Privacy Policy
Effective date: 2026-09-01
Attia AS ("Attia", "we", "us", or "our") provides a business-to-business software service for applicant tracking, recruiting workflows, and related business operations (the "Services").
This Privacy Policy explains how Attia processes personal data when we provide the Services, operate our websites, communicate with customers and users, and support our product. It is written for business customers and their authorized users, but it may also apply to candidates, applicants, referrals, employees, leads, or other people whose personal data is submitted to the Services by or on behalf of a customer.
Controller: Attia AS, Solheimgata 1a, 0267 Oslo, Norway.
Contact: hello@attia.app
Data protection contact: Njål Wiik
1. Scope and Roles
Attia is established in Norway and provides B2B Services to customers worldwide, including customers and users in the EU/EEA, the United Kingdom, Switzerland, the United States, and other countries.
Attia acts as a controller when we decide why and how personal data is processed for our own business purposes. This includes account administration, customer relationship management, billing administration, product security, service analytics, support, marketing communications, legal compliance, and vendor management.
Attia acts as a processor when we process personal data contained in customer content or customer-controlled workflows on behalf of a business customer. This may include candidate data, recruiting records, workspace content, files, prompts, messages, notes, evaluations, job postings, workflow state, and other information submitted to the Services by or for the customer.
When Attia acts as a processor, the customer is usually the controller of that data. Requests from candidates, employees, applicants, or other customer-controlled data subjects should normally be directed to the relevant customer first. Attia will support customers with data subject requests as required by law and contract.
Attia maintains a separate Data Processing Agreement ("DPA") for customer-controlled personal data at attia.app/dpa. It covers subprocessors, international transfers, security measures, deletion and return, audit rights, and assistance with data subject requests.
2. What Personal Data We Process
The categories below describe the personal data Attia may process. The exact data depends on how the Services are configured and used.
| Category | Examples | Source | Role |
|---|---|---|---|
| Account and user data | Name, business email, user ID, role, workspace membership, admin status, invitation status | Customer, user, identity provider | Controller for account administration; processor where customer controls workspace users |
| Authentication and access data | Login events, session identifiers, authentication provider metadata, access tokens where applicable | User, identity provider, service logs | Controller and processor depending on context |
| Customer company data | Company name, workspace name, business contact details, plan, procurement details | Customer, customer admin | Controller |
| Billing and payment data | Billing contact, invoice details, payment status, tax details, limited payment metadata | Customer, payment provider | Controller |
| Customer content and workspace data | Job postings, recruiting records, candidate profiles, resumes, applications, notes, communications, attachments, workflow state, comments, files, user-generated text | Customer, users, integrations, candidates where customer enables candidate-facing workflows | Processor |
| Support and communications | Support emails, messages, feedback, troubleshooting details, attachments voluntarily sent to us | Customer, user | Controller, or processor if support content includes customer-controlled data |
| Product usage and diagnostics | Feature usage, events, performance data, settings, error reports, operational metadata | Services, device, browser | Controller for service improvement and security; processor where tied to customer content |
| Logs and security data | IP address, request metadata, browser/device information, timestamps, request IDs, security events, audit records | Services, hosting provider, browser/device | Controller and processor depending on context |
| AI inputs and outputs | Prompts, selected text, editor content, document context, title, summary, description, model metadata, generated outputs, and agent session records (the steps, tool calls, and content of a multi-step agent task) | Customer or user using AI features | Usually processor for customer-controlled content; controller for security and operational logs |
| Integrations data | Data exchanged with third-party services enabled by the customer, such as job boards, email, calendar, HRIS, identity, assessment, background-check, or AI tools | Customer, user, integration provider | Usually processor |
| Marketing data | Business contact details, preferences, campaign engagement, unsubscribe records | User, customer, public business sources, marketing tools | Controller |
We do not intentionally require users to submit special-category personal data to use the Services. However, because the Services may allow customers and users to upload, generate, or process free-form content and files, the Services can technically process sensitive or regulated information if a customer submits it.
3. Sensitive and Regulated Data
Customers and users are responsible for ensuring they have the necessary rights, notices, consents, and lawful bases for the data they submit to the Services.
Unless expressly agreed in writing, the Services are not intended for processing special-category personal data under GDPR Article 9 or equivalent sensitive data, including health data, biometric data, children's data, precise location data, government ID data, background-check data, immigration data, criminal-offense data, or other regulated information.
Recruiting workflows may involve employment-related information, resumes, interview notes, application materials, compensation expectations, eligibility information, and other candidate data. Customers are responsible for their recruiting and hiring practices, including notices, retention periods, anti-discrimination compliance, accommodations, human review, and responses to candidate requests.
If a customer needs to process sensitive or regulated data through the Services, the customer should confirm with Attia in writing that the Services, DPA, subprocessors, security measures, and AI configuration are appropriate for that data before submitting it.
4. Purposes and Legal Bases
We process personal data only where we have a lawful basis.
| Purpose | Examples | Legal basis | Role |
|---|---|---|---|
| Provide and administer the Services | Create accounts, manage workspaces, authenticate users, process customer content, provide product features | Contract necessity for customer/user account data; customer instructions where Attia is processor | Controller and processor |
| Support and communicate | Respond to support requests, send service messages, provide onboarding, handle product feedback | Contract necessity; legitimate interests; legal obligation where applicable | Controller |
| Secure and protect the Services | Prevent abuse, investigate incidents, maintain logs, enforce access controls, detect errors | Legitimate interests; legal obligation; customer instructions | Controller and processor |
| Billing and commercial administration | Invoicing, payment status, tax records, procurement, renewals | Contract necessity; legal obligation; legitimate interests | Controller |
| Improve and develop the Services | Debugging, analytics, usage measurement, product research, quality improvements | Legitimate interests where permitted; consent where required for non-essential tracking | Controller |
| Marketing | Send product updates, events, newsletters, and similar business communications | Consent where required; legitimate interests for B2B marketing where permitted | Controller |
| AI functionality | Generate, summarize, edit, classify, or assist with content when a person uses an AI feature or a customer-configured automation starts it | Customer instructions where Attia is processor; contract necessity or legitimate interests for operational metadata | Usually processor |
| Legal compliance | Respond to lawful requests, maintain required records, enforce agreements, handle disputes | Legal obligation; legitimate interests | Controller |
Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the affected individuals. Where we rely on consent, consent can be withdrawn at any time without affecting processing that occurred before withdrawal.
5. AI Features
AI features may be available by default and may send content to third-party AI providers, such as OpenAI, Google, or Anthropic, when used. Making an AI feature visible or available does not by itself call a model or send customer content to an AI provider. Processing begins only when a person invokes an AI feature or a customer-configured schedule, record trigger, or delegation starts it. The workspace verifies an Editor AI integration using Vercel AI Gateway and Vercel AI SDK route handlers. The default model configured in the code is an OpenAI model, while model IDs can be configured server-side. The user-provided known facts also state that OpenAI, Google, and Anthropic may be used for AI features.
The data sent depends on the invoked feature or configured automation and may include prompts, selected text, workspace content, editor content, document context, titles, summaries, descriptions, instructions, model metadata, and AI-generated outputs. If files or file references are included in the workspace content or prompt context, those may also be sent. AI features operate within the current user's or configured automation's permissions; they do not gain access merely because Agent is available.
Attia uses AI providers to provide the requested AI functionality and configures them according to our agreements and available privacy controls.
Every AI request Attia sends is configured for zero data retention, which also disallows the use of that content to train models. This includes documentation search, where the text a user types is processed to find relevant help articles. Requests are routed only to providers that offer zero data retention for the model in question; if none is available, the request fails rather than proceeding without that protection. Attia does not verify EU-only processing for AI providers, and AI processing may take place outside the EU/EEA.
AI features candidates can use directly
One AI feature is offered to candidates rather than to customers: autofill from resume on a public application form. A candidate may choose to upload a resume so that contact fields and draft answers are filled in for them.
This runs only when the candidate asks for it. It is a separate, optional step with its own button, labelled and explained before it is used, and it is not the same as attaching a resume to an application — a resume attached to an application is not sent to an AI provider by this feature. A candidate who does not use autofill has no resume processed by AI.
When it is used, the resume file and the job's question labels are sent to an AI provider, with zero data retention enforced as described above. The extracted values are returned to the candidate's own form for them to review and edit.
Attia's servers do not keep the uploaded resume or the values extracted from it: they are held only for the duration of the request. The extracted values are placed into the candidate's own form in their browser, where they remain — as any typed answer would — until the candidate submits or leaves the page. Only what the candidate then chooses to submit is saved and handled as part of their application. As with any request to the Services, abuse-prevention and error-monitoring records described in sections 2 and 4 — such as rate-limiting counters and error reports — may still be created. The candidate is the person requesting this processing, and Attia acts on that request.
Customers should not submit sensitive, special-category, children's, health, biometric, government ID, background-check, immigration, or other regulated data to AI features unless they have confirmed that the feature, provider configuration, DPA, and their own lawful basis are appropriate for that data.
Some AI features are agents. Agent features are not enabled for any workspace at the time of writing. When launched, Agent will be available by default and a workspace admin or owner will be able to disable it workspace-wide. On a customer's instruction, and when started by a person, schedule, record trigger, or delegation, an agent can run a multi-step task and take actions inside that customer's workspace, such as reading an application, drafting a summary, updating a record, or assigning work to a member. Routine actions may run automatically within the live permissions and scope configured by the customer. The customer may require additional approvals. A qualified human must review and approve AI output before a hiring or employability decision, advice, recommendation, or similar high-risk output is acted on. This includes screening, ranking or scoring recommendations; advancing, holding, rejecting or disqualifying an application; interview or assessment selection; offers, compensation or eligibility; and AI-generated candidate-facing communications. Administrative reminders, internal task assignment, record formatting and logistics already decided by a human may run automatically when they do not evaluate or determine candidacy. Drafts and summaries require review before a high-risk decision relies on them; ambiguous actions require review.
To run a multi-step task reliably, an agent session is stored while it runs and for a period afterwards, so that it can resume after an interruption and so that the customer can see what the agent did. That stored record can include the workspace content the agent read and produced, which may include candidate data. When you use Attia's AI agent, the messages you send it and the replies it gives you are also shown as text in the hosting provider's agent observability tools, where Attia's team reads them to run and support the service. That is a view of the same stored session record rather than a separate provider. Retention is described in section 9, and the provider that stores it is listed in section 7.
AI-generated outputs may be inaccurate, incomplete, biased, or unsuitable for the customer's intended use. Customers and users should review AI outputs before relying on them. For recruiting, hiring and employability decisions, qualified-human review is required before AI output is acted on. If high-risk AI output is presented to or relied on by a candidate or other affected person, the customer must clearly disclose that AI was used.
The disable control Attia offers today is workspace-wide. A workspace admin or owner can turn Agent off for the entire workspace. There is no per-feature, per-role, or per-user switch.
6. Cookies, Local Storage, Analytics, and Tracking
The current workspace uses essential and functional browser storage for the Exponential UI registry/docs site, including theme preferences, sidebar state, docs sidebar preferences, and preview background settings. These are used to remember interface preferences and are not advertising identifiers.
The workspace also uses Vercel Speed Insights to understand page performance. Vercel's documentation describes Speed Insights as designed to provide performance information without tying it to an individual visitor or IP address.
The workspace does not show Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, PostHog, Segment, Customer.io, advertising cookies, heatmaps, or session replay.
Attia expects to add analytics or tracking later. If Attia adds non-essential analytics, advertising, session replay, or similar tracking, Attia will update this policy and, where required in the EU/EEA, Norway, the UK, Switzerland, or other jurisdictions, provide a consent banner or preference tool before setting non-essential cookies or similar technologies.
You can also control cookies through your browser settings. Browser settings may not replace a legally required consent or preference tool for non-essential tracking.
7. Sharing and Subprocessors
We share personal data only as needed to provide, secure, support, and improve the Services; comply with law; complete business transactions; or follow customer instructions.
We may share personal data with:
- hosting, infrastructure, CDN, logging, security, and monitoring providers;
- AI providers and AI gateway providers when AI features are used;
- authentication, email, support, billing, payment, analytics, and communication providers where configured;
- customer-enabled integrations and third-party services;
- professional advisers, auditors, insurers, and legal authorities where necessary;
- another organization in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate safeguards.
Public-facing subprocessor list based on this workspace:
| Vendor | Service | Personal data | Status |
|---|---|---|---|
| Vercel | Hosting and deployment, AI Gateway when used, and durable agent session state and its observability view when Agent or Loops run | Request metadata, performance data, logs, AI metadata and AI request routing data, and — for agent features — the stored agent session record, which can include the workspace and candidate content an agent read or produced. Session content, including the message that starts a session and the agent's replies, is readable as text in Vercel's agent observability dashboard by the Attia team members with access to that project | Verified in workspace. Agent session state is retained for a bounded period after a run completes and is then deleted automatically by the platform; Attia does not retain a separate copy of the execution trace. EU region pinning and customer subprocessor notice are still to be completed before Agent is available by default |
| Trigger.dev | Scheduled background jobs and maintenance sweeps | Job identifiers and operational metadata. Attia's engineering rules prohibit candidate content in job payloads, logs, tags, outputs and errors | Verified in workspace. Data is stored in a multi-tenant AWS environment in the United States; a data processing agreement has not been executed |
| OpenAI | Optional AI model provider, reached through the Vercel AI Gateway. Also provides the embeddings behind documentation search | Prompts, context, inputs, outputs, metadata depending on feature; and, for documentation search, the text a user types plus Attia's own published help articles | Model requests are sent with zero data retention enforced, which also disallows use of the content for model training. Requests are only routed to providers offering zero data retention; where none is available for a model, the request fails rather than proceeding |
| Optional AI model provider, reached through the Vercel AI Gateway | Prompts, context, inputs, outputs, metadata depending on feature | Same zero-data-retention and no-training enforcement as above | |
| Anthropic | Optional AI model provider, reached through the Vercel AI Gateway | Prompts, context, inputs, outputs, metadata depending on feature | Same zero-data-retention and no-training enforcement as above |
| GitHub | Source control and CI for this repository | Contributor and account metadata and build logs | Verified for repository operations. Production customer data lives in Supabase, not in the repository |
| Untitled UI | Private icon package registry | Developer package-install metadata, not production customer content | Verified for development dependency |
| Supabase | Primary database, file storage and candidate authentication | All workspace and candidate data, including names, contact details, CV files and application content | Verified in workspace. Your data is stored in the European Union (AWS eu-west-1, Ireland). More regions later |
| Clerk | Authentication and organisation identity for workspace members | Workspace member identity, email and organisation membership | Verified in workspace. Candidates do not authenticate with Clerk; they sign in through Supabase |
| Stripe | Subscription billing and payments | The workspace administrator's email address, a workspace identifier and a seat count, plus whatever the payer enters at checkout | Verified in workspace. No candidate data is sent |
| Sentry | Error monitoring | Error reports and request metadata, which include page paths carrying workspace and record identifiers | Verified in workspace. Configured without default personal data, without session replay and without user identification. Invitation tokens, credentials, authorization headers and cookies are removed before sending |
| Resend | Transactional email delivery, reached as the authentication mail relay | Candidate email addresses and sign-in codes | Verified in workspace |
Attia should keep a current public subprocessor list and provide customers with notice of new subprocessors as required by the DPA.
8. International Transfers
Attia is established in Norway. Your data is stored in the European Union (AWS eu-west-1, Ireland). More regions later. Attia does not verify support access locations or all AI-provider processing locations.
Some vendors, support personnel, optional integrations, AI providers, payment providers, email providers, or analytics providers may process or access limited personal data from outside the EU/EEA. Where this happens, Attia uses appropriate safeguards required by applicable law, such as adequacy decisions, standard contractual clauses, data processing agreements, and technical and organizational measures.
We do not state that all personal data stays in the EU/EEA, because support, logging, AI and background-job paths are not all EU-resident.
9. Retention
We retain personal data only for as long as needed for the purposes described in this policy, to provide the Services, follow customer instructions, comply with law, resolve disputes, enforce agreements, and maintain security.
| Data | Retention or deletion trigger |
|---|---|
| Active account and workspace administration data | For the life of the account or customer relationship |
| Deleted user account data | Workspace membership and profile records are removed with the workspace they belong to, on the 30-day cycle in the row below. Deleting a personal account outright is not yet offered as a self-serve action; write to us and we will handle it |
| Customer content and workspace data | Retained during the subscription. After termination or workspace deletion, the workspace stays available for export for 30 days, and is then permanently deleted, except for backups and legal holds |
| Candidate and recruiting data | Controlled by the customer; Attia processes according to customer instructions and the DPA |
| AI prompts and outputs | Retain as part of workspace content if saved by the user or customer. Transient AI request data is not retained: every request is sent with zero data retention enforced, and the AI gateway deletes prompts and responses once the request completes (see section 5). Agent execution records are a separate case and follow the row below |
| Agent session state | Applies when a person or configured automation runs Agent. Anything the agent was meant to keep is written to workspace content, which follows the customer content row above. The stored execution record is kept by our hosting provider for a limited period measured from when the task ends — so that an interrupted task can resume, and so a customer can see what the agent did — and is then deleted automatically. Individual records cannot be deleted on request. Where a deletion request covers agent activity, Attia deletes its own records and, for any task still running or waiting, ends that task so the provider-side record begins expiring. Attia also intends to end automatically any agent task waiting on a person for more than 7 days; that control is not yet implemented, so until it ships, ending an in-progress task in response to such a request is a manual step. Credit- or limit-blocked work does not wait or resume automatically. |
| Support messages | Retain while needed for support, customer relationship, quality, and legal purposes, typically 2 to 5 years depending on content and obligations |
| Billing, invoice, tax, and accounting records | Retained as Norwegian accounting law requires: five years after the end of the accounting year for primary documentation, and three years and six months for secondary documentation (bokføringsloven section 13). This obligation overrides a deletion request for the records it covers |
| Product usage and analytics data | Retained for the shortest period needed for product improvement and reporting |
| Application, request, and error logs | Typically 30 to 180 days unless needed for security, debugging, or legal reasons |
| Security and audit logs | 2 years from the date of the event, then deleted automatically. The client IP address recorded when an access attempt is denied is removed after 90 days, ahead of the rest of that entry. Deleting a workspace removes its audit log sooner, as part of that deletion |
| Backups | Encrypted backups are taken daily and retained on a rolling 7-day cycle; data deleted from the live database ages out of the last backup within 7 days |
| Marketing preferences and unsubscribe records | Until the person opts out, plus as long as needed to honor the opt-out |
| Trial or inactive workspaces | Retained until the customer deletes the workspace. Attia does not delete or de-identify a workspace for inactivity alone |
Uploaded files are queued for removal when a workspace is purged and are cleared by a sweep that runs daily, so file deletion completes within a day of the purge rather than instantly. Deletion from backups takes longer than deletion from active systems. Backups are isolated from ordinary processing and age out on the 7-day cycle above.
10. Security
We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. Data is encrypted in transit and at rest. Our other measures include access controls, least-privilege permissions, secure configuration, logging, monitoring, backups, vendor review, and secrets management.
The workspace verifies production safeguards for optional AI routes that fail closed unless credentials and production authorization controls are configured, including app-owned authorization and rate limiting requirements. The workspace does not verify all operational security measures, such as MFA enforcement, vulnerability management cadence, incident response procedures, admin access locations, or formal vendor review records.
No method of transmission or storage is completely secure. If we become aware of a security incident affecting personal data, we will take appropriate steps and notify affected customers, individuals, and authorities where required by law or contract.
11. Your Rights
Depending on where you live and how your personal data is processed, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about how your personal data is processed.
If Attia processes your personal data as a controller, you can contact us at hello@attia.app. We may need to verify your identity before responding.
If your request concerns customer-controlled data, such as candidate data, recruiting records, workspace content, or information submitted by an Attia customer, please contact the relevant customer first. Attia will support the customer as required by law and contract.
If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority. In Norway, the supervisory authority is Datatilsynet. UK and Swiss residents may have similar rights under the UK GDPR and Swiss FADP.
For US residents, Attia does not currently verify that it meets the thresholds for California or other US state comprehensive privacy laws. We do not sell personal data or share it for cross-context behavioral advertising based on the current workspace facts. If this changes or if Attia becomes subject to additional state privacy laws, we will update this policy.
12. Marketing Communications
We may send business communications about Attia, product updates, events, or similar topics where permitted by law. You can opt out of marketing emails by using the unsubscribe link in the email or by contacting hello@attia.app.
We may still send service, security, billing, legal, or administrative messages that are necessary for the Services or our relationship with a customer.
13. Children
The Services are intended for business use and are not directed to children. Users must be legally able to use business services and must use the Services only as authorized by their organization.
Attia does not knowingly collect personal data directly from children. If we learn that child data was provided without proper authorization, we will take appropriate steps to delete or restrict the data, unless we are required or permitted to retain it by law or customer instructions.
14. Automated Decision-Making
Attia does not itself make decisions about individuals. Where the Services act automatically, they act on the configured instruction of the customer, who is the controller of that data.
The Services include automated and AI-assisted features that help customers draft, summarize, classify, parse, review, and act on content, including agents that can run multi-step tasks and take configured actions inside a workspace. Routine actions may run automatically within live permissions and customer-configured scope, and customers may require additional approvals.
Customers are responsible for deciding whether and how to use these features in recruiting or employment workflows, including notices, bias assessments, impact assessments, appeal rights, accessibility measures, and recordkeeping. A qualified human must review and approve AI output before a hiring or employability decision, advice, recommendation, or similar high-risk output is acted on. If high-risk AI output is presented to or relied on by a candidate or other affected person, the customer must clearly disclose that AI was used. Article 22 of the GDPR and comparable laws may impose additional restrictions, and configuring the Services and workflow to meet applicable requirements remains the customer's responsibility.
15. Changes
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice in a reasonable way, such as by posting the updated policy on our website, notifying customer admins, or sending an email where appropriate.
The updated policy will apply from the effective date stated at the top of the policy.
16. Contact
Questions about this Privacy Policy or Attia's privacy practices can be sent to:
Attia AS
Solheimgata 1a
0267 Oslo
Norway
Email: hello@attia.app
Data protection contact: Njål Wiik