Privacy Policy – Broad Horizon GPT Publisher

Last updated: 8 August 2025

Broad Horizon Travel (“we”) provides a GPT Action that publishes content to our WordPress site at broad-horizon.eu.

What this Action does

  • Sends post data (titles, slugs, taxonomies, and meta fields like subtitle, SEO, sections, factbox, relations, gallery, map data) and, optionally, media files to our WordPress REST API.
  • Looks up existing categories/tags by name to use their IDs.
  • Does not read from or write to any other external service.

Data we process

  • Content you provide to the Action (text, metadata, media).
  • Minimal technical logs from our website (IP address, user agent) for security and debugging.

Authentication

  • The Action authenticates to our WordPress REST API using an Application Password bound to a dedicated user account with limited capabilities (gpt-user).
  • Credentials are stored in the GPT Actions configuration and transmitted only to broad-horizon.eu.

How we use the data

  • To create or update draft posts on our site at your request.
  • To support editorial workflows (review, formatting, publishing).

Retention

  • Content is stored in WordPress as draft or published posts until removed by our editors.
  • Web server logs are retained per our hosting provider’s standard retention (typically 30–90 days).

Sharing

  • We do not sell personal data.
  • Sub-processors: OpenAI (Action runtime/transport) and our hosting provider (serving broad-horizon.eu).

Cookies and tracking

  • The Action itself does not set cookies.
  • Our website may set cookies when you visit it; see our site-wide policy.

Security

  • HTTPS enforced.
  • Dedicated WordPress user (gpt-user) and Application Password for the Action.
  • Principle of least privilege and periodic credential rotation.

Your rights (GDPR/EEA)

  • You may request access, correction, deletion, restriction, or portability of personal data we hold about you.
  • Contact: G. Kraaijeveld – [email protected]
  • Postal address: Amersfoort, NL
  • Supervisory authority: You may lodge a complaint with your local data protection authority.

Children

Not intended for use by children under 16.

Last updated: 8 August 2025

Broad Horizon Travel (“we”) provides a GPT Action that publishes content to our WordPress site at broad-horizon.eu.

  • Sends post data (titles, slugs, taxonomies, and meta fields like subtitle, SEO, sections, factbox, relations, gallery, map data) and, optionally, media files to our WordPress REST API.
  • Looks up existing categories/tags by name to use their IDs.
  • Does not read from or write to any other external service.

Data we process

  • Content you provide to the Action (text, metadata, media).
  • Minimal technical logs from our website (IP, user agent) for security and debugging.

Authentication

  • The Action authenticates to our WordPress REST API using an Application Password bound to a specific user account with limited capabilities.
  • Credentials are stored in the GPT Actions configuration and transmitted only to broad-horizon.eu.

How we use the data

  • To create or update draft posts on our site at your request.
  • To support editorial workflows (review, formatting, publishing).

Retention

  • Content is stored in WordPress as draft or published posts until removed by our editors.
  • Web server logs are retained per our hosting provider’s standard retention (typically 30–90 days).

Sharing

  • We do not sell personal data.
  • Sub‑processors: OpenAI (Action runtime/transport) and our hosting provider (serving broad-horizon.eu).

Cookies/Tracking

  • The Action itself does not set cookies. Our website may set cookies when you visit it; see our site‑wide policy.

Security

  • HTTPS enforced.
  • Separate WordPress user and Application Password for the Action.
  • Principle of least privilege and periodic credential rotation.

Your rights (GDPR/EEA)

  • You may request access, correction, deletion, restriction, or portability of personal data we hold about you.
  • Contact: [[email protected]] or write to: [Your Legal Entity], [Address], [Country].
  • Supervisory authority: You may lodge a complaint with your local data protection authority.

Children

  • Not intended for use by children under 16.

Contact

  • Data controller: [Your Legal Entity / Company Name]
  • Email: [[email protected]]
  • Postal address: [Address]