Privacy policy
Last updated: 4 October 2026
1. Who we are and our role
The service is operated by Chiminelli Daniele, Italy, VAT no. 04341250985 ("we"). Privacy contact: info@danielechiminelli.it.
For data of visitors to our customers' websites, the customer is the data controller (the business using the service) and we act as data processor on the customer's instructions. For data of the users of our console (the customers themselves) we are the controller.
2. What data we process
| Data | Why | When |
|---|---|---|
| Ad click identifiers (GCLID, WBRAID, GBRAID) and campaign parameters (UTM) | To link an enquiry to the ad it came from | Only with the visitor's consent |
| Landing page and referrer (without query parameters) | To know which page the enquiry started from | Only with the visitor's consent |
| Reference code in the WhatsApp message and the time of the message | To recognise the message and link it to the click | When the visitor sends the message |
| Sender's phone number | To tell enquiries apart | Stored only as a one-way hash, never in clear |
| Customer account data (company name, connected WhatsApp number, connected Google Ads account, encrypted access keys) | To run the service | For the duration of the relationship |
We do not read the content of WhatsApp conversations beyond the reference code, we do not message the customer's contacts and we do not sell data.
3. Legal basis
Visitor tracking happens only with consent (Art. 6(1)(a) GDPR), collected by the customer's website. For console users, the basis is performance of a contract (Art. 6(1)(b)). For security and abuse prevention, legitimate interest (Art. 6(1)(f)).
4. Retention
- Tracking sessions expire within 30 days; after that, click identifiers and campaign parameters are cleared.
- Enquiries and recorded conversions are kept while the customer has an active account, or until the customer asks for deletion.
- When a connection (WhatsApp or Google Ads) is disconnected, we stop using it and delete the related encrypted credentials.
5. Who we share data with
- Meta Platforms (WhatsApp Business Platform): we receive messages through their services.
- Google (Google Ads): we report that a conversion linked to a click identifier occurred. We do not send phone numbers or message text.
- Hosting provider: Hostinger.
Some of these providers may process data outside the European Economic Area, with the safeguards required by the GDPR (for example standard contractual clauses).
6. Security
We use encrypted connections, key-protected access, encryption of connection tokens and data minimisation (for example the hashed phone numbers).
7. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, and to withdraw consent at any time. If you are a visitor to a website that uses the service, contact the operator of that website; you can also write to info@danielechiminelli.it and we will forward your request. You may lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
8. Changes
If this policy changes materially, we will update the date and notify customers.