COMPLIANCEDPA prelight.ai

Data processing, in plain terms.

Data processing addendum · Updated 1 October 2026 · Signed before any file moves.

Roles

You are the controller of the brand materials you send us. We are the processor. We process only on your documented instructions — to build and serve your record, and for nothing else.

Scope

Personal data can reach us in two ways: inside the assets and agreements you point Atlas at — model releases, contact blocks in a contract — and in account and usage data. Both are covered by this addendum.

Security measures

As published on the Security page: tenant isolation, scoped access with OAuth, logged transactions with the rule applied and the date, retention windows and legal hold. ISO 27001 targeted for Q1 2027.

Sub-processors

Listed on request. Sub-processors change only with advance notice, with a right to object — it is in the contract.

International transfers

Records are hosted in the EU and USA. Where a transfer needs a mechanism, it travels under the Standard Contractual Clauses.

Breach notification

We notify you without undue delay, and within 72 hours of becoming aware of a breach affecting your data — with what happened, what data is involved, and what we are doing about it.

Assistance

Help with data-subject requests, audits and impact assessments, on request. The decision trail usually answers first; when it cannot, we do.

Deletion and return

On termination: full export in an open format, and hard deletion on request, with written confirmation. A record you cannot remove is a record you should not trust.

Read next Privacy Security