Privacy Policy
Privacy Policy.
How Client Atrium handles data, written for both audiences: the agencies who are our customers, and their clients, who may only ever see their agency's branding.
Effective July 27, 2026, last updated August 4, 2026 (added the Connected Google accounts section, backup and breach-notification commitments). Client Atrium is operated by RMH Websites, a United States business owned by Ryan Huffman.
This policy works together with our Terms of Service and our Security page, which describes how we protect what this policy covers. The plain-words summaries are honest guides to each section, but the formal text is the operative language.
1. What this policy covers
In plain words: One policy for the product and this website. The website part is short, because the website collects almost nothing.
This policy covers the Client Atrium application at www.clientatrium.app (the “Service”) and the marketing website at clientatrium.com. It replaces any earlier site-only privacy page.
The marketing website carries no advertising and measures its traffic two ways. A cookieless tool from our hosting provider counts page views and referrers without storing anything in your browser. Google Analytics measures visits and where they came from, and it does use cookies; the details are in the cookies section. We use both to learn which pages are worth writing, nothing more. Our hosting provider also keeps standard server logs (IP address, page requested, time) for operations and abuse prevention. If you email hello@ or security@, we keep the email so we can answer you and remember the conversation; we do not add you to any list or share your address. That is the entire privacy story of the website. The rest of this policy is about the Service.
2. Our two roles: controller and processor
In plain words: For agency account data, we decide how it is handled, so we are the controller. For everything inside client workspaces, the agency decides and we act only on its instructions.
Client Atrium is used by agencies, our customers, who invite their own clients into workspaces. That structure gives us two distinct roles.
We are the controller for the data agencies give us directly to run their accounts: registration details, billing information, support correspondence, and the usage and security logs the Service generates.
We are a processor and service provider for everything inside client workspaces: messages, files, contracts, signature records, and the personal data of client users. For that content, the agency is the data controller (the “business” under United States state privacy laws). We process it only to provide the Service, on the agency’s instructions as expressed through the Service’s settings and features. We do not use workspace content for advertising, we do not sell it, and we do not use it to train AI models.
3. If you are a client of an agency
In plain words: If you use a portal your agency gave you, the agency runs it and we are the software underneath. Send requests about your data to the agency first; we help them answer.
You may be reading this because you use a client portal branded to an agency you work with. Client Atrium is the software underneath that portal, and our name may not appear anywhere in it. Your relationship is with the agency: it invited you, controls what the workspace contains, and decides how long your data is kept.
You are invited by email and set your own password on your first visit. Your access is limited to your own workspace, and the data you add there is visible to you and to the agency’s team, not to other clients.
Because the agency is the controller of your workspace data, requests about that data (access, correction, deletion, a copy) should go to the agency, and we assist the agency in fulfilling them. If you contact us directly, we will verify your request, pass it to your agency, and help where we can.
4. What we collect
In plain words: Account details from agencies, an email address and workspace content from client users, billing through Stripe, and the server logs any service needs. Nothing gathered for advertising.
From agencies
Account registration details (name, email address, agency name, password), plan and billing records, and any correspondence you send us. Card details go to Stripe, our payment processor; we never hold full card numbers.
From client users
The email address the agency invites you with, your name if the agency provides it, and the content you add to your workspace.
Workspace content
Messages, files, project records, contracts, and signature records, including the tamper-evident audit trail of a signing session (timestamped events and the technical details needed to make the trail verifiable).
One detail deserves calling out by name: when someone signs a document, the signing flow records their IP address and browser user agent, and both are printed on the completion certificate. That certificate is delivered to every party to the signature, so a signer’s IP address is visible to the other signers. This is how electronic signature records are ordinarily evidenced, and it is disclosed to the signer before they sign.
Collected automatically
Server and security logs: IP address, browser type, timestamps, and the resources requested. We keep these to operate and secure the Service. We do not run advertising trackers and do not track you across other sites.
5. How we use information
In plain words: To run the product, bill for it, support you, and keep it secure. We never sell personal data and never show ads.
We use the information above to:
- provide and operate the Service, including signing people in and keeping sessions;
- deliver transactional email, such as thread notifications, reply-by-email messages, and signature requests;
- bill agencies and manage subscriptions through Stripe;
- answer support requests;
- secure the Service, prevent abuse, and investigate incidents;
- improve the product, using aggregate usage patterns rather than the contents of workspaces;
- meet legal obligations.
What we never do: we do not sell personal data, we do not share it for cross-context behavioral advertising, we show no ads, and we do not use your data to train AI models.
7. AI features
In plain words: Every AI feature is off until an agency turns it on, specific clients can be excluded, and AI inputs are not used by us to train models.
The Service offers optional AI features on certain paid plans. Each feature is off by default and is enabled individually by the agency. Agencies can exclude specific clients from AI processing, and the Service honors the exclusion: content from excluded clients is not sent to AI providers.
When a feature is enabled and used, the relevant content is routed through Vercel AI Gateway to third-party model providers to generate the output. We do not use AI inputs or outputs to train models. Processing by the model providers is governed by their own terms. Until an agency enables an AI feature, none of its data touches any AI provider.
8. Connected Google accounts
In plain words: An agency can connect its own Google account so its clients’ website traffic shows up in the portal. We read analytics numbers, store them for the agency, and can be disconnected at any time. We never see passwords and never touch anything else in the Google account.
Agencies on eligible plans can connect a Google account to power the website analytics feature. The connection is optional, per-agency, and made by an agency admin through Google’s own sign-in and consent flow; we never see the account’s password.
What we access
The connection grants read-only access to Google Analytics: the list of accounts and properties the Google account can see (so the agency can map each property to one of its clients) and aggregated traffic metrics for the mapped properties, such as daily sessions, visitors, page views, engagement, traffic channels, top pages, regions, and device types. We also receive the connected account’s email address, which we show so the agency knows which account is connected. We request nothing else: no Gmail, no Drive, no contacts, no write access of any kind.
What we store
A refresh token that lets the Service fetch analytics on the agency’s behalf, stored encrypted (AES-256-GCM) with a key held only in our server environment, in a table no client-facing role can read; the connected email address; the agency’s property-to-client mappings; and the aggregated daily metric rows themselves, which become part of that agency’s workspace data. We do not receive or store data about individual visitors to the analyzed websites.
Limited use
Client Atrium’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice: Google data is used only to provide the analytics feature to the agency that connected the account. It is never used for advertising, never sold, never used to train AI models, and never read by a human except with the agency’s permission for support, for security investigation, or where the law requires.
Disconnecting
An agency admin can disconnect the Google account in the Service at any time, which deletes the stored token and stops all fetching, and can also revoke the Service’s access from Google’s security settings. Metrics already stored remain part of the agency’s workspace data, subject to the same retention, export, and deletion rules as everything else, unless the agency asks us to delete them.
9. Subprocessors
In plain words: The complete list of companies that touch your data, what each one does, and where it runs. We tell account owners before the list changes.
These are the third-party providers that process data on our behalf:
| Provider | Role | Location |
|---|---|---|
| Supabase | Database and file storage | United States |
| Vercel | Hosting, delivery, and cookieless website analytics | United States |
| Bunny.net | Media storage and content delivery | Germany (storage), European Union (CDN delivery) |
| Stripe | Payment processing | United States |
| Resend | Transactional email | United States |
| Sentry | Error tracking, dormant until enabled | United States |
| Two narrow roles: Google Analytics measures marketing website traffic (never inside the Service), and the Google Analytics APIs supply an agency's own analytics data when that agency connects its Google account (Section 8) | United States | |
| AI model providers, via Vercel AI Gateway | AI features, only for agencies that enable them | United States |
The AI model providers are conditional: no data reaches them unless an agency enables an AI feature, as described in Section 7.
When we plan to add or replace a subprocessor that will handle workspace content, we will update this list and notify agency account owners by email at least 30 days before the change takes effect, so an agency that objects has time to raise it or leave with its export.
10. Where data lives
In plain words: The database and files live in the United States, media lives in Germany with a European delivery network, and using the service means your data crosses those borders.
The Service’s database and file storage run on Supabase in the United States. Media is stored with Bunny.net in Germany and delivered over its European CDN. Payment, email, and hosting providers process data primarily in the United States.
Data is therefore processed in the United States and the European Union. If you use the Service from elsewhere, you consent to your data being transferred to and processed in those regions, where privacy law may differ from the law of your country. Agencies subject to laws that require specific transfer safeguards for their clients’ data should contact us before relying on the Service for that data.
11. Security
In plain words: Encryption in transit and at rest, database-level tenant isolation, and passwords stored only as salted hashes. We hold no certifications of our own yet, and we say so instead of implying otherwise.
Data is encrypted in transit with TLS and encrypted at rest by the storage layer. Every agency’s data is isolated at the database layer with row-level security, verified by an automated cross-tenant test suite run before every release. Passwords are stored only as salted hashes by our authentication provider, never in readable form. Signing sessions produce tamper-evident audit trails, and completion certificates carry each document’s cryptographic fingerprint.
The database is backed up nightly, and backups are encrypted. Backups exist for disaster recovery, so the Service can be restored after an infrastructure failure; they are not an archive product, and they cycle out within 90 days.
If we confirm a breach of security that affects personal data we hold, we will notify the affected agency account owners without undue delay after confirmation, describe what we know (what happened, what data was involved, what we are doing), and keep them updated as we learn more, in addition to any notice the law requires us to give.
We do not hold a SOC 2 or ISO 27001 certification today; our infrastructure providers hold theirs for the layers they operate. The full picture, including what we do not have, is on the Security page. If you believe you have found a vulnerability, email security@clientatrium.com.
12. Retention, archive, and deletion
In plain words: Deleting inside the app archives first, so mistakes are recoverable. Real deletion happens on a verified request or account deletion, allowing for backup cycles and records the law makes us keep.
The Service is built on an archive-first design: destructive actions archive rather than erase, so a mistaken click cannot destroy the history of a client relationship. Archived data remains subject to this policy.
We keep data for as long as the account it belongs to is active. An agency admin can also erase a client workspace outright from its manage page: that destroys the messages, files and their stored bytes, projects, decisions, and invoices in a single operation, along with the sign-in identities of people who existed only in that workspace. It is immediate, it asks the admin to type the workspace name first, and it is recorded in the audit log. Erased data leaves backups as those cycle, within 90 days, since backups exist for disaster recovery. We may retain records the law requires us to keep, such as billing and tax records, for the required period.
One exception is worth stating plainly. Signed agreements and their audit trails are retained after erasure, because electronic-signature law expects executed records to persist and our legal-hold exception covers them. Where such records exist for a workspace, the workspace is emptied and kept as a record of those agreements, naming who signed and when, with all other content gone. Where nobody in a workspace ever signed anything, erasure removes the workspace completely.
For workspace content, the agency decides what to archive and what to request deletion of, because the agency is the controller of that content.
13. Export and portability
In plain words: Everything you store can leave with you, in formats you can read, on every plan.
Self-serve export is included on every plan, in readable formats: threads as transcripts, files in their folders, and signed documents as PDFs with their completion certificates, which remain verifiable on their own because each certificate carries the document’s cryptographic fingerprint.
After a subscription ends or an account is terminated, the Terms of Service provide a read-only window for export before any deletion.
14. Your rights
In plain words: Access, correction, deletion, a copy of your data, and objection, honored for everyone, not just where a statute forces us. Email us and a person will handle it.
You can request access to the personal data we hold about you, correction of inaccurate data, deletion, a copy of your data in a portable format, and objection to or restriction of certain processing. We honor these requests for everyone, wherever you live, because they are reasonable requests. We do not claim certification under any privacy framework; this policy describes what we actually do, and Section 10 describes how the data is protected.
If you are a California resident, this includes your rights under the CCPA to know what personal information we collect, to access and delete it, and to correct it. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of, and we will never treat you differently for exercising a right.
To exercise a right, email hello@clientatrium.com. We will verify your identity before acting, and we aim to respond within 30 days. If you are a client user of an agency, requests about your workspace data go through the agency as controller, as Section 3 describes, and we assist the agency in answering them.
15. Age
In plain words: The service is for working adults. It is not for children, and we do not knowingly collect their data.
The Service is offered for business use by people 18 and older. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us and we will delete it.
16. Changes to this policy
In plain words: If this policy changes in a way that matters, you hear about it 30 days before it takes effect, not after.
If we make a material change to this policy, we will notify agency account owners at least 30 days before it takes effect, by email, in-app notice, or both, and we will update the effective date at the top of this page. Non-material changes, such as clarifications, may take effect when posted with an updated effective date.
17. How to reach us
In plain words: Two email addresses, both read by a person.
Privacy questions and requests: hello@clientatrium.com. Security reports: security@clientatrium.com. Client Atrium is operated by RMH Websites, Ryan Huffman, United States.