DS2 Agency is a digital automation agency operated as a sole proprietorship by Davide Senigalliesi, based in Germany. We design and operate automated communication systems for small and medium-sized businesses, with a primary focus on WhatsApp Business automation built on the Meta WhatsApp Business Platform Cloud API.
| Legal name | Davide Senigalliesi (trading as DS2 Agency) |
|---|---|
| Country | Germany |
| seniga.trento@gmail.com | |
| Website | https://ds2.studio |
| Data controller | Davide Senigalliesi |
As the data controller, DS2 Agency determines the purposes and means of processing personal data obtained through our services and through the Meta Platform.
This policy covers:
It applies to end users (customers of our business clients who interact via WhatsApp), business clients who connect their WhatsApp Business Accounts to our platform, users of the Gesigroup claims portal (Gesigroup's employees and Gesigroup's own clients), and administrators who access our dashboards.
DS2 Agency is registered as an Independent Tech Provider on the Meta WhatsApp Business Platform. Our Meta App (Gioel Servizio Clienti, App ID: 1258577862899321) holds the following approved permissions:
We use whatsapp_business_messaging exclusively to:
We use whatsapp_business_management exclusively to:
We do not use Meta Platform data for advertising, profiling, or any purpose outside the direct delivery of automation services to our clients. All data obtained through Meta permissions is used strictly in accordance with the Meta Platform Terms and the applicable WhatsApp Business Policy.
When a business client connects their WhatsApp Business Account through our onboarding page, they go through the Meta Embedded Signup flow. During this flow, Meta issues an OAuth authorisation code, which our backend exchanges for a user access token. This token is used solely to register the client's WABA with our platform and is stored securely. We do not use this token for any purpose other than managing the client's WhatsApp Business assets as described above.
Some of our applications let a user sign in with their own Google Account, and one of them additionally lets a user connect their own Google Calendar so they can work with it inside the app. This section states exactly which Google data each application accesses, why, where it is stored, and how to revoke access at any time. Two DS2 Agency applications currently request Google authorisation: the Gioel Leads sales app at davideai.com/gioel/leads (OAuth client "Gioel Leads App Calendar Connection"), covered by 4a-4e below, and the Gesigroup claims portal at ds2.studio/gesigroup (OAuth client "Gesigroup"), covered separately in 4f.
Connecting a Google Account for the Gioel Leads Calendar feature is always optional — that app is fully usable without it, the calendar features are simply hidden. For Gesigroup, signing in with Google is the only way to reach the portal at all (see 4f).
| Scope | What it allows | Why we request it |
|---|---|---|
openid, email, profile |
Read the account's email address, name, and profile picture | "Sign in with Google" — used only to identify the user and match them to their existing app account |
https://www.googleapis.com/auth/calendar.events |
View and edit events on the signed-in user's calendars | Show the user their own busy and free slots for the next 7 to 14 days while they are booking a customer appointment, and write the appointment they confirm into their own calendar |
We request no other Google scope. We do not access Gmail, Google Drive, Google Contacts, Google Photos, or any other Google service, and we never request access to anyone else's calendar — only the calendar of the signed-in user.
So that a user does not have to sign in again every hour, we store the OAuth tokens Google issues for that user in our database (table user_google_tokens, Supabase project hosted in the European Union, region eu-west-1, Ireland). Per user we store:
Row-level security in the database restricts every row to the user who owns it, so one user's tokens are never readable by another user. Tokens are transmitted over HTTPS only and are used exclusively to call the Google Calendar API on behalf of that same user.
Revoking access removes the calendar features from the app and nothing else. Appointments already written to your calendar remain in your calendar and are yours to keep or delete. Appointment data you entered in the app stays in the app and follows the retention rules in Section 9.
The Gesigroup claims portal at ds2.studio/gesigroup uses Google for one purpose only: signing users in. Its users are Gesigroup employees and Gesigroup's own clients (people with an active damage or injury compensation claim handled by Gesigroup).
openid, email, profile only — the same identity scopes listed in the table in Section 4a. Gesigroup never requests Calendar, Drive, Contacts, Gmail, or any other Google scope, and this Limited Use commitment applies to it too.| Data type | Source | Purpose |
|---|---|---|
| WhatsApp Business Account ID (WABA ID) | Embedded Signup / Graph API | Identify and manage client WABA |
| Phone Number ID | Embedded Signup / Graph API | Send and receive messages |
| User access token | OAuth code exchange | Authenticate API calls on behalf of client |
| Inbound message content | Webhook events | Process customer replies in automation flows |
| Message status events | Webhook events | Track delivery and read receipts |
| Business profile name and phone | Graph API | Display in client dashboard |
| Message template status | Graph API | Monitor template approval status |
| Data type | How collected | Purpose |
|---|---|---|
| WhatsApp phone number | Inbound message webhook | Identify the customer in the automation flow |
| Message content (text, button replies) | Inbound message webhook | Route the customer through the correct automation step |
| Name (if provided) | Client lead form or message content | Personalise outbound messages |
| Appointment or booking data | Client lead form | Schedule and confirm appointments via WhatsApp |
We collect only the minimum data necessary to operate the automation service. We do not collect sensitive personal data (such as health, financial, or government ID data) unless explicitly required and agreed with the client.
Gesigroup is a DS2 Agency client, in the same sense as the business clients in 5c: Gesigroup is the data controller for the data in this section, and DS2 Agency processes it on Gesigroup's instructions, operating the portal on Gesigroup's behalf. This is deliberately different from Sections 5a-5c above, which describe our own WhatsApp automation platform.
| Data type | Source | Purpose |
|---|---|---|
| Name, email, phone number | Entered by a Gesigroup employee, or by the client directly | Identify the case owner and let them sign in |
| Case code and case status | Imported from Gesigroup's own case-management system by a Gesigroup employee | Show the client where their claim currently stands |
| Identity documents and health/medical records uploaded by the client | Uploaded by the client through the portal | Give Gesigroup the supporting documents it needs to progress the claim |
| Notification history | Generated by the app on every case-status change | Replace the phone/WhatsApp status updates Gesigroup used to send manually |
Special category data (GDPR Art. 9). Identity documents and health/medical records are special category personal data. We process them because a Gesigroup client chooses to upload them directly, to support a damage or injury compensation claim Gesigroup is pursuing on that client's behalf — necessary for the establishment and exercise of a legal claim (Art. 9(2)(f)). Document categorisation runs entirely inside our own server process — self-hosted text recognition and image processing, no third-party API — so the document image itself is never sent to any outside service. A client sees only the documents they uploaded themselves, never another client's file; Gesigroup employees see full case files, restricted to their authorised role.
This data is stored in a separate Supabase project dedicated to Gesigroup (distinct from the sales-apps project described elsewhere in this policy), under the same encryption, access-control, and row-level-security approach described in Section 8.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Deliver WhatsApp automation services to business clients | Art. 6(1)(b) — contract performance |
| Onboard client WABAs via Embedded Signup | Art. 6(1)(b) — contract performance |
| Process inbound messages and route automation flows | Art. 6(1)(b) — contract performance |
| Store conversation logs for client dashboards | Art. 6(1)(f) — legitimate interests (service delivery and audit) |
| Improve and maintain the platform | Art. 6(1)(f) — legitimate interests |
| Comply with legal obligations | Art. 6(1)(c) — legal obligation |
| Send automated messages to end users | Art. 6(1)(a) — consent (obtained by the business client through their customer communication flow) |
DS2 Agency uses the following sub-processors to deliver its services. All sub-processors are bound by data processing agreements and operate under their own privacy and security policies.
| Processor | Country | Purpose | Policy |
|---|---|---|---|
| n8n GmbH (n8n.io) | Germany / EU | Workflow automation — all automation logic runs on n8n Cloud. Message routing, API calls, and data transformations are executed here. | n8n Privacy Policy |
| Google LLC | USA (EU SCCs apply) | Google Sign-In for authentication; Google Calendar API for the calendar features described in Section 4; Google Sheets as the data store of some automation workflows; Google Maps Platform for address search and map display in the sales apps. | Google Privacy Policy |
| Supabase Inc. | EU (region eu-west-1, Ireland) | Database, authentication, and file storage for the sales applications. Contact records, appointment data, user accounts, and the Google OAuth tokens described in Section 4 are stored here. | Supabase Privacy Policy |
| Meta Platforms, Inc. | USA (EU SCCs apply) | WhatsApp Business Platform — message delivery infrastructure, webhook events, Graph API. | Meta Privacy Policy |
| Netlify, Inc. | USA (EU SCCs apply) | Hosting of all davideai.com frontend applications including client dashboards and onboarding pages. | Netlify Privacy Policy |
DS2 Agency remains fully responsible for ensuring that all sub-processors handle data in compliance with GDPR and this Privacy Policy. We do not authorise sub-processors to use personal data for their own purposes.
We implement appropriate technical and organisational measures to protect all personal data against unauthorised access, loss, alteration, or disclosure.
| Data type | Retention period |
|---|---|
| WhatsApp conversation logs | 12 months from last message, or until client requests deletion |
| Lead and customer records | Duration of the client contract + 6 months |
| OAuth access tokens | Until revoked by the client or the token expires |
| Google OAuth tokens (access, refresh) | Until the user disconnects Google Calendar in the app, revokes access from their Google Account, or their app account is deleted — whichever comes first |
| Workflow configuration data | Duration of the client contract |
| Error and execution logs | 30 days |
After the applicable retention period, data is deleted or anonymised. Business clients may request early deletion of their data at any time. End users may request deletion of their data through the business client, who will forward the request to DS2 Agency.
Some of our sub-processors (Google LLC, Meta Platforms, Netlify) are based in the United States. When personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, including:
n8n GmbH is based in Germany and processes data within the EU, with no international transfer required for core automation logic. Our Supabase database, including the Google OAuth tokens described in Section 4, is hosted in Ireland and stays within the EU.
DS2 Agency does not sell, rent, or trade personal data. We share data only in the following circumstances:
We do not use personal data obtained through the Meta Platform for advertising targeting, audience building, or any purpose beyond the direct provision of our automation services.
DS2 Agency has not provided personal data to public authorities in response to national security requests in the past 12 months.
For any future requests, we have the following processes in place:
Under GDPR and applicable data protection law, you have the following rights regarding your personal data:
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten") |
| Restriction (Art. 18) | Request that we limit how we process your data |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw consent at any time where processing is based on consent |
To exercise any of these rights, contact us at seniga.trento@gmail.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority. In Germany, this is the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI).
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly. If you believe we have collected data from a child, please contact us immediately.
The dashboards and applications hosted on davideai.com keep your signed-in session in your browser's local or session storage, not in persistent tracking cookies. This includes the authentication token issued by Supabase and a cached copy of your own profile, which stay on your device until you sign out or clear your browser data. We do not use tracking cookies, advertising cookies, or third-party analytics cookies on our platform pages.
The Meta JavaScript SDK loaded on our onboarding page (davideai.com/gioel/onboarding) may set cookies as part of the Facebook Login for Business flow. These are governed by Meta's Cookie Policy.
We may update this Privacy Policy to reflect changes in our services, legal requirements, or data processing practices. When we make material changes, we will update the "Last updated" date at the top of this page. Business clients will be notified of significant changes via email. Continued use of our services after changes take effect constitutes acceptance of the updated policy.
Previous versions of this policy are available on request.
For any questions, requests, or concerns regarding this Privacy Policy or our data processing practices, contact:
| Name | Davide Senigalliesi — DS2 Agency |
|---|---|
| seniga.trento@gmail.com | |
| Website | https://ds2.studio |
| Country | Germany |
We aim to respond to all privacy-related inquiries within 72 hours and to resolve data subject requests within 30 days.