Atlassium
FeaturesPricingDocumentationContact
Menu
FeaturesPricingDocumentationContactClient area
Client area
Legal

Privacy policy

This Policy explains how Atlassium handles personal information when you visit our website, create an account, use the customer platform, contact us or purchase a subscription. It also explains the distinct treatment of survey and project content submitted by business customers.

Last updated: 30 August 2026
Atlassium does not sell personal information or Customer Content, and does not share personal information for cross-context behavioral advertising.
Contents1. Who we are and scope2. Information we collect3. Sources of information4. How and why we use information5. Legal bases6. How we disclose information7. Service providers and processing locations8. Cookies and browser choices9. Geospatial and Customer Content10. Retention and deletion11. Security12. International transfers13. Your privacy rights14. Children15. Automated processing16. Changes and contact

1. Who we are and scope

The controller for website visitor, account, support and direct commercial information is the Atlassium operating entity identified on your checkout, order form or invoice. If none is identified, the controller is the person or entity operating atlassium.io. Contact us at support@atlassium.io.

For imagery, geospatial files, project records and other Customer Content submitted by an organization, the organization ordinarily determines why and how the data is processed. Atlassium acts as its processor or service provider and handles that content on its documented instructions, including these Terms. Individuals should first direct Customer Content requests to the organization that controls the relevant project.

2. Information we collect

The information collected depends on how you interact with Atlassium.

  • Account and identity data: name, email, username, organization, role, locale, timezone, authentication records and invitation status.
  • Commercial and billing data: selected plan, billing email, subscription and transaction identifiers, invoice or receipt links, payment status, refunds, credits and usage. Atlassium does not receive full payment-card numbers from the merchant of record.
  • Customer Content: aerial imagery, image metadata, geolocation, ground-control files, site and project descriptions, processing parameters, previous-job references, generated maps, models, measurements, reports and other artifacts.
  • Technical and security data: IP address, browser and device information, request metadata, authentication attempts, security events, cookie choices, signed-transfer records and diagnostic errors.
  • Usage and operational data: pages or product functions used where analytics consent applies, job state, compute time, input and output size, storage use, project and membership actions, and audit records.
  • Communications: messages, attachments and information supplied when you contact support, sales, billing, privacy or security.

3. Sources of information

We receive information directly from you and authorized users; from organization administrators; automatically from browsers, applications, security controls and compute agents; from the merchant of record and other service providers; and from integrations you or an administrator configure. We may also receive business contact information from lawful public or professional sources when someone asks us to communicate with an organization.

4. How and why we use information

We use information only for the purposes below and compatible purposes permitted by law.

  • Provide accounts, projects, uploads, processing, reports, downloads, permissions and support.
  • Authenticate users, prevent abuse, investigate incidents and protect customers, systems and legal rights.
  • Schedule and recover compute jobs, measure plan usage, maintain backups and operate the service.
  • Administer trials, subscriptions, transactions, taxes, invoices, refunds and account notices.
  • Diagnose failures, monitor availability and improve reliability, usability and capacity.
  • Respond to communications and exercise or defend legal claims.
  • Comply with law, lawful process, sanctions, accounting and recordkeeping obligations.
  • Send product or marketing communications only where allowed; you can opt out of marketing without losing transactional notices.

5. Legal bases

Where the GDPR, UK GDPR or similar law applies, we rely on performance of a contract to provide accounts and Services; legitimate interests in security, support, product improvement, business administration and fraud prevention; consent for optional browser analytics or marketing where required; and legal obligation for tax, accounting, compliance and lawful requests. You may withdraw consent at any time without affecting earlier processing. Where we process Customer Content for a business customer, we rely on that customer’s instructions and legal basis.

6. How we disclose information

We disclose information only as needed for the Services, the purposes above or a lawful transaction.

  • Within a customer organization according to account and project roles. Organization owners and administrators can manage organization users, projects, subscription and content.
  • To infrastructure and service providers under contractual or equivalent duties, including cloud hosting, S3-compatible object storage, compute hosting, transactional email, security, error monitoring, operational logging, analytics and uptime monitoring.
  • To Paddle or another identified merchant of record for checkout, payment, tax, invoicing, fraud prevention, refunds and buyer support. The merchant of record also processes buyer information under its own privacy notice.
  • To professional advisers, auditors, insurers, financing sources and transaction counterparties subject to appropriate confidentiality where relevant.
  • To authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish and defend legal claims.
  • In a merger, financing, reorganization, sale or transfer of all or part of the business, subject to appropriate protections and notice where required.

7. Service providers and processing locations

The production stack may use Cloudflare for DNS, content delivery, DDoS protection and Turnstile; Paddle for merchant-of-record billing; Resend or another configured transactional email provider; Sentry for filtered actionable errors with user PII disabled by default; PostHog for consent-gated, sampled product analytics with input masking and session replay disabled by default; Grafana Cloud for warning-and-higher operational logs; UptimeRobot for external availability checks; and S3-compatible storage and rented compute infrastructure selected by Atlassium.

Photogrammetry and analytical components run on compute infrastructure controlled by Atlassium. Using an open-source processing component does not by itself transmit Customer Content to that component’s original developer. Provider selection and regions may change as we improve the service. We will use reasonable contractual, technical and transfer safeguards appropriate to the data and applicable law.

8. Cookies and browser choices

The customer platform uses necessary cookies or similar storage for authentication, security, language, account context and privacy choices. These are required for requested functionality. Optional product analytics or support widgets load only after the applicable consent choice where required by configuration and law.

PostHog analytics, when enabled, is sampled, capped per session, respects Do Not Track when configured, masks form inputs for any authorized replay setting, and can use an opaque user and account identifier. Session replay is disabled by default. You can reject optional integrations or reset privacy choices from the application footer. The static marketing site does not currently require optional analytics cookies.

9. Geospatial and Customer Content

Survey imagery and derived geospatial data can reveal location, property, infrastructure, people or activity. Business customers must determine whether their capture and intended use is lawful, provide required notices and avoid uploading unnecessary personal information.

Customer Content is scoped by account and project in the application and object keys. Authorized compute agents receive only the inputs for a leased job and return artifacts to the assigned project. Support or operations personnel may access content when necessary to investigate a request, secure the service, restore data or comply with law, subject to role and confidentiality controls.

10. Retention and deletion

We retain account, subscription, audit, usage and Customer Content for as long as needed to provide the account, meet the applicable plan or contract, resolve disputes and satisfy security, tax, accounting and legal obligations. Different records therefore have different retention periods.

A customer administrator may request deletion or account closure. After a valid request or the applicable post-termination export period, we delete or render Customer Content inaccessible from active systems on an operationally reasonable schedule unless retention is required by law or an unresolved dispute. Residual copies may remain in encrypted, rotating backups until the relevant backup cycles are overwritten and are not restored except for disaster recovery.

Short-lived uploads, security counters, sessions and compute workspaces expire or are cleaned according to operational settings. Durable job, billing and audit records may be retained longer where needed for account history, fraud prevention or legal claims. Support messages are retained while a request and related obligations remain relevant.

11. Security

We use safeguards designed to protect the nature of the data, including HTTPS, secure cookies, rate limiting and challenge verification, tenant- and project-scoped authorization, encrypted provider credentials, hashed compute tokens, signed object transfers, restricted worker services, audit records, encrypted database backups and monitored recovery processes.

No internet service can guarantee absolute security. Customers should use strong unique passwords, limit project access, protect exported files and notify us promptly of suspected compromise. Do not send credentials or full datasets by ordinary email.

12. International transfers

Atlassium and its providers may process information outside your country. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, contractual service-provider restrictions and supplementary technical measures. Business customers with specific residency requirements should contact us before uploading Customer Content.

13. Your privacy rights

Depending on location and context, you may have rights to access, correct, delete or obtain a copy of personal information; restrict or object to processing; withdraw consent; opt out of marketing; appeal a denied request; or complain to a supervisory authority. California residents may also have rights to know, correct and delete information and to opt out of sale or sharing. Atlassium does not sell personal information or share it for cross-context behavioral advertising.

Send a request to support@atlassium.io. We may verify identity and authority, ask you to work through the organization controlling a project, or retain information where an exception applies. Authorized agents must provide evidence of authority. We will not discriminate for exercising a protected right.

14. Children

The Services are intended for business users who are at least 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information without appropriate authorization.

15. Automated processing

The platform automatically assigns compatible compute jobs, applies plan limits and generates analytical outputs. These operations do not make legal or similarly significant decisions about individuals. Billing or abuse-prevention providers may use automated fraud controls under their own notices. Contact us if you believe an automated control has incorrectly affected account access.

16. Changes and contact

We may update this Policy as the service, providers or law changes. We will post the revised date and provide additional notice for material changes where required. Earlier versions may be retained for reference.

Questions, privacy requests and complaints can be sent to support@atlassium.io. If your request concerns Customer Content controlled by your employer, client or another organization, identify that organization and project so we can route the request appropriately.

AtlassiumAerial data, made useful.

Cloud photogrammetry and property intelligence for survey, construction, property and energy teams.

Product

FeaturesPricingDocumentation

Company

ContactSupportService availability

Legal

Terms of servicePrivacy policy
© 2026 Atlassium. All rights reserved.support@atlassium.io