Last updated 25 July 2026
This policy explains what Atlis Rx collects when you use Atlis Path, why, and who else processes it on our behalf. If anything here is unclear, please get in touch.
Atlis Rx provides Atlis Path, a collaborative platform for mapping treatment and patient journeys. For data you enter into the platform, your organization is the controller and Atlis Rx is the processor, acting on your instructions.
Your name, email address, the organization you belong to, and your permission level. If you sign in with Microsoft we also store the identifier Microsoft issues for your account and your organization’s tenant identifier, so we can recognise you on future sign-ins. We never receive your Microsoft password.
Blueprints, phases, roles, steps, pain points, comments, and any files or links you attach. This is your organization’s content and we do not use it to train models or share it with other customers.
If you use our contact form we keep your name, email, organization and message so we can reply.
We do not run advertising or third-party analytics trackers, and we do not sell data to anyone.
We set a single essential cookie to keep you signed in. It contains a signed session token and nothing else. Signing in with Microsoft also sets short-lived cookies that exist only for the few seconds of the sign-in exchange. We do not use advertising or tracking cookies.
We use the following subprocessors. Each is used only for the purpose described.
Application data is stored in the United States. If your organization requires data residency elsewhere, please contact us before starting.
We keep your organization’s content for as long as your account is active. On request, or when an agreement ends, we will delete it. Deletion in the platform is currently immediate and permanent, so please treat it with care.
Data is encrypted in transit and at rest by our infrastructure providers. Access within the platform is controlled by organization and permission level: content belonging to one organization is not readable by another. We are not currently certified against SOC 2 or ISO 27001, and we would rather tell you that plainly than imply otherwise.
Depending on where you are, you may have the right to access, correct, export or delete your personal data, or to object to its processing. Contact your organization’s administrator, or contact us and we will help.
If we change this policy we will update the date at the top. For material changes affecting existing customers, we will let you know directly.
Questions about this policy or about data handling can be sent through our contact form.