IATTRA
On this page

IATTRA · Legal

Privacy Policy

This Policy explains, in plain language, what data IATTRA processes — including Google user data — why it is needed, and what choices you have.

Last updated October 5, 2026Related Terms of Service

1. Who is responsible for your data

IATTRA is a B2B platform to organise company information, find potential customers, create content, and run commercial communications. The public site is https://iattra.com. For privacy questions, write to hello@iattra.com.

Google user data: access, use, storage, and sharing

IATTRA accesses Google user data only when you use a Google feature.

If you sign in with Google, IATTRA requests:

  • openid — authenticate you and receive a Google account identifier
  • email — read your verified Google email
  • profile — read your name when Google provides it

Google Login does not request Gmail, contacts, calendar, or Drive. IATTRA stores the Google identifier, email, and name on your IATTRA account. We do not read your inbox through Google Login.

Connecting Gmail is optional. If you connect it so IATTRA can send campaigns you write from your address, IATTRA requests only:

IATTRA does not request gmail.readonly, gmail.modify, mail.google.com, contacts, calendar, or Drive, and cannot read your inbox, labels, or existing mail.

How we use Google user data:

  • Login data: create and sign you in to your IATTRA account, and show your name and email in the product.
  • Gmail data: identify the connected mailbox and send only the emails you ask IATTRA to send.
  • We do not sell Google user data or use it for advertising.

How we store Google user data:

  • Google identifier, email, and name with your IATTRA account.
  • An encrypted Gmail refresh token so the mailbox stays connected. Access tokens stay in memory for sending and are not saved.
  • Mailbox address and connection status so you can see and disconnect the mailbox.

How we share Google user data:

  • With Google, to sign you in and, if you connected Gmail, to send mail.
  • With the hosting and database that run IATTRA, only as needed to operate the service.
  • With campaign recipients, only the message you chose to send.
  • We do not transfer Google user data to other apps except to provide these features or when required by law.

IATTRA’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. https://developers.google.com/terms/api-services-user-data-policy

IATTRA staff may access Google user data only with your consent, to provide the feature you asked for, to investigate a security incident or abuse, or when required by law. Staff cannot read your Gmail inbox because the product cannot read it.

You can disconnect Gmail in IATTRA settings. You can also revoke access at https://myaccount.google.com/permissions. Questions: hello@iattra.com.

2. Data we collect

Depending on the features you use, we may process:

  • Account and access data, such as name, email, protected credentials, role, and session information.
  • Company and Discovery data, such as business description, audience, goals, market, and preferences.
  • Lead and search data, including criteria you provide and professional or business information from public sources and authorised integrations.
  • Content you create or send, such as campaigns, landing pages, knowledge files, agent instructions, and messages.
  • Integration data, such as your Google account identity, a connected mailbox, and the identifiers needed to keep the connection. Gmail permission is used to send, not to read your inbox.
  • Subscription and billing data, such as plan, subscription status, and Stripe identifiers. IATTRA does not store full payment card numbers.
  • Technical and usage data, such as IP address, browser, security logs, usage events, and preferences saved on the device.

We do not ask for sensitive personal data as a normal part of the service. Avoid putting that kind of information in free-text fields, files, or messages unless there is a legitimate need and proper authorisation.

3. How we obtain data

  • Directly from you, during sign-up, Discovery, product use, support, and connecting integrations.
  • From your organisation and people authorised to use the same workspace.
  • From services you choose to connect, such as Google, Gmail, and Stripe.
  • From public business sources, such as Google Places, when you run a customer search.
  • Automatically, through essential cookies, local storage, and logs needed for authentication, security, and operation of the service.

4. How we use data

We use data to:

  • Create and protect your account, authenticate access, and provide support.
  • Personalise the product from your company context and run the actions you request.
  • Search, organise, and display leads; create landing pages; operate agents; and send communications you authorise.
  • Process payments, administer plans, and apply the matching limits.
  • Prevent abuse, investigate faults, keep the service secure, and meet legal duties.
  • Generate AI-assisted features when you use a function that depends on them.

Where the LGPD applies, processing may rely, as the case requires, on performing the contract, a legal obligation, legitimate interest, or consent.

5. Leads and third-party data

Customer search can show publicly available business information. A company or contact appearing in results does not mean that person consented to messages from IATTRA or from your company.

You are responsible for checking that you have a lawful basis and authorisation to store, enrich, or use third-party data for prospecting. IATTRA remains responsible for the processing it performs to run the platform.

Google Places content is subject to the Google Maps Platform Terms (https://cloud.google.com/maps-platform/terms) and Google’s Privacy Policy (https://policies.google.com/privacy).

6. Who we share data with

We share only what is needed with suppliers that help run the service or when you choose an integration. They may include:

  • Railway and database or infrastructure providers, to host and deliver the platform.
  • Google, for login, Google Places, and Gmail send when you connect the account.
  • Resend and other communication providers, for transactional email and requested campaigns.
  • Stripe, for checkout, billing, and subscription management.
  • Cloudflare R2, to store landing-page images and other files.
  • OpenAI and ElevenLabs, only when you use an AI or voice feature that depends on them.
  • Public authorities, when there is a legal duty or a valid request.

IATTRA does not sell your personal data or your lead lists.

7. Cookies and local storage

We use essential cookies for authentication and security, plus local storage for language, interface preferences, and a basic visit count on landing pages. The product does not currently use advertising cookies or tracking pixels on public pages.

The basic visit count uses a random identifier and does not store visitor names, emails, IP addresses for that purpose.

If non-essential technologies are added later, this Policy and the consent controls will be updated first.

8. How long we keep data

We keep the data needed while the account or workspace is active. If the account is closed without a deletion request, access is turned off and data may remain available for recovery for up to 30 days before deletion or anonymisation from active systems.

When you ask for deletion, we remove or anonymise eligible data from active systems within 30 days. Backups are protected from ordinary use and expire in cycles of up to 90 days.

Access and security logs may be kept for at least 6 months when applicable law requires it. Tax, contract, billing, fraud-prevention, and legal-defence information is kept only for the legal periods or while needed for those purposes, then deleted or anonymised.

9. How we protect data

We use technical and organisational measures suited to the service, such as encryption in transit, access control, company isolation, credential protection, and security logs. No system is fully immune to incidents.

If an incident creates relevant risk, we will investigate and make the communications required by applicable law.

10. International transfers

IATTRA uses global suppliers, so data may be processed outside the country where you are. For those transfers we require adequate contractual, technical, and organisational measures and use the mechanisms allowed by applicable law.

11. Your rights and choices

You may request confirmation of processing, access, correction, information about sharing, portability where applicable, objection, anonymisation, blocking, or deletion in the cases provided by law. You may also withdraw consent without affecting earlier processing that was valid.

To make a request, write to hello@iattra.com. We may ask for extra information to confirm your identity. You may also complain to a competent authority, such as the ANPD in Brazil.

We will confirm and respond within the time limits required by applicable law. Where the LGPD applies, detailed access requests are answered within 15 days. Eligible deletion requests are completed in active systems within 30 days and then follow the up-to-90-day backup cycle.

12. Children

You must be at least 18 years old to create an account. IATTRA is a business service, is not directed at children, and does not intentionally collect children’s data to create platform accounts.

13. Changes to this Policy

We may update this Policy when the product, suppliers, or the law change. The date at the top of the page shows the current version. Material changes will be communicated in a reasonable way.

14. Contact

Privacy contact: IATTRA — hello@iattra.com

Privacy Policy: https://iattra.com/privacy

Terms of Service: https://iattra.com/terms