Legal / Privacy Policy
Privacy Policy
Version: 1.0 Effective date: 2026-08-25 Last updated: 2026-08-25 Data controller: Atomira Technologies, S.L. (CIF B27662717, C/ Lepant 270, Bajos, 08013 Barcelona, Spain)
1. About this Policy
This Privacy Policy explains how Atomira Technologies, S.L. (“Atomira”, “we”, “us”) collects, uses, stores, and protects personal data when you use Writano (https://writano.com) and related services (the “Service”).
We take privacy seriously. Writano was designed around privacy-by-design principles: most AI processing runs locally in your browser so that your manuscripts never leave your device. This Policy explains what data does and does not flow to us, and why.
This Policy is governed by:
- Regulation (EU) 2016/679 (GDPR)
- Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD)
- Ley 34/2002 de Servicios de la Sociedad de la Información (LSSI-CE)
2. Who is the data controller?
Atomira Technologies, S.L.
- CIF: B27662717
- Registered office: C/ Lepant 270, Bajos, 08013 Barcelona, Spain
- Registro Mercantil: Barcelona, inscription nº 2026060968
- Privacy contact: privacy@writano.com
- General contact: hello@writano.com
We have not appointed a formal Data Protection Officer because we are not legally required to do so under Article 37 GDPR at our current scale. For any data-protection inquiry, please write to privacy@writano.com and we will respond within 30 days (the statutory maximum, per Article 12(3) GDPR).
3. What personal data we collect
We collect the following categories of personal data:
3.1 Account data
When you create an account, we collect:
- Email address
- Display name (if you provide one)
- Password hash (never the password itself — we use industry-standard hashing, e.g. bcrypt / argon2)
- Account-creation timestamp
- IP address at registration (for fraud prevention and audit logs)
- Authentication method (email/password, SSO provider if used)
3.2 Subscription and payment data
When you become a paying customer:
- Billing email and name (may differ from account email)
- VAT/tax number (for business customers)
- Country of residence (for VAT calculation)
- Subscription tier and history
- Invoice records (legally required to retain for 6 years under Spanish tax law)
We do not store credit-card numbers. All payment processing is handled by our payment processor (see § 6 below). The processor stores card data on its PCI-DSS-compliant infrastructure and provides us only a tokenized reference and the last 4 digits.
3.3 Content you create
Manuscripts, references, figures, code, notebooks, and other material you create or upload to the Service.
Important architectural fact: when you use Writano’s local AI features, the manuscript content stays on your device and is processed by your browser. It is not transmitted to us. The features that run locally are listed at writano.com/security.
When you use server-side features (e.g. collaboration, cloud sync, optional cloud-AI features), the relevant Content is transmitted to our servers and stored encrypted at rest. You can disable optional cloud features in account settings.
3.4 Usage data
To operate and improve the Service:
- Pages and features used (anonymized where possible)
- Approximate location (country-level, from IP address)
- Browser type, language, operating system
- Crash and error logs
- Approximate session timestamps
We use a privacy-respecting analytics solution (see § 6.5) that does not use third-party tracking cookies, does not build cross-site profiles, and is configured for GDPR consent compliance.
3.5 Communications
If you contact us by email or any support channel, we retain the communication for support, audit, and quality purposes. This includes:
- The content of your message
- Email address and any identifying information you provide
- Timestamps and which staff member responded
3.6 Data we explicitly do NOT collect
- We do not sell your personal data. Ever.
- We do not allow third-party advertising trackers on writano.com.
- We do not transmit your manuscript content to third-party AI providers when you use the default local-AI features.
- We do not collect biometric data, health data, or any data revealing racial origin, political opinion, religious belief, trade-union membership, or sexual orientation.
- We do not knowingly collect data from children under 16 (see § 11).
4. Why we use your data (purposes and legal bases)
Each category of data is used for specific purposes, each justified by a specific legal basis under Article 6 GDPR:
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and manage your account | Account data (§ 3.1) | Contract performance — Art. 6(1)(b) |
| Provide the Service | Content (§ 3.3) | Contract performance — Art. 6(1)(b) |
| Process payments and issue invoices | Subscription data (§ 3.2) | Contract performance + legal obligation — Art. 6(1)(b) + 6(1)© |
| Tax and accounting record-keeping | Invoice records | Legal obligation — Art. 6(1)© (Spanish tax law requires 6-year retention) |
| Send service-related emails (account confirmation, billing receipts, downtime notices) | Email address | Contract performance — Art. 6(1)(b) |
| Improve the Service via usage analytics | Anonymized usage data (§ 3.4) | Legitimate interest — Art. 6(1)(f) |
| Detect, prevent, and respond to security incidents and fraud | IP, account, usage data | Legitimate interest — Art. 6(1)(f) |
| Respond to your support requests | Communications (§ 3.5) | Contract performance / legitimate interest — Art. 6(1)(b) or (f) |
| Send optional product newsletters or product announcements | Email address | Consent — Art. 6(1)(a) (you may withdraw consent at any time) |
| Comply with legal obligations (e.g. responding to court orders) | Whatever is legally required | Legal obligation — Art. 6(1)© |
Where we rely on legitimate interest, we have conducted a balancing test and concluded the processing does not override your rights and freedoms. You may object to any such processing under Article 21 GDPR.
Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of past processing.
5. Who can see your data
We treat your data as confidential. Access is limited to:
- Atomira personnel with a need to know (currently: the sole administrator, Arsalan Akhtar) — bound by confidentiality
- Subprocessors listed in § 6, under data-processing agreements (DPAs) compliant with Article 28 GDPR
- Authorities when legally required (court orders, valid warrants under Spanish law). We will challenge overbroad requests and will notify you unless legally prohibited.
We do not share your data with any other third party for any other purpose without your explicit consent.
6. Categories of recipients
Personal data is shared only with service providers acting on our documented instructions as processors, all bound by data-processing agreements. In line with Article 13(1)(e) GDPR we disclose the categories of recipients:
| Category | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Cloud hosting provider | Servers, databases, storage, backups | Germany / Finland (EU) | Contractual DPA; no third-country transfer |
| Payment processor | Payment processing, subscriptions, invoicing, tax | Ireland (EU); certain card-network operations in the US | DPA; SCCs and EU-US Data Privacy Framework for any US step |
| Email delivery provider | Transactional and account email (sign-in links, notifications) | Germany (EU) | Contractual DPA; no third-country transfer |
| Identity providers (only if you choose social sign-in) | Authentication | Depends on the provider you choose | DPA + SCCs / EU-US Data Privacy Framework as applicable |
We use no analytics provider — Writano runs no tracking or analytics of any kind. The current named list of processors is available on request at privacy@writano.com, and we notify users of material changes per § 13.
7. International data transfers
Our default infrastructure is EU-only (Germany and Finland). When data has to leave the EU/EEA (e.g. for certain US-based card-network operations, or optional non-local AI features), we ensure adequate protection via one of the following:
- EU-US Data Privacy Framework adequacy (where the recipient is certified)
- Standard Contractual Clauses (Module 2: Controller to Processor)
- Supplementary technical measures (encryption in transit and at rest)
You can request a copy of the relevant transfer-safeguard documentation by emailing privacy@writano.com.
8. How long we keep your data
We keep personal data only as long as necessary for the purposes for which it was collected:
| Data category | Retention period |
|---|---|
| Account data (active accounts) | For as long as your account is active |
| Account data (inactive accounts) | Deleted after 24 months of inactivity, after 30 days’ notice to your registered email |
| Content (active accounts) | Until you delete it, or until account termination + 30 days |
| Backups (residual copies of deleted content) | Up to 90 days on our standard backup-rotation cycle, then deleted |
| Invoice records | 6 years (Spanish tax-law requirement under General Tax Law Art. 70) |
| Support communications | 24 months from last interaction |
| Security logs | 12 months, then aggregated/anonymized |
| Usage analytics | Up to 24 months in identifiable form, then aggregated/anonymized |
| Cookie data | Per § 9 and Cookie Policy |
| Newsletter consent records | Until consent withdrawn + 12 months audit |
After the retention period ends, data is either deleted or anonymized so it can no longer be linked to you.
9. Cookies and similar technologies
Our use of cookies and similar technologies is described in detail in our Cookie Policy (writano.com/cookies). In summary, we use:
- Strictly necessary cookies (essential for auth, session, security) — no consent required under Article 22.2 LSSI-CE
- Functional cookies (remember your preferences) — consent-based
- Analytics cookies (or cookieless alternative, per § 6.5) — consent-based
- No advertising or third-party tracking cookies
You can manage consent through our cookie banner and at any time via your account preferences. Withdrawing consent does not affect access to the Service, except for the features that the cookie supported.
10. Your rights under GDPR
You have the following rights in relation to your personal data:
| Right | Description | Article |
|---|---|---|
| Access | Receive a copy of the personal data we hold about you | Art. 15 |
| Rectification | Correct inaccurate or incomplete data | Art. 16 |
| Erasure (right to be forgotten) | Have your data deleted, subject to certain conditions | Art. 17 |
| Restriction | Limit how we process your data in certain circumstances | Art. 18 |
| Portability | Receive your data in a structured, machine-readable format | Art. 20 |
| Objection | Object to processing based on legitimate interest or direct marketing | Art. 21 |
| Withdraw consent | Withdraw consent at any time where consent is the legal basis | Art. 7(3) |
| Automated decision-making | Not be subject to decisions based solely on automated processing | Art. 22 |
10.1 How to exercise your rights
Send a request to privacy@writano.com. We will respond within 30 days (extendable by 60 additional days for complex cases, with prior notice to you).
We may ask you to verify your identity before processing the request, to prevent unauthorized access.
For most requests, you can exercise the right directly from your account settings:
- Access / portability: “Download my data” — exports all your data in JSON + standard formats
- Rectification: edit account settings
- Erasure: “Delete my account” — removes data on the timeline in § 8
10.2 Right to lodge a complaint with the supervisory authority
If you are unsatisfied with our handling of your data, you have the right to lodge a complaint with:
Agencia Española de Protección de Datos (AEPD) C/ Jorge Juan, 6 — 28001 Madrid, Spain 🔗 https://www.aepd.es 📞 +34 901 100 099 / +34 91 266 35 17
You may also lodge a complaint with the supervisory authority of your EU/EEA country of residence.
11. Automated decision-making
Writano’s AI features generate suggestions but do not make decisions about you with legal or similarly significant effect (Article 22 GDPR is not triggered). Your account is not subject to automated profiling, automated suspension, or automated denial of service.
If we introduce features that do involve automated decision-making with significant effect (e.g. automated fraud-prevention blocks), we will update this Policy, notify you, and provide the right to obtain human intervention.
12. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and become aware that a child has provided us with personal data, please contact privacy@writano.com so we can delete it.
13. Security
We implement appropriate technical and organizational measures to protect your data:
- TLS 1.3 in transit (HTTPS everywhere)
- Encryption at rest for production databases and backups
- Hashed and salted passwords (bcrypt / argon2)
- Principle of least privilege for internal access
- Regular security updates and patching of dependencies
- Logging and monitoring with alerting on anomalous events
- Periodic backup-restore testing
- Incident-response procedure including GDPR Art. 33 (72-hour AEPD notification) and Art. 34 (notification to affected users where high risk)
No system is 100% secure. We will notify affected users and AEPD as legally required in the event of a personal-data breach.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified to you by email (to the address on your account) and posted at writano.com/privacy with at least 30 days advance notice before they take effect.
If you do not accept the changes, you may close your account and request deletion under § 8 before the changes take effect.
15. Specific provisions for non-EU users
If you access the Service from outside the EU/EEA, your data is still processed primarily in the EU (Germany/Finland). By using the Service, you understand that European data-protection law applies to the processing.
If you are a California resident, certain rights under the CCPA may also apply. Contact privacy@writano.com for CCPA-specific requests; we will respond on a best-efforts basis.
16. Contact
For any privacy question, request, or complaint:
- Email: privacy@writano.com
- Subject line: Data subject request — [your full name]
- Post: Atomira Technologies, S.L. — C/ Lepant 270, Bajos, 08013 Barcelona, Spain
For independent review: AEPD (https://www.aepd.es).
Document history
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-08-25 | Initial public release. |
Privacy questions or GDPR requests? Email privacy@writano.com.