Privacy notice · GDPR
Privacy Policy
Last updated: 25 agosto 2026
Courtesy translation. This is an English translation of a document originally written in Italian, provided to make it readable. The Italian version is the binding one: in case of any discrepancy between the two texts, the Italian text prevails.
This notice describes how the personal data of users who visit the site and use Social Web Automation services is processed, under art. 13 of EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (the Privacy Code) as amended by Legislative Decree 101/2018.
1. Data controller
The data controller is Social Web Automation di Marco Dibenedetto (Social Web Automation), with registered office at Via Giuseppe Verdi 2B, 22072 Cermenate (CO), VAT no. 03786790133, tax code DBNMRC80E04C933Q.
Email: swsdautomation@gmail.com · Certified email: dibenedetto.80@pec.it · Tel: +39 347 719 6603.
The controller has not appointed a Data Protection Officer (DPO). For privacy requests you can contact the controller directly at swsdautomation@gmail.com.
2. What data we process
a) Data you provide
- Registration data: name, email, company, phone, chosen plan, password (hashed with bcrypt).
- Contact data: when you write to us by email, WhatsApp or a form.
- Billing data: company name, VAT number, address — handled through Stripe.
- Withdrawal and cancellation data: name, email, contract reference and date, category of the request, the declaration transmitted, date and time, case number and receipt.
- Uploaded content: images, text, brand and product data you enter into the platform.
b) Data collected automatically
- Browsing data: IP address, browser type, pages visited, timestamps (technical server logs).
- Technical cookies: necessary for operation (session, authentication). Details in the Cookie Policy.
3. Purposes and legal bases
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Delivering the service (account, content generation and publication) | Performance of a contract — point (b) |
| Invoicing and tax obligations | Legal obligation — point (c) |
| Support and replying to requests | Pre-contractual measures — point (b) |
| Security, abuse prevention, technical logs | Legitimate interest — point (f) |
| Sending transactional email (activation, notifications) | Performance of a contract — point (b) |
| Handling and evidencing withdrawal or cancellation declarations | Legal obligation — point (c) and performance of a contract — point (b) |
| Marketing and newsletter (if enabled) | Consent — point (a) |
| Advertising campaign measurement (events sent to Meta from our server) | Consent — point (a) |
4. Use of artificial intelligence
The platform uses OpenRouter, which routes third-party AI models (Google, OpenAI, Anthropic, Meta and others) to generate text and images. The data you enter (brand, products, images) may be sent to these providers solely to generate the content requested. We do not use your data to train AI models and we select providers offering contractual guarantees to that effect. See also the AI transparency notice (art. 50 of EU Regulation 2024/1689).
4-bis. Advertising campaign measurement
When a campaign is running, and only after your explicit marketing consent, our server sends Meta two events: a consultation request and the start of a purchase. It exists to know which advert brought a real contact; without it, advertising spend is blind.
What is transmitted: email address and phone number hashed with SHA-256, so Meta never reads them in clear text, together with the IP address, the browser type and the amount of the transaction. We do not transmit the content of your messages, uploaded materials or account data.
The communication leaves from our server: no Meta script is loaded on the site and no advertising cookies are set. Without consent nothing is sent, and the check sits inside the code that sends the event, not in an external configuration. Withdrawing consent from the banner stops the sending.
5. Recipients and external processors
Data may be processed on our behalf by the following providers, appointed as processors (art. 28 GDPR):
| Provider | Activity | Transfer outside the EU |
|---|---|---|
| Neon (database Postgres) | Hosting database e dati account | Possibile (USA) — SCC/Data Privacy Framework |
| Render | Hosting applicazione | Possibile (USA) — SCC |
| OpenRouter (instrada modelli di Google, OpenAI, Anthropic, Meta, ecc.) | Generazione contenuti con AI | Sì (USA) — SCC/DPF |
| Blotato | Pubblicazione programmata sui social | Possibile — SCC |
| Stripe | Pagamenti e fatturazione abbonamenti | Possibile (USA) — SCC/DPF, PCI-DSS |
| Cloudflare R2 / Backblaze B2 | Archiviazione immagini | Possibile — SCC |
| Meta (Instagram/Facebook Graph API) | Statistiche e pubblicazione (se collegato) | Sì (USA) — SCC/DPF |
| Meta (Conversions API) | Misurazione delle campagne: solo con consenso, inviata dal nostro server | Sì (USA) — SCC/DPF |
| Resend | Invio email transazionali (se attivo) | Possibile (USA) — SCC |
Some providers are based in the USA: transfers rely on Standard Contractual Clauses (SCCs) and/or adherence to the Data Privacy Framework, as provided by arts. 44-49 GDPR.
6. Retention periods
- Account data: for the duration of the relationship and up to 24 months after it ends.
- Billing data: 10 years (civil and tax obligation).
- Withdrawal and cancellation declarations: up to 10 years, to evidence the request and handle any dispute, unless a different legal obligation applies.
- Uploaded content (images, text, brand and product data): for the duration of the relationship and up to 24 months after it ends, together with the account data. Earlier deletion can be requested at any time.
- Technical logs: 12 months maximum.
- Marketing data: until consent is withdrawn.
7. Your rights
Under arts. 15-22 GDPR you have the right to: access, rectification, erasure (“the right to be forgotten”), restriction, portability, objection, and to withdraw consent at any time. To exercise them, write to swsdautomation@gmail.com. We reply within 30 days, extendable by a further 60 in the cases provided by art. 12.3 GDPR, informing you accordingly.
For the right to portability (art. 20) we hand over the data you provided in a JSON archive, a structured, machine-readable format: account data, uploaded content, publication history and the register of requests. Images and files are delivered in their original format. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of your own country of residence.
8. Security
We adopt appropriate technical and organisational measures: hashed passwords (bcrypt), HTTPS connections with HSTS, a restrictive Content-Security-Policy, multi-tenant access control, rate limiting and per-client data isolation. No system is 100% secure: which is why the breach procedure is written before it is needed, below.
9. What happens in case of a data breach
A breach is any event leading to destruction, loss, alteration, disclosure of, or unauthorised access to personal data. The procedure is this, in order:
- Detection and containment: closing the access, revoking the credentials involved and preserving the logs needed to reconstruct what happened.
- Risk assessment: within a few hours, by the controller, to establish the nature, the categories and the approximate number of data subjects and records involved.
- Notification to the supervisory authority within 72 hours of the controller becoming aware of it, under art. 33 GDPR, unless the breach is unlikely to result in a risk to people’s rights and freedoms. If 72 hours are not enough, the notification states the reason for the delay.
- Communication to data subjects without undue delay, under art. 34 GDPR, where the breach presents a high risk: what happened, which data, the likely consequences, what we did and what you should do.
- Breach register: every event is recorded with its effects and the measures taken, under art. 33.5 GDPR, even where notification is not required.
If the breach concerns a provider processing data on our behalf, the art. 28 GDPR contract requires them to inform us without undue delay, so that the deadlines above start correctly.
10. Changes
We reserve the right to update this notice. Material changes will be communicated by email or through a notice on the site.