← back to the site matteo abati · italy

privacy.

privacy policy (gdpr) · last updated 25 september 2026 · version 1.3

this page collects nothing. the server keeps logs, whop handles the payment, discord runs the server. here is who sees what, and what you can ask me.

1.who is responsible

this site is run by matteo abati, italy. i am the data controller under the general data protection regulation (eu) 2016/679 (gdpr) for everything described here. for anything about your data, write to matteoabati054@gmail.com. i have no data protection officer: the law does not require one for an activity of this size.

2.what this website collects: nothing

there is no form here, no login, no newsletter, no cart, no search box, no comments, no analytics, no advertising pixel, no embedded video, no font loaded from a third party and no cookie of mine. the page does not write anything to your browser (no cookies, no local storage) and does not track you across sites. nothing on it is loaded from anyone else: zero requests leave your browser for anyone but the server that sent you the page. the cookies page says the same thing in ten lines.

the page links out to whop, cal.com, discord, youtube, instagram, tiktok, tradeify and alpha futures. nothing from them is embedded: those sites learn nothing about you unless you click. once you click, you are on their site and their privacy policy applies, not mine, except for what you enter on my booking page on cal.com (section 5).

3.what the server sees anyway

like every website, the machine that hosts this page keeps technical logs: your ip address, the date and time, the page requested, your browser and operating system, and the size of the response. an ip address counts as personal data in the eu (court of justice, breyer, c-582/14).

i use these logs only to keep the site up and to spot abuse. legal basis: my legitimate interest in running a working, secure website (art. 6(1)(f) gdpr). the host acts as my processor under art. 28 gdpr, under its standard data processing agreement, and deletes the logs on its own schedule.

4.when you buy on whop

payment does not happen on this site. it happens on whop.com, for all three products: the 1of1 from a private whop link i send you once we have agreed it in writing by e-mail (terms, section 3), and those e-mails i keep the same way as the whop records below. whop collects your payment details, your billing address and whatever it needs for tax; i never see your card number. for the payment itself whop is an independent controller: its policy is at whop.com/privacy.

after the purchase i see what any seller sees on whop: your whop username, your e-mail address, the plan you bought, the dates and amounts, the country used for tax, and anything you write in a support or refund case. i use this to deliver what you bought, to answer you, to handle refunds and disputes, and to keep the records that tax and accounting law require. legal bases: the contract with you (art. 6(1)(b) gdpr) and my legal obligations (art. 6(1)(c)).

5.when you book a call

the 1of1 starts with a call, which you book on cal.com through a plain link: nothing from cal.com is embedded in this site, and this page still collects nothing. the booking page asks for your name, your e-mail, your time zone and your answers to a few short questions (your discord username only if you want to give it), so that i can hold the call and prepare it. legal basis: steps you asked for before a contract (art. 6(1)(b) gdpr).

cal.com runs the booking page for me as a processor under art. 28 gdpr (section 8); for the rest of its site its own policy applies (cal.com/privacy). the booking goes into my google calendar, the call runs on google meet, and my e-mail, the written agreement included, runs on gmail: google handles those under its own privacy terms. i do not record the call.

i do not ask for your capital, your income, account numbers or any login, and you should not send them. if we do not work together, the booking, your answers and my notes are deleted within six months; if we do, they are kept as purchase records (section 9).

6.inside the discord server

if you join the niche discord, discord inc. processes your data under its own policy (discord.com/privacy). inside the server i see what everyone sees: your username, your messages in the channels, and the direct messages you send me. paying members get a role that whop assigns and removes automatically when a membership starts or ends; that is the only thing whop and discord exchange about you through me.

my bot answers questions in the server: in the premium channels from my lessons and my breakdowns, in the free channels about what i sell and how the server works. what you write to it is sent to the company whose ai model powers it, to generate the answer, and i can read the exchange. provider: anthropic (the claude models), under its own privacy terms. do not paste account numbers, credentials or anything private into it; it does not need them and neither do i.

legal basis for all of this: the contract with you for the paid channels (art. 6(1)(b)), and my legitimate interest in running a community you chose to join for the free ones (art. 6(1)(f)).

7.screenshots, reviews and quotes of members

the payout screenshots, certificates, chat messages and quotes on the site and on my socials were posted by members inside the niche discord, or written as reviews on whop. i show them there as proof of what happens in the server. they show the discord username under which the message was posted, the amount, the date and the text. first names, surnames, e-mail addresses, account numbers and balances that appeared on the documents have been pixelated; whop reviews appear with the name the reviewer chose to publish on whop.

legal basis: my legitimate interest in showing, with real evidence, what my service does (art. 6(1)(f) gdpr), balanced against yours: the data is what you chose to post in a server of about a thousand people, the identifying details are removed, nothing is sold or matched with anything else, and you can have it taken down at any time.

if one of them is yours and you want it gone, or your name shortened, write to matteoabati054@gmail.com or message me on discord and it comes down. no explanation needed. that is your right to object under art. 21 gdpr, and i do not weigh it: i just remove it, from the site and from my socials. if you are no longer in the server, e-mail works.

what i show is posted under the text in force when it was posted. for anything posted before 25 september 2026 that is the old text: if your username is on the site or on my socials from back then and you would rather it was not, tell me and it is shortened, or the whole post comes down. no explanation needed.

8.where your data goes

i do not sell data and i do not share it for advertising. the only third parties involved are the host (section 3), whop (section 4), cal.com and google (section 5), discord and the ai provider behind my bot (section 6), each for the part described. whop, cal.com, discord and anthropic are established in the united states, and google may process data there too.

cal.com works for me as a processor (art. 28 gdpr), and its transfers of your data out of the eu rest on the standard contractual clauses approved by the european commission (art. 46(2)(c) gdpr). the transfers of whop, discord, anthropic and google rest on the safeguards in their own policies: the same standard contractual clauses and, where the company is certified, the eu-us data privacy framework. i am a customer of all of them and do not control their transfers; their policies say exactly which safeguard applies to which service.

9.how long i keep things

10.your rights

you can ask me, at any time and for free, to tell you what data of yours i hold and to give you a copy (access, art. 15), to correct it (art. 16), to delete it (art. 17), to restrict what i do with it (art. 18), to receive it in a portable format where it was processed by automated means on the basis of contract or consent (art. 20), and to object to any processing based on legitimate interest (art. 21), including every screenshot and quote in section 7. where i rely on consent, you can withdraw it at any time, without affecting what was done before.

write to matteoabati054@gmail.com. you get an answer within one month (art. 12(3) gdpr). i may ask you to prove that the data is yours, and nothing more.

11.complaints

if my answer is not good enough, you can complain to the italian data protection authority, the garante per la protezione dei dati personali (www.gpdp.it, piazza venezia 11, 00187 roma), or to the supervisory authority of the eu country where you live or work. you can also go to court. none of this costs you a right you already have.

12.under 18

the site, the products and the server are for adults. i do not knowingly process data of anyone under 18; if i learn that a member is, that member is removed from the server, the payment is returned (terms, section 7) and i delete the data i hold, except the purchase record that tax and accounting law makes me keep (section 9).

13.changes

if this text changes, the date at the top changes with it. changes that reduce what you can expect from me are announced in the server before they apply.