What is and is not in the published data, first — because that is the fact a reader can check directly, without taking anything else on trust. Then the crawl that reached those properties, and on what terms.
Privacy and processing
What is served, and what is not
The deposit serves no contact data. The index carries zero @ characters and zero phone numbers anywhere in entities.json; no leaf carries a populated contact value. Every one of the 1,117 records declares the withholding explicitly rather than simply omitting the field — a consumer can tell a redaction from a value that was never collected.
- 1,117 / 1,117
- records have
contact.emailwithheld. The register publishes a mailbox for every one of them; none is republished. Roughly three in four are on the business’s own domain and one in four on a free provider (Gmail and similar) — both withheld identically. - 1,108
- records have
contact.phonewithheld, because the register published a number for them. The other 9 havephone_class: "absent": the register carries no number at all, and that is a fact about the source, not a redaction. - 1,106
- of those also have
contact.phone_e164withheld. A further 2 carry a number that could not be converted to E.164 at all —phone_class: "implausible_length"— a third state, neither present nor withheld, and named as such. - 7
- records had a further field,
phone_e164_all, removed outright rather than emptied, because it held every derivable number for a record that published more than one. An emptied list-shaped field would have looked like a withholding of one value; removing the key says what actually happened. - 106
- records had their entire reachable surface withheld, not just a contact field — because for those properties the correct channel a client would open is a
tel:ormailto:address. The surface type is kept; the address behind it is not. - 18
- zero-padded placeholders in the source register (
0000...-style) are kept as served. They identify nobody, and withholding them would misrepresent what the register itself contains.
Method: the value is removed, not obscured. No hash, no pseudonym, no truncated domain — a hash of an address is still personal data and merely looks safer, which is worse, and a mutilated value inside a field named email is a value that is not an address wearing the name of one.
The originals are not ours to redistribute: they sit in Regione Puglia’s own register, CC-BY-4.0, public. Anyone who needs them takes them from that source, under a basis of their own; this index states no basis on their behalf and asserts no right over them.
The crawl
Reaching the reachability facts this index publishes required visiting each property’s own public website once. This section says who did that, what it collected, why, and how.
Who
Francesco Marinoni Moretto, independent researcher, author of Selling to Agents. No commercial relationship with any OTA, booking engine or property-management system. The crawler itself, AtlasBot/0.1, is documented in full — what it records, what it does not, how to block it — at /crawler.
What was collected
Two things: the regional register snapshot (public open data, see /licence), and AtlasBot’s own observation of each property’s public website — whether a booking path exists, which engine serves it where identifiable, that page’s address, and the date it was checked. Page text is read to locate the booking path and then discarded: not stored, not republished, not used to train a model.
Purpose
Measurement over a population defined by law: every accommodation entered in Puglia’s regional register, not a set selected by this project. The question is whether an AI agent can reach a working booking channel for each one, and the record is published as a research result.
Conduct
One request at a time, never in parallel. A minimum of three seconds between requests to the same host. Responses are cached, so a repeat analysis does not repeat the visit. robots.txt is honoured, including on redirects. No circumvention of any access control, CAPTCHA, paywall or anti-bot system: if a server refuses, the refusal is recorded as the result and never worked around. The full commitment and the per-host timing log are at /crawler.
What is not served
- Contact data — see above.
- Prices, availability or booking conditions. No record carries a price and no placeholder stands in for one.
- Reviews or ratings.
- Customer or booking data, which is not public and was never accessed.
- Page content beyond the fact of a reachable booking path.
Rights, and where to write
If a record about a property is wrong, or you want AtlasBot excluded from a site, write to crawler@atlasforagents.com — no reason required, and corrections are published, numbered and dated. For anything else concerning this processing, write to info@atlasforagents.com.
The processing this crawl relies on operates under legitimate interest, GDPR Article 6(1)(f). The documented assessment that balances that interest against the rights and expectations of the businesses recorded — the test Article 6(1)(f) itself requires — has not been completed, and this page does not claim that it has. The same is true of the assessment of disproportionate effort that would ground the Article 14(5)(b) exemption from individual notice: it does not exist yet either.
Both are pending. This section is replaced, dated, the day either one closes — and until then, this is the honest state of the record rather than a claim the record cannot support.