Privacy Policy

Effective date: 2026-09-01

Attia AS ("Attia", "we", "us", or "our") provides a business-to-business software service for applicant tracking, recruiting workflows, and related business operations (the "Services").

This Privacy Policy explains how Attia processes personal data when we provide the Services, operate our websites, communicate with customers and users, and support our product. It is written for business customers and their authorized users, but it may also apply to candidates, applicants, referrals, employees, leads, or other people whose personal data is submitted to the Services by or on behalf of a customer.

Controller: Attia AS, Solheimgata 1a, 0267 Oslo, Norway.

Contact: hello@attia.app
Data protection contact: Njål Wiik

1. Scope and Roles

Attia is established in Norway and provides B2B Services to customers worldwide, including customers and users in the EU/EEA, the United Kingdom, Switzerland, the United States, and other countries.

Attia acts as a controller when we decide why and how personal data is processed for our own business purposes. This includes account administration, customer relationship management, billing administration, product security, service analytics, support, marketing communications, legal compliance, and vendor management.

Attia acts as a processor when we process personal data contained in customer content or customer-controlled workflows on behalf of a business customer. This may include candidate data, recruiting records, workspace content, files, prompts, messages, notes, evaluations, job postings, workflow state, and other information submitted to the Services by or for the customer.

When Attia acts as a processor, the customer is usually the controller of that data. Requests from candidates, employees, applicants, or other customer-controlled data subjects should normally be directed to the relevant customer first. Attia will support customers with data subject requests as required by law and contract.

Attia maintains a separate Data Processing Agreement ("DPA") for customer-controlled personal data at attia.app/dpa. It covers subprocessors, international transfers, security measures, deletion and return, audit rights, and assistance with data subject requests.

2. What Personal Data We Process

The categories below describe the personal data Attia may process. The exact data depends on how the Services are configured and used.

CategoryExamplesSourceRole
Account and user dataName, business email, user ID, role, workspace membership, admin status, invitation statusCustomer, user, identity providerController for account administration; processor where customer controls workspace users
Authentication and access dataLogin events, session identifiers, authentication provider metadata, access tokens where applicableUser, identity provider, service logsController and processor depending on context
Customer company dataCompany name, workspace name, business contact details, plan, procurement detailsCustomer, customer adminController
Billing and payment dataBilling contact, invoice details, payment status, tax details, limited payment metadataCustomer, payment providerController
Customer content and workspace dataJob postings, recruiting records, candidate profiles, resumes, applications, notes, communications, attachments, workflow state, comments, files, user-generated textCustomer, users, integrations, candidates where customer enables candidate-facing workflowsProcessor
Support and communicationsSupport emails, messages, feedback, troubleshooting details, attachments voluntarily sent to usCustomer, userController, or processor if support content includes customer-controlled data
Product usage and diagnosticsFeature usage, events, performance data, settings, error reports, operational metadataServices, device, browserController for service improvement and security; processor where tied to customer content
Logs and security dataIP address, request metadata, browser/device information, timestamps, request IDs, security events, audit recordsServices, hosting provider, browser/deviceController and processor depending on context
AI inputs and outputsPrompts, selected text, editor content, document context, title, summary, description, model metadata, generated outputs, and agent session records (the steps, tool calls, and content of a multi-step agent task)Customer or user using AI featuresUsually processor for customer-controlled content; controller for security and operational logs
Integrations dataData exchanged with third-party services enabled by the customer, such as job boards, email, calendar, HRIS, identity, assessment, background-check, or AI toolsCustomer, user, integration providerUsually processor
Marketing dataBusiness contact details, preferences, campaign engagement, unsubscribe recordsUser, customer, public business sources, marketing toolsController

We do not intentionally require users to submit special-category personal data to use the Services. However, because the Services may allow customers and users to upload, generate, or process free-form content and files, the Services can technically process sensitive or regulated information if a customer submits it.

3. Sensitive and Regulated Data

Customers and users are responsible for ensuring they have the necessary rights, notices, consents, and lawful bases for the data they submit to the Services.

Unless expressly agreed in writing, the Services are not intended for processing special-category personal data under GDPR Article 9 or equivalent sensitive data, including health data, biometric data, children's data, precise location data, government ID data, background-check data, immigration data, criminal-offense data, or other regulated information.

Recruiting workflows may involve employment-related information, resumes, interview notes, application materials, compensation expectations, eligibility information, and other candidate data. Customers are responsible for their recruiting and hiring practices, including notices, retention periods, anti-discrimination compliance, accommodations, human review, and responses to candidate requests.

If a customer needs to process sensitive or regulated data through the Services, the customer should confirm with Attia in writing that the Services, DPA, subprocessors, security measures, and AI configuration are appropriate for that data before submitting it.

We process personal data only where we have a lawful basis.

PurposeExamplesLegal basisRole
Provide and administer the ServicesCreate accounts, manage workspaces, authenticate users, process customer content, provide product featuresContract necessity for customer/user account data; customer instructions where Attia is processorController and processor
Support and communicateRespond to support requests, send service messages, provide onboarding, handle product feedbackContract necessity; legitimate interests; legal obligation where applicableController
Secure and protect the ServicesPrevent abuse, investigate incidents, maintain logs, enforce access controls, detect errorsLegitimate interests; legal obligation; customer instructionsController and processor
Billing and commercial administrationInvoicing, payment status, tax records, procurement, renewalsContract necessity; legal obligation; legitimate interestsController
Improve and develop the ServicesDebugging, analytics, usage measurement, product research, quality improvementsLegitimate interests where permitted; consent where required for non-essential trackingController
MarketingSend product updates, events, newsletters, and similar business communicationsConsent where required; legitimate interests for B2B marketing where permittedController
AI functionalityGenerate, summarize, edit, classify, or assist with content when a person uses an AI feature or a customer-configured automation starts itCustomer instructions where Attia is processor; contract necessity or legitimate interests for operational metadataUsually processor
Legal complianceRespond to lawful requests, maintain required records, enforce agreements, handle disputesLegal obligation; legitimate interestsController

Where we rely on legitimate interests, we balance those interests against the rights and freedoms of the affected individuals. Where we rely on consent, consent can be withdrawn at any time without affecting processing that occurred before withdrawal.

5. AI Features

AI features may be available by default and may send content to third-party AI providers, such as OpenAI, Google, or Anthropic, when used. Making an AI feature visible or available does not by itself call a model or send customer content to an AI provider. Processing begins only when a person invokes an AI feature or a customer-configured schedule, record trigger, or delegation starts it. The workspace verifies an Editor AI integration using Vercel AI Gateway and Vercel AI SDK route handlers. The default model configured in the code is an OpenAI model, while model IDs can be configured server-side. The user-provided known facts also state that OpenAI, Google, and Anthropic may be used for AI features.

The data sent depends on the invoked feature or configured automation and may include prompts, selected text, workspace content, editor content, document context, titles, summaries, descriptions, instructions, model metadata, and AI-generated outputs. If files or file references are included in the workspace content or prompt context, those may also be sent. AI features operate within the current user's or configured automation's permissions; they do not gain access merely because Agent is available.

Attia uses AI providers to provide the requested AI functionality and configures them according to our agreements and available privacy controls.

Every AI request Attia sends is configured for zero data retention, which also disallows the use of that content to train models. This includes documentation search, where the text a user types is processed to find relevant help articles. Requests are routed only to providers that offer zero data retention for the model in question; if none is available, the request fails rather than proceeding without that protection. Attia does not verify EU-only processing for AI providers, and AI processing may take place outside the EU/EEA.

AI features candidates can use directly

One AI feature is offered to candidates rather than to customers: autofill from resume on a public application form. A candidate may choose to upload a resume so that contact fields and draft answers are filled in for them.

This runs only when the candidate asks for it. It is a separate, optional step with its own button, labelled and explained before it is used, and it is not the same as attaching a resume to an application — a resume attached to an application is not sent to an AI provider by this feature. A candidate who does not use autofill has no resume processed by AI.

When it is used, the resume file and the job's question labels are sent to an AI provider, with zero data retention enforced as described above. The extracted values are returned to the candidate's own form for them to review and edit.

Attia's servers do not keep the uploaded resume or the values extracted from it: they are held only for the duration of the request. The extracted values are placed into the candidate's own form in their browser, where they remain — as any typed answer would — until the candidate submits or leaves the page. Only what the candidate then chooses to submit is saved and handled as part of their application. As with any request to the Services, abuse-prevention and error-monitoring records described in sections 2 and 4 — such as rate-limiting counters and error reports — may still be created. The candidate is the person requesting this processing, and Attia acts on that request.

Customers should not submit sensitive, special-category, children's, health, biometric, government ID, background-check, immigration, or other regulated data to AI features unless they have confirmed that the feature, provider configuration, DPA, and their own lawful basis are appropriate for that data.

Some AI features are agents. Agent features are not enabled for any workspace at the time of writing. When launched, Agent will be available by default and a workspace admin or owner will be able to disable it workspace-wide. On a customer's instruction, and when started by a person, schedule, record trigger, or delegation, an agent can run a multi-step task and take actions inside that customer's workspace, such as reading an application, drafting a summary, updating a record, or assigning work to a member. Routine actions may run automatically within the live permissions and scope configured by the customer. The customer may require additional approvals. A qualified human must review and approve AI output before a hiring or employability decision, advice, recommendation, or similar high-risk output is acted on. This includes screening, ranking or scoring recommendations; advancing, holding, rejecting or disqualifying an application; interview or assessment selection; offers, compensation or eligibility; and AI-generated candidate-facing communications. Administrative reminders, internal task assignment, record formatting and logistics already decided by a human may run automatically when they do not evaluate or determine candidacy. Drafts and summaries require review before a high-risk decision relies on them; ambiguous actions require review.

To run a multi-step task reliably, an agent session is stored while it runs and for a period afterwards, so that it can resume after an interruption and so that the customer can see what the agent did. That stored record can include the workspace content the agent read and produced, which may include candidate data. When you use Attia's AI agent, the messages you send it and the replies it gives you are also shown as text in the hosting provider's agent observability tools, where Attia's team reads them to run and support the service. That is a view of the same stored session record rather than a separate provider. Retention is described in section 9, and the provider that stores it is listed in section 7.

AI-generated outputs may be inaccurate, incomplete, biased, or unsuitable for the customer's intended use. Customers and users should review AI outputs before relying on them. For recruiting, hiring and employability decisions, qualified-human review is required before AI output is acted on. If high-risk AI output is presented to or relied on by a candidate or other affected person, the customer must clearly disclose that AI was used.

The disable control Attia offers today is workspace-wide. A workspace admin or owner can turn Agent off for the entire workspace. There is no per-feature, per-role, or per-user switch.

6. Cookies, Local Storage, Analytics, and Tracking

The current workspace uses essential and functional browser storage for the Exponential UI registry/docs site, including theme preferences, sidebar state, docs sidebar preferences, and preview background settings. These are used to remember interface preferences and are not advertising identifiers.

The workspace also uses Vercel Speed Insights to understand page performance. Vercel's documentation describes Speed Insights as designed to provide performance information without tying it to an individual visitor or IP address.

The workspace does not show Google Analytics, Meta Pixel, TikTok Pixel, Hotjar, PostHog, Segment, Customer.io, advertising cookies, heatmaps, or session replay.

Attia expects to add analytics or tracking later. If Attia adds non-essential analytics, advertising, session replay, or similar tracking, Attia will update this policy and, where required in the EU/EEA, Norway, the UK, Switzerland, or other jurisdictions, provide a consent banner or preference tool before setting non-essential cookies or similar technologies.

You can also control cookies through your browser settings. Browser settings may not replace a legally required consent or preference tool for non-essential tracking.

7. Sharing and Subprocessors

We share personal data only as needed to provide, secure, support, and improve the Services; comply with law; complete business transactions; or follow customer instructions.

We may share personal data with:

  • hosting, infrastructure, CDN, logging, security, and monitoring providers;
  • AI providers and AI gateway providers when AI features are used;
  • authentication, email, support, billing, payment, analytics, and communication providers where configured;
  • customer-enabled integrations and third-party services;
  • professional advisers, auditors, insurers, and legal authorities where necessary;
  • another organization in connection with a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate safeguards.

Public-facing subprocessor list based on this workspace:

VendorServicePersonal dataStatus
VercelHosting and deployment, AI Gateway when used, and durable agent session state and its observability view when Agent or Loops runRequest metadata, performance data, logs, AI metadata and AI request routing data, and — for agent features — the stored agent session record, which can include the workspace and candidate content an agent read or produced. Session content, including the message that starts a session and the agent's replies, is readable as text in Vercel's agent observability dashboard by the Attia team members with access to that projectVerified in workspace. Agent session state is retained for a bounded period after a run completes and is then deleted automatically by the platform; Attia does not retain a separate copy of the execution trace. EU region pinning and customer subprocessor notice are still to be completed before Agent is available by default
Trigger.devScheduled background jobs and maintenance sweepsJob identifiers and operational metadata. Attia's engineering rules prohibit candidate content in job payloads, logs, tags, outputs and errorsVerified in workspace. Data is stored in a multi-tenant AWS environment in the United States; a data processing agreement has not been executed
OpenAIOptional AI model provider, reached through the Vercel AI Gateway. Also provides the embeddings behind documentation searchPrompts, context, inputs, outputs, metadata depending on feature; and, for documentation search, the text a user types plus Attia's own published help articlesModel requests are sent with zero data retention enforced, which also disallows use of the content for model training. Requests are only routed to providers offering zero data retention; where none is available for a model, the request fails rather than proceeding
GoogleOptional AI model provider, reached through the Vercel AI GatewayPrompts, context, inputs, outputs, metadata depending on featureSame zero-data-retention and no-training enforcement as above
AnthropicOptional AI model provider, reached through the Vercel AI GatewayPrompts, context, inputs, outputs, metadata depending on featureSame zero-data-retention and no-training enforcement as above
GitHubSource control and CI for this repositoryContributor and account metadata and build logsVerified for repository operations. Production customer data lives in Supabase, not in the repository
Untitled UIPrivate icon package registryDeveloper package-install metadata, not production customer contentVerified for development dependency
SupabasePrimary database, file storage and candidate authenticationAll workspace and candidate data, including names, contact details, CV files and application contentVerified in workspace. Your data is stored in the European Union (AWS eu-west-1, Ireland). More regions later
ClerkAuthentication and organisation identity for workspace membersWorkspace member identity, email and organisation membershipVerified in workspace. Candidates do not authenticate with Clerk; they sign in through Supabase
StripeSubscription billing and paymentsThe workspace administrator's email address, a workspace identifier and a seat count, plus whatever the payer enters at checkoutVerified in workspace. No candidate data is sent
SentryError monitoringError reports and request metadata, which include page paths carrying workspace and record identifiersVerified in workspace. Configured without default personal data, without session replay and without user identification. Invitation tokens, credentials, authorization headers and cookies are removed before sending
ResendTransactional email delivery, reached as the authentication mail relayCandidate email addresses and sign-in codesVerified in workspace

Attia should keep a current public subprocessor list and provide customers with notice of new subprocessors as required by the DPA.

8. International Transfers

Attia is established in Norway. Your data is stored in the European Union (AWS eu-west-1, Ireland). More regions later. Attia does not verify support access locations or all AI-provider processing locations.

Some vendors, support personnel, optional integrations, AI providers, payment providers, email providers, or analytics providers may process or access limited personal data from outside the EU/EEA. Where this happens, Attia uses appropriate safeguards required by applicable law, such as adequacy decisions, standard contractual clauses, data processing agreements, and technical and organizational measures.

We do not state that all personal data stays in the EU/EEA, because support, logging, AI and background-job paths are not all EU-resident.

9. Retention

We retain personal data only for as long as needed for the purposes described in this policy, to provide the Services, follow customer instructions, comply with law, resolve disputes, enforce agreements, and maintain security.

DataRetention or deletion trigger
Active account and workspace administration dataFor the life of the account or customer relationship
Deleted user account dataWorkspace membership and profile records are removed with the workspace they belong to, on the 30-day cycle in the row below. Deleting a personal account outright is not yet offered as a self-serve action; write to us and we will handle it
Customer content and workspace dataRetained during the subscription. After termination or workspace deletion, the workspace stays available for export for 30 days, and is then permanently deleted, except for backups and legal holds
Candidate and recruiting dataControlled by the customer; Attia processes according to customer instructions and the DPA
AI prompts and outputsRetain as part of workspace content if saved by the user or customer. Transient AI request data is not retained: every request is sent with zero data retention enforced, and the AI gateway deletes prompts and responses once the request completes (see section 5). Agent execution records are a separate case and follow the row below
Agent session stateApplies when a person or configured automation runs Agent. Anything the agent was meant to keep is written to workspace content, which follows the customer content row above. The stored execution record is kept by our hosting provider for a limited period measured from when the task ends — so that an interrupted task can resume, and so a customer can see what the agent did — and is then deleted automatically. Individual records cannot be deleted on request. Where a deletion request covers agent activity, Attia deletes its own records and, for any task still running or waiting, ends that task so the provider-side record begins expiring. Attia also intends to end automatically any agent task waiting on a person for more than 7 days; that control is not yet implemented, so until it ships, ending an in-progress task in response to such a request is a manual step. Credit- or limit-blocked work does not wait or resume automatically.
Support messagesRetain while needed for support, customer relationship, quality, and legal purposes, typically 2 to 5 years depending on content and obligations
Billing, invoice, tax, and accounting recordsRetained as Norwegian accounting law requires: five years after the end of the accounting year for primary documentation, and three years and six months for secondary documentation (bokføringsloven section 13). This obligation overrides a deletion request for the records it covers
Product usage and analytics dataRetained for the shortest period needed for product improvement and reporting
Application, request, and error logsTypically 30 to 180 days unless needed for security, debugging, or legal reasons
Security and audit logs2 years from the date of the event, then deleted automatically. The client IP address recorded when an access attempt is denied is removed after 90 days, ahead of the rest of that entry. Deleting a workspace removes its audit log sooner, as part of that deletion
BackupsEncrypted backups are taken daily and retained on a rolling 7-day cycle; data deleted from the live database ages out of the last backup within 7 days
Marketing preferences and unsubscribe recordsUntil the person opts out, plus as long as needed to honor the opt-out
Trial or inactive workspacesRetained until the customer deletes the workspace. Attia does not delete or de-identify a workspace for inactivity alone

Uploaded files are queued for removal when a workspace is purged and are cleared by a sweep that runs daily, so file deletion completes within a day of the purge rather than instantly. Deletion from backups takes longer than deletion from active systems. Backups are isolated from ordinary processing and age out on the 7-day cycle above.

10. Security

We use appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. Data is encrypted in transit and at rest. Our other measures include access controls, least-privilege permissions, secure configuration, logging, monitoring, backups, vendor review, and secrets management.

The workspace verifies production safeguards for optional AI routes that fail closed unless credentials and production authorization controls are configured, including app-owned authorization and rate limiting requirements. The workspace does not verify all operational security measures, such as MFA enforcement, vulnerability management cadence, incident response procedures, admin access locations, or formal vendor review records.

No method of transmission or storage is completely secure. If we become aware of a security incident affecting personal data, we will take appropriate steps and notify affected customers, individuals, and authorities where required by law or contract.

11. Your Rights

Depending on where you live and how your personal data is processed, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about how your personal data is processed.

If Attia processes your personal data as a controller, you can contact us at hello@attia.app. We may need to verify your identity before responding.

If your request concerns customer-controlled data, such as candidate data, recruiting records, workspace content, or information submitted by an Attia customer, please contact the relevant customer first. Attia will support the customer as required by law and contract.

If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority. In Norway, the supervisory authority is Datatilsynet. UK and Swiss residents may have similar rights under the UK GDPR and Swiss FADP.

For US residents, Attia does not currently verify that it meets the thresholds for California or other US state comprehensive privacy laws. We do not sell personal data or share it for cross-context behavioral advertising based on the current workspace facts. If this changes or if Attia becomes subject to additional state privacy laws, we will update this policy.

12. Marketing Communications

We may send business communications about Attia, product updates, events, or similar topics where permitted by law. You can opt out of marketing emails by using the unsubscribe link in the email or by contacting hello@attia.app.

We may still send service, security, billing, legal, or administrative messages that are necessary for the Services or our relationship with a customer.

13. Children

The Services are intended for business use and are not directed to children. Users must be legally able to use business services and must use the Services only as authorized by their organization.

Attia does not knowingly collect personal data directly from children. If we learn that child data was provided without proper authorization, we will take appropriate steps to delete or restrict the data, unless we are required or permitted to retain it by law or customer instructions.

14. Automated Decision-Making

Attia does not itself make decisions about individuals. Where the Services act automatically, they act on the configured instruction of the customer, who is the controller of that data.

The Services include automated and AI-assisted features that help customers draft, summarize, classify, parse, review, and act on content, including agents that can run multi-step tasks and take configured actions inside a workspace. Routine actions may run automatically within live permissions and customer-configured scope, and customers may require additional approvals.

Customers are responsible for deciding whether and how to use these features in recruiting or employment workflows, including notices, bias assessments, impact assessments, appeal rights, accessibility measures, and recordkeeping. A qualified human must review and approve AI output before a hiring or employability decision, advice, recommendation, or similar high-risk output is acted on. If high-risk AI output is presented to or relied on by a candidate or other affected person, the customer must clearly disclose that AI was used. Article 22 of the GDPR and comparable laws may impose additional restrictions, and configuring the Services and workflow to meet applicable requirements remains the customer's responsibility.

15. Changes

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice in a reasonable way, such as by posting the updated policy on our website, notifying customer admins, or sending an email where appropriate.

The updated policy will apply from the effective date stated at the top of the policy.

16. Contact

Questions about this Privacy Policy or Attia's privacy practices can be sent to:

Attia AS
Solheimgata 1a
0267 Oslo
Norway

Email: hello@attia.app
Data protection contact: Njål Wiik