Last reviewed: September 8, 2026. This policy describes Agent Registry
specifically. It sits alongside the Atlan Privacy
Notice, which governs Atlan’s business
activities generally; where this policy is silent, that notice applies.
1. Introduction
This privacy policy explains how Atlan collects, accesses, stores, discloses, shares or otherwise uses your personal data in the course of providing Agent Registry (“Processing”), and how you can exercise your rights under applicable Data Protection Laws. It may be updated from time to time as our business needs and legal obligations change.Who we are
Atlan is a trading name of Atlan Pte Ltd and its affiliates, Atlan Inc. and Atlan Technologies Pvt Ltd (together, “Atlan”, “we”, “us”, “our”). Our role depends on the data:- We are the controller for data about you as a website visitor, a prospect, or an account holder — the data described in sections 3 and 4 below.
- We are the processor for the content your organization puts into Agent Registry — skills, agents, workspace artifacts, and execution traces. Your organization is the controller for that content, and our obligations are set out in the Agent Registry Data Processing Agreement.
Who this applies to
This policy applies to visitors to platform.atlan.com, people in discussions with Atlan about Agent Registry, and authorized end users of organizations using Agent Registry.2. Contact us
To exercise your data subject rights, or with any question about this policy: Singapore, India and Rest of the World (except EU and UK) Anjali Sheoran — privacy@atlan.com EU representative (Article 27 GDPR) Adam Brogden, INSTANT EU GDPR REPRESENTATIVE LTD contact@gdprlocal.com · +353 15 549 700 Office 2, 12A Lower Main Street, Lucan Co. Dublin, K78 X5P8, Ireland UK representative (Article 27 UK GDPR) Adam Brogden, GDPR Local Ltd. contact@gdprlocal.com · +44 1772 217800 1st Floor Front Suite, 27–29 North Street, Brighton, England Security issues and suspected data incidents: hello@atlan.com.3. Account and identity data
To give you access to Agent Registry we process:
Authentication uses OAuth. Your durable session credential is never exposed to application JavaScript: in the web application it is an HttpOnly cookie, and in the desktop application the refresh token is held by the native layer in a file readable only by your own operating system user. Short-lived access tokens are held in memory only and are never written to browser storage.
4. Product usage and diagnostics
Agent Registry collects three separate streams. They are deliberately kept apart, and they carry different data.Product analytics
We record which features are used, so we can improve them. These events are identity-bearing: they are associated with your user id, name, email, roles, and organization. Analytics are collected by default whenever the application is used and are not individually toggleable in the application. Events are sent to Segment and forwarded to Mixpanel.Crash and reliability reporting
We record crashes and release health so a broken release is caught quickly. This stream is tied to an opaque install identifier only and carries no personal data. It is on by default and you can turn it off at any time in Settings → Telemetry → Crash and reliability reporting. Network failures are reported as the origin and path of the failing request. We deliberately do not capture request or response headers, bodies, or query strings, so the diagnostic record cannot carry the contents of your work.Device diagnostics (desktop only)
The desktop application samples its own CPU and memory footprint once a minute into a buffer held in memory for at most 48 hours. Samples are numbers, process names and operating-system metadata only — never file contents, file paths, email addresses, or organization identifiers. Raw samples are never streamed off your device. Only three things leave the machine: a latched threshold breach, device-load context attached to a crash report, and an export you trigger yourself.5. Content you put into Agent Registry
Skills, agents, workspace artifacts, files, and execution traces belong to your organization. Atlan processes them as a processor, under your organization’s instructions and the Agent Registry Data Processing Agreement. Execution traces can contain whatever your agents were working on. Treat them as you would any other production data, and configure what your agents emit accordingly. Credentials are write-only. A secret you store in Agent Registry is encrypted on receipt and the application never reads it back — there is no reveal, no preview, and no masked value rendered in the interface. Secrets are not logged. If you are an end user and want content about you corrected or removed, contact your own organization’s administrator first: they control it, and we act on their instruction.6. Lawful bases
If you are resident in the EEA or UK you may object at any time to processing we carry out on the basis of legitimate interests. See section 11.
We do not collect or process special categories of personal data, and we do not use automated decision-making that produces legal or similarly significant effects concerning you.
7. Sharing your personal data
We share personal data with:- our group companies and affiliates;
- tax, government and regulatory authorities where required by law;
- service providers for IT and system administration, hosting, and product analytics;
- professional advisors such as legal counsel, bankers, auditors and insurers.