Atlas AI
Menu
Legal

Privacy Policy

Version 1.1 · Last updated: July 21, 2026

1. About Us

The controller responsible for the personal data described in this policy is:

DataFit Solutions OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Registered at Tartu County Court, registry code 17005668
VAT number: EE102809620
Email: info@datafit-solutions.com

We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR. For any questions regarding data protection, please contact us at info@datafit-solutions.com.

2. Scope & Our Role

This Privacy Policy applies to all services offered by DataFit Solutions OÜ under the Atlas AI brand:

  • Web application at app.atlas-ai.health
  • Public API for third-party integrations

We act in two distinct roles, and this policy is structured accordingly:

  • Part A - Personal data we process as controller: the account, contact, billing and technical data of our API customers, for which we determine the purposes and means of processing.
  • Part B - Data we process as processor: audio recordings and text submitted through the Atlas AI API, for which we act solely as a data processor under Art. 28 GDPR on the customer's instructions.

Atlas AI is intended for API customers who integrate the service into their own products. For data submitted via the Atlas AI API, the API customer is the data controller under GDPR, and DataFit Solutions OÜ acts as a data processor (see Part B).

Part A - Personal Data We Process as Controller

This part describes the personal data for which DataFit Solutions OÜ is the controller, primarily the account and contact data of our API customers.

3. Data We Collect

3.1 Account & Contact Data

When you register for and use the service, we process:

  • Name and email address
  • Authentication data (managed by Auth0)
  • Usage and billing data (API requests processed, quota usage)

Providing this account information is necessary to create and maintain your account and to enter into and perform the contract for the Atlas AI service. Without it, we cannot provide the service.

3.2 Technical Data

  • IP addresses and access times (in server logs)
  • Device information and browser type
  • API key identifier and request metadata (timestamps, audio duration, job status)

4. How We Use This Data

  • Authentication and authorisation of users
  • Usage accounting and quota management
  • Detection and prevention of abuse and security incidents
  • Responding to support requests

5. Legal Basis for Processing (GDPR)

  • Contract performance (Art. 6(1)(b) GDPR): Account, authentication, and usage and billing data.
  • Legitimate interests (Art. 6(1)(f) GDPR): Server logs, security monitoring, and operation of the service. Our legitimate interests include maintaining the security and reliability of our services, preventing fraud and abuse, and enforcing our contractual rights.
  • Legal obligation (Art. 6(1)(c) GDPR): Where required by applicable law, e.g. statutory retention of billing records.

6. Recipients

We do not sell your data or share it with third parties for commercial purposes. Depending on the processing activity, the categories of recipients to whom personal data may be disclosed are:

  • Cloud hosting and infrastructure providers
  • Authentication providers
  • Competent public authorities, where required by law

The specific sub-processors we engage across both roles are listed in the General Information section below.

7. Data Retention

  • Account information: Retained for the duration of the contractual relationship and fully deleted within 30 days of contract termination.
  • Billing records: Retained for up to 7 years where required to comply with statutory accounting and tax obligations, and then deleted.
  • Support emails: Retained for the duration of the contractual relationship and deleted thereafter.
  • Authentication records: Identity data is retained for the duration of the account. Authentication and access logs are retained for 365 days and then deleted.
  • Server logs: Technical access logs are retained for 365 days and then deleted.

Retention of data processed as a processor is described in Part B.

8. Data Security

  • All data encrypted in transit via TLS 1.2+
  • Data at rest encrypted with AES-256 via AWS KMS
  • Infrastructure hosted in private AWS networks (C5-certified) within the EU, with no direct internet exposure
  • Access controls following least-privilege principles
  • Regular security reviews
  • Security controls based on ISO/IEC 27001 practices

These security measures apply to all data we process, including data under Part B. Additional information regarding our security measures is available on our Security page.

9. International Data Transfers

All data is processed and stored exclusively within the European Economic Area (EEA). No transfers outside the EEA take place.

Part B - Data We Process as Processor

This part describes data submitted through the Atlas AI API. For this data, the API customer is the controller and DataFit Solutions OÜ acts solely as a processor under Art. 28 GDPR.

10. API Data & Our Role as Processor

When users submit audio recordings and related text through the Atlas AI API, these are processed on behalf of the API customer acting as controller. This includes:

  • Audio recordings
  • Transcriptions of recordings
  • AI-generated text documents
  • Submitted context text and documents

This data may contain personal data, and where it relates to health it may include special categories of personal data under Art. 9 GDPR. DataFit Solutions OÜ processes such data solely on the instructions of the API customer, as a data processor. Data processed through the Atlas AI API is provided by the API customer integrating the service.

For any personal data contained in audio or text submitted via the API, the legal basis is determined solely by the data controller (the API customer). DataFit Solutions OÜ does not determine the purpose or means of processing. Where processing supports medical diagnosis or the provision of health care, Art. 9(2)(h) GDPR typically applies; the controller determines the applicable Article 9 condition.

11. Retention of API Data

  • Audio files: Processed transiently and deleted after the request is fulfilled, unless a longer retention period is agreed in writing.
  • Generated documents / transcripts: Automatically deleted no later than 48 hours after processing, unless a longer retention period is agreed in writing.

12. End Users Whose Data Appears in Submissions

If you are an end user whose personal data may have been included in audio or text processed via the Atlas AI API, your data controller is the company or application that integrated Atlas AI. Please contact them directly to exercise your rights. Where we process such data solely on behalf of API customers as a processor, the transparency obligations under Articles 13 and 14 GDPR are fulfilled by the relevant API customer acting as controller.

General Information

13. Sub-processors

To deliver the service we engage the following sub-processors. Each is bound by a data processing agreement under Art. 28 GDPR, including EU standard contractual clauses where applicable, and processing of your data takes place within the EU/EEA:

  • Amazon Web Services (AWS): cloud hosting and storage (Part A and Part B)
  • Auth0 by Okta: user authentication (Part A)
  • Speechmatics: speech recognition (Part B)
  • Google Cloud Platform: cloud computing services (Part B)

A current list is also available on request at info@datafit-solutions.com.

14. Your Rights under GDPR

As a data subject you have the following rights in respect of the data we process about you as controller:

  • Access (Art. 15 GDPR): What data we process about you
  • Rectification (Art. 16 GDPR): Correction of inaccurate data
  • Erasure (Art. 17 GDPR): Deletion of your data
  • Restriction (Art. 18 GDPR): Restriction of processing
  • Portability (Art. 20 GDPR): Receipt of your data in a machine-readable format
  • Objection (Art. 21 GDPR): Objection to processing
  • Withdrawal of consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.

To exercise your rights over data we process directly, contact us at info@datafit-solutions.com. We will respond within 30 days. If your data appears in API submissions, please see Part B and contact the relevant API customer.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement. The supervisory authority for DataFit Solutions OÜ is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee.

15. Cookies

We use only strictly necessary cookies and similar technologies required for authentication, security and the operation of the service. We do not use advertising or analytics cookies on our website. Because these cookies are strictly necessary to provide the service, no cookie consent is required for them.

16. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and "last updated" date at the top of this page reflect the latest revision. For material changes, API customers will be notified by email. Previous versions of this Privacy Policy are available on request at info@datafit-solutions.com.

17. Contact

DataFit Solutions OÜ
Email: info@datafit-solutions.com
More information: Security page