Privacy Policy
Effective Date: March 28, 2026 | Last Updated: March 28, 2026
Atrium ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our multi-tenant SaaS platform (the "App" or "Atrium").
To provide our services, we use Google OAuth for authentication. This policy specifically addresses our handle of data accessed through Google API Services.
1. Google User Data: Access and Collection
When you sign in to Atrium using your Google Account, we request access to the following information via Google API Services:
- Google ID: A unique identifier to link your Google account with your Atrium profile.
- Email Address: To verify your identity, send service notifications, and provide support.
- Profile Information: Your name and profile picture to personalize your "Digital Building" and identify you to other users (service providers or clients) within the platform.
We only request the minimum "openid", "profile", and "email" scopes required for basic authentication and identity.
2. Use of Google User Data
We use the information accessed from Google solely for the following purposes:
- Authentication: To allow you to securely log in to the App without creating a separate password.
- Identity Management: To establish your identity within the Atrium ecosystem, which is essential for the "Two-Way Handshake" scheduling process between providers and clients.
- Personalization: To display your name and picture in your profile and during interactions within the App.
- Communication: To send essential transactional emails related to your services and appointments.
We do not use Google user data for profiling, advertising, or any purpose other than providing the core functionality of the Atrium platform.
3. Data Sharing and Disclosure
We do not share your Google user data with third parties, except in the following limited circumstances:
- Service Providers: We may share data with essential infrastructure providers (e.g., Google Firebase for hosting and database) as necessary to run the App. These providers are bound by strict confidentiality agreements.
- Legal Requirements: If required by law, we may disclose information to comply with legal processes or government requests.
We strictly prohibit the sale of your Google user data to any third-party marketers or data brokers.
4. Data Storage and Protection
Your data is stored securely using industry-standard practices:
- Encryption: Data is encrypted both in transit (using SSL/TLS) and at rest (using Firebase/Firestore encryption).
- Access Control: Only authorized personnel have access to the administrative backend, and access is strictly audited.
- Infrastructure: We rely on Google Cloud Platform's world-class security infrastructure in our Frankfurt (EU) cluster to protect your information.
5. Data Retention and Deletion
We retain your Google user data for as long as your Atrium account is active.
Requesting Deletion: You can request the deletion of your account and all associated Google user data at any time:
- In-App: Navigate to Settings > Account > Delete Account.
- Via Email: Send a deletion request to [email protected] or [email protected].
Upon request, we will delete your personal data from our active databases within 30 days, subject to any legal obligations to retain certain records.
6. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at:
- General Support: [email protected]
- Legal & Privacy: [email protected]
- Website: https://atrium42.com