1. Who this Notice applies to
This Notice applies to visitors to atsrs.com, Personal account holders, Corporate account owners and authorised users, candidates or personnel whose information is managed through ATSRS, people who receive or approve a controlled sharing request, and people who contact ATSRS for support.
ATSRS is a professional document, expiry tracking, profile sharing and compliance workflow service. This Notice covers the website, authenticated platform, related email notifications and optional communications features.
2. Our data-protection roles
| Situation | ATSRS role | Other responsible party |
|---|---|---|
| Account registration, authentication, platform security, support and service administration | Controller for the operational data ATSRS determines how and why to use. | Google may act as an independent controller for Google sign-in under its own notice. |
| A Personal user stores documents, builds a profile, requests AI processing or shares selected information | Controller for providing the Personal service and protecting the account. | The user controls what they upload and whom they authorise to receive it. |
| A Corporate customer manages its candidates, personnel or company records | Processor/service provider acting on the customer’s documented instructions, except for ATSRS security and service-administration data. | The Corporate customer is normally the controller and is responsible for a lawful basis, notices, accuracy and access permissions. |
| A company independently downloads, imports or uses information after authorised sharing | ATSRS records and enforces the platform permission workflow. | The receiving company becomes responsible for its own subsequent use and retention. |
3. Personal data we handle
- Identity and account data: name, surname, email address, account type, Google account identifiers, profile photo and authentication records.
- Professional profile data: profession, position, employer, nationality, country, availability, work preferences, career history, skills, references, appraisals and CV information.
- Contact data: telephone and WhatsApp numbers, country codes, verification status and user-selected notification preferences.
- Documents and compliance data: uploaded files, licences, certificates, permits, passports, visas, seaman books, training records, issue and expiry dates, providers, document numbers and status information.
- Potentially sensitive data: medical certificates or other documents that may reveal health information, and identity documents that may contain date of birth, nationality or government identifiers.
- Corporate workspace data: company details, personnel records, projects, vessels, teams, compliance status, access requests and authorised user activity.
- Sharing and communication data: profile visibility, selected document permissions, sharing links, request status, notification delivery and support correspondence.
- Technical and security data: IP address where available to infrastructure providers, browser/device information, session and access logs, timestamps, error records, audit events and anti-abuse signals.
- AI request data: the document, image, profile fields or instructions deliberately submitted to AI Document Scan or AI CV Generator, plus the generated result and limited usage/quota records.
ATSRS may receive information directly from the individual, from a Corporate customer acting as controller, from Google sign-in, or from another user who has a lawful reason to send an access request. Corporate customers must not upload information they are not authorised to process.
4. Why we use data and our legal bases
| Purpose | Typical data | Legal basis where GDPR/UK GDPR applies |
|---|---|---|
| Create and operate an account; authenticate users; provide storage, expiry tracking, CV and sharing tools. | Identity, contact, profile, documents and account settings. | Performance of a contract or steps requested before a contract. |
| Protect accounts, prevent misuse, investigate errors, maintain auditability and enforce permissions. | Session, access, security and audit data. | Legitimate interests in secure and reliable service delivery; legal obligation where applicable. |
| Send requested expiry reminders, verification messages, sharing requests and service notices. | Email, phone/WhatsApp, preferences and delivery status. | Contract; legitimate interests; consent where required for an optional communications channel. |
| Process a user-requested AI scan or CV generation. | User-selected document or profile content and generated output. | Contract/requested service; explicit consent where required for special-category information. |
| Respond to support, privacy and security requests. | Contact details, correspondence and verification information. | Contract, legal obligation and legitimate interests. |
| Comply with law, valid legal process, disputes and regulatory duties. | Only information reasonably necessary for the relevant matter. | Legal obligation and legitimate interests in establishing or defending legal claims. |
ATSRS does not use uploaded employment or medical documents for unrelated marketing. ATSRS does not make hiring, dismissal, medical fitness or legal-compliance decisions on behalf of users or companies.
6. Profile visibility and controlled sharing
Personal profiles are private by default. A user may choose a visibility setting, create or enable a controlled profile link, select information for sharing, or approve a company’s document-access request. Preview access and file-download access may be governed by different permissions.
Before sharing, users should verify the recipient and review the selected fields and documents. After a recipient lawfully downloads or imports information, that recipient controls its own copy and must provide its own lawful basis, retention rules and security.
Corporate users must access candidate and personnel information only for legitimate professional purposes and only through permissions granted to their account.
7. Optional AI features
ATSRS uses AI only when a user deliberately starts an AI feature. AI Document Scan can analyse a selected file to suggest structured document fields. AI CV Generator can use selected profile and career information to draft a CV. Users must review AI output before relying on or saving it.
- AI output may be incomplete or inaccurate and is not verification of identity, qualifications, medical fitness or legal compliance.
- ATSRS does not use AI output to make automated hiring or employment decisions.
- Users should avoid submitting information that is unnecessary for the requested result.
- A user submitting another person’s data must have authority and an appropriate legal basis.
Limited technical records may be retained to enforce quotas, prevent abuse and diagnose failures. AI inputs and outputs are handled according to the provider arrangements in force when the request is made.
8. International data transfers
ATSRS is intended for international use. Personal data may be processed in countries other than the user’s country when infrastructure, authentication, email, AI or communications providers operate internationally.
Where European Economic Area or United Kingdom transfer rules apply, ATSRS seeks to use recognised safeguards such as adequacy decisions, approved standard contractual clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. The protections available may vary by destination and provider.
9. How long data is kept
| Record | Retention approach |
|---|---|
| Active account, profile and uploaded content | For the life of the account or Corporate customer instruction, then targeted for deletion from active systems within 30 days after a verified closure request unless a lawful exception applies. |
| Controlled sharing and access-request records | While needed to operate the request and for a reasonable audit/security period, normally no longer than 24 months after the last event unless a dispute or legal duty requires longer. |
| Notification and verification delivery records | Normally up to 12 months for delivery, abuse prevention and troubleshooting, unless a shorter period is sufficient. |
| Security, access and error logs | Normally up to 12 months, adjusted where necessary for an active security investigation or legal requirement. |
| Support and privacy correspondence | Normally up to 24 months after closure of the request, or longer if needed for a legal claim or regulatory duty. |
| AI quota and diagnostic records | Only for the period needed to enforce plan limits, prevent abuse and resolve service failures. |
| Backups | Deleted active data may remain temporarily in encrypted or access-restricted backups until the applicable provider backup cycle overwrites it. Backups are not used for ordinary business access. |
| Records required by law or legal claims | For the period required by the applicable law or reasonably necessary to establish, exercise or defend a claim. |
ATSRS may anonymise data so that it can no longer identify a person. Properly anonymised information may be kept for service measurement and reliability analysis.
10. Security and incident response
ATSRS applies role-based access controls, authenticated sessions, database row-level security, restricted storage access, controlled sharing, audit records and server-side processing for sensitive operations. Access is limited according to workspace and user permissions.
No online service can guarantee absolute security. Users must protect their Google account, device and active sessions, avoid sharing access links with unintended recipients, and report suspected misuse promptly. If a personal-data breach occurs, ATSRS will investigate, contain the incident and notify affected people or authorities when required by applicable law.
11. Your privacy rights
Depending on location and applicable law, a person may have rights to:
- receive information about processing and obtain a copy of personal data;
- correct inaccurate or incomplete information;
- request deletion or restriction of processing;
- receive portable data in an available structured format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent without affecting earlier lawful processing;
- challenge qualifying solely automated decisions; and
- complain to the competent data-protection authority.
Rights are not absolute. ATSRS may need to verify identity, preserve another person’s rights, comply with law or keep limited evidence of a completed request. When ATSRS processes Corporate workspace data only on a customer’s instructions, ATSRS may direct the request to that Corporate customer or assist it in responding.
Do not send passwords, one-time codes, identity-document scans or authentication tokens by email unless ATSRS provides a secure verification method.
13. Children
ATSRS is a professional service intended for adults and authorised business users. It is not directed to children under 18, and ATSRS does not knowingly request that children create accounts or upload professional identity and employment documents. Contact ATSRS if you believe a child’s data has been submitted without proper authority.
14. Changes to this Notice
ATSRS will review this Notice when services, providers, laws or data uses materially change. The effective date above will be updated. Material changes will be brought to users’ attention through the platform, email or another appropriate channel before a new use begins where required.
This Notice is designed to support international transparency requirements, including GDPR and UK GDPR principles where applicable. If local law grants stronger mandatory rights, that law applies to the relevant processing.
15. Contact and complaints
The service operator responsible for ATSRS privacy administration can be contacted at:
Use the subject “ATSRS Privacy Request”.
You may also complain to the data-protection authority responsible for your location or for the relevant controller. Contact ATSRS first if you would like us to investigate and try to resolve the concern promptly.