> ## Documentation Index
> Fetch the complete documentation index at: https://platform.atlan.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Agent Registry Privacy Policy

> What personal data Agent Registry collects, why, and the rights you can exercise.

<Note>
  Last reviewed: September 8, 2026. This policy describes Agent Registry
  specifically. It sits alongside the [Atlan Privacy
  Notice](https://atlan.com/privacy-policy/), which governs Atlan's business
  activities generally; where this policy is silent, that notice applies.
</Note>

## 1. Introduction

This privacy policy explains how Atlan collects, accesses, stores, discloses, shares or otherwise uses your personal data in the course of providing Agent Registry ("Processing"), and how you can exercise your rights under applicable Data Protection Laws. It may be updated from time to time as our business needs and legal obligations change.

### Who we are

Atlan is a trading name of Atlan Pte Ltd and its affiliates, Atlan Inc. and Atlan Technologies Pvt Ltd (together, "Atlan", "we", "us", "our").

Our role depends on the data:

* **We are the controller** for data about you as a website visitor, a prospect, or an account holder — the data described in sections 3 and 4 below.
* **We are the processor** for the content your organization puts into Agent Registry — skills, agents, workspace artifacts, and execution traces. Your organization is the controller for that content, and our obligations are set out in the [Agent Registry Data Processing Agreement](/legal/data-processing-agreement).

### Who this applies to

This policy applies to visitors to platform.atlan.com, people in discussions with Atlan about Agent Registry, and authorized end users of organizations using Agent Registry.

## 2. Contact us

To exercise your data subject rights, or with any question about this policy:

**Singapore, India and Rest of the World (except EU and UK)**
Anjali Sheoran — [privacy@atlan.com](mailto:privacy@atlan.com)

**EU representative** (Article 27 GDPR)
Adam Brogden, INSTANT EU GDPR REPRESENTATIVE LTD
[contact@gdprlocal.com](mailto:contact@gdprlocal.com) · +353 15 549 700
Office 2, 12A Lower Main Street, Lucan Co. Dublin, K78 X5P8, Ireland

**UK representative** (Article 27 UK GDPR)
Adam Brogden, GDPR Local Ltd.
[contact@gdprlocal.com](mailto:contact@gdprlocal.com) · +44 1772 217800
1st Floor Front Suite, 27–29 North Street, Brighton, England

Security issues and suspected data incidents: [hello@atlan.com](mailto:hello@atlan.com).

## 3. Account and identity data

To give you access to Agent Registry we process:

| Data            | Examples                                                     |
| --------------- | ------------------------------------------------------------ |
| Identity data   | First and last name                                          |
| Contact data    | Email address                                                |
| Employment data | Job title, organization, role within that organization       |
| Technical data  | IP address, device and operating system, application version |

Authentication uses OAuth. Your durable session credential is never exposed to application JavaScript: in the web application it is an HttpOnly cookie, and in the desktop application the refresh token is held by the native layer in a file readable only by your own operating system user. Short-lived access tokens are held in memory only and are never written to browser storage.

## 4. Product usage and diagnostics

Agent Registry collects three separate streams. They are deliberately kept apart, and they carry different data.

### Product analytics

We record which features are used, so we can improve them. These events are identity-bearing: they are associated with your user id, name, email, roles, and organization. Analytics are collected by default whenever the application is used and are not individually toggleable in the application. Events are sent to Segment and forwarded to Mixpanel.

### Crash and reliability reporting

We record crashes and release health so a broken release is caught quickly. This stream is tied to an **opaque install identifier only** and carries no personal data. It is on by default and you can turn it off at any time in **Settings → Telemetry → Crash and reliability reporting**.

Network failures are reported as the origin and path of the failing request. We deliberately do **not** capture request or response headers, bodies, or query strings, so the diagnostic record cannot carry the contents of your work.

### Device diagnostics (desktop only)

The desktop application samples its own CPU and memory footprint once a minute into a buffer held **in memory** for at most 48 hours. Samples are numbers, process names and operating-system metadata only — never file contents, file paths, email addresses, or organization identifiers. Raw samples are never streamed off your device. Only three things leave the machine: a latched threshold breach, device-load context attached to a crash report, and an export you trigger yourself.

## 5. Content you put into Agent Registry

Skills, agents, workspace artifacts, files, and execution traces belong to your organization. Atlan processes them as a processor, under your organization's instructions and the [Agent Registry Data Processing Agreement](/legal/data-processing-agreement).

Execution traces can contain whatever your agents were working on. Treat them as you would any other production data, and configure what your agents emit accordingly.

**Credentials are write-only.** A secret you store in Agent Registry is encrypted on receipt and the application never reads it back — there is no reveal, no preview, and no masked value rendered in the interface. Secrets are not logged.

If you are an end user and want content about you corrected or removed, contact your own organization's administrator first: they control it, and we act on their instruction.

## 6. Lawful bases

| Purpose                                                                       | Data                           | Lawful basis                                            |
| ----------------------------------------------------------------------------- | ------------------------------ | ------------------------------------------------------- |
| Providing access to Agent Registry                                            | Identity, contact              | Performance of a contract; consent                      |
| Communicating with you about your use of the service and changes to our terms | Identity, contact              | Performance of a contract; legitimate interest; consent |
| Monitoring, maintaining, troubleshooting and improving the service            | Identity, contact, technical   | Performance of a contract; legitimate interest          |
| Detecting and preventing illegal or abusive activity                          | Identity, contact, technical   | Performance of a contract; legitimate interest          |
| Analysing behaviour and trends, statistical analysis                          | Contact, technical, engagement | Legitimate interest                                     |
| Internal administration, finance and operations                               | Identity, contact              | Performance of a contract; legitimate interest; consent |

If you are resident in the EEA or UK you may object at any time to processing we carry out on the basis of legitimate interests. See section 11.

We do not collect or process special categories of personal data, and we do not use automated decision-making that produces legal or similarly significant effects concerning you.

## 7. Sharing your personal data

We share personal data with:

* our group companies and affiliates;
* tax, government and regulatory authorities where required by law;
* service providers for IT and system administration, hosting, and product analytics;
* professional advisors such as legal counsel, bankers, auditors and insurers.

We require every third party to respect the security of your personal data, to treat it in accordance with the law, and to process it only for specified purposes on our instructions.

Sub-processors used to deliver Agent Registry are notified to controllers in advance under Clause IV of the Data Processing Agreement, with a fifteen-day window to object.

## 8. Security

We use a range of security technologies and procedures to protect personal data against unauthorized access, use or disclosure, including encryption in transit and at rest, least-privilege access controls, and tenant isolation on every data path. Secrets are held in an encrypted envelope and are never returned to the client. Further information is available on request for the purposes of performing a contract.

## 9. International transfers

Your personal data may be transferred internationally to our affiliates and service providers in order to provide Agent Registry. Transfers of personal data out of the EEA are governed by the Standard Contractual Clauses, incorporated by reference into the Data Processing Agreement. We require everyone we work with to keep your personal data confidential and secure under written contract.

## 10. Retention

Personal data is stored on Atlan's servers and on the servers of the cloud providers Atlan engages. We retain personal data for as long as it is needed for the purposes described above, to meet our legal or regulatory obligations, and for the exercise or defence of legal claims. After those needs are met we do not keep it longer than necessary.

Content your organization owns is returned or deleted on your organization's instruction or on termination, as set out in Clause V of the Data Processing Agreement.

## 11. Your rights

Where Atlan is the controller, you have the right to access your personal data, to have it rectified, to have it erased, to restrict its processing, to data portability, to object to processing based on legitimate interests or direct marketing, and to withdraw consent where consent is the basis for processing.

We aim to respond to data protection requests within 30 days. Requests are usually free; we reserve the right to charge for excessive or unfounded requests, and we may ask for information to confirm your identity. Where we cannot comply — because we must retain data to provide the service, meet a legal obligation, or defend a legal claim — we will tell you in writing within a reasonable time.

If you are not satisfied with how we handle a complaint, you may refer it to the supervisory authority in the member state where you reside. The [list of EU authorities is published by the European Commission](https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm).

## 12. EU–US Data Privacy Framework

Atlan complies with the EU–U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce, and has certified its adherence to the EU–U.S. DPF Principles for personal data received from the European Union. Where this policy conflicts with the DPF Principles, the DPF Principles govern. Our certification is viewable at [dataprivacyframework.gov](https://www.dataprivacyframework.gov/).

Atlan is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission, commits to cooperate with the panel established by the EU data protection authorities on unresolved complaints, and remains liable under the DPF Principles for onward transfers to agents acting on our behalf.

## 13. Cookies

platform.atlan.com uses cookies to analyse traffic and remember your preferences. Most browsers accept cookies automatically; you can change your browser settings to decline non-essential cookies, though this may limit parts of the site.

## 14. Children's data

Agent Registry is not directed to children and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at [privacy@atlan.com](mailto:privacy@atlan.com) and we will delete it.
