A Atllanta Sign in

Privacy Policy

Last updated: 18 August 2026 · Effective date: 18 August 2026

Note: The operating entity name and registered address (shown as [LEGAL ENTITY NAME] / [REGISTERED ADDRESS] / [CITY, STATE]) are being finalised on company registration and will be inserted before commercial launch. This policy is aligned to Indian law and is not legal advice; please have it reviewed by qualified legal counsel.

This Privacy Policy explains how [LEGAL ENTITY NAME] (“Atllanta”, “we”, “us”, “our”), the operator of the Atllanta Business Operating System available at atllanta.vercel.app and its mobile/installable app (together, the “Platform”), collects, uses, discloses, retains and protects personal data. We are committed to processing personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and applicable rules made thereunder.

Contents

  1. Our role & scope
  2. Data we collect
  3. How & why we use data
  4. Consent & lawful basis
  5. Sharing & sub-processors
  6. Cross-border transfers
  7. Data retention
  8. Security
  9. Your rights
  10. Grievance redressal
  11. Children’s data
  12. Cookies & tracking
  13. Changes to this policy
  14. Governing law
  15. Contact us

1. Our role & scope

Atllanta is a business software platform used by organisations (“Customers”) to manage hiring, employees, attendance, leave and customer relationships. Under the DPDP Act, roles differ depending on the data:

“Data Principal” means the individual to whom the personal data relates. “Personal data” means any data about an individual who is identifiable by or in relation to such data.

2. Data we collect

2.1 Data you or your organisation provide

2.2 Data collected automatically

We do not knowingly collect more personal data than is necessary for the purposes described below.

3. How & why we use data

We use personal data for the following purposes:

We do not sell personal data. We do not use employee, candidate or customer data uploaded by a Customer to train our own or third parties’ general-purpose AI models.

5. Sharing & sub-processors

We share personal data only as needed to operate the Platform, and under contractual safeguards. We engage the following categories of sub-processors (“Data Processors”):

Sub-processorPurposeLocation
Supabase (database, auth, storage)Hosting the application database, authentication and file storageRegion: ap-south-1 (India)
VercelApplication hosting & content deliveryGlobal CDN
GroqAI inference for resume/JD parsing & matching (transient processing)Outside India
ResendTransactional email deliveryOutside India
Google (optional)Calendar/Meet scheduling, and Google sign-in if enabledGlobal

We may also disclose personal data: (a) to comply with law, legal process or a lawful government request; (b) to enforce our terms or protect rights, safety and property; and (c) in connection with a merger, acquisition or asset sale, subject to this policy.

6. Cross-border transfers

Some sub-processors may store or process personal data outside India. Where this occurs, we do so consistent with the DPDP Act (which permits transfer except to territories restricted by the Central Government) and apply appropriate contractual safeguards. We will honour any restrictions notified by the Government from time to time. Your primary application data — the database, authentication and file storage — is hosted in India (Supabase, ap-south-1); only limited processing (AI inference and transactional email) occurs outside India, as listed above.

7. Data retention

We retain personal data only for as long as necessary to fulfil the purposes above, to provide the Platform to the Customer, and to meet legal, accounting or reporting requirements. When a Customer’s account is closed, we delete or de-identify the associated personal data within 90 days, except where retention is required by law. Data Principals may request erasure as described below.

8. Security

We implement reasonable security practices and procedures under the SPDI Rules and the DPDP Act, including:

No method of transmission or storage is completely secure. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.

9. Your rights as a Data Principal

Subject to the DPDP Act, you have the right to:

To exercise these rights, contact us using the details below. If your data is held on behalf of your employer/organisation (Customer), we will refer your request to them or act on their instruction. We may need to verify your identity before acting on a request.

You also have a duty under the DPDP Act not to impersonate another person, suppress material information, or file false or frivolous grievances or requests.

10. Grievance redressal

In accordance with the DPDP Act and the Information Technology Act, 2000, we have appointed a Grievance Officer / Data Protection point of contact to address your concerns:

Grievance Officer: Sachin V Anchan
Email: anchansachinv99@gmail.com
Phone: +91 80731 63762
Address: [REGISTERED ADDRESS]

We will acknowledge grievances promptly and endeavour to resolve them within the timelines prescribed under applicable law (typically within 30 days). If you are not satisfied, you may escalate to the Data Protection Board of India.

11. Children’s data

The Platform is intended for use by businesses and their adult personnel and is not directed at children. We do not knowingly process the personal data of children (individuals under 18) except as permitted by law and with verifiable parental/guardian consent. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

12. Cookies & tracking

We use only strictly necessary cookies, tokens and local/IndexedDB storage to keep you signed in, remember your preferences (such as theme), and enable the installable, offline-capable app. We do not use third-party advertising or cross-site tracking cookies. You can clear this storage via your browser, but the Platform may not function correctly without it.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Platform or by email, and the “Last updated” date above will change. Your continued use of the Platform after an update constitutes acceptance of the revised policy where permitted by law.

14. Governing law & jurisdiction

This Privacy Policy is governed by the laws of India. Subject to applicable law and the jurisdiction of the Data Protection Board of India, the courts at [CITY, STATE] shall have exclusive jurisdiction over any disputes arising out of or relating to this policy.

15. Contact us

[LEGAL ENTITY NAME] (Atllanta)
Email: anchansachinv99@gmail.com
Phone: +91 80731 63762
Registered address: [REGISTERED ADDRESS]