← Stephen Bellotto ENPT

· Privacy / RGPD · 2026-07-10

Privacy Policy

This is the privacy policy for stephenbellotto.com and the « Agência de IA » dashboard. It covers both the people who use our dashboard and the third parties we analyse for commercial prospecting (see sections 12 and 13). We follow GDPR (EU 2016/679), Meta Platform Terms and the EU AI Act.

1. Who we are

Controller: Stephen Bellotto (Sliema, Malta). Contact for data protection: designer@stephenbellotto.com.

Supervisory authority: Information and Data Protection Commissioner (IDPC) Malta, idpc.org.mt.

2. Data we process

Forms (briefing, contact, newsletter): name, email, company, phone, message, attachments, language.

Admin/team access: email + hashed password + session tokens.

Technical/security logs: IP, user-agent, pages visited, timestamps.

AI interactions: prompts you submit + AI-generated content (text, image, translation, analysis).

Meta integrations (if connected): Page ID, IG User ID, access tokens (encrypted), inbox messages, post metadata.

3. Purposes and legal basis (GDPR Art. 6)

A. Reply to your contact, pre-contractual steps (Art. 6(1)(b)).

B. Deliver our services, contract performance (Art. 6(1)(b)).

C. Newsletter, explicit opt-in consent (Art. 6(1)(a)).

D. Tax / accounting obligations, legal duty (Art. 6(1)(c)).

E. Operate the dashboard, legitimate interest (Art. 6(1)(f)).

F. Generate AI content on your behalf, contract performance.

G. Publish to social networks via Meta, your explicit authorization.

H. Detect fraud, protect infrastructure, legitimate interest.

We DO NOT process special-category data (Art. 9) without explicit, specific consent.

4. Who we share data with (subprocessors)

Vercel Inc. (US), hosting, blob storage, edge functions.

OpenAI Ireland Ltd. / Anthropic PBC (US), AI generation (text/image). API mode: providers DO NOT train on your data.

Google LLC (Gmail API + Calendar API), sending transactional email and reading calendar availability on your behalf.

Translated S.r.l. (Italy, MyMemory), translation fallback.

Meta Platforms Ireland Ltd., only when you connect a Meta account.

Stephen Bellotto's use of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Google data is used only to send email and read calendar availability on your behalf, never for advertising, and no human reads it except with your explicit consent or for security or legal reasons.

5. International transfers

Some providers process data in the US under Standard Contractual Clauses (Commission Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework.

Email designer@stephenbellotto.com to request a copy of the safeguards.

6. Retention

Contact requests with no follow-up: 6 months. Client data after contract: 10 years (tax obligation, Malta). Newsletter: until unsubscribe. Technical logs: 12 months. AI prompts/output: up to 90 days. Encrypted backups: 30 days after main deletion.

7. Your rights (GDPR Arts. 15–22)

Access, rectify, erase, restrict, port, object, withdraw consent at any time, and not be subject to solely automated decisions.

How: email designer@stephenbellotto.com with proof of identity. We answer within 30 days (extendable by 60 in complex cases).

Complaint: IDPC Malta or your national authority (edpb.europa.eu).

8. Cookies

We use a minimum set of essential cookies and ask for opt-in consent for analytics/marketing cookies via a banner. See /cookies for the full table and re-open the consent manager at any time.

9. Meta integrations (Instagram, Facebook, WhatsApp)

Data collected only when you connect your Meta account: identifiers, encrypted tokens, posts you publish, inbox messages (if enabled).

Purpose: only the actions you authorize. Never used for profiling, sale or third-party analytics.

Deletion: disconnect the app under Meta Settings, or email designer@stephenbellotto.com (subject: « User Data Deletion, Meta »). We act within 30 days. We also implement the Data Deletion Callback at /api/meta-deletion-callback (Meta sends us deletion requests automatically).

10. Automated decisions and AI (GDPR Art. 22 + EU AI Act)

AI-generated content is identified as such (UI badge).

Models: OpenAI gpt-4o-mini (text), gpt-image-1 (image); or Anthropic Claude. Providers DO NOT use your data to train models.

We do not take decisions with legal or significant effect without human review. You can request human intervention and contest any automated outcome.

11. AI automation app for clients (B2B)

When you use our AI automation app for your business, we act as Processor (Art. 28). You are the Controller. We sign a Data Processing Agreement (DPA) before any data is processed. Tenants are isolated; other clients do not see your data.

12. Commercial prospecting from public sources

We reach out to companies that may need our services. To prepare that outreach we read information the company itself has made public: its website, its public Google profile (Google Business) and open social-media pages. We do not use private data, we never ask for passwords and we never access anything behind a login.

What we do with it: we generate an analysis of the business (what the brand communicates, strengths, opportunities) and, in some cases, we publish a demo landing page about the company and send an introduction email. All of it built from what was already public.

Legal basis: legitimate interest, GDPR Art. 6(1)(f). We do not ask for prior consent because B2B prospecting from public sources is a recognised legitimate interest, and because the data subject can object at any time (see « Your rights and how to opt out » below).

Legitimate Interest Assessment (LIA v1, 2026-07-10). 1) The interest: introducing our services to companies with a problem we know how to solve, in a targeted way instead of blind mass mailing. 2) Why it is necessary: without reading the company public material we could neither personalise the message nor even judge whether it makes sense to reach out, and the alternative of emailing everyone the same way would be more intrusive and lower quality. 3) Balancing test against the data subject rights: we use only already-public professional data, the volume per company is small, we do no sensitive profiling and no automated decisions with legal effect, and we offer an immediate and free removal path. The impact on the data subject is low and their rights prevail whenever exercised, including the right to object: object and we stop.

Company vs individual. When the target is a legal person (a company), there are no personal data beyond professional contacts. When the target is a natural person (for example a sole trader or a personal gmail address), we treat it more carefully: less data, and we drop the contact at the first objection or doubt. If in doubt whether a contact is personal, we assume it is and apply the more prudent treatment.

Your rights and how to opt out. You can object to being contacted, ask for access to what we hold about your company, and ask for erasure. Two ways: (a) every demo page we publish carries a « Remove this page » link that deletes the page immediately and adds your domain to our do-not-contact list, so we will not write again, and (b) email designer@stephenbellotto.com. We answer within 30 days.

13. Subprocessors that receive third-party data (prospecting)

In the prospecting described above, two providers receive information about the analysed company:

OpenAI (OpenAI Ireland Ltd. / OpenAI, L.L.C., US): we send the public website content and the public profile data so the model can generate the business analysis. In API mode, OpenAI does NOT use this data to train its models.

Google Places (Google Ireland Ltd. / Google LLC): we fetch the establishment public data (name, address, category, public ratings) from the Places API. This data is NOT used for training.

This data is used only to prepare our commercial outreach. We do not sell it, we do not combine it with other databases and we do not pass it to anyone else.

14. Security

TLS 1.3, encryption at rest for sensitive data, principle of least privilege, monitored access. Breach notification within 72h to the authority (Art. 33) and to data subjects when high risk (Art. 34).

15. Children

Service not directed to users under 16 (consent age for information-society services in Malta). Contact us to delete any inadvertent collection.

16. Changes

Material changes are communicated to subscribers/clients 30 days in advance. Current version dated 2026-07-10.

17. Contact

designer@stephenbellotto.com · Stephen Bellotto, Sliema, Malta. Applicable law: Maltese law and EU law. Forum: Maltese courts, without prejudice to consumer-protection rights in your EU country of residence.