Privacy and data protection
Privacy policy
This policy explains how the Attenva closed B2B beta handles public inquiries, optional product updates, account data and connected Gmail and Microsoft mailbox data.
- Effective:
- 14 July 2026
- Version:
- 1.3
1. Who operates Attenva
Attenva is a product and brand operated by Bearpoints Mikołaj Bednarek, Polish tax identification number (NIP) 5212136333 (the “Operator”, “Bearpoints”, “we” or “us”). Contact us at kontakt@attenva.online.
For account administration, service security and direct business contact, the Operator acts as the data controller. For mailbox content processed on the instructions of an invited business customer, that customer will generally act as controller and the Operator as processor. This closed beta does not replace any data-processing agreement required by the customer’s organisation before broader or commercial use.
2. Scope and service stage
Attenva is currently an invite-only, free B2B beta for organisations and business users in the European Union. Public self-registration and paid plans are not active. Optional AI-assisted categorisation is technically available only after the workspace gives a separate, explicit authorisation and the Operator enables the service.
3. Data we process
Account and workspace data
- name, business email address, workspace name and internal identifiers;
- password hash, authentication and multi-factor authentication state, recovery and session security metadata;
- support correspondence and records of privacy or security requests.
Mailbox connection data
- mailbox address, provider, connection status and safe server settings;
- encrypted OAuth access and refresh tokens or encrypted IMAP credentials;
- synchronisation cursors, timestamps, safe error categories and operational audit records.
Imported mail data
- sender and recipient names and addresses, subject, dates, folder or provider labels;
- message preview and content, raw message representation and attachment-related data when present;
- internal categories and user decisions made in the workspace.
Technical data
- essential session and anti-forgery cookies;
- bounded security, availability and diagnostic logs without message bodies, credentials or OAuth tokens;
- aggregated operational metrics that do not use email addresses or message content as labels.
Public beta inquiries and Attenva updates
- the email address, subject and message submitted through the public beta form;
- whether Attenva updates were requested, the consent-statement version and request, confirmation or withdrawal timestamps;
- a one-way email digest used to prevent duplicate active subscriptions and a short-lived hashed confirmation token.
4. Why and on what basis we process data
- Providing the beta service and taking pre-contractual steps: creating the workspace, connecting authorised mailboxes, importing changes and displaying the review workspace.
- Legitimate interests: securing Attenva, preventing abuse, diagnosing failures, maintaining service continuity and improving the user-facing beta without using mail for unrelated purposes.
- Legal obligations and legal claims: responding to lawful requests, protecting rights and keeping records where required by applicable law.
- Taking steps at your request and legitimate interests: receiving and answering a public beta inquiry, protecting the form from abuse and maintaining a bounded business-contact history.
- Optional consent: sending email updates about Attenva and its beta after the submitted address is confirmed. Sending an inquiry does not depend on this consent. Google and Microsoft OAuth authorisation controls mailbox API access but is not used to expand the purposes described in this policy.
5. Mailbox providers and Google Limited Use
Attenva supports read-only mailbox ingestion through Gmail and, during the controlled beta and provider acceptance stage, delegated Microsoft Graph access for Outlook.com and Microsoft 365. Microsoft access uses delegated Mail.Read; Attenva does not request application permissions, Mail.Send or Mail.ReadWrite. Revoking provider consent or disconnecting the mailbox stops future access and starts the documented deletion workflow.
Attenva requests only https://www.googleapis.com/auth/gmail.readonly in the current Gmail integration. After the user explicitly authorises access, we use it to identify the authorised Gmail mailbox, retrieve message changes, import messages and display mailbox content and metadata in that user’s Attenva workspace.
This permission does not allow Attenva to send messages, change labels, modify mailbox settings or delete Gmail messages. Background checks use Gmail History ID so that later synchronisation is incremental. Attenva may store imported Google data on its backend infrastructure to provide the visible workspace features requested by the user.
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. In particular, Google user data is not sold, used for advertising, credit scoring or surveillance, or used to train a shared AI model. It is not transferred to third parties except where necessary to provide the user-facing service with appropriate permission, for security, to comply with law, or as otherwise allowed by that policy.
Where a workspace separately authorises AI message analysis, Attenva may send the sender, subject and a bounded portion of relevant message text to Microsoft Azure OpenAI solely to categorise the message, explain the decision and suggest a next action. During the closed beta and MVP, processing is routed through Azure OpenAI EU Data Zone deployments, provider-side response storage is disabled, and API data is not used for model training by default. Attenva records content-free token, cost and reliability metadata; detailed analysis stored by Attenva is encrypted. The workspace can withdraw authorisation, after which new external analysis stops.
6. Human access to mailbox content
Operator access is restricted to what is necessary to operate and secure the service. A human may access mailbox content only when an authorised customer requests support and such access is necessary, to investigate a security incident or abuse, to protect the service and users, or where required by law. Access must not be used for advertising, curiosity, unrelated analytics or model training.
7. Recipients and infrastructure
Attenva currently uses restricted backend infrastructure hosted with cyber_Folks and interacts with the mailbox provider selected by the user, including Google for Gmail OAuth and Gmail API access and Microsoft for delegated Graph mailbox access. Microsoft processes the bounded message data described above through Azure OpenAI only after separate workspace authorisation. Stripe-hosted pages may later process billing and tax information when paid plans are explicitly opened; Attenva does not receive card details. Essential certificate, DNS and email-delivery providers may process limited connection, confirmation or correspondence data on Attenva's instructions. PostgreSQL, object storage, queues and operational telemetry used by the lab are private backend services and are not exposed directly to the public internet.
We do not use advertising networks or third-party behavioural analytics. Before appointing a new processor that will handle mailbox content, we will assess the provider, contractual safeguards and international-transfer implications and update the relevant documentation.
8. Security
We use HTTPS in transit, tenant and mailbox ownership checks, backend-only provider credentials, application-layer encryption of imported message content and stored mailbox credentials, tenant-scoped encryption keys, multi-factor authentication controls, private data services, restricted operational telemetry and controlled deletion and restore procedures. No system is completely secure, and this policy does not promise absolute protection.
9. Retention
- Each customer chooses whether Attenva keeps 3, 7, 14 or 30 days of message history; the default is 7 days. Messages outside that period, their stored content and message-level analysis are permanently removed from active PostgreSQL and object storage. This setting does not delete or modify the source mailbox.
- Attenva may retain only tenant-isolated aggregate AI preference counts after a message is removed, such as positive or negative feedback totals and category-correction counts. This preference profile contains no message text, subject, sender, mailbox address or message identifier and is not shared between customers.
- Disconnecting a mailbox immediately revokes or disables Attenva’s provider access, stops future collection and triggers deletion of imported message content for that mailbox from active PostgreSQL and object storage. Minimal security/audit tombstones may remain without message content.
- Reconnect is treated as a new connection and performs the standard bounded initial import, currently limited to the latest 30 days and the applicable provider message limit.
- Verified deletion requests are handled without undue delay. We respond in principle within one month and remove data from active systems where the right applies.
- Residual protected backup copies may remain until backup rotation completes, for no longer than 90 days, including where needed to investigate a claim or restore service integrity. They are not restored to ordinary use and must be reconciled with completed deletion requests if a disaster recovery restore occurs.
- Public beta inquiries are encrypted and retained for up to 12 months so Attenva can answer and manage the beta relationship.
- An unconfirmed Attenva updates request is removed after 30 days. A confirmed subscription remains active until consent is withdrawn. Minimal withdrawal evidence is retained for up to three years, then removed.
- Limited security and legal records may be retained for as long as necessary to establish, exercise or defend legal claims or meet a legal obligation.
10. Cookies
Attenva uses only cookies and equivalent storage necessary for authenticated sessions, multi-factor assurance and request-forgery protection. The current beta does not use advertising or cross-site tracking cookies.
11. Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability or objection and may withdraw consent where consent is the basis. Send requests from the account email address to kontakt@attenva.online. We may request proportionate information to verify identity and mailbox authority.
To withdraw consent for Attenva email updates, send a message to kontakt@attenva.online from the subscribed address. We use that matching sender address to verify the request and record the withdrawal. We do not sell subscribed addresses or disclose them to another controller for its own marketing purposes.
You may lodge a complaint with the competent supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). If a business customer controls mailbox data, requests concerning that content may need to be coordinated with that customer.
12. Disconnecting mailbox providers and deleting data
Detailed instructions are available on the Data deletion and provider access page. Removing access only in a Google or Microsoft account stops future API access but does not notify Attenva to delete an already imported copy. Use Attenva's mailbox Disconnect action as well, or contact the Operator if product access is unavailable.
13. Changes to this policy
We will update the effective date and version when this policy changes. If a change materially expands how mailbox or Google user data is used, we will provide prominent notice and obtain renewed consent where required before applying the new purpose.
14. Change history
- Version 1.3 — 14 July 2026: added Microsoft delegated read-only access and the separate public beta inquiry and optional Attenva updates purposes, consent evidence, withdrawal and retention rules.
- Version 1.2 — 13 July 2026: added customer-controlled 3–30 day hard message retention and clarified the content-free, tenant-isolated AI preference memory retained after message deletion.
- Version 1.1 — 11 July 2026: added the separately authorised OpenAI analysis boundary and future Stripe-hosted billing boundary.
- Version 1.0 — 10 July 2026: first closed-beta privacy policy, including Gmail read-only, retention, deletion and inactive-AI disclosures.