Sub-processors
- Last updated:
- Effective:
Atlas Task Manager engages third-party sub-processors to deliver the Service. Each is bound by a written data processing agreement consistent with Art. 28 GDPR. We publish the categories of sub-processors and their purpose below; the specific, current, named list is provided to customers on request under our Data Processing Agreement. Feature and integration sub-processors process customer data only when the relevant feature or integration is enabled.
1. Overview
We engage sub-processors only to the extent necessary to deliver the Service and to comply with law. Each is required to implement appropriate technical and organizational measures, process customer data only on documented instructions, and maintain confidentiality.
2. Categories of sub-processors
The categories below describe how customer data is processed. Analytics, AI, email, and payment categories are engaged only when you use the corresponding feature.
| Category | Purpose | Data categories |
|---|---|---|
| Cloud hosting and managed database | Runs the application and stores workspace data, with a managed database and cache. | Account data, workspace content, authentication metadata, operational logs. |
| Object storage and content delivery | Stores uploaded files and serves the application over a content delivery network. | Files you upload, request metadata, and IP address. |
| AI model provider | Powers AI features - the content you submit to an AI action is sent to the provider to generate the response. That content is not used to train the provider models under our contractual terms. | The specific content you submit to an AI feature, plus request metadata. |
| Product analytics | Aggregated, consent-gated product-usage measurement (loaded only after you opt in). | Pseudonymous identifiers and product-usage events. |
| Error monitoring and reliability | Detects and diagnoses crashes and errors, with PII masking applied. | Crash diagnostics, breadcrumbs, and masked session context. |
| Transactional email delivery | Sends transactional email such as verification, notifications, and receipts. | Recipient email address and message content. |
| Payment processing | Processes payments and billing when you purchase a paid plan. | Billing name, email, and payment identifiers (card data is handled by the processor). |
3. Optional integrations
Integrations you connect. They process customer data only when the integration is enabled for your workspace.
| Provider | Purpose | Data categories | Location | Transfer mechanism |
|---|---|---|---|---|
| Google LLC | OAuth sign-in and Google Calendar integration. | Profile, email, calendar events you elect to sync. | United States and global. | SCCs + EU-US DPF (certified). |
| Microsoft Corporation | OAuth sign-in and Microsoft 365 Calendar integration. | Profile, email, calendar events you elect to sync. | United States and global. | SCCs + EU-US DPF (certified). |
| GitHub, Inc. | OAuth sign-in and repository integrations when enabled by a workspace. | Profile, email, repository metadata you elect to connect. | United States. | SCCs (via Microsoft). |
| Slack Technologies, LLC | Slack workspace messaging integration when enabled by a workspace. | Workspace identifiers, channel metadata, messages you elect to sync. | United States and global. | SCCs + applicable Salesforce data processing terms. |
4. Named list of sub-processors
The specific, current list of named sub-processors, including their locations and transfer mechanisms, is available to customers on request under our Data Processing Agreement. Request it at https://atlas.wrxstack.com/legal/dpa-request or email legal@wrxstack.com.
5. Notice of changes
We update this list when we add, change, or remove a sub-processor. Subscribe to change notifications at https://atlas.wrxstack.com/legal/sub-processors. Customers with a signed DPA will receive advance notice as specified in that DPA, with a right to object within the period stated there.
6. Data processing agreement
To request a signed Data Processing Agreement (DPA) incorporating the Standard Contractual Clauses and UK IDTA Addendum, visit https://atlas.wrxstack.com/legal/dpa-request or email legal@wrxstack.com. See our Privacy Policy for how we handle personal data overall.