Legal

DunningDoctor — Privacy Policy

Effective date: July 18, 2026

This Privacy Policy explains how The Atlas Project ("we," "us," "our") handles personal information in connection with DunningDoctor at https://dunningdoctor.the-atlas-project.net ("[PRODUCT_DOMAIN]"). It applies to the Service and our marketing site. It does not cover Third-Party Services you connect (such as Stripe), which have their own policies.


§P1. Who we are; controller/processor roles

DunningDoctor connects to your Stripe account to diagnose and (if you enable recovery) recover failed payments.

Controller / processor roles.

  • For your account and billing data, we act as controller.
  • For the data the Service processes on your instruction from your Connected Stripe Account — in particular your customers' payment records and contact detailsyou are the controller and we are your processor. Those roles, and our commitments as processor, are set out in the Data Processing Addendum (§P13-DPA) below and summarized in the Terms §22.

§P2. Categories of personal information we collect

CategoryExamplesSource
Account dataname, email, password/OAuth identity, workspace settingsyou, at signup (via Supabase auth)
Billing dataplan, billing email, partial card metadata, transaction history, performance-fee statementsyou and Stripe (we do not store full card numbers)
Usage & device datalog events, feature usage, IP address, timestamps, error logsautomatically, to run and secure the Service
Support datamessages you send us, correspondenceyou
Essential cookiesSupabase auth-session cookieyour browser session
Your customers' data (processed on your instruction)failed-invoice records, payment/decline metadata, and the email addresses/contact details the Service uses to send card-update and dunning emailsyour Connected Stripe Account, read on your instruction

We do not use analytics or advertising cookies/pixels, and we do not build advertising profiles. If this changes, we will update this Policy and, where required, obtain consent first.

We do not read or store full card numbers. Card data stays within Stripe.


§P3. How and why we use personal information (purposes)

  • Provide the Service — authenticate you; run the Leak Scan; compute leaked/recoverable figures, decline-code breakdowns, benchmark percentiles, and the recovered-vs-baseline ledger; and, if you enable recovery, retry failed charges and send card-update/dunning emails to your customers.
  • Billing — process subscriptions and compute and charge the performance fee (22% of Net Recovered Revenue, capped $199/mo) or flat plan, via Stripe.
  • Communicate — send you transactional and service messages (receipts, security and product notices) via Resend. Emails to *your customers* are sent on your behalf and for your relationship with them, not our marketing.
  • Secure and maintain — detect abuse, debug, protect the Service and its users.
  • Comply — meet legal obligations and enforce our Terms; retain records needed to substantiate performance-fee billing and handle disputes.
  • Improve — understand feature usage in aggregate, and publish k-anonymized, aggregated benchmark statistics (minimum cohort size enforced) that do not identify you or your customers. We do not use the content read from your Stripe account to train generalized AI models.

DunningDoctor's recovery engine is deterministic software — it does not use third-party AI models to process your data.


§P4. Legal bases (GDPR / UK GDPR)

Where GDPR/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); legitimate interests (to secure, maintain, and improve the Service, produce anonymized benchmarks, and send limited service communications), balanced against your rights; consent (where required, e.g., any future non-essential cookies or optional marketing); and legal obligation (e.g., tax/records). For the data we process about your customers (processor role), your instructions and the Data Processing Addendum govern; you are responsible for the legal basis as controller, including any basis required to contact your customers.


§P5. Subprocessors and third-party recipients

We use the following subprocessors and service providers for DunningDoctor:

SubprocessorFunction
VercelApplication hosting / edge delivery
SupabaseDatabase and authentication
StripePayment processing (our subscription and performance-fee billing) and, via Stripe Connect, the read-only scan and read-write recovery on your Connected Stripe Account
ResendDelivery of transactional/service email to you, and of the card-update and dunning emails sent to your customers on your behalf

DunningDoctor does not use analytics vendors, advertising networks, AI-model providers, or any subprocessor beyond those listed above. We enter data-processing terms with subprocessors where required and require appropriate safeguards. We will update this list and, where required, give notice before adding a subprocessor that materially changes processing of your data. We do not sell personal information and do not share it for cross-context behavioral advertising.


§P6. Cookies and similar technologies

We use essential cookies only — specifically, the Supabase authentication-session cookie needed to keep you signed in. We do not use analytics, advertising, or tracking cookies or pixels. Because we use only strictly-necessary cookies, we do not show a consent banner for non-essential cookies. If we ever introduce non-essential cookies, we will update this Policy and obtain consent where required.


§P7. Retention

We keep account and billing data for as long as your Account is active and as needed for legitimate business and legal purposes (e.g., tax records) after closure. Data read from your Connected Stripe Account is retained to provide recovery and to substantiate the recovered-vs-baseline ledger and performance-fee statements, and is deleted or de-identified on request or on termination, subject to residual backups purged on our ordinary cycle and records we must keep by law. Performance-fee measurement records (treated invoices, baseline/control comparison, fee computation) are retained as needed to substantiate billing and handle disputes.


§P8. Security

We use reasonable technical and organizational measures appropriate to the risk, including encryption in transit, access controls, least-privilege, and reliance on reputable infrastructure providers (Vercel, Supabase, Stripe). The recovery engine uses a least-privilege approach to Stripe scopes: a read-only scope for the free scan, and a read-write scope only after you enable recovery. No system is perfectly secure; we cannot guarantee absolute security. We will notify affected users and regulators of a personal-data breach where required by law.


§P9. Your privacy rights

§P9.1 GDPR / UK GDPR (EEA/UK residents). Subject to conditions, you may request access, rectification, erasure, restriction, portability, and objection, and may withdraw consent where processing is based on consent. You may lodge a complaint with your supervisory authority. Where we act as processor (your customers' data), we will route your request to, or assist, the relevant controller (our customer).

§P9.2 CCPA / CPRA (California residents). You have rights to know/access, delete, correct, and to opt out of "sale" or "sharing." We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for purposes requiring a right-to-limit. We will not discriminate against you for exercising rights. Authorized agents may submit requests with proof of authorization.

§P9.3 Your customers' data. DunningDoctor processes personal data about your customers (e.g., their email addresses and payment metadata) on your instruction. Where an individual customer exercises a privacy right regarding that data, the request is typically directed to you as controller; we assist you as processor and direct such end users to you.

§P9.4 How to exercise rights. Email admin@the-atlas-project.net (or admin@the-atlas-project.net) from your Account address, describing your request. We will verify your identity and respond within the time required by law. For content held on your behalf (processor role), we direct end users to you as the controller.


§P10. International data transfers

We are based in the United States, and our subprocessors may process data in the US and elsewhere. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum, or another lawful mechanism. By using the Service, you understand your information may be processed in the US.


§P11. Children

The Service is not directed to individuals under 18, and we do not knowingly collect their personal information (see Terms §16).


§P12. Changes to this Policy

We may update this Policy. We will post the new version with a revised effective date and, for material changes, provide additional notice (email or in-product). Continued use after the effective date constitutes acceptance where permitted by law.


§P13. Contact

Questions or requests: admin@the-atlas-project.net (privacy) or admin@the-atlas-project.net. Postal address: The Atlas Project, [MAILING_ADDRESS — to be added once the entity is formed].


§P13-DPA. Data Processing Addendum (processor-role data)

This Addendum governs the personal data the Service processes about your customers on your instruction ("Customer Personal Data") and forms part of the Terms.

1. Roles. For Customer Personal Data (e.g., your customers' email addresses, invoice and payment metadata read from your Connected Stripe Account), you are the controller and we are the processor (or, where you are yourself a processor, we are your sub-processor).

2. Instructions. We process Customer Personal Data only (a) to provide and secure the Service — that is, to diagnose failed payments and, where you enable recovery, to retry charges and send card-update/dunning emails to your customers; (b) per your documented instructions (including your configuration and the Stripe scopes you grant); and (c) as required by law (we will tell you unless legally barred).

3. Purpose limitation. We will not sell Customer Personal Data, use it for advertising, or use it to train generalized AI models. Benchmark statistics we publish are k-anonymized and aggregated and do not identify you or your customers.

4. Confidentiality. Personnel with access are bound by confidentiality. Human access to Customer Personal Data occurs only as needed for security or support.

5. Sub-processors. You authorize the subprocessors listed in §P5 (Vercel, Supabase, Stripe, Resend). We remain responsible for their performance and will give notice of material changes with a chance to object.

6. Security. We maintain the measures in §P8 appropriate to the risk, including least-privilege Stripe scopes.

7. Assistance. Taking into account the nature of processing, we will reasonably assist you with data-subject requests, security, breach notification, and DPIAs. We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.

8. Deletion/return. On termination or your request, we will delete or return Customer Personal Data, subject to residual backups purged on our ordinary cycle and legal-retention requirements (including records needed to substantiate performance-fee billing).

9. International transfers. Where applicable, the SCCs/UK Addendum referenced in §P10 apply to Customer Personal Data.

10. Audit. We will make available information reasonably necessary to demonstrate compliance and allow for reasonable, confidential audits on notice, subject to appropriate limits.



Last updated: July 18, 2026 · The Atlas Project · admin@the-atlas-project.net · admin@the-atlas-project.net

This document was prepared with automated assistance and has not been reviewed by an attorney. It is not legal advice.