Privacy Policy — BNT Automation
Last updated: 19 August 2026
1. Who this policy is for
BNT Automation (“the App”) is a private, internal business tool operated by
[LEGAL ENTITY NAME] (“we”, “us”), a marketing agency with its registered address
at [FULL BUSINESS ADDRESS].
The App has no consumer users. Nobody signs up for it, logs into it, or installs
it. It is used only by our own staff to manage advertising and content on behalf
of businesses that have engaged us as their marketing agency (“Clients”), and it
acts on Client-owned Meta assets under authorisation those Clients grant us in
Meta Business Manager.
If you are a member of the public who interacted with an advertisement we
manage, section 6 explains how your information is handled and who controls it.
Contact: [PRIVACY CONTACT EMAIL] · [BUSINESS PHONE]
2. Our role
For the personal data of people who respond to our Clients’ advertisements, the
Client is the data controller and we act as a processor on their
documented instructions. We do not decide the purposes of that processing, and
we do not use that data for our own purposes.
For the operational data of our own staff accounts, we are the controller.
3. What the App accesses from Meta, and why
The App uses the Meta Marketing API with the following permissions. Each is
listed with the only use we make of it.
| Permission | What we do with it |
|---|---|
ads_management | Create and manage advertising campaigns, ad sets and ads in the Client’s own ad account. Campaigns are always created paused and require explicit human approval before they are enabled. |
ads_read | Read performance figures (spend, impressions, clicks, results) to produce reporting for the Client. |
business_management | Identify which ad accounts and Pages the Client has authorised us to work on. |
pages_show_list | List the Client’s Pages so the correct one can be selected. |
pages_manage_ads | Create instant lead forms on the Client’s Page, and use the Client’s own published posts as advertising creative. |
pages_read_engagement | Read public engagement counts (reactions, comments, shares) on the Client’s own posts, so a person can judge which post to promote. |
We do not request or use permissions to read private messages, friend lists,
personal profiles, or any data belonging to individuals who are not our
Client’s own business assets.
4. What we store, and for how long
The App stores the minimum needed to operate and report:
- Campaign and creative records — campaign, ad set and ad identifiers,
advertising copy, and references to the Client’s own images and videos.
- Aggregate performance data — spend, impressions, clicks and result counts.
This is statistical and does not identify individuals.
- Public post metadata — identifiers, captions, dates and public engagement
counts for the Client’s own posts.
- Operational logs — records of actions taken and errors encountered.
Records are held on our own systems for the duration of the engagement with the
Client and for up to [RETENTION PERIOD, e.g. 24 months] afterwards for
accounting and dispute-resolution purposes, then deleted.
We do not sell, rent, or share data with data brokers, and we do not use
Meta Platform Data to build profiles, to train machine-learning models, or for
any purpose other than delivering the service to the Client whose data it is.
5. Advertising creative
Advertising images and video come from material the Client supplies or has
already published. Where an illustrative image is generated with AI, it is used
only for decorative purposes and is never presented as a photograph of real work
performed by the Client.
6. If you responded to an advertisement
If you submitted an instant form on a Facebook or Instagram advertisement we
manage, the business that placed the advertisement — our Client — receives your
details and is the controller of them. Your information is delivered into that
Client’s own customer-relationship system and is used to respond to your
enquiry.
We do not retain a copy of your contact details for our own purposes, and we
do not use them to contact you on our own behalf.
To exercise your rights — access, correction, deletion, objection, or a copy of
your data — contact the business whose advertisement you responded to. You may
also contact us at [PRIVACY CONTACT EMAIL] and we will pass the request to
that Client and assist them in responding, ordinarily within 30 days.
7. Service providers
The App transmits data to the following providers, each only for the function
named. They act as sub-processors under contract.
| Provider | Purpose |
|---|---|
| Meta Platforms | Advertising delivery and reporting |
| Google (Drive, Search Console, Ads, Cloud AI) | Client asset storage, search reporting, advertising, image generation |
| GoHighLevel (LeadConnector) | The Client’s customer-relationship system, which receives leads |
| DataForSEO | Aggregate, non-personal search and keyword market data |
| Apify | Reading Meta’s public Ad Library for publicly disclosed advertising |
| Anthropic | Generating advertising copy from Client-supplied business information |
Data is processed in the [PRIMARY PROCESSING REGION, e.g. United States].
Where personal data of individuals in the EEA or UK is transferred, it is done
under Standard Contractual Clauses or another lawful transfer mechanism.
8. Data deletion
To request deletion of data the App holds, email [PRIVACY CONTACT EMAIL]
with the subject line “Data deletion request”, including the Facebook Page
or ad account concerned, or the advertisement you responded to.
We will confirm receipt within 5 business days and complete the deletion
within 30 days, except where we are required by law to retain a record. If
the data is controlled by one of our Clients, we will forward the request to
them and support them in fulfilling it.
Instructions are also published at [PUBLIC DELETION INSTRUCTIONS URL].
9. Security
Access to the App is restricted to authorised staff. API credentials are stored
as environment secrets, never committed to source control, and are rotated when
staff change or a credential is suspected of exposure. Access to Client assets
is granted through Meta Business Manager and is revoked when an engagement ends.
No system is perfectly secure. In the event of a breach affecting personal data,
we will notify the affected Client without undue delay so they can meet their
own notification obligations.
10. Children
The App is not directed at children, and we do not knowingly process the data of
anyone under 18. Advertising we manage is targeted to adults only.
11. Changes
We may update this policy. The “Last updated” date above will change, and
material changes will be communicated to affected Clients.
12. Contact
BNT Projects LLC
7901 4th St N, St. Petersburg, FL, 33702
office@bnt-projects.com
7272395814