Agent Atlas ← Back to agent-atlas.co

Data Processing Addendum

Effective date: June 20, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Agent Atlas ("Agent Atlas," "we," "us," or "our") and the customer who accepts the Terms of Service ("Customer," "you," or "your") for use of Atlas for Real Estate (the "Service"). It governs our processing of personal information that you submit to the Service or that we access on your behalf through your connected accounts. Agent Atlas is operated from Richmond, Virginia, USA.

If there is a conflict between this DPA and the Terms of Service regarding the processing of personal information, this DPA controls.

1. Definitions

Terms used but not defined here have the meaning given in the Terms of Service.

2. Roles of the parties

With respect to Customer Personal Data, you are the Controller (or business) and we are your Processor (or service provider). You determine the purposes and means of processing. We process Customer Personal Data only on your behalf and under your documented instructions, as described in Section 3. Where you are itself a processor acting for another controller (for example your brokerage), you confirm that you have the authority to engage us as a sub-processor.

3. Scope and instructions for processing

We will process Customer Personal Data only:

Your use of the Service, including your account configuration and the tasks you enable, constitutes your complete and documented instructions. We will inform you if, in our reasonable opinion, an instruction violates Applicable Data Protection Law.

Annex 1 sets out the subject matter, duration, nature, purpose, categories of Data Subjects, and types of Customer Personal Data.

4. Your responsibilities as Controller

You are responsible for:

5. Confidentiality

We will treat Customer Personal Data as confidential and will ensure that personnel authorized to process it are bound by appropriate confidentiality obligations and access it only as needed to provide the Service.

6. Security

We will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, as described in Annex 2. You are responsible for your own use of the Service, including protecting your credentials and managing who in your organization has access. You are responsible for assessing whether our measures meet your requirements under Applicable Data Protection Law.

7. Sub-processors

You authorize us to engage Sub-processors to process Customer Personal Data. Our current Sub-processors are listed in Annex 3. We will impose data protection obligations on each Sub-processor that are substantially similar to those in this DPA, and we remain responsible for each Sub-processor's performance of those obligations.

We will provide notice of any new Sub-processor (for example by updating Annex 3 or by email or in-product notice) before that Sub-processor begins processing Customer Personal Data. You may object to a new Sub-processor on reasonable data protection grounds by notifying us within ten (10) days of notice. If we cannot reasonably accommodate your objection, your sole remedy is to stop using the affected part of the Service and, if it is material, to terminate your subscription as described in the Terms of Service.

8. Assistance with Data Subject requests

The Service provides features that let you access, correct, export, and delete Customer Personal Data. Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to a Data Subject's request to exercise rights under Applicable Data Protection Law, to the extent you cannot do so yourself through the Service. If a Data Subject contacts us directly about Customer Personal Data, we will, where permitted by law, refer them to you.

9. Personal Data Breach notification

We will notify you without undue delay, and where feasible within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include the information reasonably available to us to help you meet any obligation to notify regulators or Data Subjects. We will take reasonable steps to mitigate and remediate the breach. Our notification is not an acknowledgment of fault or liability.

10. Data protection impact assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you carry out any data protection impact assessment or prior consultation with a regulator that Applicable Data Protection Law requires in connection with your use of the Service.

11. International transfers

We are located in the United States and process Customer Personal Data in the United States and in the locations used by our Sub-processors. Where Applicable Data Protection Law requires a transfer mechanism for personal data originating outside the United States (for example the EU or UK), the parties agree that the relevant Standard Contractual Clauses (or the UK International Data Transfer Addendum) are incorporated into this DPA by reference and apply to such transfers, with the parties completing the required details. If a transfer mechanism is held invalid, the parties will work in good faith to put a valid mechanism in place.

12. Return and deletion of Customer Personal Data

On termination or expiry of the Service, and on your written request, we will delete or return Customer Personal Data in our control, except for data we are required or permitted to keep by law. We will delete remaining copies within a reasonable period, and backups are purged on a rolling basis, as described in our Privacy Policy. You can also delete Customer Personal Data at any time through the Service.

13. Audits and compliance evidence

We will make available information reasonably necessary to demonstrate our compliance with this DPA, such as summaries of our security practices and any third-party assessments we hold (for example our Google CASA assessment, where applicable). Any audit right is satisfied first by our providing this information. Where Applicable Data Protection Law grants a further audit right, the parties will agree in advance on reasonable scope, timing, confidentiality, and cost, and any on-site audit will be limited to once per year absent a Personal Data Breach or a regulator's requirement.

14. US state privacy law terms (service provider / processor)

For Customer Personal Data subject to the CCPA/CPRA, VCDPA, or similar US state laws, we act as a service provider or processor. We will:

We certify that we understand and will comply with these restrictions.

15. Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, including the limitation of liability section. This DPA does not increase either party's aggregate liability beyond the cap in the Terms of Service.

16. Term

This DPA takes effect when you accept the Terms of Service and continues until we have ceased all processing of Customer Personal Data and completed the return or deletion described in Section 12. The provisions that by their nature should survive will survive termination.

17. Contact

Questions about this DPA can be sent to atlas@agent-atlas.co.


Annex 1: Details of processing

Annex 2: Technical and organizational security measures

We maintain measures designed to protect Customer Personal Data, which include:

These measures may change as the Service evolves, provided we do not materially reduce the overall level of protection during your subscription term.

Annex 3: Approved Sub-processors

Sub-processorPurposeLocation
Anthropic (Claude)AI inference and processingUnited States
StripePayment processingUnited States
SupabaseDatabase and authenticationUnited States
Google Cloud (KMS)Encryption key management for stored credentialsUnited States
RenderApplication and background-worker hostingUnited States
NetlifyMarketing website hostingUnited States
LangfuseObservability and tracing of AI activityUnited States
SentryError trackingUnited States

We will update this Annex before adding or replacing a Sub-processor, as described in Section 7. Confirm each Sub-processor's actual processing location and data residency settings before publishing, since these can change based on your configuration and the provider's plan.