Skip to content
AtomicReps

Legal

Data Processing Agreement

Last updated: August 28, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Atomic Reps AB ("Processor") and any organization that subscribes to a Atomic Reps plan or installs or uses the Service in a Slack workspace, on any plan including Free ("Controller"). It applies to all processing of Personal Data carried out by Processor on behalf of Controller in connection with the Service. Controller accepts this DPA, on behalf of itself and its Affiliates, by subscribing to a plan, installing the Slack app, or creating a workspace.

Counter-signed copies of this DPA are available on request from legal@atomicreps.com for procurement records. The terms of this published version are binding regardless of whether a counter-signed copy is requested.

1. Definitions

Capitalized terms not defined here have the meanings given in the Terms of Service or the GDPR (Regulation (EU) 2016/679).

  • Affiliate - any entity that controls, is controlled by, or is under common control with a party.
  • Controller - the customer organization that determines the purposes and means of processing Personal Data via the Service (GDPR Art 4(7)).
  • Data Subject - an identified or identifiable natural person whose Personal Data is processed.
  • EEA - the European Economic Area.
  • Personal Data - any information relating to a Data Subject as defined in GDPR Art 4(1).
  • Processor - Atomic Reps AB, processing Personal Data on behalf of Controller (GDPR Art 4(8)).
  • Processing - as defined in GDPR Art 4(2).
  • SCCs - the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914.
  • Subprocessor - a third party engaged by Processor to process Personal Data on Controller's behalf.
  • UK GDPR - the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018.

2. Roles and Scope

For all Personal Data processed under this DPA, Controller is the controller and Processor is the processor. Processor will process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law to which Processor is subject (in which case Processor will inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).

Controller's instructions are set out in (a) the Terms of Service; (b) Controller's configuration of the Service (e.g., Slack channel selection, question selection, member management); and (c) any subsequent written instructions agreed by the parties.

For the avoidance of doubt, this DPA applies only to processing in which Atomic Reps AB acts as Processor on Controller's behalf in connection with a Workspace, and does not apply to separate processing for which Atomic Reps AB acts as an independent Controller, including Personal-plan processing and Atomic Reps AB's own account, billing, marketing and controller-side analytics processing.

3. Subject Matter, Duration, Nature, and Purpose

Subject matter: Processor's provision of the Atomic Reps Service to Controller as described in the Terms of Service.

Duration: The term of Controller's subscription to the Service, plus any longer period required by applicable law (e.g., 7 years for billing/tax records under Bokföringslagen).

Nature: Hosting, storage, processing, transmission, and analysis of Personal Data submitted to the Service.

Purpose: Delivering the Service (daily skill practice via web and Slack), generating anonymous aggregate statistics used to calibrate question difficulty, and ancillary support, billing, and security functions.

4. Categories of Data Subjects and Personal Data

Categories of Data Subjects:

  • Controller's employees, contractors, and other authorized Users
  • Controller's administrators
  • Controller's billing contacts

Categories of Personal Data:

  • Identifiers: name, email, Slack user/team ID, display name, chosen leaderboard nickname, IP address, account ID
  • Authentication credentials (handled by Clerk; Processor does not have access to plaintext passwords)
  • Usage data: answer history, scores, streaks, response timing
  • Billing contact information (handled by Polar as Merchant of Record; see Annex III for Polar's role, which sits outside this DPA)
  • Technical logs (request metadata, error traces) used for security and debugging
  • Workspace administrative data: audit-log records of administrative actions taken within a Workspace, including the administrator's identity, action and timestamp

No special categories of Personal Data (GDPR Art 9) are processed. Processor instructs Controller not to submit special-category data through the Service.

5. Processor Obligations

Processor will:

  • Process Personal Data only on Controller's documented instructions (Section 2).
  • Not use Controller's Personal Data to train, fine-tune, or improve any AI or machine-learning model, and not sell or share it.
  • Ensure that persons authorized to process Personal Data have committed to confidentiality.
  • Implement appropriate technical and organizational measures (Annex II) to ensure a level of security appropriate to the risk (GDPR Art 32).
  • Engage Subprocessors only as permitted by Section 7.
  • Assist Controller in fulfilling its obligation to respond to Data Subject requests (Section 9).
  • Assist Controller in ensuring compliance with GDPR Articles 32-36 (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and information available to Processor.
  • At Controller's choice, delete or return all Personal Data after the end of the provision of services (Section 11).
  • Make available to Controller all information necessary to demonstrate compliance with GDPR Art 28.

6. Personal Data Breach

Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller's Personal Data, and will use reasonable efforts to provide an initial notification within 24 hours, so that Controller can meet its own notification deadlines. Processor may provide information in phases as it becomes available, without undue further delay. Notification is sent from a documented incident runbook, and the first notification goes out as soon as the affected scope is known. The notification will, at minimum, describe:

  • The nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned;
  • The likely consequences of the breach;
  • Measures taken or proposed to address the breach, including measures to mitigate possible adverse effects;
  • The contact point for further information.

Where information cannot be provided at the same time, it may be provided in phases without undue further delay.

7. Subprocessors

Controller provides general written authorization for Processor to engage Subprocessors. The current list of Subprocessors is set out in Annex III below and on the Privacy Policy under "Third-party services (subprocessors)".

Processor will provide Controller with at least 30 days' prior written notice of any addition or replacement of a Subprocessor. To subscribe to Subprocessor change notifications, email privacy@atomicreps.com. If Controller has a reasonable objection to a new Subprocessor based on data protection grounds, Controller may notify Processor in writing within the 30-day notice period. The parties will then work in good faith to resolve the objection; if no resolution is reached, Controller may terminate the affected Service component as its sole remedy.

Processor will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA and remains liable for the performance of each Subprocessor.

8. International Transfers

Several Subprocessors are located outside the EEA, primarily in the United States. For such transfers, the parties rely on:

  • EU-US Data Privacy Framework for Subprocessors that are certified (Clerk, and Slack through Salesforce, Inc.), with the EU Standard Contractual Clauses as a fallback should the Framework cease to provide a valid transfer mechanism;
  • EU Standard Contractual Clauses (Module 3, processor-to-processor) for onward transfers to Subprocessors not certified under the DPF; for Resend (United States), the transfers are safeguarded under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement;
  • UK Addendum to the SCCs for UK GDPR transfers, where applicable.
  • Swiss adaptation - where the Swiss Federal Act on Data Protection (FADP) applies, the SCCs apply as adapted in line with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC): references to the GDPR are read as references to the FADP, the FDPIC is the competent supervisory authority for Swiss transfers, and data subjects habitually resident in Switzerland may enforce their rights before Swiss courts.

The SCCs are incorporated into this DPA by reference. For purposes of the SCCs, Annex I (List of Parties), Annex I.B (Description of Transfer), Annex I.C (Competent Supervisory Authority, see Section 13), Annex II (Technical and Organizational Measures), and Annex III (Subprocessors) are completed below or in the referenced sections. Where Controller is established outside the EEA and its use of the Service involves a restricted transfer to Processor, Module 2 (controller-to-processor) applies between Controller and Processor; otherwise the transfers requiring Chapter V safeguards are the onward transfers from Processor to Subprocessors outside the EEA, to which Module 3 (processor-to-processor) applies, or the Subprocessor's own Data Privacy Framework certification or SCCs as set out in Annex III. The parties select Swedish law as the governing law (Clause 17) and the courts of Sweden as the forum (Clause 18(b)); the optional docking clause (Clause 7) does not apply. In the event of a conflict between this DPA and the SCCs, the SCCs prevail, and nothing in this DPA limits or derogates from the protections the SCCs afford Data Subjects.

For transfers under the SCCs, the parties apply appropriate supplementary measures where required, including encryption in transit and at rest and access controls.

9. Data Subject Requests

Processor will, taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller's obligation to respond to requests by Data Subjects under GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection, automated decision-making).

Controller's administrators can delete a workspace and its data from billing settings. For Data Subject access, portability, or erasure requests requiring Processor's direct assistance, contact privacy@atomicreps.com.

10. Audits

Processor will make available to Controller all information necessary to demonstrate compliance with this DPA and GDPR Art 28, and allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller.

In practice, Controller's audit right is satisfied by Processor providing (a) up-to-date documentation of technical and organizational measures (Annex II); (b) responses to reasonable due-diligence questionnaires; and (c) where available, third-party audit reports (e.g., SOC 2 reports of Subprocessors). On-site inspection may be requested no more than once per twelve-month period with reasonable advance notice and at Controller's expense, and is subject to Processor's confidentiality and security policies.

11. Return or Deletion

Upon termination of the Service, Processor will, at Controller's choice, delete or return all Personal Data to Controller, and delete existing copies, unless Union or Member State law requires storage. Deletion or return under this DPA applies only to Personal Data processed by Processor on Controller's behalf, and does not require deletion of separate Personal Data that Atomic Reps AB processes independently as Controller, including data generated independently through a User's Personal plan. Default behavior absent Controller instruction:

  • Attributed workspace data on Team and Enterprise: available for export until the end of the subscription term. When the subscription ends, the workspace's per-member layer is removed immediately: the practice targeting set up for each member is deleted and members' answer records are permanently unlinked from the workspace; each member retains their own practice record as an individual data subject. Controller may delete the entire workspace at any time from billing settings.
  • Free-tier aggregate statistics: continue under the 90-day rolling window (anonymous, no Data Subject identifiers, outside GDPR scope per Recital 26; any residually identifiable rows are retained for statistical purposes under GDPR Art 17(3)(d) read with Art 89(1)).
  • Billing and tax records: retained for 7 years per Bokföringslagen (1999:1078).

12. Liability

The liability of each party under this DPA is governed by the "Limitation of Liability" section of the Terms of Service. Nothing in this DPA limits liability that cannot be excluded under applicable mandatory law, including under GDPR Art 82 (right to compensation).

13. Governing Law

This DPA is governed by Swedish law and is subject to the same jurisdiction clause as the Terms of Service. For SCC purposes, the governing law is Swedish law and the supervisory authority is Integritetsskyddsmyndigheten (IMY, imy.se). For SCC Clause 13, the competent supervisory authority is that of the data exporter's place of establishment in the EEA; where the exporter is established outside the EEA, it is IMY.

Annex I - List of Parties

Data exporter (Controller): The organization that subscribes to a Atomic Reps plan or installs or uses the Service in a Slack workspace, on any plan including Free. Identification per Controller's account record (organization name and billing email, or Slack workspace identifier for unclaimed Free installs).

Data importer (Processor): Atomic Reps AB, Arvid Tydéns Allé 28, 171 69 Solna, Sweden, org. no. 559593-4398. Contact point for this DPA and the Clauses: legal@atomicreps.com. Data protection requests: privacy@atomicreps.com. Security incidents and vulnerability reports: security@atomicreps.com, also published at /.well-known/security.txt under RFC 9116.

Description of transfer: Personal Data submitted by Controller and its Users to the Service is transferred to Subprocessors located in the United States and elsewhere as required to provide the Service. The categories of data subjects and Personal Data are those set out in Section 4; retention is as set out in Section 11 and the Privacy Policy. The transfer is on a continuous basis throughout the term of Controller's subscription. For onward transfers under Module 3, the data importers are the Subprocessors listed in Annex III.

Annex II - Technical and Organizational Measures

Processor has implemented the following technical and organizational measures to ensure the security of Personal Data (GDPR Art 32):

  • Encryption in transit: All data in transit between client and Service is encrypted with TLS 1.3 or higher.
  • Encryption at rest: Personal Data stored in Convex and Cloudflare is encrypted at rest by the underlying infrastructure providers.
  • Access control: Role-based access control. Production database access restricted to a minimal set of authorized personnel with multi-factor authentication. Personnel access is logged.
  • Authentication: Customer-side authentication via Clerk with optional MFA. Internal admin access via Clerk organization roles.
  • Secrets management: Production credentials stored in encrypted secret vault (ProtonPass) and injected at deploy time via ephemeral subprocess environment. No secrets on disk in production.
  • Slack token encryption: Slack bot tokens stored in encrypted form using AES-256-GCM with rotation-capable key.
  • Logging and monitoring: Application logs reviewed for security events; webhook signature verification on all third-party callbacks (Clerk, Polar, Resend, Slack).
  • Backup and recovery: Automated daily database backups are enabled, with documented recovery procedures. Restore capability has been validated by test, and restoration is tested periodically.
  • Incident response: Documented runbook for breach response; Processor notifies Controller without undue delay per Section 6, with reasonable efforts to provide initial notice within 24 hours, and as soon as the affected scope is known where that is sooner, leaving Controller its own 72-hour authority deadline under GDPR Art 33. Processor requires each Subprocessor to notify Processor of a Personal Data Breach without undue delay.
  • Personnel: Personnel with access to Personal Data are bound by confidentiality and are trained on data protection obligations.
  • Subprocessor due diligence: Subprocessors are selected based on documented security posture; SCCs or DPF certification required for non-EEA Subprocessors.

Note: Atomic Reps AB is not currently SOC 2 certified. See /security for current security posture.

Annex III - Subprocessors

The following Subprocessors are engaged as of the date this DPA takes effect for Controller. Updates are published on the Privacy Policy with 30 days' advance notice.

  • Clerk Inc. - Authentication and user management. United States. EU-US Data Privacy Framework.
  • Convex Inc. - Database and serverless backend. United States. EU SCCs (Module 3, processor-to-processor).
  • Cloudflare Inc. - Frontend hosting, deployment, and CDN. United States and global edge network including EU points of presence. EU SCCs (Module 3, processor-to-processor).
  • Slack Technologies LLC - Workspace integration for daily practice delivery. United States. EU-US Data Privacy Framework (certified through Salesforce, Inc.).
  • Resend Inc. - Transactional and marketing email delivery. United States; transfers safeguarded under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement.
  • PostHog Inc. - Optional product analytics, crash reporting, and session replay, enabled only after consent. Once consent is given, a signed-in user's name, email address, and organization name are sent as profile properties. Replay is limited to our public marketing pages and masks all text input. PostHog additionally receives anonymous page-visit and interaction events sent from Atomic Reps AB's own servers for every visitor, keyed to a one-way daily fingerprint that creates no person profile and is never joined to an account; that is controller-side processing outside the scope of this DPA (see clause 2). EU-region instance (eu.posthog.com); where a non-EU instance is configured, EU SCCs apply (Module 2 where Atomic Reps AB acts as Controller; Module 3 where Atomic Reps AB acts as Processor on a Workspace customer's behalf).

The SCC module identified in this Annex applies to processing governed by this DPA. Separate processing for which Atomic Reps AB acts as Controller is subject to the applicable controller-to-processor transfer terms.

Polar Software Inc. is not a Subprocessor under this DPA. Polar acts as Merchant of Record and reseller in its independent capacity for the payment, tax and checkout transaction. To the extent Polar processes Atomic Reps AB-controlled billing or platform data on Atomic Reps AB's behalf, Polar acts as Atomic Reps AB's processor under a separate controller-to-processor data processing agreement, and that processing is outside the scope of this customer DPA. Polar engages Stripe, Inc. (EU-US Data Privacy Framework) for payment card handling.

See also: Privacy Policy · Terms of Service · Security