1. Who we are
Atrant is a software product operated by its founder, currently as a sole proprietorship pending the registration of a legal entity in Türkiye. References to "Atrant", "we", "us", or "our" in this policy mean [Atrant — legal entity name TBD], the data controller for the purposes of KVKK (Law No. 6698 on the Protection of Personal Data) and GDPR (Regulation (EU) 2016/679).
Contact for any privacy matter: app.atrant@proton.me. We respond within five business days, and within thirty days for formal rights requests, in line with KVKK Art. 13 and GDPR Art. 12(3).
2. What we collect
We collect the minimum we need to run the Service. There are five categories:
- Account data — Email, name, and the OAuth identity returned by Clerk (our authentication provider). We do not store your password — Clerk handles that.
- Connector data — When you connect a source via OAuth, Atrant retrieves documents, pages, threads, messages, issues, deals, calendar events, and metadata from the scopes you grant. Live connectors today: Notion, Slack, Google Drive, Gmail, Google Calendar, Confluence, Jira, Linear, HubSpot, GitHub, SharePoint, Zendesk, and direct file upload.
- Derived data — Vector embeddings, extracted entities (organisations, people, brands, campaigns), retrieval signals, and click/dwell feedback used to improve ranking inside your workspace only.
- Usage telemetry — Aggregated, anonymised request latency, error rates, and feature-usage counters. We do not include document content or query text in telemetry.
- Communications — Emails you send us and notes we keep on demo conversations.
3. How we use it
Source documents and the knowledge extracted from them are used exclusively to answer your questions and generate briefings for your workspace. Specifically, we use the data to:
- Operate the Service — index your sources, run hybrid retrieval, generate cited answers and briefings.
- Improve ranking for your tenant only — click and dwell signals tune retrieval inside your workspace; nothing crosses tenants.
- Maintain security and reliability — fraud detection, audit trails, rate-limiting.
- Communicate with you — service notifications, scheduled-maintenance notices, responses to your messages.
We do not use your content to train or fine-tune any general-purpose model. We do not sell or rent your data.
4. Lawful basis (KVKK + GDPR)
Under GDPR Art. 6 and KVKK Art. 5, we rely on the following bases:
- Contract (Art. 6(1)(b) GDPR / Art. 5(2)(c) KVKK) — for operating the Service you signed up for.
- Legitimate interests (Art. 6(1)(f) GDPR / Art. 5(2)(f) KVKK) — for security, telemetry, and product improvement, balanced against your rights.
- Consent (Art. 6(1)(a) GDPR / Art. 5(1) KVKK) — for each connector you choose to authorise — you grant specific OAuth scopes; you can revoke at any time from your provider or by disconnecting in-app.
- Legal obligation (Art. 6(1)(c) GDPR) — for tax, accounting, and lawful disclosure requirements.
5. Sub-processors
We use the following sub-processors, listed by purpose. Each has a Data Processing Agreement on file and processes data only under our instructions:
- Clerk — Authentication (account email + OAuth identity). United States.
- Vercel — Frontend hosting and edge delivery for atrant.io and app.atrant.io. Global edge network.
- Fly.io — Backend hosting (oauth.atrant.io). Primary region: Frankfurt (fra), European Union.
- Google (Gemini API) — Embedding generation and LLM inference for grounded Q&A. Only the specific text chunks relevant to a query are sent — your full corpus is never streamed continuously. Google does not use API content to train its models.
- Cohere — Optional cross-encoder reranking for the cloud tier. Disabled automatically in on-prem mode.
On-prem deployments use none of these sub-processors. See Section 6.
6. On-prem mode
Atrant ships a no-egress mode (VELTO_NO_EGRESS=1) that runs entirely inside your infrastructure. In this mode no data leaves your network: embedding, retrieval, ranking, and LLM inference all run locally against models you provision. None of the sub-processors listed in Section 5 receive your data. This is the deployment we recommend for regulated firms and clients with strict data-residency rules.
7. Retention
We retain workspace data while your account is active. On termination (by you or by us) we delete or export your data within thirty days, at your choice. Backups roll off within ninety days.
Audit logs (who asked what, when) are retained for one year by default, configurable per tenant. Telemetry counters (aggregated, no content) are retained for two years for operational analysis.
8. Your rights
Under KVKK Art. 11 and GDPR Articles 15–22, you have the right to:
- Access — receive a copy of your personal data we hold.
- Rectification — correct inaccurate data.
- Erasure — request deletion ("right to be forgotten").
- Restriction — limit how we process your data.
- Portability — export your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Complain — file a complaint with KVKK (Türkiye) or your EU member-state Data Protection Authority.
To exercise any of the above, email app.atrant@proton.me. We answer within thirty days.
9. International transfers
We process most data inside the European Union (Fly.io Frankfurt). Some sub-processors (Clerk, Vercel, Google, Cohere) are based in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. On-prem deployments avoid international transfers entirely.
10. Security
Tenant-isolated Postgres with row-level security enforced at the database layer. Encryption in transit (TLS 1.2+) and at rest. OAuth tokens encrypted with per-tenant keys (Fernet). Principle of least privilege on all internal services. We disclose a security breach affecting your personal data without undue delay and at the latest within seventy-two hours of becoming aware (GDPR Art. 33), and we will notify you directly when KVKK Art. 12(5) requires.
11. Children
Atrant is not intended for individuals under the age of eighteen. We do not knowingly collect personal data from anyone under eighteen. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We post material changes with a new "Last updated" date at the top of this page. Significant changes will also be notified by email to your account address at least thirty days before they take effect.
13. Contact
Questions, rights requests, or anything privacy-related: app.atrant@proton.me. Postal address will be added when our legal entity is registered.