1. Who operates Atrium
Atrium is operated by Tarrosa Software Development Services, a Philippine sole proprietorship. In this policy, "Atrium," "we," "us," and "our" refer to that business.
Our registered business address is Odevilas Subdivision, Mohon II, Tisa, Cebu City, Philippines. Privacy questions and requests may be sent to hello@atriumos.co.
2. Our privacy roles
We act as a personal information controller when we decide why and how to process information about website visitors, demo contacts, account holders, support contacts, service security, and our own business relationships.
Customer organizations generally decide why estate, resident, owner, vendor, employee, visitor, financial, and operational records are entered into their workspaces. For that information, the customer organization generally acts as the personal information controller and we act as its personal information processor. The actual role of each party depends on the facts and applicable law.
3. Information we process
Depending on the features used, Atrium may process:
- names, email addresses, profile details, invitations, roles, and account settings;
- organization, estate, unit, lot, address, membership, and contact information;
- resident, owner, vendor, visitor, employee, and authorized-representative records;
- budgets, assessments, balances, payments, receipts, ledger entries, forecasts, and utility records;
- contracts, purchase records, work orders, communications, documents, images, and uploaded files;
- demo requests, support messages, feedback, and other communications with us;
- session, IP address, access, audit, browser, device, diagnostic, and security information; and
- information received through optional authentication, map, weather, email, storage, or other integrations.
Customer organizations and their authorized users choose what workspace data to enter. They should collect and submit only information they are authorized to use.
4. Where information comes from
We receive information directly from you, from an organization that invites or administers you, from authorized users who enter or import records, from files and messages submitted through the service, from your use of Atrium, from configured service providers, and from lawful third-party or public sources.
5. Purposes and lawful grounds
We process personal data when necessary to:
- provide, administer, support, and secure Atrium and customer workspaces;
- authenticate users, enforce tenant and role boundaries, and prevent misuse;
- maintain financial and operational records, calculations, communications, documents, exports, and audit trails requested by authorized users;
- respond to demo requests, inquiries, support needs, and service notices;
- monitor reliability, diagnose faults, maintain backups, and improve service performance;
- comply with law, lawful requests, accounting duties, and the establishment, exercise, or defense of legal claims; and
- protect our users, customers, business, and the public from fraud, abuse, or security threats.
Our lawful grounds depend on the context and may include your consent, steps related to or necessary for a contract, compliance with legal obligations, and legitimate interests that do not override your fundamental rights and freedoms. Where a customer controls workspace data, that customer is responsible for its lawful ground and instructions to us.
6. How we process information
Atrium may collect, record, organize, store, update, retrieve, calculate, display, transmit, export, back up, restrict, delete, or otherwise use information to provide the configured service. Authorized users may generate reports and communications or send records to recipients they select.
Atrium does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals. Product calculations and operational indicators remain subject to review by authorized users.
8. International processing
Some technology providers may store or process information outside the Philippines. Where personal data is transferred, we remain accountable for processing under our control and use contractual, security, and other appropriate safeguards required by applicable law. Customers are responsible for transfers they independently direct.
9. Retention and deletion
We keep personal data while the relevant workspace, account, request, or business relationship is active and afterward only as reasonably necessary for service closure, backup rotation, security, dispute resolution, accounting, legal duties, and legitimate business records. Retention depends on the record type, customer instructions, legal requirements, risk, and whether the information can be deleted or anonymized.
When information is no longer required, we delete, anonymize, or securely dispose of it. Backup copies may remain until the applicable backup cycle completes. A customer organization may have its own retention duties and may need to address a workspace-data request before we can act on it.
10. Security
We use reasonable organizational, physical, and technical safeguards appropriate to the nature of the information and the risks involved. These include access controls, role boundaries, authentication protections, audit records, backup procedures, and safeguards used by our hosting and storage providers. No system can guarantee absolute security, so users must also protect credentials and promptly report suspected misuse.
12. Data-subject rights
Subject to the Data Privacy Act of 2012 and lawful limitations, you may have the right to be informed, object, access, rectify, erase or block personal data, obtain data portability where applicable, claim damages, and lodge a complaint with the National Privacy Commission.
Send a request to hello@atriumos.co. We may verify your identity and authority before acting. If a customer organization controls the requested workspace data, we may direct the request to that organization or assist it in responding. We may retain or restrict information where law permits or requires it. You may also contact the National Privacy Commission through its official website at privacy.gov.ph.
13. Children
Atrium is a business service for authorized organizations and is not directed to children as account holders. A customer organization that enters information about a minor is responsible for having lawful authority and providing any required notice or consent. Contact us if you believe information was submitted without proper authority.
14. Third-party services and links
Atrium may connect to or link to third-party services. Their operators control their own processing and publish separate terms and privacy notices. We encourage users and customer administrators to review those notices before enabling optional services.
15. Changes and contact
We may update this policy to reflect service, legal, or operational changes. We will update the effective date and use reasonable means to notify affected users of material changes before they take effect where appropriate.
This Privacy Policy is governed by the laws of the Republic of the Philippines and does not waive rights available to you under any other applicable law.
Your acknowledgement of this Privacy Policy confirms receipt of this notice; it is not blanket consent. Where consent is required, we request it separately.
Questions and requests may be sent to hello@atriumos.co or by mail to Tarrosa Software Development Services, Odevilas Subdivision, Mohon II, Tisa, Cebu City, Philippines. See our Terms of Service for the conditions governing use of Atrium.