Privacy Notice
1. Scope
This notice explains what personal data Atlas Help Online processes when your organisation uses Identity Provider, why we process it and how long we keep it. It applies to the id.atlas-help.online endpoint. Your employer, as the workspace owner, is the controller for workspace data; we act as processor on its documented instructions.
2. Data we process
- Account data — work email address, display name, group membership.
- Connection data — IP address, client version, TLS parameters, timestamps.
- Diagnostics — error codes and request identifiers, sampled at 1 %.
- Billing data — held at the workspace level; we store no card numbers.
3. Legal basis
Processing rests on performance of the contract with your organisation, on our legitimate interest in keeping the service secure and available, and on legal obligations for accounting records. We do not rely on consent for service operation and we do not profile users for advertising.
4. Retention
Connection logs are kept for 30 days, audit records for 90 days, and backups for 35 days on a rolling window. Deleting a workspace removes its live data immediately; backup copies age out within the window and are not restored selectively.
5. Sub-processors
We use a European infrastructure provider for compute and storage, and a payment provider for invoicing. The current list, with the region each one operates in, is available to workspace administrators in the console. We give 30 days’ notice before adding one.
6. International transfers
Workspace data is stored in the European Union. Where support requires access from outside the EU, it happens through a bastion that records the session and is covered by standard contractual clauses.
7. Your rights
Requests for access, correction, deletion or portability should go to your workspace administrator, who can act on them directly in the console. If you contact us instead, we forward the request to the controller and confirm once it has been passed on.
8. Changes
Material changes are announced to workspace administrators 30 days before they take effect. The revision number and date at the top of this page always identify the version in force.
9. Authentication events
Sign-in attempts, multi-factor challenges, token issuance and administrative changes to groups are written to an append-only audit log retained for 90 days. Administrators of your workspace can export it at any time. Passwords are never written to the log, and assertion attributes are stored only for the lifetime of the session.