18.
If Byser becomes aware that a child has submitted personal data, it will take reasonable steps to delete it.
13. Your Rights
Depending on applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive data in a portable format where the legal conditions apply;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data-protection authority.
To exercise a right, contact privacy@byser.ai. Byser may request information reasonably necessary to confirm your identity and locate the relevant data.
If you are in Italy, you may lodge a complaint with the Garante per la protezione dei dati personali.
14. External Websites
The website may link to external websites or services. Their privacy practices are governed by their own notices, and Byser is not responsible for websites it does not control.
15. Changes to This Notice
Byser may update this Notice when the website, service providers, or legal requirements change. The updated version will be posted with a revised "Last updated" date.
16. Contact
- Data controller: Elisabetta Piticco
- Location: Florence, Italy
- Privacy: privacy@byser.ai
- General enquiries: contact@byser.ai
- Legal notices: legal@byser.ai