Privacy notice / legal draft 0.4

Your business context stays yours.

This notice explains information handled through the public website, customer account and role request. Production Customer Personal Data handling is not open and requires an approved contract and deployment boundary.

1. Information we handle

  • Contact details and company information submitted when you create an account, request follow-up or otherwise contact ATACSYS.
  • Account and security data: account identifier, password hash and salt, session-token hash, sign-in method, terms acceptance and separate optional marketing preference.
  • If you choose Google or Facebook sign-in, the provider account identifier needed to maintain that sign-in method. A verified Google email may be saved as an account contact; Facebook sign-in requests only the basic profile, and you can add a contact method in your cabinet.
  • The role, desired outcome, systems and approval boundaries you describe. The account-gated role matcher does not need your name, email or company name.
  • If you opt in to anonymous site analytics, a random browser visit identifier (stored only as a server-side hash), page path, fixed interaction label, section label and a coarse time-on-page bucket. Analytics does not intentionally store IP address, query string, fragment, form value, chat content, screen fingerprint or session recording.
  • If you choose the separate browser-only human-message feature, the message you write, the human reply, timestamps, thread status and an opaque thread-token hash. It does not ask for contact details and does not deliver email, SMS or push notifications.
  • Technical security information such as IP address for rate limiting, timestamps, request identifiers, basic logs and errors.
Do not submit secretsDo not place passwords, API keys, payment details, sensitive personal information, production customer records or confidential documents into the public request form or browser-only human-message feature.

2. Why we use it

We use information to provide account access, protect role search from abuse, review and answer requests, scope a safe role, operate approved features, enforce permissions, investigate abuse, improve reliability and meet legal obligations. Opt-in anonymous analytics is used only to understand aggregate page visits, fixed control clicks and coarse exit points so we can improve the site. A browser-only human message is used only so a person can reply in that same browser thread. We do not sell role-review content or use it for advertising. Marketing updates are sent only when you separately opt in.

3. Service providers and transfers

The public website and API currently rely on hosting and infrastructure providers. A model provider is contacted only when an approved feature requires it. Before production Customer Personal Data use, ATACSYS will document the selected provider, region, retention setting, transfer basis and subprocessors in the applicable order form or DPA.

Website hosting currently uses Vercel. The application API currently uses Railway. These providers may process technical request data needed to deliver and secure the service. When enabled, Google or Meta process sign-in on their own pages and return a one-time code to ATACSYS; ATACSYS discards the resulting provider token after confirming the account identity. Cross-border processing requires a jurisdiction-specific review; it is not authorized by this notice alone.

4. Retention and isolation

We keep request, session and security information only as long as reasonably needed for role review, support, safety and legal obligations. When enabled, anonymous site analytics and browser-only human-message threads are set to expire within 30 days and are pruned during normal service use. Company Memory is designed to remain separated by customer and from an agent creator. Final production retention and deletion schedules require contractual approval.

If you signed in with Facebook, you can request deletion through Facebook. ATACSYS verifies that signed request, removes the Facebook sign-in identity and deletes a social-only account when it has no other sign-in method.

5. Cookies and local storage

The public site uses browser storage only for essential interface behavior such as your light or dark theme preference and PWA operation. If you choose optional anonymous analytics, it also stores that choice and a random visit identifier in your browser for up to 30 days. If you choose a browser-only human message, it stores the opaque thread access token in that browser so you can read a reply. Declining analytics does not affect use of the public site. A signed-in customer account also uses an essential HTTP-only session cookie. No advertising, cross-site tracking, payment cookie or session-replay tool is intentionally enabled on the public site.

6. Access, correction and deletion

You may ask what information we hold about your request, correct it or request deletion, subject to security and legal retention duties. Email hello@atacsys.com from the address used in your request. We may ask for reasonable verification before acting.

Residents may have additional rights under applicable U.S. state, Canadian/provincial or Israeli law. This draft will be replaced with the final legal entity, controller address, formal request/appeal procedure, regulator route and international-transfer details before any production data or paid launch.