Privacy Policy
Last updated: September 2026
See also: Terms of Service
1. Introduction & Identity
This Privacy Policy explains how Attimo ("we," "us," or "our") collects, uses, stores, and protects personal data when you use our cloud-based CRM platform and related services.
Operator: Attimo
Contact: [email protected]
This policy is provided for transparency and does not constitute legal advice. We encourage you to consult qualified legal counsel for questions about your specific data protection obligations.
2. Data We Collect
Account Data
- Name, email address, and organization name provided during registration
- Billing and payment information (processed by Stripe)
- Authentication credentials (passwords are hashed and never stored in plain text)
CRM Data
- Contacts, companies, and associated details you enter into the platform
- Deals, pipeline stages, and revenue data
- Notes, tasks, activities, and calendar events
- Email correspondence and calendar data from connected integrations
Usage Data
- Page views, feature usage patterns, and interaction data
- Error logs and performance metrics
- Device type, browser version, and operating system
We use PostHog(PostHog Inc., US region) as our product analytics and error-tracking processor. It is used solely to operate and improve Attimo — to diagnose errors, understand feature usage, and reproduce issues you report. We do not use third-party advertising trackers, and we do not use analytics platforms that profile users across other websites.
Session recording.To diagnose bugs, we record sessions within the authenticated Attimo application. Values you type into form fields — including passwords, payment details, and search boxes — are masked and never recorded. Recording is limited to the Attimo app itself; we do not record the public pages your customers see, such as booking, proposal, or portal pages.
3. How We Use Your Data
- Service delivery: Operating and maintaining the CRM platform, including data storage, processing, and feature functionality
- Billing: Processing subscription payments and managing your account
- Support: Responding to your inquiries and providing technical assistance
- Product improvement: Analyzing aggregated, anonymized usage patterns to improve features and user experience
- Security monitoring: Detecting and preventing unauthorized access, fraud, and abuse
4. Legal Basis for Processing
We process personal data under the following legal bases:
- US state privacy laws (e.g. CCPA/CPRA): We process personal data to perform our contract with you and for the disclosed business purposes above. We do not sell or share personal data as those terms are defined under these laws
- GDPR Art. 6(1)(b): Contract performance — processing necessary to deliver the service you subscribed to
- GDPR Art. 6(1)(f): Legitimate interest — security monitoring, fraud prevention, and service improvement
- GDPR Art. 6(1)(a): Consent — for optional integrations (e.g., connecting Google Calendar or Microsoft accounts)
For CRM data that you enter into the platform, you (the customer) are the data controller and Attimo acts as a data processor. You are responsible for ensuring that your collection and use of personal data within the CRM complies with applicable data protection laws.
5. Data Sharing & Sub-Processors
We share data only with the following categories of sub-processors, solely to provide our service:
- Stripe (payments) — Processes billing and payment data. Headquartered in the USA; data transfers governed by Standard Contractual Clauses (SCCs)
- Google Cloud Platform (compute & hosting) — Application servers hosted in the United States (us-central1 region)
- Supabase (database) — PostgreSQL database hosted in the European Union
- Google / Microsoft (calendar & email integrations) — Only when you explicitly connect your account. Data flows directly between your account and our platform
- Twilio (communications) — Processes call and message data when you use communications features
- PostHog (product analytics & error tracking) — Processes usage events, error reports, and session recordings from the Attimo application. Hosted in the United States (US region)
- OpenAI (AI processing) — Processes call audio, transcripts, and CRM content you submit to AI features, including recording transcription and assistant queries
- AI voice agent providers — Process live call audio, call recordings, and transcripts when an AI voice agent is enabled
- Google Vertex AI (AI processing) — Processes documents you upload for data extraction, and CRM content submitted to assistant features. Runs in Google's
europe-west6region (Zurich, Switzerland)
Google API Limited Use. The use of raw or derived user data received from Google APIs (including Google Calendar) will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Attimo does not use Google user data to create, train, or improve foundational or generalized AI/ML models. Any AI features that may use synced calendar data do so only to provide or improve user-facing product features for the authorizing user/organization.
We do not sell, rent, or trade your personal data to any third party.
6. International Data Transfers
Our primary infrastructure is located in the United States (Google Cloud, us-central1) and the European Union (Supabase).
- AI document extraction and assistant features run on Google Vertex AI in Switzerland (europe-west6), which the European Commission recognizes as providing an adequate level of data protection
- Payment processing via Stripe involves data transfer to the USA, protected by Standard Contractual Clauses
- Third-party integrations (Google, Microsoft) transfer data only when you explicitly connect your accounts and are subject to those providers' privacy policies
7. Data Retention
- Active subscription: Your data is retained for the duration of your subscription
- After termination: Account and CRM data are deleted within 90 days of subscription termination
- Backups: Automated backups follow a rolling purge schedule and are fully removed within the retention window
- Legal holds: Data subject to legal obligations or legitimate disputes may be retained longer as required by law
8. Your Rights
Under applicable US state privacy laws and the GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Data portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Revoke consent for optional processing (e.g., integrations) at any time
- Non-discrimination: Exercise these rights without receiving degraded service or different pricing
- Lodge a complaint: File a complaint with your state Attorney General (such as the California Privacy Protection Agency), the US Federal Trade Commission, or — if you are in the EU/EEA — the relevant EU supervisory authority
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data is encrypted at rest and in transit (TLS 1.2+)
- Organization-level data isolation through Row Level Security (RLS) at the database level
- Role-based access controls within each organization
- Integration tokens (e.g., Google Calendar, Microsoft) are stored encrypted
- Regular security reviews and infrastructure monitoring
10. Waitlist & Referral Program
When you sign up for the Attimo waitlist, we collect and process the following data:
Data Collected
- Name and email address (required to reserve your spot)
- Company name and company size (optional, to understand your needs)
- A hashed version of your IP address (for fraud prevention; we do not store raw IP addresses)
- Referral code (if you joined via a referral link, to track referral relationships)
Referral Tracking
- When you share your unique referral link, we track which signups originated from your link
- A
fp_refcookie (30-day expiry) is set when someone visits your referral link, so the referral is attributed even if they sign up later - Referral data is used solely to determine waitlist queue priority and is not shared with third parties
Email Communications
- By joining the waitlist, you consent to receiving email updates about your waitlist status, launch announcements, and early access invitations
- You may unsubscribe at any time by clicking the unsubscribe link in any email or by contacting us at [email protected]
Data Retention
- Waitlist data is retained until you convert to a paying customer or request deletion
- If you do not convert within 12 months of our launch date, your waitlist data will be automatically deleted
11. Cookies
Attimo uses essential cookies required for authentication and session management, and a first-party analytics cookie set by PostHog to recognize a returning session for error diagnosis and product analytics. We do not use advertising cookies or cross-site tracking cookies.
The fp_ref cookie is used solely to attribute waitlist referrals. It expires after 30 days and contains only the referral code (no personal data).
12. Children's Privacy
Attimo is a business-to-business service and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. For material changes that significantly affect how we handle your data, we will notify you via email or through an in-product notification.
14. Contact
For any questions or requests regarding this Privacy Policy or your personal data, contact us at:
EU residents may contact their relevant national supervisory authority.