Data processing addendum
Data processing addendum
- Effective
- 2026-07-31
- Last reviewed
- 2026-07-31
Draft — not yet reviewed by counsel
The technical statements here are generated from the systems that implement them and are accurate. The legal framing has not been reviewed by a qualified lawyer in the jurisdictions it covers, and the company details shown in brackets are placeholders. Do not rely on this document as a binding commitment until both are resolved.
This addendum governs how [[ razón social registrada — pendiente ]] processes personal data on behalf of a customer using Atisbo. It forms part of the terms of service and applies automatically — you do not need to sign it separately to be covered by it.
It is published rather than sent on request so that a security review can start before a sales call. If your procurement process needs a countersigned copy, write to legal@atisbo.dev.
1.How this becomes binding
By using Atisbo to process personal data, you (the Customer) and [[ razón social registrada — pendiente ]] (Atisbo) agree to this addendum. It takes effect when you first use the service and lasts as long as we process personal data on your behalf.
Where you have a signed agreement with us, this addendum is incorporated into it. A negotiated DPA signed by both parties replaces this one.
2.Definitions
Applicable Data Protection Law means the GDPR and UK GDPR, Colombia’s Ley 1581 de 2012 and Decreto 1377 de 2013, Brazil’s LGPD (Lei 13.709/2018), and US state privacy laws including the CCPA as amended by the CPRA — each to the extent it applies to the processing.
Customer Personal Data means personal data contained in the content you connect to or upload into a workspace, and anything derived from it. Processing, controller, processor, data subject and personal data breach carry the meanings given in the GDPR, and their equivalents under the other laws named above. SCCs means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914.
3.Roles of the parties
For Customer Personal Data, you are the controller and Atisbo is the processor. You decide what to connect and why; we process it to provide the service.
Where you are yourself a processor acting for another controller — an agency working for a client, for instance — we act as a subprocessor and Module Three of the SCCs applies instead of Module Two.
Separately, Atisbo is a controller for the account data of the people who sign in — their email, name and authentication records. That processing is governed by the privacy policy, not by this addendum.
4.Processing on your instructions
We process Customer Personal Data only on your documented instructions. Your use of the product’s features — connecting a source, running the pipeline, using an agent over MCP, exporting — constitutes those instructions, together with anything you agree with us in writing.
We will tell you if an instruction appears to breach Applicable Data Protection Law, and we may decline to carry it out. Where the law requires us to process for a reason other than your instruction, we will tell you first unless the law forbids it.
What we will not do with your data
We do not use Customer Personal Data to train machine-learning models, ours or a provider’s. We do not aggregate it into benchmarks shown to other customers. We do not sell it, and we do not share it for advertising. These are contractual commitments here, not statements of intent.
5.Confidentiality
Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, and access is limited to those who need it to run or repair the service. Support does not read workspace content except where you ask us to look at something specific.
6.Security measures
We implement appropriate technical and organisational measures, described in Annex II and published in more detail — including the controls not yet in place — in the Trust Center.
We may update those measures as the service evolves, provided we do not materially reduce the level of protection.
7.Subprocessors
You give general authorisation for us to engage the subprocessors listed in Annex III. Each is bound by written terms imposing data protection obligations no less protective than these, and we remain liable for their performance.
Before adding or replacing a subprocessor we will give you at least 30 days’ notice by email to your account contact. If you object on reasonable data protection grounds within that period, tell us and we will work to find an alternative; if we cannot, you may terminate the affected part of the service and receive a refund of fees paid for the unused remainder.
8.Helping you answer data subject requests
The product answers most requests directly: export produces a complete machine-readable copy of a workspace, deletion removes it, and content is editable in place. Those are available on every plan and are never withheld for a commercial reason.
Where a request needs more than that, we will assist you by appropriate technical and organisational measures, taking into account the nature of the processing. If a data subject contacts us directly about data in your workspace, we will not respond substantively — we will refer them to you and tell you it happened.
9.Personal data breaches
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe what we know at the time — the nature of the breach, the categories and approximate volume of data, the likely consequences and the measures taken — and we will follow up as we learn more rather than delay the first notice until the picture is complete.
Notifying regulators and data subjects is your responsibility as controller; we will give you the information you reasonably need to do it.
10.Impact assessments
Where you must carry out a data protection impact assessment or consult a supervisory authority, we will provide reasonable assistance and the information you need about the processing, taking into account what is available to us.
11.Return and deletion
On termination you keep read-only access for 14 days to export your data. After that the workspace and its contents are deleted, including encrypted credentials and the sign-in identities of its members.
Deletion removes the records immediately and becomes irreversible once the last point-in-time backup containing them expires — a window of days. We retain only what the law requires, such as invoicing records, and it stays subject to this addendum for as long as we hold it.
12.Audits and information
We will make available the information reasonably necessary to demonstrate compliance with this addendum: this document, the Trust Center including its published gaps, the subprocessor list, and the audit reports of the infrastructure providers where their terms allow us to share them.
If that is not enough for your obligations, you may request an audit no more than once in any twelve months, on 30 days’ written notice, during business hours, without disrupting the service and subject to confidentiality. We will bear our own costs unless the audit finds a material breach on our side, in which case we will bear yours too.
Stated rather than implied
Atisbo has not completed an independent SOC 2 audit. The reports referred to above belong to Supabase and Vercel and cover their platforms, not our operations. That distinction is not a formality — a vendor presenting a supplier’s certificate as its own is the most common misrepresentation in this category.
13.International transfers
The service runs in the United States, so processing Customer Personal Data involves a transfer out of the EEA, the United Kingdom, Colombia and Brazil.
For personal data subject to the GDPR, the SCCs are incorporated into this addendum by reference: Module Two where you are a controller, Module Three where you are a processor. Clause 7 (docking) applies; the option in Clause 9(a) is general written authorisation with the 30-day notice period in section 7; Clause 11 does not use the independent dispute resolution option; the governing law and forum in Clauses 17 and 18 are those of Ireland unless your establishment’s member state requires otherwise. Annexes I, II and III of the SCCs are the annexes below.
For personal data subject to the UK GDPR, the UK International Data Transfer Addendum applies to the SCCs, with the tables completed from this addendum. For Switzerland, references to the GDPR are read as references to the FADP and the Federal Data Protection and Information Commissioner is the competent authority.
Transfers from Colombia and Brazil rely on the contractual guarantees in this addendum, which provide a level of protection consistent with Ley 1581 and with Article 33 of the LGPD.
14.Colombia, Brazil and US state law
- Colombia. Atisbo acts as encargado del tratamiento and you as responsable. We process only on your instructions, keep the data secure, and channel any request from a titular to you. Consultas and reclamos received directly are acknowledged and forwarded within the statutory periods.
- Brazil. Atisbo acts as operador and you as controlador under the LGPD. We assist with requests under Articles 18 and 19 and with communications to the ANPD. Where you require a named encarregado on our side, we will record one on request.
- United States. For the purposes of the CCPA and comparable state laws, Atisbo is a service provider or processor. We do not sell or share personal information, do not retain, use or disclose it for any purpose other than providing the service, and do not combine it with personal information from other sources except as those laws permit. We certify our understanding of these restrictions.
15.Liability and precedence
Liability under this addendum is subject to the limitations in the terms of service, except where Applicable Data Protection Law does not permit that limitation.
If this addendum conflicts with the terms of service, this addendum prevails for matters of personal data processing. If it conflicts with the SCCs, the SCCs prevail.
16.Annex I — Details of processing
| Item | Detail |
|---|---|
| Data exporter | The Customer, as identified in its account. Contact: the account’s administrative email. |
| Data importer | [[ razón social registrada — pendiente ]], [[ domicilio registrado — pendiente ]]. Contact: privacy@atisbo.dev. |
| Subject matter | Providing the Atisbo product decision backlog: ingesting evidence, grouping it into problems, ranking it, and recording decisions and outcomes. |
| Duration | For the term of the agreement, plus the deletion window in section 11. |
| Nature and purpose | Collection, storage, structuring, analysis by automated means including large-language-model inference, retrieval, transmission to the Customer’s own agent on request, and erasure. |
| Categories of data subjects | The Customer’s own customers and users whose feedback is ingested; the Customer’s personnel whose internal messages, meeting notes or tracker items are connected; the Customer’s authorised users of the service. |
| Categories of personal data | Identifiers and contact details appearing in ingested content; the content of messages, transcripts, notes and tickets; professional details such as company and role; usage and technical data such as IP address. Identifiers matching known patterns are redacted before inference, as described in Annex II. |
| Special categories | None requested or required. The service is not designed for special category data, and connecting a source that carries it must be agreed with us in advance. |
| Frequency | Continuous, for as long as sources remain connected. |
| Competent supervisory authority | That of the Customer’s establishment; for SCC purposes, the authority of the EU member state in which the Customer is established or has appointed a representative. |
17.Annex II — Technical and organisational measures
- Isolation. Row-level security in the database confines every query to the tenant that made it, so a query that fails to filter returns nothing rather than another customer’s rows. Automated build checks refuse database functions that trust a caller-supplied identifier instead of verifying identity.
- Encryption. TLS in transit with HSTS; AES-256 at rest for the database, storage and backups; integration credentials and customer-supplied model keys held in an encrypted vault and decrypted only at the point of use.
- Minimisation before inference. A redaction pass replaces email addresses, phone numbers, payment card numbers (validated to avoid false matches), national identifiers including CPF, CURP, DNI and RUT, and IP addresses before text is sent for processing. It is pattern-based and is a reduction in exposure rather than anonymisation.
- Access control. Authentication with session management; roles within a workspace; administrative access to production limited to the operators who run the service.
- Logging and auditability. Actions taken in a workspace are recorded in an immutable decision trail visible to the Customer. Operational logs that can quote customer text carry the shortest retention windows we run.
- Retention limits. Enforced in code against a registry that a continuous-integration check compares with the live database in both directions. The published table is generated from that registry.
- Resilience. Managed point-in-time backups at the infrastructure provider. Restoration has not yet been exercised end to end with documented recovery objectives — stated here rather than implied.
- Application hardening. Content Security Policy, framing denied, strict transport security, and input validated at every server boundary.
18.Annex III — Subprocessors
Last updated 2026-08-01.
- SupabaseUnited States (AWS us-west-2)
- Processing
- Primary database, authentication, file storage and encrypted secret storage.
- Data
- Everything a workspace holds: evidence text, problems, decisions, chat, uploads, account identities and encrypted credentials.
- Retention
- Live for as long as the account exists. Point-in-time backups mean a deletion becomes permanent only once the last backup containing it expires.
- Assurance
- SOC 2 Type II · HIPAA · ISO 27001 (Supabase’s own audits)
- VercelUnited States (primary region iad1)
- Processing
- Application hosting, edge routing and build infrastructure.
- Data
- Request metadata and anything in transit through the application. Vercel is not a storage layer for workspace content.
- Retention
- Operational logs per Vercel’s policy; no workspace content is stored here.
- Assurance
- SOC 2 Type II · ISO 27001 (Vercel’s own audits)
- AnthropicUnited States
- Processing
- Chat answers and the inference paths pinned to a frontier model. It is NOT the majority of platform inference — see DeepSeek below, which serves most background tasks by volume.
- Data
- The text being processed, after the redaction pass described in the Trust Center. Prompts can contain end-customer wording.
- Retention
- Anthropic does not train on data submitted through its commercial API. Zero-retention is not the default of the standard API, and Message Batch results are held for 29 days.
- Assurance
- SOC 2 Type II · commercial API excluded from model training
- DeepSeekPeople’s Republic of China
- Processing
- Most of the product’s background inference: naming evidence, judging whether two problems are the same, extracting structure from conversations, and maintaining the taxonomy.
- Data
- The text being processed, after the redaction pass described in the Trust Center. Prompts routinely contain end-customer wording.
- Retention
- Governed by the provider’s policy. DeepSeek states that it stores personal data on servers in the People’s Republic of China and that submitted data may be used to train and improve its models. We hold no zero-retention or training-exclusion arrangement with this provider.
- Assurance
- Provider terms apply — we hold no independent audit of this vendor, and no contractual exclusion from model training.
- OpenRouterUnited States, routing onward to the model host it selects.
- Processing
- Routing layer used as a fallback for background inference when the primary provider is unavailable.
- Data
- The text being processed on the requests it serves.
- Retention
- OpenRouter states it does not log prompts by default, but it forwards them to third-party model hosts whose own terms then apply. Free endpoints in particular may train on or publish the prompts they receive.
- Assurance
- Provider terms apply, plus those of whichever model host the request is routed to.
- Jina AIGermany / United States, per the vendor’s deployment
- Processing
- Turns evidence into the vectors that let the system tell whether two pieces of feedback describe the same problem.
- Data
- Snippet text submitted for embedding.
- Retention
- Set by the provider; embeddings are computed per request rather than stored by us there.
- Assurance
- Provider terms apply — we hold no independent audit of this vendor.
- ComposioUnited States
- Processing
- Brokers the OAuth connection when your agent connects a third-party source, and relays that source’s events to us.
- Data
- The OAuth grant itself, plus the payloads of the sources you connect through it.
- Retention
- Composio holds the OAuth grant. Deleting the connection inside Atisbo does not revoke it there — revoke it in the source application as well.
- Assurance
- Provider terms apply.
- ResendUnited States
- Processing
- Transactional email: sign-in links, invitations and account notices.
- Data
- Recipient email address and the contents of the message sent.
- Retention
- Delivery logs per the provider’s policy.
- Assurance
- SOC 2 Type II (Resend’s own audit)
- StripeUnited States and Ireland
- Processing
- Payment processing and subscription billing.
- Data
- Billing contact and payment details. Card numbers are handled by Stripe and never reach our servers.
- Retention
- Per Stripe’s policy and applicable financial record-keeping rules.
- Assurance
- PCI DSS Level 1 · SOC 2 Type II (Stripe’s own audits)
- GitHubUnited States · only when enabled
- Processing
- Reads repository, pull-request and deployment activity so shipped work can be linked back to the decision behind it.
- Data
- Commit messages, pull-request titles and bodies, author handles, and deployment events for the repositories you connect.
- Retention
- Event records held 180 days on our side; see the retention table.
- Assurance
- SOC 2 Type II · ISO 27001 (GitHub’s own audits)
- TavilyUnited States · only when enabled
- Processing
- Searches publicly available feedback about your product so a new workspace has something real in it before you connect anything of your own.
- Data
- Your product or company name as a search term. No workspace content is sent.
- Retention
- Set by the provider.
- Assurance
- Provider terms apply.
- OpenAIUnited States · only when enabled
- Processing
- Alternative inference provider. The platform’s own processing runs on Anthropic; OpenAI is reached when a customer supplies their own key.
- Data
- The text being processed, when this provider is selected.
- Retention
- OpenAI does not train on data submitted through its business APIs. API inputs and outputs are retained up to 30 days for abuse monitoring unless a zero-retention arrangement is in place.
- Assurance
- SOC 2 Type II · business API data excluded from model training
To be notified when this list changes, write to privacy@atisbo.dev and we will add you to the notice list described in section 7.