Data Processing Addendum

Last updated

This addendum applies whenever Atmos processes personal data on your behalf. It is part of the Terms of Service and takes effect when you accept them. You do not need to sign it separately. If your procurement process requires a signed copy, write to support@atmoslab.dev and we will countersign this exact text.

1. Parties and roles

Processor: Atmos Security Consultoria em Ti LTDA, CNPJ 67.252.845/0001-45, Rua Pais Leme 215, Conj 1713, Pinheiros, São Paulo SP, 05424-150, Brazil.

Controller: the customer identified on the Atmos account, meaning the organization or person that owns the workspace.

You are the controller of the personal data your use of Atmos submits to us, and we are your processor for it. For the data we need to run our own business, such as your own account and billing details, we are a controller in our own right and the Privacy Policy governs it rather than this addendum.

In this addendum, data protection law means the Brazilian General Data Protection Law (LGPD, Law 13.709/2018), the EU General Data Protection Regulation 2016/679 and the UK GDPR, each to the extent it applies to the processing.

2. Our instructions

We process personal data only to provide the service described in the Terms, and only on your documented instructions. Your use of the product is itself an instruction: running a scan, uploading its findings, inviting a teammate and asking us for support are all instructed processing. We will tell you if an instruction appears to us to breach data protection law, and we may refuse to carry it out.

If the law requires us to process data beyond your instructions, we will tell you before we do, unless that same law forbids the notification.

We do not sell personal data, we do not use it for advertising, and we do not use it to train machine learning models.

3. Confidentiality

Everyone we let near your data is bound by confidentiality obligations and is given access only to what their role needs. Access to production data is restricted and logged.

4. Security

We implement the technical and organizational measures in Annex II, and we keep them at least as protective over time. If we change a measure, the replacement will be equivalent or better.

5. Subprocessors

You give us general authorization to use subprocessors. The subprocessors page describes the categories we use, and the current named list, with what each provider receives and where it processes, is available through the trust review described there.

Before a new subprocessor starts processing your personal data, we will notify workspace owners by email, naming it. You may object on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the affected subscription and we will refund the unused part of any prepaid period.

We impose data protection obligations on each subprocessor that are no less protective than this addendum, and we remain responsible to you for their performance.

6. Helping you with data subject requests

The product gives you export and deletion for your own workspace, which handles most requests without us. Where a request needs us, we will help you answer it within a reasonable time, taking into account what the request is and what we hold. If a data subject contacts us directly about data we hold for you, we will not answer for you beyond telling them to contact you, unless the law requires otherwise, and we will pass the request on.

7. Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences and the measures we have taken or propose. We will keep you updated as we learn more, and we will help you meet your own notification duties.

8. Deletion and return

You can export your data at any time while the account is open. When the agreement ends, we delete the personal data we process for you within 90 days, except what we must keep to comply with the law. An erasure request you make under the Privacy Policy is completed within 30 days, whether or not the agreement has ended. The fiscal records we are required to hold are described in the Privacy Policy, and they stay protected by this addendum for as long as we hold them.

9. Audits

On reasonable written request, and not more than once a year unless a regulator or a breach requires otherwise, we will give you the information necessary to demonstrate compliance with this addendum, including our security documentation and any third-party reports we hold. Where that is not enough for your legal obligations, we will agree an audit of scope, timing and cost that does not disrupt the service or expose another customer's data.

10. International transfers

Where personal data protected by the GDPR or the UK GDPR is transferred to a country without an adequacy decision, the European Commission's Standard Contractual Clauses apply, module two (controller to processor), and are incorporated into this addendum by this reference, with the UK International Data Transfer Addendum where the UK GDPR applies. Annexes I and II below populate the annexes those clauses require. Transfers out of Brazil follow the international transfer rules in LGPD Chapter V.

Annex I: the processing

Subject matterProviding the Atmos application security scanner and platform under the Terms of Service.
DurationFor as long as the account exists, plus the retention periods in the Privacy Policy.
Nature and purposeReceiving and storing scan findings, showing them to your team, metering usage against your plan, sending account email, and supporting you.
Categories of data subjectsYour workspace members and the people you invite, and the contributors to the repositories you scan.
Categories of personal dataAccount identifiers, names, email addresses and avatar URLs from GitHub. Workspace membership and invitations. One-way hashes of committer email addresses, which are pseudonymous personal data about third parties. Findings and their file paths, which can identify an individual indirectly through repository content. Source lines, only where you have turned the snippet option on. Audit logs including IP addresses. Billing identifiers.
Sensitive dataNone is requested and none is required. Do not put special categories of personal data into repository paths, rule names or support messages.
FrequencyContinuous, on each scan and each use of the platform.
Location of processingThe United States, plus the processing locations of the subprocessors on the current list (section 5).

Annex II: technical and organizational measures

  • Encryption. Data encrypted in transit with TLS and at rest by the storage provider.
  • Access control. Production access limited to the people who need it, authenticated individually and logged. Workspace tokens stored as hashes, shown once, expiring where you set an expiry, revocable at any time.
  • Data minimization in the product itself. Source lines are omitted from uploads by default. Committer email addresses never leave the customer machine, only hashes do. Values matched by secret detection rules are redacted before upload. Payment events are reduced at ingest to the billing fields, so personal details from the payment processor are never stored.
  • Tenant separation. Data is scoped to a workspace, and access checks are enforced on every request rather than by the interface alone.
  • Deletion. Account and workspace deletion cascades to findings, projects, tokens and invitations. Audit logs including IP addresses purge automatically at 12 months.
  • Secure development. Changes reviewed before merge, dependencies checked against advisories, and the product is run against itself.

Precedence

If this addendum conflicts with the Terms of Service on the processing of personal data, this addendum wins. If it conflicts with the Standard Contractual Clauses, the clauses win. Everything else in the Terms stays in force, including the limitation of liability, which applies to this addendum as one aggregate cap across both documents.