ATLAS Data Processing Addendum
Status: Effective August 15, 2026 Provider mailing address: On Spot Solutions LLC, 1 Washington Mall #1282, Boston, MA 02108, United States Version: 2026-08-11.1
This Addendum is incorporated into the ATLAS Customer Service and Data Use Agreement and governs Customer Personal Data processed by On Spot on Customer's behalf.
1. Parties, scope and precedence
Identify the customer as controller/business and On Spot Solutions LLC as processor/service provider where applicable. Define the controlling agreement, covered ATLAS services, term, conflicts and any processing where On Spot acts independently.
2. Processing details
- Subject matter: provision, security, support and administration of ATLAS.
- Duration: contracted term plus approved retrieval, deletion and backup periods.
- Nature/purpose: authentication; diagnostic AI processing; equipment/session history;
- Data subjects: customer personnel, contractors, administrators, invited users,
- Data categories: identity/contact, role, account, facility/equipment, diagnostic
- Special/sensitive data: not intended; customer must not submit it unless expressly
Organization administration; reporting; billing; support; security and audit.
support contacts and other authorized persons represented in customer content.
transcripts/outcomes, uploads/photos, support, usage, audit/security and billing metadata.
authorized under a signed addendum and supported technically.
3. Documented instructions and confidentiality
Process Customer Personal Data only on documented instructions, including service use, order forms and support requests, unless law requires otherwise. Bind personnel with appropriate confidentiality and access restrictions.
4. Security measures
Attach an accurate security exhibit covering access control, tenant isolation, encryption, secrets, logging/monitoring, vulnerability and dependency management, backups/recovery, incident response, personnel controls and secure deletion. Do not include unverified SOC 2, PITR, RPO/RTO, penetration-test, SSO or MFA claims.
5. Subprocessors
List approved subprocessors, purpose and processing location; require protective terms; define general/specific authorization, material-change notice and objection/remedy. Reconcile Supabase, Render/approved successor hosting, Hostinger, Resend, Stripe, Sentry, and the exact active Anthropic/OpenAI API configuration.
6. Assistance
Define reasonable assistance for data-subject requests, security inquiries, DPIAs, regulator consultation, audits and customer compliance. Allocate costs for exceptional requests and preserve confidentiality/tenant boundaries.
7. Security incidents
Define a verified incident-notification channel, timing standard, required available information, updates, cooperation, mitigation and no admission of fault. Align with the approved incident-response plan and governing law.
8. Return, export and deletion
At termination or pilot expiration, provide the contracted retrieval/export opportunity, then delete or return Customer Personal Data subject to legal retention and documented backup cycles. Explicitly separate Enterprise/OEM parent termination from child Organization disposition.
The candidate operational schedule is a 30-day retrieval period followed by primary deletion or de-identification, with encrypted backup expiry targeted within 35 additional days. Security/admin audit and email-delivery evidence may remain for up to 24 months; support records for up to three years; and billing/tax/dispute records for up to seven years or the legally required period. Marketing suppression records may remain as long as needed to honor the request. The final annex must reconcile these periods with actual systems and applicable controller instructions.
9. International transfers
Counsel must identify applicable transfer mechanism, locations, supplementary measures, UK addendum or other regional provisions based on actual customer and subprocessor scope.
10. Audit and evidence
Define use of independent reports, questionnaires and limited audits; frequency, notice, scope, confidentiality, cost and remediation. Do not promise certifications or reports that do not exist.
11. Product acceptance evidence
The Organization Administrator should accept the immutable DPA version for the Organization. Enterprise/OEM parent acceptance must be stored independently for the parent contract and must not imply acceptance on behalf of child Organizations. Store document ID/version, actor, account/Organization, timestamp and approved evidence fields.
12. Counsel-reserved annexes
- processing-description annex;
- technical and organizational measures;
- subprocessor list;
- transfer clauses/addenda;
- jurisdiction-specific controller/processor/service-provider restrictions;
- liability, termination and governing-law alignment with the master agreement.