Privacy Policy

Last updated: January 25, 2026

1. Introduction

At Attensus (“we,” “our,” or “us”), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

Account Information

When you create an account, we collect information such as your name, email address, company name, and password. This information is necessary to provide you with access to the Service.

Usage Data

We automatically collect information about how you interact with the Service, including:

  • Pages viewed and features used
  • Time spent on the Service
  • Browser type and version
  • IP address and device information
  • Operating system
  • Referring URLs

Customer Data

You provide information about your supply chain through the Service, including:

  • Node information (locations, facilities, production capabilities)
  • Supplier information (names, contacts, capabilities)
  • Coverage relationships and dependencies
  • Risk assessments and analysis results

This data belongs to you, and we process it only to provide the Service as described in our Terms of Service.

Payment Information

Payment information is processed by our third-party payment processor, Stripe. We do not store your complete credit card numbers on our servers. We receive limited information from Stripe, such as the last four digits of your card and expiration date, for account management purposes.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your transactions and manage your subscription
  • Send you technical notices, updates, and support messages
  • Respond to your comments, questions, and customer service requests
  • Monitor and analyze usage patterns and trends to improve user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our Terms of Service
  • Send you marketing communications (with your consent where required)

4. Data Storage and Security

Where We Store Your Data

Your data is stored in secure databases provided by Supabase, a trusted cloud infrastructure provider. Our servers are located in data centers with industry-standard physical and network security measures.

How We Protect Your Data

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption of data in transit using SSL/TLS
  • Encryption of sensitive data at rest
  • Regular security assessments and updates
  • Access controls and authentication mechanisms
  • Employee training on data protection practices

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

5. Third-Party Services

We use the following third-party services to provide and improve our Service:

Stripe (Payment Processing)

We use Stripe to process payments. Stripe's privacy policy is available at stripe.com/privacy.

Supabase (Infrastructure)

We use Supabase for database and backend infrastructure. Supabase's privacy policy is available at supabase.com/privacy.

These third parties have access to your information only to perform specific tasks on our behalf and are obligated not to disclose or use it for any other purpose.

6. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

Access and Portability

You have the right to access your personal information and receive a copy of your data in a structured, commonly used format. You can export your data at any time through the Service interface.

Correction

You have the right to correct inaccurate or incomplete personal information. You can update most of your information directly through your account settings.

Deletion

You have the right to request deletion of your personal information. You can delete your account at any time through your account settings, which will initiate the deletion of your data as described in our Terms of Service.

Objection and Restriction

You have the right to object to or restrict certain processing of your personal information, such as for marketing purposes.

Withdrawal of Consent

Where we process your data based on your consent, you have the right to withdraw that consent at any time.

To exercise these rights, please contact us at privacy@attensus.com. We will respond to your request within 30 days.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on the Service. Cookies are small data files stored on your device that help us remember your preferences and understand how you use the Service.

Types of Cookies We Use:

  • Essential Cookies: Required for the Service to function properly, such as authentication cookies
  • Analytics Cookies: Help us understand how users interact with the Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. However, disabling certain cookies may limit your ability to use some features of the Service.

8. Data Retention

We retain your information for as long as your account is active or as needed to provide you with the Service. When you delete your account, we will delete your personal information and Customer Data within 30 days, except where we are required to retain it by law or for legitimate business purposes such as:

  • Resolving disputes
  • Enforcing our agreements
  • Complying with legal obligations
  • Preventing fraud and abuse

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. These countries may have data protection laws that are different from the laws of your country.

When we transfer your data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by regulatory authorities.

10. Children's Privacy

The Service is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information, please contact us, and we will take steps to delete such information.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

privacy@attensus.com

For data protection inquiries specific to GDPR, you may also contact our Data Protection Officer at the same email address.