Atlas Hospitality OS
Privacy Policy
Atlas Hospitality OS (“we”, “us”, “the service”) helps UK hospitality businesses manage establishment journeys, food-safety handbooks, equipment registers, certificates, operational logs, and related documents. This policy explains what we collect, how we use it, and your choices.
1. Who is responsible
The service operator is the publisher of this Atlas instance (the organisation that hosts the application you are using). For questions about privacy, contact the operator via the account or contact email provided when you were invited to the service.
2. Information we collect
- Account data — email address, name (if provided), and authentication identifiers. When you sign in with Google, we receive basic profile information (such as email and name) from Google under Google’s OAuth flow.
- Business content you enter — tenant/business profile, journey tasks, handbook procedures, equipment records, certificates, temperature logs, notes, and uploaded files.
-
Google Drive (optional) — only if you explicitly connect Google Drive.
With your consent we access Drive files and folders you choose so Atlas can import
documents (for example certificates or manuals) and suggest register fields. We use
the
drive.readonlyscope: we do not edit, delete, or share your Drive files on Google’s servers. We read the selected content to store a copy in your Atlas workspace for analysis and record-keeping. - Technical logs — limited server logs (e.g. request times, errors) for reliability and security.
3. How we use information
- Provide the Atlas product features you request (journeys, handbook, registers, logs, search, AI assistance).
- Authenticate you and enforce multi-tenant access control.
- Analyse uploaded or imported documents to extract knowledge and compliance dates (using configured AI providers when enabled).
- Improve reliability and fix faults.
- Comply with legal obligations where applicable.
4. Google user data
Google account data obtained via OAuth is used only to authenticate you (and, where you connect Drive, to access Drive content you select for import). We do not sell Google user data. We do not use Google user data for advertising. We do not allow unrelated human review of Google user data except as needed to provide the service, secure the system, or comply with law. Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Sharing
We share data only as needed to run the service, for example:
- Infrastructure providers that host the application, database, object storage, and messaging (under our control or contract).
- AI providers you configure for the instance (e.g. document analysis / Atlas chat), when those features are enabled.
- When required by law or to protect the service and users.
Other members of your tenant workspace may see content belonging to that tenant according to their access rights.
6. Retention
We retain account and tenant content while your account and the operator’s instance are active. You may delete certificates, assets, documents, and other records in the product where the feature allows. You can disconnect Google Drive at any time; this stops future Drive access. Copies already imported into Atlas remain until you delete them.
7. Security
We use access controls (authenticated APIs, tenant membership checks) and standard hosting protections. No method of transmission or storage is perfectly secure.
8. International transfers
Depending on hosting and AI providers configured for the instance, data may be processed in the UK, EU, or other regions. The operator is responsible for appropriate safeguards.
9. Your rights
Depending on your location (including UK GDPR), you may have rights to access, correct, delete, or restrict processing of personal data, and to object or port data. Contact the operator to exercise these rights.
10. Children
Atlas is intended for business use and is not directed at children under 16.
11. Changes
We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date on this page.
12. Contact
For privacy requests relating to this Atlas instance, contact the service operator through the channels provided with your account (or the organisation that invited you).