Data processing, in plain terms.
Roles
You are the controller of the brand materials you send us. We are the processor. We process only on your documented instructions — to build and serve your record, and for nothing else.
Scope
Personal data can reach us in two ways: inside the assets and agreements you point Atlas at — model releases, contact blocks in a contract — and in account and usage data. Both are covered by this addendum.
Security measures
As published on the Security page: tenant isolation, scoped access with OAuth, logged transactions with the rule applied and the date, retention windows and legal hold. ISO 27001 targeted for Q1 2027.
Sub-processors
Listed on request. Sub-processors change only with advance notice, with a right to object — it is in the contract.
International transfers
Records are hosted in the EU and USA. Where a transfer needs a mechanism, it travels under the Standard Contractual Clauses.
Breach notification
We notify you without undue delay, and within 72 hours of becoming aware of a breach affecting your data — with what happened, what data is involved, and what we are doing about it.
Assistance
Help with data-subject requests, audits and impact assessments, on request. The decision trail usually answers first; when it cannot, we do.
Deletion and return
On termination: full export in an open format, and hard deletion on request, with written confirmation. A record you cannot remove is a record you should not trust.