Privacy policy
What we collect, why we hold it, and what you can ask us to do with it.
Last updated 1 September 2026
Note: this text is a structured draft and is pending legal review before launch. It is not yet a binding agreement.
1. Scope of this policy
This policy explains how KPI Atlas FZ-LLC collects and handles personal data when an agency uses our client reporting service, and when a visitor uses our website.
Where an agency connects a client's marketing accounts to KPI Atlas, the agency is the controller of that data and KPI Atlas acts as processor. Our processing obligations in that role are set out in the Data Processing Addendum.
2. Data we collect
Account data: the name, work email, agency name and billing details of the people who sign up.
Connected platform data: advertising, analytics and e-commerce metrics retrieved from sources the customer authorises. This is aggregate performance data and, where a source exposes them, campaign and creative identifiers.
Usage data: log records of feature use, report generation and delivery, retained to operate and secure the service.
Website data: pages viewed and referring source, collected in aggregate for measurement.
3. How we use data
To build, render and deliver the reports the customer configures; to authenticate users; to bill; to provide support; to detect abuse; and to notify customers of material changes to the service.
We do not sell personal data. We do not build cross-customer benchmarks. We do not use customer or connected platform data to train machine learning models.
4. Legal bases
Performance of a contract, for account and service data. Legitimate interests, for security, abuse prevention and service measurement. Consent, where required for marketing communications, withdrawable at any time.
6. International transfers
Data is processed in the region selected by the customer where available. Transfers outside that region rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.
7. Retention
Report and platform data is retained for the life of the account. On cancellation, an export window of 30 days applies, after which data is deleted from production systems and removed from backups on the standard backup cycle.
8. Your rights
Individuals may request access, correction, deletion, restriction, portability, and may object to certain processing. Requests relating to an agency's client data should be sent to that agency, and we will support them in responding.
9. Security
Encryption in transit and at rest, least-privilege internal access, audit logging of administrative actions, and periodic review of access and dependencies. Security incidents affecting personal data are notified without undue delay.
10. Contact
Privacy questions and requests: privacy@kpiatlas.com. Postal: KPI Atlas FZ-LLC, Office 214, Building 5, Dubai Media City, Dubai, United Arab Emirates.