Attribute
Log in

Privacy Policy

Effective Date: August 3, 2026
Last Updated: August 30, 2026

This Privacy Policy explains how Ultimate, Inc., which offers the Services under the Attribute brand (“Attribute,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects Personal Information in connection with the Services. The “Services” include our websites, applications, personal intelligence and self-discovery services, business and enterprise resource planning services, AI-assisted functionality, document-processing features, APIs, integrations, automation tools, support, and related offerings.

This Privacy Policy applies when Attribute determines the purposes and means of processing Personal Information. It also explains our role when we process information for an enterprise customer. It does not replace a customer’s own privacy notice or the terms of a separate written agreement between Attribute and that customer.

Important notice for enterprise and ERP users When an organization uses Attribute ERP or another enterprise service and submits information about its customers, applicants, vendors, employees, contractors, or other individuals, that organization generally controls why the information is processed. Attribute generally processes that Customer Data as a processor or service provider on the organization’s documented instructions. Individuals should direct privacy requests concerning that Customer Data to the organization that collected or submitted it. Attribute will assist the organization as required by contract and applicable law.

1. Scope, roles, and definitions

1.1 When this Privacy Policy applies

This Privacy Policy applies to Personal Information we process through the Services; when you visit or communicate with us; when you create, administer, or use an Attribute account; when you use AI, document, ERP, API, or integration features; and when you otherwise interact with Attribute in a context where we determine how and why Personal Information is processed.

1.2 Attribute as a business or controller

Attribute acts as a “business,” “controller,” or similar responsible organization under applicable privacy law when we determine the purposes and means of processing. Examples include account registration, authentication, billing, direct support, website operations, service security, legal compliance, and direct-to-user Attribute services.

1.3 Attribute as a service provider or processor

To the extent Attribute processes Personal Information contained in Customer Data solely on behalf of an enterprise customer, Attribute acts as the customer’s “service provider,” “contractor,” “processor,” or equivalent. The enterprise customer is responsible for its collection and use of the information, the notices and choices it provides, the lawfulness of its instructions, and the permissions it grants to its users, agents, integrations, and service providers. Our Data Processing Addendum and the applicable enterprise agreement govern that processing.

1.4 Key terms

“Customer” means an organization that enters into an agreement for enterprise Services or administers an organizational workspace.

“Authorized User” means an individual permitted by a Customer to access or use enterprise Services.

“Customer Data” means data, content, records, documents, instructions, and other information submitted to, stored in, transmitted through, generated for, or made available to the Services by or for a Customer, including through integrations.

“User Content” means information, files, conversations, prompts, responses, memories, preferences, assessments, and other content a direct user provides to or generates through the Services outside an enterprise Customer relationship.

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. It does not include information excluded from applicable privacy-law definitions, such as properly deidentified or aggregated information.

“AI Providers” means third parties that develop, provide, host, route, broker, or operate machine-learning or artificial-intelligence capabilities used by an Attribute feature, including direct model APIs, cloud AI platforms, multi-provider routing services, document-analysis, transcription, embedding, classification, generation, and similar services. Depending on who selects and controls the connection, an AI Provider may be an Attribute service provider or subprocessor, or a recipient selected by a Customer or user.

1.5 Services outside this policy

This Privacy Policy does not govern third-party products, websites, platforms, or services that are not controlled by Attribute, even when they connect to or are linked from the Services. An enterprise customer may also provide a separate privacy notice that governs its own collection and use of information. Employment applicant and workforce information collected directly by Attribute may be covered by a separate notice where required.

2. Our privacy commitments

Attribute is designed to support both deeply personal use and complex business operations. Our privacy commitments apply across those contexts, subject to the role distinctions described above.

We do not sell Personal Information. Attribute does not exchange Personal Information for monetary or other valuable consideration in a manner treated as a “sale” under applicable comprehensive privacy laws.

We do not use Personal Information for cross-context behavioral advertising. We do not “share” Personal Information for cross-context behavioral advertising or use Enterprise Customer Data for third-party advertising.

We do not silently train generalized AI models on your content. We do not use Customer Data or User Content to train generalized AI models for Attribute or third parties unless the applicable Customer or direct user provides separate, affirmative authorization through a clear opt-in or written agreement.

Customers retain ownership of Customer Data. Providing the Services does not transfer ownership of Customer Data to Attribute.

We limit use to disclosed and authorized purposes. We process information to provide requested Services, follow Customer instructions, support users, protect the Services, meet legal obligations, and pursue other compatible purposes described in this Policy.

We separate authority from data use. A person’s ability to access information does not by itself authorize every use of that information. AI processing, disclosure, export, and automated action may require additional purpose, consent, classification, minimization, provider, workflow, or tool controls.

We design for least privilege and accountability. Access to personal and organizational information is intended to be limited according to authenticated identity, organizational boundaries, role, scope, delegation, purpose, and other relevant authorization context, with security-relevant activity logged where appropriate.

3. Information we collect

The information we collect depends on which Services you use, the features and integrations enabled, whether you use Attribute directly or through a Customer, and the information you or others choose or are authorized to provide.

3.1 Account, identity, and organization information

We may collect names, usernames, business contact information, email addresses, telephone numbers, account identifiers, authentication and session information, organization and workspace identifiers, job title, department, role, team, membership status, account preferences, permissions, delegated authority, and similar account-administration information.

3.2 Personal profile, conversation, and self-discovery information

When using personal Attribute services, you may provide conversations, reflections, stories, goals, values, skills, preferences, plans, assessments, notes, memories, feedback, and other information about yourself or other people. Some of this content may reveal sensitive characteristics or personal circumstances. You control what you choose to provide, subject to the rights and instructions of any other individual whose information you include.

3.3 Enterprise, ERP, and operational information

Enterprise Services may process business records such as customer and prospect information; vendor, supplier, and trade-reference information; product, catalog, pricing, purchasing, inventory, warehouse, fulfillment, manufacturing, sales, accounting, approval, workflow, and audit information; employee or contractor business data; communications; transaction records; and information obtained from connected systems. Customer Data may include information about individuals who do not have Attribute accounts.

3.4 Documents, images, and extracted information

You or a Customer may upload or transmit PDFs, photographs, scans, forms, certificates, applications, invoices, identity or tax documents, resale or licensing documents, trade references, contracts, correspondence, and other files. We may process the file itself, associated metadata, extracted text, structured fields, classifications, validations, confidence scores, detected inconsistencies, and review status. For example, an enterprise customer may use document-assisted intake to extract and validate information from a business application while retaining an authorized person as the final reviewer.

3.5 Integration, API, and connected-system information

If you or a Customer connects a third-party service, Attribute may receive and transmit data authorized by the connection, including record identifiers, system metadata, synchronization state, error information, configuration, and business records. We may process credentials, API keys, tokens, certificates, or similar secrets needed to operate a connection. Such secrets are used to authenticate and operate the requested integration and are not treated as general-purpose content.

3.6 Billing and transaction information

We may collect billing contacts, subscription details, order and invoice records, payment status, tax information, and limited payment-related information. Payment card or bank information may be collected directly by a payment processor rather than stored by Attribute.

3.7 Device, usage, log, and security information

We may automatically collect IP address, approximate location derived from IP address, device and browser type, operating system, identifiers, language, referring page, dates and times of access, pages and features used, interactions, performance and diagnostic data, API requests, authentication events, administrative actions, authorization decisions, integration activity, agent and tool activity, error logs, and security signals.

3.8 Communications and support information

We collect information when you contact us, request support, participate in research, respond to surveys, attend an event, communicate with sales, submit feedback, or otherwise correspond with Attribute. This may include the content of communications, attachments, contact details, call or meeting information, and support diagnostics.

3.9 Derived information and inferences

The Services may generate summaries, structured records, embeddings, classifications, suggested relationships, assessments, recommendations, predicted fields, risk or anomaly indicators, user-specific memories, and other inferences from information lawfully available to the feature. Derived information may itself be Personal Information when it relates to an identifiable individual.

3.10 Sources of information

We collect information directly from you; from Customers and their administrators or Authorized Users; from connected systems and integrations; from people who communicate or transact with you or a Customer; from service providers; from publicly available sources where permitted; and from the use and operation of the Services.

4. Sensitive information and documents

Depending on how the Services are used, Personal Information may include government identifiers, tax or licensing information, financial account details, account credentials, private communications, precise business or residential addresses, employment information, identity documents, and information that reveals health, disability, race or ethnicity, religious or philosophical beliefs, sexual orientation, citizenship or immigration status, or other sensitive characteristics.

We process sensitive information only when reasonably necessary for a requested feature, when directed by a Customer, when the individual provides or authorizes it, when another legal basis applies, or when needed for security or legal compliance. We apply additional restrictions where required by law, contract, data classification, or Customer configuration.

Do not submit highly regulated information—including protected health information, payment-card data outside an approved payment flow, consumer-reporting data, export-controlled information, or other data subject to special legal restrictions—unless the applicable Service and written agreement expressly permit it. Customers are responsible for determining whether the Services are suitable for their regulated data and use case.

Where consent is required for sensitive-data processing, Attribute or the applicable Customer will seek consent through an appropriate mechanism. A Customer’s instructions do not eliminate its responsibility to provide required notices, obtain required permissions, and limit collection to what is lawful and necessary.

5. How we use information

We use Personal Information for the following purposes, as applicable to the relevant Service and our role:

Provide and operate the Services. Create and manage accounts; provide personal and enterprise features; store, organize, retrieve, display, and transmit content; maintain workspaces; and deliver requested functionality.

Personalize direct-user experiences. Maintain user-specific preferences, memories, context, plans, and recommendations when enabled by the user. Personalization for a specific user is not the same as training a generalized model.

Process documents and support AI features. Extract, classify, validate, summarize, transform, and generate information; provide recommendations and proposed actions; and deliver requested AI-assisted features.

Authenticate and authorize access. Verify identity, maintain sessions, resolve organizational membership and authority, enforce access controls, protect sensitive fields, and support delegated, agent, tool, or integration access.

Operate integrations and APIs. Connect to third-party systems, synchronize authorized records, execute requested transfers or actions, diagnose errors, and maintain integration health and security.

Administer Customer organizations. Enable Customer administrators to manage users, roles, teams, permissions, policies, approvals, workflows, retention settings, connected systems, and organizational configurations.

Provide support and communicate. Respond to requests, troubleshoot, provide notices, send service and security communications, and manage customer relationships.

Bill and administer subscriptions. Process purchases, invoices, payments, renewals, taxes, account credits, and subscription changes.

Secure the Services. Detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, harmful activity, policy violations, vulnerabilities, and security incidents.

Maintain and improve reliability. Analyze performance, diagnostics, usage patterns, quality, and feature effectiveness; conduct testing; and improve usability, availability, and safety. We use deidentified or aggregated information where reasonably practicable and do not treat this purpose as authorization to train generalized AI models on Customer Data or User Content.

Comply with law and protect rights. Meet legal, regulatory, tax, accounting, audit, and contractual obligations; respond to lawful requests; enforce agreements; and protect the rights, safety, and property of Attribute, our users, Customers, and others.

Manage corporate transactions. Evaluate or complete a financing, merger, acquisition, reorganization, sale of assets, or similar transaction, subject to confidentiality and applicable law.

We may use information for another purpose when the purpose is compatible with the context in which the information was collected, when we provide additional notice, when the applicable Customer directs us, or when we obtain consent as required by law. We do not materially expand the use of previously collected content for generalized AI model training merely by changing this Privacy Policy.

6. Enterprise Customer Data

6.1 Customer control and ownership

As between Attribute and a Customer, the Customer retains all right, title, and interest in and to Customer Data. Attribute receives only the limited rights needed to process Customer Data in accordance with the Customer’s agreement, documented instructions, enabled features, and applicable law.

6.2 Processing restrictions

When acting as a service provider or processor, Attribute will process Customer Data to provide, secure, support, maintain, and administer the contracted Services; operate Customer-authorized integrations and workflows; comply with documented instructions; detect and prevent fraud or security incidents; and meet applicable legal obligations. We do not use Enterprise Customer Data for third-party advertising, sell it, or use it to train generalized AI models without the Customer’s separate affirmative authorization.

6.3 Access by Customer administrators and users

A Customer controls its workspace and may permit administrators, employees, contractors, agents, integrations, or other Authorized Users to access or act on Customer Data. Customer administrators may be able to access account information, content, audit information, activity, permissions, exports, and settings of users associated with the Customer. Users should direct questions about an organization’s internal access and monitoring practices to that organization.

6.4 Attribute personnel access

Attribute personnel and contractors may access Customer Data only when reasonably necessary to provide support requested by the Customer, maintain or secure the Services, investigate abuse or incidents, comply with law, or perform another authorized function. Access is intended to be limited to personnel with a legitimate need and subject to confidentiality and security controls.

6.5 Customer instructions and lawful collection

Customers are responsible for ensuring that they have the legal authority to submit Customer Data, connect third-party systems, instruct Attribute to process data, configure automated or AI-assisted workflows, and provide access to Authorized Users. Customers are also responsible for their privacy notices, consents, employment or monitoring obligations, records-management rules, and responses to individuals, except to the extent Attribute has expressly agreed otherwise.

6.6 Data-subject requests involving Customer Data

If we receive a privacy request concerning Customer Data for which a Customer is the controller or business, we may refer the requester to the Customer and notify the Customer as appropriate. We will assist the Customer with access, correction, deletion, portability, restriction, objection, or other requests as required by the applicable Data Processing Addendum, written agreement, and law.

6.7 Return, export, and deletion

Customer Data may be exported, returned, retained, or deleted according to the Customer’s configuration, the applicable agreement, documented instructions, legal requirements, security needs, and technical backup cycles. Deleting information from Attribute does not necessarily delete copies held in a connected third-party system, and deleting information in a connected system does not necessarily delete copies lawfully retained in Attribute.

7. AI-assisted and automated processing

7.1 How AI may be used

AI-assisted features may analyze text, documents, images, records, conversations, and authorized context to extract or validate data, generate summaries, classify information, identify inconsistencies, recommend next steps, support search and retrieval, create drafts, propose business actions, or personalize a direct-user experience. Some Services depend on AI processing and cannot function as intended without it.

Depending on the feature and configuration, AI processing may use an Attribute-selected provider, a Customer- or user-selected provider account or endpoint, a cloud model platform, a multi-provider routing service, or a model operated locally or within a private or Customer-controlled environment. Representative model sources may include Anthropic Claude, Google Cloud Gemini, OpenAI models, SpaceXAI Grok, and other current or future providers; routing services may include OpenRouter. These examples do not mean that every provider is available for every Service or receives information from every Customer or user.

Where configuration controls are offered, an organization may assign approved models or provider routes to particular workspaces, internal workflows, agents, tools, purposes, or data classifications. Attribute may assign approved models to Attribute-managed features. Provider and route selection does not expand the purposes for which information may be processed, and configured privacy, authorization, data-use, residency, retention, training, and egress restrictions continue to apply.

7.2 Data minimization and context controls

We design AI processing to use information reasonably necessary for the requested purpose and to respect applicable access controls, Customer instructions, data classifications, provider restrictions, and feature settings. Permission to view a record does not automatically authorize every AI use, external disclosure, export, or tool action involving that record.

7.3 No generalized model training without affirmative authorization

Attribute does not use Customer Data or User Content to train generalized AI models for Attribute or third parties unless the applicable Customer or direct user separately and affirmatively authorizes that use through a clear opt-in or written agreement. We do not infer permission to train from ordinary use of an AI feature, from a user’s authorization to view information, or from a general right to improve the Services.

Where an Attribute-selected AI Provider processes Customer Data or User Content, we require the provider to process the information only for the authorized service and not to use that content to train generalized models except where separately authorized. When a Customer or user connects its own provider account, API credential, model endpoint, routing service, or local or private deployment, the recipient is generally selected at that Customer’s or user’s direction and its own terms and configuration may govern its independent processing. Current Attribute-selected subprocessors and AI Providers will be identified in our Subprocessor List.

7.4 User-specific personalization is not generalized training

The Services may generate and retain user-specific memories, embeddings, summaries, preferences, structured profiles, or other derived information to provide continuity and personalization to that user or Customer. This processing is limited to providing the requested service and is not, by itself, training of a generalized model for unrelated users. Users and Customers may have controls to review, correct, delete, disable, or limit particular forms of personalization, subject to product functionality, retention rules, and applicable law.

7.5 Human review and consequential decisions

AI-generated output may assist an individual or Customer in making a decision, but an AI extraction, confidence score, inconsistency flag, recommendation, or proposed action does not necessarily constitute a final decision. Customers determine how they use enterprise outputs and are responsible for required human review, notices, appeals, and legal compliance. Where Attribute itself uses automated processing to make a decision that produces legal or similarly significant effects, we will provide the notices, choices, explanations, and safeguards required by applicable law.

7.6 Automated agents, tools, and actions

Where offered, AI agents or automation may initiate or execute actions under Customer-configured permissions, delegated authority, tasks, approvals, workflows, and tool access. Information used for those actions may include identity, authority, target, context, decision, and audit information. Customers are responsible for configuring and supervising their authorized uses; Attribute is responsible for processing within the Services as described in the applicable agreement and this Policy.

7.7 Feedback and quality evaluation

We may use ratings, error reports, support cases, and other feedback to evaluate and improve the Services. If feedback would include Customer Data or User Content for generalized model training or a materially different purpose, we will seek separate authorization where required. We may use deidentified or aggregated quality and performance metrics that do not reasonably identify an individual or Customer, subject to legal and contractual restrictions.

8. How we disclose information

We disclose Personal Information only as described below, as directed by a Customer or user, or with consent. We do not sell Personal Information or disclose Enterprise Customer Data for third-party targeted advertising.

Service providers and subprocessors. We may disclose information to providers of cloud hosting, storage, databases, authentication, security, monitoring, communications, support, analytics, payment processing, document processing, direct or routed AI capabilities, model hosting, and professional services. They may process information only for authorized purposes and are subject to contractual obligations appropriate to their role.

Customers and their Authorized Users. If you use the Services through an organization, information associated with that organization may be disclosed to its administrators and other users according to the organization’s configuration, permissions, workflows, and instructions.

Third-party integrations and connected services. We disclose information to or receive information from third-party systems when a user or Customer enables an integration, invokes a tool, directs a transfer, or otherwise authorizes the connection. The third party’s handling of information is governed by its own terms and privacy practices.

At your or the Customer’s direction. We may disclose information to recipients selected by the user or Customer, including collaborators, customers, vendors, advisors, agents, service providers, external systems, and public or shared workspaces.

Professional advisors. We may disclose information to auditors, insurers, attorneys, accountants, consultants, and other professional advisors under appropriate confidentiality obligations.

Legal, security, and rights protection. We may disclose information when we reasonably believe disclosure is required by law or legal process, necessary to respond to lawful requests, or appropriate to prevent or investigate fraud, abuse, security incidents, threats, or violations; protect rights, property, or safety; or establish, exercise, or defend legal claims.

Corporate transactions. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to confidentiality and applicable law. A successor must honor this Privacy Policy for information collected under it unless it provides required notice and obtains required authorization for materially different uses.

Deidentified or aggregated information. We may disclose information that has been aggregated or deidentified so that it is not reasonably linkable to an individual or Customer, subject to commitments not to reidentify it except as permitted for testing the effectiveness of deidentification.

9. Cookies and similar technologies

We and our service providers may use cookies, local storage, pixels, software development kits, and similar technologies to operate the Services, maintain sessions, remember preferences, measure performance, diagnose errors, prevent fraud, and understand use of our websites and applications. We may provide a cookie or preference control where required or appropriate.

Attribute does not use Personal Information for cross-context behavioral advertising. We do not sell or share Personal Information through advertising cookies. Additional details about the technologies used by the Services and available controls may be provided in a separate Cookie Notice or preference center.

You may be able to control cookies through browser or device settings, but disabling strictly necessary technologies may prevent parts of the Services from functioning. Where applicable law requires recognition of a valid universal opt-out mechanism, we will honor the signal for processing to which the right applies. Because Attribute does not sell Personal Information or process it for cross-context behavioral advertising, such a signal generally will not change those practices.

10. Data retention and deletion

We retain Personal Information only for as long as reasonably necessary for the purposes described in this Policy, to follow Customer instructions, provide the Services, maintain continuity and security, comply with law, resolve disputes, enforce agreements, and protect rights. Retention depends on the type of information, the nature of the relationship, Customer configuration, user choices, sensitivity, legal requirements, and operational need.

Information categoryTypical retention approach
Account and contact informationFor the life of the account or relationship and thereafter as needed for administration, legitimate business records, legal obligations, disputes, and security.
Direct-user content and personalizationUntil deleted by the user, the account is closed, a feature-specific retention period expires, or retention is otherwise no longer necessary, subject to backups and legal exceptions.
Enterprise Customer DataAccording to Customer configuration, documented instructions, the enterprise agreement, the Data Processing Addendum, legal requirements, and backup cycles.
Documents and extracted informationAs needed for the requested workflow and any Customer- or user-selected record retention; temporary processing copies may be deleted earlier than the resulting business record.
Billing and transaction recordsFor applicable tax, accounting, audit, fraud-prevention, and contractual periods.
Security, authorization, and audit logsFor a period appropriate to security, incident response, compliance, accountability, and legal obligations; these records may be retained longer than ordinary content.

When information is deleted, it may remain in encrypted or access-restricted backups until overwritten through ordinary backup cycles, unless earlier deletion is required and technically feasible. We may retain information that has been properly deidentified, provided we maintain it in deidentified form and do not attempt to reidentify it except as permitted by law to test deidentification.

11. Security

We maintain administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized or unlawful access, acquisition, use, disclosure, alteration, loss, or destruction. The safeguards are intended to be appropriate to the nature and sensitivity of the information, the scope and context of processing, and the risks involved.

Safeguards may include identity and access management; role-, scope-, and boundary-based access restrictions; least-privilege controls; authentication and session protections; separation of personal, organizational, and platform data; protection of integration credentials; logging, monitoring, and audit records; secure development and change controls; vendor risk review; incident response; and personnel confidentiality obligations. Specific controls may vary by Service, plan, deployment, and Customer agreement.

No system can be guaranteed completely secure. Users and Customers are responsible for protecting their credentials, configuring permissions appropriately, limiting the data they submit, maintaining the security of connected systems, and promptly notifying us of suspected unauthorized access. If a security incident affects Personal Information, we will investigate and provide notices to affected Customers, users, regulators, or others as required by law and contract.

12. International data transfers

Attribute is based in the United States, and Personal Information may be processed in the United States and other countries where we, our affiliates, Customers, or service providers operate. Those countries may have data-protection laws that differ from the laws where you live.

Where required for transfers of Personal Information from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, we will use an approved transfer mechanism, contractual safeguards, or another lawful basis. Enterprise transfer terms are addressed in the applicable Data Processing Addendum. Unless a written agreement expressly provides otherwise, the Services do not guarantee that all data will remain in a particular country or region.

13. Privacy rights and choices

Depending on your location, the nature of our relationship, and applicable exceptions, you may have the right to request that we:

confirm whether we process your Personal Information and provide access to it;

correct inaccurate Personal Information;

delete Personal Information;

provide a portable copy of Personal Information you provided or that is otherwise covered by portability rights;

identify categories or specific pieces of Personal Information, sources, purposes, and recipients;

restrict or object to certain processing;

withdraw consent for future processing when processing is based on consent;

opt out of sale, targeted advertising, or certain profiling or automated decision-making;

limit certain uses or disclosures of sensitive Personal Information;

obtain information about certain automated processing and request available human review or appeal;

appeal a denial of a privacy request; and

receive equal service and not be discriminated against for exercising a privacy right.

13.1 Requests concerning data Attribute controls

To exercise a right concerning Personal Information for which Attribute acts as controller or business, contact us at privacy@ultimate.dev. Describe the request and the Attribute account or interaction to which it relates. We will respond within the period required by applicable law.

13.2 Requests concerning Enterprise Customer Data

If your information was submitted to Attribute by an employer, business customer, vendor, retailer, service provider, or other organization, please direct your request to that organization. The organization controls the relevant Customer Data and is best positioned to identify the correct records and determine whether an exception applies. We will assist the organization as required.

13.3 Verification and authorized agents

We may need to verify your identity and authority before completing a request. Verification may require information reasonably related to the request and the sensitivity of the data. An authorized agent may submit a request where permitted, but we may request proof of authorization and may verify the request directly with you. We will not provide account passwords, secret credentials, full financial account numbers, or similarly dangerous information in response to an access request.

13.4 Exceptions and appeals

Privacy rights are not absolute. We may deny or limit a request when permitted by law, including when necessary to protect another person, preserve security or fraud-prevention records, comply with legal obligations, exercise or defend legal claims, maintain privileged or confidential information, complete a transaction requested by you, or retain information that cannot reasonably be linked to the requester. If applicable law provides an appeal right, denial notices will explain how to appeal.

13.5 Communications and account controls

You may unsubscribe from promotional email using the link in the message or by contacting us. You will continue to receive transactional, account, legal, and security communications when necessary. Available account, memory, personalization, cookie, and workspace controls may be accessed through the relevant settings. Withdrawing consent or deleting information may limit functionality that depends on that information.

14. California disclosures

This section supplements the rest of the Policy for California residents and uses terms defined by the California Consumer Privacy Act, as amended (“CCPA”). The categories below describe Personal Information we may collect depending on the Services used and information submitted. Not every category applies to every person or Service.

Category and examplesSourcesPurposes and recipients
Identifiers and customer-record information
Name, alias, contact details, account and organization identifiers, online identifiers, IP address, government or tax identifiers when submitted.
You; Customers; integrations; service providers; public sources.Service delivery, accounts, authentication, documents, integrations, billing, support, security, compliance. Disclosed to service providers, Customers/Authorized Users, directed integrations, advisors, and authorities where required.
Commercial and transaction information
Subscriptions, purchases, invoices, payment status, products or services considered or used, business transactions, orders, and operational records.
You; Customers; payment providers; integrations.Service administration, billing, ERP workflows, support, analytics, security, legal records. Disclosed to service providers, Customers, and directed systems.
Internet or electronic network activity
Device, browser, logs, pages and features used, API activity, session, authentication, integration, error, and security events.
Automatically from use; Customers; service providers.Operation, diagnostics, analytics, security, fraud prevention, audit, and support. Disclosed to infrastructure, monitoring, security, analytics, and support providers.
Approximate geolocation
General location inferred from IP address; precise location only if a specific feature requests it and separate notice or consent is provided.
Devices, browsers, network information.Localization, security, fraud prevention, and compliance. Disclosed to relevant service providers.
Audio, electronic, visual, or similar information
Uploaded images, scans, documents, recordings, screenshots, meeting or support content where provided.
You; Customers; integrations; support interactions.Document and AI processing, service delivery, support, records, security, and compliance. Disclosed to authorized service providers, Customers, and directed recipients.
Professional, employment, and education information
Job title, employer, department, role, skills, work history, trade references, education, and enterprise records when submitted.
You; Customers; other users; integrations; public sources.Accounts, personal services, ERP workflows, onboarding, support, and authorized AI processing. Disclosed as directed or to service providers.
Sensitive Personal Information
Account credentials; government identifiers; financial account information; private communications; and sensitive traits or circumstances included by a user or Customer.
You; Customers; integrations; other authorized sources.Only for requested services, authentication, security, document processing, Customer instructions, or legal compliance. Disclosed only to authorized providers and recipients.
Inferences and AI-derived information
Summaries, classifications, embeddings, preferences, assessments, recommendations, structured fields, predictions, and anomaly indicators.
Generated from information lawfully available to a feature.Personalization, search, extraction, validation, recommendations, workflows, security, and quality evaluation. Disclosed to Customers/Authorized Users and service providers as needed.
Protected characteristics or other sensitive traits
Information voluntarily included in personal content or Customer Data, such as age, citizenship, disability, race or ethnicity, religion, or sexual orientation.
You; Customers; other authorized users.Only to provide a requested service, follow lawful Customer instructions, or comply with law. Not used for advertising or generalized model training without authorization.

14.1 Sale, sharing, and sensitive information

Attribute does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. We do not knowingly sell or share the Personal Information of individuals under 18. We do not use or disclose Sensitive Personal Information for purposes that require a CCPA right to limit, except where separately disclosed and legally permitted. Attribute does not currently offer a financial incentive in exchange for Personal Information.

14.2 California rights

California residents may have the right to know, access, correct, delete, and obtain information about our collection, use, and disclosure of Personal Information; to obtain a portable copy; to opt out of sale or sharing; to limit certain uses of Sensitive Personal Information; and to be free from discrimination for exercising rights. Because we do not sell or share Personal Information, an opt-out request will confirm that practice rather than change it. Submit requests as described in Section 13.

14.3 Retention

The retention criteria in Section 10 apply to the categories listed above. We do not retain a category of Personal Information longer than reasonably necessary for the disclosed purposes, subject to Customer instructions, legal obligations, security needs, disputes, backups, and applicable exceptions.

15. Other U.S. state rights

Residents of U.S. states with applicable comprehensive privacy laws may have rights that include access, correction, deletion, portability, opt-out of sale, opt-out of targeted advertising, opt-out of certain profiling, consent or withdrawal rights for sensitive information, a list of certain third parties, and appeal of a denied request. The precise rights, definitions, exceptions, and response procedures vary by state.

Attribute does not sell Personal Information or process it for targeted advertising. Where a state right applies to profiling or automated decision-making, we will provide the applicable information, opt-out, appeal, or review mechanism for processing that Attribute controls. For Customer-controlled processing, the applicable Customer is responsible for the decision and request response, with our assistance as required.

16. European Economic Area, United Kingdom, and Switzerland

16.1 Controller and processor roles

For direct-user and business-operations processing described in Section 1.2, Ultimate, Inc. is the controller unless another notice states otherwise. For Customer Data processed on behalf of an enterprise Customer, the Customer is generally the controller and Attribute is the processor. Our contact information appears in Section 20. If applicable law requires Attribute to appoint an EU or UK representative, the representative details will be made available with this Policy.

16.2 Legal bases

Where the GDPR, UK GDPR, or Swiss data-protection law applies, we process Personal Information based on one or more of the following: performance of a contract or steps requested before entering a contract; compliance with a legal obligation; our legitimate interests or those of a third party, balanced against the individual’s rights; consent; protection of vital interests; or another lawful basis. Legitimate interests may include providing and securing the Services, preventing fraud, supporting users, administering Customer relationships, improving reliability, and protecting legal rights. We do not rely on consent when the processing is not genuinely optional.

16.3 Rights

You may have rights to access, correct, erase, restrict, object, receive data portability, withdraw consent, and lodge a complaint with a supervisory authority. You may also have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects. To exercise rights, follow Section 13. If the request concerns Customer Data, contact the applicable Customer.

16.4 Transfers

International transfers are handled as described in Section 12. Where required, we may use the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, the Swiss addendum or recognized adaptations, an adequacy decision, or another lawful transfer mechanism.

17. Children’s privacy

The Services are not directed to children under 18, and individuals under 18 may not create a direct Attribute account unless a specific Service, written agreement, and legally valid authorization expressly permit it. We do not knowingly collect Personal Information directly from children under 13 in violation of the Children’s Online Privacy Protection Act. If you believe a child provided Personal Information to Attribute without appropriate authorization, contact us so we can investigate and take appropriate action.

Enterprise Customers are responsible for determining whether their use involves minors and for providing required notices, obtaining parental or guardian authorization, limiting processing, and configuring appropriate safeguards. Attribute may impose additional restrictions or decline to process children’s data unless a suitable written agreement and product configuration are in place.

18. Third-party services and integrations

The Services may connect to third-party identity providers, ERP systems, commerce platforms, payment processors, communications tools, cloud services, model providers, and other systems. When you or a Customer authorizes a connection, information may flow between Attribute and the third party according to the connection’s scope and instructions. Attribute is not responsible for the third party’s independent privacy, security, availability, or data-retention practices.

A third-party system may remain the authoritative source of a record even when Attribute displays, processes, or synchronizes a copy. Actions taken through Attribute may create, update, or delete records in a connected system, and actions in that system may affect Attribute. Review the third party’s privacy notice and the Customer’s integration configuration before enabling or using a connection.

19. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, the Services, or our practices. We will post the updated version and revise the “Last Updated” date. Where required, we will provide additional notice through the Services, by email, or by another appropriate method before a material change takes effect.

We will not rely solely on a policy update to begin using previously collected Customer Data or User Content to train generalized AI models when that use was not previously disclosed and authorized. We will obtain separate affirmative authorization when required by our commitments, contract, or law. Material changes to enterprise processing remain subject to the applicable agreement and Data Processing Addendum.

20. Contact us

Questions, complaints, and requests concerning this Privacy Policy or Attribute-controlled Personal Information may be directed to:

Ultimate, Inc. 16192 Coastal Highway Lewes, DE 19958 United States
Legal
legal@ultimate.dev
Security
security@ultimate.dev
Privacy
privacy@ultimate.dev

The Privacy Team handles requests sent to the Privacy email above.

If you are located in the EEA, United Kingdom, or Switzerland, you may also contact your local data-protection authority. If your request concerns data controlled by an enterprise Customer, contact that Customer first so it can identify and respond to the relevant records.

ContactPrivacyTermsDPASubprocessorsSecurity

Know what matters. Shape what's next.