Acyfer VisionLimited Availability preview
Draft only - legal review required

Privacy Notice

Version ACYFER-VISION-PRIVACY-LA0-2026-08-19 - last updated 19 August 2026.

1. Who we are and our roles

Acyfer Vision is operated by Acyfer di Davide Zagami, with VAT IT05836690874; registered office, jurisdiction, and legal-notice email still to be inserted. Acyfer is controller for account, contract, security, support, and service-administration data. For personal data in customer media, annotations, job results, and configured workflows, the customer is normally controller and Acyfer acts as processor under the applicable DPA.

2. Data we process

  • Account, authentication, organization, workspace, role, invitation, and API-key metadata.
  • Uploaded vehicle images and videos, validation metadata, job inputs, model selections, structured detections, masks or polygons, confidence, tracking identifiers, rendered artifacts, review changes, and exports.
  • Usage, audit, security, IP, device/browser, cookie, queue, runtime, error, monitoring, and support records.
  • Contract, billing, transactional-email, and request-management data where applicable.

3. Purposes and legal bases

Account and operational data is processed to provide and administer the requested service, perform contracts, secure the platform, prevent abuse, comply with legal obligations, and communicate about support. Customer media and results are processed on documented customer instructions. Customer media is not used to train a general or customer-specific model unless a separate written agreement identifies the purpose, data, model, retention, and effective date.

4. Providers and transfers

The final subprocessor register must identify production hosting, object storage, authentication, email, monitoring, support, and any optional inference provider before LA becomes effective. Provider locations and transfer safeguards remain placeholders in this draft. No provider-backed pilot or external model inference is included in the base scope unless separately opted into.

5. Security

Access is intended to be tenant-scoped and role-based, and public traffic is intended to use TLS. Exact encryption-at-rest, key-management, backup, recovery, monitoring, and incident-response statements must match the verified production design and the final DPA before this notice becomes effective. This draft does not represent that an unverified control is operational.

6. Retention and deletion

The proposed default customer-media and result retention is 30 days unless a narrower enrollment specifies otherwise. Automated deadline stamping, deletion sweeping, backup expiry, artifact cleanup, retry behavior, and a production deletion drill remain promotion gates. Until those controls are verified, the final notice and customer schedule must not claim that a specific deletion period is automatically enforced. Account deletion, workspace termination, active-data removal, recovery periods, and backup expiry must be stated separately.

7. Sharing

Data may be disclosed to authorized customer users, contracted subprocessors needed for the Service, professional advisers, or authorities when legally required. Acyfer does not sell customer media or use it for advertising. Customer administrators control access within their organization subject to platform roles and tenant isolation.

8. Rights and requests

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection and may complain to a supervisory authority. For content in a customer workspace, contact that organization first because it normally controls the data. Acyfer will assist the customer as required by the DPA.

9. Cookies, children, changes, and contact

The Service uses authentication/session and security cookies needed to operate the platform, not advertising cookies. It is intended for business users and is not directed to children. Material changes will be versioned and communicated before they apply. Contact support@acyfer.com for privacy requests until a final privacy address is published, and security@acyfer.com for security incidents. Do not send customer media, passwords, API keys, or sensitive results by email.