Privacy Policy

Last updated: 12 September 2026

1. Who we are

Condire Digitale is a small independent digital marketing agency based in Italy. This document describes how we collect, use, store, and protect data when we operate the internal reporting tool "Condire Digitale Report Hub" available at https://report.condiredigitale.it.

Data controller: Condire Digitale — condiredigitale@gmail.com

2. Scope of the tool

The tool is used only by our internal agency team to aggregate marketing performance data for the clients we manage. Clients themselves do not have access to the tool. The output of the tool is a periodic PDF report we deliver to each client.

3. Data we access

Through official APIs, and only after the account owner has explicitly authorized access, we read the following aggregated marketing data for each managed client:

All data is aggregated at account/campaign/post level. We do not collect personal information about end users of the client's properties (no PII, no cookies, no individual user tracking).

4. Google Ads API specific disclosures

Our use of the Google Ads API is strictly read-only: we do not create, modify, pause, or bid on campaigns. We do not perform bulk operations or bidding automation. Data retrieved via the Google Ads API is stored in our database only for the purpose of generating aggregated reports for the specific client that owns the ads account, and is never shared with third parties, resold, or used for advertising by us.

5. OAuth tokens and credentials

When a client authorizes our tool to access their Meta or Google accounts (via standard OAuth flows), we store the resulting access tokens and refresh tokens encrypted at rest in our managed database (Supabase Postgres, hosted in the EU). Tokens can be revoked at any time by the account owner from their Google / Meta account settings, or by asking us to disconnect the integration.

6. Where data is stored

Data never leaves the systems above except for the outgoing API calls to Meta and Google strictly needed to fetch the marketing metrics.

7. Retention

Marketing metrics are kept for as long as the client relationship is active, so we can produce historical comparisons in reports. When a client ends the collaboration, we delete their integrations and tokens upon request within 30 days, and their aggregated metrics within 12 months.

8. Your rights

Under the EU GDPR, any client or user whose data is processed by our tool has the right to access, rectification, deletion, restriction, portability, and to object to processing. Requests can be sent to condiredigitale@gmail.com and are handled within 30 days.

9. Third parties

We do not share the data we collect with third parties for advertising or resale. The only third parties involved are our infrastructure providers (Supabase, Vercel) and the API providers (Meta, Google), each acting as data processors bound by their own terms and privacy policies.

10. Compliance with Google API Services User Data Policy

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

11. Changes to this policy

We may update this policy occasionally. The date at the top of this page will reflect the most recent revision. Material changes affecting our clients will be communicated directly.

12. Contact

For any privacy-related question: condiredigitale@gmail.com.