GDPR Compliance

Your data, your rights

Atomic Work is built with GDPR principles from the ground up. We collect only what we need, protect it with AES-256 encryption, and give you full control to export or delete it at any time.

Your rights under GDPR

Right to Access

You can request a copy of all personal data we hold about you at any time. This includes your profile, workflows, run history, and activity logs.

Export your data from Settings → Profile → Data & Privacy.

Right to Data Portability

We provide your data in a machine-readable JSON format so you can import it into other systems.

Use the Export button in your Profile page.

Right to Erasure

You can request permanent deletion of your account and all associated data. This removes your profile, workflows, runs, and activity logs from our systems.

Delete your account from Settings → Profile → Data & Privacy.

Right to Object

You can object to our processing of your personal data for direct marketing at any time. We will stop processing immediately.

Email privacy@theatomicwork.com to opt out.

Data we collect

We collect the minimum data needed to provide the service. We never sell personal data to third parties.

CategoryExamples
Account dataName, email address, password hash (Firebase Auth)
Workflow dataWorkflows you create, step configurations, run history
Integration credentialsOAuth tokens and API keys stored AES-256 encrypted
Usage dataLogin timestamps, feature interactions, audit logs
Billing dataSubscription plan, payment method (managed by Stripe — we never store card numbers)

Technical safeguards

AES-256 encryption at rest via Google Cloud Firestore
TLS 1.3 in transit on all connections
Integration credentials encrypted and never exposed in exports
Role-based access control — users see only their data
Audit logging on all critical operations
Automatic session expiry and token rotation via Firebase Auth

Data Processing Agreement

Enterprise customers can request a Data Processing Agreement (DPA) to meet their own compliance requirements.

Request a DPA

Privacy contact

For privacy questions, data subject requests, or to exercise any of your GDPR rights, contact our privacy team directly.

privacy@theatomicwork.com