Legal

Privacy Policy

Effective August 25, 2026 · Atlas One by Heft IQ Inc.

Also see Terms of Service.

This Privacy Policy describes how Heft IQ Inc. (“HeftIQ,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information when you visit our websites, use Atlas One (the console, APIs, and MCP integrations), or otherwise interact with us. This Policy applies to personal information we process as a business (“we” or “us” as controller). Where we process personal information solely on behalf of a business customer, we act as a service provider/processor and process data according to our customer agreement and applicable law.

1. Scope and roles

Atlas One is a business-to-business service. Most personal information we handle relates to employees, contractors, or other individuals using the Service on behalf of an organization.

Controller vs. processor. When you create or administer an Atlas account, HeftIQ is generally the controller of account, authentication, billing, security, and operational data needed to run the Service. When we process names, email addresses, or similar User information solely because a Customer invited those individuals, we generally act as a processor on the Customer’s instructions.

This Policy does not apply to third-party websites, MCP hosts, or signal providers that have their own privacy practices.

2. Personal information we collect

Information you provide directly:

  • Account and profile data: name, email address, organization name, role, and authentication credentials managed through our identity provider.
  • Business context: company name, website, description, job function, goals, products, industries, locations, routes, markets, countries, and other Business Profile fields you submit or confirm.
  • Communications: support requests, feedback, and other messages you send us.
  • Billing contact and transaction details processed by our payment provider (we do not store full payment card numbers).

Information collected automatically:

  • Usage and technical data: API and MCP request metadata, timestamps, account and member identifiers, feature usage, IP address, browser type, device information, and diagnostic logs.
  • Security data: authentication events, abuse signals, and audit records for sensitive control-plane actions.
  • Cookies and similar technologies used for authentication and session management (see Section 12).

Information from other sources:

  • Public web pages and third-party research results when you request company discovery.
  • Your organization’s administrator when they invite you or assign roles.
  • Service providers that help us operate the Service.

We do not intentionally collect sensitive personal information (such as government identifiers, precise geolocation of individuals, or health data). Do not submit such information unless we have agreed in writing to process it.

3. How we use personal information

We use personal information to:

  • Provide, operate, maintain, and improve the Service.
  • Authenticate Users, manage accounts, invitations, and roles.
  • Personalize intelligence to confirmed Business Profile context.
  • Process payments, trials, subscriptions, and usage metering.
  • Monitor security, prevent fraud and abuse, and enforce our Terms.
  • Communicate about the Service, including transactional and service-related messages.
  • Comply with law and respond to lawful requests.
  • Create aggregated or de-identified data that does not identify individuals.

We do not sell personal information. We do not use personal information for cross-context behavioral advertising. We do not use Customer Content to train a shared foundation model offered to other customers. Processing Customer Content with automated systems to generate outputs for your account is part of providing the Service, not training a multi-tenant model for others.

5. How we disclose personal information

We disclose personal information to:

  • Service providers that process data on our instructions, including providers of authentication (Clerk), payments (Stripe), cloud hosting, background processing, company research, and language-model inference.
  • Signal and data providers that receive query parameters (such as locations, time windows, or trade-domain filters) needed to return external context.
  • MCP hosts you authorize (for example Claude or ChatGPT), which receive responses to requests made under your OAuth grant.
  • Professional advisers, auditors, and insurers under confidentiality obligations.
  • Law enforcement, regulators, or others when required by law or to protect rights, safety, and security.
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or notice to you.

A current list of subprocessors and security documentation is available in our Trust Center: https://app.vanta.com/heftiq.com/trust/rjikft09lfvrdep22wjzk.

6. International data transfers

HeftIQ is located in the United States. Personal information may be processed in the United States and other countries where we or our providers operate. Where required, we implement appropriate safeguards for cross-border transfers, including Standard Contractual Clauses or equivalent mechanisms with subprocessors.

7. Data retention

We retain personal information for as long as needed to provide the Service, fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type. Account and profile data are generally retained while the account is active and for a reasonable period afterward. Security and billing records may be retained longer where required. You may request deletion as described in Section 10.

8. Security

We implement administrative, technical, and organizational measures designed to protect personal information, including access controls, encryption in transit, tenant isolation in our application architecture, and auditing of sensitive actions. No security program is perfect. Report suspected vulnerabilities to security@heftiq.com.

9. Children’s privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.

10. Your privacy rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to receive a copy of personal information in a portable format. If your personal information is managed through a Customer account, contact your organization administrator first. You may also contact us at privacy@heftiq.com.

We will verify requests as required by law. We may decline requests that are unfounded, excessive, or prohibited by law.

Account settings and your organization’s admin tools may allow you to update certain information. You may revoke MCP connections from the Connections page. You may opt out of non-essential marketing emails by using the unsubscribe link in those messages.

11. California privacy rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, may provide additional rights regarding personal information we collect as a business.

Categories collected in the last 12 months may include identifiers (name, email, IP address), commercial information (subscription and usage records), internet or network activity (logs and API metadata), professional information (job function and business context you provide), and inferences drawn from the above to operate the Service.

We do not sell or share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit under CPRA.

California residents may request to know, delete, or correct personal information, and will not receive discriminatory treatment for exercising lawful privacy rights. Submit requests to privacy@heftiq.com. Authorized agents may submit requests with proof of authority as required by law.

12. Other U.S. state privacy laws

Residents of Colorado, Connecticut, Virginia, Utah, and other states with consumer privacy laws may have similar rights regarding access, correction, deletion, and opt-out of certain processing. Contact privacy@heftiq.com to exercise applicable rights. We will respond as required by applicable law.

13. EEA, UK, and Swiss rights

If you are in the EEA, UK, or Switzerland, you may lodge a complaint with your local supervisory authority. We encourage you to contact us first at privacy@heftiq.com so we can address your concern.

14. Cookies and similar technologies

We use cookies and similar technologies that are strictly necessary to operate the Service, including session and authentication cookies from our identity provider. Theme preference may be stored in your browser’s local storage. We do not use third-party advertising cookies on Atlas One today. If we introduce non-essential cookies, we will update this Policy and, where required, obtain consent.

16. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated Policy on this page and revise the effective date. Material changes will be communicated through the Service or by email where appropriate. Your continued use after the effective date constitutes acceptance of the updated Policy.

17. Contact us

Heft IQ Inc. 14607 Briar St, Leawood, Kansas 66224, United States Privacy inquiries: privacy@heftiq.com Security: security@heftiq.com General: hello@heftiq.com Website: https://heftiq.com

Privacy Policy · Atlas One