Privacy policy

What we collect, why we hold it, and what you can ask us to do with it.

Last updated 1 September 2026

Note: this text is a structured draft and is pending legal review before launch. It is not yet a binding agreement.

1. Scope of this policy

This policy explains how KPI Atlas FZ-LLC collects and handles personal data when an agency uses our client reporting service, and when a visitor uses our website.

Where an agency connects a client's marketing accounts to KPI Atlas, the agency is the controller of that data and KPI Atlas acts as processor. Our processing obligations in that role are set out in the Data Processing Addendum.

2. Data we collect

Account data: the name, work email, agency name and billing details of the people who sign up.

Connected platform data: advertising, analytics and e-commerce metrics retrieved from sources the customer authorises. This is aggregate performance data and, where a source exposes them, campaign and creative identifiers.

Usage data: log records of feature use, report generation and delivery, retained to operate and secure the service.

Website data: pages viewed and referring source, collected in aggregate for measurement.

3. How we use data

To build, render and deliver the reports the customer configures; to authenticate users; to bill; to provide support; to detect abuse; and to notify customers of material changes to the service.

We do not sell personal data. We do not build cross-customer benchmarks. We do not use customer or connected platform data to train machine learning models.

5. Sharing and subprocessors

We share data with infrastructure, email delivery, error monitoring and payment subprocessors strictly as needed to run the service. A current subprocessor list is maintained and customers are notified before a new subprocessor is added.

We disclose data to authorities only where legally compelled, and we notify the customer unless prohibited by law.

6. International transfers

Data is processed in the region selected by the customer where available. Transfers outside that region rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.

7. Retention

Report and platform data is retained for the life of the account. On cancellation, an export window of 30 days applies, after which data is deleted from production systems and removed from backups on the standard backup cycle.

8. Your rights

Individuals may request access, correction, deletion, restriction, portability, and may object to certain processing. Requests relating to an agency's client data should be sent to that agency, and we will support them in responding.

9. Security

Encryption in transit and at rest, least-privilege internal access, audit logging of administrative actions, and periodic review of access and dependencies. Security incidents affecting personal data are notified without undue delay.

10. Contact

Privacy questions and requests: privacy@kpiatlas.com. Postal: KPI Atlas FZ-LLC, Office 214, Building 5, Dubai Media City, Dubai, United Arab Emirates.