PRIVACY POLICY

Last updated: August 23, 2026

Version: 2.0


1. WHO WE ARE AND THE SCOPE OF THIS POLICY

NPATI is operated by Individual Entrepreneur KOSTASHCHUK MARIIA ARTEMONIVNA, identification code 2358722027. In this Policy, “NPATI,” “we,” and “us” refer to that operator.

  • Website: https://www.npati.com
  • Privacy contact: privacy@npati.com
  • Support: support@npati.com

This Policy explains how NPATI processes personal data when you use the NPATI marketplace, accounts, content and social features, Plugins & Apps, NPATI Hub, support, and connected services. It also explains choices and rights that may apply based on your location.

NPATI is generally the controller when it determines why and how account, marketplace, website analytics, security, billing, and support data is processed. When a customer connects a WordPress website and instructs NPATI to process that customer's website content, the customer may be the controller and NPATI may act as a processor for that content. The roles depend on the particular workflow and applicable law. Customers that need a data processing agreement or current subprocessor information may contact privacy@npati.com.

2. INFORMATION WE PROCESS

2.1 Account and marketplace information

Depending on the features you use, we may process:

  • account identifiers, name or username, email address, phone number, profile photo, profile description, location and account settings;
  • authentication, session, permission and security information;
  • listings, titles, descriptions, prices, categories, tags, photographs, video, other uploaded media and publication status;
  • messages, comments, reviews, likes, saves, follows and other interactions;
  • order, transaction and billing records where paid services are used; payment card details are handled by the relevant payment provider rather than intentionally stored as full card data by NPATI;
  • support requests, privacy requests and communications; and
  • information you choose to make public through profiles, listings or other public features.

2.2 Technical and usage information

We may receive IP address, browser and device information, timestamps, requested URLs, referral information, approximate market or country, error and security events, cookie or local-storage identifiers, and interactions with NPATI features. Optional analytics and advertising technologies are controlled through the privacy choices interface described in our Cookie Policy.

2.3 Information from connected services

If you connect a third-party account or service, we receive the identifiers, authorization status, permissions, content and request data needed for the feature you selected. The data available depends on the service and the permissions you approve. NPATI does not require you to disclose third-party credentials through ordinary content fields.

3. NPATI PLUGINS, INTEGRATIONS AND CONNECTED SERVICES

3.1 WordPress connection and NPATI Hub

The NPATI Content Automation plugin does not begin pairing merely because it is installed or activated. A WordPress administrator starts the connection flow. When pairing starts, the plugin sends NPATI Hub the WordPress site URL and name, selected NPATI market, a site fingerprint, callback URL, and WordPress, PHP and plugin versions. The pairing flow also uses temporary pairing identifiers and security challenges. After authorization, WordPress stores a site-scoped connection identifier, site identifier, NPATI username, credential, Hub public key, permissions, status and timestamps.

If an administrator chooses to create an NPATI account from WordPress, the selected username, email address and password are sent directly to the NPATI registration endpoint after the administrator submits the form. The password is not stored in WordPress.

After connection, NPATI Hub and the plugin exchange data only when a connected feature or authorized workflow is used. Depending on the action, this may include:

  • WordPress post identifiers, titles, content, excerpts, status, publication and modification times, URLs, content hashes and SEO fields;
  • category and tag identifiers, names, slugs and descriptions;
  • media identifiers, URLs, filenames, MIME types, titles, alt text and captions;
  • publishing or scheduling instructions, workflow requests and permission information;
  • selected listing, profile, address, product or WooCommerce information when the corresponding marketplace feature is used; and
  • connection status, request identifiers, error codes and limited operational audit data.

Supported workflows can list, create, update, publish or move WordPress posts to Trash; list, upload or delete supported media; and list, create or delete categories and tags. These actions are limited by the connected permissions and plugin settings. Remote publishing is disabled by default and must be enabled in the plugin settings.

The purpose of this processing is to authenticate the site connection, provide requested content and publishing workflows, maintain synchronization, prevent replay or unauthorized requests, diagnose errors and protect the integration. Where the GDPR or similar law applies, the legal basis may be performance of a contract, the customer's documented instructions, consent for optional features, compliance with law, or NPATI's legitimate interests in providing and securing the service, depending on the data and context.

3.2 Local plugin data and retention

The plugin stores connection records, content mappings, processed-request records, settings and limited audit events in the WordPress database. Audit context excludes common credential, token, secret, password and signature fields. The configured audit retention is 7, 30 or 90 days, with 30 days as the default. Processed webhook request records are removed after 7 days. Pairing data is stored in a WordPress transient for up to 15 minutes.

Local plugin data remains under the WordPress site owner's control. Deactivation does not delete that data. During uninstall, data is deleted only if the administrator previously enabled the plugin's full-cleanup setting. Otherwise the plugin preserves local settings and planned work. Website owners should apply their own retention, backup and deletion policies to WordPress content.

3.3 Disconnecting and deletion

An administrator can disconnect the site from the plugin. Disconnecting asks NPATI Hub to revoke the connection, clears the active local site credential and stops future synchronization. It does not automatically delete WordPress posts, media, listings, previously published material, logs that must be retained for security, or content already sent to a connected service. To request deletion of NPATI account or Hub data, use https://www.npati.com/privacy/request or email privacy@npati.com. Deletion remains subject to backups, legal obligations, fraud prevention and the rights of other users.

3.4 Optional OpenAI integration

OpenAI is an optional third-party service. It is not contacted by the plugin until an administrator enters an OpenAI API key and tests or uses the AI feature. The plugin sends the key to OpenAI to retrieve compatible models and stores the selected key locally in WordPress using authenticated encryption derived from WordPress security salts; Sodium support is required. Disconnecting OpenAI deletes that local option.

For article generation, the plugin may send OpenAI an editorial title, description, keywords and category together with generation instructions. For social-copy generation, it may send an article title, URL and text. OpenAI returns generated text and metadata. The plugin currently sends store=false with Responses API requests, but OpenAI may still process request content and operational or abuse-monitoring data under its applicable business terms, privacy materials and data-control documentation. Do not include personal or confidential information in an AI request unless you are authorized to do so.

OpenAI API use is governed by the terms and privacy documentation associated with the administrator's OpenAI account:

  • OpenAI business terms: https://openai.com/policies/business-terms/
  • OpenAI privacy policy: https://openai.com/policies/privacy-policy/
  • OpenAI API data controls: https://platform.openai.com/docs/models/default-usage-policies-by-endpoint

3.5 ChatGPT-connected workflows

When a user invokes a compatible NPATI workflow through ChatGPT, the general flow may be: user to ChatGPT, ChatGPT to an NPATI tool or NPATI Hub, and NPATI Hub to the authorized WordPress website or connected social service. The instruction, account and connection identifiers, relevant content, tool results and technical request data may pass through the services involved. NPATI processes the request to authenticate the user, apply permissions and perform the selected action. OpenAI processes information in ChatGPT under the terms and privacy settings applicable to that user's ChatGPT account.

3.6 Social and other platform integrations

If you connect a social platform, NPATI Hub may process the account identifier, authorization token, granted permissions, target account, content, media URLs, schedule, time zone, publication status and service responses needed for the requested workflow. Social-network access tokens are not stored by the WordPress plugin and the plugin does not publish directly to a social API. NPATI Hub handles those connections. Each connected platform processes data under its own terms and privacy policy.

4. WHY WE USE INFORMATION

We process information as needed to:

  • provide accounts, marketplace, content, messaging, support, plugin, Hub and connected-workflow features;
  • authenticate users and integrations, apply permissions and carry out requested actions;
  • publish, schedule, synchronize and manage content selected by an authorized user;
  • process payments and maintain business and tax records where applicable;
  • maintain, troubleshoot, measure and improve NPATI;
  • prevent fraud, misuse, unauthorized access and security incidents;
  • communicate about the service and respond to requests; and
  • meet legal obligations and establish, exercise or defend legal claims.

Where applicable, direct marketing and optional analytics or advertising processing rely on the choice presented to the user or another lawful basis available in the relevant jurisdiction. You can change optional cookie choices at any time.

Where the GDPR or a similar law applies, account and requested-service processing generally relies on performance of a contract or steps requested before a contract; security, abuse prevention and service reliability may rely on legitimate interests after balancing affected rights; record keeping and lawful requests may rely on legal obligations; and optional marketing or technologies rely on consent when consent is required. The applicable basis depends on the specific purpose and jurisdiction.

5. DISCLOSURES AND RECIPIENTS

We may disclose relevant data to hosting and infrastructure providers, security and support providers, email providers, analytics providers selected through our consent controls, payment providers, professional advisers, OpenAI when the optional integration is used, and connected WordPress, social or other services selected by the user. We may also disclose information where required by law or necessary to protect rights, users and the service.

Public profile, listing, comment and other public content is visible to other users and may be indexed or copied outside NPATI. Messages are disclosed to their intended participants.

NPATI does not authorize service providers to use customer data for unrelated purposes, but third-party services connected directly by a user may act as independent controllers under their own terms.

6. INTERNATIONAL PROCESSING

NPATI and its providers may process information in countries other than the country where you live. The available transfer mechanism depends on the parties, locations and data involved. Where EU or UK transfer rules apply, NPATI will use an applicable lawful mechanism, such as an adequacy decision, approved contractual safeguards or a permitted derogation, as appropriate. Contact privacy@npati.com for information about safeguards relevant to a particular transfer. This Policy does not claim that a specific transfer mechanism applies where it has not been implemented and documented.

7. RETENTION

We retain data only for as long as reasonably necessary for the purpose for which it was collected, including to provide an active account or connection, complete a requested workflow, maintain security records, resolve disputes and meet legal, accounting or reporting duties. Retention depends on the type of record, account status, user choices, contractual requirements and applicable law.

Public content may remain until it is deleted or the account is removed, subject to moderation, backups, other users' rights and legal duties. Consent records are configured for up to 12 months. Analytics identifiers may persist for the periods listed in the Cookie Policy unless consent is withdrawn or browser storage is cleared. The plugin-specific local periods are described in Section 3.2. NPATI Hub records may remain after disconnect while needed under operational, security or legal retention criteria; disconnecting alone is not a remote-data deletion request.

8. SECURITY

No online service can guarantee absolute security. NPATI applies measures appropriate to the relevant feature, which include HTTPS for production API calls, site-scoped credentials, permission checks, signed and time-limited WordPress webhook requests, replay protection, limited audit logging and encrypted local storage of the optional OpenAI key. WordPress administrators remain responsible for securing their site, accounts, backups, users and hosting environment.

9. COOKIES, ANALYTICS AND PRIVACY CHOICES

Strictly necessary technologies support authentication, security and requested functionality. Functional, analytics and advertising technologies are disabled until the user makes the corresponding choice. Current storage keys, providers, purposes and durations are listed at https://www.npati.com/cookies.

Where supported by the browser, NPATI treats Global Privacy Control as an opt-out of advertising, sale or sharing preferences. You can reopen the privacy choices interface, withdraw optional consent or submit a privacy request. Withdrawing consent affects future use and does not by itself erase data previously processed under a lawful basis.

10. YOUR RIGHTS

Depending on your location and the law that applies, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about recipients and transfers. You may also have the right to complain to a competent data-protection authority. Withdrawal does not affect processing lawfully completed before withdrawal.

Submit a request at https://www.npati.com/privacy/request or email privacy@npati.com. We may need to verify identity and authority before acting. We will respond within the period required by applicable law and may retain information where an exception applies.

If NPATI processes WordPress or connected-service data solely for a customer, the customer may need to handle the request as controller. NPATI will provide reasonable assistance required by the applicable agreement and law.

11. EEA, UK AND UKRAINE INFORMATION

Where the GDPR, UK GDPR or Ukrainian data-protection law applies, the processing bases and roles are determined per purpose as described above. Legitimate interests may include securing NPATI, preventing abuse, providing requested non-sensitive service functionality and improving reliability, balanced against the individual's rights. Individuals may object where applicable and may lodge a complaint with the supervisory authority in their place of residence, work or the alleged infringement.

NPATI does not use plugin or AI workflows to make decisions based solely on automated processing that produce legal or similarly significant effects about website visitors. Automated workflows do carry out the authorized user's content instructions.

12. CALIFORNIA AND OTHER U.S. STATE RIGHTS

U.S. state privacy laws apply only when their statutory scope and thresholds are met. NPATI does not represent through this Policy that every such law applies to every NPATI activity. Where an applicable law grants rights, an eligible resident may request access or knowledge, correction, deletion and a portable copy; request limits on qualifying uses or disclosures of sensitive personal information; and appeal or opt out of processing designated by that law, subject to exceptions. NPATI will not unlawfully discriminate against a person for exercising an applicable privacy right.

Information categories processed during the preceding 12 months may include identifiers; customer records; commercial and transaction information; internet or network activity; approximate geolocation; audio, visual and user content; inferences used for recommendations; and account credentials or content that may be sensitive under a particular statute. Sources include users, devices and browsers, connected services, transaction providers and other users. Purposes and recipient categories are described in Sections 4 and 5.

Some U.S. laws define “sale,” “sharing,” or targeted advertising broadly. NPATI therefore provides an advertising and sale/sharing opt-out instead of making an unqualified claim that no activity can fall within those definitions. NPATI honors browser Global Privacy Control for that preference where supported. Submit other requests through https://www.npati.com/privacy/request or privacy@npati.com.

13. CHILDREN

NPATI is not directed to children under 13, and marketplace transactions and commercial publishing tools are intended for adults or duly authorized business users. If you believe a child provided personal data contrary to applicable requirements, contact privacy@npati.com.

14. CHANGES AND CONTACT

We may update this Policy as services, integrations or legal requirements change. The current version and update date will remain available at https://www.npati.com/privacy. Where required, we will provide additional notice or request consent for a materially different use.

Questions and requests may be sent to privacy@npati.com. General support is available at support@npati.com.