Privacy Policy
Version 2026-07-17. Covers processing where Atlas Holly is the controller. For data inside our customers' websites (for example their customers' bookings) the customer is the controller and we are the processor - see the Data Processing Agreement.
1. What we process
- Account data: name, email address, language preference, sign-in events.
- Company and billing data: company name, registration number, VAT number, address, country, invoice history. Card details are handled by Stripe and never reach our servers.
- Usage data: technical logs (IP address, timestamp, action) for operations and security, and an outbound email log (recipient and subject, never content) pruned after 30 days.
- Support tickets: what you write to support, including attachments.
2. Purposes and legal bases
- Providing and invoicing the service - performance of contract.
- Operations, troubleshooting and security (logs, suppression lists, abuse protection) - legitimate interest.
- Bookkeeping and archiving of invoice records - legal obligation (the Swedish Bookkeeping Act).
- Product emails about your subscription and the service - performance of contract; newsletters only with consent, revocable in every mailing.
3. Recipients and subprocessors
Data is shared only with the vendors required to run the service: Amazon Web Services (hosting and storage, EU/Stockholm region), Stripe (payments), Amazon SES (email) and AI services via Amazon Bedrock (EU region) for content generation. We never sell personal data. The current subprocessor list is part of the Data Processing Agreement.
4. Retention
- Account data: for as long as the account exists. On deletion everything personal is removed immediately.
- Invoice records: seven years in de-identified archive form (Bookkeeping Act).
- The email log: 30 days. Technical security logs: at most 90 days.
- Backups: 35 days, then deleted automatically.
5. Where data is processed
All hosting is within the EU (AWS eu-north-1, Stockholm). No third-country transfer takes place as part of normal operations; should a vendor require it, the EU Commission's standard contractual clauses are used.
6. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interest. Data export and account deletion are available as self-service in the product. You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
7. Cookies
We use essential cookies only (session and security). Our visitor statistics are first-party and cookie-free. That is why you see no cookie banner.
8. Contact
Questions about personal data are handled through the in-service support function or the contact form on this website.