Skip to main content

Data Processing Agreement

Effective June 11, 2026 · Last updated June 11, 2026

What this means

When you use Clapleads Atlas, you are the data controller for the contacts you manage and we process that data on your behalf. This page lists who else touches that data, how transfers outside your region are covered, and how we would notify you of a breach.

Roles: controller and processor

For the contact and organization records you manage, search, and export in Clapleads Atlas, you are the data controller and we act as your data processor. You decide what data to collect and how to use it; we process it on your behalf under your instructions, as described in our Terms of Use.

For account data (your name, email, billing details), we act as the controller — see the Privacy Policy for that relationship.

Sub-processors

We use a small number of third parties to run the platform. Each only sees the data it needs to do its job.

Sub-processorPurpose
Stripe, Inc.Payment processing and subscription billing.
Anthropic, PBCOptional AI features (chat, summarization, writing assistant) — only when your account has this enabled.
Transactional email provider (SMTP)Delivering account, notification, and status-update emails. Configurable per deployment.
Cloud/VPS infrastructure providersHosting the application, database, and background workers.

This is the complete list — we do not use undisclosed sub-processors.

How we notify you of changes

If we add or replace a sub-processor, we will update the table above and change the "Last updated" date on this page. For a material change — a new sub-processor that will handle your data — we will also post it on our release notes and, once we support it, an email notice, before the change takes effect.

International transfers

Where a sub-processor is located outside your region and that transfer requires a legal safeguard, we rely on that provider's Standard Contractual Clauses (SCCs) as the transfer mechanism — the same mechanism used across the industry for cross-border processing. We do not maintain a separate, platform-specific SCC addendum today; if you need one executed directly with us for your organization, contact support.

Security measures

The technical and organizational measures that protect data processed on your behalf are described in full on the Security page — including account protection, encryption in transit, suppression-list enforcement on every export, and audit logging. We do not currently hold SOC 2, ISO 27001, or similar third-party certifications.

Breach notification

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of data you have entrusted to us, we will notify you without undue delay after becoming aware of it, with what we know at the time: the nature of the incident, the data categories likely affected, and the steps we are taking. We will follow up as our investigation progresses.

Data return and deletion

You can export your data at any time while your account is active. If you close your account, we delete or anonymize your account data within a reasonable period, consistent with our Privacy Policy and any retention we are legally required to keep (for example, billing records).

Related policies

Questions or requests

If anything on this page is unclear, or you want to act on your rights, you can reach us through the support page. To ask about data we hold on you or your business, use the data request portal — no account is needed.

Data protection contact

For data-protection matters — access, correction, deletion, objection, portability, or “do not sell” requests under GDPR/CCPA — the fastest route is the data request portal, which is logged and tracked to completion. Identity is verified before any personal data is disclosed.