Data Processing Agreement
Last updated: May 12, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Advisor Media Group LLC and its affiliate Advisor Media Group (Bangladesh) (collectively, "Atmos," "Processor," "we," "us") and you ("Controller," "Customer") and governs the processing of personal data by Atmos on behalf of the Customer.
This DPA complies with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- "Data Subject" means the individual to whom Personal Data relates.
- "Sub-processor" means any third party engaged by Atmos to process Personal Data.
3. Scope of Processing
Atmos processes Personal Data solely for the purpose of providing the Services as described in the Terms of Service, including:
- Providing AI-powered advertising creative generation
- Managing and syncing advertising campaigns across platforms
- Generating analytics and performance reports
- Providing customer support
- Improving and developing the Services
4. Categories of Data Processed
4.1 Customer Data
- Account information (name, email, company name)
- Billing information
- Brand assets and creative materials
- Campaign data and settings
4.2 Third-Party Platform Data
- Advertising account information from connected platforms
- Campaign performance metrics
- Audience data and insights
5. Processor Obligations
Atmos agrees to:
- Process Personal Data only on documented instructions from the Controller
- Ensure personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to Data Subject requests
- Delete or return Personal Data upon termination of Services
- Make available information necessary to demonstrate compliance
- Notify the Controller of any data breach without undue delay
- Not use Personal Data, third-party platform API data, or Customer Data to train, fine-tune, evaluate, or otherwise develop any machine-learning or artificial-intelligence model (whether owned by Atmos or by any third party), and to ensure that all AI inference Sub-processors operate under contractual terms that prohibit them from training on Customer inputs or outputs — see Section 5.1 below
5.1 No AI/ML Training Commitment
Consistent with the Google Ads API Terms of Service, the Google API Services User Data Policy (Limited Use), the Meta Platform Terms, the TikTok Marketing API Terms, and the equivalent developer policies of every other platform Atmos integrates with, Atmos commits as a binding term of this DPA that:
- (a) Atmos does not use any data we obtain from third-party platform APIs you connect (Google Ads, GA4, Search Console, Tag Manager, Google Business Profile, YouTube, Meta, Instagram, WhatsApp, TikTok, Pinterest, Twitter/X, Reddit, LinkedIn, Snapchat, Mailchimp, Twilio, etc.) — whether raw, normalized, derived, aggregated, or anonymized — to train, fine-tune, validate, evaluate, benchmark, distill, or otherwise develop any machine-learning or AI model.
- (b) Atmos does not use Customer Data or User Content (brand assets, ad copy, campaign configurations, audience lists, etc.) to train AI/ML models.
- (c) When Atmos routes inputs to AI Sub-processors (Anthropic, OpenAI, Google AI) to deliver AI features, Atmos calls them through commercial API endpoints whose terms expressly prohibit training on Customer inputs and outputs (see Sub-processor table below).
- (d) Atmos does not sell, license, share, or transfer Customer Data or platform API data to any third party for AI/ML training purposes, and does not participate in any cross-customer data-pooling for model development.
- (e) The sole exception is the Atmos website-visitor intent-scoring feature, in which Atmos may train a small per-Controller model exclusively on that Controller's own first-party website-visitor session data, used only for that Controller's benefit, never pooled or shared. This exception is fully described in our Privacy Policy and can be disabled by the Controller at any time.
Any proposed change to this Section 5.1 will be communicated to the Controller with at least 30 days' prior notice and, where required by applicable law or platform terms, requires the Controller's affirmative consent.
6. Sub-processors
The Controller authorizes Atmos to engage Sub-processors for data processing. We maintain a list of current Sub-processors, which includes:
| Sub-processor | Purpose | Location | Training on Customer Data |
|---|---|---|---|
| Hetzner Cloud GmbH | Primary application hosting (servers, database) | USA / Germany | N/A (infrastructure only) |
| Amazon Web Services | Object storage (S3), transactional email (SES) | USA | N/A (infrastructure only) |
| Cloudflare, Inc. | CDN, DNS, DDoS protection, edge security | USA (global edge) | N/A (infrastructure only) |
| Anthropic, PBC | AI inference (Claude family) for chat & agentic features | USA | Contractually prohibited — Anthropic Commercial Terms forbid training on API customer inputs/outputs |
| OpenAI, L.L.C. | AI inference (GPT family) for creative generation & embeddings | USA | Contractually prohibited — OpenAI API does not train on API data per OpenAI Enterprise Privacy |
| Google LLC (Gemini API, paid tier) | AI inference (Gemini family) for select features | USA | Contractually prohibited — paid-tier Gemini API does not use inputs/outputs to improve Google products |
| Stripe, Inc. | Subscription payment processing | USA | No (payments only) |
| Twilio Inc. | SMS notifications, two-factor authentication | USA | No (telecom only) |
| Intercom, Inc. | Customer support messaging | USA | No (support only) |
Atmos does not enroll in any data-sharing, feedback, or evaluation program offered by any AI Sub-processor that would grant the Sub-processor training rights over Customer inputs or outputs. Atmos calls each AI provider exclusively through its commercial API endpoint (not consumer endpoints such as chat.openai.com or gemini.google.com).
We will notify the Controller of any changes to Sub-processors. The Controller may object to new Sub-processors within 30 days.
7. Security Measures
Atmos implements the following security measures:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Access controls and authentication requirements
- Regular security assessments and penetration testing
- Employee security training and background checks
- Incident response and disaster recovery procedures
- SOC 2 Type II certification
8. International Transfers
For transfers of Personal Data outside the European Economic Area, Atmos relies on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework certification where applicable
- Supplementary measures as required by applicable law
9. Data Subject Rights
Atmos will assist the Controller in fulfilling Data Subject requests, including rights to:
- Access their Personal Data
- Rectify inaccurate data
- Erase their data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
10. Audit Rights
Upon reasonable notice, the Controller may audit Atmos's compliance with this DPA. Atmos will provide necessary information and allow for audits conducted by the Controller or an independent auditor.
11. Term and Termination
This DPA remains in effect for the duration of the Services. Upon termination, Atmos will delete or return all Personal Data within 30 days, unless retention is required by law.
12. Contact
For questions about this DPA or to exercise data protection rights:
Advisor Media Group LLC (US) and Advisor Media Group (Bangladesh)
Data Protection Officer
Email: policy@atmosagi.com
Asia Branch: Advisor Media Group, House-80, Bir Uttam Ziaur Rahman Road, Banani, Dhaka-1213, Bangladesh
United States: Advisor Media Group LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA