← Back to Atlas

Atlas Privacy Policy

Effective date: July 22, 2026

This Atlas Privacy Policy explains how Licentium Ltd ("Licentium", "we") handles personal data in the Atlas service. It supplements the general Privacy Policy; where it differs for Atlas, this notice prevails for Atlas. "Inputs" means customer-submitted content screened through Atlas. "Outputs" means the flags, scores, suggested wording, summaries, and records that Atlas generates from Inputs.

1. Our role as controller

Licentium acts as a controller for the personal data it processes in Atlas. We determine the purposes and means of the processing described in this Policy, including the processing of personal data contained in customer Inputs.

This controller role covers account, authentication, billing, website analytics, support, direct-marketing, customer Inputs, Outputs, security, and service-administration data. Sections 2 to 7 below describe the categories, purposes, lawful bases, sharing, transfers, and retention.

A business customer that submits an Input may be a controller for its own collection and disclosure of the personal data in that Input. The customer is responsible for its own compliance, including having a lawful basis to submit the data to Atlas and providing any privacy information it is required to provide. Licentium acts as a separate controller for the processing described here.

2. Personal data we process

Identity and contact data; account and authentication data; enquiry, support and communications data; transaction and billing data; usage, device and technical data; marketing and preference data; and personal data contained in customer Inputs and resulting Outputs. Personal data in Inputs is generally obtained from the customer that submits the material. We process that data for the purposes described in section 3, including screening the Input, generating and storing Outputs, securing and administering Atlas, providing support, and complying with law. Some account, authentication, and billing fields are necessary to enter into or perform the contract; if you do not provide them, we may be unable to create an account, take payment, or provide Atlas. Mandatory fields are identified at the point of collection. We also explain whether they are required by law or contract, or are necessary to enter into a contract, and the possible consequences of not providing them.

3. Purposes and lawful bases

We do not use one broad purpose. The table sets out each purpose, our role as controller, and our lawful basis.

PurposeRoleData usedLawful basis
Screen customer Inputs and generate OutputsControllerInputs and OutputsContract where the data subject is the contracting party; otherwise legitimate interests in providing and securing the Atlas screening service. The customer is separately responsible for having a lawful basis to submit personal data. Special-category data is accepted only where expressly supported and an applicable Article 9 condition applies.
Account, authentication, and service administrationControllerAccount, authentication, usageContract where the data subject is the contracting party; otherwise legitimate interests in administering the organisation's account.
Billing, tax, and transaction recordsControllerAccount, billingContract for payment administration where the data subject is the contracting party; legal obligation for tax and accounting records; legitimate interests in fraud prevention and dispute management.
Security, fraud, and abuse preventionControllerUsage, technicalLegitimate interests; legal obligation where applicable.
SupportControllerSupport, accountContract where applicable; legitimate interests.
Product analyticsControllerAnonymous statistics or minimised usage and technical dataOutside data-protection law where data is genuinely anonymous; otherwise legitimate interests.
Optional product-improvement programme using customer Inputs or OutputsController for the separate purpose, if introducedInputs/OutputsNot used as part of the standard service. Before introducing any optional programme, Licentium will determine and document an applicable Article 6 lawful basis and, where the content includes special-category personal data, an applicable Article 9 condition. A customer's opt-in does not constitute consent on behalf of another person whose personal data appears in the content.
Direct marketing to youControllerContact, preferenceConsent or legitimate interests under Article 6, as applicable; electronic marketing is sent only with consent or under an applicable exception in the Privacy and Electronic Communications Regulations 2003, including the soft opt-in where its conditions are met.
Comply with law, enforce rightsControllerAs neededLegal obligation; legitimate interests.

4. Model training and product improvement (no-training default)

By default, we do not use your Inputs or Outputs to train AI models, and we do not permit our model providers to train on your content. Our inference providers process Atlas content under data-processing terms that prohibit training on it. We require the relevant provider terms, account settings, and routing arrangements to prohibit that use for Atlas content.

Atlas does not use Inputs or Outputs for model training or product improvement as part of the standard service. Licentium will not start an optional product-improvement programme unless it first documents the purpose, its role as controller, a valid lawful basis for each affected data subject, any Article 9 condition, minimisation, retention, the applicable withdrawal or objection route, and gives the required notice. A customer's opt-in does not by itself provide consent for another person whose data appears in an Input. The broader improvement licence in the General Terms does not apply to Atlas Inputs. These restrictions apply to both Atlas Inputs and Outputs and prevail over any inconsistent permission in the General Terms.

5. How we share data; service providers and other recipients

We use service providers to run Atlas. These may include providers of hosting and cloud infrastructure, AI inference, payment processing, authentication, communications, customer support, analytics, and security services. Current provider information identifies each relevant provider's legal entity, the service it performs, its role, the categories of personal data it processes, and its principal processing locations. Some providers may act as independent controllers for particular functions. Where a provider processes personal data on our behalf, it acts as our processor and is engaged under written terms that include the requirements of Article 28 where applicable. Before appointing or replacing a processor, Licentium carries out appropriate due diligence and puts the required written terms in place. A current provider list is available at the contracting stage and thereafter on request using the contact details in section 12. We do not sell personal data. We do not otherwise share your data except to run the service, comply with law, or on your instruction.

6. International transfers and data flows

6.1 Where data is processed. Account and content storage is in the EU (Frankfurt) for the primary production environment, as reflected in the current provider information. Some processing, in particular LLM inference and certain support or infrastructure access, may occur outside the UK/EEA depending on the provider, the service configuration, and the location from which the relevant processing or access occurs. EU hosting of storage is not the same as EU-only processing where a provider accesses data elsewhere, so we state the actual position here rather than an unqualified "EU-only" claim.

6.2 Transfer safeguards. For any restricted transfer we rely on a lawful mechanism: for UK transfers, adequacy, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses; for EU/EEA transfers, an adequacy decision or an Article 46 safeguard, together with any required transfer risk assessment. We rely on an Article 49 derogation only for a specific situation and not as the routine transfer mechanism. Details are available on request.

7. Retention and deletion

7.1 Retention. We keep each category only as long as needed, by stated period or criteria: the applicable plan, account status, deletion request, service and security needs, legal and accounting obligations, dispute-management requirements, and documented backup cycle determine the retention period for Inputs and Outputs; for review findings; for account data (life of account plus a defined period); for billing (as required by law); for logs and support records; and for backups. Legal holds may extend a period.

7.2 Deletion. Deleting a review removes it from your active review history and disables Licentium-hosted share links associated with that review. We apply the deletion request to the active production record and revoke the associated Licentium-hosted share links, subject to any legal hold or backup retention described below. It does not delete copies that you or a recipient already downloaded or exported. Backup copies expire on a rolling schedule rather than instantly; saved findings and server-held exports are handled as described in the app. The backup-retention period is determined by our documented backup cycle. Saved findings and server-held exports remain subject to the retention settings and deletion controls shown in Atlas, unless a legal hold or other legal requirement applies.

8. Read-only share links

Where enabled, Atlas share links use technical and organisational controls designed to restrict unauthorised access, which may include unique link tokens, expiry and revocation controls, search-engine exclusion, access logging, and authentication where available. Once a link expires or is revoked, Atlas stops serving the shared review through that link.

9. Security

We implement technical and organisational measures appropriate to the risk. We select and review those measures having regard to the nature, scope, context and purposes of processing, the state of the art, implementation costs, and the likelihood and severity of risks to individuals.

10. Your rights

You may request access, correction, deletion, restriction, portability, and objection, and may withdraw consent, subject to legal limits. These rights apply to personal data in customer Inputs and Outputs as well as account and other service data. To exercise a right or make a data-protection complaint, contact us using the privacy contact details in section 12. We may ask for information that reasonably identifies the relevant customer, review, or content so that we can locate the data and verify the request. For complaints covered by section 164A of the Data Protection Act 2018, we provide a clear route to complain, acknowledge receipt within 30 days, take appropriate steps without undue delay, keep you informed of progress, and communicate the outcome. You may also make a complaint to the UK Information Commissioner under section 165 of that Act or, where the EU GDPR applies, to the competent supervisory authority.

11. EU users

Where the EU GDPR applies to our processing, you may exercise your data-protection rights by contacting Licentium directly using the details in section 12. You may also lodge a complaint with a competent supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. Licentium is established in the United Kingdom. We also maintain our UK data-protection fee registration where required. Where applicable, our current registration can be checked on the ICO's public register.

12. Contact

Controller: Licentium Ltd, registered in England and Wales (company no. 17057360), registered office 128 City Road, London, EC1V 2NX. Privacy contact: <hello@licentium.io>.