Legal
AtlasXT Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between AtlasXT LLC (“AtlasXT”) and the applicable customer (“Customer”) governing Customer’s use of the AtlasXT Services.
This DPA applies where AtlasXT processes Personal Data on behalf of Customer and applicable data-protection law requires the parties to enter into a data-processing agreement.
1. Definitions
“Applicable Data Protection Law” means laws and regulations governing the processing of Personal Data applicable to the parties or processing activities.
“Controller” means the entity that determines the purposes and means of processing Personal Data.
“Processor” means an entity that processes Personal Data on behalf of a Controller.
“Personal Data” means information protected as personal data, personal information, or a substantially similar term under Applicable Data Protection Law.
“Processing” means any operation performed on Personal Data.
“Subprocessor” means a third party engaged by AtlasXT to process Personal Data on AtlasXT’s behalf in connection with the Services.
2. Roles of the Parties
For Customer Data processed through the Services on Customer’s behalf:
- Customer acts as Controller or equivalent;
- AtlasXT acts as Processor or equivalent.
AtlasXT will process Personal Data only:
- according to Customer’s documented instructions;
- to provide the Services;
- to perform functions requested by Customer;
- to maintain security;
- to prevent fraud and abuse;
- to comply with applicable law; or
- for other purposes expressly permitted under the agreement.
3. Customer Instructions
Customer instructs AtlasXT to process Personal Data as reasonably necessary to provide:
- SaaS functionality;
- hosting;
- storage;
- workflows;
- dashboards;
- reporting;
- integrations;
- authentication;
- Google Sheets importing;
- customer support;
- diagnostics;
- security;
- backup and recovery;
- optional user-initiated AI functionality; and
- other functionality requested through the Services.
4. Customer Responsibilities
Customer is responsible for:
- establishing a lawful basis for processing;
- providing required notices;
- obtaining required consents;
- ensuring appropriate permissions;
- configuring the Services;
- managing users and administrators;
- responding to Data Subject requests where Customer is responsible;
- determining appropriate retention periods; and
- complying with Applicable Data Protection Law.
Utah law, where applicable, requires processors to follow controller instructions and assist controllers with specified obligations, including security and breach-related obligations.
5. Categories of Personal Data
Depending on Customer’s use of the Services, Personal Data may include:
- names;
- email addresses;
- telephone numbers;
- business contact information;
- job titles;
- organization information;
- account identifiers;
- user-generated content;
- relationship information;
- project information;
- notes;
- communications;
- spreadsheet information;
- authentication information;
- technical information; and
- usage information.
6. Categories of Data Subjects
Data Subjects may include:
- employees;
- contractors;
- customers;
- prospects;
- vendors;
- business partners;
- users;
- contacts; and
- other individuals whose information Customer submits to the Services.
7. Nature and Purpose of Processing
AtlasXT may perform the following types of processing:
- collection;
- storage;
- organization;
- retrieval;
- transmission;
- display;
- synchronization;
- import;
- export;
- security monitoring;
- troubleshooting;
- backup;
- recovery; and
- deletion.
Processing is performed to provide and support the Services.
8. Confidentiality
AtlasXT will require personnel authorized to process Customer Personal Data to maintain confidentiality obligations appropriate to their role.
9. Security
AtlasXT maintains reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized or unlawful access, use, alteration, destruction, loss, or disclosure.
Safeguards may include:
- access controls;
- authentication;
- authorization;
- least-privilege practices;
- credential management;
- logging;
- monitoring;
- backup procedures;
- incident response procedures;
- security procedures;
- secure development practices; and
- confidentiality obligations.
10. Subprocessors
Customer authorizes AtlasXT to use Subprocessors reasonably necessary to provide the Services.
AtlasXT’s current principal service providers include:
- Amazon Web Services;
- Google;
- Twilio;
- SendGrid;
- OpenRouter and applicable model providers;
- Microsoft Entra ID or another customer-selected identity provider; and
- Logflare.
The applicable service provider may vary depending on which AtlasXT functionality Customer uses.
AtlasXT will require applicable Subprocessors to maintain appropriate obligations concerning confidentiality and protection of Personal Data.
AtlasXT remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
11. Google Data
Google data is processed only for authorized functionality.
AtlasXT’s Google Sheets integration is read-only.
AtlasXT does not use the integration to modify or delete source Google Sheets.
Imported Google data may become Customer Data and may be stored within AtlasXT.
OAuth credentials may be stored as reasonably necessary to maintain the authorized integration.
AtlasXT will comply with applicable Google API policies concerning Google user data.
12. AI Processing
AI processing is optional and user-initiated.
When a user intentionally invokes an AI feature, AtlasXT may transmit selected Customer Data to OpenRouter and the applicable AI model provider.
AtlasXT does not transmit all Customer Data to AI providers merely because that information is stored in AtlasXT.
13. Data Subject Requests
Where required by Applicable Data Protection Law, AtlasXT will provide reasonable assistance to Customer in responding to Data Subject requests relating to processing performed by AtlasXT.
Customer remains responsible for determining whether and how a request must be fulfilled.
14. Security Incidents
“Security Incident” means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Customer Personal Data within AtlasXT’s systems, excluding unsuccessful attempts that do not result in unauthorized access.
AtlasXT will maintain reasonable procedures designed to detect, investigate, contain, mitigate, and remediate Security Incidents.
Where required by Applicable Data Protection Law, AtlasXT will notify Customer without undue delay after confirming a Security Incident involving Customer Personal Data.
To the extent reasonably available and legally permissible, the notification may include:
- a description of the incident;
- the categories of information involved;
- known or reasonably suspected effects; and
- mitigation measures taken or planned.
Customer is responsible for determining whether it must notify regulators or affected individuals.
15. Government Requests
AtlasXT may disclose Personal Data when required by law, subpoena, court order, or other legally valid process.
Where legally permitted, AtlasXT will provide reasonable notice to Customer and reasonably cooperate with Customer’s efforts to challenge or limit the disclosure.
16. International Transfers
Personal Data may be processed in the United States and other jurisdictions where AtlasXT or its service providers operate.
Where required by Applicable Data Protection Law, the parties will use an appropriate legal mechanism for the transfer.
17. Deletion and Return
Upon termination of the Services, AtlasXT will delete or return Customer Personal Data in accordance with the applicable agreement and Customer’s reasonable request, subject to legal and operational requirements.
AtlasXT may retain information where necessary for:
- legal obligations;
- security;
- fraud prevention;
- dispute resolution;
- legal holds;
- backup systems;
- accounting;
- enforcement; or
- other lawful purposes.
Backup copies may remain until removed through ordinary backup procedures.
18. Audits and Compliance Information
Where required by Applicable Data Protection Law, AtlasXT will make available reasonable information necessary to demonstrate compliance with applicable processor obligations.
Where appropriate, AtlasXT may satisfy reasonable audit requests through:
- security documentation;
- questionnaires;
- policies;
- certifications;
- third-party reports;
- summaries of controls; or
- other appropriate documentation.
Audits must:
- be conducted with reasonable notice;
- occur during normal business hours;
- minimize disruption;
- protect confidential information;
- protect other customers; and
- not compromise the security of AtlasXT or other customers.
19. Data Protection Impact Assessments
Where required by Applicable Data Protection Law, AtlasXT will provide reasonable assistance concerning Customer’s data protection impact assessments to the extent that the assistance relates to processing performed by AtlasXT.
20. Regulated Data
Customer will not provide information requiring specialized controls unless AtlasXT has expressly agreed in writing to provide those controls.
21. HIPAA
Unless AtlasXT and Customer have executed a separate Business Associate Agreement, AtlasXT is not acting as a HIPAA Business Associate.
Customer must not submit Protected Health Information to AtlasXT for processing on behalf of a Covered Entity or Business Associate unless expressly authorized in writing.
22. Government and Industry Certifications
AtlasXT does not represent that it is SOC 2, ISO 27001, FedRAMP, StateRAMP, FISMA, HIPAA, or otherwise certified unless AtlasXT expressly states such certification in a written agreement or official AtlasXT documentation.
23. Conflict
If this DPA conflicts with the Terms concerning the processing of Personal Data, this DPA controls with respect to that conflict.
24. Liability
The liability provisions of the applicable agreement govern this DPA unless expressly modified by a written agreement signed by the parties.
25. Duration
This DPA remains effective for as long as AtlasXT processes Personal Data on behalf of Customer.