Data Processing Addendum
How Atlas processes personal data on behalf of customers, and the safeguards we apply.
Last updated: 17 July 2026
This Data Processing Addendum ("DPA") describes how Atlas TMS processes personal data on behalf of its customers in connection with the Service. It supplements the agreement between the parties and is intended to reflect the requirements of the GDPR and comparable laws. This is a generic sample overview provided for illustration.
1. Roles of the parties
For personal data processed through the Service, the customer acts as the controller and Atlas acts as the processor. Atlas processes personal data only on documented instructions from the customer, including with regard to international transfers, unless required to act otherwise by law.
2. Scope and purpose of processing
The subject matter of processing is the provision of the Service. The duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are as described in the agreement and the customer's configuration of the Service — typically including customer, account, transaction, and staff-user data.
3. Subprocessors
Atlas engages subprocessors to help deliver the Service, such as cloud infrastructure, monitoring, and communication providers. We impose data protection obligations on each subprocessor consistent with this DPA, maintain a current list of subprocessors, and provide a mechanism for customers to be informed of changes and to object on reasonable grounds.
4. International transfers
Where personal data is transferred across borders, we rely on appropriate transfer mechanisms, such as Standard Contractual Clauses or equivalent safeguards, together with supplementary measures where necessary to protect the data.
5. Security measures
Atlas maintains technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, audit logging, network segmentation, and continuous monitoring. Measures are reviewed and updated as part of our security programme.
6. Data-subject requests
Taking into account the nature of the processing, Atlas assists the customer with appropriate technical and organisational measures to respond to requests from data subjects exercising their rights — including access, correction, deletion, restriction, and portability.
7. Breach notification
Atlas notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, and provides information reasonably necessary for the customer to meet its own notification obligations.
8. Return and deletion
On termination of the Service, and at the customer's choice, Atlas deletes or returns personal data processed on the customer's behalf, unless retention is required by applicable law.
9. Contact us
To request a signed copy of our DPA or to ask a question about data processing, please contact us.