Atlas IQ

Privacy Policy

Last updated: 2026-04-21

Atlas Concept SASU — SIRET 98002778300011

1. Data Controller

Atlas Concept SASU

Legal form: Société par actions simplifiée unipersonnelle

SIRET: 98002778300011 | VAT: FR72980027783

RCS Strasbourg

Registered address: 8 rue Alfred Kastler, 67300 Schiltigheim, France

DPO: info@atlasiq.app

Pursuant to Regulation (EU) 2016/679 (GDPR) and French Data Protection Act No. 78-17, Atlas Concept SASU is the data controller for personal data collected through the AtlasIQ platform.

2. Data We Collect

Account Data

  • First name, last name
  • Email address
  • Password (bcrypt hashed)
  • Profile photo (optional)
  • Company (optional)

Usage Data

  • IP address
  • Browser type and OS
  • Pages visited and actions
  • Session timestamps

OAuth Tokens

  • Meta Ads (AES-256-GCM encrypted)
  • TikTok Ads (encrypted)
  • Google Ads (encrypted)
  • Shopify/Amazon (encrypted)
  • CJ Dropshipping (encrypted)

Payment Data

  • Processed by Stripe — NOT stored
  • Billing email
  • Transaction history

4. Sub-Processors

NamePurposeCountryTransfer
Supabase (PostgreSQL)Primary database hostingEU (Frankfurt)EU hosting, no international transfer
Redis (Self-hosted)Caching and session managementFrance (OVH)EU hosting, no international transfer
OVH SASVPS infrastructure hostingFranceNo international transfer
OpenAIAI content generation (ad copy, product descriptions)United StatesStandard Contractual Clauses (SCCs)
StripePayment processingUnited States / IrelandStandard Contractual Clauses (SCCs), Stripe is PCI DSS Level 1 certified
SendGrid (Twilio)Transactional email deliveryUnited StatesStandard Contractual Clauses (SCCs)
SentryError tracking and application monitoringUnited StatesStandard Contractual Clauses (SCCs)
AWS (S3/SES)File storage and email infrastructureEU (eu-west-3, Paris)EU hosting, no international transfer
Meta PlatformsAd campaign management via user OAuthUnited States / IrelandStandard Contractual Clauses (SCCs)
TikTok (ByteDance)Ad campaign management via user OAuthSingapore / IrelandStandard Contractual Clauses (SCCs)
Google (Google Ads)Ad campaign management via user OAuthUnited States / IrelandStandard Contractual Clauses (SCCs), EU–US Data Privacy Framework

5. International Transfers

Transfers outside the EEA are governed by Standard Contractual Clauses (SCCs) pursuant to GDPR Articles 46(2)(c).

OpenAI

US

SCCs

AI content only — NO personal data

Meta

US/IE

SCCs

Campaigns via user OAuth

TikTok

SG/IE

SCCs

Campaigns via user OAuth

Stripe

US/IE

SCCs + PCI DSS L1

Payments

Google

US/IE

SCCs + DPF

Campaigns via OAuth

SendGrid

US

SCCs

Transactional emails

6. Security Measures

OAuth Encryption

AES-256-GCM, per-tenant keys

Transport

TLS 1.3

Passwords

bcrypt, cost ≥ 12

Access Control

RBAC

Backups

Encrypted, daily, 30d retention

Audit

Full audit logging

AtlasIQ does not hold SOC 2 Type II or ISO 27001 certifications.

7. Data Retention

DataActivePost-DeleteLegal
Account data (name, email)Duration of account30 days (soft delete)Invoices: 10 years (French Commercial Code)
OAuth tokens (Meta, TikTok, Google, Shopify)Duration of integration connectionImmediately revoked and deletedNone
Usage logs and analytics24 months rollingAnonymized after 30 daysConnection logs: 1 year (LCEN)
Payment dataProcessed by Stripe — not stored on our serversN/A (managed by Stripe)Transaction records: 10 years
Support tickets and communicationsDuration of account + 12 monthsDeleted after 30 daysNone
Cookie consent records13 months (CNIL guideline)Deleted with accountProof of consent: 3 years (statute of limitations)

8. Your Rights (GDPR)

Art. 15

Right of Access

Obtain a copy of your data via "Export" in your account or by email.

Art. 16

Right to Rectification

Correct or update your data through account settings.

Art. 17

Right to Erasure

Request deletion (30-day soft delete). Excludes invoices (10 years, Commercial Code).

Art. 18

Right to Restriction

Restrict processing in certain circumstances.

Art. 20

Right to Portability

Receive your data in JSON or CSV format.

Art. 21

Right to Object

Object to processing based on legitimate interest.

Art. 7(3)

Withdraw Consent

Withdraw cookie consent anytime via the banner.

Art. 77

CNIL Complaint

Lodge a complaint with CNIL (see section 10).

Contact info@atlasiq.app. Response within 1 month (Art. 12(3) GDPR).

9. Children's Privacy

Per GDPR Article 8, AtlasIQ is not intended for persons under 16 (minimum age in France). We do not knowingly collect data from minors.

10. DPO & CNIL

Data Protection Officer

Atlas Concept SASU8 rue Alfred Kastler, 67300 Schiltigheim, France

Email: info@atlasiq.app

CNIL

3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

Phone: +33 1 53 73 22 22

www.cnil.fr/fr/plaintes

11. Policy Changes

For material changes, we will notify you by email, display a banner in the app, and update the date above. If the change concerns consent-based processing, new consent will be requested.