Privacy
Who is responsible
Alessandro Raffa, an Italian sole trader trading as Telyvar, VAT number IT07270350825, is the data controller for everything described here. Reachable at hello@telyvar.com, which is also where you exercise any of the rights below.
No cookies, no analytics, no forms
Not as a policy statement — as a property of the pages, and one you can verify without trusting this paragraph. Open your browser's network tab and reload. What a web server unavoidably records in order to answer at all is described further down, because a page that claimed to collect nothing would be contradicting itself two paragraphs later.
- No cookies, and nothing in local or session storage.
- No analytics of any kind. There is no measurement of who visits, how often, or what they read.
- Nothing is loaded from anyone else. The typeface is served from this domain rather than from a font CDN, specifically so that loading a page tells nobody else that you did. Every asset a page needs comes from this domain.
- No JavaScript written by us. The pages are built without any, and the build refuses to publish a page carrying a
scriptelement that is not a block of structured data — text a search engine reads, not code that runs. That is checked on every build rather than asserted here.
Two things reach you from the network in front of this site, and they are named because the paragraph above invites you to look and you would find them. The CDN may rewrite email addresses into a small script served from this domain, which reassembles the address in your browser so that automated harvesters do not read it; it watches nothing and reports nowhere. And the responses carry Cloudflare's network error logging, which asks your browser to report to a Cloudflare address if a request fails — never on a request that succeeds. - No forms. There is nothing here to submit, so there is nothing here to collect.
What remains is what any web server records in order to answer a request at all: your IP address, the page asked for, the time, and the user agent your browser sends. This site is served by Cloudflare Pages, so those logs are Cloudflare's, kept undertheir retention policy and used for security and operations. We do not download them, and they are not combined with anything else, because there is nothing else to combine them with.
If you write to us
We process what you put in the message and your address, in order to answer — that is the whole basis and the whole purpose. Correspondence is kept while the matter is open and for as long afterwards as an accounting or legal obligation requires, and is not used to contact you about anything you did not ask about.
What a capability does with what you send it
A capability runs on the infrastructure of the marketplace that sells it — today that isApify Store — inside a run that belongs to your account there. When you call one, this is exactly what happens to your input, and it is the whole of it:
- It is processed in memory to produce a result.
- One result row per item is written to your run's own dataset, and a short report of counts — delivered, succeeded, failed, not attempted — to your run's own key-value store. Both belong to your run, on your account, under the marketplace's retention rules.
- Nothing else is written anywhere. The code holds no database, sends nothing to any third party, and does not log your input — not to a file, not to a console, not to us. There is no copy of what you sent on any machine of ours, because there is no machine of ours in the path.
We can see what the marketplace shows a publisher: how many runs happened, how much they cost and what they earned. That is counting, not content.
If what you send contains personal data
These capabilities take arbitrary strings, so they can be handed personal data — a URL with a name in it, an encoded record. If you do that, you are the controller and the processing above is carried out on your instructions: for the length of one run, without retention beyond your own run's storage, and with no other purpose.
Two practical consequences, said plainly rather than left to be inferred.
Not for the sensitive categories. Nothing here is designed for what Article 9 of the GDPR calls special categories — health, sex life or orientation, political opinions, religion, trade union membership, biometrics, ethnic origin — and none of these capabilities should be handed any of it.
Where the written agreement has to come from. The retention, access controls and location of the run's storage are the marketplace's rather than ours, so the agreement covering the storage of what you send is theirs. What our code does inside your run is described above and is the whole of it. If you need that in a signed document rather than on a page, write to us and say so: we would rather put it in writing than have you infer it from this paragraph.
Your rights
Under the GDPR you may ask for access to your data, its correction or erasure, a restriction on how it is processed, a copy in a portable form, and you may object to processing based on legitimate interests. Write to the address above; there is deliberately no form.
In practice the honest answer to most such requests will be that we hold nothing about you, because nothing here collects anything. If you believe otherwise you may complain to the Italian supervisory authority, the Garante per la protezione dei dati personali, or to the authority where you live.
Changes to this notice
It changes when the code changes, because it is generated from the same repository as the code it describes: a claim here that stopped being true is a line somebody had to edit. Last changed on 2026-09-18.