This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Platform Terms of Use & Services Agreement between Atlas and the Manager (the "Agreement"). It governs Atlas's Processing of Manager Personal Data on the Manager's behalf in connection with the Services. Capitalized terms not defined here have the meanings given in the Agreement. If there is a conflict between this DPA and the rest of the Agreement solely with respect to the Processing of Personal Data, this DPA controls.
1. Definitions
- "Applicable Data Protection Laws" means all privacy and data protection laws applicable to the Processing of Manager Personal Data under this DPA, including, as applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and other U.S. state privacy laws, and the EU General Data Protection Regulation and the UK GDPR (together, "GDPR").
- "Controller," "Processor," "Data Subject," "Personal Data," and "Processing" have the meanings given under Applicable Data Protection Laws; "Controller" includes "Business," and "Processor" includes "Service Provider," as those terms are used under the CCPA/CPRA.
- "Manager Personal Data" means Personal Data that Atlas Processes on the Manager's behalf under the Agreement, including Inquiry Data and Engagement Data (as defined in the Agreement) that identifies or relates to an identified or identifiable individual, such as an Advisor's name, firm, and engagement activity captured through an Advisor Link.
- "Sub-processor" means any third party engaged by Atlas to Process Manager Personal Data.
- "Security Incident" means a breach of Atlas's security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Manager Personal Data Processed by Atlas.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission for the transfer of Personal Data to processors established in third countries, and, for the United Kingdom, the UK International Data Transfer Addendum.
2. Roles of the Parties
As between the parties, with respect to Manager Personal Data the Manager is the Controller (Business) and Atlas is the Processor (Service Provider) acting on the Manager's behalf. Each party will comply with its respective obligations under Applicable Data Protection Laws. This DPA does not apply to data that Atlas Processes as a Controller for its own business purposes (such as Atlas's own account administration, billing, security, and product analytics), which is governed by the Atlas Privacy Policy.
↑ Top3. Manager Obligations and Warranties
This Section is material to Atlas's agreement to provide the Services and to the allocation of responsibility between the parties.
The Manager represents, warrants, and covenants, on a continuing basis, that:
- It is and will remain solely responsible for the accuracy, quality, integrity, and legality of Manager Personal Data and for the means by which it acquired that data.
- It has provided all notices to, and has obtained and will maintain all rights, lawful bases, authorizations, and consents from, the relevant Data Subjects that are required for Atlas to Process Manager Personal Data as contemplated by the Agreement and this DPA. This includes, without limitation, any relationship, notice, or consent required to generate and send an Advisor Link to a given Advisor and to track, measure, and score that Advisor's engagement.
- Its instructions to Atlas for the Processing of Manager Personal Data, including through its configuration and use of the Services, will comply with Applicable Data Protection Laws, and the Manager is solely responsible for those instructions.
- It will not provide to, or cause Atlas to Process, any "special categories" of Personal Data, government identifiers, financial-account credentials, or Personal Data of children, and will not use the Services to Process Personal Data in any manner that would require Atlas to obtain any registration or license or that is inconsistent with the Agreement.
- It will fulfill its own obligations as Controller, including responding to Data Subject rights requests and providing required privacy notices, except to the extent expressly assumed by Atlas under this DPA.
4. Atlas Obligations
- Processing on instructions. Atlas will Process Manager Personal Data only on the Manager's documented instructions — which the parties agree consist of the Agreement, this DPA, and the Manager's use and configuration of the Services — and as required to provide the Services, unless Processing is required by law, in which case Atlas will (where legally permitted) inform the Manager. Atlas will inform the Manager if, in Atlas's opinion, an instruction infringes Applicable Data Protection Laws; Atlas may suspend Processing of, or decline, an instruction it reasonably believes to be unlawful, and has no liability for doing so.
- Confidentiality. Atlas will ensure that personnel authorized to Process Manager Personal Data are bound by appropriate confidentiality obligations.
- Security. Atlas will implement and maintain appropriate technical and organizational measures designed to protect Manager Personal Data against a Security Incident, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as further described in Annex B. The Manager is responsible for its own use of the Services, including securing its account credentials and configuring available controls, and for the security of any Manager systems.
- Sub-processors. The Manager provides general authorization for Atlas to engage Sub-processors to Process Manager Personal Data. A current list is set out in Annex C. Atlas will impose data-protection obligations on each Sub-processor that are materially no less protective than those in this DPA, and will remain responsible for each Sub-processor's compliance with such obligations. Atlas will give the Manager notice (which may be by updating Annex C or by email) before adding or replacing a Sub-processor; the Manager may object on reasonable, good-faith data-protection grounds within fifteen (15) days, and if the parties cannot resolve the objection, the Manager's sole remedy is to terminate the affected Services and receive a pro-rated refund of any pre-paid, unused fees.
- Assistance. Taking into account the nature of the Processing and the information available to Atlas, Atlas will provide reasonable assistance to the Manager, at the Manager's expense for any non-trivial assistance, with: (a) responding to verified Data Subject rights requests that Atlas cannot fulfill through the self-service functionality of the Services; (b) the security of Processing and notification of Security Incidents; and (c) data protection impact assessments and prior consultations with supervisory authorities. Where Atlas receives a request directly from a Data Subject regarding Manager Personal Data, Atlas will not respond except to acknowledge and refer the request to the Manager, unless legally required to do otherwise.
- Security Incident notification. Atlas will notify the Manager without undue delay after becoming aware of a Security Incident affecting Manager Personal Data and will provide information then reasonably available to assist the Manager in meeting its own obligations. Atlas's notification or response is not an acknowledgment by Atlas of any fault or liability. The Manager is responsible for any notifications to Data Subjects, regulators, or others that it is required to make.
- Deletion or return. On termination or expiry of the Agreement, Atlas will, at the Manager's election and within a commercially reasonable period, delete or return Manager Personal Data in Atlas's possession, and delete existing copies, except to the extent retention is required by law or is contained in routine backups (which Atlas will delete or de-identify in the ordinary course) or in aggregated or de-identified form. Atlas will confirm deletion in writing on request.
- Records and audits. Atlas will maintain records of its Processing and, on the Manager's reasonable written request (no more than once in any twelve-month period, on at least thirty (30) days' notice), make available information reasonably necessary to demonstrate compliance with this DPA. Any audit is subject to reasonable scope, time, and confidentiality restrictions, will not include access to other customers' data or to Atlas confidential or security-sensitive information, will be conducted at the Manager's cost during business hours in a manner that does not disrupt Atlas's operations, and may be satisfied by Atlas providing its then-current third-party audit reports, certifications, or completed security questionnaires.
5. CCPA / CPRA Service-Provider Terms
To the extent the CCPA/CPRA applies, Atlas is a Service Provider. Atlas will not: (a) sell or share Manager Personal Data (as "sell" and "share" are defined under the CCPA/CPRA); (b) retain, use, or disclose Manager Personal Data for any purpose other than the business purpose of providing the Services specified in the Agreement, or as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose Manager Personal Data outside the direct business relationship between the parties; or (d) combine Manager Personal Data with Personal Data received from or on behalf of another person, except as permitted by the CCPA/CPRA. Atlas certifies that it understands and will comply with these restrictions. The Manager may take reasonable and appropriate steps to help ensure that Atlas uses Manager Personal Data in a manner consistent with the Manager's obligations under the CCPA/CPRA, and to stop and remediate any unauthorized use.
↑ Top6. International Transfers
Where Atlas Processes Manager Personal Data protected by the GDPR and transfers it to a country that has not received an adequacy decision, the parties agree that the applicable module of the Standard Contractual Clauses (controller-to-processor) is incorporated into this DPA by reference and completed by the details in the Annexes, with Atlas as "data importer" and the Manager as "data exporter." The UK International Data Transfer Addendum and equivalent Swiss requirements apply where relevant. Atlas may adopt an alternative lawful transfer mechanism, in which case that mechanism will apply in place of the SCCs to the extent valid under Applicable Data Protection Laws.
↑ Top7. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits any liability that cannot be limited or excluded under Applicable Data Protection Laws.
↑ Top8. Indemnification
The Manager will defend, indemnify, and hold harmless Atlas and its members, officers, employees, agents, and Sub-processors from and against any claims, losses, liabilities, damages, costs, and reasonable attorneys' fees arising out of or relating to (a) the Manager's breach of Section 3 or of its obligations or warranties under this DPA or Applicable Data Protection Laws, (b) any instruction from the Manager, or (c) the Manager's collection, use, or transfer of Manager Personal Data (including any Advisor Link it sends), except to the extent finally determined to result directly from Atlas's breach of this DPA.
↑ Top9. Term; Conflicts; Changes
This DPA takes effect on the Manager's acceptance of the Agreement and remains in effect for as long as Atlas Processes Manager Personal Data; provisions that by their nature should survive will survive termination. Atlas may update this DPA to reflect changes in Applicable Data Protection Laws, guidance, or Atlas's Sub-processors or practices, and will provide notice of material changes as set out in the Agreement. Except as stated in this DPA, the Agreement remains in full force and effect; this DPA is governed by, and construed under, the governing law and dispute-resolution terms of the Agreement.
↑ TopAnnex A — Details of Processing
- Subject matter: Atlas's provision of the Services to the Manager.
- Duration: the term of the Agreement, plus any legally required or routine-backup retention period.
- Nature and purpose: hosting and operating the Services; routing Advisor inquiries to the Manager; and, through Advisor Links, measuring and attributing Advisor engagement with the Manager's own content and computing engagement indicators for the Manager's use.
- Types of Personal Data: business contact details (name, firm, email/phone) of Advisors and prospects; the content of their inquiries; and engagement events associated with an identified Advisor (page visits, video plays and completions, downloads, comparisons, conversation requests) and derived Engagement Scores and levels.
- Categories of Data Subjects: financial professionals ("Advisors") and other business prospects who interact with the Manager through the Services.
- Sensitive data: none is intended or permitted to be Processed.
Annex B — Technical and Organizational Security Measures
Atlas maintains a security program with measures appropriate to the risk, which include, without limitation: encryption of Personal Data in transit over public networks and, where supported by Atlas's infrastructure providers, at rest; access controls based on least privilege and unique credentials, with administrative access restricted to authorized personnel; authenticated sign-in for the Services; logical separation of customer data in Atlas's multi-tenant environment, including row-level access restrictions that limit each Manager to its own data; use of reputable infrastructure Sub-processors that maintain recognized security practices; monitoring and logging; routine backups; a documented incident-response process; personnel confidentiality obligations; and periodic review of these measures. Atlas may update these measures provided the level of protection is not materially reduced.
↑ TopAnnex C — Sub-processors
As of the "Last updated" date above, Atlas uses the following Sub-processors to Process Manager Personal Data:
- Netlify, Inc. — website and form hosting, delivery, and DNS (United States).
- Supabase, Inc. — application database and authentication, including storage of engagement events and Advisor Link records (United States).
- Stripe, Inc. — payment processing for Manager subscriptions (United States). Stripe acts as an independent controller of payment data under its own terms.
- Resend (Plumb Software, Inc.) — transactional and sign-in email delivery (United States).
Atlas will update this Annex when it adds or replaces a Sub-processor, consistent with Section 4.4.
How to reach us. Data-protection questions or requests under this DPA: info@atlassignalis.com.