Privacy Policy
Last updated: August 2026
1. Controller and Contact Details
Controller within the meaning of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG):
Sprad Software GmbH Kaiserstraße 16 / 7-9 1070 Vienna, Austria
Company registration number: FN 558095d Commercial court: Commercial Court of Vienna VAT ID: ATU77057159
E-mail: [email protected]
2. Principles and Constitutional Framework
This Privacy Policy is based on Regulation (EU) 2016/679 (GDPR), the Austrian Data Protection Act (Datenschutzgesetz, DSG) as amended, the Austrian Telecommunications Act 2021 (TKG 2021), and Regulation (EU) 2024/1689 on Artificial Intelligence (the AI Act).
Under § 1 DSG, every person has a right to confidentiality of their personal data, insofar as they have a legitimate interest in such confidentiality. This constitutionally guaranteed right is subject to the principle of proportionality; interferences are permitted only to the least extent necessary.
All employees of Sprad Software GmbH and its processors are subject to the duty of data secrecy under § 6 DSG. They are contractually obliged to maintain the confidentiality of all personal data that becomes accessible to them in the course of their professional activities. This obligation continues even after the end of the employment relationship.
Use of the Platform is subject to the Terms and Conditions, including their annexes (AI Usage Terms, Acceptable Use Policy), available at https://atlas.now/terms.
3. Overview of Processing Activities
Atlas Apply is an AI-powered B2C platform aimed at consumers in the European Economic Area (EEA) and Switzerland. Candidates receive a personalized, tokenized link by e-mail and go through an onboarding process (text input, optional PDF upload, voice-based interaction with the Voice Agent, AI-assisted CV generation). They then have access to a jobs hub featuring matched positions and tailored application documents. Registration is free of charge and includes a one-time usage quota; in addition, paid subscriptions with a monthly usage quota are available.
4. Categories of Personal Data
We process the following categories of personal data:
| Data Category | Description | Collection |
|---|---|---|
| Core personal data | Name, e-mail address, phone number where applicable | Directly, upon registration/onboarding |
| Profile and career data | Profile texts, work experience, qualifications, career preferences, salary expectations | Directly (text input, Voice Agent) |
| Uploaded documents | Résumés, certificates, credentials (PDF/images) | Directly (upload) |
| Voice data | Audio recordings of Voice Agent sessions and transcripts generated from them | Directly (voice session) |
| AI-generated data | Generated résumés, cover letters, profile summaries, match scores | Automatically, by AI systems |
| Research/matching data | Job research results, job matches, employer data | Automatically, through AI research |
| Payment data | Subscription purchases, transaction history, invoice data, SEPA mandate references, credit/debit card numbers | Provided by you at purchase |
| Browser telemetry | Journey events, page views, fetch errors, device information | Automatically (with consent) |
| E-mail communication data | Content of transactional e-mails (confirmations, notifications), delivery status, recipient e-mail address, timestamps | Automatically, upon sending e-mails |
Special note on voice data Voice recordings may qualify as biometric data within the meaning of Art. 9 GDPR if processed to uniquely identify a person. We use your voice recordings exclusively for transcription and profile capture during onboarding, not for biometric identification. Processing is based on your express consent (Art. 6(1)(a), Art. 9(2)(a) GDPR).
5. Purposes and Legal Bases of Processing
5.1 Performance of a contract (Art. 6(1)(b) GDPR)
- Providing the Platform and its core features (onboarding, profile creation, job matching, CV generation, application creation)
- Managing your user account
- Processing payment transactions
- Communicating with you about your account and applications
- Sending transactional e-mails (contract confirmations, withdrawal confirmations, account notifications, password resets)
5.2 Consent (Art. 6(1)(a) GDPR)
- Processing of voice data (recording and transcription in the Voice Agent), including transfer to the USA
- Browser telemetry and usage analytics (§ 165(3) TKG 2021)
- Processing of data by AI systems, insofar as this goes beyond mere performance of the contract
Consent may be withdrawn at any time with effect for the future (see Section 11). Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
5.3 Legitimate interests (Art. 6(1)(f) GDPR)
- Improving and further developing the Platform
- Ensuring IT security and detecting misuse
- Logging, error analysis, and quality assurance of AI inputs and outputs on our own infrastructure
- Defending legal claims (including retention under § 29 of the Austrian Equal Treatment Act, GlBG)
- Using anonymized and aggregated data (which does not permit any inference to individual users) to improve the Platform and for statistical analysis (see § 12(5) of the Terms). Anonymized data is not subject to the GDPR.
5.4 Legal obligations (Art. 6(1)(c) GDPR)
- Retention of tax-relevant records (§ 132 of the Austrian Federal Fiscal Code, BAO: 7 years) and commercial-law records (§§ 190–212 of the Austrian Commercial Code, UGB: 7 years)
- Other statutory documentation obligations
5.5 Performance of a contract for one-off purchases (Art. 6(1)(b) GDPR) To the extent the Platform offers individual digital content in addition to the subscription (e.g. one-off quota top-ups), we process the personal data required for this purpose (in particular payment and usage data) on the basis of contract performance. The provisions of § 7(6) of the Terms apply to the lapse of the right of withdrawal for digital content under § 18(1)(11) FAGG. The express consent and acknowledgment required for this are documented during the order process.
6. Use of Artificial Intelligence / Transparency Notices
6.1 AI systems Atlas Apply uses several AI systems. In accordance with Art. 50 of the AI Act (Regulation (EU) 2024/1689) and Art. 13(2)(f) GDPR, we inform you transparently about their use:
| AI Function | Description | Provider | Data Flow |
|---|---|---|---|
| CV generation / profile summary | AI generates professional résumés and context summaries from your information | Anthropic (Claude API) | Profile data to Anthropic (USA) |
| Application materials | AI creates tailored cover letters based on your profile and the job posting | Anthropic (Claude API) | Profile and job data to Anthropic (USA) |
| Job matching | AI-assisted comparison of your profile against available job postings and assessment of fit | Anthropic (Claude API) | Profile and job data to Anthropic (USA) |
| Voice Agent | AI-powered voice assistant for capturing your professional profile | ElevenLabs | Audio data to ElevenLabs (USA) |
| AI logging | Recording of AI requests and responses for error analysis and quality assurance | Atlas Apply (own infrastructure) | No transfer to third parties; stored in Germany |
Important notice pursuant to Art. 50(1) of the AI Act: When you interact with the Voice Agent or an AI-powered chatbot, you are speaking with an artificial intelligence system, not a human. All content generated by the AI (résumés, cover letters, profile summaries) is AI-generated.
6.2 Automated decision-making and profiling (Art. 22 GDPR) Atlas Apply carries out profiling within the meaning of Art. 4(4) GDPR: we automatically analyze your career data in order to compare your profile against job postings and identify suitable positions (job matching).
How the job-matching algorithm works The system analyzes your professional qualifications, experience, skills, and preferences and compares them with the requirements and characteristics of job postings. In particular, the following factors are taken into account:
- Match between qualifications and job requirements
- Work experience and career level
- Industry knowledge and specializations
- Your stated preferences (location, salary, work arrangement)
- Language skills and other skills
Significance and consequences The matching results determine which job postings are shown to you and in what order, and form the basis for the AI-generated application documents.
Not a purely automated decision with legal effect. The final decision as to whether and to which position you apply rests solely with you. Atlas Apply does not automatically reject any candidate and does not make automated hiring decisions. The AI-generated recommendations are suggestions that remain subject to your assessment and control.
Your rights regarding automated processing Notwithstanding the above classification, we guarantee you the following rights in accordance with Art. 22(3) GDPR:
- Right to human review: you may at any time request that AI results be reviewed by a human
- Right to express your point of view: you may raise objections to matching results
- Right to contest: you may contest AI-generated results and request a reassessment
- Right to an explanation: you are entitled to meaningful information about the logic and principles actually applied in the automated processing
Contact for exercising these rights: [email protected]
No processing of special categories of data: the matching algorithm does not use data concerning racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, or sexual orientation (Art. 9 GDPR). If you voluntarily provide such information in your profile texts, we ask that you refrain from doing so.
7. Processors and Recipients
7.1 Overview of processors We use the following processors:
| Processor | Purpose | Location | Transfer Mechanism | Certifications |
|---|---|---|---|---|
| Hetzner Online GmbH | Server, database, and storage infrastructure (hosting) | Germany | No third-country transfer | ISO/IEC 27001:2022, BSI C5 Type 2 |
| Amazon Web Services EMEA SARL | Encrypted backups | EU, Frankfurt (eu-central-1) | EU-based processing; for any US access: EU SCCs (Modules 2+3, Decision 2021/914) | ISO 27001, SOC 1, SOC 2, BSI C5 |
| Anthropic PBC | CV generation, profile summarization, application materials, job matching | USA | EU SCCs (Modules 2+3, Decision 2021/914) | SOC 2, ISO 27001, ISO 42001 |
| ElevenLabs, Inc. | Voice Agent, transcription | USA | EU-US DPF, supplemented by EU SCCs (Modules 2+3, Decision 2021/914) | SOC 2, ISO 27001, ISO/IEC 42001, PCI DSS |
| Stripe Payments Europe, Limited / Stripe, Inc. | Payment processing, subscription management, invoicing, fraud detection, tax calculation | EU (Ireland); USA | EU-based processing (Ireland); for US access: EU SCCs (Modules 2+3) | PCI DSS Level 1, SOC 1, SOC 2 |
| Mailgun Technologies, Inc. | Transactional e-mail delivery (confirmations, notifications, password resets) | EU (Germany) | EU-based processing; for any US access: EU-US DPF + EU SCCs (Modules 2+3, Decision 2021/914) | SOC 2, ISO 27001, ISO 27701 |
7.2 Details on processors Hetzner (hosting infrastructure): Atlas Apply's server, database, and storage infrastructure is operated by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany. All profile, career, and document data, as well as all database content, is stored exclusively in data centers in Germany; no transfer to third countries takes place. Hetzner processes data strictly on our instructions under a data processing agreement pursuant to Art. 28 GDPR. Access occurs only to the extent necessary for operation, maintenance, and support. Hetzner operates an information security management system certified to ISO/IEC 27001:2022 and holds a BSI C5 attestation.
Amazon Web Services (backups): To protect against data loss, we store encrypted backups with Amazon Web Services in the Frankfurt region (eu-central-1). The contracting party for customers in the European Economic Area is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. Backup data does not leave the EEA in normal operation. Since Amazon.com, Inc.'s corporate headquarters are located in the USA, access from the USA cannot be entirely ruled out; in that case, the EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 apply, automatically incorporated via the AWS Data Processing Addendum. Backups are overwritten on a rolling basis after 30 days at the latest; data you delete is therefore also removed from backups within 30 days at the latest.
Anthropic (Claude API): Anthropic processes data submitted to the API exclusively to provide the service (profile creation, context summarization, CV generation, creation of application documents, and job matching). Anthropic does not use API data to train its AI models. Prompts and outputs are deleted by default within 30 days. Based on publicly available information, Anthropic is not certified under the EU-US Data Privacy Framework; transfers are therefore based on the EU Standard Contractual Clauses (SCCs) under Implementing Decision (EU) 2021/914.
ElevenLabs (Voice Agent): Voice synthesis and transcription in the Voice Agent are provided by ElevenLabs. Processing takes place on servers located in the United States. According to ElevenLabs, the responsible group entity for voice data is Eleven Labs Poland sp. z o.o., Warsaw, while technical processing is carried out by Eleven Labs, Inc. (USA). The transfer relies on the US entity's certification under the EU-US Data Privacy Framework (verifiable at dataprivacyframework.gov), supplemented by the EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914, which form part of the contract via ElevenLabs' data processing agreement. We have additionally carried out a Transfer Impact Assessment. Processing takes place solely on the basis of your express consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR); this consent expressly covers the transfer of your voice data to the USA. We have disabled the use of your voice data for training ElevenLabs' models. Voice recordings and session data are deleted by ElevenLabs after 30 days; for technical reasons, they may remain in ElevenLabs' backup copies for a further period of up to 30 days.
Stripe (payment processing): Payment processing is carried out via Stripe Payments Europe, Limited, based in Ireland. Stripe processes payment data submitted to the API exclusively to provide the payment service. Complete credit and debit card numbers are processed exclusively by Stripe and secured in accordance with PCI DSS Level 1; the Provider never has access to this data. Stripe uses cookies and similar technologies for fraud detection (Stripe Radar); these are classified as technically necessary. For tax calculation (Stripe Tax), we transmit the User's address or location to Stripe in order to determine the correct value-added tax for the country of destination. Stripe automatically generates invoices (Stripe Invoicing) showing the country-specific value-added tax. Data processing takes place primarily on servers within the EU, in particular in Ireland. Since Stripe, Inc.'s group headquarters are located in the USA, access to personal data from the USA cannot be ruled out; in that case, we have agreed EU Standard Contractual Clauses (SCCs) under Implementing Decision (EU) 2021/914. Stripe's privacy policy is available at stripe.com/privacy.
Mailgun (e-mail delivery): Transactional e-mails (in particular contract confirmations, withdrawal confirmations, acknowledgments of receipt of withdrawal forms, account notifications, password resets, and notices of changes to the Terms) are sent via Mailgun Technologies, Inc., a subsidiary of Sinch AB (publ), Sweden. Mailgun processes the data transmitted (name, e-mail address, e-mail content, delivery metadata) exclusively to provide the e-mail service. We use Mailgun's EU region; data processing takes place on servers within the EU (Google Cloud, Germany). Since Mailgun Technologies, Inc. is headquartered in the USA (112 E Pecan St, Suite 1135, San Antonio, TX 78205), access to personal data from the USA cannot be ruled out. In that case, we rely on Mailgun's DPF certification (verifiable at dataprivacyframework.gov) as well as EU Standard Contractual Clauses (SCCs) under Implementing Decision (EU) 2021/914. The data processing agreement (DPA version 8, October 2025) is automatically concluded together with Mailgun's terms of use and is available at mailgun.com/dpa. E-mail content is stored by Mailgun for a maximum of 7 days; following account deletion, complete erasure occurs within 90 days. Mailgun's privacy policy is available at mailgun.com/legal/privacy-policy.
7.3 Other recipients Personal data may also be disclosed to the following recipients:
- Stripe Payments Europe, Limited (Ireland) for payment processing, subscription management, automated invoicing, and fraud detection (see § 7.2 for details)
- Authorities where legally required (e.g. tax authorities, courts)
- IT service providers for hosting, maintenance, and support
- Providers of analytics, performance, and functional services under the Cookie Policy (e.g. web analytics, behavioral analytics, support chat). A complete list of these recipients, including the respective transfer mechanisms, can be found in our Cookie Policy.
8. International Data Transfers
8.1 Transfers to the USA Several of our processors are based in the United States. Transfers of personal data to the USA are safeguarded as follows:
EU-US Data Privacy Framework (DPF): For ElevenLabs and Mailgun, we rely on the European Commission's adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795). Both providers are certified under the DPF. In Mailgun's case, processing additionally takes place on servers within the EU (Germany), so that a regular third-country transfer only occurs with ElevenLabs. We note that the adequacy decision is subject to appeal proceedings before the Court of Justice of the European Union; it is currently fully valid. In the event it is overturned, we have additionally agreed Standard Contractual Clauses with all affected providers.
EU Standard Contractual Clauses (SCCs): For Anthropic, ElevenLabs, Amazon Web Services, Stripe, and Mailgun, we have agreed EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 (Module 2 for transfers from controller to processor, Module 3 for transfers to sub-processors). We have additionally carried out Transfer Impact Assessments (TIAs). Stripe processes payment data primarily in Ireland, Amazon Web Services stores backups exclusively in Frankfurt, and Mailgun sends e-mails via servers in Germany; in these cases, the SCCs serve as a safeguard against any access from the USA.
8.2 Processing within the EU/EEA Core data storage (application servers, database, file storage) is carried out by Hetzner Online GmbH in Germany. Encrypted backups are held by Amazon Web Services in Frankfurt. Logging of AI processing takes place on our own infrastructure in Germany. In normal operation, this data does not leave the European Economic Area.
9. Cookies, Browser Telemetry, and § 165 TKG 2021
9.1 Technically necessary cookies Pursuant to § 165(3) TKG 2021, we use the following technically necessary cookies, which do not require consent because they are strictly necessary to provide the service you have expressly requested:
- Session cookies for authentication and session management
- CSRF tokens to protect against cross-site request forgery attacks
- Cookie consent storage to document your cookie preferences
- Cookies and similar technologies used by our payment provider Stripe for fraud detection, device recognition, and secure payment processing (Stripe Radar)
9.2 Technologies requiring consent In addition, we use technologies that require consent, in particular for web analytics, behavioral analytics, and functional services (e.g. support chat). These technologies are activated only with your prior, active consent pursuant to § 165(3) TKG 2021 in conjunction with Art. 6(1)(a) GDPR.
A complete list of all cookies and similar technologies used, including provider names, purposes, retention periods, and any third-country transfers, can be found in our Cookie Policy at https://atlas.now/cookie-policy. The Cookie Policy forms part of this Privacy Policy for the purposes of the information obligations under Art. 13 GDPR.
We obtain your consent via a cookie/consent banner before setting non-essential cookies. Consent may be withdrawn at any time; withdrawal is as easy as giving consent (via consent settings). Default settings are always set to "declined" (privacy by default).
10. Retention Periods
We retain personal data only for as long as necessary for the respective processing purpose, or as required by statutory retention obligations:
| Data Category | Retention Period | Legal Basis/Justification |
|---|---|---|
| Account data (active users) | Duration of the contractual relationship | Art. 6(1)(b) GDPR |
| Profile and career data | Duration of the active account; upon deletion: 30 days | Art. 6(1)(b) GDPR |
| Uploaded documents | Duration of the active account; upon deletion: 30 days | Art. 6(1)(b) GDPR |
| Voice recordings | At Atlas Apply: max. 30 days after the session; transcripts as part of the profile | Art. 6(1)(a) GDPR (consent) |
| Voice data at ElevenLabs | Max. 30 days after the session, plus up to a further 30 days in ElevenLabs' backup copies | DPA arrangements |
| AI-generated documents | Duration of the active account; upon deletion: 30 days | Art. 6(1)(b) GDPR |
| AI log data (own infrastructure) | Max. 12 months; correspondingly longer where the record-keeping obligations of Regulation (EU) 2024/1689 become applicable | Art. 6(1)(f) GDPR (legitimate interest); Arts. 12, 19, 26(6) AI Act |
| Browser telemetry | Max. 13 months, then anonymization/deletion | Art. 6(1)(a) GDPR (consent) |
| Payment/invoice data | 7 years from the end of the calendar year | § 132 BAO, §§ 190–212 UGB |
| Data held by API processors | Anthropic: max. 30 days | DPA arrangements |
| Backups (AWS Frankfurt) | Max. 30 days on a rolling basis, then automatically overwritten | Art. 6(1)(f) GDPR (data security) |
| Inactive accounts | 24 months of inactivity → notification; then deletion after 30 days | Art. 6(1)(f) GDPR |
| Records of consent | 3 years after the end of processing | Art. 7(1) GDPR (accountability) |
| Data held by Stripe | Transaction data: duration of the business relationship plus 7 years (tax retention); tokenized card data: until revocation/account deletion | Art. 6(1)(b) GDPR (contract performance); § 132 BAO, §§ 190–212 UGB (retention obligations) |
| Data held by Mailgun | E-mail content: max. 7 days; delivery logs: max. 30 days; after account deletion: complete erasure within 90 days | DPA arrangements |
Defense of legal claims (GlBG): To the extent Atlas Apply processes data in connection with application processes, we retain relevant data for up to 7 months after the conclusion of an application process in order to be able to defend against potential discrimination claims under § 29(1) of the Austrian Equal Treatment Act (Gleichbehandlungsgesetz, GlBG) (legal basis: Art. 17(3)(e) GDPR).
Data export at end of contract: After termination of the contractual relationship, you may, within 30 days, request an export of your stored data and documents (see § 15(2) of the Terms). After this period has expired, your personal data will be deleted unless statutory retention obligations prevent this.
11. Your Rights as a Data Subject
You have the following rights under the GDPR, the DSG, and the AI Act:
GDPR rights
- Right of access (Art. 15 GDPR): you have the right to learn which personal data we process about you, including information on the origin of the data, its recipients, and the purpose of processing.
- Right to rectification (Art. 16 GDPR): inaccurate data will be corrected without undue delay upon your notice.
- Right to erasure (Art. 17 GDPR): you may request deletion of your data where the purpose of processing has ceased to apply, you have withdrawn your consent, or the processing was unlawful. Exceptions apply where statutory retention obligations exist. Upon deletion, all AI-generated derived data will also be deleted.
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR): you may receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR): you may object at any time to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3) GDPR): consent given may be withdrawn at any time with effect for the future.
Exercising your rights You may exercise all of the above rights by e-mail to [email protected] or by post to the address stated above. We respond within one month (extendable by a further two months for complex requests, pursuant to Art. 12(3) GDPR). Exercising your rights is free of charge.
Right to lodge a complaint with the supervisory authority You have the right to lodge a complaint with the Austrian Data Protection Authority (DSB): Austrian Data Protection Authority (Österreichische Datenschutzbehörde) Barichgasse 40-42 1030 Vienna, Austria Phone: +43 1 52 152-0 E-mail: [email protected] Web: https://www.dsb.gv.at
12. Age Restriction
Atlas Apply is intended exclusively for persons who have reached the age of 18 (see § 2(2) of the Terms). We do not knowingly process personal data of persons under the age of 18. Should we become aware that a person under 18 is using the Platform, we will delete the relevant data without undue delay.
13. Changes to This Privacy Policy
We review this Privacy Policy regularly and update it as necessary, in particular in response to changes in our processing activities, the legal situation, or regulatory requirements. We will inform you of material changes by e-mail or via the Platform. The current version is always available at https://atlas.now/privacy.
14. Contact
If you have questions about data protection, about exercising your rights, or about this Privacy Policy, please contact: Sprad Software GmbH Kaiserstraße 16 / 7-9 1070 Vienna, Austria E-mail: [email protected]