Privacy policy
This policy explains what information Teuscan collects, what we do with it, who else receives it, and the choices you have.
Who we are
Teuscan is operated by Bruno Development EOOD, a company incorporated in Bulgaria and trading as Teuscan. Where this policy says “we”, “us” or “our”, it means that company.
Questions about this policy, and any request concerning your information, should be sent to oleksii@teuscan.com. That address reaches the founder directly.
What this policy covers
This policy covers the Teuscan website, the demonstration tool on it, and the Teuscan application programming interface.
When we analyse images for a customer under a pilot or a paid plan, the customer decides what is submitted and why; we handle that material on the customer’s instructions and under our agreement with it. This policy describes how we handle it in either case.
Information we collect
We do not operate accounts on this website, and we collect nothing beyond the following.
- Images you submit for analysis. A photograph of freight is not usually personal information, but it can contain it incidentally — a person in frame, a vehicle plate, a name on a shipping document.
- Technical information needed to serve a request: IP address, date and time, the page or endpoint requested, the response status, and the browser user-agent string.
- Measurement and session-replay data from the two analytics tools described under “Cookies and tracking”: pages viewed, referrer, country, device and browser type, and — for the replay tool — a reconstruction of your visit, including pointer movement, clicks and scrolling.
- Anything you put in an e-mail to us, together with your address and our reply.
- Business contact and billing details of customers, and records of the services we have supplied to them.
How we use it
We use the information above only for the following purposes.
- To run the analysis you asked for and return the result.
- To operate, secure and maintain the service — including rate limiting, preventing and investigating abuse, and diagnosing faults.
- To check and improve the accuracy of the analysis, by re-running submitted photographs against the service and comparing what it returns.
- To understand how the site is used, so that we can improve it — which pages people read, and where the interface confuses them.
- To answer correspondence and to manage our relationship with customers.
- To meet our accounting, tax and other legal obligations.
What happens to the photos you submit
This is the part most people are asking about, so it is stated in full.
An image you submit is received by our server, prepared for analysis, and passed to the service providers described in the next clause for the processing you asked for.
We keep a copy. The demonstration tool is still under development, and we retain the photograph exactly as you submitted it, on a server we control, so that we can reproduce a result that looks wrong and measure whether a change to the analysis improves it. Stored with it are the result, the date, and technical details of the request. Not stored with it are your name, your e-mail address, your IP address or any account: a retained image is not linked to an identity, and we have no way to work back from an image to the person who submitted it.
We do not use submitted images to train or fine-tune any model, we do not disclose them to anyone beyond the service providers listed below, and they are not published. Our application logging excludes image data separately, so a photograph cannot end up in a server log.
Because an image can contain personal information incidentally, please do not submit photographs containing personal or confidential material that you are not free to share with a third-party service provider.
Who else receives information
We use as few service providers as the product allows. They act for us, on our instructions, and may use what they receive only to provide their service to us.
- The technology providers that carry out the image processing behind the service. This is the only category of recipient that receives a submitted image, and it is inherent in how the service works.
- Our hosting provider, which handles the technical information described above in the course of serving the site.
- Our two analytics providers. The measurement one receives page-view data through our own domain. The session-replay one is a large technology company whose script runs in your browser and sends what it records directly to it; it is the one recipient in this list that also uses what it receives for its own purposes, under its own terms. Neither receives a submitted image.
- Our e-mail provider, for correspondence.
- Our accountants, and government authorities where the law requires disclosure.
If you need the current providers named in writing for a vendor review, ask us and we will send them.
We do not sell or share your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We have never done so.
The providers listed above act for us and are permitted to use what they receive only to supply their service, with the single exception noted there — the session-replay provider, which also uses the data it collects for its own purposes under its own terms. If you would rather it did not, blocking its script stops it, and the rest of the site works normally without it.
Cookies and tracking
This website runs two analytics tools, and they are not equivalent.
- A privacy-focused measurement tool, served from our own domain. It sets no cookies, stores nothing on your device, and does not identify or follow you between visits. It counts page views, referrers, countries and device types.
- A session-replay and heatmap tool from a large technology company, loaded from that company’s own domain. It sets cookies, and it records a reconstruction of your visit — pointer movement, clicks, scrolling and the pages you moved between — which we watch to find where the interface confuses people. It masks text input by default.
We run no advertising or conversion pixels, no tag manager, and no fingerprinting, and we do not sell what these tools collect.
Neither tool receives an image you submit for analysis, and neither runs anywhere but the public site: on a development or preview build both are switched off entirely.
The site does not currently respond to Do Not Track or Global Privacy Control signals. Blocking the session-replay script — most content blockers do so by default — stops the recording, and the site works normally without it.
How long we keep things
- Images submitted for analysis: kept while the demonstration tool is under development, and deleted when they are no longer useful for the testing described above. The store is capped in size and is not linked to any identity. We will delete a specific image on request if you can give us enough detail to find it.
- Analytics and session-replay data: the retention period configured at each provider. For the session-replay tool that is a matter of months, set by the provider rather than by us.
- Rate-limiting counters: the length of one limit window, then discarded.
- Server logs: the period configured at our hosting provider, measured in weeks.
- Correspondence: for the conversation and any relationship that follows it, and afterwards only where a legal retention period applies.
- Accounting and tax records: for the periods the law requires.
Security
We apply measures appropriate to the sensitivity of what we handle. Traffic to the site and the interface is encrypted in transit. Retained images are held on a server we control, not in public storage, and are reachable only by the people who operate the service. Analysis credentials are held on the server and are never exposed to the browser. Uploads are size- and type-checked, and the demonstration endpoint is rate limited. Logs redact image data and credentials.
No system can be guaranteed secure. If you find a vulnerability, please report it to the address in clause 1 and we will address it.
Your choices and your rights
You can ask us what personal information we hold about you, ask us to correct it, ask us to delete it, or object to our use of it. Write to the address in clause 1. We will respond within forty-five days, and we will not treat you any differently for having asked.
We will ask for enough information to satisfy ourselves that the request comes from you, or from someone you have authorised to act for you, before we act on it.
For a visitor who has used the demonstration tool, note that an image is not associated with you or with any account, so we will need enough detail to identify the submission before we can act on a request about it.
If you are in the European Economic Area or the United Kingdom
The General Data Protection Regulation gives you rights of access, correction, deletion, restriction, portability and objection, and a right to withdraw any consent you have given without affecting processing carried out beforehand. Requests go to the address in clause 1.
We rely on the following legal bases: our legitimate interest in providing the demonstration you asked for, in keeping the service secure and available, and in answering correspondence; the performance of our contract with customers on a pilot or a paid plan; your consent where you volunteer information we did not need; and compliance with legal obligations for accounting and tax records.
Some of the service providers described in clause 6 are established in the United States, so an image you submit is transferred outside the EEA and the UK for the time it takes to process it. Where information is transferred out of those areas, we rely on a transfer mechanism permitted by applicable data protection law; details of the mechanism applying to a given transfer are available on request.
You may also complain to a supervisory authority — in the country where you live or work, or where you consider the problem arose. The authority for the country in which we are established is the Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria, kzld@cpdp.bg, www.cpdp.bg.
We have not appointed a data protection officer; our processing does not meet the conditions that would require one. Enquiries go to the address in clause 1.
Automated analysis
The service analyses images automatically and reports what is visible in them. That analysis is about goods, not about you: we make no automated decisions about individuals, and we do not profile visitors or customers.
Children
The service is sold to businesses and is not directed at children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy. The version and date of the current text are shown at the top of this page. If a change materially affects how we handle a customer’s information, we will tell that customer by e-mail in advance rather than leaving the change to be discovered here.
