Platform privacy notice
WP Feedback Limited (trading as Atarim)
This notice explains what personal data the Atarim platform handles, why, and what your rights are. It covers the platform itself. Our separate website privacy notice covers visitors to atarim.io.
Version 1.0 | 19th August 2026
1. Who this notice is for
Three different groups of people have personal data in Atarim, and they stand in quite different relationships to us. This notice covers all three, and says plainly which parts apply to whom.
Account holders. Agencies, brands and their teams who hold an Atarim account, together with the stakeholders and clients they invite into a workspace.
Guests. People who comment through a collaboration link without holding an account.
People who appear on a reviewed page. When someone uses Atarim to review a website, the platform captures an image of that page. If the page was displaying personal data at that moment, that data is captured too. Those individuals may never have heard of Atarim. Section 4 is about them.
2. Who is responsible for your data
This matters, because it determines who you go to.
Where a business uses Atarim to review websites, that business decides what goes into the platform and why. It is the controller. Atarim provides the software and processes the content on that business’s instructions. We are the processor.
In practice, if your data is inside someone’s workspace, the organisation that runs that workspace is responsible for it, not us. If you ask us to delete something, we will pass your request to them rather than acting on it ourselves. We explain why in section 8.
Where we handle data for our own purposes, we are the controller in our own right. That is a narrow set of things: running and securing the service, diagnosing faults, billing, and communicating with our own account holders. Section 9 covers it.
Where a business buys Atarim through a reseller, we and that reseller each decide our own purposes for the limited information we exchange with one another, such as staff contacts and account provisioning details. Neither instructs the other.
3. What the platform holds
| What | Detail |
|---|---|
| Account details | Name, email address, username, avatar, hashed password, role, time zone, and your onboarding or trial status |
| Guest details | Display name and email address, held against the comments you leave |
| Comments and tasks | The text you write, including anything personal you choose to put in it |
| Page details | The address and title of the page you commented on, which element you pinned the comment to, and where on the page it sits. A page address can itself identify someone, depending on how the site is built |
| Technical details | Which browser you used and related information shown in the task panel |
| Screenshots | Images of the page as your browser displayed it. See section 4 |
| Uploads | Files and attachments you add to a task |
| Inbound email | Where mail is sent to a workspace address, the full message and the sender’s address become a task |
| Connected tool access | Where a workspace connects its own Slack, Jira or similar, the credentials needed to do so |
| Search terms | Where you or the AI features search for stock imagery, the search text |
| Derived data | Data derived from workspace content, used so the AI features can recall earlier context |
| Activity records | References to who did what and when. These record which record was touched, not its contents |
| Billing references | Plan, subscription status and a reference to the payment provider |
The platform is not intended for health data, criminal records, payment card numbers, government ID numbers or anything comparable, and our terms prohibit submitting them to the AI features.
4. Screenshots, and people who never signed up
How it works. When someone reviews a page, the screenshot is produced in their own browser. It captures the page exactly as that person could see it, including anything behind a login.
What that means. If a reviewer is logged in to an area showing customer records, an order list, a member directory or a submitted form, that information is captured into the image. The people in it have no relationship with Atarim.
What we cannot do. We cannot detect when an image contains information of that kind. The platform sees a picture.
Who is responsible. The business operating the workspace is the controller of those images. It decides to use the product, its people take the screenshots, and it is responsible for telling affected individuals and for having a lawful reason to hold the data.
What can be done about it. Any element on a page carrying the CSS class no-screenshot is excluded from every capture, and we honour that by default. If you operate a website being reviewed, applying that class to areas showing customer records prevents them being captured at all. It is the single most effective control available, and it works best applied before a review programme starts rather than after.
If you think you appear in a screenshot, contact the business whose workspace it sits in. If you do not know who that is, write to us at operations@atarim.io and we will help you identify them.
5. Where your data is held
The main database, file storage and the store used by the AI recall features are all in Ireland. Backups are held in Ireland. Edge processing runs with regional controls that keep it within the European Union.
Some of the services we rely on are outside the UK and European Economic Area, mostly in the United States. Where that happens we use a transfer mechanism recognised under data protection law: either the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or the EU Standard Contractual Clauses with the UK Addendum, supported by an assessment of the risks for each provider.
The current list of providers, what each receives, where it is located and which mechanism applies is set out in our Data Processing Agreement, available on request.
6. Who we share it with
We do not sell personal data and we do not share it for anyone else’s marketing.
We use service providers to run the platform. Broadly:
- Infrastructure and storage, to host the service and hold files
- Artificial intelligence providers, described in section 7
- Email, to send service messages and to receive mail sent to workspace addresses
- Payments and subscriptions, to bill account holders
- Error monitoring and analytics, to keep the service working and improve it
- Rendering and file conversion, where a screenshot cannot be captured in the browser or a file needs converting
- Tools a workspace connects itself, such as Slack or Jira, which only receive data because that workspace chose to connect them
Each provider is under a contract requiring it to protect the data and to use it only for the service it provides to us. We remain responsible for what they do with it.
7. Artificial intelligence
What reaches a model. Comment threads and task context when you use the AI conversation features. The existing content of an element and the change you asked for when you use AI editing. The task text, and screenshots where visual scoring is switched on. A site’s public pages when brand details are extracted. And workspace content, so that the AI features can recall earlier context.
Is it used for training? No. Our AI requests are routed only to providers that operate on a zero data retention basis, meaning the provider does not keep the prompt or the response and therefore cannot train on it. We do not train our own models on customer content.
One exception. One of the providers we use for the AI recall features does not keep content for training, but does generate abuse monitoring records that may contain submitted content and holds them for up to 30 days before deleting them.
What the AI does not do. The platform does not make automated decisions about people that produce legal or similarly significant effects. The AI features act on website content, not on individuals.
8. Your rights
You have the right to ask for a copy of your data, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. You can also complain to a regulator.
Who to ask depends on whose data it is.
If your data sits in a business’s workspace, that business is the controller and the request goes to them. If you send it to us, we will not act on it ourselves, because doing so would mean changing their data without their instruction. We will forward it to them promptly and tell you we have done so.
If your data is held by us for our own purposes, as described in section 9, send your request to operations@atarim.io. We will respond within one month. If a request is complex we may need a further two months, and we will tell you within the first month if so.
Withdrawing consent. Where we rely on your consent, you can withdraw it at any time by contacting operations@atarim.io or our support team. Withdrawal does not affect anything done before you withdrew.
Complaints. In the UK, the Information Commissioner’s Office at ico.org.uk. In the EU, the supervisory authority in your own country. You do not have to come to us first, though we would rather you did so we can try to put things right.
9. What we hold for our own purposes
Separately from the content in workspaces, we hold a limited set of data as controller:
| What | Why | Our lawful basis |
|---|---|---|
| Account and billing records | To provide and bill for the service | Performance of our contract with you |
| Product usage data | To operate, secure and improve the platform | Our legitimate interest in a working product |
| Error and diagnostic data | To find and fix faults | Our legitimate interest in a reliable service |
| Messages to account holders | To tell you about the service and, where you have agreed, about new features | Consent, or our legitimate interest in servicing our own customers |
Where we rely on legitimate interests we have weighed our interest against your rights and recorded that assessment. You can object to processing on that basis at any time.
Analytics. We record how the Atarim application is used. We do not record what visitors do on a website being reviewed: session recording, automatic click capture and page view tracking are all switched off in the layer we inject into a reviewed page.
10. How long we keep Data
| Data | How long |
|---|---|
| Rate limiting records | 10 minutes |
| Cached AI responses | 24 hours |
| Files sent for format conversion | 24 hours |
| Backups | 7 days |
| Error and diagnostic data | 90 days |
| Product usage data | 24 months |
| Billing records | 6 years, to meet tax and accounting requirements |
| Activity records | Kept indefinitely, for security monitoring, audit and resolving disputes. These record references to actions rather than the content of records |
| Account and workspace content | For as long as the account is active, then as set out below |
When an account is deleted, the identifying details in the account record are replaced with a non-identifying placeholder and workspaces are removed from our database. That is completed within 30 days of a request, or within 90 days where deletion follows the end of a licence or a long period of inactivity.
What deletion does not reach. Stored images and file attachments remain in our file storage. So do the numeric representations used for AI recall, and any cached AI responses until they expire. Anything a workspace has already synchronised to its own connected tools is governed by that workspace’s arrangements with those tools. And deleted data may sit in our routine backups until they cycle out, which takes up to seven days.
We describe this as removing identifying details rather than as anonymisation, because related content is retained and the two mean different things.
11. Information Security
The database and file storage are encrypted, and data is encrypted in transit. The production database cannot be reached from the public internet, and the network is segmented.
Access by our staff requires an approved request, is granted on a least privilege basis, requires multi-factor authentication for production systems, is reviewed annually, and is removed within 24 hours of someone leaving.
Where Atarim writes changes to a WordPress site, it does so as the account you connected and can never exceed the permissions that account already had.
We hold a SOC 2 Type 2 report covering security, examined by an independent auditor, and we commission independent penetration testing at least annually. Details are available to business customers under a confidentiality agreement.
If something goes wrong, we notify affected business customers without undue delay and in any event within 72 hours of becoming aware, with what we know at the time and updates as we learn more.
12. Contact
WP Feedback Limited (trading as Atarim)
28 Kipling Way, Borehamwood, Hertfordshire WD6 2FS, United Kingdom
Company number 12010526
Data Protection Lead: operations@atarim.io
We use a role-based address rather than an individual so that your message reaches someone whatever changes internally.
13. Changes to this notice
We review this notice at least annually and whenever the platform changes in a way that affects it. Where a change materially affects your rights or how your data is handled, we will tell account holders directly rather than relying on you noticing.
Version 1.0, 19th August 2026. This is the first version of this notice.
This notice covers the Atarim platform. Visitors to atarim.io are covered by our website privacy notice. Business customers should read this alongside our Data Processing Agreement, which governs the terms on which we process data on their behalf.