Privacy Policy
Alessandro Content Factory
Effective date: 21 September 2026
VAT number (P.IVA): 14107020969
Place of business: Milan, Italy
Contact: azoncadaweb@gmail.com
1. Scope of this Privacy Policy
This Privacy Policy explains how personal data is handled when a user connects a supported social-media account to Alessandro Content Factory and uses the workflow to prepare, review and, where enabled, publish content through official platform APIs. It does not replace any separate privacy notice that may apply to other features of the main website.
2. Personal data we may process
2.1 Account and profile data
When you connect a third-party social account through the provider's official authorization flow, the service may receive basic account information made available under the permissions you approve, such as an account identifier, display name, username, profile information, and information about the permissions granted to the application.
2.2 Authentication data
The service may receive and store OAuth access tokens, refresh tokens where supported, token expiry information, authorization state, and related technical credentials needed to keep an authorized account connected. Passwords for social-media accounts are not requested or stored by Alessandro Content Factory.
2.3 Content and publishing data
When you prepare or publish content, the service may process media files, captions, publishing options, approval status, provider-specific settings, publication identifiers, publication status, and error or response metadata returned by the connected platform.
In the current implementation the workflow prepares and validates content locally and stops at a human approval step: publication identifiers and publication status are processed only if and when a publishing action is actually carried out.
2.4 Technical and security data
The service may process technical logs needed to operate and secure the workflow, such as timestamps, content identifiers, provider name, requested action, connection state, validation results, error categories, and external publication identifiers. Secrets and full authentication tokens are not intended to be written to ordinary application logs.
2.5 Data included in user content
Content submitted by a user may itself contain personal data relating to the user or third parties. The user is responsible for ensuring that they have the rights and legal basis necessary to use and publish that content.
3. Where the data comes from
Personal data may be obtained:
- directly from you when you configure or use the service;
- from a connected platform after you authorize access through its official OAuth flow;
- from files and content that you choose to process or publish through the service;
- from technical events generated while the workflow is operating.
4. Purposes and legal bases
Depending on the context, personal data may be processed for the following purposes:
- Account connection and authentication: to establish and maintain an authorized connection to a supported platform.
- Content preparation and publishing: to validate, prepare and carry out publishing actions explicitly requested or approved by the user.
- Security and fraud prevention: to protect tokens, prevent unauthorized actions, validate OAuth state and investigate technical or security incidents.
- Technical operation and troubleshooting: to diagnose errors, maintain the workflow and verify publication status.
- Legal compliance: to meet applicable legal obligations and respond to lawful requests where required.
Where the GDPR applies, processing may be based, as appropriate, on the performance of a contract or steps taken at the user's request, the controller's legitimate interests in operating and securing the service, compliance with legal obligations, or another lawful basis applicable to the specific processing. Granting permissions in a third-party OAuth screen is a technical authorization and is not automatically treated as GDPR consent for every processing activity.
5. Connected platforms and recipients
The service is designed to communicate with supported social-media providers through their official developer APIs. Depending on which account you connect, personal data may be exchanged with providers such as TikTok and Meta/Instagram in order to authenticate the account, retrieve permitted account information, validate publishing capabilities, upload or publish content, and retrieve publication status. Those providers process data under their own terms and privacy notices for activities they determine independently.
Other service providers may process limited technical data only where they are actually used to host the official website or provide necessary infrastructure.
6. International data transfers
Connected social-media providers may process personal data outside the European Economic Area. Where the controller itself transfers personal data internationally, appropriate safeguards required by applicable data-protection law will be used where necessary. Independent transfers carried out by third-party platforms are governed by those platforms' own privacy documentation and transfer mechanisms.
7. Retention
Authentication data is retained only for as long as it is needed to keep the relevant account connected, until the authorization is revoked, disconnected, expires without renewal, or is otherwise no longer required for the service. Publishing metadata and technical logs are retained for the period reasonably necessary to operate, secure, troubleshoot and document the workflow, and may be retained longer where required by law or to establish, exercise or defend legal claims.
8. Security
Alessandro Content Factory is designed to use official authorization mechanisms rather than collecting social-media passwords. Application secrets are intended to remain outside public source code, and authentication tokens are intended to be stored separately from ordinary project files. The workflow is designed to avoid exposing tokens in ordinary logs and to use authorization-state checks and other safeguards appropriate to the supported OAuth flows.
No method of storage or transmission can be guaranteed to be completely secure.
9. Sale of personal data and advertising
Alessandro Content Factory is not designed to sell personal data or use connected-account data for third-party behavioral advertising. If this changes, this Privacy Policy must be updated before such processing begins.
10. Automated decisions
The service may automate technical and editorial workflow steps, but it is not intended to make decisions producing legal effects or similarly significant effects about individuals solely through automated processing. Real publishing is designed to remain subject to the approval rules configured for the workflow.
11. Your data-protection rights
Where the GDPR applies, you may have the right to request access to your personal data, rectification, erasure, restriction of processing, portability, and to object to certain processing. Where processing is based on consent, you may have the right to withdraw that consent without affecting the lawfulness of processing carried out before withdrawal. These rights are subject to the conditions and limitations provided by applicable law.
You also have the right to lodge a complaint with the competent supervisory authority. In Italy, this is the Garante per la protezione dei dati personali.
12. Disconnecting a social account
A connected account may be disconnected through the service where that feature is available, and access may also be revoked from the relevant third-party platform.
Disconnecting through the service deletes the stored authentication data from the device on which the workflow runs. It does not by itself withdraw the authorization held by the third-party platform, which has to be removed from the settings of the relevant platform account.
Revoking access may prevent future API operations but does not necessarily remove content already published on the third-party platform.
13. Children
Alessandro Content Factory is not directed to children and is not intended to knowingly collect personal data from children through the account-connection workflow.
14. Changes to this Privacy Policy
This Privacy Policy may be updated when the service, its connected platforms, its technical architecture, or applicable legal requirements change. The effective date shown at the top identifies the current version.
15. Contact
To exercise your rights or ask questions about this Privacy Policy, contact: azoncadaweb@gmail.com.