Privacy policy
Last updated: 9 July 2026 · Version 1.0
This policy explains how SellFactory ("SellFactory", "we"), a product operated by CG Comunicazione Globale, handles personal data. We apply the EU General Data Protection Regulation (GDPR) as our standard. The policy covers two distinct groups: visitors to this website, and customers of the platform.
A. Visitors to this website
What we collect
If you contact us (for example by email or an information request), we receive the details you choose to send us — typically your name, company, email address and message. This website uses only technical cookies necessary for it to function; it does not use advertising or profiling cookies.
Why, and on what basis
We use this information to reply to you and to evaluate early-access enquiries, on the basis of your request and our legitimate interest in responding. We do not sell your data and do not use it for automated profiling.
Retention
We keep enquiry correspondence only as long as needed to handle your request and any resulting relationship, then delete it.
B. Customers of the platform
Roles
For account data (users, workspace configuration) SellFactory acts as data controller. For the commerce and advertising data a customer connects through authorized integrations, SellFactory acts as a data processor on the customer's behalf and under the customer's instructions.
Categories of data
- Account data: user name, email, role, workspace settings.
- Connected commerce data: sales, orders, products and advertising performance retrieved through integrations that the customer authorizes.
In its current design, the platform is built not to collect end-buyer personal information (such as buyer names, shipping addresses or invoices). When marketplace integrations go live, they will request only the minimum data scopes required for the analytics we describe.
Bring-your-own AI
AI features operate under a bring-your-own-provider model: the customer selects and controls their own AI provider. Customer data is not used to train AI models. Any transfer of data to an AI provider, and any resulting international transfer, follows the provider chosen by the customer.
Sub-processors
We use hosting infrastructure located in the European Union. AI processing, where enabled, is performed by the provider the customer chooses. We limit sub-processors to what is necessary to run the service.
Security
We protect data with tenant isolation enforced at the database, encryption of connected-account credentials, hashed session tokens and audit logging. See our data-protection overview.
Retention & deletion
Connected commerce data is deleted when a customer revokes an integration or ends the service, subject to any short technical retention needed for backups.
Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. You may also lodge a complaint with your supervisory authority (in Italy, the Garante per la protezione dei dati personali). To exercise your rights, contact us at g.contaldi@cgcomunicazioneglobale.com.
Contact
Data controller: CG Comunicazione Globale (SellFactory). Email: g.contaldi@cgcomunicazioneglobale.com. Full legal details (registered office and VAT number) are available on request and will be added here on publication of the reviewed version.