Skip to content

Home / Legal / Privacy Policy

Legal

Privacy Policy

What ATNOS collects, why, who it is shared with, how long it is kept, and the rights you hold over it.

Sections

  1. Who we are

    ATNOS Technologies Inc., 1 Market Street, Suite 3600, San Francisco, CA 94105. Data questions go to privacy@atnos.ai.

  2. Account information

    What you give us to create and run a workspace.

  3. Usage data

    How the workspace itself is used, and what we keep from that.

  4. OAuth permissions and connected credentials

    The section specific to a platform that acts inside your own accounts.

  5. Third-party integrations

    Google, Meta, commerce and CRM, AI model providers.

  6. Cookies and analytics

    Covered in full by the Cookie Policy.

  7. Lawful basis

    Why each category of processing is permitted.

  8. Data retention

    Full schedule below.

  9. Your rights

    Access, rectification, erasure, restriction, portability, withdraw consent, complaint.

  10. International transfers

    Standard Contractual Clauses and the UK Addendum.

  11. Security

    Summarised here, detailed on the security page.

  12. Children

    The service is not directed to children.

  13. Changes and contact

    How we notify you of material changes.

Google user data and Limited Use

ATNOS's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What we access. Only the scopes required by the features you enable: advertising data from Google Ads, traffic and conversion data from Google Analytics, search performance from Search Console, and listing data from Business Profile. The full per-service breakdown, including what is read and what is written back, is on Connected access.

Why we access it. To plan, prepare and report on the marketing work inside your own accounts. Nothing that changes publicly visible material is executed without your approval.

What we never do with it. We do not transfer it to third parties except as needed to provide the features you enabled, to comply with applicable law, or as part of a merger or acquisition. We do not use it for advertising. We do not use it to train generalised models. No human reads it except with your explicit permission, for security purposes, or where the law requires it.

How long we keep it. Access and refresh tokens are destroyed immediately on disconnection or deletion. Everything else follows the retention schedule below.

Retention schedule

CategoryPeriod
OAuth access and refresh tokensDestroyed immediately on disconnection or deletion
Account and workspace recordsLife of the account plus 30 days
Campaign, analytics and CRM data25 months, then aggregated irreversibly
Application and security logs12 months
Audit logs12 months (longer under an enterprise agreement)
Consent records24 months from the consent event
Invoices and financial records7 years, as required by tax law
Encrypted backups35-day rolling window