Skip to main content
AtlyBack to product

Provisional product description — not a substitute for counsel-reviewed contracts. Will be replaced after legal review.

Data Processing Agreement (Art. 28 outline + AI annex)

AtlyTech s.r.o. ID 29944627, VAT CZ29944627, Dandova 2619/13, Horní Počernice, 193 00 Praha 9. We are VAT-registered.

The company is registered in the Commercial Register kept by Městský soud v Praze, oddíl C, vložka 454920.

Version: 2026-08-30 (provisional). Structured on GDPR Article 28 requirements and what the Atly product actually does. Not a substitute for counsel-reviewed contracts.

1. Parties and roles

2. Subject matter and duration

Atly processes Customer personal data to provide AI-assisted operations features (inbox/WhatsApp/Messenger triage, drafting, briefing, Company DNA, calendar proposals, human approval queues; later optional missed-call follow-up). Processing continues for the term of the service relationship and for a reasonable closure window after termination or account deletion request, unless a longer period is required by law.

3. Nature and purpose of processing

Nature: infrastructure operation, storage, retrieval, analysis, transcription, summarisation, drafting, logging, and transmission to configured sub-processors as needed to run the product.

Purpose: deliver Atly features described in product documentation and the Terms; improve operational reliability of the Customer’s isolated company space (not training Atly-owned foundation models on Customer content).

4. Types of personal data

Depending on connected channels and settings, processing may include:

Special categories of data are not sought by Atly. Customers must not intentionally upload special-category data unless they have a lawful basis and instruct Atly accordingly.

5. Categories of data subjects

6. Customer instructions

Atly processes personal data only on documented Customer instructions: use of the product features, connected integrations, autonomy/LLM settings, and written instructions (including support requests). Atly informs the Customer if an instruction appears to infringe GDPR; Atly may refuse unlawful instructions.

7. Confidentiality

Persons authorised to process personal data are bound by confidentiality obligations (contractual and/or statutory).

8. Security measures (summary)

Technical and organisational measures include, as implemented in product:

Details: product Security documentation and internal RoPA.

9. Sub-processors

Customer authorises Atly to use the following categories of sub-processors as configured for the deployment:

Atly will inform Customers of material sub-processor changes via product notice or documentation update with reasonable advance notice where feasible. Continued use after notice constitutes acceptance on a provisional basis until counsel provides a formal sub-processor schedule.

10. International transfers

Where a sub-processor processes data outside the EEA/UK, transfers rely on the provider’s applicable transfer mechanisms (e.g. SCCs, adequacy) as stated in that provider’s DPA. Customers should review provider terms for their region.

11. Assistance to the controller

Taking into account the nature of processing, Atly assists the Customer with:

12. Retention, return, and deletion

13. Audits

Upon reasonable written request, and no more than once per year unless a breach investigation requires otherwise, Atly will make available information necessary to demonstrate Art. 28 compliance (documentation, security summary). On-site audits require mutual agreement on scope, timing, and confidentiality; Customer bears external auditor costs unless a material breach by Atly is confirmed.

14. Support-assisted account recovery

Atly support staff can perform two narrowly defined administrative acts on a Customer's isolated company space, so that a Customer is not permanently locked out when the account holder is unreachable. Both are performed only at the Customer's request:

Both acts concern account administration only. They do not give Atly support staff access to Customer communication content, and they are not a consent to such access; Atly access to Customer data continues to be governed by sections 6 and 7.

Each act is written to the company's audit log as a separate internal-operations entry naming the person at Atly who performed it, the company concerned, the versions or roles affected, and the reason they gave. It is recorded distinctly from the same act performed by the Customer, so the two cannot be confused when the log is read later. Atly provides the relevant audit records to the Customer on request.

15. AI annex (product guarantees)

16. Liability and provisional status

Liability allocation for this provisional DPA follows the Terms of Service until counsel issues a signed Art. 28 agreement. This document describes what the product actually does; it is a provisional in-product acceptance text for pilots and procurement transparency.

17. Precedence

If counsel later provides a signed DPA, that signed document prevails over this provisional text for the covered relationship. The in-product acceptance version is identified as DPA_VERSION 2026-08-30.

Full public page: /legal/dpa. Related: /legal/privacy, /legal/ai-policy, /legal/terms.