1. Who we are and our role
Atrium is a client-experience platform that Firms use to keep their clients informed about the progress of their projects. When a Firm uses Atrium, the Firm is the controller of the data it and its clients put into the Service, and Atrium acts as a processor that handles that data on the Firm’s behalf and under its instructions. For our website and account records, Atrium is the controller.
2. Information we collect
- Account information: names, email addresses, roles, and firm details used to create and secure accounts.
- Project content: project milestones, schedules, approvals, messages, documents, and images that Firms and their clients create in the Service.
- Connected accounting data: when a Firm connects QuickBooks Online, we receive a limited, read-only copy of invoice and payment records (see Section 4).
- Billing information: subscription and payment status. Card details are handled by our payment processor (Stripe) and are never stored on our servers.
- Usage and device data: log data such as IP address, browser type, and pages viewed, used to operate and secure the Service.
3. How we use information
- To provide, maintain, and secure the Service and its features.
- To display project status and (where a Firm enables it) financial status to clients.
- To send transactional messages such as reminders, digests, and account notices.
- To process subscription billing and prevent fraud and abuse.
- To provide support and to comply with legal obligations.
We do not sell personal information, and we do not use it for advertising.
4. QuickBooks Online and Intuit data
When a Firm’s administrator connects their QuickBooks Online company, Atrium accesses Intuit data solely through the Intuit Accounting API using OAuth 2.0 authorization granted by that administrator. Our handling of this data is as follows:
What we access
We read only Invoice and Payment records, and only the fields needed to show a project’s billing status (such as amount, balance, due date, invoice number, and, where enabled, the QuickBooks pay-online link). Our access is read-only: Atrium never creates, edits, or deletes any data in QuickBooks, and we do not access QuickBooks Payments, banking, payroll, or customer bank/card details.
How we use it
This data is used only to mirror invoice and payment status into the connected Firm’s project ledgers, and to optionally display invoice amount, status, and the QuickBooks pay-online link to that Firm’s clients when the Firm turns that setting on. QuickBooks data is never sent to any artificial-intelligence model or used to train any model.
How we store and protect it
OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. Mirrored invoice and payment data is stored in our access-controlled database and is logically separated by Firm so that one Firm’s data is never visible to another.
How you can remove it
A Firm can disconnect QuickBooks at any time from the Firm’s integration settings, which revokes Atrium’s access token with Intuit and stops further syncing. On disconnection or on request, we delete the stored Intuit tokens and mirrored accounting data associated with that connection, except where retention is required by law. Our access, use, storage, and disclosure of Intuit data comply with the Intuit Developer terms and applicable data-handling requirements.
5. Artificial intelligence features
Atrium uses generative AI to help Firms draft client-facing status summaries. These features operate only on project data authored within Atrium (such as milestones, schedule changes, and activity). As stated above, QuickBooks and other Intuit data is never provided to any AI model. AI-generated drafts are reviewed by the Firm before they are shared with a client.
6. How we share information
We share information only as needed to run the Service:
- Within a Firm’s workspace: a Firm’s team members and its invited clients see the content shared with them, according to permissions set by the Firm.
- Service providers (subprocessors): we use a small number of vendors to operate Atrium: cloud hosting and database infrastructure, email delivery, payment processing (Stripe), and a generative-AI provider (for the non-Intuit AI features above). Each is bound to protect the data and use it only to provide their service to us.
- Legal and safety: where required by law, or to protect the rights, safety, and security of Atrium, our users, or the public.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell or rent personal information to third parties.
7. Data retention
We retain information for as long as an account is active and as needed to provide the Service. After an account is cancelled, workspace data remains available for export for 90 days, then we delete or anonymize it within a reasonable period, unless a longer retention is required by law. Firms can download a complete copy of their workspace from workspace settings at any time, and may request deletion of their workspace data as described below.
8. Security
We use technical and organizational measures appropriate to the sensitivity of the data, including encryption in transit (TLS), encryption of connected-service tokens at rest, access controls, and tenant isolation. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address issues we identify.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. Because much of the data in Atrium is controlled by a Firm, we may direct rights requests to the relevant Firm, or act on the Firm’s instructions. You can exercise choices, or ask us to route a request, by contacting us at the address below.
10. International users
Atrium is operated in the United States. If you access the Service from outside the United States, your information may be processed in the United States, where data-protection laws may differ from those in your country.
11. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice.
12. Contact us
Questions about this Policy or your information can be sent to Comber LLC at support@atriumportal.io.