DATA PROCESSING AGREEMENT
How Atom9 processes personal data on your behalf.
This Data Processing Agreement (DPA) applies when a customer uses Atom9 to process
personal data of that customer's own users. It sets out the GDPR Article 28 terms:
what Atom9 may do with the data, how it is secured, who else may process it, and how
rights, transfers, and deletion are handled.
Effective date & status
July 23, 2026. This DPA forms part of the Terms between Atom9 and the customer. Where a signed customer agreement includes a specific DPA, that signed document controls. In this DPA, the customer is the data controller and Atom9 is the data processor for the personal data of the customer's end-users. Enterprise customers can request a countersigned copy through our data request form.
DPA 1
Roles and scope of processing.
1.1 Controller and processor
The customer determines the purposes and means of processing its end-users' personal data and is the controller. Atom9 processes that personal data only on the customer's behalf and is the processor. For Atom9's own account, billing, and security data about the customer, Atom9 acts as an independent controller under the Privacy Policy.
1.2 Subject matter, duration, nature and purpose
Subject matter: provision of the Atom9 identity and platform services. Duration: the term of the Terms plus any legally required retention. Nature and purpose: authenticating end-users, and — where the customer enables it — storing and managing end-user profile and service data so the customer can operate its own service.
1.3 Categories of data and data subjects
Data subjects: the customer's end-users (and, where applicable, the customer's staff). Categories: identifiers and contact data (email, phone), authentication data (credentials held only as hashes, session and device metadata), and — only where the customer configures managed profiles — the profile fields the customer defines. The customer must not submit special-category data except in a workspace configured for it and with a lawful basis (Terms 5.3).
1.4 Documented instructions
Atom9 processes personal data only on the customer's documented instructions, including the configuration the customer sets in the product and this DPA, unless law requires otherwise (in which case Atom9 informs the customer where permitted). Atom9 will tell the customer if, in its opinion, an instruction infringes data-protection law.
DPA 2
Confidentiality and security.
2.1 Confidentiality
Atom9 ensures that people authorised to process the personal data are bound by confidentiality and access it only as needed to provide the service.
2.2 Security measures (Article 32)
Atom9 applies appropriate technical and organisational measures, including: encryption of secrets at rest and pseudonymisation of identifiers; per-customer data isolation; access control, session and service authentication; a tamper-evident audit trail; key management and rotation; backups; monitoring; and incident response. Security details are summarised on the Security page and may evolve as the service improves, without reducing the overall level of protection.
DPA 3
Sub-processors.
3.1 Authorised sub-processors
The customer gives general authorisation for Atom9 to engage sub-processors to help provide the service — for example infrastructure hosting, AI model inference, transactional email delivery, and social-login identity providers where the customer enables them. Atom9 maintains a current list of sub-processors and makes it available to the customer.
3.2 Flow-down and changes
Atom9 imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable for its sub-processors. Atom9 will give the customer notice of an intended addition or replacement of a sub-processor, giving the customer the opportunity to object on reasonable data-protection grounds.
DPA 4
Assistance to the controller.
4.1 Data-subject rights
Taking account of the nature of the processing, Atom9 provides tools and reasonable assistance so the customer can respond to end-user requests to access, correct, delete, restrict, port, or object. Where Atom9 receives a request directly, it refers the person to the responsible customer unless legally required to act.
4.2 Security, breaches, and impact assessments
Atom9 assists the customer with its obligations under Articles 32 to 36, including security, breach handling, and data-protection impact assessments, taking into account the information available to Atom9. Atom9 notifies the customer without undue delay after becoming aware of a personal-data breach affecting the customer's data, with the information needed for the customer to meet its own notification duties.
DPA 5
International transfers.
5.1 Transfer safeguards
Where personal data is transferred outside the EU/EEA — for example to a sub-processor — Atom9 relies on an appropriate transfer mechanism such as an adequacy decision, Standard Contractual Clauses, or an equivalent lawful safeguard, and applies additional measures where required. The sub-processor list identifies where processing takes place.
DPA 6
Return, deletion, and audits.
6.1 Deletion or return on termination
On termination, and at the customer's choice, Atom9 deletes or returns the personal data it processes for the customer, except where law requires Atom9 to retain it (for example bookkeeping or dispute records), in which case the data is retained only for that purpose and under restriction. Atom9's routed-erasure model suppresses, holds where a legal basis requires, and then scrubs personal data; residual copies in encrypted backups age out on the backup lifecycle.
6.2 Information and audits
Atom9 makes available the information reasonably necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the customer or an auditor it mandates, subject to reasonable notice, confidentiality, and security. Atom9 can satisfy audit requests through documentation, its security and compliance materials, and third-party reports where available.
DPA 7
General.
7.1 Order of precedence and contact
This DPA supplements the Terms; if they conflict on the processing of personal data, this DPA controls. Data-protection questions and requests for a countersigned copy go through our data request form (see Contact & legal information). Governing law follows the Terms (Sweden).