Privacy Policy
What Atomic Studio Cloud receives, what it keeps, and for how long.
In short
This policy is short because there is very little to describe, and that is a design decision rather than an omission. Atomic Studio Cloud does not keep the designs you convert or the content generated from them — only a short import history with a small preview of each imported frame, plus the imports you choose to share — and the WordPress plugin stores one thing on your site: a private key, encrypted, that it uses to sign its requests and never sends anywhere.
Atomic Studio Cloud converts Figma designs into Elementor content. This policy covers that service and the Atomic Studio for Elementor plugin that talks to it.
Atomic Studio is the name of the product, not of a company. The service is run by the company below, which decides how your personal data is used: the data controller under the GDPR, and the responsible party under South Africa's POPIA. "We" and "us" in this policy mean that company.
- Khomba Business Networking (PTY) LTD, a private company registered in South Africa
- Registration number: 2013/217447/07
- VAT number: 4450319621
- Address: Unit 2 Tana Close, 2 12th Street, 2195 Linden, South Africa
What we receive, and when
Everything the plugin sends is listed below. There is nothing else — the plugin has no other outbound request. One row is not received by us: during an import your site downloads the design's images directly from Figma's image storage.
| What | When | Why |
|---|---|---|
| Your site's address | Every time you open an Atomic Studio screen | It identifies your site, and it is the key your Figma authorization is stored under |
| A signed, single-use statement from your site | Every time you open an Atomic Studio screen | It proves the request comes from your site: your site signs it with a private key only your site holds, and Atomic Studio Cloud accepts each statement once |
| Your site's public key | In that statement, and in your site's answer the first time Atomic Studio Cloud asks to confirm it | It identifies your site. It is public by design; the private half never leaves your site |
| Your WordPress admin's address | In that signed statement | So Atomic Studio Cloud accepts calls from your admin screens when they are on a different address from your site |
| Your WordPress user ID and capabilities | In that signed statement | So Atomic Studio Cloud allows only the actions you are allowed to take |
| The Atomic Studio plugin's version number | With every request the plugin's screens make to Atomic Studio Cloud | So Atomic Studio Cloud can keep older plugin versions working |
| The Figma file and frame URL you paste | When you convert a design | It is the thing being converted. Atomic Studio Cloud reads that frame from Figma on your behalf |
| Your site's server address (its IP address), to Figma's image storage on Amazon S3 | When you import a design that contains images | Your site downloads each image into its media library from the address Figma issued for it, so your published pages never load images from Figma |
| Whether you chose to share imported designs to improve conversion quality | In that signed statement | Atomic Studio Cloud keeps a copy of a conversion only when your site says an administrator opted in |
| The ID and address of the page an import created, or the error code if it failed | After each import | So the import history can say what each import produced and link to the page |
What is never sent:
- Your posts, pages or any other site content
- Your users, their emails, or their passwords
- Comments, orders, or anything from other plugins
- Your site's private key — it never leaves your site
If you use the sandbox at our website without installing the plugin, we receive the Figma URL you paste and the usual information any web server receives: your IP address, your browser's user agent, and the time of the request.
If you create an account on our website, we receive your email address and, if you enter them, your name and organization. If you sign in with Google or GitHub, we receive your name and email address from them. If you set a password, we store it only as a hash.
Why we hold so little
The plugin proves your site's identity with a key of its own. When you open an Atomic Studio screen, your site signs a single-use statement with its private key, and we check the signature against its public key. The first time we see a key, we make one request back to your site's address to confirm the key belongs to it; only whoever controls the domain can answer. A site we cannot reach, such as a local or password-protected one, still works: we then know it only by its key, and never connect it to the site that owns that address.
The private key never leaves your site, and we hold only the public half, so nothing we store could be used to act as your site. Changing your site's address makes you a different site to us, and you will need to authorize Figma again.
How long we keep things
| Data | Kept for |
|---|---|
| The designs you convert, and the Elementor content produced from them | Not kept at all, unless you opt in to sharing imported designs. Converted and returned. Unless an administrator opted in to sharing, neither the design's content nor the generated Elementor content is written to disk or database. |
| Shared imports, only if you opt in: what Atomic Studio Cloud read from Figma for each import, a picture of each frame, and the Elementor content it made. Nothing from your WordPress site | 90 days, or until you turn sharing off, delete the import's history entry, or your site record is deleted |
| Import history: the Figma file and frame names and IDs, a small preview image of the frame, and the ID and address of the page each import created | 180 days, or until you delete the entry or your site record is deleted |
| Figma authorization | Until you disconnect, or 90 days after your site stops appearing |
| Site record (address, public key and timestamps) | Until 90 days idle, then deleted — 14 days for a site Atomic Studio Cloud could not reach |
| Rate-limit counters | 24 hours |
| Server logs | 30 days. Tokens never appear in them |
| Screen sessions | One hour. Stored hashed, never the token itself |
| Sandbox previews at a shared link | 7 days, then deleted automatically |
| Your website account: email address, name and organization | Until you ask us to delete it |
The first row is the important one. Your designs and the Elementor content generated from them are converted and returned. Unless you opt in to sharing them, they are not written to a disk or a database, so there is nothing to delete, leak or hand over.
The import history is the other exception. For each import it records which Figma frame was used, a small preview image of that frame, and which page it created on your site, so the Import history screen can show them side by side. The page itself is never copied to us: the screen asks your site for it. You can delete any entry from that screen, and every entry is deleted after 180 days.
Sharing imported designs is the exception you choose. It is off unless an administrator ticks the box when agreeing to use Atomic Studio Cloud, or switches it on later on the Import history screen. While it is on, for each import we keep what we read from Figma for that import, a picture of each frame as Figma draws it, and the Elementor content we produced. We use these copies only to improve conversion quality: we re-run the conversion with later versions of the converter and measure how closely the result matches the design. Atomic Studio staff may download the copies to their own computers to do that work. Nothing from your WordPress site is included. Each copy is deleted after 90 days, when you delete that import's history entry, or when you switch sharing off — switching it off deletes everything already shared.
Previews created in the sandbox are the exception, because a shareable link has to point at something. They are deleted automatically after seven days, and you can delete one yourself at any time from the preview itself.
Who else is involved
| Who | What for | When |
|---|---|---|
| Figma | Reads the design you asked to convert, and serves its images to your site from Amazon S3 during an import | Only when you convert or import, and only the file you named |
| Our hosting provider | Runs Atomic Studio Cloud, so it receives each request's IP address and keeps the server logs | Continuously |
| Our database provider | Stores site records, Figma authorizations, import history, website accounts and, if you opt in, shared imports | Continuously |
Atomic Studio Cloud runs, and stores your data, in the European Union, in Ireland. Figma, which you connect yourself, is a company in the United States.
We name the providers we use on request — write to the address in the last section. We will update this list before we start using a new kind of provider, not afterwards.
Your rights
Under the GDPR and similar laws you can ask for a copy of your personal data, ask us to correct or delete it, and object to how we use it. Given how little we hold, most of these requests resolve quickly.
You can act on most of them without contacting us at all: disconnecting Figma removes the authorization, switching off sharing deletes every shared import, deleting a preview removes it immediately, and a site record disappears on its own 90 days after your last use.
For anything else, write to us at the address in the last section. We will respond within 30 days.
If you are unhappy with how we handle your data, you can complain to a supervisory authority: in South Africa the Information Regulator, and in the European Union the data protection authority of the country where you live or work.
Changes to this policy
The version and effective date at the top of this page change whenever the text does. If a change materially affects what we collect or how long we keep it, we will say so on the Atomic Studio screens in WordPress rather than relying on you to re-read this page.
The plugin ships a copy of the disclosure that matches the version it was released with. If the two ever disagree, this page is the current one.
Contact
Questions about this policy, or a request about your data: privacy@atomicstudio.ai. Post goes to the address under "In short".
Our Information Officer under South Africa's POPIA, and our representative in the European Union under Article 27 of the GDPR, is Jan Hendrik van Vlastuin. Both are reachable at privacy@atomicstudio.ai.