Privacy Policy
How Bellerofonte collects, uses and deletes data, with a dedicated section on data obtained from Meta platforms (Facebook and Instagram).
Last updated: 2026-09-20
This is the English translation of the Italian original, which prevails in case of discrepancy. Both versions are public and require no login.
1. Who processes the data
Bellerofonte is the social and media intelligence platform operated by the
Controller at https://dashboard.bellerofontedata.com.
2. What Bellerofonte does
Bellerofonte analyses the public communication of organisations: public bodies, companies, publishers, Pages and professional accounts. A customer connects the social channels they own or are entitled to monitor, and the platform computes aggregate indicators — publishing cadence, interactions received, overall sentiment of the responses, recurring keywords and topics, period-over-period comparisons.
Bellerofonte is not a people-surveillance tool. We do not build dossiers on individuals, we do not track individuals over time, we do not infer protected attributes (ethnicity, religion, political opinions, health, sexual orientation), and we do not use the data to determine anyone's eligibility for employment, housing, credit or insurance. Comments ingested from Meta's APIs are stored without an author: Meta does not provide us with the identity of the person who commented, and we do not ask for it. The other limits we set ourselves are described on the How we handle Meta Platform Data page.
3. What data we process
3.1 Platform user data
- account data: first and last name, email address, the Google identifier used to sign in, if applicable;
- technical session data: session and CSRF cookies (see the cookie policy), application logs recording date, time and outcome of operations;
- access tokens issued by connected platforms, stored encrypted.
3.2 Data from monitored channels
- public channel information: name, username, identifier, description, profile picture, follower count;
- content published by the channel: post text, timestamp, permalink, media type, the media reference on the source platform's CDN, counts of reactions, shares and comments;
- the text of public comments received by the channel's content;
- channel and media insights, where the channel owner made them available by connecting the channel.
Channel content may contain third parties' personal data — for instance the text of a comment written by an individual. We process it to compute aggregate indicators about the channel, not to profile the author.
4. Data obtained from Facebook and Instagram
When a customer connects a Facebook Page or an Instagram professional account,
we access data exclusively through Meta's official APIs
(graph.facebook.com), using the permissions the customer explicitly
grants in the Facebook authorisation dialog. We do not collect data from Facebook
or Instagram by any automated means other than the official APIs, and we never
request anyone's Facebook or Instagram login credentials.
These are the permissions we request and what we do with them:
| Permission | Data accessed | Purpose |
|---|---|---|
instagram_basic |
Username, ID, profile picture and biography of the connected Instagram professional account; the list and metadata of its published media. | Identify the connected channel inside the platform and attribute content to the correct channel. |
instagram_manage_insights |
Account and media insights (reach, views, interactions, saves, follower trend); public data about other professional accounts through Business Discovery. | Build the channel's performance charts and the comparisons against the public benchmark accounts the customer selected. |
pages_show_list |
The list of Facebook Pages the user administers. | Show the user which Pages they can connect and verify they administer them. Required as a technical dependency of the Instagram permissions. |
pages_read_engagement |
Content published by the Page, Page metadata and Page engagement data. | Read the connected Page's content and engagement, and support the Instagram permissions above. |
What we do not do with these permissions. We do not publish content on the customer's behalf, we do not handle private messages, we do not use advertising data, we do not sell or license data obtained from Meta — including aggregated or derived data — and we do not combine it with other sources at individual-person level.
Data belonging to one customer is kept separate from every other customer's data. A customer only sees the channels in their own project.
5. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service to the platform user (account, access, support). | Art. 6(1)(b) — performance of a contract. |
| Analysing the channels the customer connected or designated for monitoring. | Art. 6(1)(b) towards the customer; for third parties' personal data contained in public content, Art. 6(1)(f) — the channel owner's legitimate interest in understanding how their public communication is received. |
| Platform security, logging, abuse prevention. | Art. 6(1)(f) — legitimate interest. |
| Legal obligations and obligations towards Meta (deletions, audits). | Art. 6(1)(c) — legal obligation; Art. 6(1)(b) — contractual obligations towards Meta. |
6. Who can see the data
Bellerofonte has no public feed, directory or search over Meta-sourced content and comments: to consult them you have to be an authenticated user of the project the channel belongs to.
- In full form it is accessible to the Controller's authorised internal staff, solely for service delivery, data quality control and support. Access is named and individual.
- To the customer, only the channels in their own project are visible.
- In aggregate form, stripped of personal identifiers, it feeds the platform's indicators: sentiment, keywords, topics, trends, reports.
7. Analysis, anonymisation and derived data
We run automated processing on the collected text: sentiment analysis, keyword and topic extraction, summarisation, trend indicators. The output is an aggregate per channel, per period or per topic: we do not produce profiles of individuals and we do not tie indicators to an identified person.
Language processing runs on models hosted on the Controller's own infrastructure. Where a specific feature requires sending text to an external language-model provider, that provider is listed on the Processors page and is bound by a written agreement to process data only on our behalf.
When we delete a record, we also delete the derived outputs that remain associable with it (for example that comment's sentiment score). Only aggregates that can no longer be associated with a particular user, browser or device are retained.
8. How long we keep it
| Category | Retention |
|---|---|
| Meta-sourced content, comments and metrics | 90 days from publication, then automatic deletion. |
| Meta access tokens | Until revocation, expiry or channel disconnection; then deleted. |
| Aggregate indicators not associable with individuals | For the duration of the customer relationship. |
| Platform user account data | For the duration of the relationship and any subsequent statutory period. |
| Application and security logs | 12 months. |
| Deletion requests and their outcome | 24 months, as evidence of compliance. |
We delete Meta-sourced data without waiting for expiry when: the channel is disconnected, consent is withdrawn, the user removes the application from their Facebook settings, the data subject requests it, or Meta or the law requires it.
Deletion of the content on the source platform is not one of those cases: if a post or a comment is removed on Facebook or Instagram we do not notice on our own, because we do not re-read already ingested content to check that it still exists. Our copy goes away with expiry, with the disconnection of the channel, or on a deletion request.
9. Who we share it with
We do not sell, license or transfer the data. We share it only with vendors providing us technical services, appointed as processors under a written agreement pursuant to Art. 28 GDPR: the current list is on the Processors page.
We may also disclose data to judicial or other authorities where required by law, and to Meta when requested in the exercise of its audit rights under the Platform Terms.
10. Transfers outside the EEA
Bellerofonte's infrastructure and its language-analysis models are located within the European Economic Area. Where a vendor would involve a transfer to a third country, this is stated on the Processors page and covered by an adequacy decision or by the European Commission's Standard Contractual Clauses.
11. How we protect it
- encrypted transport (HTTPS/TLS);
- access tokens and application credentials encrypted at rest and never written to logs in cleartext;
- system access restricted to authorised, individually named staff;
- data separated per project and per customer;
- a vulnerability reporting channel described on the Security page;
- in the event of a personal data breach, notification to the supervisory authority within 72 hours and to Meta without delay.
We do not list as controls what is not yet in operation: multi-factor authentication on administrative tooling, a centralised access log subject to periodic review, and a tested incident response plan are planned work, not active measures.
12. Your rights, and how to delete your data
You may exercise the rights under Articles 15–22 GDPR at any time: access, rectification, erasure, restriction, portability and objection. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
To request deletion — even if you are not a customer and have never held an account with us — use the public form:
You will receive a code to track the status of your request. If you connected a Meta account to Bellerofonte, you can also remove the application from your Facebook account settings: we receive the notification from Meta and proceed with deletion without any further action on your part.
For any other request, write to privacy@piavedigitalagency.it. We respond within 30 days.
13. Changes to this policy
If the purposes or the categories of processed data change, we update this page and the date at the top. Changes that broaden the processing of data already collected are communicated to the affected customers before taking effect.