Privacy Policy

Last updated: 9 May 2026

1. Controller

The controller responsible for the processing of your personal data within the meaning of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:

Aleksandar Mijić (sole proprietor / Einzelunternehmer)
Potsdamer Str. 102, 10785 Berlin, Germany
Email: privacy@atidon.com

2. Scope

This Policy describes how we process personal data when you visit our website, create an account, or use the ATIDON service (the "Service"). It supplements our Terms of Service.

3. Categories of personal data we process

  • Account data: name, business email, password hash, organisation, role.
  • Usage data: log data, pages visited, features used, device, browser, approximate location derived from IP.
  • Customer Data: data you upload to the Service, including contact and company information for prospects you wish to enrich or track.
  • Third-party data: publicly available business information about companies and individuals in professional roles, aggregated from public sources and licensed providers.
  • Communications data: messages you send to support, feedback, and survey responses.
  • Billing data (if applicable): name, billing address, VAT ID, payment-instrument metadata. Card numbers are handled by our payment processor; we do not store full card data.

4. Purposes and lawful bases (Art. 6 GDPR)

  • Providing the Service (account creation, authentication, core functionality): performance of a contract, Art. 6(1)(b).
  • Securing the Service (abuse prevention, fraud detection, logging): legitimate interests, Art. 6(1)(f).
  • Improving the Service (aggregate analytics, feature usage): legitimate interests, Art. 6(1)(f).
  • Marketing communications to existing customers about similar services: legitimate interests, Art. 6(1)(f) and §7(3) UWG; for non-customers, prior consent under Art. 6(1)(a) and §7(2) UWG.
  • Cookies and similar technologies beyond strictly necessary: consent, Art. 6(1)(a) GDPR and §25(1) TTDSG.
  • Compliance with legal obligations (tax, accounting, lawful requests): Art. 6(1)(c).

5. Customer Data and the controller / processor relationship

When you use the Service to process personal data of your own contacts (e.g. prospects in your CRM), you act as the controller of that data and we act as your processor under Art. 28 GDPR. Our Data Processing Addendum (DPA), including standard contractual clauses where applicable, is available on request from privacy@atidon.com. You are responsible for having a valid lawful basis before sending personal data to the Service.

6. Recipients and processors

We share personal data only with the following categories of recipients, each engaged under a written processing agreement where required:

  • Cloud-infrastructure and hosting providers (compute, storage, database).
  • Email and customer-communication providers (transactional email, support).
  • Product analytics, error monitoring, and logging providers.
  • Payment-processing providers (where you purchase a plan).
  • Data-enrichment and signal providers that supply third-party business information.
  • Professional advisors (lawyers, accountants, auditors) and authorities, where required by law.

A current list of subprocessors is available on request from privacy@atidon.com.

7. International transfers

Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision of the European Commission (e.g. the EU-U.S. Data Privacy Framework) or, where no adequacy decision applies, on Standard Contractual Clauses adopted by the European Commission together with supplementary technical and organisational measures.

8. Retention

  • Account data: for the lifetime of the account and for up to 90 days after closure to allow recovery and dispute handling.
  • Customer Data: while your account is active; available for export for 30 days after termination, then deleted, except where longer retention is required by law.
  • Security and access logs: typically 12 months, longer where required for incident investigation.
  • Billing and tax records: retained for the applicable statutory period under §147 AO (typically up to 10 years).

9. Your rights

Subject to the conditions in the GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21), including direct marketing. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise your rights, contact privacy@atidon.com. You also have the right to lodge a complaint with a supervisory authority, in particular the supervisory authority of your habitual residence or place of work. The competent supervisory authority for Aleksandar Mijić is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), datenschutz-berlin.de.

10. Cookies and similar technologies

We use cookies and similar technologies that are strictly necessary to provide the Service (e.g. authentication, security) on the basis of §25(2) TTDSG. Any non-essential cookies, including for analytics or marketing, are set only with your prior consent via our cookie banner, which you can change or withdraw at any time.

11. Automated decision-making

We do not use automated decision-making producing legal or similarly significant effects on you within the meaning of Art. 22 GDPR.

12. Children

The Service is intended for business users and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact privacy@atidon.com and we will delete it.

13. Security

We implement appropriate technical and organisational measures under Art. 32 GDPR to protect personal data, including encryption in transit, access controls, audit logging, and regular review of our security posture. No method of transmission or storage is entirely secure; we will notify affected users and authorities of personal-data breaches as required by Arts. 33 and 34 GDPR.

14. Changes to this Policy

We may update this Policy. For material changes we will give at least 30 days' notice in-app or by email before the changes take effect. The "Last updated" date at the top of this page reflects the latest revision.

15. Contact

Privacy enquiries: privacy@atidon.com. General support: support@atidon.com.

16. Attributions

Company logos displayed in the Service are provided by Logo.dev.

Logos provided by Logo.dev