Atlantia.ai

Privacy Policy

ASIA is a business-to-business sales platform. This policy explains what personal data we handle, why, who else touches it, how long we keep it, and how you get it deleted.

Last updated: 22 September 2026

1.Who we are

ASIA (Automated Sales Intelligence & Acquisition) is a software platform operated by Atlantia ("ASIA", "we", "us"). It lets a business create AI sales avatars that run outreach campaigns to that business's own prospects across email, LinkedIn, WhatsApp, Telegram and automated voice calls, and that keep the resulting conversations, contacts and deals in a built-in CRM.

Postal address: Av. Paseo de la Reforma 296, Cuauhtémoc, 06600 Mexico City, Mexico.
Privacy contact: privacy@atlantia.ai
Deletion requests: privacy@atlantia.ai — see the dedicated Data Deletion page for step-by-step instructions.

This policy is ours. It describes this platform and no other, and it applies to the ASIA web application at asia.atlantia.ai and to the background services that send and receive messages on our customers' behalf.

2.Our two roles: controller and processor

ASIA handles two very different kinds of personal data, and our legal role is different for each. Reading this section first will make the rest of the document make sense.

We are the controller of our own users' data

When someone signs up, logs in, configures a workspace or is billed, we decide why and how that data is processed. That covers account details, authentication, access and activity logs, support exchanges, and subscription and billing records. If you are an ASIA user, this policy is the one that governs your data, and you can bring your requests directly to us.

We are a processor for the prospect data our customers load

Everything a customer imports, captures or generates about the people they want to sell to — contacts, companies, deals, notes, and the content of the messages exchanged with them — is processed by us on that customer's instructions. The customer decides who gets contacted, on which channel and with what message; the customer is the controller and is responsible for having a lawful basis to make contact. We process that data only to provide the platform.

If you were contacted by a business using ASIA and you want your data corrected or deleted, the fastest route is to reply to that business, because they control the list. You can also write to privacy@atlantia.ai and we will identify the customer responsible and pass your request to them, as described on the Data Deletion page.

3.What data we collect

a. Data you give us as a user

  • Identity and contact: name, work email address, company, job role, preferred language.
  • Credentials for the channels you connect: OAuth tokens for Gmail or Microsoft 365 mailboxes and calendars, WhatsApp Business access tokens, LinkedIn session credentials, CRM API keys and OAuth tokens. These are stored encrypted (see Security).
  • Content you create: products, campaign scripts, message templates, avatar personas, documents you upload.
  • Voice samples, if you use voice cloning: a recording you upload so an avatar can speak in that voice (see Voice calls).
  • Billing and subscription data for paid plans.

b. Data collected automatically when you use ASIA

  • Authentication events, IP address and browser user-agent at sign-in.
  • Audit and activity logs: which user did what, to which record, and when.
  • Service logs and error traces produced by our servers.
  • Usage counters we need to enforce plan limits and channel rate limits.

c. Prospect data our customers load or generate

  • Contact details: name, work email, phone number, job title, employer, LinkedIn profile URL, plus any custom fields the customer defines.
  • Message content across every channel we support: emails sent and received, LinkedIn messages and invitations, WhatsApp and Telegram messages, and voice-call recordings, transcripts and summaries.
  • Engagement signals: delivery, bounce and reply status, and — where the customer enables open and click tracking on outreach email — the recipient's IP address and user-agent at the moment the email is opened or a link is clicked.
  • CRM records built on top of that: companies, deals, notes, tasks, tickets, orders and timeline events.

d. Data from third parties

  • Connected mailboxes. With the user's OAuth consent we read messages from the connected mailbox in order to match replies to campaigns and populate the shared inbox.
  • Connected CRMs. When a customer connects HubSpot, Zoho, Pipedrive, monday, Odoo or Salesforce, we import the contact, company and deal records they choose to sync.
  • Enrichment and research. Apollo.io supplies professional contact data for prospect discovery; Tavily supplies public web results used to research a company before writing to it.
  • Messaging platforms. Data that reaches us from Meta, LinkedIn and the telephony network — covered in section 5.

5.Data from Meta and other connected platforms

Meta / WhatsApp Business Platform

When a customer connects their WhatsApp Business account, we receive from Meta and store: the WhatsApp Business Account and phone-number identifiers, the display name and quality rating of the number, the message templates registered on it, access tokens issued to us for that account, inbound messages sent to that number (including the sender's phone number and WhatsApp profile name), and delivery and read status for messages we send.

We use that data for one thing only: to operate the WhatsApp channel the customer asked us to operate — sending the messages they schedule, receiving replies into their inbox, syncing their templates, and reporting delivery. We do not use data received from Meta for advertising, we do not sell it, we do not combine it across customers, and we do not use it to train AI models.

Access tokens are stored encrypted and are deleted when the customer disconnects the channel or closes the account. WhatsApp message content is stored as part of the customer's conversation history and is deleted with it — see section 10 and the Data Deletion page. A deletion request covering data received from Meta is handled through exactly the same route as any other request.

Google user data (Gmail and Google Calendar)

When a user connects a Gmail mailbox we request the scopes needed to send mail, read mail and manage message labels, plus calendar access for meeting scheduling. ASIA's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to provide the outreach and shared-inbox features the user connected the mailbox for; we do not transfer it to others except as needed to provide those features, and we do not use it for advertising or to train generalised AI models.

Microsoft 365, LinkedIn and telephony

  • Microsoft 365: mail send/read/write and read-only calendar access, used for the same outreach and inbox features as Gmail.
  • LinkedIn: connected through Unipile. We receive the connected account's profile, its conversations and invitation status, and the public profile data of the people the customer targets.
  • Telephony: the numbers dialled and received, call duration and outcome, and the audio of the call where recording is in use.

6.Processing with artificial intelligence

ASIA uses large language models to do the work the product exists for: research a prospect, draft and translate outreach copy, decide which channel and moment to use, read an incoming reply and classify its intent, summarise a conversation, and drive the dialogue of an automated voice call.

What is sent to a model. The prompt typically contains the campaign brief and the customer's product information, the prospect's CRM record, and the message history of that conversation. Our primary provider is Google Vertex AI (Gemini); OpenAI is used as a fallback and for specific features.

Training. ASIA does not train, fine-tune or improve any general-purpose AI model with customer or prospect data, and we do not license that data to anyone for model training. The one case where content you provide is used to build a model is voice cloning, which happens only for the voice sample you deliberately upload, only in the provider account we operate, and only to produce a voice your own avatars use — described in the next section.

Human oversight. AI output is generated text. It can be wrong. Campaigns can be configured so a person approves messages before they go out, and the customer remains responsible for what is sent under their name.

7.Voice calls: recording and transcription

When a customer runs a voice campaign, ASIA places automated calls in which an AI agent speaks with the person who answers. Those calls are recorded and transcribed.

For each call we store the number dialled, the time and duration, the call outcome, the full turn-by-turn transcript, an AI-generated summary of it, and the call audio, which is kept in Google Cloud Storage in a private bucket and served only to authorised users of the owning workspace.

Consent is the caller's responsibility. Recording a call without the required notice or consent is unlawful in many countries and in several US states. The customer running the campaign decides who is called and what the agent says, and is responsible for giving whatever notice the law of the recipient's location requires. Our Terms of Service require it.

Voice cloning. If you upload a recording of a voice so an avatar can speak with it, that recording is sent to the cloning provider (ElevenLabs or Fish Audio) and used to create a synthetic voice tied to your workspace. Only upload a voice you are the owner of, or have written permission to clone.

Recordings, transcripts and summaries are deleted when the workspace or the call record is deleted; see section 10 for what that means in practice today.

8.Subprocessors

We use the providers below to run the platform. Every one of them is bound to process data only on our instructions. Providers that appear only when a customer chooses to connect them are marked as optional.

ProviderPurposePrimary location
Google Cloud PlatformHosting, database, file and recording storage, secret managementUnited States (us-central1)
Google Cloud — Vertex AI (Gemini)Message generation, reply classification, conversation intelligenceUnited States
OpenAIFallback and feature-specific language modelUnited States
SendGrid (Twilio)Outbound email delivery and inbound mail routingUnited States
Google (Gmail API)Sending and reading mail from a connected Google mailbox — optionalUnited States
Microsoft (Graph API)Sending and reading mail from a connected Microsoft 365 mailbox — optionalUnited States / EU
Meta Platforms (WhatsApp Business Platform)WhatsApp message delivery, templates and webhooksUnited States / Ireland
KapsoWhatsApp Business account provisioning and message routingChile
TwilioWhatsApp and SMS delivery for numbers connected through Twilio — optionalUnited States
UnipileLinkedIn account connection, messaging and invitations — optionalFrance
ElevenLabsConversational voice agents, speech synthesis and voice cloningUnited States
Fish Audio (Hanabi AI Inc.)Speech synthesis and voice cloningUnited States
TelnyxTelephony: phone numbers and call carriageUnited States
Apollo.ioProspect discovery and contact enrichment — optionalUnited States
TavilyWeb research used to prepare company and prospect briefingsUnited States
HubSpot, Zoho, Pipedrive, monday.com, Odoo, SalesforceTwo-way CRM synchronisation — optional, only when the customer connects oneVaries by provider

We do not sell personal data and we do not share it with advertising networks. We disclose data to public authorities only where we are legally required to.

9.International transfers

ASIA runs in the United States. Our application servers, our database and our file and recording storage are hosted on Google Cloud in the us-central1 region (Iowa, USA). Most of the providers in the table above are also based in the United States.

That means personal data of people located in the European Economic Area, the United Kingdom, Switzerland, Mexico or elsewhere is transferred to and stored in the United States. If you are in a jurisdiction that restricts such transfers, take this into account before loading data into the platform, and contact us at privacy@atlantia.ai to discuss the transfer safeguards applicable to your contract.

10.How long we keep data

We keep data for as long as the customer's account is active, unless a shorter period applies below. The periods marked as enforced automatically are applied by scheduled jobs; the rest happen when an account, workspace or record is deleted.

DataRetention
CRM records a user deletes (contacts, companies, deals, notes)Moved to a recycle bin, where they are restorable for 30 days and are then permanently deleted
Copies of messages synced from a connected mailboxKept for the retention window the customer sets on their workspace, then archived and permanently deleted after a further 30 days — enforced automatically when the setting is on. When no window is set, copies are kept for the life of the account
Audit logsKept for the period the customer configures on their workspace, 24 months by default
Channel rate-limit counters90 days — enforced automatically
Campaign messages, conversations and engagement dataFor the life of the account, then deleted with it
Voice-call recordings, transcripts and summariesFor the life of the account. There is no automatic expiry today: they are deleted when the call record, the workspace or the account is deleted, or on request
Connected-channel credentials and access tokensUntil the channel is disconnected or the account is closed
Account, subscription and billing recordsFor the life of the account and afterwards for as long as tax and accounting law requires

11.Your rights, and how to delete your data

Depending on where you live, you may have the right to access your personal data, to have it corrected, to have it deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw a consent you gave. You can exercise any of them by writing to privacy@atlantia.ai.

Deletion has its own page. Step-by-step instructions — for a user deleting their own account, for a customer deleting an entire workspace, and for someone who was contacted by a business using ASIA — are on the Data Deletion page, along with what is deleted, what is kept, and how long it takes.

We will ask for enough information to confirm who you are before acting, so that we do not disclose or delete someone else's data on a stranger's say-so. Where we act as a processor for a customer, we will forward your request to that customer and tell you we have done so.

If you no longer want to be contacted by campaigns run through ASIA, every outreach email carries an unsubscribe link, and you can also write to unsubscribe@atlantia.ai. An opt-out is honoured across the platform and cannot be overridden by a campaign setting.

12.Security

  • Credentials are encrypted at rest. OAuth tokens, API keys and channel credentials are encrypted in the database with a key held in Google Secret Manager, separate from the data.
  • Tenant isolation. Every record carries the identifier of the company that owns it, and every query is scoped to the requesting user's company. Users only see their own organisation's data.
  • Access control. Access to the application is authenticated and role-based; permissions are granular and administered per company.
  • Audit trail. Administrative and data-affecting actions are logged with the user, the target record and the timestamp.
  • Infrastructure. Data is encrypted in transit, hosted on Google Cloud, with secrets held in Google Secret Manager and access to production systems limited to authorised personnel.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to privacy@atlantia.ai rather than disclosing it publicly.

13.Cookies

The ASIA application uses strictly necessary cookies only. There are three: an access_token cookie and an admin_access_token cookie that keep you signed in, and a NEXT_LOCALE cookie that remembers your interface language. We run no advertising, analytics or session-replay trackers on the application, so there is nothing here to consent to or opt out of.

Separately, outreach emails sent through ASIA may contain an open-tracking pixel and tracked links when the customer enables them. That is the customer's choice about their own campaign, and it is covered in section 3(c).

14.Children, changes and complaints

Children. ASIA is a tool for businesses. It is not directed at children, we do not knowingly collect data from anyone under 18, and accounts may only be created by adults acting for an organisation.

Changes. We will update this page when the platform changes, and the date at the top always reflects the current version. Material changes are notified to account owners.

Complaints. Write to us first at privacy@atlantia.ai — we would rather fix it. If you are in the EEA or the UK you also have the right to lodge a complaint with your national data protection authority.