Data processing agreement
Last updated: 20 September 2026
This agreement under Art. 28 GDPR is part of the terms of use wherever the organization using Atlas is a business or another body. It is concluded when the organization accepts the terms; nothing has to be signed. An organization that needs a signed copy can ask for one at alex@tailored.hu.
1. Parties and roles
The controller is the organization that uses Atlas. The processor is the operator of this installation:
Alex Szabo
Alex Szabo
Email: alex@tailored.hu
This agreement covers the personal data in the content the organization keeps in Atlas. Where the operator decides about purposes and means itself, such as for accounts, security, billing and analytics, it is a controller; the privacy policy describes that processing.
2. What is processed
| Item | Description |
|---|---|
| Subject matter | Providing Atlas: storing, displaying, transmitting and backing up the organization's content |
| Duration | The term of the contract, and the 90 days after it described in the terms |
| Nature and purpose | Hosting a web application for planning and tracking work, including git repositories |
| Kinds of data | Names, usernames and email addresses of members; whatever personal data members put into tasks, goals, comments, chat messages, pull requests, reviews, notes, files and git commits |
| People concerned | The organization's members, and anyone the members mention in their content or who authored commits |
| Special categories | None intended; the terms ask the organization not to store them without a legal basis |
3. Instructions
The processor processes the data only on documented instructions from the controller. The terms, this agreement and the way the controller's members use Atlas's functions are those instructions. Further instructions can be given in text form to alex@tailored.hu, as far as they are within what Atlas offers.
If the processor believes an instruction breaks data protection law, it says so at once and may hold off until the controller confirms or changes it. If the law of the European Union or of a member state requires the processor to process the data otherwise, it tells the controller beforehand unless that law forbids it.
4. Confidentiality
Everyone the processor allows to handle the data is bound to confidentiality, by contract or by law, and stays bound after their work ends. Access is limited to those who need it to run the service.
5. Security
The processor takes the measures required by Art. 32 GDPR. They are listed in the annex. The processor may change them as technology moves on, as long as the level of protection does not fall.
6. Sub-processors
The controller agrees in general to the processor using sub-processors. Those in use now are:
| Sub-processor | Task | Place |
|---|---|---|
| IONOS SE, Montabaur, Germany | Servers, disks and the storage for encrypted backups | Germany |
| The operator's mail provider, named on request | Delivering verification, invitation and password reset emails | European Union |
The processor binds each sub-processor to the same data protection duties as in this agreement and remains liable to the controller for them. It announces a new or replaced sub-processor by email to the organization's admins at least 30 days ahead. The controller may object for good reason within that time; if the two cannot agree, the controller may end the contract to the date of the change and gets back the fee for the unused time.
GitHub, Google and Creem are not sub-processors. Members who sign in with GitHub or Google, and admins who buy a membership from Creem, deal with them directly.
7. Place of processing
The data is processed in the European Union. A transfer to a third country happens only on the controller's instruction or with its agreement, and only under the conditions of Art. 44 and following GDPR.
8. Helping the controller
Taking into account the nature of the processing, the processor helps the controller:
- to answer requests from people who exercise their rights. Atlas lets members correct and delete their own data; an admin can remove a member. A request that reaches the processor directly is passed on to the controller without delay and not answered by the processor itself;
- to meet its duties under Art. 32 to 36 GDPR, namely security, reporting breaches, impact assessments and consulting the authority, with the information the processor has.
Help that goes beyond what Atlas offers and beyond the processor's legal duties may be charged at cost, after the processor has named the cost.
9. Personal data breaches
The processor tells the controller without undue delay, and where feasible within 48 hours, after it becomes aware of a personal data breach that affects the controller's data. The notice goes by email to the organization's admins and says what is known: what happened, which data and roughly how many people are affected, the likely consequences and what is being done. What is not known yet follows as it becomes known.
10. Deletion and return
When the contract ends, the processor hands over and deletes the data as described in the terms: it keeps the content for 90 days, hands it over on request in that time, and then deletes it, or earlier if the controller asks. Backups expire as described in the privacy policy. Data the processor must keep by law is kept locked for that purpose only.
11. Proof and audits
The processor gives the controller the information needed to show that this agreement is kept. As a rule this is done with written answers and documents, such as the description of the measures in the annex and the certificates of the hosting provider.
If that is not enough in a particular case, the controller, or an auditor it names who is bound to confidentiality and is not a competitor of the processor, may carry out an inspection: with 30 days' notice, during business hours, at most once a year unless there is a specific reason, and without access to the data of other customers. Each side bears its own costs.
12. Liability and rank
Liability follows the terms of use, within the limits of Art. 82 GDPR. Where this agreement and the terms say different things about data protection, this agreement comes first.
Annex: technical and organizational measures
Confidentiality
- Servers in IONOS data centers in Germany, certified to ISO 27001; physical access is controlled by IONOS.
- Administrative access only over SSH with keys; password logins are off; the firewall allows only web traffic and SSH.
- The database, telemetry and internal services are reachable only from the server itself.
- Each organization's data is separated in the application; every query is scoped to the organization, and this is covered by automated tests.
- Passwords are hashed with argon2id. Sessions, tokens and single-use links are stored only as SHA-256 hashes. Two-factor secrets are encrypted with AES-256-GCM.
- Two-factor authentication is available to every member.
- Telemetry carries pseudonyms instead of identities; request paths are scrubbed of personal parts.
Integrity
- All traffic is encrypted with TLS; certificates are renewed automatically.
- A strict content security policy, security headers and rate limits on sign-in, sign-up, password reset and uploads.
- An audit log records changes to organizations, without names or email addresses.
- Changes to the software are reviewed, tested automatically and released through a scripted deployment.
Availability and resilience
- Encrypted backups every hour and every night on a separate disk, and every night to a storage bucket in a different region.
- Backups are checked automatically every week.
- The service records logs, traces and metrics; security updates to the operating system are installed automatically.
Regular review
- Dependencies and container images are pinned and updated regularly.
- At least once a year the whole installation is restored from the backups onto a separate server, and these measures are reviewed.