DS2 Studio
Casi d'uso Privacy Terms Book a call
Legal

Privacy Policy

Last updated: August 15, 2026  ·  Version 2.2

This Privacy Policy applies to all products, services, and applications operated by DS2 Agency (Davide Senigalliesi), including our WhatsApp Business automation platform, client onboarding tools, the sales applications we operate for our clients' teams, and any integrations built on the Meta WhatsApp Business Platform or on Google APIs. It explains what data we collect, why we collect it, how we protect it, and what rights you have over it.
Contents
  1. Who we are
  2. Scope of this policy
  3. Use of the Meta WhatsApp Business Platform
  4. Use of Google APIs and Google user data
  5. Data we collect and process
  6. Purpose and legal basis
  7. Data processors and sub-processors
  8. Data storage and security
  9. Data retention
  10. International data transfers
  11. Data sharing and disclosure
  12. Requests from public authorities
  13. Your rights
  14. Children's privacy
  15. Cookies
  16. Changes to this policy
  17. Contact

1. Who we are

DS2 Agency is a digital automation agency operated as a sole proprietorship by Davide Senigalliesi, based in Germany. We design and operate automated communication systems for small and medium-sized businesses, with a primary focus on WhatsApp Business automation built on the Meta WhatsApp Business Platform Cloud API.

Legal nameDavide Senigalliesi (trading as DS2 Agency)
CountryGermany
Emailseniga.trento@gmail.com
Websitehttps://ds2.studio
Data controllerDavide Senigalliesi

As the data controller, DS2 Agency determines the purposes and means of processing personal data obtained through our services and through the Meta Platform.

2. Scope of this policy

This policy covers:

  • The DS2 Agency WhatsApp Business automation platform and all associated workflows
  • The client onboarding application hosted at davideai.com/gioel/onboarding and any future onboarding URLs, which use the Meta Embedded Signup flow
  • All client-facing dashboards and tools hosted on davideai.com
  • The sales applications we operate for our clients' teams, including the Gioel Leads app at davideai.com/gioel/leads, and its optional Google Calendar connection (see Section 4)
  • The Gesigroup claims portal at ds2.studio/gesigroup, an insurance-claims case portal we operate on behalf of our client Gesigroup (an Italian insurance-claims intermediation agency), including its Google Sign-In (see Section 4) and the claims data described in Section 5d
  • Any data received from Meta through the WhatsApp Business API, Facebook Login for Business, or the Meta Graph API

It applies to end users (customers of our business clients who interact via WhatsApp), business clients who connect their WhatsApp Business Accounts to our platform, users of the Gesigroup claims portal (Gesigroup's employees and Gesigroup's own clients), and administrators who access our dashboards.

3. Use of the Meta WhatsApp Business Platform

DS2 Agency is registered as an Independent Tech Provider on the Meta WhatsApp Business Platform. Our Meta App (Gioel Servizio Clienti, App ID: 1258577862899321) holds the following approved permissions:

  • Approved  whatsapp_business_messaging — allows sending and receiving WhatsApp messages on behalf of connected business clients
  • Pending  whatsapp_business_management — allows managing WhatsApp Business Accounts, phone numbers, message templates, and webhook subscriptions on behalf of clients

How we use these permissions

We use whatsapp_business_messaging exclusively to:

  • Send automated WhatsApp messages to end users (customers) on behalf of our business clients, using pre-approved message templates
  • Receive and process inbound WhatsApp messages from end users and route them through client-specific automation workflows
  • Log message events (sent, delivered, read) for operational purposes

We use whatsapp_business_management exclusively to:

  • Onboard client WhatsApp Business Accounts (WABAs) via the Meta Embedded Signup flow
  • Create, submit, and manage message templates on behalf of clients
  • Register phone numbers and manage webhook subscriptions for client WABAs
  • Retrieve WABA analytics and account information for display in client dashboards

We do not use Meta Platform data for advertising, profiling, or any purpose outside the direct delivery of automation services to our clients. All data obtained through Meta permissions is used strictly in accordance with the Meta Platform Terms and the applicable WhatsApp Business Policy.

Embedded Signup

When a business client connects their WhatsApp Business Account through our onboarding page, they go through the Meta Embedded Signup flow. During this flow, Meta issues an OAuth authorisation code, which our backend exchanges for a user access token. This token is used solely to register the client's WABA with our platform and is stored securely. We do not use this token for any purpose other than managing the client's WhatsApp Business assets as described above.

4. Use of Google APIs and Google user data

Some of our applications let a user sign in with their own Google Account, and one of them additionally lets a user connect their own Google Calendar so they can work with it inside the app. This section states exactly which Google data each application accesses, why, where it is stored, and how to revoke access at any time. Two DS2 Agency applications currently request Google authorisation: the Gioel Leads sales app at davideai.com/gioel/leads (OAuth client "Gioel Leads App Calendar Connection"), covered by 4a-4e below, and the Gesigroup claims portal at ds2.studio/gesigroup (OAuth client "Gesigroup"), covered separately in 4f.

Connecting a Google Account for the Gioel Leads Calendar feature is always optional — that app is fully usable without it, the calendar features are simply hidden. For Gesigroup, signing in with Google is the only way to reach the portal at all (see 4f).

4a. Scopes we request

ScopeWhat it allowsWhy we request it
openid, email, profile Read the account's email address, name, and profile picture "Sign in with Google" — used only to identify the user and match them to their existing app account
https://www.googleapis.com/auth/calendar.events View and edit events on the signed-in user's calendars Show the user their own busy and free slots for the next 7 to 14 days while they are booking a customer appointment, and write the appointment they confirm into their own calendar

We request no other Google scope. We do not access Gmail, Google Drive, Google Contacts, Google Photos, or any other Google service, and we never request access to anyone else's calendar — only the calendar of the signed-in user.

4b. What we do with Google Calendar data

  • Reading: when the user opens the appointment picker, the app reads events from their primary calendar for the next 7 or 14 days and displays them as busy or free slots. Those events are rendered in the user's browser for as long as that screen is open. Event titles, guests, locations, and descriptions are never written to our database, never written to our logs, and never shown to anyone other than the signed-in user.
  • Writing: when the user confirms an appointment, we create one calendar event containing the appointment date and time and the name of the contact being visited. Events are created only as the direct result of an action the user takes in the app. We never delete or modify events we did not create.
  • Nothing else: Google user data is never used for advertising or profiling, never sold or rented, never transferred to another company, and never used to train machine-learning or AI models. No DS2 Agency staff reads a user's calendar content; access is limited to what the app needs to draw the two screens described above.

4c. Google tokens we store

So that a user does not have to sign in again every hour, we store the OAuth tokens Google issues for that user in our database (table user_google_tokens, Supabase project hosted in the European Union, region eu-west-1, Ireland). Per user we store:

  • the access token and refresh token issued by Google
  • the token expiry timestamp and the scope that was granted
  • the internal app user id the tokens belong to, plus creation and update timestamps

Row-level security in the database restricts every row to the user who owns it, so one user's tokens are never readable by another user. Tokens are transmitted over HTTPS only and are used exclusively to call the Google Calendar API on behalf of that same user.

4d. How to revoke access

  • In the app: open the profile settings and press "Disconnetti" under Google Calendar. The stored tokens are deleted immediately.
  • From your Google Account: go to myaccount.google.com/permissions, select the app, and choose "Remove access". Any token we still hold stops working at once.

Revoking access removes the calendar features from the app and nothing else. Appointments already written to your calendar remain in your calendar and are yours to keep or delete. Appointment data you entered in the app stays in the app and follows the retention rules in Section 9.

4e. Limited Use commitment

DS2 Agency's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4f. Google Sign-In for the Gesigroup claims portal

The Gesigroup claims portal at ds2.studio/gesigroup uses Google for one purpose only: signing users in. Its users are Gesigroup employees and Gesigroup's own clients (people with an active damage or injury compensation claim handled by Gesigroup).

  • Scope requested: openid, email, profile only — the same identity scopes listed in the table in Section 4a. Gesigroup never requests Calendar, Drive, Contacts, Gmail, or any other Google scope, and this Limited Use commitment applies to it too.
  • How sign-in works: the OAuth exchange is handled by our sub-processor Supabase (Section 7) through its Auth service, not by custom DS2 Agency code. We do not receive or independently store the Google access or refresh token — Supabase Auth holds it, encrypted, to maintain the session. What our own database stores afterwards is the Google account's stable identifier, linked to that person's row in Gesigroup's employee or client records, so a future sign-in with the same Google account resolves to the same case.
  • Signing in only proves who you are. Whether you then see any case data — and which — depends entirely on whether that email address already exists in Gesigroup's own records. An email that matches neither is signed out to an "unauthorised" screen with no case data shown.
  • Revoking access: same as 4d — remove the app from myaccount.google.com/permissions at any time. Since Google Sign-In is Gesigroup's only login method, this also means you can no longer sign in to the portal.

5. Data we collect and process

5a. Data received from Meta

Data typeSourcePurpose
WhatsApp Business Account ID (WABA ID)Embedded Signup / Graph APIIdentify and manage client WABA
Phone Number IDEmbedded Signup / Graph APISend and receive messages
User access tokenOAuth code exchangeAuthenticate API calls on behalf of client
Inbound message contentWebhook eventsProcess customer replies in automation flows
Message status eventsWebhook eventsTrack delivery and read receipts
Business profile name and phoneGraph APIDisplay in client dashboard
Message template statusGraph APIMonitor template approval status

5b. Data collected from end users (customers of our clients)

Data typeHow collectedPurpose
WhatsApp phone numberInbound message webhookIdentify the customer in the automation flow
Message content (text, button replies)Inbound message webhookRoute the customer through the correct automation step
Name (if provided)Client lead form or message contentPersonalise outbound messages
Appointment or booking dataClient lead formSchedule and confirm appointments via WhatsApp

We collect only the minimum data necessary to operate the automation service. We do not collect sensitive personal data (such as health, financial, or government ID data) unless explicitly required and agreed with the client.

5c. Data collected from business clients

  • Name and email address of the account administrator
  • Meta Business Manager credentials (access tokens, WABA IDs) — stored securely
  • Configuration data (workflow settings, template content, manager assignments)

5d. Data collected through the Gesigroup claims portal

Gesigroup is a DS2 Agency client, in the same sense as the business clients in 5c: Gesigroup is the data controller for the data in this section, and DS2 Agency processes it on Gesigroup's instructions, operating the portal on Gesigroup's behalf. This is deliberately different from Sections 5a-5c above, which describe our own WhatsApp automation platform.

Data typeSourcePurpose
Name, email, phone numberEntered by a Gesigroup employee, or by the client directlyIdentify the case owner and let them sign in
Case code and case statusImported from Gesigroup's own case-management system by a Gesigroup employeeShow the client where their claim currently stands
Identity documents and health/medical records uploaded by the clientUploaded by the client through the portalGive Gesigroup the supporting documents it needs to progress the claim
Notification historyGenerated by the app on every case-status changeReplace the phone/WhatsApp status updates Gesigroup used to send manually

Special category data (GDPR Art. 9). Identity documents and health/medical records are special category personal data. We process them because a Gesigroup client chooses to upload them directly, to support a damage or injury compensation claim Gesigroup is pursuing on that client's behalf — necessary for the establishment and exercise of a legal claim (Art. 9(2)(f)). Document categorisation runs entirely inside our own server process — self-hosted text recognition and image processing, no third-party API — so the document image itself is never sent to any outside service. A client sees only the documents they uploaded themselves, never another client's file; Gesigroup employees see full case files, restricted to their authorised role.

This data is stored in a separate Supabase project dedicated to Gesigroup (distinct from the sales-apps project described elsewhere in this policy), under the same encryption, access-control, and row-level-security approach described in Section 8.

6. Purpose and legal basis

PurposeLegal basis (GDPR Art. 6)
Deliver WhatsApp automation services to business clientsArt. 6(1)(b) — contract performance
Onboard client WABAs via Embedded SignupArt. 6(1)(b) — contract performance
Process inbound messages and route automation flowsArt. 6(1)(b) — contract performance
Store conversation logs for client dashboardsArt. 6(1)(f) — legitimate interests (service delivery and audit)
Improve and maintain the platformArt. 6(1)(f) — legitimate interests
Comply with legal obligationsArt. 6(1)(c) — legal obligation
Send automated messages to end usersArt. 6(1)(a) — consent (obtained by the business client through their customer communication flow)

7. Data processors and sub-processors

DS2 Agency uses the following sub-processors to deliver its services. All sub-processors are bound by data processing agreements and operate under their own privacy and security policies.

ProcessorCountryPurposePolicy
n8n GmbH (n8n.io) Germany / EU Workflow automation — all automation logic runs on n8n Cloud. Message routing, API calls, and data transformations are executed here. n8n Privacy Policy
Google LLC USA (EU SCCs apply) Google Sign-In for authentication; Google Calendar API for the calendar features described in Section 4; Google Sheets as the data store of some automation workflows; Google Maps Platform for address search and map display in the sales apps. Google Privacy Policy
Supabase Inc. EU (region eu-west-1, Ireland) Database, authentication, and file storage for the sales applications. Contact records, appointment data, user accounts, and the Google OAuth tokens described in Section 4 are stored here. Supabase Privacy Policy
Meta Platforms, Inc. USA (EU SCCs apply) WhatsApp Business Platform — message delivery infrastructure, webhook events, Graph API. Meta Privacy Policy
Netlify, Inc. USA (EU SCCs apply) Hosting of all davideai.com frontend applications including client dashboards and onboarding pages. Netlify Privacy Policy

DS2 Agency remains fully responsible for ensuring that all sub-processors handle data in compliance with GDPR and this Privacy Policy. We do not authorise sub-processors to use personal data for their own purposes.

8. Data storage and security

We implement appropriate technical and organisational measures to protect all personal data against unauthorised access, loss, alteration, or disclosure.

Technical measures

  • Encryption in transit: all data is transmitted over HTTPS/TLS. Webhook endpoints are HTTPS-only.
  • Encryption at rest: access tokens, API keys, and credentials are stored encrypted within n8n Cloud's credential vault and never exposed in plaintext in logs or frontend code.
  • Access control: client dashboards require authentication. API credentials are scoped to the minimum permissions required.
  • Webhook verification: all inbound webhook events from Meta are verified using the X-Hub-Signature-256 mechanism to ensure they originate from Meta's servers.
  • Token security: user access tokens obtained via OAuth are stored server-side only and are never transmitted to the client browser beyond what is required by the Embedded Signup flow.
  • No credential exposure: App secrets and API keys are stored exclusively in n8n's encrypted credential store. They are never committed to version control or exposed in frontend code.

Organisational measures

  • Access to production systems is restricted to authorised DS2 Agency personnel only
  • Client data is logically separated — each client's data is stored in dedicated spreadsheets or database tables accessible only to that client's authorised users
  • Credentials and access tokens are rotated when personnel change or when a security incident is suspected
  • Third-party processors are selected based on their compliance certifications (SOC 2, ISO 27001, GDPR adequacy)

9. Data retention

Data typeRetention period
WhatsApp conversation logs12 months from last message, or until client requests deletion
Lead and customer recordsDuration of the client contract + 6 months
OAuth access tokensUntil revoked by the client or the token expires
Google OAuth tokens (access, refresh)Until the user disconnects Google Calendar in the app, revokes access from their Google Account, or their app account is deleted — whichever comes first
Workflow configuration dataDuration of the client contract
Error and execution logs30 days

After the applicable retention period, data is deleted or anonymised. Business clients may request early deletion of their data at any time. End users may request deletion of their data through the business client, who will forward the request to DS2 Agency.

10. International data transfers

Some of our sub-processors (Google LLC, Meta Platforms, Netlify) are based in the United States. When personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) — approved by the European Commission under GDPR Art. 46(2)(c)
  • Adequacy decisions — where applicable under the EU-US Data Privacy Framework

n8n GmbH is based in Germany and processes data within the EU, with no international transfer required for core automation logic. Our Supabase database, including the Google OAuth tokens described in Section 4, is hosted in Ireland and stays within the EU.

11. Data sharing and disclosure

DS2 Agency does not sell, rent, or trade personal data. We share data only in the following circumstances:

  • With sub-processors: as described in Section 7, solely to deliver the contracted services
  • With business clients: conversation logs and lead data are accessible to the business client whose customers generated the data
  • With Meta: message content is transmitted to Meta's WhatsApp infrastructure to deliver messages. Meta's own privacy policy governs their use of this data
  • Legal requirements: if required by applicable law, court order, or governmental authority — subject to the safeguards described in Section 12

We do not use personal data obtained through the Meta Platform for advertising targeting, audience building, or any purpose beyond the direct provision of our automation services.

12. Requests from public authorities

DS2 Agency has not provided personal data to public authorities in response to national security requests in the past 12 months.

For any future requests, we have the following processes in place:

  • Review of legality: all requests are reviewed to confirm they have a valid legal basis before any data is disclosed
  • Challenge of unlawful requests: requests that are overbroad, lack legal basis, or violate fundamental rights will be challenged
  • Data minimisation: only the minimum data strictly required by the request will be disclosed
  • Documentation: all requests and our responses are documented, including the legal reasoning and the actors involved
  • Notification: where legally permitted, we will notify the affected data subject or business client before disclosing their data

13. Your rights

Under GDPR and applicable data protection law, you have the following rights regarding your personal data:

RightWhat it means
Access (Art. 15)Request a copy of the personal data we hold about you
Rectification (Art. 16)Request correction of inaccurate or incomplete data
Erasure (Art. 17)Request deletion of your data ("right to be forgotten")
Restriction (Art. 18)Request that we limit how we process your data
Portability (Art. 20)Receive your data in a structured, machine-readable format
Objection (Art. 21)Object to processing based on legitimate interests
Withdraw consentWithdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at seniga.trento@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority. In Germany, this is the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI).

14. Children's privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly. If you believe we have collected data from a child, please contact us immediately.

15. Cookies

The dashboards and applications hosted on davideai.com keep your signed-in session in your browser's local or session storage, not in persistent tracking cookies. This includes the authentication token issued by Supabase and a cached copy of your own profile, which stay on your device until you sign out or clear your browser data. We do not use tracking cookies, advertising cookies, or third-party analytics cookies on our platform pages.

The Meta JavaScript SDK loaded on our onboarding page (davideai.com/gioel/onboarding) may set cookies as part of the Facebook Login for Business flow. These are governed by Meta's Cookie Policy.

16. Changes to this policy

We may update this Privacy Policy to reflect changes in our services, legal requirements, or data processing practices. When we make material changes, we will update the "Last updated" date at the top of this page. Business clients will be notified of significant changes via email. Continued use of our services after changes take effect constitutes acceptance of the updated policy.

Previous versions of this policy are available on request.

17. Contact

For any questions, requests, or concerns regarding this Privacy Policy or our data processing practices, contact:

NameDavide Senigalliesi — DS2 Agency
Emailseniga.trento@gmail.com
Websitehttps://ds2.studio
CountryGermany

We aim to respond to all privacy-related inquiries within 72 hours and to resolve data subject requests within 30 days.

DS2 Studio
davide@ds2.studio Casi d'uso Privacy Terms © 2026