Privacy Policy
Last updated 10 July 2026
Atrio ("Atrio", "we", "us", "our") is operated by Bletchley Consulting Services Limited, with its registered address at Pioneer Centre, 750 Nathan Road, Kowloon, Hong Kong. This Privacy Policy explains how we collect, use, and protect information when you use atrio.cc, app.atrio.cc, and related services (the "Service").
By using the Service you agree to this Policy. If you do not agree, do not use the Service.
1. Who this Policy covers, and the two kinds of data
Atrio serves organisations. It's important to distinguish two roles:
- Account data — information about the organisations and individuals who hold Atrio accounts (names, emails, billing details, usage). For this data, Atrio is the data controller.
- Customer content — the dashboards, files, datasets, and related material that customers upload, host, or share using the Service, which may contain personal or business data chosen by the customer. For this data, Atrio acts as a data processor on behalf of the customer, who is the controller. The customer is responsible for having the right to upload and share that content and for its lawfulness.
2. Information we collect
You provide:
- Account and profile information (name, work email, organisation name, role).
- Billing information (processed by our payment provider; we do not store full card numbers).
- Content you upload, host, or share, and any datasets you attach.
- Communications you send us (support requests, feedback).
Collected automatically:
- Usage and log data (actions taken, features used, pages viewed, timestamps).
- Device and technical data (IP address, browser type, operating system).
- Cookies and similar technologies (see Section 9).
- Audit records of actions that touch content (for security and to provide the Service).
From third parties:
- Authentication and identity information from sign-in providers you choose to use.
- Billing and fraud-prevention data from our payment processor.
3. How we use information
We use information to:
- Provide, operate, maintain, and secure the Service;
- Authenticate users and enforce the permissions and sharing rules customers configure;
- Process payments and manage subscriptions;
- Provide support and respond to requests;
- Monitor, prevent, and investigate security incidents, fraud, abuse, and violations of our terms;
- Analyse and improve the Service, including developing new features;
- Comply with legal obligations and enforce our agreements.
Customer content specifically: we process customer content to provide the Service — hosting it, rendering it, applying the access controls the customer sets, enabling the optional "Ask the data" feature, and supporting the customer. We do not sell customer content, and we do not use the contents of your dashboards or datasets to train AI models.
Aggregated / de-identified data: we may create and use aggregated or de-identified data (which does not identify you or any individual) for any business purpose, including improving and promoting the Service.
4. The "Ask the data" AI feature
When a customer enables "Ask the data," questions and the relevant attached data are sent to third-party AI model providers (currently Google, for Gemini models, and Anthropic, for Claude models) to generate an answer, and returned to the authorised viewer. We select providers that contractually commit not to train their models on data passed through their APIs. We are not responsible for the accuracy of AI-generated answers; they are provided as-is to help explore data and should not be relied on as professional advice.
5. How we share information
We do not sell personal information. We share information only as follows:
- Service providers / subprocessors — hosting, storage, authentication, payments, analytics, AI inference, email delivery — who process data on our behalf under contract.
- Within a customer's organisation — according to the permissions and sharing that customer's users configure. Atrio enforces those settings but is not responsible for a customer's own choices about who they share with.
- Legal and safety — where required by law, legal process, or government request, or to protect the rights, property, safety, or security of Atrio, our users, or the public, or to investigate fraud or abuse.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, in which case information may be transferred as a business asset.
- With your direction or consent — for anything else.
6. International transfers
Atrio is based in Hong Kong and uses infrastructure and providers that may be located in other countries. By using the Service, you acknowledge your information may be transferred to and processed in countries whose data-protection laws differ from your own. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, where applicable) for such transfers.
7. Data retention
We retain information for as long as your account is active and as needed to provide the Service. After account closure, we delete or de-identify customer content within 30 days, except where we must retain certain data to comply with legal obligations, resolve disputes, prevent fraud, or enforce our agreements. Backups may persist for a limited additional period before being overwritten. Customers are responsible for exporting content they wish to keep before closure.
8. Security
We implement technical and organisational measures designed to protect information, including encryption in transit and at rest, access controls, and audit logging. Access to customer content by Atrio personnel is restricted to what is necessary to operate and support the Service.
However, no method of transmission or storage is completely secure. We cannot and do not guarantee absolute security, and we are not liable for unauthorised access, disclosure, or loss that occurs despite reasonable safeguards, except to the extent required by law. You are responsible for maintaining the confidentiality of your account credentials and for the security choices you make (such as who you share content with and whether you use passwords or expiry on shares).
9. Cookies
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage. You can control cookies through your browser settings; disabling some may affect functionality.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, or to object to certain processing. To exercise these, contact us at privacy@atrio.cc. We will respond as required by applicable law. We may need to verify your identity first.
For customer content, if you are an individual whose personal data appears in content uploaded by a customer (for example, you're in a dataset someone hosted), your request is generally directed to that customer as the controller; we will assist them as their processor.
11. Children
The Service is not directed to individuals under 18, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by posting the updated Policy with a new "Last updated" date and, where appropriate, by other means. Your continued use of the Service after changes take effect constitutes acceptance.
13. Contact
Questions about this Policy or your information: Bletchley Consulting Services Limited Pioneer Centre, 750 Nathan Road, Kowloon, Hong Kong privacy@atrio.cc