Atlantic Atlantic
  • How It Works
  • Roles
  • Pricing
  • Blog
Sign In Deploy Free
How It Works Roles Pricing Blog Sign In Deploy Free

Privacy Policy

Last updated: April 10, 2026

1. Who We Are and What This Policy Covers

Atlantic, Inc. ("the Company," "we," "us," or "our") operates getatiantic.com and the Atlantic AI agent operating system (together, the "Service"). Atlantic is a B2B software platform that lets growing companies deploy role-based AI agents into their operations, finance, and sales workflows. We give each company role a defined AI agent with a configured action scope, a set of connected integrations, and a clear escalation path to a human.

This Privacy Policy explains what information we collect through the Service and through direct communications with you, how we use it, and the choices available to you. It applies to visitors to our marketing website and to users of the Atlantic platform.

The Company is headquartered at 1035 Folsom Street, Suite 300, San Francisco, CA 94103, and can be reached at [email protected].

2. Information We Collect

2.1 Information You Provide

We collect information you submit directly, including:

  • Account registration details: your name, work email address, job title, and company name;
  • Billing and payment information (processed through our payment provider; the Company does not store raw card numbers);
  • Role configuration settings you create inside the Atlantic platform, including the names, action scopes, trigger conditions, and escalation rules you define for deployed agents;
  • Contact form submissions, support requests, and direct email correspondence.

2.2 Information Collected Automatically

When you visit getatiantic.com or use the Atlantic platform, we automatically collect:

  • IP address and approximate location (city and region level only);
  • Browser type, operating system, and device class;
  • Pages visited, navigation paths, session duration, and referring URLs;
  • Platform usage telemetry: which roles are deployed, action log summaries (task counts, success and failure rates, escalation events), integration connection status, and API call latency metrics;
  • Error events and agent execution diagnostics used for reliability monitoring and debugging.

2.3 Customer Workload Data

The Atlantic platform executes tasks on your behalf through integrations with tools you choose to connect, such as Slack, HubSpot, Google Workspace, QuickBooks, and others. Data flowing through those integrations as part of agent execution (for example, email threads reviewed by an Operations Agent, CRM contact records updated by an SDR Agent, or vendor invoices processed by a Finance Agent) is customer workload data. The Company processes this data as a service provider acting on your instructions and does not collect it for its own commercial purposes. Customer workload data is governed by our customer agreements and is not covered by this Policy's sections on the Company's own information practices.

2.4 We Do Not Knowingly Collect Children's Data

The Service is directed at business users and is not intended for children under 13. We do not knowingly collect personal information from children. If you believe a child has provided information to us, contact [email protected] and we will delete it promptly.

3. How We Use Information

We use the information we collect to:

  • Provision and operate the Atlantic platform, including authenticating accounts, processing agent role deployments, and delivering the monitoring dashboard where you see every action your agents take;
  • Generate action logs, execution metrics, and escalation event records that appear in your Atlantic account;
  • Route authenticated API calls to model providers (AI API services that power agent intelligence) and to the integration platforms your agents use;
  • Process payments and manage your subscription, including plan upgrades, downgrades, and billing notifications;
  • Send transactional communications (account alerts, escalation notifications, action-limit warnings, billing receipts) and, with your consent where required, product update and marketing emails;
  • Diagnose errors, detect abuse, and improve the reliability, performance, and safety of agent execution;
  • Comply with legal obligations.

We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.

4. Sharing of Information

We share personal information only with:

  • Infrastructure and hosting providers who store and serve the Atlantic platform under contractual confidentiality and data-processing agreements;
  • Model providers (AI API services that provide the language model intelligence for agent task execution): the Company routes instrumented API calls to these providers as part of operating the platform; model providers are bound by their own data-processing terms and our written agreements with them;
  • Integration platforms you connect (Slack, HubSpot, Google Workspace, QuickBooks, and others): data exchanged with these platforms is scoped to what your configured agent role requires to complete its defined tasks;
  • Payment processor for billing and subscription management;
  • Legal authorities, when required by law or to protect rights, safety, or property;
  • A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy and applicable law.

We do not sell personal information to third parties.

5. Cookies and Tracking

We use cookies and similar technologies to operate the site, maintain authenticated sessions, and measure usage. For details and your choices, see our Cookie Policy.

6. Data Retention

Account data is retained while your account is active and for 30 days following account deletion, after which it is permanently purged. Agent execution logs are retained for 90 days by default; platform customers may configure a shorter retention window in account settings. Website analytics data is aggregated and retained for up to 13 months. Billing records are kept for 7 years to satisfy tax and accounting obligations. Support correspondence is retained for 3 years from the date of last interaction.

7. Security

The Company applies administrative, technical, and physical safeguards to protect personal information, including TLS encryption in transit, access-controlled databases with least-privilege permissions, environment separation between customer tenants, and encrypted storage of integration credentials (OAuth tokens) at rest. No security system is perfectly reliable; we cannot guarantee absolute security, and we encourage you to use strong passwords and keep your API credentials private.

8. Your General Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal information. To make a request, email [email protected]. The Company will respond within the timeframe required by applicable law.

9. California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of the Policy.

9.1 Categories We Collect

In the past 12 months, we have collected the following categories of personal information as defined under Cal. Civ. Code §1798.140: identifiers (name, work email address, IP address, account login credentials); professional and employment information (job title, company name, estimated team size provided during onboarding); commercial information (subscription tier, payment records, billing history); usage data and inferences (agent action logs, tool-call telemetry, escalation event records, integration connection status, platform performance metrics); and internet or network activity (browsing behavior on getatiantic.com). The Company does not collect sensitive personal information, as defined under Cal. Civ. Code §1798.140(ae), for its own commercial purposes. Customer workload data that flows through agent integrations (which may include email content or CRM records) is processed solely as a service provider acting on customer instructions and falls outside this section.

9.2 Sources, Purposes, Disclosure

We obtain this information from you directly (account registration, contact forms, support communications), through automatic platform instrumentation, and through your use of integrated third-party tools. We use it to operate the Atlantic platform, deliver agent execution services, communicate with you, process payments, and meet legal obligations. We disclose it only to the categories of service providers described in Section 4 (infrastructure, model providers, integration platforms, payment processor) under written contracts, and to legal authorities where required.

9.3 Your CCPA / CPRA Rights

  • Right to Know: request the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell personal information; we do not "share" it for cross-context behavioral advertising as defined under CPRA.
  • Right to Limit Use of Sensitive PI: we do not use sensitive personal information for purposes beyond those permitted without authorization.
  • Right to Non-Discrimination: we will not deny services, charge different prices, or provide a different level of service because you exercised a right.

9.4 How to Exercise

Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for us to verify you are the person whose information is the subject of the request. We respond within 45 days, with a possible 45-day extension for which we will notify you.

9.5 Authorized Agents

You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; we may also require you to verify your identity directly.

9.6 "Shine the Light"

California Civil Code §1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.

9.7 Do Not Track and Global Privacy Control

Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.

11. Contact

Questions, requests, or complaints about this Policy can be sent to:

Atlantic, Inc.
1035 Folsom Street, Suite 300, San Francisco, CA 94103
Email: [email protected]
Phone: +1 (415) 553-1182
Atlantic

The agent OS for your company.

Platform

  • How It Works
  • Roles
  • Pricing
  • What's New

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Atlantic, Inc. · 1035 Folsom Street, Suite 300, San Francisco, CA 94103

Privacy Terms Cookie preferences