Atlas Trust Center / Data Processing Agreement

Data Processing Agreement

This is the standing DPA template Atlas (Talent Phantom, Inc.) offers every customer. To request an executable PDF — potentially customized for your jurisdiction or specific requirements — email trust@atlas.ai.

Template version 2026-06.v1 · Aligned with GDPR Article 28 and CCPA service provider requirements

Article 1

Definitions

Atlas. Atlas, the workforce intelligence platform operated by Talent Phantom, Inc., a Delaware corporation.
Customer. The entity that has entered into a subscription agreement with Talent Phantom, Inc. for use of Atlas.
Customer Personal Data. Personal data (as defined under GDPR Article 4) that Customer uploads to or transmits through Atlas, including but not limited to: candidate names + contact information, employee roster data, opportunity pipeline data, and outreach content.
Sub-processor. Any third party engaged by Atlas to process Customer Personal Data on Atlas's behalf. The current sub-processor list is published at /trust/sub-processors.
Article 2

Subject Matter + Duration

Atlas processes Customer Personal Data solely for the purpose of providing the Atlas service to Customer. This DPA remains in effect for the duration of the Customer's subscription, and for any period during which Atlas continues to process Customer Personal Data after termination (limited to deletion / return procedures).

Article 3

Customer Instructions

Atlas processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers of Personal Data to third countries. Customer's instructions are documented in: (a) this DPA, (b) the subscription agreement, and (c) any explicit instructions Customer provides through the Atlas service (e.g. data deletion requests, consent settings).

Atlas will immediately inform Customer if it believes an instruction violates applicable data protection law.

Article 4

Confidentiality

Atlas ensures that personnel authorized to process Customer Personal Data have committed themselves to confidentiality and have appropriate training. Atlas restricts access to Customer Personal Data to personnel who require such access to perform their duties.

Article 5

Technical and Organizational Measures

Atlas implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are documented at /trust/security and include:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-Level Security and workspace isolation in the database
  • Zero Data Retention configuration on all LLM API calls
  • PII-stripped server-side logging
  • Multi-factor authentication for Atlas operator accounts
  • Incident response procedures with 72-hour customer notification SLA
Article 6

Sub-Processors

Atlas's current sub-processors are published at /trust/sub-processors. Customer hereby provides general written authorization for Atlas to engage these sub-processors.

Atlas commits to: (a) notifying Customer of any intended addition or replacement of sub-processors at least 30 days in advance, (b) imposing the same data protection obligations on each sub-processor by contract, and (c) remaining liable to Customer for any sub-processor's breach.

Customer may object to a new sub-processor by notifying Atlas in writing within the 30-day notice period. If the objection cannot be resolved, Customer may terminate the affected portion of the subscription with pro-rated refund of pre-paid fees.

Article 7

Data Subject Rights

Atlas assists Customer in responding to data subject requests (access, rectification, erasure, restriction, objection, portability) by providing technical and organizational tools through the Atlas service. Customers on the Enterprise tier additionally receive: per-row deletion workflows, exportable customer data reports, and audit log access.

Article 8

Personal Data Breach Notification

Atlas notifies Customer without undue delay (no later than 72 hours) after becoming aware of a personal data breach affecting Customer Personal Data. Notification will include (to the extent known at the time): the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

Article 9

Audit Rights

Atlas makes available to Customer all information necessary to demonstrate compliance with this DPA. Customer may audit Atlas's compliance on reasonable notice (no more than once annually) at Customer's expense, subject to reasonable confidentiality obligations.

Atlas's SOC 2 Type II report (available on the Enterprise tier) and penetration test results satisfy this audit obligation for most customers.

Article 10

Return + Deletion at End of Service

Upon termination of the subscription, at Customer's choice Atlas will: (a) delete all Customer Personal Data within 30 days, or (b) return Customer Personal Data via export within 30 days, then delete within an additional 30 days. Atlas may retain Customer Personal Data only to the extent required by applicable law and in encrypted backup form for up to 90 days post-deletion.

Note: Customer Personal Data that has been incorporated into the Industry Capability Atlas (anonymized cross- customer aggregate dataset, only with customer_consent_for_atlas = TRUE records) is anonymized at the query layer and is not individually deletable. Customer can revoke consent for any future inclusion.

Article 11

International Transfers

For transfers of Customer Personal Data from the European Economic Area, United Kingdom, or Switzerland to the United States or other countries lacking an adequacy decision, Atlas relies on the Standard Contractual Clauses (Module Two: Controller to Processor) as the transfer mechanism. The full SCC text is incorporated by reference and is available on request.

Article 12

Governing Law + Conflicts

This DPA is governed by the law specified in the subscription agreement. In the event of conflict between this DPA and the subscription agreement, this DPA prevails with respect to data protection matters.

This template is provided for review purposes. To execute a DPA — or to request EU-specific terms, healthcare-specific terms, or additional standard contractual clause modules — contact trust@atlas.ai.

Atlas reviews this template annually and will publish updates here. Material changes affecting executed DPAs are communicated directly to Customers.