Privacy Policy
Last updated: 09/08/2026
1. Data controller
The controller responsible for processing the personal data collected through the DatomWorx platform (hereinafter, "DatomWorx") is:
- Owner: Daniel Tomás Moronta
- Tax ID: 54049424E
- Trade name: DatomWorx
- Registered address: Carrer dels Jurats 22, 19, Valencia, España
- Privacy contact email: info@datomworx.com
- Website: https://datomworx.com
- Data Protection Officer (DPO): not appointed (not mandatory under art. 37 GDPR for processing of this scale). For any privacy query, use the email address above.
2. Data we process
Depending on how you use DatomWorx, we may process the following categories of data:
- Registration data: name or alias, email address and password (stored encrypted with bcrypt). You decide which name you give us.
- Google sign-up data: if you register with your Google account, we receive your name, email address and, where applicable, your profile picture and account identifier, according to the permissions you authorize.
- Account and plan data: plan type (Trial, Free, Pro or BOSS), subscription status, purchased or assigned passes, and relevant activity history (last login, active devices).
- Content you create: the content you generate in DatomWorx applications (projects, routes, simulations, exams, settings and similar; for example, projects and routes in the simulator or exams in the exam application) and anything you choose to share with other users.
- Data related to collaborative use: when you share a project, a template or any content with another DatomWorx user, we record that relationship (who shares, with whom, what content, date of sharing) to provide the collaboration feature and let you revoke access at any time.
- Tax data (BOSS accounts only): registered business name, tax ID, address and phone number, needed to issue you invoices.
- Payment data (paid plans only): your card or payment method details are processed directly by Stripe Payments Europe Ltd. (Ireland). We only keep the customer identifier and transaction reference for invoicing and support purposes. We never see or store full card numbers.
- Technical and usage data: IP address, browser type, operating system, language, session identifiers and access/security logs.
- Data derived from map use: when you enable Google Maps in the applications that integrate it (e.g. the simulator), your interactions with the map are processed by Google (see section 6).
3. Purposes and legal bases (art. 6 GDPR)
| Purpose | Legal basis |
| Create and manage your account and grant access to DatomWorx. | Performance of a contract (art. 6.1.b GDPR). |
| Provide the service's features (saving and sharing content, simulating, grading tests, maps, etc.). | Performance of a contract. |
| Manage subscriptions, payments, BOSS passes and invoicing. | Performance of a contract and legal obligation (tax and accounting regulations). |
| Handle queries, support and complaints. | Performance of a contract or legitimate interest (art. 6.1.f GDPR). |
| Ensure security, prevent fraud and abuse. | Legitimate interest and legal obligation. |
| Comply with tax, accounting and commercial obligations. | Legal obligation (art. 6.1.c GDPR). |
| Optional cookies (analytics, marketing). | Consent (art. 6.1.a GDPR), revocable at any time. |
| Sending commercial communications about DatomWorx (news, tips). | Express consent (optional checkbox at sign-up). |
We do not use automated decision-making or profiling systems with legal effects significant to users. Decisions about your account (plan assignment, suspensions, etc.) are made by people or by simple technical rules (e.g. subscription expiry) that do not fall within the scope of art. 22 GDPR.
4. Retention periods
- Account data: for as long as you keep your account active. If you request its deletion, it is erased within a maximum of 30 days, unless the law requires us to keep it longer.
- Invoicing and payments: 6 years from issuance, in accordance with art. 30 of the Spanish Commercial Code and tax regulations.
- Economic records of your driving school (BOSS accounts): the payments, receipts, expenses and cash movements you manage for your driving school are kept for 6 years from their date, in accordance with art. 30 of the Spanish Commercial Code and tax regulations, even if you close your account or stop being a BOSS. DatomWorx does not issue invoices: it generates payment receipts for your students; issuing invoices, if your driving school needs them, is your own responsibility, outside the platform.
- Technical and security logs: 12 months from their creation.
- Legal acceptance signatures (consents): for as long as the account exists and a minimum of 5 years after its closure, to demonstrate GDPR compliance.
- Accounts anonymized for not signing new legal versions (see section 10): personal data and content are deleted after the 3-month period described in section 10. Only invoices and the minimum records required by tax and accounting law are kept, dissociated from the holder's identity.
5. Recipients (data processors)
We share data with the following providers, all under data processing agreements compliant with art. 28 GDPR:
- Hosting: Hostinger International Ltd. (headquartered in the European Union; physical infrastructure in a data center within the European Economic Area).
- Payment gateway: Stripe Payments Europe Ltd. (Ireland, EU).
- Maps: Google Ireland Ltd. (Ireland, EU), provider of the Google Maps Platform service.
- Transactional email: Hostinger's SMTP service, under the same data processing agreement as hosting.
International transfers
Although all the providers above contract through their European subsidiary, some of them (in particular Google and Stripe) belong to corporate groups headquartered in the United States. As a result, part of the technical data processing may take place on group infrastructure outside the European Economic Area.
These transfers are safeguarded by:
- The Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914).
- The EU-US Data Privacy Framework, where providers are certified under it.
- Additional technical and organizational measures (encryption in transit and at rest, access controls, pseudonymization where applicable).
You can review the specific safeguards in Google's and Stripe's privacy policies linked in this document. We do not carry out any additional international transfers of personal data outside the European Economic Area beyond those described in this section.
6. Use of Google Maps
Some DatomWorx applications (e.g. the simulator) integrate Google Maps as an optional feature. When you enable it, Google Ireland Ltd. may process your technical data (IP, device identifier, map queries) in accordance with its Google Privacy Policy. If you do not want that processing to take place, do not enable real maps.
7. Your rights
As the data subject, you may exercise the following rights at any time:
- Access: obtain confirmation as to whether we process your data and which data.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request the deletion of your data.
- Objection: object to the processing under certain circumstances.
- Restriction: request that we restrict the processing.
- Portability: receive your data in a structured, machine-readable format.
- Withdrawal of consent for cookies and commercial communications at any time, without affecting prior processing.
- Not to be subject to automated decisions producing significant legal effects (a right that applies even though, as stated in section 3, we do not carry out this type of decision-making).
To exercise them, write to us at info@datomworx.com stating "Exercise of GDPR rights" and attaching a copy of your ID document or equivalent. We will respond within the legal period of 30 days, extendable to 60 if the request is complex.
If you believe your rights have not been properly addressed, you may file a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).
8. Security
We apply reasonable and proportionate technical and organizational measures to protect your data:
- Encryption of communications via HTTPS/TLS.
- Passwords stored with bcrypt hashing (cannot be recovered in plain text).
- CSRF tokens on all forms and invisible anti-bot protection on login/registration.
- Security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy).
- Periodic encrypted backups.
- Access restricted to the controller and strictly necessary personnel.
- Logging of security incidents and notification to the AEPD within 72 hours where applicable (art. 33 GDPR).
9. Minimum age
The service is aimed exclusively at people over 18 years of age. By registering, you declare and warrant that you have reached the legal age of majority. If we detect that a user is under 18, we will suspend their account immediately and delete their personal data within a maximum of 30 days, except for data we are legally required to retain (invoicing).
10. Changes to this policy
If we modify this policy, we will notify you when you enter the application through a prominent notice. We distinguish two types of changes:
10.1. Minor changes
Wording corrections, clarifications, readability improvements or adjustments with no impact on your rights. These will apply automatically after a period of 15 days from notification. They do not require express signature; if you keep using the service after those 15 days, tacit acceptance will be understood, in line with the general doctrine of acceptance through conclusive acts.
10.2. Substantial changes
New processing purposes, new data processors, changes to your rights, changes to international transfers, or equivalent modifications affecting your privacy. We will ask for your new express acceptance. The procedure will be:
- You will have 15 days from notification to review and sign the new version. During that period you may keep using the service normally.
- After 15 days without signing, your session will be closed automatically. To access the service again you will need to either:
- Sign the new version by clicking "Accept", or
- Sign out permanently without accepting, by clicking "Review later and sign out". You may try again at any time while your account remains active.
- If 3 months after notification you still have not signed, your account will be automatically anonymized: your personal data and all your content (projects, routes, simulations, exams, settings, shared items and similar) will be permanently deleted. Only invoices and the minimum records required by tax and accounting regulations will be kept for the legal period of 6 years, dissociated from your identity.
You may delete your account voluntarily at any time from "Settings → Delete account" or by writing to info@datomworx.com.
11. Contact
For any query about privacy or data protection: info@datomworx.com.
Versión 1.5 · publicada el 09/08/2026