ATMA AI and the ATMA website at https://atma10.com are operated by Bogdan Martsun, an individual (natural person), not a registered company, established in Montenegro (“ATMA”, “we”, “us”, or “our”).
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the ATMA website, practitioner workspace, Zoom integration, AI-assisted tools, bookings, and related services (the “Service”).
Privacy questions and requests: privacy@atma10.com. Support: support@atma10.com. A correspondence address in Montenegro is provided on request for data-protection, regulatory, and legal notices. Email is the primary contact channel.
1. Who this Policy applies to
This Policy applies to therapists, mental-health practitioners, other authorized staff users, clients who create an ATMA account, and visitors of the public website.
ATMA is a professional support and practice workspace. It is not an emergency service, a licensed healthcare institution, a medical device, or a substitute for medical, psychological, psychiatric, legal, or other professional advice.
If you are a practitioner using ATMA in connection with clients or sessions, you remain responsible for your own legal and professional obligations, including notices, permissions, confidentiality, and consents required from clients or meeting participants.
2. Personal data we collect
Account and contact data
Name, email address, login credentials, role (practitioner, client, or operator), profile information you choose to publish, support requests, and communications with us.
Technical and usage data
IP address, device and browser type, operating system, pages or features used, timestamps, diagnostic logs, and security-related events. We do not write Zoom access tokens, refresh tokens, or passwords into application logs.
Zoom integration data
If you — as a practitioner — choose to connect your own Zoom account, we may process:
- your Zoom account identifier, display name, and email returned by Zoom;
- OAuth access and refresh tokens, stored only on our servers in encrypted form;
- granted Zoom scopes and connection status;
- meeting metadata for meetings created through ATMA (meeting id, times, join/start information, participant identifiers and display names provided by Zoom);
- webhook events needed to operate the integration (for example RTMS and recording events).
When you explicitly start listening / transcription for an ATMA session, ATMA receives live meeting audio through Zoom RTMS and generates a transcript. When cloud recording is enabled for that meeting, ATMA may download the recording file after Zoom reports that it is ready. ATMA then stores the transcript and, if fetched, the recording in ATMA systems so the practitioner can review notes, receive optional AI drafts, and — if the practitioner chooses — send a session overview or video link to the client.
ATMA does not join, record, or transcribe Zoom meetings by default. Those features run only when a practitioner creates a session in ATMA, connects Zoom, and uses the relevant controls. ATMA does not use the Zoom integration to access meetings that the practitioner did not create through ATMA.
Content submitted by users
Practitioner notes, prompts, tasks, session summaries, player/client names and emails you enter, consent records, and other workspace content. Practitioners should not submit client or health information unless they have a valid legal basis and have taken the required professional and organizational steps.
Payments and bookings
If you pay for a book, session, or game seat, our payment processor receives the payment details needed to complete the transaction. ATMA stores order status, amount, and the email associated with the purchase. We do not store full card numbers.
3. How we use personal data
- create, operate, and secure your ATMA account;
- provide the practitioner workspace, sessions, game flow, bookings, and support;
- enable and manage the Zoom integration you authorize;
- transcribe practitioner-enabled session audio and generate optional AI drafts;
- authenticate users and prevent fraud, abuse, and unauthorized access;
- send service emails (verification, session materials, booking notices);
- investigate errors, security incidents, and violations of our Terms;
- comply with legal obligations;
- create aggregated or de-identified analytics to improve the Service, where permitted by law.
We do not sell personal data. We do not use Zoom user data for advertising or to build advertising audiences.
4. Legal bases
Where GDPR, the UK GDPR, or the Montenegro Law on Personal Data Protection applies, we process personal data on one or more of these bases:
- Contract — to provide the Service you request.
- Consent — where you connect Zoom or enable optional features, and consent is required.
- Legitimate interests — to secure, operate, and improve the Service, provided these interests are not overridden by your rights.
- Legal obligation — where processing is required by law.
If you are a practitioner and enter personal data about clients, you are responsible for having an appropriate lawful basis for that processing.
5. AI-assisted functionality
ATMA may provide optional AI-assisted draft suggestions for practitioner review. Outputs are not medical advice and do not replace professional judgment, diagnosis, treatment decisions, clinical supervision, or emergency services. The practitioner reviews and controls all outputs before use.
Depending on the feature you use, we send the minimum information necessary to contracted processors:
- DeepSeek — server-side API for live practitioner hints and session summaries generated from transcripts or notes the practitioner submits.
- ElevenLabs — speech-to-text on live Zoom RTMS audio when the practitioner enables listening / transcription.
- YandexGPT and Yandex SpeechKit — the separate in-browser AI session on ATMA. That product uses the user’s microphone in the browser; it does not use Zoom OAuth, Zoom RTMS, or Zoom recordings.
We do not send Zoom OAuth access tokens or refresh tokens to AI providers. Zoom tokens stay on ATMA servers.
6. How we share personal data
We may share personal data with service providers that help us operate ATMA, subject to contractual or legal safeguards:
- hosting and infrastructure for the ATMA servers and database;
- S3-compatible storage for recordings and media;
- email delivery;
- payment processors, where you make a purchase;
- AI and speech providers listed above, only for the feature you use;
- Zoom, in connection with the integration you authorize;
- Meta Platforms (Meta Pixel) on public marketing pages, to measure visits and advertising conversions such as a retreat application. We do not send Zoom tokens, session transcripts, or client session notes to Meta;
- professional advisers, regulators, or law enforcement where required by law or necessary to protect legal rights and safety.
We do not sell personal data to third parties.
7. International data transfers
Personal data may be processed in Montenegro, the European Economic Area, the United Kingdom, the United States, and other countries where our processors operate (including AI and speech providers). Where required, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms.
8. Data retention
- Account information — for the life of the account and a limited period afterwards as needed for security, disputes, and legal compliance.
- Zoom authorization tokens — until you disconnect Zoom, the authorization expires or is revoked, or they are no longer needed.
- Transcript segments — generally 30 days, after which they are purged. Successful AI analyses may be kept with the session record for the practitioner.
- Cloud recordings fetched into ATMA — until deleted on request or no longer needed for the session materials the practitioner chose to keep or send.
- Client PDF overview links — 14 days.
- Support messages — as reasonably needed to handle the request.
- Security and technical logs — a limited period for security, troubleshooting, and legal compliance.
You may request deletion of your account and associated personal data at privacy@atma10.com, subject to legal obligations and legitimate retention needs.
9. Security
We use technical and organizational measures designed to protect personal data, including HTTPS/TLS in transit, encrypted storage of Zoom OAuth tokens (AES-256-GCM for Zoom OAuth tokens and other sensitive fields), server-side secrets, restricted production access, and role-based access so that a practitioner manages only their own Zoom connection and sessions. No system is completely secure. You are responsible for keeping your credentials confidential.
Stack in brief: Next.js 15, React 19, TypeScript, Tailwind CSS; Node.js via Next.js Route Handlers and a dedicated Linux worker process; Self-hosted Docker Compose on a dedicated Linux VPS behind nginx, HTTPS on atma10.com; PostgreSQL 16; Auth.js v5 (NextAuth) with server-side session cookies.
10. Your data-protection rights
Depending on your location and applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing;
- request portability of data;
- withdraw consent where processing is based on consent; and
- complain to a relevant data-protection authority.
To exercise a right, email privacy@atma10.com with the subject line “Privacy Request”. We may need to verify your identity. We aim to respond within the time required by applicable law.
In Montenegro, you may complain to the Agency for Personal Data Protection and Free Access to Information of Montenegro (AZLP): https://www.azlp.me/. If you are in the United Kingdom, you may also complain to the ICO: https://ico.org.uk/make-a-complaint/. If you are in the EEA, you may complain to your local supervisory authority.
11. Zoom integration and revoking access
Disconnect Zoom at any time in ATMA: Settings → Integrations → Zoom → Disconnect Zoom. You may also revoke ATMA’s authorization in your Zoom account or the Zoom App Marketplace.
After access is revoked, ATMA stops making new Zoom API requests with that authorization. Some information may be retained where necessary for security, legal compliance, dispute resolution, or other legitimate purposes in this Policy. To request deletion of Zoom-related data stored in ATMA, email privacy@atma10.com.
Step-by-step instructions: Zoom Integration Guide.
12. Children
ATMA is not directed to children. Do not use the Service if you are under the minimum age required to enter into a binding agreement in your jurisdiction. Practitioners must not submit children’s personal data unless they have all required legal authority and safeguards.
13. Changes
We may update this Privacy Policy. The current version is posted on this page with a new “Last updated” date. Where required by law, we will provide additional notice of material changes.
14. Contact
Bogdan Martsun
Individual operator, Montenegro
Privacy: privacy@atma10.com
Support: support@atma10.com
A correspondence address in Montenegro is provided on request for data-protection, regulatory, and legal notices. Email is the primary contact channel.