Daily Edition • Live Collaborative Storytelling • Coffee not included, but highly recommended

Privacy Policy and Personal Data Protection (GDPR)

Last updated: September 5, 2026 Version: 1.1 (Gutenberg Edition) DPO / Privacy Contact: legal@nodurix.com


1. Data Controller

The controller responsible for the processing of personal data collected through the CoPencils platform is:

ParameterCorporate Detail
Responsible Owner:Jaime Mateu Rico
Commercial Name / Project:Nodurix
N.I.F.:46956269-K
Contact Address:C/ Sant Jordi, 4, 07350 Binissalem (Illes Balears), Spain
Privacy and Rights Email:legal@nodurix.com
Activity Regime:Economic activity and software development managed by a natural person on an individual basis.

The Controller guarantees the protection of personal data in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).


2. Categories of Personal Data Processed

In compliance with the principle of data minimization (Art. 5.1.c GDPR), CoPencils processes exclusively the data necessary for the provision of the service and compliance with legal obligations:

  • Identification and account data: Name, surnames, pseudonym or author alias, email address, password protected by one-way cryptographic functions (irreversible hash), and profile picture or avatar.
  • Waitlist and early access data: Email address, verification identifier, and temporary record of the date and time of the request.
  • Subscription and billing data: Status of the contracted plan, tokenized identifiers assigned by the payment entity, transaction history, amounts paid, and currency.
📜Información Relevante

Informational note on payments: CoPencils does not access or store credit card numbers, billing bank accounts, or security codes (CVC/CVV). All payment operations are executed in secure environments and certified under the PCI-DSS standard directly by the payment entity (Stripe Payments Europe, Ltd.).

  • Tax and banking settlement data (exclusive for the payment of literary royalties): Full name and surnames, Tax Identification Number (NIF, NIE, or equivalent tax identification number for foreign residents), tax address, and banking data for transfer (IBAN/BIC code) or enabled digital collection account.
  • Navigation and telemetry data: Anonymized IP address, technical server logs necessary for abuse prevention, aggregated analytical events (only under express consent in the cookie selector), and performance metrics.

3. Purposes and Legal Bases of Processing

The processing of personal data is carried out in accordance with the following legitimizing bases (Art. 6 GDPR):

Purpose of ProcessingData CategoriesLegal Base (Art. 6 GDPR)
Management of registration, authentication, and use of writing and voting roomsIdentification data and access credentialsExecution of the service contract (Art. 6.1.b GDPR): The processing is essential for the registration and operation of the account.
Management of the waitlist and early access invitationsEmail and temporary verification identifierConsent of the data subject (Art. 6.1.a GDPR) manifested by voluntarily registering on the waitlist.
Collection of periodic subscriptions and specific servicesSubscription data, billing, and payment gateway tokensContractual execution (Art. 6.1.b GDPR).
Settlement of royalties to co-authors and compliance with tax obligationsTax data, billing, NIF, and payment bank accountCompliance with legal obligations (Art. 6.1.c GDPR), pursuant to the General Tax Law and applicable personal income tax/VAT regulations.
Preventive moderation and coherence analysis of literary textsProposed manuscripts and provided narrative sheetsLegitimate interest (Art. 6.1.f GDPR) in ensuring the security of the service against illicit or hate content and preserving product quality.
Statistical metrics and web usage analyticsAnalytical cookies and session logsExplicit consent (Art. 6.1.a GDPR) granted through the cookie configuration panel.

4. Recipients and Data Processors

Personal data is not transferred to third parties for advertising or commercial purposes unrelated to the service. For the operation of the infrastructure, certain technological service providers access data as Data Processors under Article 28 of the GDPR:

  1. Payment Gateway and Cross-Border Billing:
    Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA), in charge of payment management and automated calculation of applicable taxes.
  2. Hosting Infrastructure and Servers:
    Dedicated data centers located entirely within the European Union (Germany/Finland) contracted with cloud technology infrastructure providers with high physical and logical security standards.
  3. Transactional Communications and Notifications:
    Authenticated transactional email services under SPF, DKIM protocols, and TLS in-transit encryption.
  4. Web Analytics:
    Google Ireland Limited, restricted by default and activated exclusively when the user grants prior and unambiguous consent.

5. International Data Transfers

  • 5.1. Main Geographical Scope: Generally, data is stored and processed on servers located within the European Economic Area (EEA).
  • 5.2. Providers outside the EEA: In cases where auxiliary providers located outside the EEA process information (such as the headquarters of technological providers in the United States), such transfers are carried out under the European Commission's Adequacy Decision regarding the EU-US Data Privacy Framework or, failing that, by signing Standard Contractual Clauses (SCC) approved by the European Commission, ensuring a level of protection substantially equivalent to the community standard.

6. Data Retention Periods

Data will be kept for the strictly necessary periods taking into account their nature:

  • Active account data: Kept as long as the user maintains their operational account. Upon request for cancellation, the information will be deleted or anonymized.
  • Waitlist data: Maintained until the general opening of the service or until the user exercises their right to withdraw consent through the cancellation links provided in the emails sent.
  • Tax, accounting, and transactional documentation: In accordance with the Spanish Commercial Code and General Tax Law, invoices, payment receipts, and royalty settlements will be kept duly blocked for a period of five (5) to six (6) years exclusively available to the Tax Administration and judicial authorities for the attention of possible liabilities.
  • Authorial mention in published works: The name, alias, or pseudonym formally linked to consolidated chapters in completed works will be kept indefinitely in the credits of the work in unavoidable compliance with the inalienable moral right to authorship of the literary work (article 14 of the Intellectual Property Law).

7. Technical and Organizational Security Measures

In accordance with Article 32 of the GDPR, security measures aimed at safeguarding the confidentiality, integrity, and resilience of the systems are applied:

  • Encrypted communications in transit: In all sessions via secure HTTPS protocols (TLS 1.3) with updated certificates.
  • Strong passwords: Processed exclusively using high-strength one-way cryptographic functions (salting and robust bcrypt hash functions), preventing reading in clear text.
  • Environment isolation: Strict separation of production environments and databases with restricted access control and technical audit logs.
  • Preventive defenses: Systematic prevention of code injections through parameterized SQL queries in data access and web application firewall systems against unauthorized access.

8. User Rights (GDPR)

The interested party may exercise at any time, and free of charge, their rights recognized in articles 15 to 22 of the GDPR:

  • Access: Consult what personal data is being processed and request a copy thereof.
  • Rectification: Request the correction of inaccurate or incomplete data.
  • Erasure (Right to be forgotten): Request the deletion of their data when no longer necessary for the purposes collected, among other legal scenarios.
  • Restriction of processing: Request that the processing of their data be temporarily suspended in legally established cases.
  • Portability: Receive their data in an interoperable, structured, and machine-readable format, or request its direct transfer to another controller when technically feasible.
  • Objection: Object to the processing of their data when it is based on legitimate interest or directed to sending informative product communications.

Exercise Procedure

💡Canal de Ejercicio y Recomendación

Official Rights Service Channel:
Direct your request in writing to the official privacy email:
👉 legal@nodurix.com
Subject: Exercise of Data Protection Rights - CoPencils
Attach a copy or sufficient proof of your identity and detail the specific right you wish to exercise. The request will be answered within the maximum legal period of one (1) month from receipt.

Likewise, if you consider that the processing of your data violates regulations or you have not seen the exercise of your rights satisfied, you have the right to file a formal complaint with the supervisory authority:

  • Spanish Data Protection Agency (AEPD)
    C/ Jorge Juan, 6 - 28001 Madrid
    Website: www.aepd.es