Privacy Policy — BNT Automation

Last updated: 19 August 2026


1. Who this policy is for

BNT Automation (“the App”) is a private, internal business tool operated by

[LEGAL ENTITY NAME] (“we”, “us”), a marketing agency with its registered address

at [FULL BUSINESS ADDRESS].

The App has no consumer users. Nobody signs up for it, logs into it, or installs

it. It is used only by our own staff to manage advertising and content on behalf

of businesses that have engaged us as their marketing agency (“Clients”), and it

acts on Client-owned Meta assets under authorisation those Clients grant us in

Meta Business Manager.

If you are a member of the public who interacted with an advertisement we

manage, section 6 explains how your information is handled and who controls it.

Contact: [PRIVACY CONTACT EMAIL] · [BUSINESS PHONE]


2. Our role

For the personal data of people who respond to our Clients’ advertisements, the

Client is the data controller and we act as a processor on their

documented instructions. We do not decide the purposes of that processing, and

we do not use that data for our own purposes.

For the operational data of our own staff accounts, we are the controller.


3. What the App accesses from Meta, and why

The App uses the Meta Marketing API with the following permissions. Each is

listed with the only use we make of it.

PermissionWhat we do with it
ads_managementCreate and manage advertising campaigns, ad sets and ads in the Client’s own ad account. Campaigns are always created paused and require explicit human approval before they are enabled.
ads_readRead performance figures (spend, impressions, clicks, results) to produce reporting for the Client.
business_managementIdentify which ad accounts and Pages the Client has authorised us to work on.
pages_show_listList the Client’s Pages so the correct one can be selected.
pages_manage_adsCreate instant lead forms on the Client’s Page, and use the Client’s own published posts as advertising creative.
pages_read_engagementRead public engagement counts (reactions, comments, shares) on the Client’s own posts, so a person can judge which post to promote.

We do not request or use permissions to read private messages, friend lists,

personal profiles, or any data belonging to individuals who are not our

Client’s own business assets.


4. What we store, and for how long

The App stores the minimum needed to operate and report:

  • Campaign and creative records — campaign, ad set and ad identifiers,

advertising copy, and references to the Client’s own images and videos.

  • Aggregate performance data — spend, impressions, clicks and result counts.

This is statistical and does not identify individuals.

  • Public post metadata — identifiers, captions, dates and public engagement

counts for the Client’s own posts.

  • Operational logs — records of actions taken and errors encountered.

Records are held on our own systems for the duration of the engagement with the

Client and for up to [RETENTION PERIOD, e.g. 24 months] afterwards for

accounting and dispute-resolution purposes, then deleted.

We do not sell, rent, or share data with data brokers, and we do not use

Meta Platform Data to build profiles, to train machine-learning models, or for

any purpose other than delivering the service to the Client whose data it is.


5. Advertising creative

Advertising images and video come from material the Client supplies or has

already published. Where an illustrative image is generated with AI, it is used

only for decorative purposes and is never presented as a photograph of real work

performed by the Client.


6. If you responded to an advertisement

If you submitted an instant form on a Facebook or Instagram advertisement we

manage, the business that placed the advertisement — our Client — receives your

details and is the controller of them. Your information is delivered into that

Client’s own customer-relationship system and is used to respond to your

enquiry.

We do not retain a copy of your contact details for our own purposes, and we

do not use them to contact you on our own behalf.

To exercise your rights — access, correction, deletion, objection, or a copy of

your data — contact the business whose advertisement you responded to. You may

also contact us at [PRIVACY CONTACT EMAIL] and we will pass the request to

that Client and assist them in responding, ordinarily within 30 days.


7. Service providers

The App transmits data to the following providers, each only for the function

named. They act as sub-processors under contract.

ProviderPurpose
Meta PlatformsAdvertising delivery and reporting
Google (Drive, Search Console, Ads, Cloud AI)Client asset storage, search reporting, advertising, image generation
GoHighLevel (LeadConnector)The Client’s customer-relationship system, which receives leads
DataForSEOAggregate, non-personal search and keyword market data
ApifyReading Meta’s public Ad Library for publicly disclosed advertising
AnthropicGenerating advertising copy from Client-supplied business information

Data is processed in the [PRIMARY PROCESSING REGION, e.g. United States].

Where personal data of individuals in the EEA or UK is transferred, it is done

under Standard Contractual Clauses or another lawful transfer mechanism.


8. Data deletion

To request deletion of data the App holds, email [PRIVACY CONTACT EMAIL]

with the subject line “Data deletion request”, including the Facebook Page

or ad account concerned, or the advertisement you responded to.

We will confirm receipt within 5 business days and complete the deletion

within 30 days, except where we are required by law to retain a record. If

the data is controlled by one of our Clients, we will forward the request to

them and support them in fulfilling it.

Instructions are also published at [PUBLIC DELETION INSTRUCTIONS URL].


9. Security

Access to the App is restricted to authorised staff. API credentials are stored

as environment secrets, never committed to source control, and are rotated when

staff change or a credential is suspected of exposure. Access to Client assets

is granted through Meta Business Manager and is revoked when an engagement ends.

No system is perfectly secure. In the event of a breach affecting personal data,

we will notify the affected Client without undue delay so they can meet their

own notification obligations.


10. Children

The App is not directed at children, and we do not knowingly process the data of

anyone under 18. Advertising we manage is targeted to adults only.


11. Changes

We may update this policy. The “Last updated” date above will change, and

material changes will be communicated to affected Clients.


12. Contact

BNT Projects LLC

7901 4th St N, St. Petersburg, FL, 33702

office@bnt-projects.com

7272395814