Legal · attache.group

Privacy Statement

How Attaché collects, uses, stores and shares information — written to be read, not to be skimmed past.

Effective 09-22-2026 Last updated 09-22-2026 Applies to the Attaché platform and attache.group

The short version

  • Your CRM data is yours. We hold it to run the service for you, and we do not sell it, rent it, or use it to advertise to anyone.
  • Each customer's data lives in its own database schema. Not a shared table with a filter on it — a separate namespace, addressed by a connection that has never been able to reach another customer's tables.
  • If you connect a mailbox, we store message subjects and bodies so they can appear on your contact and deal timelines. That is the most sensitive thing we hold, so it is stated here rather than left to be inferred.
  • We use Google Gemini for AI features, and we send it only the text a given task needs. Google's paid API terms exclude that text from training its models.
  • We process data in the United States, for every customer, on purpose. Section 8 explains why, and who should not sign up because of it.
  • This website sets no cookies and runs no analytics. The application sets two, and both are required to keep you signed in.

Who we are

Attaché is a product of Attache Holdings LLC, a limited liability company with its registered address at 7 Portwalk Place, Portsmouth, New Hampshire 03801, United States. In this statement, “Attaché”, “we”, “us” and “our” mean that company.

Attaché is a self-serve, multi-tenant CRM with AI agents, sold per seat. Customers sign up and run themselves. There is no per-customer deployment and no professional-services engagement in the middle — one platform, one set of infrastructure, many customers isolated inside it.

Which product this statement covers. Attache Holdings LLC operates more than one product, and this domain is the company’s rather than any one product’s. This statement covers Attaché — the self-serve platform — and this website. It does not cover Sentinel, our contracted life-sciences build, which runs as a single-tenant deployment on its own infrastructure with its own controls; how we handle data there is governed by the agreement signed with that customer and by the data processing agreement under it, not by this page.

Our role: processor or controller

Which hat we wear depends on which data you mean, and the distinction matters for your rights.

Data you put into Attaché — we are the processor

The accounts, contacts, deals, notes, tasks, files and mail in your workspace belong to you. You decide what goes in, why it is there, and how long it stays. We process it on your instructions in order to provide the service. Under the GDPR and similar laws, you are the controller and we are the processor, and the people whose details you store are the data subjects.

If one of your contacts asks us directly what we hold about them, we will not answer for you. We will refer them to you and help you respond.

Your own account and billing data — we are the controller

The name, work email and password of the people on your account, your subscription and payment records, and our server and usage logs are data we determine the purposes for. For that narrow set, we are the controller.

Information we collect

Information you give us

  • Account information — the name, work email address and password of each person you give a seat to, and the organization name.
  • Workspace content — everything you or your team enter or import: accounts, contacts, deals, quotes, notes, tasks, expenses, attachments.
  • Support correspondence — what you write to us when you ask for help.

Information that arrives because you connected something

  • Mailbox and calendar content, if and only if a user on your account connects a mailbox. Section 4 covers this in full.

Information we generate

  • Authentication records — every sign-in, multi-factor challenge, pass, failure, enrollment and sign-out is appended to an audit log.
  • Audit trail — every change to your data is recorded with who made it and when.
  • AI usage metering — for each AI action, the kind of job, the model tier and the token count, so that your usage dashboard can show you what the AI layer did and what it cost.
  • Technical logs — ordinary server logs: request paths, timestamps, IP address, error traces.

We do not buy personal data about you from data brokers to enrich your account, and we do not build advertising profiles.

Connected mailboxes

Connecting a mailbox is optional, it is off until a user turns it on, and it is the part of Attaché that touches the most sensitive information. So here is exactly what happens.

What we ask for

When you connect a Microsoft 365 or Google Workspace mailbox, you are shown your provider's own consent screen listing the permissions we request. They are:

PermissionMicrosoft 365Google WorkspaceWhat it is for
Read your mailMail.Readgmail.readonlyPutting the messages on a contact or deal onto its timeline
Send mail as youMail.Sendgmail.sendSending a message you wrote and sent from inside Attaché, in your own thread and filed in your own Sent folder
Know who signed inUser.Readuserinfo.email, userinfo.profile, openidRecording which address the mailbox actually belongs to
Keep the connection aliveoffline_accessRefreshing access without asking you to sign in again every hour

That is the whole list. On the direct Microsoft and Google connections we do not request access to your calendar, your contacts, your files or your drive, and we cannot read them. The read permission is deliberately the narrow, read-only one: we cannot modify or delete anything in your mailbox.

We never send mail on your behalf on our own initiative. The send permission is used only when a person on your account composes and sends a message in Attaché. We do not send marketing from your address, and we do not auto-reply.

What we store

When a mailbox is connected, message subjects and full message bodies are stored in your workspace, alongside a one-line AI-generated summary used on the timeline. Attachments you choose to save are stored too. Where calendar sync is in use, we store an event's subject, time, participants and conferencing link — not its full description.

We store the message body because the timeline is only useful if the message is actually there. If that is more than you want us to hold, do not connect the mailbox — every other part of Attaché works without it.

Turning it off

You can disconnect a mailbox in Attaché at any time, and you can independently revoke our access from your Microsoft or Google account settings without involving us. Revoking stops all further access immediately. Mail already stored in your workspace stays there until you delete it or close your account; ask us and we will delete it for you.

How we use information

  • To provide the service — storing, organizing and showing you your own data, and running the features you use.
  • To authenticate and secure accounts — signing people in, running multi-factor checks, detecting abuse, keeping the audit trail.
  • To run AI features you invoke, as described in section 6.
  • To bill you and to meter AI usage against your plan.
  • To support you when you contact us, which sometimes means a member of our team looking at your workspace to reproduce a problem. We do that to answer a request, not on a schedule.
  • To keep the platform working — diagnosing errors, capacity planning, and improving the product in aggregate.
  • To meet legal obligations and to enforce our terms.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your workspace content to train AI models, ours or anyone else's.

Where the GDPR applies to our own controller-side processing, our legal bases are performance of a contract (running your subscription), legitimate interests (securing the platform, preventing abuse, improving the product), and legal obligation (tax and accounting records).

AI processing

All AI features in Attaché run on Google Gemini, called through a single point in our code so that every model call is recorded with its job kind, model tier and token count.

We send only the text a specific task needs. The case worth naming: when a connected mailbox takes in a message longer than 500 characters, up to 8,000 characters of the message body are sent to Gemini to produce the one-line summary you see on the timeline. Shorter messages use the provider's own snippet and are not sent at all.

Training. Google's paid API terms exclude the inputs and outputs of these calls from training Google's models. We do not train models on your data ourselves.

Region. These calls go to a global Google endpoint with no region selection. Google's regional-endpoint product is not in use.

AI output can be wrong. Summaries, extractions and suggestions are drafts for a person to check, and anything read out of an external document is confirmed by a human before it is written into your records.

Who we share information with

We share data with the service providers below, and with nobody else except as described at the end of this section. This is the actual list as of the date at the top of this page — not a list of everything we might one day use.

ProviderWhat it does for usWhat it can seeWhen
Google CloudHosting, database and object storageAll customer data, at rest and in transitAlways
Google (Gemini)AI reasoningOnly the text sent for a given task — see section 6Always
NylasMailbox and calendar sync for providers we cannot connect to directlyMailbox and calendar contentOpt-in, and only where there is no direct alternative
Microsoft / GoogleYour own mailbox, connected directlyMailbox content, passing between your tenant and usOpt-in

Attaché checks for a direct connection before offering the one we pay for. If you are on Google Workspace or Microsoft 365, we guide you to connect your own mailbox directly, and Nylas is offered only to customers with no such option. We built that to control cost, but it has a privacy consequence worth stating: on the direct road there is one fewer company touching your mail. It does not remove the others — on either road the message body is stored by us and excerpted to Gemini.

That is the whole list. No other company is set up to receive your data. Anything we add appears in this table before it is switched on.

We may also disclose information when the law requires it — a valid subpoena, court order or similar legal process — and to protect our rights or someone's safety. If we are ever compelled to hand over a customer's data, we will tell that customer unless we are legally prohibited from doing so. If Attaché is acquired or merged, customer data may transfer as part of that transaction, and you will be told before it becomes subject to a different privacy statement.

Where your data is processed

Attaché runs one set of infrastructure for every customer worldwide, located in the United States. We do not create per-region infrastructure, and we do not intend to. A self-serve product priced per seat cannot carry a separate database and storage footprint per jurisdiction; regional infrastructure is what a contracted single-tenant deployment buys, and it is priced accordingly.

Said plainly rather than buried: if you are outside the United States, you are served from infrastructure inside the United States. Personal data of people in the EU and UK is processed in the US — by the platform, by Gemini, and by Nylas where it is used. Where we rely on a transfer instrument for that, it is the EU-US Data Privacy Framework where a provider is certified, and standard contractual clauses otherwise.

If you are under a hard data-residency obligation — a regulated financial institution, a public body, a controller with a residency clause in its own contracts — Attaché self-serve is probably not the right product for you, and you should not connect a mailbox to it. Talk to us about a contracted deployment instead. We would rather say this here than have you find it out later.

How long we keep it

Your workspace content stays until you delete it or close your account. We do not age it out on a schedule.

When you close your account, we delete your workspace. Your records live in a database of your own and your files are stored under your workspace's own name, so deleting everything we hold on you is one operation rather than a hunt through shared tables. It removes your records, your files, and your registration with us. We do this within 30 days of closure, and sooner on request. Ask us and we will confirm in writing when it is done.

Backups are the one honest exception. Our automated database backups still hold a copy of your data until they expire on their normal cycle, which is no longer than 30 days after the deletion. They are encrypted, they are not used to serve the product, and nothing is restored from them to bring your data back.

Two things outlive that deletion, and you should know about both. Ordinary backups roll off on their own cycle, so data can persist in a backup for a short period after it is gone from the live system; it is not restored to anyone. And we keep billing and tax records for as long as the law requires us to, independently of your workspace.

Before you close an account, export what you want to keep. Section 11 covers how.

How we protect it

  • Tenant isolation. Each customer gets its own PostgreSQL schema — a separate namespace with its own copy of every table, not a shared table with a customer column on it. The schema is fixed when a database connection is opened and never changed afterward, so a connection serving one customer has never been able to address another's tables. This is the strongest control we have and the reason it is listed first.
  • Passwords are stored using scrypt with a per-user random salt and compared in constant time. They are never reversible and never written to a log.
  • Sessions are a signed, HTTP-only cookie marked secure in production — not a token sitting in browser storage where a script could read it.
  • Multi-factor authentication is available to every user via an authenticator app. It is per user and is not currently something an administrator can force on the whole organization.
  • Encryption. TLS for all traffic between your browser and us and between us and our providers. Platform-managed encryption at rest on the database and on file storage.
  • Authorization and audit. Permissions are named capabilities resolved per role and adjustable per organization. Every write goes through one layer that applies the permission check and records the audit entry, so neither can be skipped by new code.
  • Access by our staff is limited to the people who need it to operate and support the platform.

No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability, write to support@attache.group and we will respond.

Your choices and rights

Everyone

  • See and correct your own account details in the application.
  • Export your workspace data in a portable format — ask us if the in-app export does not cover what you need.
  • Delete individual records at any time, or close your account and have the whole workspace removed.
  • Disconnect any connected mailbox, from Attaché or from your provider directly.

If the GDPR, UK GDPR, CCPA/CPRA or a similar law covers you

You have rights of access, correction, deletion, portability, restriction and objection, and the right not to be discriminated against for exercising them. Where we are the controller — your own account and billing data — exercise them by writing to us at the address in section 15. We will respond within the time the applicable law allows, normally 30 days.

Where we are the processor — the contacts and companies in someone's workspace — the customer who operates that workspace is the controller, and the request belongs to them. Contact them. If you do not know who they are, write to us and we will forward your request to the right customer and tell you that we have.

We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. We do not make decisions producing legal effects about you by automated means alone.

If you are in the EEA, the UK or Switzerland, you may also complain to your local data protection authority. We would rather you came to us first.

Cookies

This website — attache.group — sets no cookies at all. It is static HTML and CSS with no scripts, no analytics, no tag manager, no advertising pixels and no embedded third-party content. Nothing here follows you anywhere.

The application sets two cookies, both strictly necessary and neither used for tracking: a signed session cookie that keeps you signed in, and a short-lived cookie used while completing a multi-factor challenge. Both are HTTP-only. Blocking them means you cannot sign in.

Children

Attaché is a business tool sold to businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has reached us, write to us and we will delete it.

Changes to this statement

We update this statement when the product changes, and the date at the top always reflects the current version. If we make a change that materially affects how we handle your data — a new category of information, a new purpose, or a new provider with access to customer data — we will tell account administrators by email before it takes effect, not after.

Contact us

Privacy questions, data requests, and security reports all go to the same place, and a person reads it.

Email: support@attache.group
Post: Attache Holdings LLC, 7 Portwalk Place, Portsmouth, NH 03801, United States

See also our Terms of Service.