Aller au contenu

Privacy and data protection

How Ystara handles data — beginning with the part that matters most: the cameras count people, and never keep a picture of them.

Last updated 2026-08-18. Written in plain language on purpose — if any part of it is unclear, that is a defect, and contact@ystara.com will answer it.

01The cameras do not photograph you

Ystara measures how busy a beach is using its own camera units installed on the coast. Each unit takes an image, counts the people it can see, and discards the image immediately — the counting happens on the device itself. No photograph or video is stored, transmitted, or retrievable, by us or by anyone else. What leaves the beach is a number, a timestamp and some information about the unit's own health.

There is no face recognition, no identification, no tracking of individuals between visits or between beaches, and no attempt to distinguish one person from another. The system cannot tell you whether a particular person was at a particular beach, because it never held the information required to answer that question.

The result is that the measurement data this platform publishes and sells contains no personal data. Analyses built on it inherit that property.

02Who is responsible

The controller for the personal data described below is Youlytics, operating as Ystara, Karreweg 63C, 9770 Kruisem, Belgium. Enterprise number BE 1025.901.593. Questions, requests and complaints: contact@ystara.com.

Ystara has not appointed a Data Protection Officer. The tests in Article 37 GDPR turn on large-scale monitoring or large-scale processing of personal data, and — for the reason in section 1 — the measurement activity processes none. Should that change, this notice changes with it.

03If you only look at the map

Visiting ystara.com to see how busy a beach is requires no account and creates no record of you. Specifically:

No cookies

An anonymous visitor is set no cookie of any kind. A cookie appears only after you sign in — to an operator account or to a visitor account you created yourself — and it exists solely to keep you signed in. It holds a random value, not your identity; signing out revokes it on our side as well as removing it from your browser.

No analytics, no trackers

There is no Google Analytics, no tag manager, no advertising pixel, no session recorder, no third-party script of any kind. Fonts and map tiles are served from our own server rather than a CDN, so no third party learns that you visited.

One preference, stored on your device

Your chosen language, colour theme and last-viewed country are kept in your browser's local storage so the site remembers them. That data never reaches our server, and clearing your browser data removes it.

Server logs

Requests are logged with the method, path, status and a request identifier for debugging. IP addresses are not written to these logs.

Because nothing here is used for tracking or advertising, there is no consent banner to click. A preference you set yourself does not require your permission to be remembered.

04Personal data the platform does hold

Ystara is also an operations platform for the people who run the camera network, a place where members of the public can tell us a camera is wrong, and a data service for organisations that licence the measurements. Those uses involve ordinary account data:

Operator and administrator accounts

Name, email address, a hashed password (never the password itself), the role and countries assigned to the account, sign-in times, and an audit record of administrative actions taken. Legal basis: performance of a contract, and our legitimate interest in an accountable operations trail. The account data is kept for as long as the account exists; the record of an individual sign-in for 30 days after it ends; the audit record for 2 years, which is long enough to outlive the staff turnover and the contract term it exists to evidence, and short enough to be a bounded record rather than a permanent one.

Visitor accounts

Anyone may create an account, and it exists for exactly one purpose: submitting beach reports. We store the name you give, your email address, a hashed password, and the times you signed in. A visitor account belongs to no organisation, holds no role and carries no permission of any kind — it cannot see device health, telemetry, configuration or anyone else's data, and there is no setting that would let it. Legal basis: consent. You can change your password and delete the whole account yourself, at any time, from your account page.

Confirming your email address

When you sign up, or ask for a new confirmation or password-reset link, we store a one-time record holding a keyed hash of that link (never the link itself), the account it belongs to, an expiry, and the IP address the request came from. The IP is kept to stop the endpoint being used to send unwanted mail to somebody else's address. These records are short-lived by design — a confirmation link lasts a day, a reset link an hour — and are deleted within a week of expiring or being used, immediately if you delete your account. Legal basis: our legitimate interest in verifying that an address belongs to the person using it, and in not being turned into a mail relay.

Beach reports from signed-in visitors

If you are signed in and tell us how busy a beach actually looked, we store your account identifier, your rating, any note you write, the language you wrote in, and what the platform was publishing at that moment. This is how camera accuracy is checked; the beach page shows your first name only, never your full name or your address. Legal basis: consent.

“Tell me when my country is covered”

If you ask to be notified about a country we do not yet cover, we store the email address you gave, the country, the language you were reading in, and anything optional you added about your organisation or role. Legal basis: consent. It is used for exactly one thing: a single message, in that language, telling you that a beach on your coast is now measured and linking to it. There is no newsletter, nothing else is ever sent to that address, and it is not shared, exported or combined with anything. Once the message has gone out the record has served its purpose and is deleted; until then it is kept so that the promise can be kept, and so that nobody is written to twice. You can ask us to delete it at any point before that, and we will.

Data-service customers

A contact address per API key, and per-day counts of requests made. The counts are the basis of the invoice; the address is how a lost key is recovered. Legal basis: performance of a contract. The counts are kept for 13 months, so any month in a licence year can still be checked against our own record rather than only against yours.

Those periods are enforced by the platform itself — a scheduled job deletes what has aged out, every day — rather than left to somebody remembering. Two things are kept without a time limit, and both on purpose: your account, for as long as you keep it, and the beach measurements, which contain no personal data at all. A count of people on sand is not a record about any of them.

05Who else sees it

Nobody, in the ordinary case. Ystara does not sell, rent or share personal data, and runs no advertising. The platform is hosted on servers in the European Union (Hetzner, Falkenstein, Germany), and the only outbound request it makes is to Open-Meteo for beach weather — which receives a set of coordinates and nothing about you.

When email is enabled, an email delivery provider necessarily handles the messages we send you; it is used for delivery only. If a court or supervisory authority compels disclosure we will comply, and will tell you unless we are forbidden to.

06Your rights

If you have a visitor account, the two you are most likely to want are built into the product rather than reserved for an email exchange: you can change your password and delete your account outright from your account page, without asking anyone. Deletion is immediate and is not a request we review.

Deleting your account removes your name, your email address, your password, every note you wrote, and every session and pending link belonging to you. It does not delete the measurements your reports produced — the record that a person saw one crowd level while a camera published another, and when. Those rows are separated from you permanently: the link to your account is severed, your notes are erased, and what remains identifies nobody. We keep them because they are facts about a piece of hardware rather than about you, and because the camera-accuracy figures we publish are built from them; letting one deletion silently move a number the public is invited to check would make that number worthless. If you disagree with that reasoning, write to us — and the supervisory authorities named at the end of this section are open to you regardless of what we say.

More generally, you may ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing based on legitimate interest, and ask for your data in a portable form. Write to contact@ystara.com and we will answer within one month.

Requests are free. We will ask enough to be sure it is your data you are asking about, and nothing more.

If you are unhappy with how we handle it, you may complain to a supervisory authority: Gegevensbeschermingsautoriteit / Autorité de protection des données — gegevensbeschermingsautoriteit.be (Belgium); Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) — cndp.ma (Morocco).

07Security, and what happens if we get it wrong

Passwords are stored using scrypt with a per-password salt. Session tokens, device credentials and API keys are stored only as keyed hashes, so a stolen copy of the database yields no working credential. Traffic is encrypted in transit. Access to the production system is limited to the people who operate it, and administrative actions are recorded.

The platform is reviewed for security, and findings are fixed rather than filed. If a breach ever affects personal data, we will notify the supervisory authority within 72 hours as Article 33 requires, and tell affected people directly where Article 34 applies.

08Installations and local law

Camera units are installed in public space with the agreement of the authority responsible for that beach, and are declared to the relevant regulator before they operate — in Morocco, the CNDP; in Belgium and the wider EU, under the GDPR framework with the operating commune. Because the units keep no imagery, these filings describe a counting sensor rather than a surveillance camera, and we are careful never to describe them as anything else.

Read how the counting works for the technical detail behind these claims.

Related: Privacy · Terms · Legal notice · How the counting works

Supervisory authorities: Gegevensbeschermingsautoriteit / Autorité de protection des données (Belgium) · Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) (Morocco)