ATLAS · ON SPOT SOLUTIONS LLC
Effective Data Processing Addendum. Version 2026-08-11.1 applies beginning August 15, 2026 and is incorporated into the ATLAS customer agreement.

ATLAS Data Processing Addendum

Status: Effective August 15, 2026 Provider mailing address: On Spot Solutions LLC, 1 Washington Mall #1282, Boston, MA 02108, United States Version: 2026-08-11.1

This Addendum is incorporated into the ATLAS Customer Service and Data Use Agreement and governs Customer Personal Data processed by On Spot on Customer's behalf.

1. Parties, scope and precedence

Identify the customer as controller/business and On Spot Solutions LLC as processor/service provider where applicable. Define the controlling agreement, covered ATLAS services, term, conflicts and any processing where On Spot acts independently.

2. Processing details

3. Documented instructions and confidentiality

Process Customer Personal Data only on documented instructions, including service use, order forms and support requests, unless law requires otherwise. Bind personnel with appropriate confidentiality and access restrictions.

4. Security measures

Attach an accurate security exhibit covering access control, tenant isolation, encryption, secrets, logging/monitoring, vulnerability and dependency management, backups/recovery, incident response, personnel controls and secure deletion. Do not include unverified SOC 2, PITR, RPO/RTO, penetration-test, SSO or MFA claims.

5. Subprocessors

List approved subprocessors, purpose and processing location; require protective terms; define general/specific authorization, material-change notice and objection/remedy. Reconcile Supabase, Render/approved successor hosting, Hostinger, Resend, Stripe, Sentry, and the exact active Anthropic/OpenAI API configuration.

6. Assistance

Define reasonable assistance for data-subject requests, security inquiries, DPIAs, regulator consultation, audits and customer compliance. Allocate costs for exceptional requests and preserve confidentiality/tenant boundaries.

7. Security incidents

Define a verified incident-notification channel, timing standard, required available information, updates, cooperation, mitigation and no admission of fault. Align with the approved incident-response plan and governing law.

8. Return, export and deletion

At termination or pilot expiration, provide the contracted retrieval/export opportunity, then delete or return Customer Personal Data subject to legal retention and documented backup cycles. Explicitly separate Enterprise/OEM parent termination from child Organization disposition.

The candidate operational schedule is a 30-day retrieval period followed by primary deletion or de-identification, with encrypted backup expiry targeted within 35 additional days. Security/admin audit and email-delivery evidence may remain for up to 24 months; support records for up to three years; and billing/tax/dispute records for up to seven years or the legally required period. Marketing suppression records may remain as long as needed to honor the request. The final annex must reconcile these periods with actual systems and applicable controller instructions.

9. International transfers

Counsel must identify applicable transfer mechanism, locations, supplementary measures, UK addendum or other regional provisions based on actual customer and subprocessor scope.

10. Audit and evidence

Define use of independent reports, questionnaires and limited audits; frequency, notice, scope, confidentiality, cost and remediation. Do not promise certifications or reports that do not exist.

11. Product acceptance evidence

The Organization Administrator should accept the immutable DPA version for the Organization. Enterprise/OEM parent acceptance must be stored independently for the parent contract and must not imply acceptance on behalf of child Organizations. Store document ID/version, actor, account/Organization, timestamp and approved evidence fields.

12. Counsel-reserved annexes