ATSRSBack to product overview
DATA PROTECTION

GDPR principles, explained for ATSRS.

This overview explains how ATSRS is designed to support transparent, limited and user-controlled processing. It is not a certification statement or a substitute for a customer’s own legal assessment.

Last reviewed: 10 August 2026Applies to: Personal, Corporate and Candidate workflows
Purpose limitationAccount, document, expiry, sharing and requested AI data are used to operate those services.
Controlled accessProfile visibility, document preview, download permission and company access remain separate choices.
Rights processAccess, correction, export and deletion requests are verified before action is taken.
ON THIS PAGE
1. Scope2. Responsibilities3. Core principles4. Individual rights5. Security6. Important limits

1. What this overview covers

ATSRS is an international document-readiness platform for individuals and organisations. It supports document storage, expiry tracking, controlled profile and document sharing, candidate visibility, personnel workflows, notifications and user-requested AI assistance.

The detailed categories, purposes, providers, retention approach and transfer safeguards are described in the Privacy Notice.

2. Different responsibilities

ATSRS normally determines how account registration, authentication, platform security and service administration data are used. When a Corporate customer manages candidate or personnel information for its own purposes, that customer is normally responsible for its lawful basis, notices, accuracy and access decisions.

Corporate customers: using ATSRS does not replace your own employment, privacy, retention or sector-specific compliance duties.

3. How GDPR principles shape the product

  • Transparency: users can see why information is requested and how sharing works.
  • Data minimisation: only information needed for the selected workflow should be collected.
  • Accuracy: AI suggestions and document dates must be reviewed by a person before reliance.
  • Storage limitation: records are retained according to operational, security and legal needs rather than indefinitely by default.
  • Integrity and confidentiality: authenticated sessions, workspace permissions, restricted storage and controlled links limit access.
  • Accountability: access requests, permissions and important workspace actions are designed to remain traceable.

4. Individual rights

Depending on applicable law, individuals may request access, correction, export, restriction, objection or deletion. ATSRS verifies requests to protect the account and may coordinate with the responsible Corporate customer when that customer controls the relevant record.

Read the Data Rights process.

5. Security and incident handling

ATSRS uses access controls and server-side safeguards appropriate to the current service. No online system can promise absolute security. Suspected vulnerabilities should be reported privately through the Security Reporting Policy.

6. Important limits

ATSRS does not certify that a person, document, company or project is legally compliant, medically fit or eligible for a role. Date status is a workflow aid based on stored information. Customers remain responsible for legal review and real-world decisions.

Statements on this page describe the present product approach. ATSRS does not claim an external GDPR certification, approved code of conduct, formal DPA availability or employee-training programme unless separate verified evidence is published.

© 2026 ATSRSData Protection & GDPRTerms of UsePrivacy NoticeData RightsReport a Security Issue