01Who we are
Atrium is made and operated by Sehsaa Solutions Private Limited, a company incorporated in India with its registered office at Block No. 23, Kotkar Industrial Estate, Off Aarey Road, Goregaon East, Mumbai, Maharashtra 400063.
Corporate Identity Number: U62099MH2024PTC426242. GSTIN: 27ABNCS5815L1ZP.
You can reach a person about anything on this page at contact@sehsaa.com, or on WhatsApp at +91 93725 21198. Our named Grievance Officer, and what they are obliged to do, is in section 14.
This notice is written to meet our obligations under India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Where you see a section number in square brackets it refers to that Act.
02The two roles, kept separate
Almost every complaint about a privacy policy for software like this comes from one page trying to cover two completely different situations at once. So, plainly:
We are the Data Fiduciary
For the people who buy and use Atrium — the operator who signs up, the staff they invite, anyone who fills in a form on this website. We decide what to collect and why. Everything in section 3 is ours to answer for.
We are a Data Processor
For everything an operator puts into their Atrium workspace about their members, guests and visitors. The operator is the Data Fiduciary there. We hold and process it on their written instructions and for no purpose of our own. See section 4.
The practical consequence: if you are a member of a coworking space that runs on Atrium and you want your data corrected or deleted, the space is the right place to ask. We will help them do it, and we will tell you who they are, but we cannot go into their records on our own initiative. That is the point of the arrangement, not an evasion of it.
The contractual terms of the second role are set out in full in our Data Processing Addendum, which forms part of every Atrium subscription.
03Data about our own customers and visitors
This is the personal data we decide to collect, for our own purposes. There is not much of it, and there is nothing here we do not use.
| What | When | Why |
|---|---|---|
| Work email address and WhatsApp number | You start a signup at /signup | To send the six-digit sign-in code, to identify your account afterwards, and to reach you about it. Sign-in codes are the only thing your number is used for unless you ask us for something else. |
| Your full name, the name of your space, its short name, your city | You create a workspace | To create the workspace, name it, put your name on invoices and correspondence, and set you up as its owner. |
| Name, space name, email, phone, city, number of branches and desks, the system you use today, your message | You send the enquiry form on the home page | To answer your enquiry and prepare a sensible first conversation. Nothing else. We do not run a newsletter and we do not sell or share this. |
| IP address, browser user agent, the page you came from | You submit the enquiry form | Recorded with the enquiry so we can tell a real enquiry from a bot flood and rate-limit abuse. |
| IP address and timestamp of each sign-in and each code we issue | Every time you sign in | Security. It is what lets us see an account being attacked and tell you about it. |
| Billing details — your legal name, address, GSTIN, what you were charged and what you paid | You move to a paid plan | To raise a valid GST invoice and keep the books the law requires us to keep. If you pay one of our invoices online, the payment is taken by Razorpay on Sehsaa's own merchant account (section 6). |
| Support correspondence — the emails and messages you send us | You contact us | To answer you, and to remember what was agreed. |
What we do not do
- We do not sell personal data, and we do not share it for anyone else's advertising.
- We do not run advertising or analytics trackers on this website. There is no Google Analytics, no advertising pixel, no third-party tag.
- We do not use your data, or your members' data, to train machine learning models.
- We do not build a profile of you across other websites, because we have no way to see them.
Cookies and things like cookies
The marketing pages set no cookies. The Atrium app stores your sign-in token in your own browser so you are not asked for a code on every page; that is a functional necessity, it never leaves your browser except to authenticate you to our own API, and clearing your browser storage removes it.
Two typefaces on these pages and in the app are served by Google Fonts. That means Google receives the IP address of anyone who loads a page, which is a real disclosure and not a footnote — see section 6.
04Data we hold on an operator's behalf
When an operator runs their space on Atrium, their workspace fills up with personal data about people who are not our customers: member companies and the individuals in them, meeting-room guests, day-pass holders, walk-in visitors, sales leads. We are not the Data Fiduciary for any of it. The operator is.
We are telling you what it can contain anyway, because a member or a visitor has a right to know what a system holds about them, and because an operator's own privacy notice has to describe it accurately.
| Category | What it can contain |
|---|---|
| Member companies and their contacts | Legal and trade name, billing address, PAN, primary contact name, email and phone, and the names, emails and phone numbers of individual contacts at that company. |
| Agreements and billing | Seats and cabins held, rates, notice periods, invoices, payments, and the bank name on a payment. No card numbers: Atrium never stores card details, and never sees them. |
| Bookings | Who booked which room or desk, when, and for a guest booking the guest's name, email and phone. |
| Visitors at the front desk | Visitor name, phone, email, company, who they came to see, when they arrived and left — and, if the operator uses the entry form's photo capture, a photograph of the visitor. |
| Day passes | Pass holder name, email, phone and company. |
| Leads | Contact name, company, email, phone, and the notes an operator's staff record about a conversation. |
| Uploaded documents | Whatever the operator attaches to a member or an agreement — commonly identity or address documents. Atrium does not require any of these; what gets uploaded is entirely the operator's decision. |
| Staff accounts and activity | Name, email, mobile number, role, and an audit trail recording who changed what, when, and from which IP address. |
Visitor photographs and identity documents are the sharpest edge here. Both are optional features. If you are an operator and you switch them on, you are the one who owes visitors a notice and a lawful basis for it, and you should decide deliberately how long you keep them. We will delete either on your instruction; you can also simply not use them.
What we do with it
We process it to run the service for the operator, and for nothing else. Specifically: to store and serve it, to send the messages the operator has configured, to generate the operator's invoices, to back it up, and to fix it when something breaks.
Our staff do not browse customer data. Access for support is through an audited impersonation route in our platform console: it records who did it, for which workspace, and the reason given, and that record cannot be edited from within the app. We use it when a customer asks us to look at something, and we would rather you asked us for the log than took our word for it.
05Why we are allowed to process it
The DPDP Act does not have the long list of lawful bases some other laws do. There are two routes, and we rely on both.
Your consent [s.6]. When you start a signup you are shown, on the form itself, an itemised list of what we are collecting and what for, and you choose to continue. That is your consent, it is specific to those purposes, and you can withdraw it — see section 10. Section 15 of this page reproduces that notice in full.
Certain legitimate uses [s.7]. Where you voluntarily give us personal data for a specified purpose and have not indicated that you object to its use for that purpose, we rely on section 7(a). A support email you send us is the clearest example: you sent it so we would read it.
Where we are a processor, we are not choosing a basis at all. We process on the operator's documented instructions under a contract, which is the arrangement section 8(2) of the Act requires between a Data Fiduciary and its Data Processor. Choosing the basis for member and visitor data is the operator's job, and our Data Processing Addendum says so in terms.
We also keep certain records because Indian tax and company law requires it, regardless of consent.
06Who else touches the data
This is the complete list of third parties that can hold or transmit personal data from Atrium. It is short on purpose, and it is checked against what the software actually does rather than what we might add later.
| Who | What they do | Status |
|---|---|---|
| DigitalOceanBangalore, India (BLR1) | Provides the server, disk and database that Atrium runs on. Everything in Atrium sits here. | In use for everything |
| Fast2SMSIndia · fast2sms.com | Delivers our WhatsApp messages: sign-in codes, booking confirmations, payment reminders. Receives the recipient's phone number and the message content. | In use |
| Meta PlatformsOutside India | Operates WhatsApp itself. Every WhatsApp message we send travels over Meta's WhatsApp Business Platform, so Meta handles the recipient's number and the message on its way to their phone. This is inherent in sending anything on WhatsApp. | In use, onward from Fast2SMS |
| RazorpayIndia · Sehsaa's own account | Takes card, UPI and netbanking payments when an operator pays Sehsaa's invoice for their Atrium subscription, using Sehsaa's own Razorpay merchant account. Receives the payer's name, contact details, the amount and our invoice number. Card details go to Razorpay directly from the payer's browser and never reach Atrium. | Used whenever an operator pays one of our invoices online |
| RazorpayIndia · an operator's own account | Takes card, UPI and netbanking payments against an operator's invoices, using that operator's own Razorpay account and keys. Receives the payer's name, contact details and the amount. Card details go to Razorpay directly from the payer's browser and never reach Atrium. | Available; switched on only by an operator who adds their own keys |
| GoogleOutside India | Serves two typefaces (Google Fonts) to this website and to the Atrium app. Google receives the IP address and browser user agent of anyone loading a page. No account data or member data is sent, and no analytics or advertising product of Google's is used. | In use on the public site and the app |
That is the list. There is no analytics provider, no advertising network, no email marketing platform, no customer-data platform and no session-recording tool, because we do not use any. If we add a sub-processor we will update this table and, where an operator's member data is involved, tell affected customers before it starts.
Separately from this list: we will disclose personal data if a court or a lawful government order requires it. Where we are legally permitted to tell the customer first, we will.
07Where the data lives, and when it leaves India
Atrium runs on a single server in DigitalOcean's Bangalore region. Every database, every uploaded file and every backup is there. Each customer gets a separate database rather than a shared one with a tenant column, which is what makes a clean export and a clean deletion possible.
Two things cross the border, and we would rather name them than bury them:
- WhatsApp messages. A message sent to a member or a visitor passes through Meta's infrastructure, which is outside India. The phone number and the message content go with it.
- Font requests. Loading a page fetches typefaces from Google's servers outside India, which reveals the visitor's IP address and browser to Google.
Section 16 of the DPDP Act permits transfer outside India except to countries the Central Government notifies as restricted. No such list has been notified. If one is, and it affects either of the above, we will change what we do rather than argue about it. Sector-specific localisation rules — for example those the Reserve Bank of India applies to payment data — sit with Razorpay, who are the regulated entity for a payment.
08How it is protected
Concretely, rather than by adjective:
- Everything travels over HTTPS. The site and the API do not answer on plain HTTP.
- Each customer's data is in its own database with its own credentials, not a shared table filtered by a column.
- Sign-in codes are stored as a SHA-256 hash and never in the clear, expire in ten minutes, are limited to five attempts, and any earlier unused code is retired the moment a new one is issued.
- Every write in the app is checked against the signed-in user's permissions and their branch scope on the server, not only in the browser.
- Databases are backed up daily. The backup of our configuration secrets is encrypted with AES-256 before it is written, and the plain copy is shredded. Backups are kept for ninety days and then deleted.
- Staff access to customer data goes through an audited impersonation route that records who, which workspace, and why.
We are a small company and we will not pretend otherwise: we hold no ISO 27001 or SOC 2 certificate today, and we will not claim one. What we will do is answer a specific security question specifically, and let a prospective customer's security team ask.
09How long we keep it
The honest general rule: while your account is live, we keep your data so the product works. When it ends, we delete it.
- A live workspace. Kept for as long as the subscription runs.
- After termination. Your workspace stays available for export for thirty days after the subscription ends. After that we delete the database. It disappears from the backups within the following ninety days as those roll off. The Terms say the same thing, and bind us to it.
- Sign-in codes. Ten minutes, then dead. The hash of a used code is retained in the sign-in log.
- Sign-in and audit records. Kept for the life of the workspace, because they are the evidence of who did what. They go when the workspace goes.
- Enquiries from this website. Kept while we are talking to you and while there is a reasonable prospect of doing business. Email us and we will delete yours; we do not need a reason from you.
- Invoices and accounting records. Kept for as long as Indian tax and company law requires, which is longer than the account itself. We cannot delete these on request.
For personal data held on an operator's behalf, the operator sets the retention period and can ask us to delete specific records at any time. We do not delete an operator's records on our own judgement.
10Your rights, and exactly how to use them
Under the DPDP Act, as a Data Principal you have the right to:
- Get a summary of your data and how it is processed [s.11], including who we have shared it with.
- Have it corrected, completed, updated or erased [s.12].
- Have a working way to complain to us before you go anywhere else [s.13].
- Nominate someone to exercise these rights for you if you die or become incapacitated [s.14].
- Withdraw consent at any time, as easily as you gave it [s.6(4)–(6)]. Withdrawing it does not undo what was lawfully done before, and it will usually mean we can no longer provide the account.
How to ask
Email contact@sehsaa.com with the word Privacy in the subject, from the email address the account uses, and say what you want. If you cannot use that address, tell us and we will find another way to establish that the request is really yours — we ask because handing your data to someone impersonating you would be the worse failure.
Tell us, if you can, which coworking space is involved. It decides whether the request is ours to answer or theirs.
What happens then
We acknowledge within three working days and aim to complete within thirty days. The outer limit set by the DPDP Rules for responding to a grievance is ninety days from receipt, and we will not use the full ninety days as a default.
If your request concerns data held inside a coworking space's own workspace, we are the processor, not the fiduciary: we will pass the request to that operator, tell you we have done it and who they are, and then help them carry it out. We will not make the change ourselves without their instruction.
If we get it wrong
Take it to our Grievance Officer in section 14 first — that is what they are there for, and the Act expects that route to be exhausted first [s.13]. If you are still not satisfied, you can complain to the Data Protection Board of India.
11Children
Atrium is business software sold to companies. It is not intended for anyone under 18, and we do not knowingly collect a child's personal data as a Data Fiduciary. We do not do behavioural monitoring or targeted advertising at all, so the specific prohibitions in section 9 of the Act do not arise in our own processing.
An operator who runs a space where minors are present — a student campus, a family visit at the front desk — is the Data Fiduciary for that record, and the Act's requirement for verifiable parental consent falls on them. If you are in that position, talk to us before switching on visitor photographs.
12If something goes wrong
If personal data in our care is breached, we will tell the affected people and the Data Protection Board of India, in the form and within the time the DPDP Rules require — intimation without delay, and a detailed report to the Board within 72 hours of becoming aware.
Where the breach touches data we hold for an operator, we will notify that operator without undue delay and give them what they need to make their own notifications, since the obligation to notify their members is theirs. We will not wait for a complete forensic picture before telling you something happened.
13Changes to this notice
When we change this page we change the version and the date at the top. If a change materially affects what we do with your personal data — a new sub-processor, a new purpose, a shorter or longer retention — we will email account owners before it takes effect rather than relying on you to re-read the page.
Previous versions are available on request.
14Grievance Officer
Section 8(9) of the DPDP Act requires us to publish the business contact information of a person who can answer your questions about how your personal data is processed, and section 8(10) requires a mechanism that actually redresses grievances. This is both.
Grievance Officer, Sehsaa Solutions Private Limited
- Name
- Jeet
- Designation
- Chief Executive Officer
- contact@sehsaa.com — put Grievance in the subject
- +91 93725 21198
- Post
- Block No. 23, Kotkar Industrial Estate, Off Aarey Road, Goregaon East, Mumbai, Maharashtra 400063
- Hours
- Monday to Friday, 10:00 to 18:00 IST, excluding public holidays in Maharashtra
A complaint is acknowledged within three working days and answered within thirty days wherever we can, and in any case within the ninety days the Rules allow. If we cannot do what you asked, we will tell you why in writing rather than let it lapse.
15The signup notice, in full
The DPDP Act requires that a request for consent be accompanied by a notice that itemises what is being collected and what for, in plain language, with a way to reach us and a way to complain [s.5]. This is that notice, reproduced here so it can be read at leisure rather than at the moment of signing up.
When you sign up for Atrium, Sehsaa Solutions Private Limited collects:
your work email address and WhatsApp number, to send you a six-digit sign-in code, to identify your account when you return, and to contact you about it; and — if you go on to create a workspace — your full name, the name of your coworking space, its short name and your city, to create and label that workspace and to make you its owner.
We do not use any of it for advertising, we do not sell it, and we do not pass it to anyone except the sub-processors listed in section 6 of this notice.
You can withdraw your consent, or ask us to correct or erase this data, at any time by emailing contact@sehsaa.com. Withdrawing consent means we can no longer keep the account open. You can complain to our Grievance Officer, and after that to the Data Protection Board of India.
Personal data that an operator later enters about their own members and visitors is not covered by that consent and is not ours to consent to. It is covered by the Data Processing Addendum.