Least-data account handling
RxAtlas describes entities, not people. Customer personal data is limited to account, authentication, payment, support, and usage records needed to operate the service.
security·procurement posture
RxAtlas publishes the basics vendor-risk teams ask for: data handling, sub-processors, DPA terms, retention, and download controls. Security questionnaires can be sent through the contact form.
RxAtlas describes entities, not people. Customer personal data is limited to account, authentication, payment, support, and usage records needed to operate the service.
Paid snapshot URLs are issued only after authentication and entitlement checks, expire after 1 hour, and can be regenerated from the portal. API tokens are stored as hashes, and traffic is served over HTTPS.
procurement pack
Review data rights, privacy terms, source licences, and the DPA before procurement.
Processor terms for account, authentication, API, and support data.
Personal-data categories, legal bases, sub-processors, transfers, and retention.
Per-source licence, attribution, and redistribution context.
How exported values retain source context for audit.
sub-processors
Payment providers and consent-gated analytics are described separately in the Privacy Policy and DPA where applicable.
| provider | role | data | regions |
|---|---|---|---|
| Vercel | Website & API hosting, CDN, and Blob storage for snapshot delivery | IP address, request logs, snapshot files | US, EU |
| Vercel Web Analytics | Cookieless aggregate audience measurement, plus consent-gated bounded custom events | Query-free page paths, origin-only referrers, coarse device/geo and a daily request-derived visitor hash; bounded custom events only after Analytics consent | US, EU |
| Vercel Speed Insights | Consent-gated real-user performance and Core Web Vitals measurement | Query-free page paths, route templates, device context and Core Web Vitals, only after Analytics consent | US, EU |
| Neon | Managed PostgreSQL database hosting (account data, hashed tokens, billing metadata) | Account email, hashed API tokens, billing metadata | US, EU |
| Upstash | Serverless Redis for API abuse prevention and anonymous rate limiting | Short-lived SHA-256-derived rate-limit keys and request counters; no raw client IP address | US |
| Resend | Magic-link / transactional email delivery for passwordless auth | Account email, message metadata | US |
| Google Workspace | Business email for support, security and corrections enquiries (data@, security@, corrections@ addresses) | Email message content and metadata for messages sent to our contact addresses | US, EU |
retention
Retention periods vary by purpose and legal obligation.
life of the account + 12 months after closure (reactivation, disputes, legal claims), then deleted or anonymised
7 years from the end of the financial year in which the transaction was recorded (Estonian Accounting Act § 12; Taxation Act § 58)
12 months, then deleted or aggregated into non-identifying statistics
24 months