Skip to content
AtomicReps

Legal

Data Processing Agreement

Last updated: September 23, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Atomic Reps AB ("Processor") and any organization that subscribes to a Atomic Reps plan or installs or uses the Service in a Slack workspace, on any workplace plan including Free, and any educational institution under an Atomic Campus order form (Schedule E) ("Controller"). It applies to all processing of Personal Data carried out by Processor on behalf of Controller in connection with the Service. Controller accepts this DPA, on behalf of itself and its Affiliates, by subscribing to a plan, installing the Slack app, or creating a workspace.

Counter-signed copies of this DPA are available on request from legal@atomicreps.com for procurement records. The terms of this published version are binding regardless of whether a counter-signed copy is requested.

1. Definitions

Capitalized terms not defined here have the meanings given in the Terms of Service or the GDPR (Regulation (EU) 2016/679).

  • Affiliate - any entity that controls, is controlled by, or is under common control with a party.
  • Controller - the customer organization that determines the purposes and means of processing Personal Data via the Service (GDPR Art 4(7)).
  • Data Subject - an identified or identifiable natural person whose Personal Data is processed.
  • EEA - the European Economic Area.
  • Personal Data - any information relating to a Data Subject as defined in GDPR Art 4(1).
  • Processor - Atomic Reps AB, processing Personal Data on behalf of Controller (GDPR Art 4(8)).
  • Processing - as defined in GDPR Art 4(2).
  • SCCs - the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914.
  • Subprocessor - a third party engaged by Processor to process Personal Data on Controller's behalf.
  • UK GDPR - the GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018.

2. Roles and Scope

For all Personal Data processed under this DPA, Controller is the controller and Processor is the processor. Processor will process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law to which Processor is subject (in which case Processor will inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).

Controller's instructions are set out in (a) the Terms of Service; (b) Controller's configuration of the Service (e.g., Slack channel selection, question selection, member management); and (c) any subsequent written instructions agreed by the parties.

For the avoidance of doubt, this DPA applies only to processing in which Atomic Reps AB acts as Processor on Controller's behalf in connection with a Workspace, and does not apply to separate processing for which Atomic Reps AB acts as an independent Controller, including Personal-plan processing and Atomic Reps AB's own account, billing, marketing and controller-side analytics processing.

3. Subject Matter, Duration, Nature, and Purpose

Subject matter: Processor's provision of the Atomic Reps Service to Controller as described in the Terms of Service.

Duration: The term of Controller's subscription to the Service, plus any longer period required by applicable law (e.g., 7 years for billing/tax records under Bokföringslagen).

Nature: Hosting, storage, processing, transmission, and analysis of Personal Data submitted to the Service.

Purpose: Delivering the Service (daily skill practice via web and Slack), generating anonymous aggregate statistics used to calibrate question difficulty, and ancillary support, billing, and security functions.

4. Categories of Data Subjects and Personal Data

Categories of Data Subjects:

  • Controller's employees, contractors, and other authorized Users
  • Controller's administrators
  • Controller's billing contacts

Categories of Personal Data:

  • Identifiers: name, email, Slack user/team ID, display name, chosen leaderboard nickname, IP address, account ID
  • Authentication credentials (handled by Clerk; Processor does not have access to plaintext passwords)
  • Usage data: answer history, scores, streaks, response timing
  • Billing contact information (handled by Polar as Merchant of Record; see Annex III for Polar's role, which sits outside this DPA)
  • Technical logs (request metadata, error traces) used for security and debugging
  • Workspace administrative data: audit-log records of administrative actions taken within a Workspace, including the administrator's identity, action and timestamp

No special categories of Personal Data (GDPR Art 9) are processed. Processor instructs Controller not to submit special-category data through the Service.

5. Processor Obligations

Processor will:

  • Process Personal Data only on Controller's documented instructions (Section 2).
  • Not use Controller's Personal Data to train, fine-tune, or improve any AI or machine-learning model, and not sell or share it.
  • Ensure that persons authorized to process Personal Data have committed to confidentiality.
  • Implement appropriate technical and organizational measures (Annex II) to ensure a level of security appropriate to the risk (GDPR Art 32).
  • Engage Subprocessors only as permitted by Section 7.
  • Assist Controller in fulfilling its obligation to respond to Data Subject requests (Section 9).
  • Assist Controller in ensuring compliance with GDPR Articles 32-36 (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and information available to Processor.
  • At Controller's choice, delete or return all Personal Data after the end of the provision of services (Section 11).
  • Make available to Controller all information necessary to demonstrate compliance with GDPR Art 28.

6. Personal Data Breach

Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller's Personal Data, and will use reasonable efforts to provide an initial notification within 24 hours, so that Controller can meet its own notification deadlines. Processor may provide information in phases as it becomes available, without undue further delay. Notification is sent from a documented incident runbook, and the first notification goes out as soon as the affected scope is known. The notification will, at minimum, describe:

  • The nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned;
  • The likely consequences of the breach;
  • Measures taken or proposed to address the breach, including measures to mitigate possible adverse effects;
  • The contact point for further information.

Where information cannot be provided at the same time, it may be provided in phases without undue further delay.

7. Subprocessors

Controller provides general written authorization for Processor to engage Subprocessors. The current list of Subprocessors is set out in Annex III below and on the Privacy Policy under "Third-party services (subprocessors)".

Processor will provide Controller with at least 30 days' prior written notice of any addition or replacement of a Subprocessor. To subscribe to Subprocessor change notifications, email privacy@atomicreps.com. If Controller has a reasonable objection to a new Subprocessor based on data protection grounds, Controller may notify Processor in writing within the 30-day notice period. The parties will then work in good faith to resolve the objection; if no resolution is reached, Controller may terminate the affected Service component as its sole remedy.

Processor will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA and remains liable for the performance of each Subprocessor.

8. International Transfers

Several Subprocessors are located outside the EEA, primarily in the United States. For such transfers, the parties rely on:

  • EU-US Data Privacy Framework for Subprocessors that are certified (Clerk, and Slack through Salesforce, Inc.), with the EU Standard Contractual Clauses as a fallback should the Framework cease to provide a valid transfer mechanism;
  • EU Standard Contractual Clauses (Module 3, processor-to-processor) for onward transfers to Subprocessors not certified under the DPF; for Resend (United States), the transfers are safeguarded under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement;
  • UK Addendum to the SCCs for UK GDPR transfers, where applicable.
  • Swiss adaptation - where the Swiss Federal Act on Data Protection (FADP) applies, the SCCs apply as adapted in line with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC): references to the GDPR are read as references to the FADP, the FDPIC is the competent supervisory authority for Swiss transfers, and data subjects habitually resident in Switzerland may enforce their rights before Swiss courts.

The SCCs are incorporated into this DPA by reference. For purposes of the SCCs, Annex I (List of Parties), Annex I.B (Description of Transfer), Annex I.C (Competent Supervisory Authority, see Section 13), Annex II (Technical and Organizational Measures), and Annex III (Subprocessors) are completed below or in the referenced sections. Where Controller is established outside the EEA and its use of the Service involves a restricted transfer to Processor, Module 2 (controller-to-processor) applies between Controller and Processor; otherwise the transfers requiring Chapter V safeguards are the onward transfers from Processor to Subprocessors outside the EEA, to which Module 3 (processor-to-processor) applies, or the Subprocessor's own Data Privacy Framework certification or SCCs as set out in Annex III. The parties select Swedish law as the governing law (Clause 17) and the courts of Sweden as the forum (Clause 18(b)); the optional docking clause (Clause 7) does not apply. In the event of a conflict between this DPA and the SCCs, the SCCs prevail, and nothing in this DPA limits or derogates from the protections the SCCs afford Data Subjects.

For transfers under the SCCs, the parties apply appropriate supplementary measures where required, including encryption in transit and at rest and access controls.

9. Data Subject Requests

Processor will, taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller's obligation to respond to requests by Data Subjects under GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection, automated decision-making).

Controller's administrators can delete a workspace and its data from billing settings. For Data Subject access, portability, or erasure requests requiring Processor's direct assistance, contact privacy@atomicreps.com.

10. Audits

Processor will make available to Controller all information necessary to demonstrate compliance with this DPA and GDPR Art 28, and allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller.

In practice, Controller's audit right is satisfied by Processor providing (a) up-to-date documentation of technical and organizational measures (Annex II); (b) responses to reasonable due-diligence questionnaires; and (c) where available, third-party audit reports (e.g., SOC 2 reports of Subprocessors). On-site inspection may be requested no more than once per twelve-month period with reasonable advance notice and at Controller's expense, and is subject to Processor's confidentiality and security policies.

11. Return or Deletion

Upon termination of the Service, Processor will, at Controller's choice, delete or return all Personal Data to Controller, and delete existing copies, unless Union or Member State law requires storage. Deletion or return under this DPA applies only to Personal Data processed by Processor on Controller's behalf, and does not require deletion of separate Personal Data that Atomic Reps AB processes independently as Controller, including data generated independently through a User's Personal plan. Default behavior absent Controller instruction:

  • Attributed workspace data on Team and Enterprise: available for export until the end of the subscription term. When the subscription ends, the workspace's per-member layer is removed immediately: the practice targeting set up for each member is deleted and members' answer records are permanently unlinked from the workspace; each member retains their own practice record as an individual data subject. Controller may delete the entire workspace at any time from billing settings.
  • Free-tier aggregate statistics: continue under the 90-day rolling window (anonymous, no Data Subject identifiers, outside GDPR scope per Recital 26; any residually identifiable rows are retained for statistical purposes under GDPR Art 17(3)(d) read with Art 89(1)).
  • Billing and tax records: retained for 7 years per Bokföringslagen (1999:1078).

12. Liability

The liability of each party under this DPA is governed by the "Limitation of Liability" section of the Terms of Service. Nothing in this DPA limits liability that cannot be excluded under applicable mandatory law, including under GDPR Art 82 (right to compensation).

13. Governing Law

This DPA is governed by Swedish law and is subject to the same jurisdiction clause as the Terms of Service. For SCC purposes, the governing law is Swedish law and the supervisory authority is Integritetsskyddsmyndigheten (IMY, imy.se). For SCC Clause 13, the competent supervisory authority is that of the data exporter's place of establishment in the EEA; where the exporter is established outside the EEA, it is IMY.

Annex I - List of Parties

Data exporter (Controller): The organization that subscribes to a Atomic Reps plan or installs or uses the Service in a Slack workspace, on any workplace plan including Free, or the educational institution named on an Atomic Campus order form (Schedule E). Identification per Controller's account record (organization name and billing email, or Slack workspace identifier for unclaimed Free installs) or the order form.

Data importer (Processor): Atomic Reps AB, Arvid Tydéns Allé 28, 171 69 Solna, Sweden, org. no. 559593-4398. Contact point for this DPA and the Clauses: legal@atomicreps.com. Data protection requests: privacy@atomicreps.com. Security incidents and vulnerability reports: security@atomicreps.com, also published at /.well-known/security.txt under RFC 9116.

Description of transfer: Personal Data submitted by Controller and its Users to the Service is transferred to Subprocessors located in the United States and elsewhere as required to provide the Service. The categories of data subjects and Personal Data are those set out in Section 4; retention is as set out in Section 11 and the Privacy Policy. The transfer is on a continuous basis throughout the term of Controller's subscription. For onward transfers under Module 3, the data importers are the Subprocessors listed in Annex III.

Annex II - Technical and Organizational Measures

Processor has implemented the following technical and organizational measures to ensure the security of Personal Data (GDPR Art 32):

  • Encryption in transit: All data in transit between client and Service is encrypted with TLS 1.3 or higher.
  • Encryption at rest: Personal Data stored in Convex and Cloudflare is encrypted at rest by the underlying infrastructure providers.
  • Access control: Role-based access control. Production database access restricted to a minimal set of authorized personnel with multi-factor authentication. Personnel access is logged.
  • Authentication: Customer-side authentication via Clerk with optional MFA. Internal admin access via Clerk organization roles.
  • Secrets management: Production credentials stored in encrypted secret vault (ProtonPass) and injected at deploy time via ephemeral subprocess environment. No secrets on disk in production.
  • Slack token encryption: Slack bot tokens stored in encrypted form using AES-256-GCM with rotation-capable key.
  • Logging and monitoring: Application logs reviewed for security events; webhook signature verification on all third-party callbacks (Clerk, Polar, Resend, Slack).
  • Backup and recovery: Automated daily database backups are enabled, with documented recovery procedures. Restore capability has been validated by test, and restoration is tested periodically.
  • Incident response: Documented runbook for breach response; Processor notifies Controller without undue delay per Section 6, with reasonable efforts to provide initial notice within 24 hours, and as soon as the affected scope is known where that is sooner, leaving Controller its own 72-hour authority deadline under GDPR Art 33. Processor requires each Subprocessor to notify Processor of a Personal Data Breach without undue delay.
  • Personnel: Personnel with access to Personal Data are bound by confidentiality and are trained on data protection obligations.
  • Subprocessor due diligence: Subprocessors are selected based on documented security posture; SCCs or DPF certification required for non-EEA Subprocessors.

Note: Atomic Reps AB is not currently SOC 2 certified. See /security for current security posture.

Annex III - Subprocessors

The following Subprocessors are engaged as of the date this DPA takes effect for Controller. Updates are published on the Privacy Policy with 30 days' advance notice.

  • Clerk Inc. - Authentication and user management. United States. EU-US Data Privacy Framework.
  • Convex Inc. - Database and serverless backend. EU West (Ireland). Convex Inc. is a US company; EU SCCs (Module 3, processor-to-processor) cover vendor support access from the United States.
  • Cloudflare Inc. - Frontend hosting, deployment, and CDN. United States and global edge network including EU points of presence. EU SCCs (Module 3, processor-to-processor).
  • Slack Technologies LLC - Workspace integration for daily practice delivery. United States. EU-US Data Privacy Framework (certified through Salesforce, Inc.).
  • Resend Inc. - Transactional and marketing email delivery. United States; transfers safeguarded under the EU Standard Contractual Clauses incorporated in Resend's Data Processing Agreement.
  • RevenueCat, Inc. - Not yet active: paid plans cannot be bought in the iPhone app today and RevenueCat processes no Personal Data. Once App Store purchases open, it will hold subscription status for them (the member's account identifier, the vendor identifier iOS assigns to the app on the device, and Apple's purchase records). United States. Its published Data Processing Addendum (paragraph 11) incorporates the EU Standard Contractual Clauses, Modules 2 and 3, with the UK addendum and the Swiss adaptation; Processor will accept it before the first purchase is possible. Apple, Inc. distributes the app as an independent controller and is not a Subprocessor.
  • PostHog Inc. - Optional product analytics, crash reporting, and session replay, enabled only after consent. Once consent is given, a signed-in user's name, email address, and organization name are sent as profile properties. Replay is limited to our public marketing pages and masks all text input. PostHog additionally receives anonymous page-visit and interaction events sent from Atomic Reps AB's own servers for every visitor, keyed to a one-way daily fingerprint that creates no person profile and is never joined to an account; that is controller-side processing outside the scope of this DPA (see clause 2). EU-region instance (eu.posthog.com); where a non-EU instance is configured, EU SCCs apply (Module 2 where Atomic Reps AB acts as Controller; Module 3 where Atomic Reps AB acts as Processor on a Workspace customer's behalf).

The SCC module identified in this Annex applies to processing governed by this DPA. Separate processing for which Atomic Reps AB acts as Controller is subject to the applicable controller-to-processor transfer terms.

Polar Software Inc. is not a Subprocessor under this DPA. Polar acts as Merchant of Record and reseller in its independent capacity for the payment, tax and checkout transaction. To the extent Polar processes Atomic Reps AB-controlled billing or platform data on Atomic Reps AB's behalf, Polar acts as Atomic Reps AB's processor under a separate controller-to-processor data processing agreement, and that processing is outside the scope of this customer DPA. Polar engages Stripe, Inc. (EU-US Data Privacy Framework) for payment card handling.

Schedule E - Atomic Campus

This Schedule applies where Controller is an educational institution, a vocational programme, a bootcamp or an academy that has signed an Atomic Campus order form ("Institution"). It adds to this DPA; where the two differ for course data, this Schedule governs. Atomic Campus is a separate product from the workplace plans: the Institution buys an instructor view of its students' practice, and nothing in this Schedule changes what a workplace administrator can see on Free, Pro or Team.

E1. Controller per seat. For seats the Institution provisions, the Institution is Controller and Atomic Reps AB is Processor under this DPA. Where the Institution is an employer and a trainee is on its payroll during training, the employer is Controller, the per-student view is switched off by default, and the employer confirms its own basis (in Sweden, the negotiation required under MBL 11 §) before switching it on. For a student account a student buys themselves with a verified school email, Atomic Reps AB is independent Controller under clause 2, and that account never appears in any Institution's console.

E2. Subject matter and purpose. Spaced retrieval practice on the topics of a named course, and a report to the Institution's instructors of observed facts about that practice so they can decide what to reteach. The purpose excludes admissions, discipline, grading for credit by the Service, and staff evaluation. Processing includes participation records: which questions a student answered, when, and whether the answer matched the authored key.

E3. Categories of Personal Data. Per enrolled student, inside the course only: answered, correct, elapsed time, last active, per-topic counts, attempts, which weeks of the term the student answered in and the last of those weeks, paused states (by the student or by the Service after unanswered reps), and, where the student gives it, how sure they said they were when they answered. The confidence answer is optional for the student, costs nothing to skip, and reaches the Institution only inside class-level counts, never for a named student. Identity (name, email) from the Institution's roster, joined at display time; no name or student number is stored in the practice tables. Two of the course-level count tables are held for every course, with no student column in either: counts of missed and asked per question per day (educationQuestionDays), which also count the answers given while sure and how many of those were wrong, and counts per sub-skill by difficulty (educationSkillStats). They are the shape behind the per-topic counts above, not a further category of data about a student. Where the Institution switches on the class re-ask, and only there, the Service also holds the weekly list of returning questions (educationClassWeeks) and, per question, how many students missed it and how many have since answered it correctly (educationReAskOutcomes); and, per student, the days on which the student later answered a missed question correctly (reAskCorrectDays) and the student's number of misses per concept on questions that came back (conceptMisses), both of which the student reads and no instructor row shows. conceptMisses drives one fixed published rule and nothing else: after three misses on a concept that had already come back to that student, the Service stops sending that concept back to them as a returning question and shows the instructor the concept and how many students reached the limit, never which ones. A miss on a question the student is meeting for the first time is not counted toward it. The Service produces no score, level, rank, risk flag or recommendation about a student, and will not: build one; infer emotion; proctor; ingest transcripts, keystrokes or session recordings; score plagiarism or AI use; or show a leaderboard that names a student in a course. Those limits are pinned by automated tests in Processor's codebase and are the Schedule A never-build list on the order form.

E4. Retention. Course rows are deleted at term end plus a stated window: 90 days after the term end date recorded on the course, unless the Institution sets a shorter window. The student's own answer row persists under Processor's permanent-record policy with the institutional link severed, only where the student holds their own account; where they do not, nothing persists. Erasure on request completes within 30 days. Billing records are retained for 7 years under Bokföringslagen.

E5. Subprocessors and regions. Those in Annex III. Class data is stored and processed with Convex Inc. in the EU (Ireland), in pseudonymous tables keyed by account id, with the EU SCCs (Module 3) covering vendor support access from the United States; identity with Clerk Inc. (United States, EU-US Data Privacy Framework); analytics with PostHog Inc. in the EU (Frankfurt), with no identified event per rep for Institution tenants; Cloudflare Inc. in transit only; Slack Technologies LLC only where the Institution connects Slack. Processor's written transfer impact assessment is available on request from legal@atomicreps.com.

E6. Data Subject requests. For a provisioned seat, a student's access, rectification, erasure, restriction or portability request goes to the Institution, and Processor answers the Institution within 12 business days so that the Institution can meet its one-month deadline. Every student can read, inside the Service, the rows the Institution can read about them and a log of each instructor read. For a student account, Atomic Reps AB answers the student directly within one month through the self-serve export and deletion described in the Privacy Policy.

E7. No marketing. Processor sends no marketing for its personal or workplace plans to a student enrolled in a course during the term or for 90 days after it, on any surface including the MCP server. Where the Institution is flagged as teaching minors, no such marketing reaches that roster at all.

E8. Notice before change and termination. If what the Institution can see about a student ever changes, this Schedule changes first, in writing, before any customer gets the feature, and Processor emails every existing customer when it does. If Processor ships any item in E3's never-build list, the Institution may terminate the order form on written notice with a pro-rata refund of prepaid fees for the remaining term.

The compliance pack index lists the rest of the Atomic Campus documents and says which of them are published rather than sent on request. That page restates this Schedule and links back to it; where the two differ, this Schedule governs.

See also: Privacy Policy · Terms of Service · Security