Launch privacy evidence review

Last reviewed: January 8, 2026

This page records controlled-launch privacy scope for atonCRM. Privacy claims require counsel and evidence before publication.

Data lifecycle proof required before retention or deletion claims. Workspace-specific collection, provider, security, transfer, and rights terms are confirmed before activation.

Information We Collect

Information You Provide

Account Information

During controlled launch, account-data collection is reviewed for:

  • Name and email address
  • Company name and size
  • Phone number (optional)
  • Commercial contact details when approved for billing review
  • Authentication data handling evidence

CRM Data

When you use atonCRM, you may input:

  • Contact and account information
  • Deal and opportunity data
  • Activities and communications
  • Documents and files
  • Custom field data

Communications

When you contact us during launch, intake scope is reviewed for:

  • Email correspondence
  • Launch support intake notes
  • Survey responses
  • Feedback you provide

Information Collected Automatically

Usage Data

During controlled launch, usage-data collection scope is reviewed for:

  • Pages and features you access
  • Time spent on the platform
  • Actions taken (e.g., deals created, emails sent)
  • Error logs and crash reports

Device and Technical Data

Device and technical data scope is reviewed for:

  • IP address
  • Browser type and version
  • Operating system
  • Device identifiers
  • Referring URLs

How We Use Your Information

To Provide Our Services

  • Creating and managing your account
  • Processing transactions and billing
  • Providing customer support
  • Delivering features and functionality
  • Sending service-related communications

To Improve Our Platform

  • Analyzing usage patterns
  • Identifying and fixing bugs
  • Developing new features
  • Personalizing your experience
  • Conducting research and analytics

To Communicate With You

  • Responding to your inquiries
  • Sending product updates and announcements
  • Providing security alerts
  • Marketing communications (with your consent)

To Ensure Security

  • Detecting and preventing fraud
  • Protecting against unauthorized access
  • Monitoring for security threats
  • Enforcing our terms of service

How We Share Your Information

Sale and Sharing Review

Sale, sharing, and provider-use statements require counsel-reviewed evidence before customer promotion.

Service Providers

Provider categories are reviewed before publication and confirmed for each launch workspace:

  • Infrastructure provider scope
  • Billing provider scope
  • Email service providers
  • Analytics services
  • Customer support tools

Provider contracts, subprocessors, transfer terms, and customer data flows require current evidence before publication.

Legal Requirements

Legal disclosure terms require counsel review before publication, including whether and how information may be used to:

  • Comply with legal process
  • Protect our rights and property
  • Protect user safety
  • Investigate fraud or security issues

Business Transfers

Business-transfer treatment requires owner and counsel approval before publication.

Your Data Rights

Access and Portability

Export timing and formats require launch proof before publication.

Correction

Correction paths require launch support proof before publication.

Deletion

Deletion timing requires retention, backup, and legal-hold evidence.

Restriction

Request limits on how we use your data.

Objection

Object to certain processing, including marketing.

Withdrawal

Withdraw consent for processing at any time.

Rights request path: Contact us at privacy@atoncrm.com. Self-serve rights paths require launch proof before publication.

Data Security

Technical Measures

  • Transport protection evidence reviewed before publication
  • Storage protection evidence reviewed before publication
  • Security assessment evidence required before audit claims
  • Certification claims require current owner-approved reports
  • Hosting and physical-control claims require provider evidence

Organizational Measures

  • Training evidence required before publication
  • Access-control scope requires owner-approved evidence
  • Incident-process claims require current runbook proof
  • Security review cadence requires current evidence

Breach Notification

Security-event notification terms require counsel, owner, and incident-process review before publication.

Data Retention

Active Accounts

Active-account retention terms require current retention evidence before publication.

Closed Accounts

After account closure:

  • Deletion timing requires current retention evidence
  • Anonymized analytics data may be retained
  • Backup handling requires purge and restore evidence
  • Data required for legal compliance retained as necessary

International Data Transfers

Company location, hosting location, and cross-border processing statements require legal review before publication.

For users outside the United States, transfer terms require legal review and current safeguards before publication, including:

  • Transfer mechanism review
  • Data processing term review
  • Jurisdiction applicability review

Cookies and Tracking

Essential Cookies

Essential cookie categories require a current cookie table before publication.

  • Authentication cookie scope review
  • Session-management scope review
  • Security-token scope review

Analytics Cookies

Analytics cookie use requires current tool, consent, and data-flow review before publication.

  • Usage patterns
  • Feature adoption
  • Performance metrics

Preference Cookies

Preference cookie use requires current cookie-table evidence before publication.

  • Language preferences
  • Display settings
  • Dashboard layouts

Managing Cookies

Cookie management instructions require current consent, browser-behavior, and product-functionality review before publication.

Children's Privacy

Children's privacy applicability, age limits, and contact instructions require counsel review before publication.

California Privacy Applicability Review

California privacy notices and rights statements require counsel review and applicability confirmation before publication:

  • Know/Access Review: Confirm required notice and response language
  • Deletion Review: Confirm deletion request language and evidence
  • Sale/Sharing Review: Confirm whether opt-out language applies to current launch practices
  • Treatment Review: Confirm any required anti-retaliation language with counsel

To exercise these rights, contact privacy@atoncrm.com.

EEA/UK Privacy Applicability Review

EEA and UK privacy terms require counsel review and launch evidence before publication, including:

  • Service basis review: Confirm any contract language
  • Business-interest review: Confirm platform improvement and security language
  • Consent review: Confirm marketing communication language
  • Legal-obligation review: Confirm compliance language

Complaint, representative, and authority language requires counsel review before publication.

Changes to This Policy

Policy-change notice, acceptance, and versioning language require counsel review and owner approval before publication.

Contact Us

Privacy Questions:

privacy@atoncrm.com

Privacy Review Contact:

privacy@atoncrm.com

Mailing Address:

atonCRM, Inc.
Attn: Privacy Team

Related Policies

Review timestamp: January 8, 2026

Privacy FAQs