Version: 2026-08-30 (provisional). Structured on GDPR Article 28 requirements and what the Atly product actually does. Not a substitute for counsel-reviewed contracts.
1. Parties and roles
- Processor: AtlyTech s.r.o., IČO 29944627, DIČ CZ29944627, registered office Dandova 2619/13, Horní Počernice, 193 00 Praha 9, registered at Městský soud v Praze, oddíl C, vložka 454920, (“Atly”, “we”).
- Controller: the customer company that creates an isolated company space in Atly and connects its communication systems (“Customer”, “you”).
- This Data Processing Agreement (DPA) applies when Atly processes personal data on your behalf to provide the Atly AI operations service.
2. Subject matter and duration
Atly processes Customer personal data to provide AI-assisted operations features (inbox/WhatsApp/Messenger triage, drafting, briefing, Company DNA, calendar proposals, human approval queues; later optional missed-call follow-up). Processing continues for the term of the service relationship and for a reasonable closure window after termination or account deletion request, unless a longer period is required by law.
3. Nature and purpose of processing
Nature: infrastructure operation, storage, retrieval, analysis, transcription, summarisation, drafting, logging, and transmission to configured sub-processors as needed to run the product.
Purpose: deliver Atly features described in product documentation and the Terms; improve operational reliability of the Customer’s isolated company space (not training Atly-owned foundation models on Customer content).
4. Types of personal data
Depending on connected channels and settings, processing may include:
- Operator account data linked to the company (name, email, authentication identifiers, locale).
- Business communication content and metadata: email messages; WhatsApp Business messages when enabled; Facebook Messenger messages when a company Page is connected (Page ID, PSID, 24-hour reply window; not a personal profile); SMS to or from the Atly company number when that number can send or receive SMS (not a general SMS inbox, not a campaign); optional missed-call audio (transient) / transcripts / short outbound SMS replies to those callers; calendar event subjects/descriptions/times; related contact identifiers.
- Operational records: PendingAction proposals, AuditLog entries, UsageLog usage counters, Company DNA / style corrections (DNA extraction anonymises PII locally, as far as technically possible, before selected LLM paths).
- When the account holder orders a live AutoReply number (including a Czech mobile number): company address, registration papers, and representative ID forwarded to Twilio or Telnyx for the number order. Atly does not keep file copies after the upload; the number provider stores them for regulatory review.
Special categories of data are not sought by Atly. Customers must not intentionally upload special-category data unless they have a lawful basis and instruct Atly accordingly.
5. Categories of data subjects
- Customer’s employees and operators.
- Customer’s clients, suppliers, and other communication counterparts appearing in connected mail, WhatsApp, Messenger, calendar, or (later) missed-call data.
6. Customer instructions
Atly processes personal data only on documented Customer instructions: use of the product features, connected integrations, autonomy/LLM settings, and written instructions (including support requests). Atly informs the Customer if an instruction appears to infringe GDPR; Atly may refuse unlawful instructions.
7. Confidentiality
Persons authorised to process personal data are bound by confidentiality obligations (contractual and/or statutory).
8. Security measures (summary)
Technical and organisational measures include, as implemented in product:
- TLS for live integrations and HTTPS for the application.
- Encryption of integration login details at rest (AES-256-GCM).
- Password hashing with argon2id for password-based accounts.
- Application-level isolation so each company only sees its own data in queries.
- Human approval for outbound customer email, WhatsApp, Messenger, and SMS (proposals require human approval; send_email / send_whatsapp / send_messenger / send_sms do not auto-execute). SMS is only to a known contact or a missed-call caller, and only where the company number can send SMS. A general SMS inbox, campaign SMS, and reading SMS from the owner's personal phone are not offered.
- The company must switch LLM use on, and can switch it off with an emergency stop, before customer content is sent to an LLM.
- Audit logging of approve / reject / execute and sensitive settings changes.
- Twilio or Telnyx webhook signature verification (WhatsApp / Messenger and, later, Call Control); missed-call recordings deleted after transcription where the pipeline completes successfully.
Details: product Security documentation and internal RoPA.
9. Sub-processors
Customer authorises Atly to use the following categories of sub-processors as configured for the deployment:
- Database / infrastructure provider for PostgreSQL and application infrastructure (including Google Cloud Logging / Monitoring when deployed on GCP).
- Google (OAuth, Gmail, Google Calendar) when Customer connects Google.
- Google (sign-in via OAuth) when Customer uses Google to sign in to Atly.
- Microsoft Entra ID (work or school sign-in) when Customer uses Microsoft to sign in to Atly.
- Microsoft Graph when Customer connects Microsoft mail/calendar.
- IMAP / SMTP mail providers when Customer configures generic mail login details.
- CalDAV calendar providers when Customer configures CalDAV.
- Together AI (primary LLM inference) when Customer enables LLM customer content.
- OpenAI API only when Customer connects their own OpenAI API key.
- Stripe for subscription billing and Customer Portal (payment cards handled by Stripe; no card store in the product).
- Twilio (primary) or Telnyx (backup for GB, PL, BE, NL, SE, LT) for the WhatsApp Business API company number and, on Twilio, a company Facebook Page for Messenger, number-order KYC documents (address and registration papers including for a Czech mobile number), and later missed-call Call Control / recordings and optional callback SMS, when Customer uses Phase 2 channel features (`ENABLE_PHASE_2`).
- Meta Platforms (WhatsApp Business and Facebook Messenger Page infrastructure) when Customer enables the WhatsApp channel; message content and sender phone numbers transit Meta's WhatsApp Business platform. Provider transfer tools (e.g. SCCs) apply per Meta's terms.
- Speech-to-text provider configured by Atly for voice transcription when voice is enabled.
- Sentry (Functional Software, Inc.) for application error diagnostics. Personal data in error payloads is scrubbed before transmission (`sendDefaultPii` disabled; `beforeSend` filters). Provider transfer tools (e.g. SCCs) may apply depending on Sentry organisation region. SaaS retention is not wiped per company account via product API.
- Cloudflare (Turnstile) for bot protection on Atly's unauthenticated forms (sign-up, sign-in, password reset, Demo, public booking and estimate links). Cloudflare receives the visitor IP, user agent, and browser signals for the challenge; it does not receive Customer communication content. Provider transfer tools (e.g. SCCs) apply per Cloudflare's DPA.
Atly will inform Customers of material sub-processor changes via product notice or documentation update with reasonable advance notice where feasible. Continued use after notice constitutes acceptance on a provisional basis until counsel provides a formal sub-processor schedule.
10. International transfers
Where a sub-processor processes data outside the EEA/UK, transfers rely on the provider’s applicable transfer mechanisms (e.g. SCCs, adequacy) as stated in that provider’s DPA. Customers should review provider terms for their region.
11. Assistance to the controller
Taking into account the nature of processing, Atly assists the Customer with:
- Responses to data-subject requests (access, rectification, erasure, restriction, portability, objection) to the extent data is available in the product (disconnect in product settings, deletion/account-closure requests).
- Security incident notification without undue delay after Atly becomes aware of a personal-data breach affecting Customer data in Atly systems.
- DPIA and prior consultation support by providing product documentation (RoPA, security summary) on request.
12. Retention, return, and deletion
- Customer may disconnect integrations in product settings; synced provider data then follows product sync/cleanup rules.
- Inbound and outbound WhatsApp, SMS/MMS and e-mail attachments (images, video, PDF) are stored in Atly-controlled EU object storage under the company prefix and kept as operational records for as long as the message is retained — until the Customer wipes or closes the account. Company wipe deletes that object prefix.
- Missed-call audio is intended to be deleted after successful STT processing; transcripts/summaries may remain as operational Message / PendingAction records until Customer deletion or account closure.
- On termination or written deletion request, Atly will delete or return Customer personal data in Atly-controlled storage within a reasonable period, except data Atly must retain under law or for dispute/security logs (minimised and access-controlled).
13. Audits
Upon reasonable written request, and no more than once per year unless a breach investigation requires otherwise, Atly will make available information necessary to demonstrate Art. 28 compliance (documentation, security summary). On-site audits require mutual agreement on scope, timing, and confidentiality; Customer bears external auditor costs unless a material breach by Atly is confirmed.
14. Support-assisted account recovery
Atly support staff can perform two narrowly defined administrative acts on a Customer's isolated company space, so that a Customer is not permanently locked out when the account holder is unreachable. Both are performed only at the Customer's request:
- Recording acceptance of updated legal documents. When this DPA or the Terms are revised, only the account holder can accept the new version in the product, and the company is held at the acceptance screen until they do. Where the account holder cannot act — they have left the Customer, or lost access to their account — Atly support staff may record that acceptance for the Customer.
- Reassigning the account-holder role within the Customer's own team. Atly support staff may make another user who already belongs to that company its account holder; the previous account holder becomes an admin. A person from outside the company cannot be added or made account holder this way, and Atly support staff cannot make themselves an account holder.
Both acts concern account administration only. They do not give Atly support staff access to Customer communication content, and they are not a consent to such access; Atly access to Customer data continues to be governed by sections 6 and 7.
Each act is written to the company's audit log as a separate internal-operations entry naming the person at Atly who performed it, the company concerned, the versions or roles affected, and the reason they gave. It is recorded distinctly from the same act performed by the Customer, so the two cannot be confused when the log is read later. Atly provides the relevant audit records to the Customer on request.
15. AI annex (product guarantees)
- No training: Customer personal data is not used to train or fine-tune third-party LLM foundation models by Atly. Processing is via API (Together AI; OpenAI only when Customer uses their own API key, with store=false on OpenAI Responses where applicable).
- PII redaction: local redaction/anonymisation as far as technically possible before selected LLM paths (especially Company DNA).
- Human approval: outbound email, WhatsApp, Messenger, and SMS require human approval; calendar writes follow product approval rules.
- Transparency: Atly selects models on Together AI for your plan; optional Customer OpenAI API key where product settings allow it; AI-generated outputs are labelled in-product; outbound mail includes AI disclosure footer and X-Atly-AI-* metadata.
- Audit: approve, reject, execute, and sensitive settings changes are logged in AuditLog.
- See also /legal/ai-policy.
16. Liability and provisional status
Liability allocation for this provisional DPA follows the Terms of Service until counsel issues a signed Art. 28 agreement. This document describes what the product actually does; it is a provisional in-product acceptance text for pilots and procurement transparency.
17. Precedence
If counsel later provides a signed DPA, that signed document prevails over this provisional text for the covered relationship. The in-product acceptance version is identified as DPA_VERSION 2026-08-30.
Full public page: /legal/dpa. Related: /legal/privacy, /legal/ai-policy, /legal/terms.
← Back to product