Last updated: 3 July 2026)}
This policy explains what personal data Atsus ("we", "us") collects about you, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. By using Atsus you confirm you have read this policy.
When you sign up as the owner of a crew (the "boss" role), you are the data controller for the customer information, job records, and team member information you add. Atsus is your data processor for that data — we store and process it on your behalf under a Data Processing Agreement, the terms of which are these.
For data we collect to run the service itself (your name, email, login records, device info), Atsus is the controller.
Account data: name, email address, phone number (optional), password (stored as a one-way hash, never readable by us), profile picture colour, role (boss or crew member), and the date you joined.
Job data: job titles, customer names and contact details you enter, site addresses, photos you take, time entries, materials used, signatures captured, notes, GPS coordinates when you tap "Start job" (only at that moment — we do not track your location otherwise).
Technical data: device type, operating system version, app version, IP address (for security and abuse prevention), crash reports (when the app errors).
Push notification tokens if you opt in to notifications.
We process your data on these legal bases under Article 6 GDPR:
• Contract (Art 6(1)(b)): to provide the service you signed up for — showing your jobs, calculating hours, surfacing job history, syncing across your devices.
• Legitimate interests (Art 6(1)(f)): security, abuse prevention, fixing crashes, improving the service.
• Consent (Art 6(1)(a)): push notifications, camera access, location access — you can withdraw consent at any time in your device settings or in-app.
• Legal obligation (Art 6(1)(c)): to respond to lawful requests from authorities.
When you add a customer (their name, phone, address, signature) you are the controller of that data. Under GDPR you must:
• Have a lawful basis for collecting it (usually contract — they hired you to do the work).
• Tell the customer their data will be stored in Atsus.
• Honour any access, correction, or deletion request they make.
Atsus provides tools to support this: every customer record can be edited or deleted from the customer detail screen, and the boss can export the full record for a Subject Access Request.
Atsus is hosted on Google Cloud Platform (Firebase). Data is stored in the europe-west1 region (Belgium) by default. Photos are stored in Cloud Storage with bucket-scoped, org-scoped, role-scoped access rules — only signed-in members of your organisation can read them.
Backups are retained on encrypted Google Cloud storage for up to 30 days.
If you are based outside the European Economic Area, your data may transit through Google's global infrastructure, but the data at rest stays in the EU. Google uses Standard Contractual Clauses approved by the European Commission for any incidental transfers.
• Members of your organisation only. Job photos, time entries, customer details, and time-off requests are visible only to crew members and the boss of the same organisation.
• Atsus staff: we will access your data only to investigate a support request you raise, or to comply with a lawful order. We log every such access internally.
• Sub-processors: Google (hosting, push notifications), Apple (Sign in with Apple), and Stripe (payment processing for paid subscriptions). A full list and copies of the relevant Data Processing Agreements are available on request.
We do not sell, rent, share or use your data for advertising, ever.
• Active account data: kept while your account is active.
• Closed account: personal data deleted within 30 days. Anonymised job statistics may be retained for service analytics.
• Backups: rotated out within 30 days after deletion.
• Financial / tax records (when applicable): 7 years, per Irish Revenue requirements.
You have the right to:
• Access your data — request a copy from Profile → Account → Export.
• Rectify incorrect data — edit it directly in the app, or email us.
• Erase your data — delete your account from Profile → Account → Delete account. The deletion is immediate and irreversible.
• Restrict processing — email us to pause processing while we investigate any complaint.
• Data portability — export approved jobs as CSV from Profile → Export approved jobs.
• Object to processing based on legitimate interests.
• Withdraw consent for camera, location, or notifications at any time.
• Lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.
Atsus is intended for adults working in trades and businesses. We do not knowingly collect data from anyone under 16. If you become aware that a child has provided personal data, contact us and we will delete it.
Atsus uses only essential storage to keep you signed in and remember your settings. We do not use third-party advertising cookies, fingerprinting, or cross-site tracking. The PWA caches assets in your browser for offline use; clear them anytime from your browser or device settings.
Data is encrypted in transit (HTTPS / TLS 1.3) and at rest (AES-256 on Google Cloud). Passwords are hashed with industry-standard algorithms. Access control rules in the database ensure each organisation can only read its own data. If a breach occurs that risks your rights and freedoms, we will notify you and the Data Protection Commission within 72 hours.
If we change this policy materially, we will show an in-app banner at least 14 days before the new policy applies. Continued use after that date is treated as acceptance.
Data protection enquiries, access requests, complaints: support@atsus.app
General questions: support@atsus.app