Atol, Inc. ("Atol", "we", "our", or "us") is a Delaware corporation. We operate the Atol platform: an identity, authorization, and device-trust service available at atol.sh and related subdomains.
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Atol, Inc. is the data controller for personal data we process about visitors to atol.sh and subscribers to our beta waitlist. For personal data we process on behalf of our customers when they use the Atol platform to manage their own end users, Atol acts as a data processor and each customer is the controller. That processing is governed by our Data Processing Addendum (DPA).
Contact address for privacy matters: privacy@atol.sh -- see Section 12 for how to submit requests.
When you submit your email on atol.sh to join the private beta, we collect:
Purpose and lawful basis. We send a single confirmation email and, once the beta opens, one launch notification. Under GDPR Art. 6(1)(a) the lawful basis is your explicit consent, given by checking the consent box and clicking the confirmation link in the email (double opt-in). Under CASL (Canada's Anti-Spam Legislation) your express consent is recorded at the same point. You can withdraw consent at any time by clicking "unsubscribe" in any email we send or by emailing privacy@atol.sh.
CCPA / CPRA notice at collection. If you are a California resident, the category of personal information collected is "Identifiers" (email address, IP address). The business purpose is communications about the Atol beta program. We do not sell or share this information with third parties for cross-context behavioral advertising (see Section 5).
When you use the contact form at /contact we collect your name, email address, and the message you write. We use this solely to reply to your inquiry (GDPR Art. 6(1)(f) -- legitimate interest in responding to genuine business inquiries; CCPA category: Identifiers and "Internet or other electronic network activity").
Customers who sign up for the Atol console provide an email address, authenticate via OIDC PKCE, and may configure an organization with one or more members. We process this data to deliver the service (GDPR Art. 6(1)(b) -- necessary for performance of a contract). Account data is retained for the life of the account and then only as long as needed to complete deletion, expire backups, resolve disputes, and meet legal obligations.
When your customers use an application that has integrated the Atol SDK, the @atol-sh/fingerprint browser library may collect the signals described in our technical documentation at Device intelligence: data collection. These include browser and hardware characteristics used to build a device fingerprint for fraud prevention and session-binding purposes.
In this context Atol is a data processor acting on behalf of our customer (who is your controller). The customer is responsible for obtaining any required consent from their end users. Our DPA and the technical controls described in the SDK documentation apply.
Any HTTPS connection to our servers produces standard infrastructure logs that include IP addresses, HTTP status codes, and timestamps. We use these for security monitoring, abuse prevention, and operational diagnostics. We retain each log category only for the shortest period reasonably necessary for those purposes, considering security investigations, contractual requirements, and applicable law.
The public atol.sh marketing site does not use advertising pixels, session replay, visitor fingerprinting, or third-party analytics. Its initial page load makes no third-party request. Fonts, scripts, and images needed to render the page are served by Atol.
Public forms use Google reCAPTCHA Enterprise for abuse prevention. The reCAPTCHA script is not requested until you check the unticked consent box next to that form and submit it. If you leave the box unchecked, no data is sent to Google. After consent, Google may receive device and network data and may set a cookie under Google's privacy terms. That consent is limited to verifying the submitted form and is not consent to advertising or cross-context behavioral tracking.
The Atol console uses session cookies necessary for authentication (GDPR Art. 6(1)(b); CCPA category: "Internet or other electronic network activity"). No third-party advertising or analytics cookies are set.
This section supplements the rest of this policy for California residents and is provided pursuant to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Categories of personal information collected (12 months): Identifiers (email, IP address); Commercial information (subscription status); Internet or other electronic network activity (log data, reCAPTCHA signals); Professional or employment-related information (company name, where voluntarily provided).
Do Not Sell or Share My Personal Information. Atol does not sell personal information and does not share personal information with third parties for cross-context behavioral advertising. You may email privacy@atol.sh to confirm or exercise an opt-out right.
Global Privacy Control. We recognize a supported Global Privacy Control signal as an opt-out of sale and sharing for that browser or device. Because no sale- or sharing-related request is enabled on our sites, the signal preserves the same default-denied state. We do not treat the later absence of the signal as consent. A separate, affirmative request to use reCAPTCHA applies only to that form's abuse-prevention check.
Sensitive personal information. We do not collect or use sensitive personal information as defined under CPRA for any purpose other than those listed in Section 7027(m) of the CPRA regulations.
Your California rights: Right to know (categories and specific pieces), right to delete, right to correct, right to opt out of sale/sharing, right to limit use of sensitive personal information, right to non-discrimination. To exercise these rights see Section 12.
We will verify your identity before processing a deletion or access request. We do not discriminate against you for exercising these rights.
We share personal data only with the sub-processors listed at /subprocessors. We do not sell personal data. We do not share personal data with third parties for advertising.
We may disclose data where required by law, to enforce our Terms of Service, or to protect the rights or safety of Atol, our customers, or others.
Atol is headquartered in the United States. If you are located in the European Economic Area (EEA), UK, or Switzerland, your personal data is transferred to and processed in the United States. We rely on the European Commission's Standard Contractual Clauses (SCCs) (2021/914/EU) -- Module 1 (controller-to-controller) for transfers of waitlist and contact data -- as the legal mechanism for these transfers.
Transfers from the EEA to sub-processors are covered by Module 2 (controller-to-processor) SCCs incorporated in our agreements with those sub-processors. See the DPA for the mechanism applicable to customer data.
We implement technical and organizational security measures including TLS 1.2+ for all connections, HSM-backed key management for cryptographic operations, access controls, and structured audit logging. However, no internet transmission is 100% secure.
We will notify affected controllers and, where required, supervisory authorities, of any personal data breach in accordance with GDPR Art. 33 and applicable law.
We use Google reCAPTCHA Enterprise on public forms only after the visitor's specific affirmative consent. reCAPTCHA is subject to Google's Privacy Policy and Terms of Service. Google processes the reCAPTCHA token and associated anti-abuse signals as a service provider under our agreement.
We use Postmark to send transactional email (beta confirmation, waitlist confirmation). We use Google Cloud for infrastructure hosting. A full list of sub-processors is at /subprocessors.
Under the GDPR and UK GDPR you have the right to: access your personal data; rectify inaccurate data; erasure ("right to be forgotten") in certain circumstances; restriction of processing; data portability; object to processing based on legitimate interests; and not be subject to solely automated decisions with legal or similarly significant effects.
Where processing is based on consent (waitlist email), you have the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with your local supervisory authority. In the EEA this is your national data protection authority; in the UK this is the Information Commissioner's Office (ICO) at ico.org.uk.
The Atol platform is not directed at children under 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us at privacy@atol.sh and we will delete it promptly.
To submit a privacy request (access, deletion, correction, opt-out, portability) or to withdraw consent, email privacy@atol.sh with the subject line "Privacy request" and a description of your request. We will respond within 30 days (GDPR) or 45 days (CCPA), with one extension of equal length where reasonably necessary.
Privacy contact: privacy@atol.sh
We may update this Privacy Policy from time to time. If we make material changes we will notify registered users by email and update the version date at the top. Your continued use of the platform after changes constitutes acceptance of the updated policy.