Privacy
We protect personal data and explain here what e-label Atlas processes, why we process it, and what rights you have.
1. Who we are and how to contact us
The controller under the General Data Protection Regulation is:
Essential Code GmbH
Glücksallee 8
3012 Wolfsgraben
Austria
Email: david@essentialcode.eu
2. Our data processing
2.1 General
We process personal data under the GDPR and the Austrian Data Protection Act. Depending on the activity, the legal basis is performance of a contract or steps requested before a contract under Article 6(1)(b) GDPR, compliance with a legal obligation under Article 6(1)(c), or our legitimate interests in operating, securing and improving Atlas under Article 6(1)(f). We do not use automated decision-making.
2.2 Website delivery and security
When you request a page or API endpoint, the hosting infrastructure receives technical request data such as your IP address, date and time, requested URL, response status, referring page, browser and operating system. This is necessary to deliver Atlas, keep it reliable, investigate faults and protect it from abuse. The legal basis is our legitimate interest in operating a secure service under Article 6(1)(f) GDPR.
2.3 Accounts and identity
Atlas uses Hanko for sign-in by email passcode. Atlas does not offer passwords or passkeys. Hanko processes the identity and session information needed to authenticate you. Our local user record stores your Hanko subject identifier and email address so that your account can be linked to Atlas data. It never stores a credential.
A necessary session cookie keeps you signed in. Beyond that session cookie, Atlas sets no cookie.
2.4 Provider accounts
For providers, we store the workspace and its contact details, members and roles, invitations, acceptance of the provider terms, and API key metadata. API key secrets are returned once and never stored. Atlas stores only a cryptographic hash and a short display prefix.
If a provider configures webhooks, we store the subscription, an encrypted signing secret, and delivery attempts including their status and safe failure information. We do not retain receiver response bodies.
2.5 Data consumer accounts and exports
If you register as a data consumer, we store your organisation name, country, organisation type, intended use, optional website, terms acceptance and timestamps. Every spreadsheet export is logged with your consumer profile, search text, filters, row count and time. We log who exports what because Atlas needs to know how its data is being used.
2.6 Public record data
Atlas records are product data that providers deliberately publish for public access. They describe products, not people, and providers must not submit personal data in those records.
2.7 Analytics
Public pages use Plausible Analytics, with its script served from plausible.io. Plausible is a privacy-friendly, cookieless analytics service. It does not perform cross-site tracking, build advertising profiles or create personal profiles. We use only aggregate page statistics to understand which public pages are useful. Plausible does not run on signed-in pages.
Beyond Plausible, Atlas has no other third-party script, no advertising, and no cookie other than the session cookie needed to stay signed in.
2.8 Hosting and processors
Hanko is our identity processor. Bunny is our hosting and infrastructure processor: Atlas runs in a Bunny Magic Container, account and record data is held in Bunny Database in Austria, and record images use Bunny storage and CDN services. Plausible is our analytics processor for aggregate use of public pages.
3. How long we store personal data
We keep account and organisation data while the account is active and as long as it is needed to operate Atlas, handle security issues, meet legal obligations, or establish and defend legal claims. Invitations, API key metadata, webhook delivery history and export logs are retained only for those operational and accountability purposes. When data is no longer needed, we delete or anonymise it unless a legal retention duty requires us to keep it longer.
4. Your rights
Where the legal conditions are met, you have the right to:
- request access to your personal data
- have inaccurate or incomplete data corrected
- request erasure or restriction of processing
- receive data you provided in a portable format where Article 20 GDPR applies
- object to processing based on legitimate interests for reasons arising from your situation
- withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing
To exercise a right, email david@essentialcode.eu.
4.1 Right to complain
You may complain to a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, www.dsb.gv.at.