Data Processing Addendum (DPA)
Last updated: August 14, 2026
1. Object & Scope of Processing
This Data Processing Addendum ("DPA") applies to the processing of personal data uploaded by users to the Atlas interface. It forms an integral part of the Terms of Service between Atlas Knowledge Systems, Inc. and the customer, regulating data protection compliance in accordance with GDPR, UK GDPR, and other applicable laws.
2. Controller & Processor Roles
The user acts as the Data Controller, specifying document scopes and query directions. Atlas acts as the Data Processor, carrying out automated document extraction, text vectorization, similarity searching, and prompt mapping instructions exclusively on behalf of and according to instructions from the Controller.
3. Technical & Organizational Measures
Atlas implements robust security frameworks, including tenant-isolated vector namespaces, HTTPS transit layers, encrypted document storage, multi-factor authorization systems, and strict log controls. Our team does not manually read customer data unless authorized for technical support.
4. Subprocessors
The Controller agrees that the Processor may engage third-party subprocessors to perform data hosting, database indexing, and AI model inference functions. A current list of subprocessors (including secure cloud providers, vector database hosting platforms, and selected AI endpoints) is maintained and can be provided upon request.
5. Security Incident Notification
In the event of a verified physical or logical security breach affecting personal data processed within the Atlas tenant buckets, the Processor will notify the Controller without undue delay (and in any case, within 72 hours) and provide assistance to mitigate risks.
Corporate Execution
Corporate clients requiring signed Standard Contractual Clauses (SCCs) or a signed copy of this DPA can execute it by contacting our compliance desk at atlas.document.interface@gmail.com.