1.Who we are
ASIA (Automated Sales Intelligence & Acquisition) is a software platform operated by Atlantia ("ASIA", "we", "us"). It lets a business create AI sales avatars that run outreach campaigns to that business's own prospects across email, LinkedIn, WhatsApp, Telegram and automated voice calls, and that keep the resulting conversations, contacts and deals in a built-in CRM.
Postal address: Av. Paseo de la Reforma 296, Cuauhtémoc, 06600 Mexico City, Mexico.
Privacy contact: privacy@atlantia.ai
Deletion requests: privacy@atlantia.ai — see the dedicated Data Deletion page for step-by-step instructions.
This policy is ours. It describes this platform and no other, and it applies to the ASIA web application at asia.atlantia.ai and to the background services that send and receive messages on our customers' behalf.
2.Our two roles: controller and processor
ASIA handles two very different kinds of personal data, and our legal role is different for each. Reading this section first will make the rest of the document make sense.
We are the controller of our own users' data
When someone signs up, logs in, configures a workspace or is billed, we decide why and how that data is processed. That covers account details, authentication, access and activity logs, support exchanges, and subscription and billing records. If you are an ASIA user, this policy is the one that governs your data, and you can bring your requests directly to us.
We are a processor for the prospect data our customers load
Everything a customer imports, captures or generates about the people they want to sell to — contacts, companies, deals, notes, and the content of the messages exchanged with them — is processed by us on that customer's instructions. The customer decides who gets contacted, on which channel and with what message; the customer is the controller and is responsible for having a lawful basis to make contact. We process that data only to provide the platform.
3.What data we collect
a. Data you give us as a user
- Identity and contact: name, work email address, company, job role, preferred language.
- Credentials for the channels you connect: OAuth tokens for Gmail or Microsoft 365 mailboxes and calendars, WhatsApp Business access tokens, LinkedIn session credentials, CRM API keys and OAuth tokens. These are stored encrypted (see Security).
- Content you create: products, campaign scripts, message templates, avatar personas, documents you upload.
- Voice samples, if you use voice cloning: a recording you upload so an avatar can speak in that voice (see Voice calls).
- Billing and subscription data for paid plans.
b. Data collected automatically when you use ASIA
- Authentication events, IP address and browser user-agent at sign-in.
- Audit and activity logs: which user did what, to which record, and when.
- Service logs and error traces produced by our servers.
- Usage counters we need to enforce plan limits and channel rate limits.
c. Prospect data our customers load or generate
- Contact details: name, work email, phone number, job title, employer, LinkedIn profile URL, plus any custom fields the customer defines.
- Message content across every channel we support: emails sent and received, LinkedIn messages and invitations, WhatsApp and Telegram messages, and voice-call recordings, transcripts and summaries.
- Engagement signals: delivery, bounce and reply status, and — where the customer enables open and click tracking on outreach email — the recipient's IP address and user-agent at the moment the email is opened or a link is clicked.
- CRM records built on top of that: companies, deals, notes, tasks, tickets, orders and timeline events.
d. Data from third parties
- Connected mailboxes. With the user's OAuth consent we read messages from the connected mailbox in order to match replies to campaigns and populate the shared inbox.
- Connected CRMs. When a customer connects HubSpot, Zoho, Pipedrive, monday, Odoo or Salesforce, we import the contact, company and deal records they choose to sync.
- Enrichment and research. Apollo.io supplies professional contact data for prospect discovery; Tavily supplies public web results used to research a company before writing to it.
- Messaging platforms. Data that reaches us from Meta, LinkedIn and the telephony network — covered in section 5.
4.Why we use it, and our legal basis
Where the GDPR or a comparable law applies, these are the purposes and the basis we rely on (Art. 6 GDPR). For prospect data we act on our customer's instructions, so the basis for contacting a prospect is the customer's to establish, not ours.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the platform to a customer: campaigns, CRM, inbox, analytics | User data, prospect data | Performance of the contract with the customer (Art. 6(1)(b)); for prospect data, processing on the controller’s instructions (Art. 28) |
| Sending and receiving messages on the connected channels | Channel credentials, message content, delivery metadata | Performance of the contract (Art. 6(1)(b)) |
| Generating and adapting message copy and call scripts with AI | Campaign context, product data, prospect record, conversation history | Performance of the contract (Art. 6(1)(b)) |
| Security, abuse prevention, audit logging and incident investigation | Access logs, IP, user-agent, audit trail | Legitimate interest in keeping the service secure (Art. 6(1)(f)) |
| Billing, accounting and tax records | Account and subscription data | Contract and legal obligation (Art. 6(1)(b) and (c)) |
| Service notices and support | Account contact details | Performance of the contract (Art. 6(1)(b)) |
| Voice cloning of a voice you record and upload | The voice sample you provide | Your consent (Art. 6(1)(a)), withdrawable at any time by deleting the cloned voice |
5.Data from Meta and other connected platforms
Meta / WhatsApp Business Platform
When a customer connects their WhatsApp Business account, we receive from Meta and store: the WhatsApp Business Account and phone-number identifiers, the display name and quality rating of the number, the message templates registered on it, access tokens issued to us for that account, inbound messages sent to that number (including the sender's phone number and WhatsApp profile name), and delivery and read status for messages we send.
We use that data for one thing only: to operate the WhatsApp channel the customer asked us to operate — sending the messages they schedule, receiving replies into their inbox, syncing their templates, and reporting delivery. We do not use data received from Meta for advertising, we do not sell it, we do not combine it across customers, and we do not use it to train AI models.
Access tokens are stored encrypted and are deleted when the customer disconnects the channel or closes the account. WhatsApp message content is stored as part of the customer's conversation history and is deleted with it — see section 10 and the Data Deletion page. A deletion request covering data received from Meta is handled through exactly the same route as any other request.
Google user data (Gmail and Google Calendar)
When a user connects a Gmail mailbox we request the scopes needed to send mail, read mail and manage message labels, plus calendar access for meeting scheduling. ASIA's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide the outreach and shared-inbox features the user connected the mailbox for; we do not transfer it to others except as needed to provide those features, and we do not use it for advertising or to train generalised AI models.
Microsoft 365, LinkedIn and telephony
- Microsoft 365: mail send/read/write and read-only calendar access, used for the same outreach and inbox features as Gmail.
- LinkedIn: connected through Unipile. We receive the connected account's profile, its conversations and invitation status, and the public profile data of the people the customer targets.
- Telephony: the numbers dialled and received, call duration and outcome, and the audio of the call where recording is in use.
6.Processing with artificial intelligence
ASIA uses large language models to do the work the product exists for: research a prospect, draft and translate outreach copy, decide which channel and moment to use, read an incoming reply and classify its intent, summarise a conversation, and drive the dialogue of an automated voice call.
What is sent to a model. The prompt typically contains the campaign brief and the customer's product information, the prospect's CRM record, and the message history of that conversation. Our primary provider is Google Vertex AI (Gemini); OpenAI is used as a fallback and for specific features.
Training. ASIA does not train, fine-tune or improve any general-purpose AI model with customer or prospect data, and we do not license that data to anyone for model training. The one case where content you provide is used to build a model is voice cloning, which happens only for the voice sample you deliberately upload, only in the provider account we operate, and only to produce a voice your own avatars use — described in the next section.
Human oversight. AI output is generated text. It can be wrong. Campaigns can be configured so a person approves messages before they go out, and the customer remains responsible for what is sent under their name.
7.Voice calls: recording and transcription
For each call we store the number dialled, the time and duration, the call outcome, the full turn-by-turn transcript, an AI-generated summary of it, and the call audio, which is kept in Google Cloud Storage in a private bucket and served only to authorised users of the owning workspace.
Consent is the caller's responsibility. Recording a call without the required notice or consent is unlawful in many countries and in several US states. The customer running the campaign decides who is called and what the agent says, and is responsible for giving whatever notice the law of the recipient's location requires. Our Terms of Service require it.
Voice cloning. If you upload a recording of a voice so an avatar can speak with it, that recording is sent to the cloning provider (ElevenLabs or Fish Audio) and used to create a synthetic voice tied to your workspace. Only upload a voice you are the owner of, or have written permission to clone.
Recordings, transcripts and summaries are deleted when the workspace or the call record is deleted; see section 10 for what that means in practice today.
8.Subprocessors
We use the providers below to run the platform. Every one of them is bound to process data only on our instructions. Providers that appear only when a customer chooses to connect them are marked as optional.
| Provider | Purpose | Primary location |
|---|---|---|
| Google Cloud Platform | Hosting, database, file and recording storage, secret management | United States (us-central1) |
| Google Cloud — Vertex AI (Gemini) | Message generation, reply classification, conversation intelligence | United States |
| OpenAI | Fallback and feature-specific language model | United States |
| SendGrid (Twilio) | Outbound email delivery and inbound mail routing | United States |
| Google (Gmail API) | Sending and reading mail from a connected Google mailbox — optional | United States |
| Microsoft (Graph API) | Sending and reading mail from a connected Microsoft 365 mailbox — optional | United States / EU |
| Meta Platforms (WhatsApp Business Platform) | WhatsApp message delivery, templates and webhooks | United States / Ireland |
| Kapso | WhatsApp Business account provisioning and message routing | Chile |
| Twilio | WhatsApp and SMS delivery for numbers connected through Twilio — optional | United States |
| Unipile | LinkedIn account connection, messaging and invitations — optional | France |
| ElevenLabs | Conversational voice agents, speech synthesis and voice cloning | United States |
| Fish Audio (Hanabi AI Inc.) | Speech synthesis and voice cloning | United States |
| Telnyx | Telephony: phone numbers and call carriage | United States |
| Apollo.io | Prospect discovery and contact enrichment — optional | United States |
| Tavily | Web research used to prepare company and prospect briefings | United States |
| HubSpot, Zoho, Pipedrive, monday.com, Odoo, Salesforce | Two-way CRM synchronisation — optional, only when the customer connects one | Varies by provider |
We do not sell personal data and we do not share it with advertising networks. We disclose data to public authorities only where we are legally required to.
9.International transfers
ASIA runs in the United States. Our application servers, our database and our file and recording storage are hosted on Google Cloud in the us-central1 region (Iowa, USA). Most of the providers in the table above are also based in the United States.
That means personal data of people located in the European Economic Area, the United Kingdom, Switzerland, Mexico or elsewhere is transferred to and stored in the United States. If you are in a jurisdiction that restricts such transfers, take this into account before loading data into the platform, and contact us at privacy@atlantia.ai to discuss the transfer safeguards applicable to your contract.
10.How long we keep data
We keep data for as long as the customer's account is active, unless a shorter period applies below. The periods marked as enforced automatically are applied by scheduled jobs; the rest happen when an account, workspace or record is deleted.
| Data | Retention |
|---|---|
| CRM records a user deletes (contacts, companies, deals, notes) | Moved to a recycle bin, where they are restorable for 30 days and are then permanently deleted |
| Copies of messages synced from a connected mailbox | Kept for the retention window the customer sets on their workspace, then archived and permanently deleted after a further 30 days — enforced automatically when the setting is on. When no window is set, copies are kept for the life of the account |
| Audit logs | Kept for the period the customer configures on their workspace, 24 months by default |
| Channel rate-limit counters | 90 days — enforced automatically |
| Campaign messages, conversations and engagement data | For the life of the account, then deleted with it |
| Voice-call recordings, transcripts and summaries | For the life of the account. There is no automatic expiry today: they are deleted when the call record, the workspace or the account is deleted, or on request |
| Connected-channel credentials and access tokens | Until the channel is disconnected or the account is closed |
| Account, subscription and billing records | For the life of the account and afterwards for as long as tax and accounting law requires |
11.Your rights, and how to delete your data
Depending on where you live, you may have the right to access your personal data, to have it corrected, to have it deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw a consent you gave. You can exercise any of them by writing to privacy@atlantia.ai.
Deletion has its own page. Step-by-step instructions — for a user deleting their own account, for a customer deleting an entire workspace, and for someone who was contacted by a business using ASIA — are on the Data Deletion page, along with what is deleted, what is kept, and how long it takes.
We will ask for enough information to confirm who you are before acting, so that we do not disclose or delete someone else's data on a stranger's say-so. Where we act as a processor for a customer, we will forward your request to that customer and tell you we have done so.
If you no longer want to be contacted by campaigns run through ASIA, every outreach email carries an unsubscribe link, and you can also write to unsubscribe@atlantia.ai. An opt-out is honoured across the platform and cannot be overridden by a campaign setting.
12.Security
- Credentials are encrypted at rest. OAuth tokens, API keys and channel credentials are encrypted in the database with a key held in Google Secret Manager, separate from the data.
- Tenant isolation. Every record carries the identifier of the company that owns it, and every query is scoped to the requesting user's company. Users only see their own organisation's data.
- Access control. Access to the application is authenticated and role-based; permissions are granular and administered per company.
- Audit trail. Administrative and data-affecting actions are logged with the user, the target record and the timestamp.
- Infrastructure. Data is encrypted in transit, hosted on Google Cloud, with secrets held in Google Secret Manager and access to production systems limited to authorised personnel.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to privacy@atlantia.ai rather than disclosing it publicly.
14.Children, changes and complaints
Children. ASIA is a tool for businesses. It is not directed at children, we do not knowingly collect data from anyone under 18, and accounts may only be created by adults acting for an organisation.
Changes. We will update this page when the platform changes, and the date at the top always reflects the current version. Material changes are notified to account owners.
Complaints. Write to us first at privacy@atlantia.ai — we would rather fix it. If you are in the EEA or the UK you also have the right to lodge a complaint with your national data protection authority.