Privacy Policy
Last updated: 27/09/2026
1. Data controller
The controller responsible for processing the personal data collected through the DatomWorx platform (hereinafter, "DatomWorx") is:
- Owner: Daniel Tomás Moronta
- Tax ID: 54049424E
- Trade name: DatomWorx
- Registered address: Carrer dels Jurats 22, 19, Valencia, España
- Privacy contact email: info@datomworx.com
- Website: https://datomworx.com
- Data Protection Officer (DPO): not appointed (not mandatory under art. 37 GDPR for processing of this scale). For any privacy query, use the email address above.
2. Data we process
Depending on how you use DatomWorx, we may process the following categories of data:
- Registration data: name or alias, email address and password (stored encrypted with bcrypt). You decide which name you give us.
- Google sign-up data: if you register with your Google account, we receive your name, email address and, where applicable, your profile picture and account identifier, according to the permissions you authorize.
- Account and plan data: plan type (Trial, Free, Pro or BOSS), subscription status, purchased or assigned passes, and relevant activity history (last login, active devices).
- Content you create: the content you generate in DatomWorx applications (projects, paths, simulations, exams, settings and similar; for example, projects and paths in the simulator or exams in the exam application) and anything you choose to share with other users.
- Data related to collaborative use: when you share a project, a template or any content with another DatomWorx user, we record that relationship (who shares, with whom, what content, date of sharing) to provide the collaboration feature and let you revoke access at any time.
- Location data (Routes): if you use the Routes application to record a route with GPS, we process the coordinates of that route — and those of your students, when it is linked to one of them — solely to save it and show it to you later.
- Vehicle data (Vehicles): if you use the Vehicles application, we process the registration number, make, model, mileage and the maintenance and incident history of the vehicles you manage.
- Community content: if you use the Community application, we process the posts, comments, chat messages, reactions and the details of your public profile (nickname, driving school, avatar) that you choose to share with other users. Community chat messages are not end-to-end encrypted; you can find full details in the Terms of access to the Community.
- Tax data (BOSS accounts only): registered business name, tax ID, address and phone number.
- Payment data (paid plans only): your card or payment method details are processed directly by Stripe Payments Europe Ltd. (Ireland). We only keep the customer identifier and transaction reference to issue receipts and provide support. We never see or store full card numbers.
- Technical and usage data: IP address, browser type, operating system, language, session identifiers and access/security logs.
- Free trial anti-fraud fingerprint: when you start the trial period of an application, we store an encrypted, irreversible code calculated from your email address and, if you have provided it, your tax ID (NIF), together with the application the trial relates to. See the section "Repeated use of the free trial" at the end of this policy.
- Data derived from map use: when you enable Google Maps in the applications that integrate it (e.g. the simulator), your interactions with the map are processed by Google (see section 6).
If you use DatomWorx as the owner, instructor or administrative staff of a driving school, and you record data about your students on the platform (identity, contact details, academic progress and, if your driving school requires it, data from the psychophysical medical examination required by traffic regulations — a special category of data under art. 9 GDPR), DatomWorx does not act as the controller of your students' data, but as a data processor on behalf of your driving school, which decides what that data is used for and is responsible for informing them appropriately. That processing is governed by the Data Processing Agreement, not by this Privacy Policy. If you are a student and wish to exercise your rights over that data, please contact your instructor or driving school.
3. Purposes and legal bases (art. 6 GDPR)
| Purpose | Legal basis |
| Create and manage your account and grant access to DatomWorx. | Performance of a contract (art. 6.1.b GDPR). |
| Provide the service's features (saving and sharing content, simulating, grading tests, maps, etc.). | Performance of a contract. |
| Manage subscriptions, payments, BOSS passes and receipts. | Performance of a contract and legal obligation (tax and accounting regulations). |
| Handle queries, support and complaints. | Performance of a contract or legitimate interest (art. 6.1.f GDPR). |
| Ensure security, prevent fraud and abuse (including preventing repeated use of the free trial and reviewing accounts with very similar data). | Legitimate interest and legal obligation. |
| Comply with tax, accounting and commercial obligations. | Legal obligation (art. 6.1.c GDPR). |
| Optional cookies (analytics, marketing). | Consent (art. 6.1.a GDPR), revocable at any time. |
| Sending commercial communications about DatomWorx (news, tips). | Express consent (optional checkbox at sign-up). |
We do not use automated decision-making or profiling systems with legal effects significant to users. Decisions about your account (plan assignment, suspensions, etc.) are made by people or by simple technical rules (e.g. subscription expiry) that do not fall within the scope of art. 22 GDPR.
4. Retention periods
- Account data: for as long as you keep your account active. If you request its deletion, it is erased within a maximum of 30 days, unless the law requires us to keep it longer.
- Payments and receipts: 6 years from issuance, in accordance with art. 30 of the Spanish Commercial Code and tax regulations.
- Economic records of your driving school (BOSS accounts): the payments, receipts, expenses and cash movements you manage for your driving school are kept for 6 years from their date, in accordance with art. 30 of the Spanish Commercial Code and tax regulations, even if you close your account or stop being a BOSS. DatomWorx does not issue invoices: it generates payment receipts for your students; issuing invoices, if your driving school needs them, is your own responsibility, outside the platform.
- Technical and security logs: 12 months from their creation.
- Free trial anti-fraud fingerprint: for as long as you keep your account. If you delete it, the fingerprint immediately ceases to be linked to you and is permanently erased after 2 years.
- Legal acceptance signatures (consents): for as long as the account exists and a minimum of 5 years after its closure, to demonstrate GDPR compliance.
- Accounts anonymized for not signing new legal versions (see section 10): personal data and content are deleted after the 3-month period described in section 10. Only receipts and the minimum records required by tax and accounting law are kept, dissociated from the holder's identity.
5. Recipients (data processors)
We share data with the following providers, all under data processing agreements compliant with art. 28 GDPR:
- Hosting: Hostinger International Ltd. (headquartered in the European Union; physical infrastructure in a data center within the European Economic Area).
- Payment gateway: Stripe Payments Europe Ltd. (Ireland, EU).
- Maps: Google Ireland Ltd. (Ireland, EU), provider of the Google Maps Platform service.
- Transactional email: Hostinger's SMTP service, under the same data processing agreement as hosting.
International transfers
Although all the providers above contract through their European subsidiary, some of them (in particular Google and Stripe) belong to corporate groups headquartered in the United States. As a result, part of the technical data processing may take place on group infrastructure outside the European Economic Area.
These transfers are safeguarded by:
- The Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914).
- The EU-US Data Privacy Framework, where providers are certified under it.
- Additional technical and organizational measures (encryption in transit and at rest, access controls, pseudonymization where applicable).
You can review the specific safeguards in Google's and Stripe's privacy policies linked in this document. We do not carry out any additional international transfers of personal data outside the European Economic Area beyond those described in this section.
6. Use of Google Maps
Some DatomWorx applications (e.g. the simulator) integrate Google Maps as an optional feature. When you enable it, Google Ireland Ltd. may process your technical data (IP, device identifier, map queries) in accordance with its Google Privacy Policy. If you do not want that processing to take place, do not enable real maps.
7. Your rights
As the data subject, you may exercise the following rights at any time:
- Access: obtain confirmation as to whether we process your data and which data.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): request the deletion of your data.
- Objection: object to the processing under certain circumstances.
- Restriction: request that we restrict the processing.
- Portability: receive your data in a structured, machine-readable format.
- Withdrawal of consent for cookies and commercial communications at any time, without affecting prior processing.
- Not to be subject to automated decisions producing significant legal effects (a right that applies even though, as stated in section 3, we do not carry out this type of decision-making).
To exercise them, write to us at info@datomworx.com stating "Exercise of GDPR rights" and attaching a copy of your ID document or equivalent. We will respond within the legal period of 30 days, extendable to 60 if the request is complex.
If you believe your rights have not been properly addressed, you may file a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).
8. Security
We apply reasonable and proportionate technical and organizational measures to protect your data:
- Encryption of communications via HTTPS/TLS.
- Passwords stored with bcrypt hashing (cannot be recovered in plain text).
- CSRF tokens on all forms and invisible anti-bot protection on login/registration.
- Security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy).
- Periodic encrypted backups.
- Access restricted to the controller and strictly necessary personnel.
- Logging of security incidents and notification to the AEPD within 72 hours where applicable (art. 33 GDPR).
9. Minimum age
The service is aimed exclusively at people over 18 years of age. By registering, you declare and warrant that you have reached the legal age of majority. If we detect that a user is under 18, we will suspend their account immediately and delete their personal data within a maximum of 30 days, except for data we are legally required to retain (receipts and accounting records).
10. Changes to this policy
If we modify this policy, we will notify you when you enter the application through a prominent notice. We distinguish two types of changes:
10.1. Minor changes
Wording corrections, clarifications, readability improvements or adjustments with no impact on your rights. These will apply automatically after a period of 15 days from notification. They do not require express signature; if you keep using the service after those 15 days, tacit acceptance will be understood, in line with the general doctrine of acceptance through conclusive acts.
10.2. Substantial changes
New processing purposes, new data processors, changes to your rights, changes to international transfers, or equivalent modifications affecting your privacy. We will ask for your new express acceptance. The procedure will be:
- You will have 15 days from notification to review and sign the new version. During that period you may keep using the service normally.
- After 15 days without signing, your session will be closed automatically. To access the service again you will need to either:
- Sign the new version by clicking "Accept", or
- Sign out permanently without accepting, by clicking "Review later and sign out". You may try again at any time while your account remains active.
- If 3 months after notification you still have not signed, your account will be automatically anonymized: your personal data and all your content (projects, paths, simulations, exams, settings, shared items and similar) will be permanently deleted. Only receipts and the minimum records required by tax and accounting regulations will be kept for the legal period of 6 years, dissociated from your identity.
You may delete your account voluntarily at any time from "Settings → Delete account" or by writing to info@datomworx.com.
11. Contact
For any query about privacy or data protection: info@datomworx.com.
Protection against unauthorized copies
The Simulator code includes a mechanism that detects when it is run outside DatomWorx's own domains (datomworx.com / datomworx.app) — for example, if someone copies the code and publishes it on their own website without authorization. In that specific case, the IP address, browser, language, screen resolution and the URL from which it is accessed are recorded, together with the infringing domain. This processing is based on our legitimate interest in protecting DatomWorx's intellectual property (GDPR art. 6.1.f) and is only activated outside our own domains — never when you use the Simulator normally on datomworx.com or datomworx.app.
Repeated use of the free trial
To prevent the same person from using an application's free trial period more than once, when you start a trial (or if you later add your tax ID to your account, for applications where you have already had a trial or a subscription) we store a fingerprint: an encrypted, irreversible code calculated from your email address (normalized: for example, without "+something" style additions, which do not change the mailbox) and, if you have provided it, your tax ID (NIF), together with the application the trial relates to. This fingerprint cannot be used to find out your email address or your tax ID; it only serves to know whether a trial has already been used in that application. If one has already been used, you will still be able to register and use the free plan normally; a new trial simply will not be opened.
In addition, to detect possible abuse, we may manually review accounts with very similar data (for example, the same mailbox, the same tax ID, numbered names or the same registration IP address). This review is carried out by a person and never blocks an account automatically.
Legal basis: our legitimate interest in preventing fraud (GDPR art. 6.1.f). The fingerprint is kept for as long as you keep your account; if you delete your account, the fingerprint immediately ceases to be linked to you and is permanently erased after 2 years. You can object to this processing by writing to info@datomworx.com.
Versión 1.1 · publicada el 27/09/2026