Legal

Privacy Policy

Last updated:

This English text is a translation, provided for convenience. The Romanian version is the legally binding one: read it in Romanian.

This policy explains how Farcaș Mihai Cristian Persoană Fizică Autorizată processes personal data when you visit atlas-ai.ro, use the Atlas application or contact us. We comply with Regulation (EU) 2016/679 (the “GDPR”) and Romanian Law no. 190/2018.

1. Who we are

The controller is Farcaș Mihai Cristian Persoană Fizică Autorizată, an authorised self-employed person (PFA) with its professional address at Strada Henri Coandă 1, Alba Iulia, Alba, România, tax ID (CUI) 52297606, Trade Register no. F2025028974009.

For any question about personal data, write to contact@atlas-ai.ro. We have not appointed a data protection officer, because our activity does not require one (Article 37 GDPR).

2. When we are the controller and when we act for customers

We are the controller for the data of website visitors, user-account data, security and operational data, messages sent to the team, demo requests, and customers’ contract and billing data.

We act on behalf of customers (as a processor) for the documents uploaded into workspaces and for the content of conversations. For this data, the controller is the organisation using Atlas (usually your employer), and we process it under the Data Processing Agreement concluded with it. For requests about this data, contact your organisation. If you write to us, we forward the request to them.

3. What data we process, why and for how long

Visiting the website

  • Data: your IP address and the browser’s technical data, used only to deliver the pages; the theme you chose (light or dark), stored only in your browser.
  • Purpose: serving the website securely.
  • Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
  • Retention: we keep no access logs for the website pages. We use no analytics, advertising or tracking tools.

Demo requests and correspondence

  • Data: your name, email address, company, role, the content of your messages and any documents you send us for the demo.
  • Purpose: replying to you, preparing the demo and an offer.
  • Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR) and our legitimate interest in replying (point (f)).
  • Retention: up to 24 months after the last message, if no contract follows. Documents sent for a demo are deleted at the end of the evaluation (see the Terms, 11.5).

Your user account

  • Data: your email address, name (optional), role, password (stored only as an irreversible Argon2 hash), the account’s creation date, and the workspaces you own or belong to.
  • Purpose: giving you access to the Service.
  • Legal basis: performance of the contract, if you are the customer (Article 6(1)(b) GDPR); otherwise, our and your organisation’s legitimate interest in providing the service it contracted (point (f)).
  • Retention: while the account is active. We delete the account at your request, at your organisation’s request, or when the contract ends, under section 11 of the Terms.

Security and operations

  • Data: IP address, date and time, the address requested and the response code, in the application server’s logs; counters for sign-in attempts (by IP address), for messages sent (per hour) and for documents uploaded (per day); aggregated daily usage statistics, not linked to users.
  • Purpose: protecting the Service, preventing abuse, enforcing usage limits and diagnosing errors.
  • Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
  • Retention: logs are rotated automatically by size (at most 30 MB per component), usually within days or weeks. Counters expire automatically within 26 hours. Aggregated statistics are kept for 40 days.

Messages to the team (“Contact support”)

  • Data: your message, a reply-to email address (optional), your account email and ID (if you are signed in), IP address, date and time, and technical details about your browser: user agent, language, time zone, screen and window size, the page of the app you were on and the app version.
  • Purpose: replying to you, and reproducing and fixing the reported issue.
  • Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
  • Retention: up to 24 months after the request is closed.

Customers and billing

  • Data: names and contact details of the customer’s representatives, billing details, invoices and payments.
  • Purpose: concluding and performing the contract, invoicing and bookkeeping.
  • Legal basis: performance of the contract (Article 6(1)(b) GDPR) and legal obligations (point (c)).
  • Retention: accounting records for the period required by Romanian Accounting Law no. 82/1991 (currently between 5 and 10 years); other contract data for the term of the contract and 3 more years (the general limitation period).

Documents and conversations (on behalf of the customer)

  • Data: the uploaded documents and any personal data in them, workspace names and descriptions, questions, answers and citations.
  • Purpose: providing the Service to your organisation.
  • Legal basis and retention: set by your organisation, as controller. You can delete your conversations at any time. Documents and workspaces can be deleted by those entitled to (the workspace owner, or the person who uploaded the document).
  • Deletion: a deleted document disappears from the app at once. Within an hour we also delete its remaining copies, including the conversion kept by Mathpix, and keep a record of these deletions. Technical derived copies (numerical representations and short descriptions of formulas and figures) are deleted automatically 30 days after they were created.

4. How the AI processing works

When you upload a document, it is sent to Mathpix to recognise text, formulas and tables. Passages and figures are sent to Voyage AI to compute the numerical representations used for search. Formulas, and figures without a caption, are sent to Google Gemini, which writes short descriptions of them.

When you ask a question, it is sent to Voyage AI for search, and to Cohere, together with the candidate passages, to rank the results. The question, part of the conversation history and the passages found are sent to Google Gemini, which writes the answer and the conversation title.

We do not use your data to train AI models. We work with these providers only in configurations in which they may not use it to train their own models.

Images of figures cropped from documents are kept on our servers, together with the document, and your browser loads them from us. Right after processing, we ask Mathpix to delete everything it kept for the document: the source, the results and the images.

AI-generated answers are informational. We do not use them to make decisions based solely on automated processing that produce legal effects concerning you or similarly affect you (Article 22 GDPR).

5. Who we share data with

  • Providers that help us run the Service: hosting (Hetzner Online GmbH, Germany) and the AI providers Mathpix, Voyage AI, Cohere and Google. The full list, with locations, is on the Subprocessors page. Emails sent to contact@atlas-ai.ro are forwarded through Cloudflare, and messages to the team land in our mailbox hosted by Google.
  • Your organisation and colleagues: members of a workspace see its content, and your organisation may receive information about your account.
  • Public authorities, when the law requires it.
  • Professional advisers (lawyers, accountants, auditors), who are bound by confidentiality.
  • A successor, if the business is transferred, with notice to you.

We do not sell personal data and do not use it for advertising.

6. Transfers outside the European Economic Area

Some providers (Mathpix, Voyage AI, Cohere and Google) are based in the United States or Canada or may process data there. Transfers happen only with the safeguards of Chapter V GDPR:

  • an adequacy decision of the European Commission, including the EU–U.S. Data Privacy Framework for certified companies;
  • or the standard contractual clauses adopted by Decision (EU) 2021/914, with supplementary measures where needed.

On request, we send you a copy of the relevant safeguards.

7. How we protect data

Our measures include:

  • encrypted connections (TLS, with HSTS);
  • passwords stored only as Argon2 hashes;
  • an HTTP-only, Secure session cookie;
  • rate-limited sign-in;
  • workspace isolation inside the search index itself;
  • databases that are not reachable from the internet;
  • restricted administrative access.

The full measures are in Annex 2 of the Data Processing Agreement.

8. Your rights

You have the following rights:

  • the right of access to your data (Article 15 GDPR);
  • the right to rectification (Article 16);
  • the right to erasure, also called the “right to be forgotten” (Article 17);
  • the right to restriction of processing (Article 18);
  • the right to data portability (Article 20);
  • the right to object, in particular to processing based on legitimate interest (Article 21);
  • the right not to be subject to a decision based solely on automated processing (Article 22).

How to exercise them. Write to contact@atlas-ai.ro. We reply free of charge within one month. For complex requests the deadline can be extended by two more months, in which case we let you know. We may ask for information to confirm your identity.

Deleting your account. On request, we delete your account and your conversations within 30 days. We keep only the data the law requires us to keep (for example, invoices) or that we need to defend legal claims. Workspaces you own that have other members pass to the longest-standing member, because they belong to your organisation. Workspaces with no other members are deleted together with their documents. Documents you uploaded to shared workspaces stay there, no longer linked to your account.

Complaints. You can lodge a complaint with the Romanian data protection authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest, www.dataprotection.ro, anspdcp@dataprotection.ro. You can also go to court.

9. Children

The Service is meant for professionals and is not directed at anyone under 18. We do not knowingly collect children’s data. If you find out that we have, write to us and we will delete it.

10. Marketing communications

The application does not currently send automated emails to users. Service messages — for example about security, the contract, invoices or changes to the legal documents — are needed to perform the contract and are not marketing.

We send marketing communications only with your consent. Existing customers are the exception: we may write to them about similar services, under Article 12 of Romanian Law no. 506/2004. Every marketing communication contains an unsubscribe link, and unsubscribing is free and immediate.

11. Cookies

We use only one cookie and a few locally stored preferences, all strictly necessary. The details are in the Cookie Policy.

12. Changes

The date of the last update is shown at the top of this page. We announce significant changes in the app or by email before they apply.