Data Processing Addendum

Article 28 terms for personal data AtlastFMS processes on behalf of a business customer. This addendum does not cover data for which AtlastFMS is an independent controller.

Version 2026-08-10 · Effective date: 10 August 2026

1. Scope, parties and priority

This addendum forms part of the Business Terms between the customer as controller (or processor appointing another processor) and ATLASTFMS LTD as processor. It applies to customer personal data processed to provide AtlastFMS. It prevails over conflicting data-protection wording in the Business Terms. The Privacy Policy explains processing for which AtlastFMS is controller.

2. Processing details

  • Subject and purpose: hosting, securing, organising, extracting, presenting, exporting and transmitting business financial records and connected-service data to provide AtlastFMS.
  • Duration: the account term plus the documented return, deletion, backup and legal-retention period.
  • Nature: collection, storage, retrieval, structuring, comparison, classification, generation of drafts, disclosure to authorised integrations, restriction, export and deletion.
  • Data subjects: authorised users and the customer's clients, suppliers, workers, advisers, counterparties and other people represented in business records.
  • Data types: contact and identity data, transaction and invoice details, bank and payment data, tax identifiers and records, documents, communications, device/security data and customer-selected AI inputs/outputs.

3. Instructions, law and confidentiality

AtlastFMS will process customer personal data only on documented instructions in the agreement and authorised product actions, including for a UK restricted transfer, unless UK law requires otherwise. Where lawful, we will tell the customer before processing required by law. We will promptly inform the customer if we reasonably believe an instruction infringes data-protection law. People authorised to process the data are bound by confidentiality.

4. Security

Taking account of risk, state of the art, cost and context, AtlastFMS will maintain appropriate technical and organisational measures. Current product measures include authenticated access, tenant-scoped row-level security, server-only secrets, encryption of HMRC OAuth tokens, HTTPS in production, rate limits, validation gates, audit evidence, access restriction and incident handling. We may improve measures without materially reducing overall protection.

5. Subprocessors and transfers

The customer gives general written authorisation for the providers identified in the current Subprocessor Register. Customers and authorised representatives can request a copy from contact@atlastfms.com. AtlastFMS will impose materially equivalent Article 28 duties, remain responsible for subprocessor performance as required by law, and give reasonable advance notice of material changes with an objection process. Restricted transfers require an applicable UK adequacy regulation or safeguards such as the IDTA or UK Addendum and a transfer risk assessment where required.

6. Rights, compliance and incidents

Taking account of the processing and information available, AtlastFMS will reasonably assist the customer with data-subject requests, security, breach notifications, DPIAs, prior consultation and compliance evidence. We will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data and provide available information needed for the customer's assessment and notification. The customer remains responsible for deciding whether and how to notify regulators or individuals.

7. Return, deletion and audit

At the customer's choice and subject to authenticated export capabilities, AtlastFMS will return or delete customer personal data after service end unless UK law requires retention. Backup deletion follows the secure backup lifecycle; restored data remains protected and subject to the deletion instruction. We will make information reasonably necessary to demonstrate Article 28 compliance available and permit proportionate audits, normally beginning with documents or an independent report, subject to confidentiality, security, reasonable notice and avoiding disruption. This does not restrict regulator powers.

8. Customer obligations and liability

The customer is responsible for lawful instructions, transparency to data subjects, lawful bases, data minimisation, user authority and responding as controller. Each party's liability under this addendum is subject to the liability terms in the Business Terms; neither party is relieved of direct statutory responsibilities.