Atelove
Privacy Policy
How Atelove handles personal data, under GDPR, LGPD and CCPA/CPRA.
This page is in the language selected above. The version that applies to you is the one in the displayed language.
This Privacy Policy explains how Atelove handles personal data. It applies to the European Economic Area and the United Kingdom (GDPR/UK GDPR), Brazil (LGPD), the United States (including California's CCPA/CPRA) and the rest of the Americas, to the extent those laws apply.
Controller: Atelove. Data Protection Officer (DPO) contact: goatelove@gmail.com.
1. Roles: the triangle
The relationship involves three parties: Atelove (the platform), the architect (our client) and her end client. Data protection roles vary depending on the data:
- For the architect's account data (registration, billing, platform usage), Atelove is the controller.
- For the data the architect enters about her end clients, Atelove acts as a processor: it processes that data on behalf of and under the instructions of the architect. In this case, the architect is the controller of her end clients' data.
For processing as a processor, we offer the architect a Data Processing Agreement (DPA), governing obligations, security and subprocessors. Request the DPA at goatelove@gmail.com.
2. Data we process
- Account data: name, email, credentials, studio name, language and preferences.
- Content and media: text, images, photos, projects, proposals and specifications you upload or generate.
- End client data entered by the architect: name, contact and project information (processed as a processor).
- Usage and analytics data: pages accessed, actions, device, technical records and security logs.
- Cookies and similar technologies (see the dedicated section).
- Payment data: processed by a third-party processor; we do not store full card data.
3. Legal bases and purposes
We process personal data based on one or more of the following grounds, depending on the purpose:
- Performance of a contract: to create and operate your account, provide the Service and offer support.
- Consent: where applicable, for example for certain cookies and marketing communications.
- Legitimate interest: security, fraud prevention, Service improvement and operational communication, balanced against your rights.
- Compliance with a legal obligation: tax, accounting and regulatory obligations.
4. Subprocessors and international transfers
To operate the Service, we rely on third-party providers that may process personal data as subprocessors, including:
- Supabase: database and authentication;
- Vercel: application hosting and delivery;
- Stripe: payment processing;
- Resend: transactional email delivery;
- Cloudflare: content delivery network and security.
Data may be processed on servers located in different countries (for example, the European Union, the United States and Brazil). Where there is an international transfer, we apply appropriate safeguards, such as standard contractual clauses (SCCs) or adequacy decisions, to the maximum extent required by applicable law.
5. Your rights
Subject to applicable law, you may exercise the following rights over your personal data:
- GDPR/UK and LGPD: access, correction, deletion, portability, restriction, objection and withdrawal of consent.
- CCPA/CPRA (California): to know what data is processed, request deletion, correct it, and opt out of the "sale" or "sharing" of data, without discrimination for exercising your rights.
To exercise your rights, write to goatelove@gmail.com. If you are an end client of an architect, send your request to her (the controller); Atelove will assist as a processor.
6. Retention
We keep data for as long as necessary for the purposes described, to comply with legal obligations and to defend rights. After that period, data is deleted or anonymized. Technical backups may retain copies for a limited period.
7. Security
- Encryption in transit and technical and organizational measures appropriate to the risk.
- Per-tenant data isolation, with record-level access control (RLS).
- Removal of sensitive metadata from photos (for example, EXIF/GPS data) when processing images.
- Access controls, event logging and monitoring.
No system is fully immune to risk; in case of a relevant security incident, we will notify as required by applicable law (GDPR/LGPD).
9. Minors
The Service is intended for professionals aged 18 or older and is not directed at minors. We do not knowingly collect data from minors under 18.
10. Changes to this Policy
We may update this Policy. When a change is material, we will notify you by reasonable means. The effective date at the top indicates the current version.
11. Google account data (Google Calendar integration)
If you connect your Google account, Atelove requests the minimum access needed: creating a dedicated calendar (named 'Atelove') in your account and writing your dated task events to it, plus reading your email address to identify the connected account. The app only accesses the calendar it creates: it does not read, change or delete your other calendars or events.
- Access tokens are stored encrypted and used exclusively for the synchronization described above.
- We do not sell data obtained from Google accounts, do not use it for advertising, and do not allow humans to read it, except with your explicit consent, for security reasons, or when required by law.
- You can disconnect at any time in the platform (My account, Integrations) or revoke access at myaccount.google.com/permissions; upon disconnection the tokens are discarded.
- Atelove's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
12. Contact and data protection officer
For privacy matters, contact the DPO: goatelove@gmail.com.