This policy covers the Atlas platform — the software Execution Partner provides to businesses and agencies, including Atlas HQ and the client Nexus workspaces. It explains what the platform handles, how connected accounts work, and what we commit to when a business connects a third-party account such as Google.
General website privacy is covered by our website privacy policy. The Atlas Connect mobile app is covered by its own policy.
Our role
Businesses that use Atlas own their data. We process it on their behalf and under their instruction, to operate the features they have turned on. Each business's workspace is isolated from every other business's workspace. We do not pool one customer's data into another customer's workspace.
What the platform handles
- Account information. Names, email addresses, and roles of the people a business authorizes to use its workspace.
- Business and customer records. Contacts, conversations (SMS, email, calls, voicemail), appointments, jobs, opportunities, forms, and related notes belonging to the business.
- Connected account data. Data retrieved from third-party services a business chooses to connect — described below.
- Credentials for connected accounts. Access and refresh tokens, encrypted at rest.
- Operational data. Logs, usage metering, and diagnostics used to run, bill, and troubleshoot the platform.
Connected accounts
A business can connect third-party services to Atlas. Connecting is always initiated by an authorized user of that business, and can be disconnected at any time from the same screen. We request the narrowest access that makes the feature work.
When a business connects a Google account, Atlas may request the following access, depending on which features that business uses:
- Google Ads and Local Services Ads (
adwords) — to read Local Services lead reports and account performance reports for the accounts the business has linked, and to establish that account link. Atlas uses this to show the business its own leads and ad performance, and to create a contact record for each new lead. - Gmail (
gmail.send,gmail.readonly) — to send email on the user's behalf from the workspace and to thread replies back onto the right customer record. - Google Calendar (
calendar.events) — to read and write appointments so bookings stay in sync. - Google account email address (
userinfo.email) — to identify which account was connected. - Postmaster Tools (
postmaster.readonly) — to read sending-domain reputation metrics so we can protect email deliverability.
We use this data only to provide the features described above to the business that connected the account. We do not use Google user data for advertising. We do not sell it. We do not use it to train generalized artificial intelligence or machine learning models. Humans do not read it, except where the business asks us to help with a specific problem, where it is necessary for security or to fix a bug, or where the law requires it.
Limited Use. Atlas's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Other services
Businesses may also connect services such as Meta (Facebook and Instagram), telephony and messaging providers, payment providers, calendar and field-service systems, and analytics tools. The same principles apply: access is granted by the business, used only to deliver the feature, and revocable at any time.
How we store and protect credentials
Access and refresh tokens for connected accounts are encrypted at rest with AES-256-GCM and are held server-side only. They are never exposed to the browser and never shown in the interface. Access to production systems is restricted to the staff who need it.
Sub-processors
We use a small set of infrastructure and service providers to run the platform — including cloud hosting, database and storage, telephony and messaging, email delivery, and AI model providers. They process data on our behalf, under contract, for the purpose of delivering the service. We do not sell data to anyone.
AI processing
Some features send business content to AI model providers to generate drafts, summaries, or replies. We use providers under agreements that prohibit training their general models on our customers' content. Data retrieved from Google APIs is not used for model training.
Retention and deletion
We keep a business's data for as long as its account is active, and for a reasonable period afterward to meet legal, tax, and backup obligations. A business can ask us to export or delete its data by emailing the address below.
Disconnecting a connected account stops all further access immediately and removes the stored credentials for it. A user can also revoke Atlas's access to their Google account at any time from myaccount.google.com/permissions.
Your rights
Individuals whose information appears in a business's workspace should contact that business first, since it controls the data. If you contact us directly, we will route the request to the business and support them in responding. Depending on where you live, you may have rights to access, correct, or delete information held about you.
Children
Atlas is a business tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Updates
We may update this policy. The effective date at the top reflects the most recent revision. Material changes will be communicated to account administrators.
Contact
For questions about this policy, data requests, or security matters, email contact@executionpartner.ai.