ATLASO
LabPricing
Log inGet Started

Data Processing Addendum

Last updated September 27, 2026

Pending final review by counsel; not yet in effect.

Contents

  • 0. Status of this document — template offered to business customers
  • 1. Definitions
  • 2. Roles of the parties
  • 3. Subject matter, duration, nature, and purpose of Processing
  • 4. Customer instructions
  • 5. Confidentiality
  • 6. Security measures (GDPR Article 32)
  • 7. Sub-processing
  • 8. Assistance with Data Subject requests
  • 9. Special categories and regulated data
  • 10. Personal Data Breach notification
  • 11. Return and deletion on termination
  • 12. Audits
  • 13. International transfers
  • 14. CCPA/CPRA Service Provider terms
  • 15. Liability
  • 16. General
  • 17. Contact
  • Annex 1 — Description of Processing (Article 28(3) / SCC particulars)
  • Annex 2 — Technical and Organisational Measures (Article 32)
  • Annex 3 — Approved Sub-processors

This Data Processing Addendum ("DPA") forms part of the agreement between Atlaso Labs Inc. and a business customer for the provision of the Atlaso Service. In plain English: when you (a business or other organisation) use Atlaso to process personal data about your own users, employees, or other individuals, this document sets out the data-protection terms — what Atlaso does with that data, how we keep it secure, the sub-processors we rely on, how we help you respond to your obligations under laws like the GDPR, and what happens to the data when our relationship ends. It is the contract that lets a privacy-conscious organisation use Atlaso in compliance with applicable data-protection law.

0. Status of this document — template offered to business customers

This DPA is available to business and enterprise customers of Atlaso on request. It is not automatically in force for every user, and it is not incorporated by default into the Terms of Service. It becomes binding, and governs the processor relationship, only once it has been executed by both parties — whether by signature, by a click-through acceptance during onboarding, or by reference into a separate written agreement with Atlaso — and only where:

  1. you are a business, organisation, or other legal entity using the Service to process personal data on behalf of identifiable individuals (your "data subjects"); and
  2. Atlaso acts as a processor (or sub-processor) on your behalf in respect of that data.

Individual (non-business) consumers using Atlaso for their own personal Memories do not need this DPA. For them, Atlaso is the controller that determines the purposes and means of processing their Memory, and the Privacy Policy governs — including the international-transfer safeguards for their data. This DPA governs only the business-customer processor relationship described above.

To request execution of this DPA, contact support@atlaso.ai. The version in force is the one accepted by both parties. Once executed, this DPA sits within the order of precedence set out in the Terms of Service and summarised in Section 16: the Terms of Service are the master agreement; where documents conflict, the more specific document controls for its subject matter; this DPA controls only for the processing of a business customer's personal data where Atlaso acts as processor; and the Standard Contractual Clauses control for restricted international transfers.

In this document, "Atlaso", "we", "us", and "our" mean Atlaso Labs Inc., a Delaware C-Corporation. "Service" means the Atlaso memory layer (dashboard, brain/API, Connectors, and CLI). "You", "Customer", and "your" mean the business customer that has entered into this DPA. Capitalised terms not defined here have the meaning given in the Terms of Service and Privacy Policy.

1. Definitions

For the purposes of this DPA:

  • "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including, as applicable: the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); the UK GDPR and the UK Data Protection Act 2018 ("UK GDPR"); the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"); and the Indian Digital Personal Data Protection Act, 2023 ("DPDP Act"); together with any successor or implementing legislation.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR. Where CCPA/CPRA applies, "Business", "Service Provider", "Consumer", "Personal Information", and "Sell/Share" carry their CCPA/CPRA meanings, and references to Controller/Processor/Personal Data shall be read to include the corresponding CCPA/CPRA roles and terms.
  • "Customer Personal Data" means Personal Data contained within the Content (including Memories) that Atlaso Processes on your behalf under this DPA.
  • "Sub-processor" means any third party engaged by Atlaso to Process Customer Personal Data.
  • "Standard Contractual Clauses" or "SCCs" means (a) for the EU, the clauses annexed to European Commission Implementing Decision (EU) 2021/914; and (b) for the UK, the UK International Data Transfer Addendum to those SCCs issued by the UK Information Commissioner ("UK Addendum").
  • "TOMs" means the technical and organisational measures set out in Annex 2.

Other capitalised terms (Service, Memory/Memories, Content, Connectors, Free, Pro, Device, Account, User) have the meanings given in the Terms of Service.

2. Roles of the parties

2.1 Atlaso as Processor

Where you use the Service to Process Customer Personal Data, you are the Controller (or, where you act on behalf of a third party, the processor) and Atlaso acts as your Processor (or sub-processor). In that capacity, Atlaso Processes Customer Personal Data only on your documented instructions, as set out in Section 4. Under CCPA/CPRA, Atlaso acts as a Service Provider with respect to such data.

2.2 Atlaso as Controller

Atlaso acts as an independent Controller for certain data it Processes in connection with the Service, including: Account and authentication data (email, user id, name, passkeys); Device registry data; subscription and billing data; content-free usage analytics (DAU/MAU counters); and infrastructure logs. This data is governed by the Atlaso Privacy Policy, not by this DPA. Where the two overlap, this DPA governs the processor relationship for Customer Personal Data and the Privacy Policy governs Atlaso's own controller processing.

2.3 Customer responsibilities

You warrant that: (a) you have established and will maintain a valid legal basis under Applicable Data Protection Law for the Processing you instruct Atlaso to perform; (b) your instructions comply with Applicable Data Protection Law; and (c) you have provided all required notices and obtained all required consents from Data Subjects. You are responsible for the accuracy, quality, and legality of the Customer Personal Data and the means by which you acquired it.

3. Subject matter, duration, nature, and purpose of Processing

The required particulars of Processing (per GDPR Article 28(3)) are set out in Annex 1 and summarised here:

  • Subject matter: Atlaso's provision of the Service: a memory layer that stores, retrieves, synchronises, and uses AI to summarise and (for Pro features) enrich Memories and related Content on your behalf.
  • Duration: For the term of your agreement with Atlaso, plus the limited period required to return or delete Customer Personal Data under Section 11.
  • Nature of Processing: Collection, storage, organisation, structuring, retrieval, transmission, synchronisation across Devices, redaction of secrets, and submission of selected Memory text to a large language model sub-processor (on every plan, for the dashboard greeting and Ambient Memory summaries; on Pro, also for enrichment and question-answering), all as described in the Privacy Policy.
  • Purpose: To provide, maintain, secure, and support the Service.
  • Types of Personal Data: As set out in Annex 1 — principally the contents of Memories and captured snippets, which may contain whatever Personal Data the Customer or its end users choose to store, plus associated Account/Device identifiers.
  • Categories of Data Subjects: As set out in Annex 1 — the Customer's authorised users and any individuals referenced within the Customer's Content.

4. Customer instructions

4.1 Processing on documented instructions

Atlaso shall Process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Atlaso will inform you of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest).

4.2 Scope of instructions

Your documented instructions are constituted by: (a) this DPA; (b) the Terms of Service and Privacy Policy; (c) your configuration and use of the Service (for example, which Connectors you enable, whether you are on the Free or Pro tier, and the Memories you deposit or capture); and (d) any further written instructions agreed by the parties. Processing necessary to provide the Pro AI features (Ambient Memory, L2 enrichment, and "Ask your memory") — which submit Content to the LLM sub-processor — is part of your instructions when you enable those features on a Pro plan.

4.3 Unlawful instructions

Atlaso shall inform you if, in its opinion, an instruction infringes Applicable Data Protection Law. Atlaso is not obliged to perform a legal review of your instructions but will notify you if it becomes aware of an apparent infringement.

5. Confidentiality

Atlaso shall ensure that any person authorised to Process Customer Personal Data (whether an employee, contractor, or Sub-processor's personnel) is subject to an appropriate obligation of confidentiality (whether a contractual or statutory duty) and Processes Customer Personal Data only as necessary to provide the Service or as otherwise instructed. Atlaso limits access to Customer Personal Data to those personnel who require access to perform their duties.

6. Security measures (GDPR Article 32)

6.1 Technical and organisational measures

Atlaso shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects. The measures in force as at the Last Updated date are described in Annex 2 (Technical and Organisational Measures).

6.2 Accurate description of encryption

For the avoidance of doubt and consistent with the Privacy Policy:

  • In transit: Customer Personal Data is encrypted in transit using HTTPS/TLS across all network paths, and database connections use TLS (sslmode=require).
  • At rest: Customer Personal Data is protected by provider-level (infrastructure) encryption at rest provided by our hosting and database sub-processors. Atlaso does not currently apply application-level (field-level) encryption to Memory content. You should not interpret any statement in this DPA as a representation that Atlaso encrypts Memory content with keys it controls at the application layer.

6.3 Secret redaction

Atlaso operates an automated secret-scrubbing process that attempts to redact credentials (such as private keys, API tokens, JWTs, bearer tokens, and high-entropy secrets) from Content on ingress and on enriched output, on a fail-closed basis. This is a best-effort defence-in-depth measure, not a guarantee. Secret material may be transiently present in transit before redaction. You must not rely on this feature and must not instruct the Processing of regulated or secret data except as permitted under Section 9 and the Acceptable Use Policy.

6.4 Updates to measures

Atlaso may update its security measures from time to time provided that such updates do not materially reduce the overall level of security of the Service.

7. Sub-processing

7.1 General authorisation

You grant Atlaso a general authorisation to engage Sub-processors to Process Customer Personal Data, subject to this Section 7. The current list of Sub-processors is maintained at Sub-processors List, which is incorporated into this DPA by reference in Annex 3.

7.2 Sub-processor obligations

Where Atlaso engages a Sub-processor, it shall do so by way of a written contract imposing data-protection obligations substantially equivalent to those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Atlaso remains fully liable to you for the performance of each Sub-processor's data-protection obligations.

7.3 Change notice and objection

Atlaso shall notify you of any intended addition or replacement of a Sub-processor, giving you a reasonable opportunity to object on reasonable, data-protection-related grounds. Notice will be given by updating the Sub-processors List and, where you have subscribed to change notifications, by the notification mechanism described there. Unless you object in writing within 30 days of notice, the change is deemed accepted. If you object on reasonable grounds and the parties cannot agree a resolution, you may terminate the affected portion of the Service in accordance with the Terms of Service as your sole remedy.

8. Assistance with Data Subject requests

8.1 Cooperation

Taking into account the nature of the Processing, Atlaso shall assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests by Data Subjects exercising their rights (including access, rectification, erasure, restriction, portability, and objection) under Applicable Data Protection Law.

8.2 Forwarding requests

If Atlaso receives a request from a Data Subject relating to Customer Personal Data, Atlaso shall, unless legally prohibited, promptly forward the request to you and shall not respond directly except on your documented instructions or as required by law.

8.3 Operational reality of erasure

You acknowledge that, as at the Last Updated date, certain erasure operations across Atlaso's systems are performed manually rather than by a self-service or fully automated mechanism. Atlaso will use commercially reasonable efforts to give effect to verified erasure and other rights requests without undue delay and within the statutory timeframes required by Applicable Data Protection Law, as described in the Privacy Policy.

9. Special categories and regulated data

The Service is not designed for, and you must not use it to Process, special categories of Personal Data (GDPR Article 9), data relating to criminal convictions, protected health information (PHI), payment-card data subject to PCI-DSS, or other data subject to heightened regulatory regimes, unless separately agreed in writing with Atlaso. This restriction is reflected in the Acceptable Use Policy. You are responsible for ensuring your Content complies with this Section.

10. Personal Data Breach notification

10.1 Notice to Customer

Atlaso shall notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event in a manner that allows you to meet your own notification obligations under Applicable Data Protection Law.

10.2 Content of notice

To the extent known and available, Atlaso's notice shall describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information. Atlaso may provide information in phases as it becomes available.

10.3 No admission

Atlaso's notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.

11. Return and deletion on termination

Upon termination or expiry of your agreement, and at your choice, Atlaso shall delete or return all Customer Personal Data and delete existing copies, unless retention is required by applicable law. Specifically:

  • You may export or retrieve your Memories through the Service prior to termination.
  • Following termination, Atlaso will delete Customer Personal Data without undue delay and within 30 days of a verified request or of termination, subject to the manual operational constraints described in Section 8.3. This 30-day window is stated identically in the Privacy Policy.
  • Legal-hold / preservation carve-out. Where Atlaso is required by applicable law, legal process, or a legal-hold or law-enforcement preservation obligation (including the duty to preserve and report suspected illegal content, such as apparent child sexual abuse material under 18 U.S.C. §2258A) to retain Customer Personal Data, the deletion window above is suspended for the data subject to that obligation, and Atlaso will retain that data only for the period and purpose required, continuing to protect it under this DPA and deleting it once the obligation ends.
  • LLM sub-processor position. Content is submitted to our large-language-model sub-processor only at the point of use, to generate results, and we do not maintain a separate store of Customer Personal Data with that sub-processor. To the extent it operates under zero-data-retention terms (Section 7 and Annex 3), it retains no Customer Personal Data to delete on termination.
  • Note on retention generally: Atlaso does not operate automated expiry of Memory content; authentication tokens expire after 90 days; transient raw capture text held in the enrichment queue is cleared after processing. See the Privacy Policy for full retention details.

12. Audits

12.1 Information and audit rights

Atlaso shall make available to you all information reasonably necessary to demonstrate compliance with this DPA and the obligations in GDPR Article 28, and shall allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you.

12.2 Process and limits

To balance audit rights against security and confidentiality:

  • You shall give Atlaso at least 30 days' prior written notice, save where an audit is required by a Supervisory Authority or following a Personal Data Breach.
  • Audits shall be conducted no more than once per twelve (12) months (except where required by a Supervisory Authority or following a breach), during business hours, in a manner that does not unreasonably disrupt Atlaso's operations, and subject to confidentiality obligations.
  • Atlaso may satisfy an audit request in the first instance by providing relevant third-party certifications, audit reports, or completed security questionnaires where these reasonably address your request.
  • Each party bears its own costs of an audit, unless the audit reveals a material breach by Atlaso, in which case Atlaso shall bear the reasonable costs.

13. International transfers

13.1 Cross-border Processing

Atlaso and its Sub-processors are located in the United States, and Atlaso's operations also involve personnel and activity in India. Customer Personal Data may therefore be transferred to, stored in, and Processed in the United States, India, and other jurisdictions in which Atlaso or its Sub-processors operate.

13.2 Transfer mechanism

Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy decision, the parties agree that the Standard Contractual Clauses apply and are incorporated into this DPA by reference:

  • For EEA transfers, the EU SCCs (Implementing Decision (EU) 2021/914) apply, with Module Two (Controller-to-Processor) where Atlaso acts as your Processor, and Module Three (Processor-to-Processor) where you act as a processor and Atlaso as your sub-processor.
  • For UK transfers, the UK Addendum to the EU SCCs applies.
  • For Swiss transfers, the EU SCCs apply with the amendments necessary under Swiss law (references to the GDPR read as the Swiss FADP; the Swiss FDPIC as competent authority).

13.3 SCC operative elements

For the purposes of the SCCs: the data exporter is the Customer; the data importer is Atlaso; the optional docking clause applies; the description of transfer is set out in Annex 1; the technical and organisational measures are set out in Annex 2; and the list of Sub-processors is set out in Annex 3 / the Sub-processors List.

The SCC Module Two / Module Three elections, the governing-law and forum elections (SCC Clauses 17 and 18), and the competent Supervisory Authority are to be completed by the parties on execution of the applicable SCCs and recorded in Annex 1; they are not pre-completed, and nothing in this DPA should be read as an assertion that the SCCs have already been executed for any given transfer. The parties further acknowledge that, because the same entity (Atlaso Labs Inc.) processes Customer Personal Data both in the United States and through its own personnel in India (an intra-organizational transfer rather than a transfer between two distinct parties), the off-the-shelf SCC Modules do not map cleanly, and appropriate Article 46 safeguards for that same-entity US↔India transfer will be put in place on execution. In the event of any conflict between the SCCs, once executed, and this DPA, the SCCs prevail with respect to the transfer.

13.4 Transfer impact assessment and India posture

The parties will cooperate in good faith on any transfer impact assessment ("TIA") reasonably required for a restricted transfer. Atlaso's Processing involving India is subject to the DPDP Act; the parties acknowledge that India-related transfer disclosures, hosting-region confirmations, and any additional safeguards remain subject to confirmation with Indian counsel before Atlaso relies on this Section for a given transfer.

14. CCPA/CPRA Service Provider terms

Where Atlaso Processes Personal Information subject to the CCPA/CPRA on your behalf:

  • Atlaso acts as a Service Provider and Processes Personal Information solely to perform the Service under your agreement (the "Business Purpose").
  • Atlaso shall not Sell or Share Personal Information, and shall not retain, use, or disclose it for any purpose other than the Business Purpose or as otherwise permitted by the CCPA/CPRA.
  • Atlaso shall not retain, use, or disclose Personal Information outside the direct business relationship with you, and shall not combine it with Personal Information from other sources except as permitted by the CCPA/CPRA.
  • Atlaso certifies that it understands and will comply with these restrictions.
  • Atlaso shall assist you in responding to verifiable consumer requests as set out in Section 8.

15. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in those Terms to the liability of a party means the aggregate liability of that party under the Terms and this DPA together. Nothing in this DPA or the Terms limits or excludes either party's liability where it may not lawfully be limited or excluded under Applicable Data Protection Law, including liability to Data Subjects under the SCCs.

16. General

  • Order of precedence. The Terms of Service are the master agreement. Where the documents conflict, the more specific document controls for its subject matter. This DPA controls only for the Processing of a business customer's personal data where Atlaso acts as processor; and the Standard Contractual Clauses control for restricted international transfers (Section 13.3). Accordingly, in the event of a conflict between this DPA and the Terms of Service or Privacy Policy regarding the Processing of Customer Personal Data in that processor relationship, this DPA prevails; and the SCCs prevail over this DPA with respect to those transfers.
  • Changes. Atlaso may update this DPA to reflect changes in Applicable Data Protection Law, Sub-processors, or the Service, provided that no update will materially reduce the protections afforded to Customer Personal Data. Material changes will be notified as described in Section 7.3 or by the means set out in the Privacy Policy.
  • Governing law. Except as otherwise required by the SCCs or by mandatory Applicable Data Protection Law, this DPA is governed by the laws of the State of Delaware, USA, without regard to conflict-of-laws rules, consistent with the Terms of Service. Nothing in this clause deprives a Data Subject or consumer of mandatory protections of their country of residence.
  • Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect.
  • Survival. Sections concerning confidentiality, security, deletion/return, liability, and international transfers survive termination to the extent necessary.

17. Contact

All enquiries — including data-protection matters, DPA execution, privacy requests, legal notices, and support — should be sent to support@atlaso.ai.

Atlaso Labs Inc. Registered-agent address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States (a registered-agent address, not an operating office; Atlaso's operations and personnel are located in India, and personal data is processed in the United States and in India).

Our EU/UK Representative (GDPR Article 27) can be reached at support@atlaso.ai. Our India Data Protection / Grievance Officer (DPDP Act) can be reached at support@atlaso.ai.

Annex 1 — Description of Processing (Article 28(3) / SCC particulars)

Data exporter: The Customer (the business entity that has accepted this DPA). Data importer: Atlaso Labs Inc., a Delaware C-Corporation, provider of the Atlaso Service.

Subject matter of the Processing: Provision of the Atlaso memory layer (dashboard, brain/API, Connectors, and CLI), enabling storage, synchronisation, retrieval, AI summaries on every plan, and (for Pro features) AI enrichment of Memories and related Content.

Duration of the Processing: For the term of the Customer's agreement, plus the return/deletion period in Section 11.

Nature and purpose of the Processing: Collection, storage, organisation, retrieval, transmission, cross-Device synchronisation, secret redaction, and submission of selected Memory text to a large language model sub-processor: on every plan, for the dashboard greeting and Ambient Memory summaries; on Pro, also for nightly L2 enrichment, "Ask your memory" queries, and Ambient distillation. Purpose: to provide, secure, support, and maintain the Service.

Types of Personal Data:

  • Contents of Memories and auto-captured conversation snippets (user-submitted text plus a truncated assistant reply), which may contain any Personal Data, project facts, decisions, preferences, or code the Customer or its end users choose to store.
  • Associated identifiers: Account email and user id, name, and server-minted Device identifiers.
  • (Special-category data is not permitted unless separately agreed — see Section 9.)

Categories of Data Subjects: The Customer's authorised users of the Service, and any individuals whose Personal Data appears within the Customer's Content.

Frequency of transfer: Continuous, for the duration of the agreement.

Competent Supervisory Authority (SCCs): determined by the data exporter's place of establishment (or, where the exporter has no EEA establishment, its EEA representative) and to be recorded here on execution of the applicable SCCs.

SCC governing law and forum (Clause 17 / 18): the EU Member State law and courts to be elected by the parties on execution of the applicable SCCs, consistent with Section 13.3.

Annex 2 — Technical and Organisational Measures (Article 32)

Atlaso maintains, at minimum, the following measures (as at the Last Updated date):

Access control and authentication

  • Authentication, session, and identity managed via our authentication sub-processor (Clerk); optional passkey support.
  • Per-tenant isolation enforced by authenticated user_id; per-project visibility is fail-closed; cross-user access attempts return HTTP 404 rather than disclosing existence.
  • Authentication tokens stored only as sha256 hashes; OAuth authorization codes and refresh tokens stored hashed; plaintext device tokens held only briefly during the approve-to-consume window.
  • Service-to-service calls between the dashboard and brain are gated by a service secret compared in constant time (secrets.compare_digest).
  • Device connection uses PKCE with loopback redirect (RFC 7636 / RFC 8252); an OAuth 2.1 authorization server with its own consent page, dynamic client registration, and token revocation.

Encryption

  • In transit: HTTPS/TLS everywhere; database connections require TLS (sslmode=require).
  • At rest: provider-level (infrastructure) encryption via hosting/database sub-processors. No application-level field encryption of Memory content (see Section 6.2).

Data minimisation and protective processing

  • Automated, fail-closed secret scrubbing on ingress and on enriched output (private keys, sk-/GitHub/AWS/Google/Slack tokens, JWTs, bearer tokens, URI credentials, high-entropy blobs).
  • IP addresses used only for in-memory rate limiting and are not persisted in any Atlaso database table (they may appear in infrastructure logs).
  • Usage analytics are content-free counters only (no prompt or code content).
  • Free-tier Content is not enriched (it is drained from the enrichment queue without enrichment); transient raw capture text is cleared from the queue after processing.

Resilience and abuse prevention

  • Rate limiting and denial-of-service guards (e.g. 64KB text cap, batch cap of 100, per-Device caps).
  • Data directories restricted with chmod 0700 file permissions.

Organisational measures

  • Access to Customer Personal Data limited to personnel who require it, subject to confidentiality obligations (Section 5).
  • Sub-processor due diligence and contractual flow-down of data-protection obligations (Section 7).

Atlaso may update these measures provided the overall level of security is not materially reduced.

Annex 3 — Approved Sub-processors

The approved Sub-processors are those listed on the Sub-processors List, which is incorporated into this DPA by reference. That page is the authoritative, current list, with its own last-updated date, and this Annex does not keep a separate copy of it.

No-training commitment. We do not operate a training endpoint and we do not train Atlaso models on your Memory. On every plan, selected Memory text is sent to Fireworks AI for the features described in our Privacy Policy Section 6, where it is processed on open models with zero data retention. We use that processing to generate your results, not to train AI models. Fireworks does not use this text to train or improve its models, because that requires an explicit opt-in, which Atlaso has not given.

This DPA cross-references the Terms of Service, Privacy Policy, Sub-processors List, Acceptable Use Policy, Refund & Cancellation Policy, and Cookie Policy.

ATLASO

One memory for every AI tool you use.

Product

  • Pricing
  • Lab
  • Contact

© 2026 Atlaso Labs Inc. All rights reserved.

Legal & policies
Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseRefundsDPASub-processors