Legal
Privacy policy
All legal pages apply to Inowara, a service owned by UMS Solutions d.o.o., Belgrade 11050, Serbia — VAT ID 114522183, company number 22034588. Responsible person: Marko Uljarević.
1. Who processes your data
The data controller is UMS Solutions d.o.o., Belgrade 11050, Serbia — VAT ID 114522183, company number 22034588, the company providing the Inowara service at inowara.com, app.inowara.com and social.inowara.com.
For any data protection question: office@inowara.com. We have not appointed a Data Protection Officer, because the law does not yet require one for us; if that changes we publish the contact here.
This policy explains what we do with the data of Inowara users and of visitors to inowara.com.
2. What data we collect
Account data
Username, email address, password (stored encrypted — we never see it), company name and site address, billing details if you are on a paid plan, content language and settings.
Service usage data
The sites you add, the pages we fetch from your site, topics and keywords in the plan, texts we generate and you edit, images, the publishing calendar, the history of publishes to connected channels, and plan consumption.
Technical data
IP address, device and browser type, access time, pages opened in the application and errors that occurred. This is created automatically and serves security and troubleshooting.
Communication
Messages you send through the contact form or by email, and our correspondence with you.
What we do not ask for: we do not want special categories of data — health, religion, political opinions, biometrics. Please do not enter them into free-text fields.
3. Why we process data and on what basis
| What we do | Why | Legal basis |
|---|---|---|
| Opening and running an account, access to the app | Without it there is no service | Performance of a contract |
| Reading your site, writing and publishing content | That is the service you asked for | Performance of a contract |
| Billing, invoices, accounting | To charge for the service and meet tax obligations | Contract and legal obligation |
| Support and answering questions | So you get help when something breaks | Contract / legitimate interest |
| Security, abuse prevention, access logs | To keep the service safe | Legitimate interest |
| Product improvement and aggregate usage statistics | So we know what to fix | Legitimate interest |
Where we rely on legitimate interest, we assess that this interest does not override your rights — and we can show you that assessment on request.
4. Data from your website
For Inowara to write about your services, it first has to read your site. We fetch publicly
available pages (through sitemap.xml or a shallow crawl), respect
robots.txt and never attempt to reach anything behind a login.
- From the fetched pages we build a knowledge base about your business: services, audience, advantages, locations and the contact details you published yourself.
- If your public pages contain personal data (staff names, phone numbers, addresses), it can enter that knowledge base and the generated texts. You are responsible for the content of your site and for the basis on which that data is published there.
- The knowledge base is used only for your account. It is not used for other sites, not included in shared datasets and never sold.
- Deleting a site from the account deletes the fetched pages and the knowledge base with it.
5. How long we keep data
- Account data and content in the account — while you have an account. After account deletion: 30 days during which it can be restored, then permanent deletion.
- Billing data and invoices — as long as tax law requires; in Serbia that is 10 years.
- Fetched pages and knowledge base — while the site exists in the account; deleted together with it.
- Technical logs — 7 days.
- Support correspondence — 24 months.
Backups are deleted on the normal rotation cycle, at the latest 90 days after deletion from production.
6. Who we share data with
We do not sell your data. To anyone, ever.
We share it only with processors that help the service run, and only to the minimum extent needed. Categories of processors:
- Hosting and infrastructure — servers and databases located in the European Union.
- AI text processing provider — processing text to produce content. What is sent is what the writing needs (topic, keywords, an extract from your knowledge base), not your login credentials or billing data.
- Image provider — sourcing or generating illustrations for articles, based on the article topic.
- Email provider — sending notifications about generation and publishing.
- Platforms you connect yourself — Google, Meta, TikTok, your CMS. They receive what you asked to be published or read; details are in the next three sections.
7. Google Search Console
If you connect your Google Search Console account, the following applies — and it is written more strictly than the law requires:
Access is read-only. We change nothing in your Google account, we do not add or remove sites, and we send nothing back. We do not share the retrieved data with anyone.
Which permissions we request
On Google's consent screen you see exactly this — nothing more is requested:
- openid and email — so we know which account is connected and can link it to your account with us.
- Search Console, read-only (
webmasters.readonly) — the list of sites you have in Search Console and their search data: queries, clicks, impressions, positions and pages.
We do not request write permission and cannot obtain it silently — Google would display it on that same screen.
What we do with that data
- We show it to you in your account and use it to spot texts that are underperforming and suggest refreshing them.
- We do not use it for other accounts, do not include it in aggregate statistics anyone else can see, and do not sell it.
- You can disconnect at any time from the site settings. We then stop retrieving new data, and the history already retrieved is deleted together with the site.
Google API Services User Data Policy
Inowara's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Facebook, Instagram and TikTok
If you connect social accounts, Inowara publishes content you approved on your behalf. We request only the permissions needed for that:
- Facebook / Instagram (Meta) — the list of pages you manage, basic details of the connected Instagram account, publishing content, and reading statistics for posts we created.
- TikTok — basic account details and publishing the video you approved.
Access tokens are stored encrypted. We do not read your private messages, we publish nothing you have not approved through the calendar or through automatic publishing you switched on yourself, and we use data from your accounts for nothing other than showing you the results. You can disconnect at any time in the settings, and revoke access from Meta's or TikTok's side as well.
9. Access to your site and CMS
To publish a text to your site we need access credentials — for example a WordPress application password, a Webflow API token or a Ghost Admin API key.
- Those secrets are stored encrypted (AES-256-GCM) and used solely to publish the content you ordered.
- We use the minimum scope needed: we write articles, images and article labels. We do not touch site settings, users or other content.
- You can delete an integration at any time, which deletes the stored secret. We recommend also revoking that access on your side afterwards.
10. Your rights
Under the GDPR and Serbian data protection law you have the right to:
- access — to learn what data we hold about you and receive a copy;
- rectification — to correct inaccurate or incomplete data;
- erasure — to request deletion, except what we must keep by law;
- restriction of processing — to freeze processing while something is clarified;
- portability — to receive your data in a common, machine-readable format;
- objection — to object to processing based on legitimate interest, including direct marketing;
- withdrawal of consent — at any time, without affecting processing already carried out;
- complaint to a supervisory authority — in Serbia that is the Commissioner for Information of Public Importance and Personal Data Protection; in the EU, the authority in your country.
Send requests to office@inowara.com. We answer within 30 days; if a request is complex the deadline can be extended, and we tell you so. Requests are free unless manifestly unfounded or repeated without reason. Instructions for deleting data are on the Data deletion page.
We make no automated decisions about you that produce legal effects for you.
11. Security
What we do concretely:
- encrypted connections (HTTPS) on all pages and for all calls;
- passwords stored in a form that cannot be reversed into readable text;
- secrets for connected accounts and CMSes stored encrypted (AES-256-GCM);
- access to data limited to those who need it for the work, with access records;
- regular backups, separated from production;
- regular component updates and monitoring of security advisories.
No system is impenetrable. If a breach occurs that may put your rights at risk, we notify the supervisory authority within 72 hours and you without delay where the risk is high.
12. Children
The service is not intended for people under 18 and we do not knowingly collect their data. If we learn that a child opened an account without parental consent, we delete it.
13. Changes to this policy
We update this policy when the way we work or the law changes. The date of the last change is always at the top of the page. Material changes are announced by email at least 15 days in advance.
14. Data protection contact
Support and requests: office@inowara.com
Supervisory authority in Serbia: Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, Belgrade.