Legal

Data Processing Agreement

Last updated:

This English text is a translation, provided for convenience. The Romanian version is the legally binding one: read it in Romanian.

This agreement (the “DPA”) is an annex to the Atlas Terms of Service and forms part of the Contract between the Customer and Farcaș Mihai Cristian Persoană Fizică Autorizată (the “Provider”). It governs the processing of personal data that the Provider carries out on behalf of the Customer, under Article 28 of Regulation (EU) 2016/679 (the “GDPR”). The DPA applies automatically with the Contract. A signed version is available on request.

1. Definitions and roles

1.1. Terms used here have the meaning given in the GDPR and in the Terms. “Customer Data” means the personal data in Customer Content (documents, workspaces, questions, conversations and answers) that the Provider processes on behalf of the Customer.

1.2. For Customer Data, the Customer is the controller and the Provider is the processor. For account data and for security, billing and communication data, the Provider is an independent controller, as set out in the Privacy Policy.

2. Subject matter and details of the processing

The subject matter, duration, nature and purpose of the processing, the types of data and the categories of data subjects are described in Annex 1.

3. The Customer’s instructions

3.1. The Provider processes Customer Data only on the Customer’s documented instructions, including with regard to international transfers. The instructions are the Contract and the way the Customer and its Users use the Service. Additional instructions are given in writing.

3.2. The exception is processing required by Union or Romanian law. In that case the Provider informs the Customer before processing, unless the law prohibits it.

3.3. The Provider immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection provisions.

3.4. The Customer is responsible for the lawfulness of the processing: the legal basis, informing the data subjects and its right to upload the documents to the Service.

4. Confidentiality

The Provider ensures that persons authorised to process Customer Data have committed to confidentiality or are under an appropriate statutory obligation. Staff access to Customer Data is limited to the cases in 6.6 of the Terms: running the Service, support at the Customer’s request, security and legal obligations.

5. Security of processing

5.1. The Provider applies the technical and organisational measures in Annex 2, under Article 32 GDPR.

5.2. The Provider may update the measures as technology evolves, without lowering the overall level of protection.

6. Subprocessors

6.1. The Customer gives general authorisation for the subprocessors listed on the Subprocessors page (Annex 3).

6.2. The Provider imposes on each subprocessor, by contract, data-protection obligations at least equivalent to those in this DPA. The Provider remains liable to the Customer for its subprocessors’ performance.

6.3. The Provider notifies the Customer by email of any new or replacement subprocessor at least 30 days in advance. Within that period, the Customer may object on reasonable data-protection grounds. If the parties cannot find a solution, the Customer may end the Contract, with a refund of amounts prepaid for the unused period.

7. International transfers

The Provider transfers Customer Data outside the European Economic Area only in compliance with Chapter V GDPR. The grounds are an adequacy decision (including the EU–U.S. Data Privacy Framework, for certified recipients) or the standard contractual clauses of Decision (EU) 2021/914, with supplementary measures where needed. The Customer authorises transfers to the subprocessors in Annex 3 on those terms.

8. Assistance to the Customer

8.1. Data subject requests. The Provider forwards to the Customer, without undue delay, any requests it receives from data subjects, and does not answer them directly unless the Customer authorises it. The Service lets the Customer delete documents, workspaces and conversations. For other requests, such as access or export, the Provider assists within timeframes that let the Customer reply within the legal deadline.

8.2. Other obligations. The Provider helps the Customer meet its obligations under Articles 32–36 GDPR (security, breach notification, impact assessment and prior consultation), taking into account the nature of the processing and the information available to it.

9. Personal data breaches

9.1. The Provider notifies the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Data.

9.2. The notification includes, as far as available, the information in Article 33(3) GDPR. Information not available immediately is provided as it becomes available.

9.3. The Provider takes immediate measures to contain the breach and cooperates with the Customer.

10. Deletion and return of data

10.1. During the Contract.

  • Deleting a document removes the file, the extracted text and its entries in the search index.
  • Deleting a workspace removes all of its documents.
  • Deleting a conversation removes its messages.

Every deletion is recorded in a ledger. An automated process, run every 15 minutes, completes the deletion wherever data remains and retries until it succeeds: the search index, the files, the document’s caches and the conversion kept by Mathpix (Mathpix confirms the deletion by no longer serving the result). The ledger shows, for each document, when deletion was requested and when it completed.

To avoid reprocessing, the Service also keeps technical copies derived from content: numerical representations of passages and short descriptions generated for formulas and figures. They are identified only by a fingerprint (hash) of the content, not linked to an account or a workspace, and are deleted automatically 30 days after they were created.

10.2. When the Contract ends. The Customer can export its data during the transition and retrieval periods in section 11 of the Terms. After that, the Provider deletes all Customer Data from its systems, including copies, within 30 days, and asks its subprocessors to delete copies that are not deleted automatically. Data that Union or Romanian law requires to be kept is excepted. Technical logs are deleted through their normal rotation. On request, the Provider confirms the deletion in writing.

10.3. Data held by subprocessors. Subprocessors keep the data they receive under their contracts with the Provider. What each one keeps is described in Annex 3. Right after a document is processed, the Provider keeps the figure images with the document and asks Mathpix to delete the conversion, through the same automated process as in 10.1.

11. Information and audits

11.1. The Provider makes available to the Customer the information needed to demonstrate compliance with Article 28 GDPR.

11.2. The Customer may carry out an audit, or have it carried out by an independent auditor bound by confidentiality, at most once a year. Audits required by a supervisory authority or prompted by a personal data breach are excepted from this limit.

11.3. An audit is announced at least 30 days in advance, takes place during business hours without compromising other customers’ security, and is at the Customer’s expense.

12. Term, liability and precedence

12.1. This DPA applies for as long as the Provider processes Customer Data.

12.2. The parties’ liability is as set out in the Terms, except where the GDPR does not allow it to be limited.

12.3. For data protection, this DPA prevails over the Terms. It is governed by Romanian law.


Annex 1 — Description of the processing

Subject matter. Hosting the Customer’s documents, converting them to text, indexing them, searching them and generating AI answers with citations to the documents.

Duration. The term of the Contract, plus the transition, retrieval and deletion periods in section 11 of the Terms.

Nature of the processing.

  • storing the documents;
  • recognising text (OCR), formulas and tables;
  • structuring documents into passages;
  • computing the numerical representations used for search;
  • searching and ranking results;
  • generating answers, titles and descriptions of formulas and figures;
  • displaying the documents and deleting data.

Purpose. Providing the Service to the Customer and its Users.

Data subjects.

  • the Customer’s Users;
  • people whose data appears in the documents the Customer uploads, for example the Customer’s employees, clients, suppliers or contractors, or the documents’ authors.

Types of data.

  • identification and contact data in conversations and documents;
  • the content of questions and answers;
  • any other personal data the Customer chooses to include in documents.

Special categories of data. None are foreseen. The Customer does not upload such data without the Provider’s prior agreement (section 6.5 of the Terms).

Annex 2 — Technical and organisational measures

Encryption in transit. All traffic uses HTTPS (TLS), with one-year HSTS. Communication with the AI providers uses HTTPS APIs.

Authentication and sessions.

  • Passwords are stored only as Argon2 hashes.
  • The session uses a signed token kept in an HTTP-only, Secure, SameSite=Lax cookie, valid for 14 days.
  • Sign-in attempts are rate-limited by IP address.
  • Password-reset links are single-use.

Access control.

  • Every request is authorised at workspace level.
  • Every search is filtered by workspace inside the vector database itself, so other customers’ passages cannot be results.
  • The application’s admin role is reserved for the Provider by configuration. It manages accounts and sees only document metadata (name, size, processing status) and aggregate figures. It cannot open documents, see conversations or their titles, or set a user’s password.
  • Only a small number of the Provider’s administrators have access to the infrastructure.

Network and infrastructure.

  • The database, search index and processing queue listen only locally, and only the web server is exposed to the internet (ports 80 and 443).
  • The API and background workers run in containers as an unprivileged user.
  • The application refuses to start in production with weak or default secrets.

Application security.

  • A strict Content Security Policy and security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy).
  • Upload size limits, plus quotas and rate limits.

Minimisation. No analytics, advertising or tracking tools. Logs normally contain no document or conversation content. Some search-index errors may log the search query that failed. Logs are rotated automatically by size.

Providers. Processing agreements with subprocessors. AI providers are used in configurations that do not let them train models on Customer Data.

Organisational. Confidentiality obligations for staff, need-to-know access, and a procedure for handling and notifying security incidents.

Annex 3 — Subprocessors

The current list, with each subprocessor’s purpose, data and location, is on the Subprocessors page.