Legal
Privacy Policy
Last updated August 2026. Promatics Technologies Inc. operates Attergo.
Attergo handles two distinct categories of information and treats them differently. Information about you as a visitor or customer contact is ordinary business data. Information about patients is protected health information that belongs to the provider we serve; we process it solely on that provider's instructions, under a business associate agreement.
We do not sell either category. We do not use patient information to train models for third parties, and we do not use it for advertising.
Information we collect
From this website
This site is static and carries no analytics, advertising or tracking scripts. If you email us, we receive what you chose to include and retain it to respond and to keep a record of the correspondence.
From customers using the platform
Account information: names, work email addresses, roles and authentication credentials. Credentials are stored hashed, never in a readable form.
On behalf of customers
Prescription, dispensing, claim and remittance events published by a customer's own systems, which may contain protected health information. These arrive because the customer directed their system to send them, and we hold them as a business associate.
How we use it
To provide the service the customer purchased: computing margin, detecting documentation gaps, assembling audit evidence, and the functions of the products they operate. To keep the service secure and available. To support the customer. To meet legal obligations.
We may use aggregated, de-identified information to improve the platform. De-identified means it cannot reasonably identify a patient or a customer; we do not re-identify it and do not permit anyone else to.
Protected health information never reaches our logs
This is enforced in code. The platform maintains a registry of fields treated as protected health information, a redactor that strips them from anything written to a log, and an automated build check that fails a release if a registry field is passed to a logging call. Diagnostics identify records, never people. Access to patient information within the platform is recorded to an append-only access log.
How we protect it
Information is encrypted in transit and at rest. Separation between customers is enforced by the database through row-level security, so an application defect cannot expose one customer's data to another. Access within our team is limited to those who operate the service.
If we discover a breach affecting your information, we notify you promptly and within every timeframe the law and our agreement with you require.
Who we share it with
Service providers who help us run the platform, such as hosting and email delivery, each bound by confidentiality and, where they may touch protected health information, by a business associate agreement. Payers, clearinghouses and other recipients where the customer directs transmission on their behalf. Authorities where the law compels disclosure, in which case we inform the customer unless legally prohibited.
We do not sell personal information or protected health information.
How long we keep it
The raw event archive is retained for a minimum of ten years: it is the record that answers an audit years after a fill, and that horizon is the reason it exists. Account and contact information is kept while the relationship is active and as long afterwards as legal and accounting obligations require. On termination, customers receive a complete export, including the raw archive.
Your rights
If you are a patient, your rights in your health information run through your provider, the covered entity that controls the record. Contact them; we support their response. If you are a customer contact or a visitor, you may request a copy of the information we hold about you, its correction, or its deletion, subject to records we are required to retain. Write to privacy@attergo.com.
Changes
Material changes to this policy are notified to customers in advance.
Contact
Privacy: privacy@attergo.com. Security reports: security@attergo.com.