GDPR Compliance
Last updated · August 2026
This page describes how ATLAS ANALYTICS PTE. LTD. meets its obligations under the EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR when it provides the ATLAS METIS Service. It complements our Privacy Policy and explains how we handle personal data.
1. Roles
For data we hold about our own visitors, prospective customers, and users (for example, sign-in details and billing information), Atlas is a controller.
For Customer Data that customers submit to or generate through the Service (including target-account information and outreach context), Atlas acts as a processor on behalf of that customer. The customer determines the purposes and the categories of data processed; Atlas processes that data only on documented instructions.
2. Lawful Bases
Where Atlas acts as a controller, we rely on the lawful bases set out in Article 6 GDPR: typically performance of a contract, our legitimate interests (balanced against your rights), compliance with a legal obligation, or consent where required. Where special categories of data are involved (which is not a routine part of the Service), we will rely on one of the bases set out in Article 9.
3. Data Subject Rights
Individuals whose personal data we process have the rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where consent was the basis. Requests can be sent to privacy@atlas-metis.com. Where Atlas processes the data as a processor on behalf of a customer, we will forward the request to the relevant customer and assist them in responding.
4. Data-Processing Terms
Our data-processing terms — covering our role as processor, security measures, sub-processors, and international-transfer safeguards — are set out in the Service Agreement signed by our customers, which serves as the data processing agreement for the purposes of Article 28 GDPR. For any data-protection questions, contact privacy@atlas-metis.com.
5. Sub-Processors
Atlas engages a limited number of sub-processors to provide the Service. Each is bound by contractual data-protection obligations no less protective than our data-processing terms. The current list:
| Sub-processor | Purpose | Region |
|---|---|---|
| Vercel Inc. | Website and application hosting, content delivery | USA / EU edge |
| Supabase, Inc. | Application database and file storage | EU (Frankfurt) |
| Google (Ireland Ltd. / LLC) | Workspace: business email and documents; Gemini AI processing; Analytics (opt-in only) | EU / USA |
| Anthropic, PBC | AI model processing for agent workflows | USA |
| OpenAI | AI model processing for agent workflows | USA |
| Perplexity AI, Inc. | AI-assisted research and search | USA |
| xAI (Grok) | AI model processing | USA |
| Moonshot AI (Kimi) | AI-assisted search | Singapore / China |
| Apollo.io, Inc. | B2B contact sourcing and enrichment | USA |
| Clay Labs, Inc. | Data enrichment workflows | USA |
| AI Ark | B2B company and contact data sourcing | USA |
| BetterContact (Hackeez Consulting SAS) | Waterfall contact enrichment | EU (France) |
| Tomba Technology Web Service LLC | Email finding | USA |
| Reoon Technology | Email verification | USA |
| Exa Labs, Inc. | Web research and search API | USA |
| Brevo SAS | Newsletter and email delivery | EU (France) |
Transfers outside the EEA or UK are safeguarded as described in Section 6. We give prior notice of material additions or replacements by updating this page and, for customers with a signed Service Agreement, by email. Internal tooling that does not process customer personal data (for example, design or code-hosting platforms) is not listed.
6. International Transfers
Atlas is established in Singapore and uses sub-processors in multiple jurisdictions, including the EEA, the United Kingdom, and the United States. Transfers of personal data outside the EEA or UK rely on appropriate safeguards under Chapter V GDPR: most commonly the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with transfer-impact assessments where required.
7. Retention and Deletion
We retain personal data for no longer than necessary for the purposes for which it was collected and to meet legal obligations. Customer Data is retained for the duration of the customer’s subscription; on termination we make it available for export for a reasonable period and then delete it in accordance with the Terms of Service and our data-processing terms.
8. Breach Notification
Atlas operates a documented incident-response process. In the event of a personal-data breach affecting customer data, we notify the relevant customer without undue delay and in line with our data-processing terms, supporting them in their own notification obligations to supervisory authorities and data subjects.
9. Data Protection Contact
ATLAS ANALYTICS PTE. LTD., 160 Robinson Road, #14-04 SBF Center, 068914 Singapore. For any matter relating to the GDPR or UK GDPR, contact privacy@atlas-metis.com.
Because our customers are established in the European Union and we have no establishment there ourselves, we are appointing an EU representative pursuant to Article 27 GDPR. The representative’s name and contact details will be published here once the appointment is confirmed; until then, all GDPR matters are handled directly via privacy@atlas-metis.com.
