Deduptio

Privacy Policy

Deduptio (“we”, “us”) is operated by VentuRise OÜ (registry code 17064180), Ruunaoja tn 3, Lasnamäe linnaosa, Tallinn, Harju maakond 11415, Estonia. This policy explains what we collect when you use deduptio.com, why, and how long we keep it.

What we collect

Account data. Your email address and a hashed password. We never store your password in readable form. We also record when you verified your email and when your account was created.

Security data. Hashed session tokens, and a log of login attempts including the email tried, the IP address, and whether it succeeded. We use this to rate-limit and detect abuse.

Your Attio connection. When you connect Attio, we store the OAuth access token that authorizes us to read and modify records on your behalf. Tokens are encrypted at rest.

Your CRM record data. To find duplicates we read records from the Attio objects you select and store their field values on our servers. Depending on your CRM, this can include personal data about your contacts — names, email addresses, phone numbers, company associations, and any other attributes on those records. We process this data solely to group duplicates, plan merges, and let you undo them.

Billing data. If you subscribe, we store your Stripe customer and subscription identifiers and your plan. We never see or store your card details — Stripe handles payment information directly.

How long we keep it

Who we share it with

We do not sell your data. We share it only with the providers that run the service:

Staff access

A small number of named operators can view operational metadata about your account — workspace name, plan, scan and merge statuses, and error messages — to provide support and keep the service reliable. The admin interface cannot display the field values of your CRM records: operator visibility is limited to counts, statuses, and errors. Every admin page view and action is logged, and that log is retained for 90 days. Admin access additionally requires the operator to re-confirm their password.

The one exception is the managed cleanup service: if you purchase it, you authorize our operators to view and merge the record data in your workspace for the duration of that engagement, so they can do the cleanup for you. That access ends when the engagement does.

Security

Attio access tokens are encrypted at rest. Passwords are hashed with Argon2. Traffic is served over TLS. Sessions expire on both an idle and an absolute timeout, and can be revoked. No system is perfectly secure, but we design merges to be reversible precisely because mistakes happen.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict its processing. You can disconnect Attio at any time, which stops us reading further records. Deleting your account removes your account data and the record data associated with it. For any of these requests, contact us at help@deduptio.com.

Where you use Deduptio to process personal data about your own contacts, you are the data controller and we act as your processor.

Changes

We'll update this page if this policy changes and revise the date above. Material changes will be emailed to account holders.

Contact

Questions about this policy: help@deduptio.com.