Your revenue, your customer list, your employee records — all of it stays on your own computer.
On your own computer. It is not copied, uploaded or moved. The team that builds ATLAS has no access to your data.
Raw records are never sent. Invoice lines, individual employee records and customer lists do not leave the premises. Only your question and the prepared summary figures are passed on.
If you prefer, the AI layer also runs entirely on your own machine. In that case nothing leaves at all — you do not even need an internet connection.
Role-based access. The production manager cannot see HR data; the operator sees only their own form.
If the cloud model is chosen, the API key lives on the server only; it is never embedded in the dashboard, the browser or the HTML.
Who entered which data and when, and who viewed what, is recorded. It can be used for audit and accountability purposes.
ATLAS is designed to make your obligations easier under Türkiye's Personal Data Protection Law No. 6698 (KVKK) — and, by the same architecture, under the EU General Data Protection Regulation (GDPR).
ATLAS runs on your company's own hardware. The personal data it processes — employee records, attendance and leave records, customer contact details — stays within your company's boundaries. It is not transferred to the team that builds ATLAS and it is not stored on third-party servers.
Keeping data inside the company removes one of the hardest problems in both KVKK and GDPR — cross-border data transfer — before it arises. Even if you choose the cloud-based AI option, no raw personal data is sent; only de-identified summary figures are passed on. If you want no personal data sent at all, you use the local model option — in which case data never leaves the machine.
ATLAS processes only the data the relevant department needs. It does not collect unnecessary data and does not read fields it has no use for.
Role-based authorisation is the technical implementation of the “access for authorised persons only” principle that both regimes require. The authorisation matrix is defined together with you during implementation.
Which data was entered and viewed, by whom and when, is recorded. That log can be used to support your audit and accountability obligations.
Because the data sits in your own system, you apply retention periods and erasure requests according to your own policy. There is no external provider to request deletion from and no process to wait on.
Please note: this text is for information only and does not constitute legal advice. Your company's compliance documentation (privacy notices, consent forms, records of processing, registry filings) should be prepared by your own legal counsel.