Skip to main content

Legal

Data Processing Addendum

Effective Date: August 10, 2026

This Data Processing Addendum ("DPA") is between SingleStack Ventures, LLC, doing business as Atlas Visibility ("Atlas"), and the Client that has accepted the Atlas Terms of Use or an applicable order. It forms part of the agreement between Atlas and Client when Atlas processes Client Personal Data on Client's behalf.

1. Scope and Definitions

"Client Personal Data" means personal information contained in Client Materials that Atlas processes on Client's behalf to provide the Services. "Data Protection Law" means a U.S. privacy or data protection law applicable to that processing. "Process," "personal information," "controller," "business," "processor," and "service provider" have the meanings given by applicable Data Protection Law.

This DPA does not apply when Atlas processes information for its own independent business purposes as described in the Privacy Policy, including account administration, security, legal compliance, and Atlas's own website analytics or advertising activities.

2. Roles and Instructions

Client acts as the controller or business and Atlas acts as the processor or service provider for Client Personal Data, except where applicable law assigns a different role. Client instructs Atlas to process Client Personal Data as necessary to provide, secure, support, document, and improve the reliability of the contracted Services; create and publish authorized deliverables; comply with the agreement; and follow Client's documented lawful instructions.

Atlas will not sell Client Personal Data, share it for Atlas's own cross-context behavioral advertising, retain or use it outside the business relationship for an unrelated commercial purpose, or combine it with personal information received from another source, except as permitted by applicable Data Protection Law.

3. Processing Details

  • Subject and purpose: visibility services, knowledge-base development, AI-assisted content, publishing, reporting, support, security, and related contracted operations
  • Duration: the service relationship and any additional period permitted by the agreement or required for deletion, legal, security, backup, or recordkeeping purposes
  • Data: business contact information, Client Materials, authorized knowledge-base information, content, correspondence, credentials where required, technical metadata, workflow records, and limited personal information included by Client in those materials
  • People: Client's representatives, personnel, customers, prospects, vendors, reviewers, and other individuals whose information Client lawfully provides

The Services are not designed for protected health information, payment-card numbers, government identification numbers, children's data, or other regulated or highly sensitive information. Client will not provide that information unless Atlas expressly agrees in a signed addendum.

4. Client Responsibilities

Client is responsible for the lawfulness, fairness, accuracy, and transparency of its instructions and Client Personal Data. Client will provide required notices, obtain required consents, honor applicable rights, minimize information supplied to Atlas, and ensure that its instructions do not violate Data Protection Law or third-party rights.

5. Atlas Obligations

Atlas will:

  • process Client Personal Data only on documented instructions
  • ensure that personnel authorized to process it are subject to appropriate confidentiality obligations
  • maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the processing
  • reasonably assist Client with applicable rights requests, security obligations, assessments, and regulator inquiries, taking into account the nature of the processing
  • notify Client if Atlas reasonably believes an instruction violates applicable Data Protection Law and may suspend the affected processing while the parties address the concern

6. Security

Atlas's safeguards may include access controls, authentication, least-privilege practices, encryption where appropriate, secure transmission, system and provider configuration, backups, vulnerability and dependency review, logging, incident response, and personnel or contractor controls. No security program can guarantee that an incident will never occur.

7. Subprocessors

Client gives Atlas general authorization to engage subprocessors needed to provide the Services. Atlas will require each subprocessor to protect Client Personal Data through written obligations appropriate to the services it performs. Atlas remains responsible for its subprocessors to the extent required by applicable law and the agreement.

Atlas maintains a current Subprocessors and Service Providers page. Atlas will update that page when a material provider is added or replaced and will provide direct notice where required by applicable law or an Order. Client may raise a reasonable, documented data-protection objection by contacting Atlas promptly. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate only the affected Service.

8. Rights Requests

If Atlas receives a verified request concerning Client Personal Data, Atlas may direct the requester to Client unless prohibited by law. On Client's written request and at Client's expense for unusually burdensome work, Atlas will provide reasonable assistance using capabilities available to Atlas. Client remains responsible for responding to the requester.

9. Security Incidents

Atlas will notify Client without undue delay after confirming a breach of security affecting Client Personal Data for which notice is required by applicable law. Notice will include information reasonably available to Atlas. Atlas's notice is not an admission of fault or liability. Client is responsible for notices to its own customers, regulators, or other parties unless law assigns that duty to Atlas.

10. Legal Requests

Atlas may disclose Client Personal Data when required by valid legal process. Where legally permitted, Atlas will notify Client before disclosure and reasonably cooperate with Client's effort to seek confidential treatment or narrow the request.

11. Return and Deletion

At the end of the Services, Atlas will return or delete Client Personal Data on written request when reasonably practicable, unless retention is required or permitted for legal holds, security, backups, fraud prevention, insurance, dispute resolution, or legal, tax, accounting, and contract records. Information published at Client's direction or retained independently by third parties may remain outside Atlas's control.

12. Information and Audits

On reasonable written request, Atlas will provide information reasonably necessary to demonstrate compliance with this DPA. If required by applicable law and the information supplied is insufficient, Client may request one audit per year during normal business hours, subject to reasonable scope, confidentiality, security, noninterference, and cost controls. An auditor may not be a competitor of Atlas. Atlas may satisfy an audit request with a current independent report where appropriate.

13. Provider Terms and Retention

Provider retention, model-improvement, access, and deletion practices depend on the provider, product tier, contract, and Atlas account configuration. This DPA does not make an account-specific no-training or fixed-retention promise unless Atlas confirms it in a signed writing.

14. Order of Precedence and Liability

If this DPA conflicts with the Terms on the processing of Client Personal Data, this DPA controls only for that subject. The limitations of liability, dispute provisions, governing law, and other remedies in the Terms apply to this DPA unless applicable law requires otherwise.

15. Contact

Questions or requests concerning this DPA may be sent to team@atlasvisibility.com.

Protect your business from being erased by Google and ChatGPT.

The Atlas Visibility Engine was built for every local business that depends on customers finding them online.

Get Started →