This policy covers two distinct things: the website holtibitri.com, and the LinkedIn application “Holti Bitri Publishing”. They process different data and are described separately below.
1. Data controller
The data controller is Holti Bitri, a natural person based in Milan, Italy, acting in a personal capacity for both the website and the LinkedIn application. Neither is operated on behalf of an employer or a commercial entity.
Contact: info@holtibitri.com
2. The website holtibitri.com
Analytics
This site uses Umami Cloud to count page views. Umami is a privacy-focused analytics tool: it sets no cookies, does not use fingerprinting, does not track visitors across websites, and does not collect data that identifies an individual. The data collected is aggregated and limited to page URL, referrer, approximate country, browser, operating system and device type.
Hosting and server logs
The site is a set of static files hosted on GitHub Pages (GitHub, Inc.). As with any web server, GitHub processes technical connection data, including the visitor IP address, in order to deliver the pages. This processing is governed by the GitHub Privacy Statement.
Web fonts
The site loads typefaces from Google Fonts, which requires your browser to contact fonts.googleapis.com and fonts.gstatic.com. Your IP address is visible to Google as part of that request.
If you write to info@holtibitri.com, the address and the content of the message are used solely to reply to you. They are not added to any mailing list and are not shared.
3. The LinkedIn application “Holti Bitri Publishing”
This application has exactly one user: its owner. It is a personal tool used to publish posts to the owner’s own LinkedIn profile through the official LinkedIn API. It is not offered to third parties, has no sign-up, and does not process data belonging to other people.
What the application accesses
| Permission | What it is used for |
|---|---|
openid, profile |
To retrieve the owner’s own LinkedIn member identifier, which the API requires as the author of every post. |
w_member_social |
To publish posts to the owner’s own LinkedIn profile. |
What the application does not do
- It does not read or store the owner’s connections, messages, or contact list.
- It does not read or store content belonging to other LinkedIn members.
- It does not collect data about the people who view or interact with the published posts.
- It does not post on behalf of anyone other than its owner.
- It does not use automated browsing or scraping of the LinkedIn interface. All access is through the official LinkedIn API.
Storage and retention
The OAuth access token issued by LinkedIn is stored in a configuration file on private infrastructure under the sole control of the data controller. It is never transmitted to any third party, never sent to an external service, and never included in logs. The token expires automatically after the period set by LinkedIn, and is deleted or replaced when it expires or when access is revoked.
No copy of LinkedIn profile data is retained beyond the member identifier required to compose an API request. Published post content originates from the owner and is stored in the owner’s own private notes and task systems, not collected from LinkedIn.
Revoking access
Access granted to this application can be revoked at any time from LinkedIn: Settings & Privacy → Data privacy → Other applications → Permitted services. Revocation invalidates the token immediately.
4. Sharing with third parties
No personal data is sold, rented, or shared for advertising or profiling purposes. There are no advertising networks, no data brokers, and no third-party marketing tools on this site or in the application. The only external parties involved are the technical providers named above (GitHub Pages, Umami Cloud, Google Fonts, LinkedIn), each acting strictly to deliver the service described.
5. Legal basis and your rights
Under the General Data Protection Regulation (EU) 2016/679, the processing described here rests on the legitimate interest of operating a personal website and a personal publishing tool, and, for the LinkedIn application, on the explicit consent given by the owner through the OAuth authorisation flow.
You have the right to request access to your personal data, and its rectification, erasure, restriction, or portability, as well as the right to object to processing. Requests can be sent to info@holtibitri.com and will be answered within 30 days.
You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.
6. Changes to this policy
If this policy changes, the revised version is published at this address and the “last updated” date at the top is amended. Material changes affecting how data is processed will be reflected here before the change takes effect.
7. Contact
Questions about this policy: info@holtibitri.com