Legal

Privacy Policy

Last updated: 9 September 2026

This Policy explains how Scicolone Consulting FZ-LLC, operating the Pitch Peasy website and service, handles personal data. Pitch Peasy is a business-to-business service for people aged 18 or over. Questions and privacy requests can be sent to privacy@pitchpeasy.com.

1. Who is responsible for your data

Scicolone Consulting FZ-LLC is registered in the RAKEZ Free Zone under registration number 0000004092258 and services licence 47034656. Its registered address is FDBC1714, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.

We act as controller for account administration, security, support, website measurement, marketing and our business operations. When a customer uploads a brief, connects a platform or asks Pitch Peasy to produce work using customer data, we normally act as processor or subprocessor under the customer's instructions. Agency customers are responsible for having authority from their clients and users to provide that data.

2. Data we collect

  • Account details, such as name, business email, organisation, role and authentication data.
  • Project content, including briefs, files, instructions, client context, sources and deliverables.
  • Connected-platform data, account identifiers, authorised scopes, reports and aggregated metrics.
  • AI-assisted work, including structured requirements, research, strategy, drafts and approvals.
  • Technical data, such as IP address, device, browser, session, security, error and performance data.
  • Website activity, campaign attribution, advertising identifiers and interaction recordings.
  • Support messages, privacy requests, marketing preferences and consent records.
  • Contract, billing, subscription, invoice and payment metadata. If self-service billing is enabled, the checkout identifies its payment provider before payment.

Customers must not submit children's data or sensitive data such as health, biometric, precise location, government identifier or highly sensitive financial information unless we have expressly approved that use in writing after a separate assessment.

3. Why we use personal data

  • To provide, administer, secure and support Pitch Peasy and perform our contracts.
  • To process customer content and connected-platform data on documented customer instructions.
  • To prevent misuse, investigate incidents and protect customers, users and the service.
  • To measure website and product use, understand journeys and improve performance.
  • To measure advertising, build audiences and run retargeting where the user has consented.
  • To send service messages and, where permitted, marketing messages that can be unsubscribed from.
  • To meet legal, tax, record-keeping and dispute-resolution obligations.

Depending on the activity and location, we rely on contract, legal obligations, legitimate interests or consent. Analytics, advertising pixels, retargeting and heatmaps are disabled until consent where consent is required. Consent can be withdrawn at any time through Cookie Settings or the unsubscribe link in a marketing email.

4. AI and connected platforms

Pitch Peasy uses AI to structure briefs, analyse approved information, support research and strategy, and draft deliverables. Outputs can be incomplete or wrong and require meaningful human review before use. Connected-platform queries are limited to the customer-selected account, purpose and permissions.

We do not use customer content or connected-platform data to train a shared Pitch Peasy model or a third party's shared model, and we do not opt that data into voluntary provider training or feedback. We send only the data needed for the requested function to an approved provider.

5. Analytics, advertising and communications

With consent, we use Google Analytics 4 to understand use and campaign performance. Optional heatmap tools such as Hotjar and advertising pixels remain inactive unless they are deployed, identified in Cookie Settings and accepted for their category. An active email provider, including Brevo if enabled, is identified in the relevant communication. Marketing messages identify the sender and include an unsubscribe option.

We use Sentry for operational error and performance monitoring. Its configuration is intended to minimise personal data and exclude customer content. Authentication and security cookies remain active because the requested service cannot operate safely without them. See our Cookie Policy.

6. Who receives data

We share data only as needed with approved providers for authentication, database and storage, hosting, AI processing, monitoring, analytics, heatmaps, communications, advertising and payments; with platforms a customer chooses to connect; with professional advisers under confidentiality; and where required by law or necessary to protect rights and safety. Active providers are reviewed before receiving customer personal data. We do not sell customer content.

Advertising partners may use consented identifiers for measurement, audience creation and retargeting under their own terms. Users can refuse or withdraw this consent through Cookie Settings.

7. International transfers

We operate from the United Arab Emirates and use providers that may process data in other countries. Where required, we use recognised adequacy decisions, contractual safeguards or other valid transfer mechanisms and apply additional technical and organisational safeguards appropriate to the data.

8. How long we keep data

  • Project content and deliverables: while active and normally for 24 months after the last substantive activity.
  • Inactive workspaces: normally closed after 24 months of inactivity with at least 30 days' notice.
  • Closed accounts: a 30-day export window, followed by primary-system deletion within 30 further days.
  • Backups: removed through the rolling backup cycle within 90 days after primary deletion.
  • Security and operational logs: normally 12 months.
  • Support and privacy cases: normally three years after closure.
  • Consent, contract, incident and material compliance records: normally six years.
  • Tax and billing records: for the period required by applicable law.

A shorter legal, contractual, customer or provider limit takes priority. We may retain a restricted subset for a documented legal hold, security investigation or legal obligation.

9. Security

We use access controls, tenant separation, private storage, encryption for connector credentials, scoped authorisation, input validation, logging safeguards, bounded AI operations, provenance and human approvals. No system is completely secure. Valentino Scicolone owns privacy and incident escalation, with Francesco Frigento as deputy.

10. Your choices and rights

Depending on your location, you may ask to access, correct, delete, restrict or receive your personal data; object to certain processing; withdraw consent; opt out of targeted advertising; appeal a decision; or complain to a regulator. Email privacy@pitchpeasy.com and identify your account, organisation and request. We may verify identity and authority. If the data belongs to a customer workspace, we will normally coordinate the request with that customer.

11. Changes and contact

We will update the date above and provide appropriate notice before a material change takes effect. Privacy requests and complaints: privacy@pitchpeasy.com. Product and customer support: support@pitchpeasy.com.