Legal & privacy

Privacy Notice

How BXST.com’s current early-access service handles personal information, essential authentication cookies and privacy requests.

Last updated: 17 September 2026

On this page

1. Who this notice covers

This notice explains personal-data handling by BXST.com — early-access website operator (“we”, “us”) when you visit the website, create an account, use a business workspace or contact us. It describes the current service; an early-access label does not remove rights under applicable data-protection law.

BXST.com is the website name. The operator’s legal name and service address have not yet been published, so this notice is not presented as a complete controller-identification notice until those details are added.

For privacy questions and requests, contact info@bxst.com. If Turkish personal-data law applies, also read our Türkiye KVKK Notice. Our Terms of Use describe the service.

For account administration, website operation, security and correspondence, the operator determines the purposes of processing. For personal data an organization puts in its workspace for its own business purposes, that organization may be the controller and we may process on its behalf. The role depends on the activity and applicable arrangement. Contact the relevant organization as well as us if your request concerns its records.

2. Information we handle

  • Account information: your name, email address, password hash, email-verification state, account dates, organization memberships and role. Passwords are processed to authenticate you; the database stores a password hash rather than the readable password.
  • Workspace information: company name, website, country/city, industry, employee range, target markets, objectives and information supplied through available business tools. RFQs, answers, notes and assignments can contain personal information about you or other people.
  • Authentication and security information: session identifiers, authentication-link hashes, creation/expiry/use times, IP address, browser or device User-Agent, and records of relevant workspace actions. Rate-limit identifiers are hashed, but session records can include the full IP address.
  • Website and hosting information: requests, technical connection information and operational or security logs handled by our hosting provider. Searches and filters included in a page URL can also appear in request records.
  • Correspondence and transactional email: your name, email address, optional company, selected topic and message when you use the contact form; other information you send us; and verification or password-recovery messages and associated delivery information handled by the email provider.

3. Where information comes from

Most account and workspace information comes directly from you or from an authorized person in your organization. Authentication and technical information arises when you interact with the service. Business records entered by an organization may include details about its contacts or other organizations.

Required signup fields are needed to create and protect an account. If you do not provide them, registration cannot be completed. Optional company fields can be left blank where the interface allows it. Please avoid adding unnecessary personal information about other people.

Do not submit sensitive personal information, identity-document copies or payment-card details. The current service is not designed to collect those categories. Catalog uploads, live external data integrations and team invitation acceptance are currently unavailable; demonstrations of those features are not evidence that live data has been imported.

4. Why information is used

We use information to create and administer accounts, verify email addresses, authenticate users, recover access, save and display workspace information, apply access permissions, respond to requests and protect the service from misuse. Relevant action records help investigate problems and support accountability.

Where the GDPR applies, processing necessary to provide a service you request may rely on steps before a contract or performance of that contract. Where you act as an employee or representative of a business, account administration and business communications may instead rely on legitimate interests in operating that relationship. Security, abuse prevention and defending legal claims may rely on legitimate interests, subject to the required balancing of your rights. Processing required by law relies on the relevant legal obligation.

Where a processing activity requires consent, it must be requested separately and for that activity. Reading this notice or creating an account is not blanket consent to unrelated processing, marketing, or every international transfer. You can withdraw consent where consent is the applicable basis, without affecting earlier lawful processing.

5. Cookies and similar storage

The application uses the bxst_session cookie to keep you signed in. It contains a random session token, is restricted from ordinary browser scripts, and is sent over secure connections in production. It is a browser-session cookie with no persistent expiry set by the application. Browsers normally clear it when the browser session ends, although browser session-restoration features can preserve it. The server limits a session to 30 days even if the browser restores it. Signing out removes the current session cookie and revokes that session; resetting a password revokes the account’s existing sessions.

This is an authentication cookie needed for the account functions you request. Blocking or deleting it prevents the service from keeping you signed in. The current application does not install advertising trackers or marketing-analytics cookies. Hosting providers may process technical request information for delivery and security.

If optional tracking is introduced, this notice and the relevant controls must be updated before that processing begins, including consent where required. The current website does not use a cookie choice as consent to its essential account processing.

6. Who may receive information

  • Authorized workspace members can access information permitted by their roles. Consider your organization’s own privacy and confidentiality rules when adding information.
  • Vercel provides website hosting and application delivery. Neon provides the managed PostgreSQL database. Resend delivers account verification, password-recovery and contact-form messages, receiving their addresses and content, including authentication links where relevant. See Vercel’s privacy notice, Neon’s current terms and Resend’s privacy policy for their own activities.
  • Cloudflare Email Routing forwards messages addressed to info@bxst.com to the operator’s Google Gmail inbox. Cloudflare and Google process the sender’s address, message and delivery information for this correspondence. See Cloudflare’s privacy policy and Google’s privacy policy.
  • Infrastructure and communication providers may use additional service providers. The applicable provider documentation describes those subprocessors. Listing a provider here does not mean every product offered by that provider is used by BXST.com.
  • We may disclose relevant information when required by law or reasonably necessary to establish, exercise or defend legal claims, investigate misuse or protect rights and safety, subject to applicable legal requirements.

7. Public profiles and document records

An authorized owner or administrator can opt to publish an organization’s supplier profile. Published profiles can expose company details, selected published products, certifications and facility information to anyone, including search engines. Draft products are excluded from the public supplier profile. Do not publish information you lack authority to disclose.

A document-record page is accessible to people who have its record code and can display the recorded title, issuer, dates, status and fingerprint. Such a link should not be treated as confidential. The current demonstration records are samples.

Unpublishing a profile changes its availability through the service, but copies, search results or caches maintained by other parties may remain. Their removal is subject to those parties’ processes and applicable law.

8. International processing

The service uses infrastructure outside Türkiye and the European Economic Area, including the United States. The current production database is hosted in a US region. Resend states that it stores message content and delivery logs in the US, even when an email sending region is selected elsewhere. Vercel uses international infrastructure and service providers.

The providers publish information about their processing and transfer terms: Vercel DPA, Neon terms, and Resend data-processing information. The availability of these documents is not a statement that every contractual or country-specific requirement for BXST.com has been completed.

Where applicable law requires an international-transfer mechanism or additional safeguards, those requirements apply to the relevant transfer. We do not claim that selecting an EU sending region, accepting these Terms, or a provider’s certification alone satisfies them. Contact info@bxst.com for information about the arrangements relevant to your data and any available copy of applicable safeguards.

9. Retention and deletion

Retention is assessed according to the purpose of the information, whether an account or workspace is active, security and abuse-prevention needs, unresolved requests or disputes, and applicable legal requirements. Account and workspace records do not currently have a fixed automatic expiry. Contact us to request a review, correction, closure or deletion.

Verification links are valid for up to 24 hours and password-reset links for up to 30 minutes, and successful use prevents reuse. These validity periods are not promises that related security records are immediately erased. Session expiry similarly ends authorization; retained operational records and provider logs can have different retention periods.

The current account interface does not provide self-service account deletion or a complete personal-data export. Requests can be made by email. We may need to distinguish your own information from records an organization must retain, verify authority and identity, and consider lawful retention or others’ rights before taking action. Signing out or clearing cookies does not delete stored account information.

Service-provider logs and backups follow their applicable retention arrangements and may persist separately from active application records. We do not promise immediate deletion of every backup or copy held by another party. Any applicable statutory restriction or deletion duty remains in force.

10. Security and automated features

Controls in the service include password hashing, email verification, expiring single-use authentication links, secure session cookies, authentication rate limits and role-based organization access checks. These measures reduce risk but cannot guarantee that every incident or unauthorized access will be prevented.

Current copilot answers and briefs are assembled from workspace information and rules. They are decision-support information for human review. The current user flows do not send copilot questions to an external generative-AI provider. Introducing a different processing flow requires review and an updated notice where appropriate.

The current service is not designed to make decisions about individuals solely by automated means that produce legal or similarly significant effects. If your organization uses outputs for decisions about people, it remains responsible for assessing the applicable rules and providing any required human review.

11. Your choices and rights

Contact info@bxst.com with a description of your request and enough information to locate the relevant account or records. Do not send your password or an active authentication link. We may request proportionate information to verify identity or authority; please do not send identity documents unless a secure and necessary method has been agreed.

Depending on the law that applies and its conditions, you may request access, correction, erasure, restriction, or a portable copy of your data; object to processing, including processing based on legitimate interests; withdraw consent where used; and exercise protections relating to significant solely automated decisions. These rights are subject to their legal conditions and do not require every record to be deleted in every situation.

Where the GDPR applies, we respond without undue delay and normally within one month of receiving a rights request. When permitted because of complexity or the number of requests, that period may be extended by up to two further months, with notice and reasons within the first month. Different mandatory periods apply under other laws, including Türkiye’s KVKK.

You may complain to the competent data-protection authority. Where the GDPR applies, this includes the authority in your habitual residence, place of work or the place of the alleged infringement. For Türkiye, the KVKK Notice explains the relevant application and complaint route. Contacting us does not waive your rights.

12. Children and notice updates

The service is intended for adults in a business context and is not directed at children. If you believe a child has provided personal information through an account, contact us so the situation can be reviewed.

We may update this notice when processing practices or applicable requirements change. The date above identifies the version. Where a change requires additional notice or consent, the applicable requirement must be met before relying on that change.