Overview

Atrium ("we", "our", or "us") operates the Atrium mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your personal information when you use the App.

We take privacy seriously. Your travel data and residency information are sensitive. We collect only what is necessary and never sell your data to third parties.

Information We Collect

We collect the following types of information:

How We Use Your Information

We do not use your data for advertising. We do not sell your personal data. We share personal data only where necessary to provide the App's services, with our infrastructure providers, with advisers or assistants you authorise, or where required by law.

Legal Basis for UK and EU Users

Where UK GDPR or EU GDPR applies, we process your personal data on the following bases: performance of a contract to provide the App, your consent for optional location permissions and notifications, our legitimate interests in maintaining security and improving the service, and legal obligations where applicable.

Uploaded Documents and Access

Uploaded documents may include boarding passes, tickets, passport stamps, hotel receipts, or other evidence you choose to add. These files are stored in access-controlled cloud storage and linked to your account or authorised workspace.

We do not routinely review uploaded documents. However, Atrium and our cloud service providers may have limited authorised technical access where necessary to operate document-processing features, provide support you request, maintain security, investigate abuse, comply with law, or enforce our terms. Access is limited to authorised personnel or systems with a need to know.

Data Storage and Security

Your data is protected using encryption in transit and at rest, access controls, and operational safeguards. We use Firebase (Google Cloud) as our backend infrastructure. Firebase and Google Cloud maintain security and compliance programmes including SOC 2, ISO 27001, and GDPR-related commitments.

Data Retention

We retain your account data, travel records, and uploaded evidence for as long as your account is active or as long as needed to provide the App's residency and evidence features. You may delete records in the App where available or request deletion of your account and associated data by contacting privacy@atrium.tax. We will process deletion requests within 30 days, unless we are required to retain limited information for legal, security, dispute-resolution, or fraud-prevention purposes.

Residual copies may remain in encrypted backups or logs for a limited period before automatic deletion according to our backup and security retention practices.

Third-Party Services

The App uses the following third-party services:

Your Rights

You have the right to:

To exercise any of these rights, contact us at privacy@atrium.tax.

Children's Privacy

The App is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via the App or by email. Continued use of the App after changes constitutes acceptance of the updated policy.

Contact

For privacy-related questions or requests:

Email: privacy@atrium.tax
Website: www.atrium.tax