Legal

GDPR

Last updated: July 1, 2026

1. Our commitment to GDPR

The General Data Protection Regulation (GDPR) sets a high standard for how personal data of individuals in the European Economic Area (EEA) and the United Kingdom is handled. Atlas HR is built with data protection in mind and supports our customers in meeting their GDPR obligations.

2. Controller and processor roles

For personal data our customers upload about their employees and candidates, the customer is the data controller and Atlas HR acts as a data processor, processing that data only on documented instructions. For our own website visitors and account holders, Atlas HR is the controller.

3. Data Processing Agreement

We make a Data Processing Agreement (DPA) available to customers, incorporating the commitments required under Article 28 of the GDPR, including confidentiality, security, subprocessor terms, assistance with data subject requests, and deletion or return of personal data at the end of the engagement.

4. Data subject rights

The GDPR grants individuals rights to access, rectify, erase, restrict, and port their personal data, and to object to certain processing. Atlas HR provides tools and support to help controllers respond to these requests. If you are an employee of an Atlas HR customer, please direct your request to your employer as the controller, and we will assist them.

5. Lawful basis and consent

Controllers are responsible for establishing a lawful basis for processing personal data in Atlas HR. Where consent is the basis (for example, certain marketing communications), we provide mechanisms to capture and withdraw consent.

6. Subprocessors

We engage a limited set of subprocessors (such as hosting, authentication, and payment providers) to deliver the Services. We impose data protection obligations on subprocessors consistent with the GDPR and maintain a list of subprocessors available to customers on request.

7. International data transfers

Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required.

8. Security measures

We implement technical and organizational measures appropriate to the risk, including role-based access control, row-level security for organization data, audit logging, encryption in transit, and access separation for service roles.

9. Data breach notification

In the event of a personal data breach affecting Customer Data, we will notify affected customers without undue delay and provide information reasonably necessary to help them meet their own notification obligations.

10. Data retention and deletion

We retain personal data only as long as necessary for the purposes for which it is processed or as required by law. Customers can request export or deletion of their workspace data, and we delete or return personal data upon termination in accordance with the DPA.

11. Contact our data protection team

For GDPR-related questions, DPA requests, or to exercise data protection rights, contact us at privacy@atlashr.xyz.

Looking for more on our security and privacy posture? Visit the Trust Center or read our Privacy Policy.