Privacy statement
Last updated 24 September 2026
Atlas is a CRM for business relationships, projects and opportunities. It is operated by DigitalEase Solutions and Consultancy (Stormerdijkstraat 1, 3431 CP Nieuwegein, KvK 93063245), based in the Netherlands. This statement explains which personal data Atlas processes, why, and what you can do about it.
Who is responsible
Organisations use Atlas to manage their own business contacts. For the CRM data an organisation puts into Atlas (companies, contacts, projects, opportunities, notes and synchronised meetings and emails), that organisation is the controller and DigitalEase Solutions and Consultancy processes the data on its behalf, as a processor. Questions about that data are best sent to the organisation that uses Atlas.
For the data we need to run the service itself (your account, sign-in and security logs, billing contacts), DigitalEase Solutions and Consultancy is the controller.
What we process
- Your account: name, email address, password (stored only as a secure hash), the organisations you belong to and your role and permissions in them.
- CRM data your organisation enters or imports: companies, contacts and their job history, projects, opportunities, notes, tasks and relationship assessments.
- Microsoft 365 data, only if you connect your account: for meetings, the time, organiser, attendees and, if your organisation allows it, the subject; for emails, the sender, recipients, time and, if your organisation allows it, the subject. Atlas never reads or stores email bodies or attachments, and it only keeps meetings and emails that involve contacts already in your organisation’s CRM. Everything else is discarded during synchronisation.
- Usage and security data: an audit log of changes inside each organisation, and technical logs (such as IP address and error reports) used to keep the service secure and working.
Why we process it
- To provide the service your organisation signed up for (performance of a contract).
- To keep the service secure, prevent abuse and fix errors (our legitimate interest in a safe, working service).
- To send you the emails the service needs: confirming your address, resetting your password, invitations and important notices about your organisation.
- To meet legal obligations, such as keeping financial records.
We do not sell personal data and we do not use it for advertising.
AI features
Organisations can switch on optional AI features, such as meeting briefs and follow-up suggestions. They are off until an owner or admin switches them on. When used, the relevant CRM records are sent to our AI provider, Anthropic, to produce the result; notes and meetings marked private or team-only are never sent. Anthropic processes the data on our behalf and does not use it to train its models.
Who else processes data
We use these service providers, each under a data processing agreement:
- Supabase: database, sign-in and file storage (hosted in London, United Kingdom).
- Vercel: application hosting (functions run in London, United Kingdom).
- Resend: delivery of the service’s emails.
- Microsoft: only when you connect Microsoft 365 or sign in with Microsoft.
- Anthropic: only when your organisation switches on AI features.
- Sentry: error reports, stripped of personal data where possible.
The United Kingdom has an adequacy decision from the European Commission. Where a provider processes data outside the European Economic Area or the United Kingdom, the transfer is covered by the European Commission’s standard contractual clauses or an equivalent safeguard.
How long we keep it
- CRM data is kept for as long as your organisation uses Atlas. Owners and admins can set automatic deletion for captured emails and meetings, the audit log, AI outputs and market signals.
- When an organisation is deleted, it is removed after a 30-day cooling-off period, together with all of its data and files.
- Disconnecting Microsoft 365 deletes the access tokens at once; meetings and emails already captured stay with the organisation until they are deleted.
- Full data exports are deleted automatically after 7 days.
Security
Every organisation’s data is separated at database level, so one organisation can never read another’s. Data is encrypted in transit and at rest, Microsoft access tokens are additionally encrypted with keys held outside the database, and every change is recorded in the organisation’s audit log. Support staff can only look inside an organisation when an owner grants time-limited, read-only access, and that access is logged.
Cookies
Atlas only uses cookies that are strictly necessary: to keep you signed in and, for a few minutes while you connect Microsoft 365, to secure that connection. There are no analytics or advertising cookies.
Your rights
You can ask to see, correct, delete or export your personal data, object to its processing, or ask us to restrict it. For CRM data we will pass your request to the organisation that controls it and help them answer it. You can also revoke Atlas’s access to your Microsoft account at any time, in Atlas (Settings › Integrations › Disconnect) or at myapps.microsoft.com (work accounts) or account.microsoft.com (personal accounts).
If you are not satisfied with how we handle your data, you can complain to the Dutch Data Protection Authority, Autoriteit Persoonsgegevens.
Contact
Email info@work-force.nl with any question about privacy. We answer within one month.
Changes
We update this statement when Atlas changes how it handles data. The date at the top shows the latest version; we tell organisation owners by email about important changes.