Last updated: September 4, 2026

1. Data Controller and Contact

Pursuant to Article 13 of Regulation (EU) 2016/679 (hereinafter "GDPR") and Italian legislation on the protection of personal data (D.Lgs. 196/2003 and subsequent amendments, the "Privacy Code"), this notice describes the methods of processing personal data of users who visit the website travelinfluencer.co (including related subdomains), use the content management platform Horizon Studio and the web application Horizon, including all associated services.

Data Controller:
Made by West - Dylan Succi
VAT Number: 04229770369
Registered Office: Via Verica 150, 41026 Pavullo n/F (MO), Italy
Email: support@travelinfluencer.co
Website: travelinfluencer.co

The Data Controller is the entity that determines the purposes and means of processing personal data. For any questions regarding this notice or the processing of your personal data, you may contact the Controller using the details above.

Data Protection Officer (DPO): The Controller has not appointed a Data Protection Officer as it does not fall within the mandatory cases provided for by Article 37 of the GDPR.

The Controller is at your disposal for any clarification regarding this notice and the processing of your personal data, using the contact details shown in this section.

2. Types of Data Collected

The personal data collected by the travelinfluencer.co platform, Horizon Studio, and the Horizon app can be divided into the following categories:

2.1 Data provided or configured by the user

  • Account data: email address and, where applicable, name and country — received automatically from the payment provider Creem upon activation of a plan, including free plans (see sect. 2.3) — as well as the password chosen by the user, stored in encrypted form
  • Profile data: information freely configured by the Customer in the reserved area, including data relating to the travel influencer activity, nickname, bio, avatar, hero banner image and custom colors of the public author profile, as well as, if provided, business and contact data (About Us, legal address, VAT number, opening hours, phone/WhatsApp/email), the address with Google Maps link, up to 5 profile categories and the public statistics of the profile and content (views and likes)
  • Travelinfluencer Business data: data voluntarily provided by the Customer for the visibility of their profile in Travelinfluencer Business, including but not limited to: contact email, professional bio, niche, follower range, social platforms, Horizon profile link, availability for collaborations, languages spoken, and main destinations, as well as profile categories (up to 5), audience statistics (views and likes), and address (if made visible). Participation in Travelinfluencer Business is optional and subject to the Customer's explicit and separate consent, who can choose which information to make visible and revoke participation at any time
  • User-generated content: posts, articles, attached documents (PDF or .travel itinerary files), uploaded images, video links (YouTube/Vimeo) published on the platform through Horizon Studio
  • Email communications: name, email, subject and message the user voluntarily sends to support@travelinfluencer.co via the dedicated link on the site. The data is delivered directly to the Controller's mailbox, without passing through third-party services or third-party cookies

2.2 Automatically collected data

  • Browsing data: IP address (anonymized), browser type, operating system, device type
  • Usage data: pages visited, traffic source, browser and country — collected anonymously and in aggregate form via Umami (section 5.3)
  • Technical data: system logs, errors, performance
  • HorizonAI (local AI assistant): the travel assistant based on an artificial intelligence model processes data entirely locally on the user's device and no conversation content is transmitted to external servers. Internet connection is required for the initial download of the AI model at the first app launch: during this download, the user's IP address is communicated to the CDN of the provider distributing the model (Hugging Face) — see Section 6 (Data Recipients)
  • Trip management ("My Trips"): data related to trips created by the user (destinations, dates, expense categories such as accommodation/transport/food/activities, amounts, notes, trip status, as well as photos, documents attached to the trip, cover image, and pre-departure checklist) are stored and processed exclusively locally on the user's device. Trip data is stored and processed exclusively locally on the device and is not transmitted to the Controller's servers. Searching for a location to set a destination sends the searched term to the OpenStreetMap geocoding service (Nominatim) — see "Interactive map". The user can export individual trips in a dedicated file format (.travel) for data portability
  • Travel document import (PDF): the user can import travel documents in PDF format (flight confirmations, hotel reservations, etc.) for automatic extraction of trip-related data. PDF document processing occurs entirely locally on the user's device. No document content is transmitted to external servers
  • Interactive map (OpenStreetMap): the app uses third-party map services (OpenStreetMap) for trip visualization. Loading map tiles automatically transmits the user's IP address and requested tile coordinates to OpenStreetMap servers. Place search and reverse coordinate lookup (reverse geocoding) additionally transmit the searched text or the coordinates to OpenStreetMap (Nominatim) servers, in addition to the IP address. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). Retention: according to the OpenStreetMap privacy policy. The feature does not use device GPS or geolocation. For more information: OpenStreetMap Privacy Policy
  • Content indexing: content published by users on the platform is publicly accessible and, as such, may be indexed by search engines, web crawlers, and artificial intelligence agents according to normal web dynamics
  • Like system: the like status on articles is anonymous, requires no authentication and is accessible to all visitors. No personal data is transmitted to external servers for this feature
  • View monitoring: article view counting is automatic and active by default for all published content. The counter is incremented on each visit to the individual article
  • User/influencer profile views: author/influencer profile view counting is automatic and active by default. The counter is incremented on each visit to the author's/influencer's profile
  • Promo popup: the app may show a dismissible promotional popup with customized promotional content. The popup may link to third-party sites: in such cases, user data may be collected by those sites according to their respective privacy policies
  • WebView and external content: the app uses WebView components to display external web content. When the user navigates to external sites through affiliate links, travel services (flights, hotels, car rentals, insurance, eSIM, tours), or other links, browsing data may be collected by the respective third-party sites according to their privacy policies
  • Google Fonts (site and app): the travelinfluencer.co website and Customers' white-label apps may load fonts from the Google Fonts service (fonts.googleapis.com). This HTTP request may include the user's IP address in Google's server logs
  • Cookies and similar technologies: as described in the dedicated section (Section 5)

2.3 Data received from the payment provider (Creem)

  • Sole source of third-party data: the data necessary to create and manage the account — including, where applicable, email address, name, country, subscribed plan, status, renewals and cancellations of the subscription and subscription ID — are received automatically via the Creem APIs (Merchant of Record) within the purchase process initiated by the user. No other personal data is received from third parties

3. Purposes of Processing

The personal data collected is processed for the following purposes:

3.1 Contractual purposes and service execution

  • Provision of services offered by the travelinfluencer.co platform, including the proprietary Horizon app with AI features, mini-blog, and trip management
  • User account management and authentication
  • Management of subscriptions and payments through the payment provider Creem
  • Technical assistance and customer support
  • Operational communications relating to purchased services
  • Management of contact requests sent voluntarily via email to the Controller's address
  • Service and informational communications (for example: changes to the Terms, maintenance, service status and platform notices) sent via in-dashboard banners and, where necessary, via collective email messages to registered users. These communications are operational in nature and not commercial
  • Publication and management of the profile in Travelinfluencer Business, including but not limited to the display of contact data, professional information, niche, statistics, and availability for collaborations, accessible to users with a Travelinfluencer Business subscription

3.2 Legitimate interests

  • Improvement and optimization of the platform and services
  • Anonymous or aggregated statistical analysis of traffic and website usage
  • Operation of the HorizonAI AI assistant to improve the user's travel experience, with exclusively client-side processing and no transmission of personal data
  • Website security and prevention of fraud, abuse, and unauthorized access
  • Compliance with legal obligations, regulations, or requests from competent authorities
  • Exercise or defense of rights in legal proceedings
  • Dispute management

3.3 Any marketing purposes (subject to consent)

The following purposes are potential and become active only upon the eventual collection of the user's specific and revocable consent:

  • Any sending of newsletters and promotional communications via email
  • Any personalized commercial communications, promotion of new services, features or special offers

3.4 Nature of data provision

The provision of data for the purposes referred to in point 3.1 is necessary for the use of the services. Refusal to provide such data may result in the inability to use the services offered. The provision of data for any marketing purposes referred to in point 3.3 is optional and requires the user's prior consent, which may be revoked at any time.

The provision of data for visibility in Travelinfluencer Business is optional and requires the explicit prior consent of the Customer. The Customer may freely choose which information to make visible in Travelinfluencer Business and may revoke consent at any time, with immediate effect on the removal of their profile from Travelinfluencer Business. Revocation of consent does not entail any consequences on the use of the other services of the platform.

4. Legal Basis for Processing

The processing of personal data is based on the following legal bases pursuant to Article 6 of the GDPR:

  • Article 6, paragraph 1, letter a) – Consent: for any processing of personal data for marketing purposes, for the use of non-essential cookies, and for the publication of Customer data in Travelinfluencer Business, including but not limited to contact data, professional information, and statistics, made visible to Travelinfluencer Business subscribers
  • Article 6, paragraph 1, letter b) – Performance of a contract: for processing necessary to provide the services requested by the user and to execute the contract
  • Article 6, paragraph 1, letter c) – Legal obligation: for processing necessary to comply with applicable legal, fiscal, and accounting obligations
  • Article 6, paragraph 1, letter f) – Legitimate interest: for processing necessary to pursue a legitimate interest of the Controller, such as website security, statistical analysis, fraud prevention, and defense of rights

4.1 Automated Decision-Making and Profiling (Art. 22 GDPR)

The Controller declares that the platform does not use fully automated decision-making processes, including profiling, that produce legal effects or significantly affect users, pursuant to Article 22 of the GDPR.

HorizonAI is a travel planning support assistant with entirely local processing. It does not have the ability to make bookings, payments, or actions with legal effect. The user always retains full control of their decisions.

Important note: The travelinfluencer.co website does not use tracking cookies or a cookie consent banner: only technical cookies are used, and statistical measurement is handled by a self-hosted instance of Umami, cookieless and anonymous analytics (section 5.3). No third-party analytical cookies and no marketing or advertising cookies are used, and no prior consent is therefore required. The Horizon app does not use cookies. The technologies used are described below.

5.1 Technical cookies (necessary)

These cookies are essential for the operation of the site and for access to the reserved area and do not require the user's consent.

  • Session cookies: necessary for browsing and authentication to the reserved area
  • Security cookies: protect against CSRF attacks and ensure browsing security

5.2 Absence of tracking and profiling cookies

The travelinfluencer.co website does not use tracking cookies (analytical, profiling or marketing) and does not employ any cookie consent banner: only the technical cookies described in section 5.1 are set and site statistics are collected anonymously and in aggregate form via Umami (section 5.3). The Controller does not use social media pixels (Facebook Pixel, Instagram, etc.), conversion tags, marketing, advertising or remarketing cookies or other advertising profiling technologies. Since no cookies or tracking tools subject to consent are used, no prior consent is requested from the user. Should marketing or tracking services be activated in the future, this notice will be updated and consent will be requested in advance in accordance with the regulations, including the possible adoption of a cookie consent banner.

The affiliate links and travel services present in the app are redirects to third-party sites: after the click, the cookie policies of the destination sites apply. In any case the Controller does not use tracking cookies for affiliate monitoring; until configuration by the Customer, the app may show default affiliate links of the Controller (see the Terms and Conditions).

5.3 Statistical analysis of the site (self-hosted Umami)

Site statistics are handled by a self-hosted instance of Umami, an open source web analytics platform managed directly by the Controller on its own servers in the European Union. Umami does not use cookies or persistent identifiers, does not collect personal data, does not track the user across multiple sites and does not share data with third parties for advertising purposes.

Umami collects exclusively anonymous and aggregate statistical data (pages visited, traffic source, browser, country) and anonymizes IP addresses. Since no cookies or tracking technologies are used and the data cannot be linked to identified or identifiable persons, statistical analysis does not require prior consent pursuant to art. 122 of the Privacy Code. More information about the software: umami.is.

5.4 Cookie management

Users can manage their cookie preferences through their browser settings. Please note that disabling some cookies may affect the functionality of the website. For more information on managing cookies, consult the guides for major browsers:

5.5 White-label apps and absence of cookies

The influencer Horizon (white-label) apps are cookieless and do not use proprietary tracking cookies. Content displayed through iframes within the apps is under the exclusive responsibility of the third-party sites shown, including the adoption of GDPR-compliant cookie consent systems. The Controller is not responsible for the cookie management practices of sites displayed through iframes.

6. Data Recipients

Personal data may be shared with the following categories of recipients, in compliance with the adequate guarantees provided by the GDPR:

  • Euronodes (hosting): hosting provider with servers located in the European Union. Euronodes acts as a data processor pursuant to Art. 28 of the GDPR. The Data Processing Agreement (DPA) is available at: Euronodes GDPR Agreement
  • Any other technology providers eventually used (e.g. cloud services), in compliance with their respective data processing agreements
  • Creem (payments and subscriptions): Merchant of Record that processes payments, issues invoices and handles tax obligations (VAT and sales tax) in accordance with PCI-DSS regulations. Payment data (credit card, etc.) is processed directly by Creem as an independent data controller and is not stored on this site. Through the Creem APIs the platform receives the data necessary for account and subscription management (see sect. 2.3)
  • Google LLC: for loading website and Customer white-label app fonts (Google Fonts). HTTP requests may include the user's IP address in Google server logs. For more information: Google Privacy Policy
  • Hugging Face (AI model download): CDN from which the Horizon app downloads the HorizonAI assistant model on first use. The HTTP request includes the user's IP address in the provider's logs (communication limited to the initial model download only; no conversation content is transmitted). Legal basis: legitimate interest (Art. 6(1)(f) GDPR). For more information: Hugging Face Privacy Policy
  • Umami (statistical analysis): the anonymous and aggregate statistics of the site are processed through a self-hosted instance of Umami on the Controller's infrastructure (EU servers): this is not a communication to third parties and no cookies are used nor personal data collected (section 5.3)
  • OpenStreetMap: map service used in the app for interactive trip visualization. Loading map tiles transmits the user's IP address to OpenStreetMap servers. For more information: OpenStreetMap Privacy Policy
  • Consultants and professionals: accountant, lawyer, tax consultant, to the extent necessary for the execution of their respective assignments
  • Travelinfluencer Business subscribers: data of Customers who have given their explicit consent for visibility in Travelinfluencer Business is accessible to users with an active Travelinfluencer Business subscription, including but not limited to: contact data, professional information, niche, statistics, and availability for collaborations. Access is regulated by the platform's Terms and Conditions which prohibit improper use of data
  • Public authorities: where required by law or orders from competent authorities

The complete and updated list of data processors is available upon request by contacting the Controller at support@travelinfluencer.co.

Data Processing Agreements (DPA): the Controller has entered into — or, in the case of platform services, accepted — a Data Processing Agreement pursuant to Article 28 of the GDPR with each data processor listed above. These agreements define the purposes and duration of processing, the type of personal data processed, the obligations and rights of the Controller, and the security measures adopted by the processor.

App with Customer's custom domain: When the Customer configures their app on a domain they own, the Customer becomes the Data Controller of the personal data of visitors to their website. The platform Controller remains the Data Controller exclusively for data processed by the travelinfluencer.co platform and backend functionalities. The Customer is responsible for providing their own GDPR-compliant privacy notice on their domain.

Affiliate links and external services: the Horizon app includes affiliate links and travel services (flights, hotels, vacation rentals, car rentals, insurance, eSIM, tours, and other services) that redirect to third-party sites. When the user clicks on these links, they are directed to external platforms that may collect personal data according to their respective privacy policies. The Controller is not responsible for the privacy practices of third-party sites. It is recommended to consult the privacy policies of the destination sites before entering personal data.

7. Data Transfer Outside the European Union

Some of the third-party services used by this site may transfer data outside the European Union (EU) or the European Economic Area (EEA). In such cases, the transfer occurs in compliance with the appropriate safeguards provided by the GDPR, including:

Servers in the European Union: the servers used for hosting the site and the travelinfluencer.co platform are located within the European Union, ensuring that personal data is not transferred outside the EU for primary processing.

HorizonAI and My Trips: it is specified that the HorizonAI AI assistant and the "My Trips" feature process all data locally on the user's device and do not transfer personal data outside the EU or to any external server, with the sole exception of the initial AI model download, during which the user's IP address is communicated to the provider's CDN (Hugging Face, see Section 6); no conversation or trip content ever leaves the user's device.

  • Adequacy decision: transfer to countries for which the European Commission has adopted an adequacy decision (e.g., United Kingdom, Switzerland, Japan)
  • Standard Contractual Clauses (SCC): use of standard contractual clauses approved by the European Commission for data transfer to third countries
  • Specific derogations: in specific cases provided for by Article 49 of the GDPR (e.g., explicit consent of the data subject, performance of a contract)

8. Data Retention

Personal data will be retained for the time necessary to achieve the purposes for which it was collected, in compliance with the principles of storage limitation and data minimization provided by the GDPR. In particular:

  • Contractual, accounting and fiscal data (invoices, billing data, receipts): for the entire duration of the relationship and for the subsequent 10 years, where required by legal obligations (fiscal, accounting, civil). These documents are mainly managed by Creem as Merchant of Record. Account content (articles, images, app configurations) is instead deleted within 30 days of account closure, as specified in the dedicated item below
  • Browsing and log data: for a maximum of 14 months, as provided by Italian regulations (Garante Privacy Provision of May 8, 2014)
  • Marketing data: until consent is revoked by the data subject
  • Data relating to support requests: for the time necessary to manage the request and, in any case, no longer than 24 months from the closure of the case
  • Cookies: as specified in the dedicated cookies section (Section 5)
  • User data after account deletion: to delete the account, the user must first cancel their subscription or let it expire. Once the subscription is expired or cancelled, articles, images, app settings, and other user-generated content are retained for a maximum period of 30 days from the subscription expiry date, during which the account is suspended: published data and content remain but cannot be modified nor can management functions be accessed. If the user renews any subscription within this 30-day period, the deletion process is automatically cancelled and the account returns to fully active. After the 30-day period without an active subscription, all data and the account are deleted permanently and irreversibly. For accounts on a free plan (e.g. Starter), deletion is immediate and irreversible upon confirmation of the request submitted via the dedicated function or through support; in addition, inactive free accounts (no login for at least 6 months) may be deleted without prior notice, as provided in the Terms and Conditions.

At the end of the retention period, data will be deleted or anonymized irreversibly, unless otherwise required by law.

9. Data Subject Rights

Pursuant to Articles 15-22 of the GDPR, the data subject has the right to exercise the following rights against the Data Controller:

9.1 Right of access (Art. 15)

The data subject has the right to obtain confirmation as to whether or not personal data concerning them is being processed, and if so, to obtain access to the personal data and information relating to the processing.

9.2 Right to rectification (Art. 16)

The data subject has the right to obtain the rectification of inaccurate personal data concerning them without undue delay. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed.

9.3 Right to erasure ("Right to be forgotten") (Art. 17)

The data subject has the right to obtain the erasure of personal data concerning them without undue delay, where one of the grounds provided by law applies (e.g., the data is no longer necessary, consent has been withdrawn, the data subject has objected to processing, the data has been unlawfully processed).

9.4 Right to restriction of processing (Art. 18)

The data subject has the right to obtain the restriction of processing in the cases provided by law (e.g., contesting the accuracy of the data, unlawful processing, opposition to erasure, necessity for the exercise of rights in legal proceedings).

9.5 Right to data portability (Art. 20)

The data subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used, and machine-readable format, and the right to transmit such data to another Controller without hindrance.

9.6 Right to object (Art. 21)

The data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data based on the Controller's legitimate interest, unless compelling legitimate grounds for the processing are demonstrated that override the interests, rights, and freedoms of the data subject.

9.7 Right to withdraw consent (Art. 7)

The data subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

9.8 Right to lodge a complaint (Art. 77)

The data subject has the right to lodge a complaint with a competent Supervisory Authority. In Italy, the competent authority is the Garante per la protezione dei dati personali (Data Protection Authority), contactable at:

Garante per la protezione dei dati personali
Piazza Venezia, 11 – 00187 Rome
Email: garante@gpdp.it
PEC: protocollo@gpdp.it
Website: www.garanteprivacy.it

9.9 How to exercise your rights (in practice)

  • Access and rectification: you can view and modify your data directly from the profile settings in the reserved area;
  • Erasure: cancel or let your subscription expire — or, for free-plan accounts, use the dedicated function or support — and, after the 30-day grace period without an active subscription, the account and all data are permanently and irreversibly deleted (for free accounts deletion is immediate); early deletion can also be requested by contacting the Controller;
  • Portability and objection: send a request to support@travelinfluencer.co.

The Controller undertakes to respond to the request within 30 days of receipt, as required by the GDPR. This period may be extended by a further 60 days in cases of particular complexity, with appropriate communication to the data subject.

10. Protection of Minors

The services offered by travelinfluencer.co are not intended for minors under 18 years of age, consistent with the Terms and Conditions which reserve the Service to adults only. The Controller does not knowingly collect personal data from minors under this age. If the Controller becomes aware that personal data of minors has been inadvertently collected, it will promptly proceed with its deletion.

If you are a parent or guardian and believe that your child has provided personal data without your consent, please contact us at support@travelinfluencer.co.

11. Changes to the Privacy Policy

The Controller reserves the right to make changes to this Privacy Policy at any time, to account for any regulatory, technological, or organizational changes. Changes will be published on this page with the date of the last update indicated.

Users are invited to periodically consult this page to stay informed about the latest developments in data protection. In case of substantial changes, the Controller will inform users through a notification on the site or via email.

12. Image Attribution

The images used on this site were sourced from the platforms Unsplash and Pexels. The authors and artists of the photographs retain their respective rights to the original works, in compliance with the licenses applied by the aforementioned platforms.

13. Data Breach Notification

In compliance with Articles 33 and 34 of the GDPR, in the event of a personal data breach that may present a risk to the rights and freedoms of data subjects, the Controller undertakes to:

  • Notify the breach to the Garante per la protezione dei dati personali within 72 hours from the moment of becoming aware of it, unless it is unlikely that the breach presents a risk to the rights and freedoms of natural persons
  • Communicate the breach to the data subjects without undue delay where the breach is likely to present a high risk to their rights and freedoms
  • Document all data breaches, including the facts, effects, and corrective actions taken

The Controller has adopted appropriate technical and organizational measures to prevent data breaches and to minimize the impact of any incidents.

14. Detail of Processing by Data Category

The following table summarizes the categories of data processed, with their purposes, legal bases and retention periods.

Category of dataPurposeLegal basis (Art. 6 GDPR)Retention
Authentication and security — email, password (stored in encrypted form), acceptance of the Terms and Conditions recorded with date and time, last accessAuthentication, account recovery, security, verification of inactivity for the deletion of inactive free accountsContract and legitimate interest (Art. 6(1)(b) and (f))Duration of the account; deletion within 30 days of closure; the last access data is overwritten on each access
Subscription (received from Creem) — plan, status, renewals and cancellations, subscription ID; email, name and country where applicable (sect. 2.3)Creation and management of the account and subscriptionContract (Art. 6(1)(b))Duration of the account
Profile and business data — nickname, avatar, bio, contacts (phone/WhatsApp/email), website, colors, app title, "About Us" description, legal address, VAT number, opening hours; public author profile (hero banner, bio, colors, up to 5 profile categories). Business data is optional and, if filled in, is publicly visible in the app info page and powers the contact buttonsPersonalization of the app, the user profile and the public author page on Horizon StudioContract (Art. 6(1)(b))Duration of the account; modifiable or deletable at any time from the profile settings
Visibility in Travelinfluencer Business (opt-in) — voluntary activation recorded with date and time; the profile page and articles remain in any case accessible to anyone who knows their URLInclusion in the list of profiles (directory) visible exclusively to Travelinfluencer Business subscribers in their own dashboardConsent (Art. 6(1)(a))Duration of the account; revocable at any time by switching the option off, with immediate effect
User-generated content — posts and articles, attached documents (PDF or .travel itineraries), uploaded images, video links (YouTube/Vimeo)Publication and management of the personal blog through Horizon StudioContract (Art. 6(1)(b))Duration of the account and up to a maximum of 30 days after closure for possible recovery, then irreversible deletion; deletable by the user at any time
Access security — failed access attempts monitored per individual account, without IP address trackingPrevention of unauthorized access attemptsLegitimate interest (Art. 6(1)(f))Counters automatically reset at the end of the temporary lockout
Imported PDF travel documents — flight confirmations, hotel reservations, etc.Automatic compilation of trip data in the "My Trips" section — processing exclusively local on the user's deviceContract (Art. 6(1)(b))Never transmitted nor stored on external servers
Maps (OpenStreetMap) — IP address, coordinates of the requested tiles, searched text and coordinates for reverse geocoding (no use of device GPS)Loading of interactive maps for trip visualization, destination search and reverse geocodingLegitimate interest (Art. 6(1)(f))Processed by OpenStreetMap (Nominatim) according to its own privacy policy: OpenStreetMap Privacy Policy