PRIVACY & DATA PROTECTION

Privacy Notice

This Notice explains how ATSRS handles personal data across Personal and Corporate workspaces, document storage, controlled profile sharing, reminders and optional AI features.

Effective: 4 August 2026 Last reviewed: 4 August 2026 Contact: anaragasiyev@gmail.com
Private by defaultDocuments and profile details are not shared with a company unless the user enables visibility or approves access.
No sale of personal dataATSRS does not sell personal data or use it for cross-context behavioural advertising.
User-controlled AIAI processing starts only when a user actively selects an AI feature and submits information for that purpose.

1. Who this Notice applies to

This Notice applies to visitors to atsrs.com, Personal account holders, Corporate account owners and authorised users, candidates or personnel whose information is managed through ATSRS, people who receive or approve a controlled sharing request, and people who contact ATSRS for support.

ATSRS is a professional document, expiry tracking, profile sharing and compliance workflow service. This Notice covers the website, authenticated platform, related email notifications and optional communications features.

Important: when a company uses ATSRS to manage candidate or personnel information, that company may have its own privacy notice. The company’s notice should explain its independent purposes, legal bases and employment-related decisions.

2. Our data-protection roles

SituationATSRS roleOther responsible party
Account registration, authentication, platform security, support and service administrationController for the operational data ATSRS determines how and why to use.Google may act as an independent controller for Google sign-in under its own notice.
A Personal user stores documents, builds a profile, requests AI processing or shares selected informationController for providing the Personal service and protecting the account.The user controls what they upload and whom they authorise to receive it.
A Corporate customer manages its candidates, personnel or company recordsProcessor/service provider acting on the customer’s documented instructions, except for ATSRS security and service-administration data.The Corporate customer is normally the controller and is responsible for a lawful basis, notices, accuracy and access permissions.
A company independently downloads, imports or uses information after authorised sharingATSRS records and enforces the platform permission workflow.The receiving company becomes responsible for its own subsequent use and retention.

3. Personal data we handle

  • Identity and account data: name, surname, email address, account type, Google account identifiers, profile photo and authentication records.
  • Professional profile data: profession, position, employer, nationality, country, availability, work preferences, career history, skills, references, appraisals and CV information.
  • Contact data: telephone and WhatsApp numbers, country codes, verification status and user-selected notification preferences.
  • Documents and compliance data: uploaded files, licences, certificates, permits, passports, visas, seaman books, training records, issue and expiry dates, providers, document numbers and status information.
  • Potentially sensitive data: medical certificates or other documents that may reveal health information, and identity documents that may contain date of birth, nationality or government identifiers.
  • Corporate workspace data: company details, personnel records, projects, vessels, teams, compliance status, access requests and authorised user activity.
  • Sharing and communication data: profile visibility, selected document permissions, sharing links, request status, notification delivery and support correspondence.
  • Technical and security data: IP address where available to infrastructure providers, browser/device information, session and access logs, timestamps, error records, audit events and anti-abuse signals.
  • AI request data: the document, image, profile fields or instructions deliberately submitted to AI Document Scan or AI CV Generator, plus the generated result and limited usage/quota records.

ATSRS may receive information directly from the individual, from a Corporate customer acting as controller, from Google sign-in, or from another user who has a lawful reason to send an access request. Corporate customers must not upload information they are not authorised to process.

4. Why we use data and our legal bases

PurposeTypical dataLegal basis where GDPR/UK GDPR applies
Create and operate an account; authenticate users; provide storage, expiry tracking, CV and sharing tools.Identity, contact, profile, documents and account settings.Performance of a contract or steps requested before a contract.
Protect accounts, prevent misuse, investigate errors, maintain auditability and enforce permissions.Session, access, security and audit data.Legitimate interests in secure and reliable service delivery; legal obligation where applicable.
Send requested expiry reminders, verification messages, sharing requests and service notices.Email, phone/WhatsApp, preferences and delivery status.Contract; legitimate interests; consent where required for an optional communications channel.
Process a user-requested AI scan or CV generation.User-selected document or profile content and generated output.Contract/requested service; explicit consent where required for special-category information.
Respond to support, privacy and security requests.Contact details, correspondence and verification information.Contract, legal obligation and legitimate interests.
Comply with law, valid legal process, disputes and regulatory duties.Only information reasonably necessary for the relevant matter.Legal obligation and legitimate interests in establishing or defending legal claims.

ATSRS does not use uploaded employment or medical documents for unrelated marketing. ATSRS does not make hiring, dismissal, medical fitness or legal-compliance decisions on behalf of users or companies.

5. When data is shared

ATSRS limits disclosure to what is needed to provide, secure and support the service. Current categories of service providers include:

  • Supabase: authentication, database, file storage and server-side functions.
  • Google: optional Google sign-in.
  • OpenAI: optional AI Document Scan and AI CV Generator requests initiated by the user.
  • Resend: transactional email delivery, including service and expiry notifications.
  • GitHub: public website hosting and delivery.
  • Meta/WhatsApp: verification or notification delivery only when the relevant WhatsApp feature is enabled and used.

Providers receive only the information reasonably required for their service and are subject to their own legal obligations and applicable contractual safeguards. ATSRS may also disclose limited information when required by law, to protect rights and safety, or as part of a properly structured business transfer with appropriate confidentiality protections.

ATSRS does not sell personal data. ATSRS does not permit service providers to use uploaded documents for their own advertising.

6. Profile visibility and controlled sharing

Personal profiles are private by default. A user may choose a visibility setting, create or enable a controlled profile link, select information for sharing, or approve a company’s document-access request. Preview access and file-download access may be governed by different permissions.

Before sharing, users should verify the recipient and review the selected fields and documents. After a recipient lawfully downloads or imports information, that recipient controls its own copy and must provide its own lawful basis, retention rules and security.

Corporate users must access candidate and personnel information only for legitimate professional purposes and only through permissions granted to their account.

7. Optional AI features

ATSRS uses AI only when a user deliberately starts an AI feature. AI Document Scan can analyse a selected file to suggest structured document fields. AI CV Generator can use selected profile and career information to draft a CV. Users must review AI output before relying on or saving it.

  • AI output may be incomplete or inaccurate and is not verification of identity, qualifications, medical fitness or legal compliance.
  • ATSRS does not use AI output to make automated hiring or employment decisions.
  • Users should avoid submitting information that is unnecessary for the requested result.
  • A user submitting another person’s data must have authority and an appropriate legal basis.

Limited technical records may be retained to enforce quotas, prevent abuse and diagnose failures. AI inputs and outputs are handled according to the provider arrangements in force when the request is made.

8. International data transfers

ATSRS is intended for international use. Personal data may be processed in countries other than the user’s country when infrastructure, authentication, email, AI or communications providers operate internationally.

Where European Economic Area or United Kingdom transfer rules apply, ATSRS seeks to use recognised safeguards such as adequacy decisions, approved standard contractual clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. The protections available may vary by destination and provider.

9. How long data is kept

RecordRetention approach
Active account, profile and uploaded contentFor the life of the account or Corporate customer instruction, then targeted for deletion from active systems within 30 days after a verified closure request unless a lawful exception applies.
Controlled sharing and access-request recordsWhile needed to operate the request and for a reasonable audit/security period, normally no longer than 24 months after the last event unless a dispute or legal duty requires longer.
Notification and verification delivery recordsNormally up to 12 months for delivery, abuse prevention and troubleshooting, unless a shorter period is sufficient.
Security, access and error logsNormally up to 12 months, adjusted where necessary for an active security investigation or legal requirement.
Support and privacy correspondenceNormally up to 24 months after closure of the request, or longer if needed for a legal claim or regulatory duty.
AI quota and diagnostic recordsOnly for the period needed to enforce plan limits, prevent abuse and resolve service failures.
BackupsDeleted active data may remain temporarily in encrypted or access-restricted backups until the applicable provider backup cycle overwrites it. Backups are not used for ordinary business access.
Records required by law or legal claimsFor the period required by the applicable law or reasonably necessary to establish, exercise or defend a claim.

ATSRS may anonymise data so that it can no longer identify a person. Properly anonymised information may be kept for service measurement and reliability analysis.

10. Security and incident response

ATSRS applies role-based access controls, authenticated sessions, database row-level security, restricted storage access, controlled sharing, audit records and server-side processing for sensitive operations. Access is limited according to workspace and user permissions.

No online service can guarantee absolute security. Users must protect their Google account, device and active sessions, avoid sharing access links with unintended recipients, and report suspected misuse promptly. If a personal-data breach occurs, ATSRS will investigate, contain the incident and notify affected people or authorities when required by applicable law.

11. Your privacy rights

Depending on location and applicable law, a person may have rights to:

  • receive information about processing and obtain a copy of personal data;
  • correct inaccurate or incomplete information;
  • request deletion or restriction of processing;
  • receive portable data in an available structured format;
  • object to processing based on legitimate interests or direct marketing;
  • withdraw consent without affecting earlier lawful processing;
  • challenge qualifying solely automated decisions; and
  • complain to the competent data-protection authority.

Rights are not absolute. ATSRS may need to verify identity, preserve another person’s rights, comply with law or keep limited evidence of a completed request. When ATSRS processes Corporate workspace data only on a customer’s instructions, ATSRS may direct the request to that Corporate customer or assist it in responding.

Request access, correction or deletion

Do not send passwords, one-time codes, identity-document scans or authentication tokens by email unless ATSRS provides a secure verification method.

View request process

12. Cookies, sessions and local storage

ATSRS uses essential browser storage and authentication/session technologies to sign users in, protect accounts, remember workspace or interface preferences, maintain user-requested state and support secure platform operation. These technologies are necessary for the service requested by the user.

ATSRS currently does not use third-party advertising cookies or cross-site behavioural advertising. If optional analytics or advertising technologies are introduced, ATSRS will update this Notice and provide any consent or rejection controls required by applicable law before non-essential access begins.

Blocking essential browser storage may prevent authentication, saved preferences or other platform functions from working correctly.

13. Children

ATSRS is a professional service intended for adults and authorised business users. It is not directed to children under 18, and ATSRS does not knowingly request that children create accounts or upload professional identity and employment documents. Contact ATSRS if you believe a child’s data has been submitted without proper authority.

14. Changes to this Notice

ATSRS will review this Notice when services, providers, laws or data uses materially change. The effective date above will be updated. Material changes will be brought to users’ attention through the platform, email or another appropriate channel before a new use begins where required.

This Notice is designed to support international transparency requirements, including GDPR and UK GDPR principles where applicable. If local law grants stronger mandatory rights, that law applies to the relevant processing.

15. Contact and complaints

The service operator responsible for ATSRS privacy administration can be contacted at:

ATSRS Privacy

anaragasiyev@gmail.com

Use the subject “ATSRS Privacy Request”.

Contact privacy

You may also complain to the data-protection authority responsible for your location or for the relevant controller. Contact ATSRS first if you would like us to investigate and try to resolve the concern promptly.