Privacy Policy

Last updated: 26 August 2026

Attentico remembers birthdays and helps you send a personal card. To do that, we process data about you — and about the people you care about. This page explains exactly what we collect, what we do with it, and what we emphatically don't do: no selling of data, no ad profiles, no tracking.

1. Who is responsible

Attentico is a service of Studio Northstar B.V. in The Hague, the data controller for the data you entrust to us. Send privacy questions to hello@attentico.nl — we read every message ourselves.

2. What data we process

We only process what the service needs to work:

  • Account data: your name and email address, plus a password (stored as an encrypted hash) or your Google sign-in
  • Contacts: names, birthdays and whatever you add yourself, such as an address or personal notes
  • Cards: the cards you create and send, including the message and the delivery address
  • Payment data: payments run through Mollie — we never see or store account or card numbers
  • AI texts: the card messages the AI suggests, so you can edit and approve them
  • Imported contacts (optional): if you use the import from Google Contacts or Outlook, we take over name, email address, phone number and birthday — and, if present in your address book, address, job title, company and notes
  • Session data: functional cookies that keep you signed in — no tracking

Some of this data concerns people who don't have an Attentico account themselves: your contacts, and the people who receive your cards. We get that data exclusively from you — you enter it yourself or import it from Google Contacts or Outlook. We don't collect it anywhere else, we don't buy it, and we don't approach these people. As a contact you have the same rights as a user; see chapter 9.

3. Importing contacts from Google or Outlook

The import does one thing: it puts your contacts into your own Attentico account, so you don't have to retype birthdays. For Google we request the read-only scope contacts.readonly; for Microsoft (Outlook) the comparable scope Contacts.Read. So we can read your address book, but never change or delete anything.

  • We use imported data exclusively to create contacts in your account.
  • The access token only exists during the import itself; we don't store it.
  • The temporary import overview is deleted the moment you confirm the import.
  • We never use your Google or Microsoft data for advertising, profiling or resale, and we don't pass it on to AI models or analytics tools.
  • Nobody looks into your imported data, unless you ask us to (for example with a support question), it's needed for security research, or the law requires it.
  • You can delete imported contacts at any time, right in the app.
  • You can always revoke access, via myaccount.google.com/permissions or account.microsoft.com.

Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

“Attentico’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.”

4. How we protect your data

We take appropriate technical and organisational measures. Connections and storage are encrypted, the database isolates data per user, admin access requires two-step verification, and sensitive actions are recorded in a tamper-proof log. Security researchers can report vulnerabilities via security.txt on this site.

If something goes wrong despite all this, we report a data breach to the Dutch Data Protection Authority within 72 hours where the law requires it. If you are at risk yourself, you'll hear it from us directly.

5. Our legal bases (GDPR art. 6)

  • Performance of a contract (art. 6(1)(b)): your account, contacts, cards and payments — without this data we can't provide the service.
  • Consent (art. 6(1)(a)): the contact import from Google or Outlook only starts after you approve it yourself, and you can withdraw that consent at any time.
  • Legitimate interest (art. 6(1)(f)): security, fraud prevention and improving the service.

6. Who else works with your data

A small number of services work on our behalf and under our instructions (processors):

ProcessorPurposeLocation
SupabaseDatabase & sign-inEurope
VercelHosting of website and appEU / US*
Anthropic (Claude)Writes card messages at your request; input is retained for at most 30 days and never used to train AI modelsUS*
OpenAI (GPT)Writes card messages and performs other AI tasks at your request; API input is retained for at most 30 days for abuse monitoring and never used to train AI modelsUS*
Microsoft Azure Communication ServicesSending emailEurope
Print.onePrinting and postal delivery of physical cardsNL
CloudflareBot protection on sign-in and sign-up (Turnstile)EU / US*
Google MapsAddress suggestions while you type a delivery addressEU / US*
Your browser's push service (Google, Mozilla or Apple)Notifications you switched on yourselfEU / US*

* Transfers outside the EU are based on the European Commission's Standard Contractual Clauses (SCCs).

In addition, some parties process your data under their own responsibility and privacy policy:

  • Mollie handles your payment as an independent, regulated payment institution — see mollie.com/en/privacy.
  • Google and Microsoft are the source when you import contacts; what they retain themselves is covered by their own policies.

If we engage a new processor, we update this list before any data goes their way.

7. How long we keep data

  • Your account and everything in it: for as long as your account exists. Delete it and nearly everything is erased immediately and permanently — no waiting period, no archive copy. Two things stay on for a while, with no link to you: the security log we have to keep (24 months) and the AI logs below.
  • Import files from Google or Outlook: deleted as soon as you confirm the import. If you cancel, the import session expires after 30 minutes and is erased for good at the next cleanup.
  • Cards and delivery addresses: kept in your card history for as long as your account exists, so you can look back at what you sent. You can delete them yourself.
  • Payment data: the transaction lives with Mollie, which as a payment institution has its own statutory retention periods.
  • AI logs: we keep technical logs of AI calls for cost monitoring and abuse detection. Personal details are redacted before storage, and deleting your account removes the link to you.

8. Cookies

Attentico only uses cookies and local storage that the service needs to work: signing in, your language, your display preferences. No analytics cookies, no marketing cookies, no tracking — which is why we don't ask for cookie consent either. See the full list in the cookie policy.

9. Your rights (GDPR)

You have the following rights regarding your personal data:

  • Access (art. 15): request what data we hold about you
  • Rectification (art. 16): have incorrect data corrected
  • Erasure (art. 17): delete your account and nearly all associated data immediately and permanently — yourself, via Security in the app; §7 lists what stays on for a while
  • Restriction (art. 18): temporarily restrict processing
  • Portability (art. 20): download all your data as a machine-readable JSON file, via Security in the app
  • Objection (art. 21): object to processing based on legitimate interest
  • Withdraw consent: for the contact import, via myaccount.google.com/permissions or account.microsoft.com

Automated decision-making (art. 22): Attentico makes no decisions with legal or similarly significant effect based solely on automated processing. AI suggests card messages; you approve every send yourself before anything goes out the door.

For the other rights, email hello@attentico.nl. We respond within a month.

10. Business use

If an organisation uses Attentico for its employees, Attentico acts as a processor within the meaning of the GDPR. The accompanying data processing agreement is published at attentico.nl/dpa and forms part of the terms for business use.

11. Filing a complaint

If you disagree with how we handle your data, we'd like to hear it from you first. You also always have the right to lodge a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl.

12. Changes

We may update this privacy policy. For significant changes we will email you; the date at the top shows when it was last updated.

13. Contact

hello@attentico.nl