PublicViews

Data processing agreement

You are the controller. We are the processor. This draft sets out what that means in practice: what we process, on whose instructions, how it is protected, who else can reach it, and how it is deleted.

Description
Categories of data subjectThe people represented in the records a publisher publishes, typically their clients, contacts, partners, investors or candidates. Plus the people a publisher sends a link to.
Types of personal dataWhatever attributes the publisher includes: names, email addresses, phone numbers, job titles, company affiliations, locations, and any other attribute switched on or used to sort, group, label a linked record, or decide which viewer sees which rows. Plus the email address a viewer gives to a view gated by email, confirmed from their inbox or not as the publisher chooses; the values a viewer submits as edits and the values those replace; hashed IP addresses; and visit events.
Special category dataNot requested, not required, and not detected. A publisher who publishes it does so on their own assessment. Nothing in the product is designed around it.
Nature and purposeCaching a defined projection of Attio records; rendering them on a view the publisher configured; enforcing the publisher's access policy; receiving edits from viewers and writing them back to Attio — held for the publisher's approval by default, or applied without it on a view the publisher has configured that way; recording access and changes in an audit trail.
DurationFor as long as the publisher keeps the relevant view published, and no longer than the retention periods in section 8.
FrequencyContinuous while a view is published. Records are re-read from Attio on the schedule the publisher's plan sets.