[ legal ]

Data Processing Addendum

Last updated: June 17, 2026 (v2026-06-17)

This Data Processing Addendum ("DPA") supplements the Terms of Service between Atol, Inc. ("Atol" or "Processor") and the customer entity ("Controller") and governs Atol's processing of personal data on behalf of the Controller in connection with the Atol platform. In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.

This DPA is entered into as of the date the Controller first accepts the Terms of Service (the "Effective Date").

1. Definitions

  • "Controller" means the customer who determines the purposes and means of processing personal data using the Atol platform.
  • "Processor" means Atol, Inc., which processes personal data on behalf of the Controller.
  • "Data Subject" means an identified or identifiable natural person whose personal data is processed.
  • "Personal Data" has the meaning given in applicable Data Protection Law, including EU GDPR Art. 4(1).
  • "Data Protection Law" means, as applicable: the EU General Data Protection Regulation (EU 2016/679) ("GDPR"); the UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"); the California Consumer Privacy Act as amended by CPRA ("CCPA/CPRA"); and any other applicable data protection or privacy law.
  • "Sub-processor" means a third party engaged by Atol to process personal data in connection with providing the Service.
  • "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

2. Processing details (GDPR Art. 28(3))

  • Subject matter: Provision of the Atol identity, authorization, and device-trust platform.
  • Duration: The term of the Terms of Service plus the deletion/return period in Section 9.
  • Nature and purpose: Authenticating end users, evaluating authorization decisions, processing device signals, and maintaining audit logs, solely on behalf of the Controller and in accordance with documented instructions.
  • Types of personal data: As determined by the Controller; may include identifiers (email, user ID), authentication credentials, device characteristics, IP addresses, and access decision logs.
  • Categories of data subjects: The Controller's end users and administrators.

3. Processor obligations

Atol agrees to:

  • Process personal data only on documented instructions from the Controller, including with regard to transfers (see Section 7), unless required to do so by applicable law (in which case Atol will inform the Controller before processing, unless prohibited);
  • Ensure that all persons authorized to process personal data are under appropriate obligations of confidentiality;
  • Implement the technical and organizational security measures described in Section 5;
  • Respect the conditions in Section 4 for engaging sub-processors;
  • Take appropriate technical and organizational measures to assist the Controller in responding to data subject requests (Section 6);
  • Assist the Controller in ensuring compliance with GDPR Arts. 32-36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and information available;
  • Delete or return all personal data to the Controller after the end of the service, and delete existing copies, unless retention is required by applicable law (Section 9);
  • Make available to the Controller all information necessary to demonstrate compliance with GDPR Art. 28 and allow for and contribute to audits (Section 8).

4. Sub-processors

The Controller provides general written authorization for Atol to engage sub-processors. Atol will maintain a current list at /subprocessors and will give the Controller at least 14 days advance notice of any new or replacement sub-processor by updating that page and, where the Controller has registered an email address, by email.

The Controller may object to a new or replacement sub-processor on reasonable data protection grounds within 14 days of notice. If a reasonable objection cannot be resolved, the Controller may terminate the applicable service on 30 days written notice without penalty.

Atol requires all sub-processors to comply with data protection obligations substantially equivalent to this DPA. Atol remains fully liable to the Controller for the acts and omissions of its sub-processors.

5. Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, Atol implements and maintains the following measures:

  • Encryption in transit: TLS 1.2 or higher on all external connections; TLS on internal service-to-service connections.
  • Encryption at rest: Database-level and application-level encryption using HSM-backed key management (Aiku CA key hierarchy).
  • Access controls: Role-based access to production systems; multi-factor authentication required for privileged access; least-privilege principles enforced via the Atol authorization engine itself.
  • Audit logging: Append-only structured audit logs of all authentication events, access decisions, and administrative actions. Logs are immutable after write.
  • Vulnerability management: Automated dependency scanning; regular security reviews; responsible disclosure program.
  • Incident response: A documented incident-response plan including procedures for detection, containment, notification, and post-incident review.
  • Physical security: Data is hosted on Google Cloud Platform, which maintains ISO 27001 and SOC 2 Type II certifications.

6. Data subject requests

Atol will promptly notify the Controller if it receives a request from a data subject exercising rights under applicable Data Protection Law. Atol will not respond to such requests on the Controller's behalf without the Controller's written authorization but will cooperate and provide reasonable assistance to enable the Controller to respond within the applicable time limits.

The Atol API provides endpoints for Controller-initiated deletion and export of end-user data. Device data erasure is described in the technical documentation at /docs/privacy.

7. International data transfers

The Controller instructs Atol to transfer personal data to the United States (where Atol is headquartered and its primary infrastructure operates) and, where sub-processors are engaged, to any country in which those sub-processors operate.

For transfers from the EEA or UK to Atol (as Processor), the parties incorporate the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914/EU, Module 2 (Controller to Processor), including the UK Addendum issued by the ICO where applicable. These SCCs are incorporated by reference as if set out in full in this DPA, with the following selections: (a) Clause 7 (docking clause) -- applicable; (b) Clause 11 (redress) -- the optional language is not included; (c) Clause 17 -- governing law: Republic of Ireland (for EU transfers) / England and Wales (for UK transfers); (d) Clause 18 -- courts: the competent courts of the relevant governing law jurisdiction.

8. Audits

Upon the Controller's written request no more than once per year (and at any time following a Security Incident), Atol will provide the Controller with relevant security documentation (including any current third-party audit reports, certifications, or SOC 2 reports) to verify compliance with this DPA, subject to reasonable confidentiality obligations.

If documentation is insufficient, the Controller may request an audit conducted by the Controller or a mutually agreed third-party auditor, at the Controller's expense, with at least 30 days written notice and subject to reasonable conditions to protect Atol's confidential information and other customers' data.

9. Deletion and return of data

Upon termination or expiry of the Terms of Service (or on the Controller's earlier written request), Atol will, at the Controller's election, either delete or return all personal data processed on the Controller's behalf and delete existing copies, unless retention is required by applicable law.

Deletion will be completed within [PLACEHOLDER: e.g. '90 days'] of the termination date. Atol will confirm completion in writing. Append-only audit logs that cannot be selectively deleted will be pseudonymized or suppressed from any further processing within the same period.

10. Security incident notification

Atol will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting the Controller's personal data. Notification will be sent to the email address registered for the Controller's account or via the security contact designated in the console.

The notification will include, to the extent then known: the nature of the incident, the categories and approximate number of data subjects and personal data records concerned, the likely consequences, and the measures taken or proposed. Atol will provide further information as it becomes available.

The Controller is responsible for notifying supervisory authorities and data subjects as required under applicable Data Protection Law. Atol will cooperate and provide reasonable assistance.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where applicable Data Protection Law provides otherwise.

Where both parties are liable to a data subject for damage caused by a breach of GDPR, they will be jointly and severally liable as provided by GDPR Art. 82, subject to the right to claim back the part of compensation corresponding to the other party's part of responsibility.

12. CCPA provisions

To the extent the CCPA/CPRA applies, Atol agrees:

  • Atol processes personal information only as a "service provider" as defined in CCPA, solely for the business purpose of providing the Atol platform;
  • Atol will not sell or share personal information (as those terms are defined in CCPA/CPRA) or retain, use, or disclose it outside the direct business relationship with the Controller or for any commercial purpose other than providing the Service;
  • Atol will cooperate with the Controller in responding to consumer requests to know, delete, or opt out, as required under CCPA/CPRA;
  • Atol certifies that it understands and will comply with these restrictions.