Privacy Policy
Last Updated:
This Privacy Policy (“Privacy Policy”) describes how CodeAce IT Solutions LLP (“CodeAce,” “Writto,” “we,” “us,” or “our”) collects, uses, processes, stores, discloses, and protects information when you access or use Writto, including our website, application, software, features, and related services (collectively, the “Services”).
This Privacy Policy also explains your privacy rights and choices regarding your personal information.
Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.
If you do not agree with the practices described in this Privacy Policy, you should not access or use the Services.
This Privacy Policy forms part of and is incorporated into the Writto Terms of Service. Capitalized terms not defined in this Privacy Policy have the meanings given to them in the Terms of Service.
1. Definitions
For purposes of this Privacy Policy, the following terms have the meanings set out below:
“Account” means an account created by you to access or use the Services.
“Customer Content” means content, information, documents, files, prompts, instructions, data, and other materials submitted, uploaded, connected, transmitted, or otherwise made available to Writto through the Services.
“Personal Data” or “Personal Information” means information that identifies, relates to, describes, or can reasonably be associated with an identified or identifiable individual, as defined by applicable privacy and data-protection laws.
“Processing” means any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, use, disclosure, alteration, retrieval, or deletion.
“Service Provider” means a third party that processes information on behalf of CodeAce to provide, support, secure, or improve the Services.
“Services” means Writto's website, application, software, features, content, and related services.
“Usage Data” means information collected automatically about how you access or use the Services, including technical, diagnostic, and interaction information.
“You” or “User” means the individual accessing or using the Services or the company, organization, or other legal entity on whose behalf that individual is accessing or using the Services.
2. Information We Collect
We collect information that you provide directly, information generated through your use of the Services, and information collected automatically.
The categories of information we may collect include the following.
2.1 Account and Registration Information
When you create or manage an Account, we may collect information such as:
- First and last name;
- Email address;
- Password or authentication information;
- Company or organization name;
- Job title or professional information;
- Account preferences; and
- Other information you choose to provide.
2.2 Billing and Transaction Information
If you purchase a paid Subscription Plan, we may collect information relating to your subscription and transactions, including:
- Subscription plan;
- Billing status;
- Transaction history;
- Billing address;
- Invoice information; and
- Payment-related information.
Payment card information may be collected and processed directly by third-party payment providers. We may receive limited payment information from such providers as necessary to process and manage your subscription.
2.3 Customer Content
When you use Writto, you may provide Customer Content such as:
- Text and documents;
- Prompts and instructions;
- Reference materials;
- Brand information;
- Content guidelines;
- Brand voice information;
- Files and other materials;
- Projects and campaigns;
- Content drafts;
- Content generated or edited through the Services; and
- Other information you choose to submit or store through Writto.
Customer Content may contain Personal Data depending on what you choose to provide.
You are responsible for ensuring that you have the appropriate rights and permissions to provide information to Writto for processing.
2.4 Communications
If you contact us, request customer support, submit feedback, participate in surveys, or otherwise communicate with us, we may collect:
- Your name;
- Contact information;
- The contents of your communication;
- Support requests and related information; and
- Other information you voluntarily provide.
2.5 Usage Data
We may automatically collect information about your interaction with the Services.
This may include:
- IP address;
- Browser type and version;
- Operating system;
- Device type;
- Device identifiers;
- Pages or screens accessed;
- Features used;
- Dates and times of access;
- Session information;
- Referring and exit pages;
- General location information;
- Interaction and usage information;
- Error and diagnostic information; and
- Other technical information.
We use Usage Data primarily to operate, secure, monitor, analyze, and improve the Services.
3. Information Collected Through Cookies and Similar Technologies
We may use cookies, pixels, local storage, software development kits, and similar technologies to operate and improve the Services.
These technologies may allow us to:
- Keep you signed in;
- Remember your preferences;
- Maintain session security;
- Understand how the website and Services are used;
- Measure performance;
- Detect errors and security threats;
- Improve functionality; and
- Support marketing activities where permitted by applicable law.
Where required by applicable law, we will obtain consent before using non-essential cookies or similar technologies.
Additional information about our use of cookies is provided in our Cookie Policy.
4. How We Use Personal Data
We may use Personal Data for the following purposes:
4.1 Providing the Services
We may use Personal Data to:
- Create and maintain your Account;
- Authenticate users;
- Provide requested features;
- Process Customer Content;
- Generate and deliver Outputs;
- Maintain your workspace;
- Provide integrations;
- Process subscriptions and transactions; and
- Provide customer support.
4.2 Operating and Improving Writto
We may use information to:
- Monitor and analyze use of the Services;
- Understand user preferences and product usage;
- Develop new features;
- Improve existing features;
- Diagnose technical problems;
- Test functionality;
- Improve reliability and performance; and
- Develop and improve our products and services.
4.3 Security and Fraud Prevention
We may process information to:
- Protect Accounts;
- Detect unauthorized access;
- Prevent fraud and abuse;
- Investigate security incidents;
- Protect the Services and infrastructure;
- Enforce our policies; and
- Protect the rights, property, and safety of Writto, our users, and others.
4.4 Communications
We may use your information to communicate with you regarding:
- Your Account;
- Subscriptions and payments;
- Security alerts;
- Service updates;
- Technical notices;
- Changes to our policies; and
- Customer support matters.
Where permitted by applicable law, we may also send promotional or marketing communications.
4.5 Legal and Regulatory Compliance
We may process Personal Data where necessary to:
- Comply with applicable laws;
- Respond to lawful requests;
- Comply with court orders or legal processes;
- Establish, exercise, or defend legal claims;
- Investigate suspected unlawful activity; or
- Protect our legal rights and interests.
5. AI-Powered Features and Processing
Writto provides AI-powered features that may process Inputs, Customer Content, and other information to generate Outputs or perform requested functions.
Depending on the feature you use, information submitted to Writto may be processed through third-party AI technologies or service providers that support our Services.
AI processing may include:
- Processing prompts and instructions;
- Processing reference materials;
- Generating or modifying content;
- Analyzing content;
- Providing recommendations;
- Optimizing content; and
- Performing other AI-assisted functions requested by you.
5.1 AI Model Training
Writto does not use Customer Content to train general-purpose AI models unless you have expressly agreed to such use or such use is otherwise permitted under an applicable agreement.
Where third-party AI providers process Customer Content on our behalf, we seek to use appropriate contractual and technical safeguards consistent with our obligations.
The specific AI providers used by Writto may change as our Services develop.
6. Legal Bases for Processing
Where applicable data-protection laws require us to identify a legal basis for processing Personal Data, we may rely on one or more of the following legal bases:
6.1 Performance of a Contract
We may process Personal Data where necessary to provide the Services, manage your Account, process transactions, or fulfill our obligations under our agreement with you.
6.2 Consent
We may process Personal Data where you have provided consent for a specific purpose.
Where processing is based on consent, you may withdraw your consent where permitted by applicable law.
Withdrawal of consent will not affect the lawfulness of processing conducted before the withdrawal.
6.3 Legitimate Interests
We may process Personal Data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your applicable rights and interests.
These interests may include operating, securing, improving, and developing our Services, preventing fraud, and communicating with users.
6.4 Legal Obligations
We may process Personal Data where necessary to comply with a legal or regulatory obligation.
6.5 Other Lawful Bases
We may rely on other lawful bases where permitted by applicable law.
The applicable legal basis may depend on the type of Personal Data, the purpose of processing, and the jurisdiction in which you are located.
7. How We Share Personal Data
We do not sell your Personal Data.
We may disclose or make Personal Data available to the following categories of recipients where reasonably necessary to provide the Services or operate our business.
7.1 Service Providers
We may use third-party Service Providers to support areas including:
- Cloud hosting and infrastructure;
- AI and machine-learning services;
- Payment processing;
- Authentication;
- Analytics;
- Customer support;
- Email and communications;
- Security and fraud prevention;
- Error monitoring;
- Application performance; and
- Other operational services.
Service Providers may process Personal Data only as necessary to provide services to us and subject to appropriate contractual, technical, or legal protections.
7.2 Business Transfers
If CodeAce participates in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, Personal Data may be transferred as part of that transaction.
Where required by applicable law, we will provide appropriate notice regarding such transfer.
7.3 Legal and Regulatory Authorities
We may disclose Personal Data when reasonably necessary to:
- Comply with applicable law;
- Respond to a valid legal request;
- Comply with a court order or governmental request;
- Protect our rights or property;
- Protect the safety of users or others; or
- Investigate fraud, abuse, or security incidents.
7.4 With Your Direction
We may disclose information when you direct us to do so or when disclosure is necessary to provide a feature or integration that you have requested.
8. Third-Party Services and Integrations
Writto may integrate with or provide access to third-party platforms, applications, APIs, AI providers, payment services, analytics providers, publishing platforms, and other services.
If you choose to connect a third-party service to Writto, information may be exchanged between Writto and that service as necessary to provide the integration.
Third-party services are governed by their own privacy policies and terms.
We are not responsible for the privacy practices, security, content, or policies of third-party services that we do not control.
9. Data Retention
We retain Personal Data for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, including to:
- Provide the Services;
- Maintain your Account;
- Fulfill contractual obligations;
- Comply with legal and regulatory requirements;
- Resolve disputes;
- Enforce our agreements;
- Prevent fraud and abuse; and
- Protect our legitimate business interests.
The specific retention period may vary depending on the type of information and the purpose for which it was collected.
When Personal Data is no longer required, we may delete, anonymize, or securely dispose of it, subject to applicable legal, contractual, and operational requirements.
Information stored in backups may remain for a limited period before being overwritten or securely deleted.
10. Data Security
We take reasonable technical, administrative, and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
Our security measures may include appropriate access controls, authentication mechanisms, monitoring, and other safeguards appropriate to the nature of the information and the risks involved.
However, no method of transmission or electronic storage is completely secure. We therefore cannot guarantee absolute security.
Additional information about our security practices is available in our Security / Data Security Policy.
11. International Data Transfers
Writto may use service providers, infrastructure, and technologies located in countries other than the country in which you reside.
As a result, Personal Data may be transferred to and processed in jurisdictions whose data-protection laws may differ from those of your jurisdiction.
Where required by applicable law, we will implement appropriate safeguards for international transfers of Personal Data.
These safeguards may include contractual protections, recognized transfer mechanisms, or other legally permitted measures.
12. Your Privacy Rights
Depending on your location and applicable law, you may have certain rights regarding your Personal Data.
These rights may include:
12.1 Right to Access
You may have the right to request information about the Personal Data we hold about you and to receive a copy of such information.
12.2 Right to Correction
You may have the right to request correction of inaccurate or incomplete Personal Data.
12.3 Right to Deletion
You may have the right to request deletion of your Personal Data in certain circumstances.
12.4 Right to Restrict Processing
You may have the right to request that we restrict the processing of your Personal Data in certain circumstances.
12.5 Right to Object
You may have the right to object to certain processing activities, including certain forms of direct marketing or processing based on legitimate interests.
12.6 Right to Data Portability
Where applicable, you may have the right to receive certain Personal Data in a structured, commonly used, and machine-readable format and to transmit it to another organization.
12.7 Right to Withdraw Consent
Where processing is based on consent, you may have the right to withdraw that consent.
12.8 Right to Lodge a Complaint
You may have the right to lodge a complaint with the data-protection or privacy authority applicable to your location.
These rights may be subject to limitations and exceptions under applicable law.
13. How to Exercise Your Privacy Rights
To exercise an applicable privacy right or submit a privacy-related request, contact us using the information provided in the Contact Us section below.
We may request information necessary to verify your identity before processing certain requests.
We will respond to valid requests within the period required by applicable law.
If we are unable to fulfill a request, we will explain the reason where required by law.
14. Marketing Communications
We may send you service-related communications necessary to operate your Account or provide the Services.
These may include:
- Account notifications;
- Billing communications;
- Security alerts;
- Product updates;
- Important service announcements; and
- Changes to our legal policies.
Where permitted by applicable law, we may also send promotional communications.
You may unsubscribe from promotional emails by using the unsubscribe mechanism provided in the communication or by contacting us.
Unsubscribing from marketing communications will not prevent us from sending essential service-related communications.
15. Children's Privacy
The Services are not intended for children who are below the minimum age required to use online services under applicable law.
We do not knowingly collect Personal Data from children in violation of applicable law.
If you believe that a child has provided Personal Data to us without appropriate authorization, please contact us so that we can investigate and take appropriate action.
16. Your Responsibilities Regarding Personal Data
If you submit Personal Data relating to another individual through Writto, you are responsible for ensuring that you have the necessary legal authority, consent, or other lawful basis to provide that information to us and for us to process it through the Services.
You should not submit sensitive Personal Data, confidential information, or other information to Writto unless:
- You are legally authorized to do so;
- The processing is appropriate for your intended use of the Services; and
- You have considered any applicable privacy, confidentiality, contractual, or regulatory requirements.
17. Data Controller and Data Processor Roles
Depending on the circumstances, CodeAce may process Personal Data in different capacities.
Where we determine the purposes and means of processing Personal Data, we may act as a data controller, Data Fiduciary, or equivalent role under applicable law.
Where we process Personal Data on behalf of a business customer according to that customer's instructions, we may act as a data processor, Data Processor, or equivalent role under applicable law.
Where required, additional contractual terms, including a Data Processing Agreement, may apply to such processing.
18. Account Deletion
You may request deletion of your Writto Account by contacting us or using available account-management functionality.
Following account deletion, we may delete or anonymize Personal Data and Customer Content associated with your Account in accordance with this Privacy Policy and our applicable retention practices.
We may retain certain information where necessary to:
- Comply with legal obligations;
- Resolve disputes;
- Prevent fraud or abuse;
- Enforce our agreements;
- Protect our legal rights; or
- Fulfill other lawful purposes.
19. Third-Party Links
The Services may contain links to websites, applications, or services operated by third parties.
We do not control those third parties and are not responsible for their privacy practices, security, content, or policies.
We encourage you to review the privacy policy of each third-party website or service you access.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
- The Services;
- Our business practices;
- Technologies we use;
- Applicable laws or regulations; or
- Our privacy and data-protection practices.
When we make material changes, we may provide notice through the Services, our website, email, or another appropriate method where required by applicable law.
The revised Privacy Policy will become effective on the date stated at the beginning of the updated policy.
We encourage you to review this Privacy Policy periodically to remain informed about our privacy practices.
21. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or Writto's privacy practices, please contact us:
CodeAce IT Solutions LLP
India
Email: admin@writto.ai
For privacy rights requests, please include sufficient information to identify your Account and understand the nature of your request.