Legal
Privacy Policy
Last updated: July 17, 2026
1.General Information
This Privacy Policy describes how Liaisone.io, operated by Drum Class S.R.L. (Italy), processes personal and business data in accordance with Regulation (EU) 2016/679 (GDPR).
Liaisone.io is a B2B marketing platform: an AI agent that analyzes and, upon explicit user confirmation, manages Meta advertising on behalf of its business clients. The Company acts as a Data Processor, processing data strictly on behalf of its business clients and under their instructions.
2.Data We Process
Depending on enabled services and integrations, we may process:
- Account Data: email address, encrypted password
- Authentication Data: Google OAuth identifiers (email, profile ID)
- Advertising Data: ad account IDs, campaign IDs, ad set IDs, creative IDs
- Lead Data: Meta Lead ID, creation timestamps, form identifiers
- Contact Data: phone numbers, names, emails, only if transmitted by connected systems
- CRM Data: deal status, revenue, timestamps, internal lead identifiers
- Billing Data: subscription plan and payment status. Card details are processed by our payment provider (Stripe) and never stored on our servers
- Call Tracking Data: call metadata (timestamps, phone numbers, call outcome) when the user connects a telephony integration
We do not intentionally process sensitive personal data.
3.Advertising Platforms & APIs
Upon explicit authorization by the user, Liaisone.io integrates with Meta Platforms (Facebook / Instagram) via the Marketing API.
The platform may request the following permissions, each used only for the purpose described:
ads_management– read ad accounts, campaigns, ad sets, ads and their performance metrics to calculate attribution and efficiency (ROI, VALI).leads_retrieval– retrieve Meta Lead Ads form submissions (lead identifiers and the contact fields the user submitted) for connected accounts.pages_show_list– list the Pages the user manages so they can choose which Page(s) to connect.pages_read_engagement,pages_manage_ads– read Page and ad metadata required to associate ads, forms and leads correctly.pages_manage_metadata– subscribe our application to the selected Page'sleadgenwebhook so new leads are delivered to Liaisone.io in real time. Used only to manage the leadgen webhook subscription for Pages the user explicitly connects; we do not modify any other Page settings or content.business_management– resolve which ad accounts and Pages the user has authorized via Business Manager.public_profile– basic account identity used to authenticate the user.
These permissions are requested only after explicit user authorization and are used solely to retrieve advertising performance data, lead identifiers, and attribution information necessary to calculate marketing efficiency metrics such as ROI and VALI. We request only the access required for the features the user connects, and the user may revoke access at any time.
4.CRM Integrations
Users may connect third-party CRM systems (including but not limited to Kommo or similar platforms). CRM data is used exclusively to match leads, calculate revenue attribution, and provide analytics dashboards.
5.Webhooks & Automation
Liaisone.io may receive real-time data via secure webhooks from connected platforms. These webhooks are used solely for synchronization, analytics, and performance calculations.
For Meta, we subscribe the connected Page to the leadgen webhook (using pages_manage_metadata) so that new Lead Ads submissions are received as they occur.
6.AI Assistants & Conversational Access (Model Context Protocol)
Liaisone.io may be accessed through AI assistants that connect to our Model Context Protocol (MCP) server (for example, Anthropic Claude and OpenAI ChatGPT) over an OAuth 2.0 session that the user explicitly authorizes. When the user invokes a Liaison tool from within an AI assistant, the assistant transmits a tool request to our server and receives only the data scoped to that request: the same data the user could see in the Liaison web app. The MCP interface is read-only: no tool available to an assistant can create, modify, or delete anything in the user’s advertising or CRM accounts. Advertising changes are performed only inside the Liaison web application, each upon the user’s explicit confirmation.
- What we receive: the tool name and its parameters (for example, date range, account ID).
- What we return: the requested data from the user's connected ad accounts and CRM, scoped to the active member.
Data exchanged via MCP transits the AI provider's infrastructure under that provider's own privacy policy. Liaisone.io does not use data accessed via MCP to train any AI model, and does not share MCP traffic or user data with any third party other than the AI provider the user has chosen to authorize. The user may revoke authorization at any time from within the AI assistant or from their Liaison account settings.
7.Purpose of Processing
- Marketing performance analytics
- Lead attribution and revenue analysis
- Synchronization between advertising platforms and CRM systems
- Operation, security, and improvement of the platform
8.Legal Basis
Processing is based on:
- Article 6(1)(b) GDPR – performance of a contract (B2B)
- Article 6(1)(f) GDPR – legitimate business interest
9.Cookies & Tracking
Liaisone.io does not use advertising cookies or third-party tracking tools. Only essential technical mechanisms may be used for security and authentication.
10.Data Storage & Retention
All data are stored and processed within the European Economic Area (EEA). Data are retained only for the duration of the contractual relationship or until account deletion, unless otherwise required by law.
To operate the service we rely on the following sub-processors, which process data on our behalf under data-processing terms: Cloudflare (hosting, storage and content delivery), Memberstack (account authentication), Stripe (payment processing), and OpenAI (AI request processing for the Lia assistant; API traffic is not used to train models).
11.User Rights
Users may request access, correction, deletion, restriction, or portability of their data in accordance with GDPR.
Requests can be sent to: [email protected]