1. Who we are and scope
The controller for website visitor, account, support and direct commercial information is the Atlassium operating entity identified on your checkout, order form or invoice. If none is identified, the controller is the person or entity operating atlassium.io. Contact us at support@atlassium.io.
For imagery, geospatial files, project records and other Customer Content submitted by an organization, the organization ordinarily determines why and how the data is processed. Atlassium acts as its processor or service provider and handles that content on its documented instructions, including these Terms. Individuals should first direct Customer Content requests to the organization that controls the relevant project.
2. Information we collect
The information collected depends on how you interact with Atlassium.
- Account and identity data: name, email, username, organization, role, locale, timezone, authentication records and invitation status.
- Commercial and billing data: selected plan, billing email, subscription and transaction identifiers, invoice or receipt links, payment status, refunds, credits and usage. Atlassium does not receive full payment-card numbers from the merchant of record.
- Customer Content: aerial imagery, image metadata, geolocation, ground-control files, site and project descriptions, processing parameters, previous-job references, generated maps, models, measurements, reports and other artifacts.
- Technical and security data: IP address, browser and device information, request metadata, authentication attempts, security events, cookie choices, signed-transfer records and diagnostic errors.
- Usage and operational data: pages or product functions used where analytics consent applies, job state, compute time, input and output size, storage use, project and membership actions, and audit records.
- Communications: messages, attachments and information supplied when you contact support, sales, billing, privacy or security.
3. Sources of information
We receive information directly from you and authorized users; from organization administrators; automatically from browsers, applications, security controls and compute agents; from the merchant of record and other service providers; and from integrations you or an administrator configure. We may also receive business contact information from lawful public or professional sources when someone asks us to communicate with an organization.
4. How and why we use information
We use information only for the purposes below and compatible purposes permitted by law.
- Provide accounts, projects, uploads, processing, reports, downloads, permissions and support.
- Authenticate users, prevent abuse, investigate incidents and protect customers, systems and legal rights.
- Schedule and recover compute jobs, measure plan usage, maintain backups and operate the service.
- Administer trials, subscriptions, transactions, taxes, invoices, refunds and account notices.
- Diagnose failures, monitor availability and improve reliability, usability and capacity.
- Respond to communications and exercise or defend legal claims.
- Comply with law, lawful process, sanctions, accounting and recordkeeping obligations.
- Send product or marketing communications only where allowed; you can opt out of marketing without losing transactional notices.
5. Legal bases
Where the GDPR, UK GDPR or similar law applies, we rely on performance of a contract to provide accounts and Services; legitimate interests in security, support, product improvement, business administration and fraud prevention; consent for optional browser analytics or marketing where required; and legal obligation for tax, accounting, compliance and lawful requests. You may withdraw consent at any time without affecting earlier processing. Where we process Customer Content for a business customer, we rely on that customer’s instructions and legal basis.
7. Service providers and processing locations
The production stack may use Cloudflare for DNS, content delivery, DDoS protection and Turnstile; Paddle for merchant-of-record billing; Resend or another configured transactional email provider; Sentry for filtered actionable errors with user PII disabled by default; PostHog for consent-gated, sampled product analytics with input masking and session replay disabled by default; Grafana Cloud for warning-and-higher operational logs; UptimeRobot for external availability checks; and S3-compatible storage and rented compute infrastructure selected by Atlassium.
Photogrammetry and analytical components run on compute infrastructure controlled by Atlassium. Using an open-source processing component does not by itself transmit Customer Content to that component’s original developer. Provider selection and regions may change as we improve the service. We will use reasonable contractual, technical and transfer safeguards appropriate to the data and applicable law.
9. Geospatial and Customer Content
Survey imagery and derived geospatial data can reveal location, property, infrastructure, people or activity. Business customers must determine whether their capture and intended use is lawful, provide required notices and avoid uploading unnecessary personal information.
Customer Content is scoped by account and project in the application and object keys. Authorized compute agents receive only the inputs for a leased job and return artifacts to the assigned project. Support or operations personnel may access content when necessary to investigate a request, secure the service, restore data or comply with law, subject to role and confidentiality controls.
10. Retention and deletion
We retain account, subscription, audit, usage and Customer Content for as long as needed to provide the account, meet the applicable plan or contract, resolve disputes and satisfy security, tax, accounting and legal obligations. Different records therefore have different retention periods.
A customer administrator may request deletion or account closure. After a valid request or the applicable post-termination export period, we delete or render Customer Content inaccessible from active systems on an operationally reasonable schedule unless retention is required by law or an unresolved dispute. Residual copies may remain in encrypted, rotating backups until the relevant backup cycles are overwritten and are not restored except for disaster recovery.
Short-lived uploads, security counters, sessions and compute workspaces expire or are cleaned according to operational settings. Durable job, billing and audit records may be retained longer where needed for account history, fraud prevention or legal claims. Support messages are retained while a request and related obligations remain relevant.
11. Security
We use safeguards designed to protect the nature of the data, including HTTPS, secure cookies, rate limiting and challenge verification, tenant- and project-scoped authorization, encrypted provider credentials, hashed compute tokens, signed object transfers, restricted worker services, audit records, encrypted database backups and monitored recovery processes.
No internet service can guarantee absolute security. Customers should use strong unique passwords, limit project access, protect exported files and notify us promptly of suspected compromise. Do not send credentials or full datasets by ordinary email.
12. International transfers
Atlassium and its providers may process information outside your country. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, contractual service-provider restrictions and supplementary technical measures. Business customers with specific residency requirements should contact us before uploading Customer Content.
13. Your privacy rights
Depending on location and context, you may have rights to access, correct, delete or obtain a copy of personal information; restrict or object to processing; withdraw consent; opt out of marketing; appeal a denied request; or complain to a supervisory authority. California residents may also have rights to know, correct and delete information and to opt out of sale or sharing. Atlassium does not sell personal information or share it for cross-context behavioral advertising.
Send a request to support@atlassium.io. We may verify identity and authority, ask you to work through the organization controlling a project, or retain information where an exception applies. Authorized agents must provide evidence of authority. We will not discriminate for exercising a protected right.
14. Children
The Services are intended for business users who are at least 18. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information without appropriate authorization.
15. Automated processing
The platform automatically assigns compatible compute jobs, applies plan limits and generates analytical outputs. These operations do not make legal or similarly significant decisions about individuals. Billing or abuse-prevention providers may use automated fraud controls under their own notices. Contact us if you believe an automated control has incorrectly affected account access.
16. Changes and contact
We may update this Policy as the service, providers or law changes. We will post the revised date and provide additional notice for material changes where required. Earlier versions may be retained for reference.
Questions, privacy requests and complaints can be sent to support@atlassium.io. If your request concerns Customer Content controlled by your employer, client or another organization, identify that organization and project so we can route the request appropriately.