latest update:
[RxAtlas]

security·procurement posture

Security and data handling

RxAtlas publishes the basics vendor-risk teams ask for: data handling, sub-processors, DPA terms, retention, and download controls. Security questionnaires can be sent through the contact form.

Least-data account handling

RxAtlas describes entities, not people. Customer personal data is limited to account, authentication, payment, support, and usage records needed to operate the service.

Short-lived, audited downloads

Paid snapshot URLs are issued only after authentication and entitlement checks, expire after 1 hour, and can be regenerated from the portal. API tokens are stored as hashes, and traffic is served over HTTPS.

sub-processors

Service providers involved in operating the product.

Payment providers and consent-gated analytics are described separately in the Privacy Policy and DPA where applicable.

providerroledataregions
VercelWebsite & API hosting, CDN, and Blob storage for snapshot deliveryIP address, request logs, snapshot filesUS, EU
Vercel Web AnalyticsCookieless aggregate audience measurement, plus consent-gated bounded custom eventsQuery-free page paths, origin-only referrers, coarse device/geo and a daily request-derived visitor hash; bounded custom events only after Analytics consentUS, EU
Vercel Speed InsightsConsent-gated real-user performance and Core Web Vitals measurementQuery-free page paths, route templates, device context and Core Web Vitals, only after Analytics consentUS, EU
NeonManaged PostgreSQL database hosting (account data, hashed tokens, billing metadata)Account email, hashed API tokens, billing metadataUS, EU
UpstashServerless Redis for API abuse prevention and anonymous rate limitingShort-lived SHA-256-derived rate-limit keys and request counters; no raw client IP addressUS
ResendMagic-link / transactional email delivery for passwordless authAccount email, message metadataUS
Google WorkspaceBusiness email for support, security and corrections enquiries (data@, security@, corrections@ addresses)Email message content and metadata for messages sent to our contact addressesUS, EU

retention

How long account and service data is retained.

Retention periods vary by purpose and legal obligation.

retention schedule

  • Account data (email, hashed tokens, settings)

    life of the account + 12 months after closure (reactivation, disputes, legal claims), then deleted or anonymised

  • Invoices, payments & accounting records

    7 years from the end of the financial year in which the transaction was recorded (Estonian Accounting Act § 12; Taxation Act § 58)

  • Security, request & usage logs (incl. IP)

    12 months, then deleted or aggregated into non-identifying statistics

  • Support correspondence

    24 months