Privacy Policy
Last updated: 28 June 2026
Attaché Desk AI ("Attaché Desk", "we", "us", or "our"), a company incorporated in Dublin, Ireland, respects your privacy and is committed to protecting personal data processed in connection with the Attaché platform.
This Privacy Policy describes how we collect, use, share, and process personal data when you access or use our website at attachedesk.ai (the "Site"), the Attaché AI Desk platform, any associated desktop or browser application, add-ins (Word, Outlook, Google Docs), and any other digital service that links to this policy (together, the "Services"). It also covers personal data we process in offline contexts — for example, during demos, events, or sales conversations.
For details on how we use cookies and similar tracking technologies on our Site, see our Cookie Policy.
"Personal data" means any information that relates to an identified or identifiable individual.
1. Scope and Our Role
1.1 When we are data controller
This Privacy Policy applies when Attaché Desk acts as the data controller responsible for processing personal data of:
Visitors to and users of the Site and Services;
Customers and prospective customers and their representatives;
Attendees of Attaché Desk events, webinars, or demonstrations;
Subscribers to Attaché Desk communications and updates;
Suppliers, service providers, and business partners.
1.2 When we are data processor — Subscriber Content
This Privacy Policy does not apply to drafts, documents, dossier contents, talking points, cables, counterpart profiles, agreed-language corpora, or any other material that subscribers upload to or generate within the Services ("Subscriber Content"). Attaché Desk processes Subscriber Content as a data processor on behalf of our Subscribers (the data controllers), governed by the applicable Subscriber Agreement and Data Processing Agreement. Rights requests relating to personal data contained in Subscriber Content should be directed to the relevant Subscriber; where we receive such requests in our processor capacity, we will forward them accordingly.
1.3 Publicly available information about diplomatic actors
The Services incorporate publicly available source material — UN resolutions, OSCE decisions, EU Council conclusions, foreign ministry statements, think-tank analyses, and similar official or public records. Some of this material may contain personal data relating to public officials, diplomats, or other public figures acting in their professional capacity. We process such data only to the extent necessary to enable the platform's research, citation, and drafting functions, and only in connection with their public roles.
2. What Personal Data We Collect
Our principle is to collect only what is necessary to deliver, secure, and improve the Services.
2.1 Information you provide to us
Account information. When you or your organization creates an account, we collect your name, work email address, role or title, organization, language preferences, and account credentials. For mission or ministry accounts, we may also record your post, portfolio region, or team structure as configured by your administrator.
Billing and contract information. For paid plans and enterprise agreements, we collect billing contact details, billing address, and tax identifiers. Payment card data is handled directly by our payment processor and is never stored by Attaché Desk.
Communications. When you contact our team — whether for support, sales inquiries, security disclosures, or general questions — we record the content of those communications, your contact details, and any attachments. We may transcribe or record calls and meetings with prior notice, for quality and documentation purposes.
Demo and event information. When you register for a demo, webinar, or event, we collect the information you provide on registration forms.
Feedback and surveys. If you participate in satisfaction surveys, usability research, or submit a product review or testimonial, we collect the information you choose to share. Testimonials are published only with your explicit permission.
Social media. When you interact with our accounts on LinkedIn or X, we may receive the public profile information associated with those interactions.
2.2 Information we collect automatically
When you access or use the Services, the following is collected automatically:
Log and network data. Our servers record your IP address, browser type and version, operating system, pages and endpoints accessed, referrer and exit pages, time zone, and the date and time of each request.
Device information. We collect device type, OS name and version, browser version, and similar configuration data to ensure correct rendering and to diagnose issues.
Usage data. We observe how the Services are used: screens and features accessed, agents or workflows invoked, queries submitted, time spent, navigation paths, Protocol Score checks, export actions, and errors encountered. We do not collect or store the content of Subscriber Content (drafts, documents, dossier materials) for controller-level analytics purposes beyond what is required under the applicable Subscriber Agreement.
Cookies and tracking technologies. We use cookies and similar technologies on the Site as described in our Cookie Policy.
2.3 Information from third parties
We may receive information about you from data-enrichment and business-contact providers, security and fraud-prevention partners, marketing platforms, event organizers, or from Subscribers who provision accounts for users in their organization. We combine such data with information we already hold and use it as described in this Policy.
2.4 Aggregated and de-identified data
We may produce aggregated or de-identified data — such as feature adoption statistics or platform performance metrics — that cannot be linked back to any individual. Once properly anonymized, we may use, share, or publish such data for any lawful purpose without further notice.
3. How We Use Personal Data and Legal Bases
We use personal data to:
Provide, maintain, secure, and improve the Services;
Create and manage accounts, authenticate users, and support single sign-on;
Process payments and manage billing under Subscriber Agreements;
Respond to support requests and manage customer relationships;
Send service communications and, where permitted, marketing about Attaché Desk;
Analyse product performance and develop new features;
Detect, investigate, and respond to fraud, abuse, and security incidents;
Enforce our terms and acceptable use policies;
Comply with legal obligations and respond to lawful authority requests;
Establish, exercise, or defend legal claims.
The table below sets out the legal bases under the GDPR:
Purpose Legal basis (GDPR) Providing the Services under a Subscriber Agreement; account creation and authentication Art. 6(1)(b) — performance of a contract Support, customer relationship management, satisfaction surveys Art. 6(1)(f) — legitimate interest in a well-run service Security, fraud prevention, and abuse detection Art. 6(1)(f) — legitimate interest (shared with Subscribers) in a secure platform Product analytics and service improvement Art. 6(1)(f) — legitimate interest in improving the product Billing, metering, and usage-based fee reconciliation Art. 6(1)(b) and Art. 6(1)(f) Consent-based marketing communications and newsletters Art. 6(1)(a) — consent; unsubscribe available at any time B2B outreach to prospects Art. 6(1)(f) — legitimate interest in identifying potential customers, subject to opt-out Processing publicly available information about diplomatic actors in their public role Art. 6(1)(f) — legitimate interest; data processed only in connection with public role Compliance with tax, accounting, and other legal obligations Art. 6(1)(c) — legal obligation Bringing or defending legal claims Art. 6(1)(f) — legitimate interest
Where we rely on legitimate interests, we carry out a balancing assessment, document it, and ensure the processing is proportionate and does not override your rights and freedoms. You may object to legitimate-interest processing at any time — see Section 6.
4. Sharing of Personal Data
We do not sell personal data. We share it only in the following circumstances:
Within the Attaché Desk group. Personal data may be shared between Attaché Desk legal entities operating on shared infrastructure, subject to the same protections as described here.
AI model and infrastructure providers. The Services integrate APIs from model providers including Anthropic, Mistral, Google (Gemini), and Perplexity. Each API call is governed by contractual no-training terms. These providers process prompts and outputs as data processors on our behalf and may not use Subscriber Content to train their models. See our Security Policy for further detail.
Vendors and service providers. We rely on cloud infrastructure, identity, email, analytics, payment, support, and similar vendors who act as data processors under binding data processing agreements.
Collaboration within your organization. Features such as shared dossiers, clearance queues, and co-edited documents make certain actions visible to other authorized users within the same Subscriber account, by design.
Third-party integrations. If you connect Attaché Desk to an external service (Microsoft Word, Outlook, Google Docs, calendar providers), information is exchanged as needed for the integration. Once in the third party's systems, that party's own terms and privacy policy apply.
Business transactions. In the event of a financing, merger, acquisition, or sale of business or assets, personal data may be disclosed to counterparties during due diligence and transferred to a successor, consistent with this Privacy Policy.
Legal and safety disclosures. We may disclose personal data where required by law, court order, or a binding governmental request, or where necessary to protect the rights, property, or safety of Attaché Desk, our users, or others.
5. International Data Transfers
Attaché Desk stores and primarily processes customer data in the European Union. All Subscriber Content is hosted in EU data centres. Tenant isolation is enforced at the database level via row-level security.
Some of our vendors and model providers operate outside the EEA. Where personal data is transferred outside the EEA, we put appropriate safeguards in place, which may include:
European Commission adequacy decisions covering the recipient country;
Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional technical and organizational measures;
Participation in approved transfer frameworks such as the EU–US Data Privacy Framework where the recipient is certified;
Article 49 GDPR derogations in limited circumstances.
6. Your Rights
Under the GDPR and applicable data protection law, you have the following rights:
Right to information and access. You may ask whether we hold personal data about you and request a copy, together with information on its source, recipients, purposes, and retention periods.
Right to rectification. You may ask us to correct inaccurate or incomplete personal data.
Right to erasure. You may ask us to delete personal data about you where we no longer need it for the purpose it was collected, or where you have withdrawn consent on which processing was based, subject to our legal retention obligations.
Right to restriction. You may ask us to pause processing in specific circumstances — for example, while we verify accuracy or evaluate an objection.
Right to object. You may object to processing based on legitimate interests, on grounds relating to your specific situation. You may also opt out of direct marketing at any time, without giving reasons.
Right to data portability. Where processing is based on consent or contract and is carried out by automated means, you may request your data in a structured, machine-readable format.
Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Right to lodge a complaint. If you believe we have mishandled your personal data, you have the right to lodge a complaint with the Irish Data Protection Commission (our lead supervisory authority) or the supervisory authority in your country of residence.
To exercise any of these rights, please contact us at privacy@attachedesk.ai. We may ask you to verify your identity before processing your request.
7. How We Keep Your Data Safe
We implement appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. For full details of our security program, please see our Security Policy.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described above:
Subscriber users: Data is deleted or returned in accordance with the applicable Subscriber Agreement, typically within 30 days of termination.
Legally required retention: Data subject to tax, accounting, or anti-money-laundering obligations is retained for the periods mandated by applicable law (generally 7 years under Irish and EU law).
Other data: Retained only as long as necessary for the original purpose, or as required to protect our legal rights.
Append-only audit logs are retained for a minimum of 12 months and up to 7 years for compliance purposes, depending on account type.
When we no longer need personal data, we delete or anonymize it in accordance with our retention schedule. Where immediate deletion is not possible (e.g., data in backup archives), we securely isolate it from further processing pending deletion.
9. Updates to This Policy
We may update this Privacy Policy to reflect changes in our Services, practices, or applicable law. We will update the "Last updated" date above and, for material changes, notify you through the Services, by email, or another appropriate channel. Continued use of the Services after an update constitutes acceptance of the revised Policy to the extent permitted by law.
10. Contact Us
Data controller:
Attaché Desk Ltd
Dublin, Ireland
European Union
Privacy enquiries: privacy@attachedesk.ai
DPA requests: legal@attachedesk.ai
For urgent security matters, see our Security Policy.