AtlasEQ
Product
Methodology
Data Constellation
Blog
Beta
Download the beta
Contact

Privacy

Privacy Policy

How we collect, use, and protect your personal data.

1. Overview2. Information We Collect3. How We Use Your Information4. Cookies & Analytics5. Data Sharing6. Data Security7. Data Retention8. Your Rights Under GDPR9. International Data Transfers10. Policy Updates11. Contact Us
0%
Effective September 16, 2026Version 6

1. Overview

AtlasEQ provides professional equity research software that aggregates financial data from official regulatory sources. This Privacy Policy explains how we handle your personal information across our website (atlas-eq.com) and desktop application.

Beta status: AtlasEQ is currently in closed beta. During this period the service is provided to a limited number of testers, features may change or be removed, and data associated with beta accounts may be reset before general release. We will notify beta users by email before any such reset.

Data Controller

AtlasEQ is a service operated by Matheo Menges, established in France. Matheo Menges is the data controller responsible for your personal data and is subject to the General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).

Matheo Menges (AtlasEQ)

France

Email: info@atlas-eq.com

Supervisory Authority

Our supervisory authority is the French Data Protection Authority (CNIL - Commission Nationale de l'Informatique et des Libertés):

CNIL

3 Place de Fontenoy, TSA 80715

75334 Paris Cedex 07, France

Website: www.cnil.fr

By using our services, you acknowledge that you have read and understood this policy. If you do not agree with our practices, please do not use our services.

Minimum Age

AtlasEQ is intended for professional and educational use by individuals aged 16 or over. We do not knowingly collect personal data from anyone under 16. If you believe a person under 16 has provided us with personal data, contact us at info@atlas-eq.com and we will delete it.

2. Information We Collect

2.1 Information You Provide Directly

When you interact with AtlasEQ, you may provide:

- Account Information: Email address, username, name and password when creating an account, together with any company, role or reason for requesting access that you choose to give us during signup

- Contact Form Submissions: Name, email, company name, and message content when contacting us

- Support Communications: Information shared when requesting technical support, including messages you send us through the in-app messaging feature

- Product Feedback: Responses to the in-app beta questionnaire, including ratings, written comments, and whether you are willing to speak with us

We do not currently process payments and collect no billing or payment card information. If paid plans are introduced, this policy will be updated before any payment data is collected.

2.2 Information from the Desktop Application

The AtlasEQ desktop application processes financial data locally on your device. We collect the following data from application usage:

- License Validation: Your account credentials to verify subscription status

- Error Reports: Crash reports and error logs. These include the technical traceback, your app version and operating system, and, where you are signed in, your account identifier and IP address, so we can follow up on a specific fault. They also include the random session identifier described below, so that a crash can be matched to the actions that preceded it. Network identifiers are erased after 90 days; the remaining technical report is deleted after 12 months.

- Feature Usage: A limited, fixed set of product events, linked to your account, so we can understand how the product is used and what to improve. Deleted after 12 months. The complete list is set out in section 2.3.

- Product Feedback: Responses to the in-app beta questionnaire, including your ratings, written comments and whether you offered a call. Linked to your account so we can follow up on what you report. Deleted within 12 months of the beta programme ending.

- Where your work is stored: Your research notes and portfolio data are stored locally on your device, and we do not have access to them unless you explicitly share them with us for support purposes. Saved screens, valuation models and scenarios are stored on our servers under your account, so that they are available when you sign in from another device.

- AI processing happens on your device: AI-generated summaries are produced by a model running locally on your own computer. The filings and text being summarised are not transmitted to us or to any third-party AI provider. If this changes in a future release, we will update this policy and tell you before it takes effect.

2.3 Product Usage Data: Exactly What We Record

We believe you should be able to read the full list rather than a general description, so this is all of it. The desktop application records only the following events, and nothing else:

- Application opened: your app version, operating system and its version, and whether you are running a packaged build

- Sign-in and sign-out, and how long the session lasted

- Which feature area you opened (for example: dashboard, screener, tracker, workspace, portfolio, research notes, tools, messaging, settings)

- That a search was performed, and whether it returned a result

- That a document was exported, its type, and its size

- Aggregate statistics about requests to our servers over each 30-second interval: how many were made, how many failed, and their average and maximum response time

- That an error message was shown to you, and which one

- That a local AI model was downloaded, or that a local AI model was run, and how long it took

- That the application checked for or installed an update

- That a subscription tier limit was reached

Each of these carries a session identifier: a random value generated fresh every time you launch the application. It is not derived from your device, your hardware or your account, it is never stored on your computer, and it cannot be used to recognise you across installations. Its only purpose is to group one session's events together.

What we deliberately do not collect

The following are never recorded, never transmitted and never stored on our servers:

- Which companies, tickers or securities you research. Opening a company dashboard records that the dashboard was opened, and nothing about the company you were looking at.

- What you type into search. We record only whether a search returned a result.

- The content of your research notes, portfolios, saved screens, valuation models or scenarios, except where you have explicitly saved them to your account so they follow you between devices.

- Keystrokes, screen contents, screenshots, mouse movement or session recordings.

- The contents of files you open, export or analyse.

- Any text you write anywhere in the application, other than messages and feedback you deliberately send us.

This is a design constraint, not only a policy commitment. The application can only send event types drawn from the fixed list above, and it discards any value that is not a simple number, true/false flag or short label, so free-form text cannot reach us by accident.

Turning it off

You can switch product usage collection off at any time in the application's settings, under Privacy. This does not affect your ability to use any feature. Crash reports, security records and the data needed to operate your account are handled separately and are described in their own sections.

2.4 Security and Authentication Records

To protect accounts against unauthorised access, our servers keep a record of authentication activity. This is separate from product usage data, is not affected by the usage setting described above, and cannot be switched off, because it is what allows us to detect and investigate an attack on your account.

We record:

- Sign-in attempts, whether they succeeded or failed, and the reason for a failure (for example an incorrect password, or an unrecognised username)

- The username submitted with an attempt, including where no such account exists, which is how we detect someone working through a list of guessed names

- Two-factor authentication attempts, and occasions where a security limit temporarily blocked further attempts

- Password reset and password change attempts. Where a reset is requested for an email address that has no account, we store only a partially masked form of the address (for example ma***@example.com), so that repeated targeting of one address is visible without us building a record of addresses that are not ours

- Sign-out, and the revocation of sessions

- The IP address, and the application or browser version, associated with each of the above

- Requests that were refused because they were unauthenticated, not permitted for your subscription tier, or exceeded a rate limit

- Where you are signed in, the application version and device description associated with each active session, so that you and we can tell your own sessions apart

We use this only to secure the service and investigate suspected unauthorised access. We do not use it to analyse your behaviour or build a profile of you. It is retained for 24 months and then deleted automatically.

2.5 Information Collected Automatically (Website)

When you visit our website and consent to analytics cookies, we collect:

- Pages viewed and navigation paths

- Time spent on each page

- Referral source (how you found us)

- General geographic location (country/region level)

- Device type, browser, and operating system

3. How We Use Your Information

We use your information for the following purposes:

Service Delivery

- Create and manage your account

- Provide customer support and respond to inquiries

- Deliver software updates and security patches

Product Improvement

- Understand which parts of the product are used, and which are not

- Identify and fix technical issues and performance problems

- Develop new functionality based on user needs and the feedback you send us

Communication

- Send transactional emails (account confirmation, password reset, security codes)

- Notify you of important service updates or security issues

- Follow up on feedback or fault reports you have sent us

- Provide product announcements (you can opt out of non-essential communications)

Legal & Security

- Comply with legal obligations

- Detect, investigate and prevent unauthorised access to accounts

- Protect against fraudulent activity and abuse of the service

- Enforce our Terms of Service

Automated Decision-Making

We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of GDPR Article 22.

4. Cookies & Analytics

4.1 Our Approach

When you first visit our website, a banner asks whether you accept analytics cookies. Until you accept, nothing is loaded from Google: no analytics script runs, no data is sent to Google and no cookies are set. If you decline, it stays that way. The website's fonts are served from our own servers, so browsing the site does not contact Google either.

The desktop application does not use cookies, does not use any third-party analytics service, and does not track you across other websites or applications.

4.2 Types of Storage We Use

- Local storage (cookieConsent): remembers your choice and the date you made it. Strictly necessary, so it does not require consent. We ask for your choice again after six months.

- Google Analytics cookies (_ga and _ga_ followed by an identifier): measure how the website is used. Set only if you accept, and they expire after 13 months at most.

4.3 Managing Your Preferences

You can change or withdraw your choice at any time from the Cookie settings link at the foot of every page of our website. If you withdraw your consent, measurement stops and the Google Analytics cookies are deleted from your browser. You can also block cookies in your browser settings.

4.4 Google Analytics

We use Google Analytics 4 to understand how our website is used. Google Analytics 4 does not log or store IP addresses. We have configured it so that:

- Google signals and ad personalisation are turned off, and your data is not used for advertising

- Analytics data is deleted automatically after 14 months

- Its cookies expire after 13 months at most

5. Data Sharing

We do not sell your personal information. We share data only in these limited circumstances:

Service Providers

We work with the following processors, who handle data on our behalf and are contractually obliged to protect it and use it only for the services they provide to us:

- OVHcloud (France) — hosting of our servers, databases and email. All account data, saved screens, valuation models, crash reports, product usage data, security records and feedback are stored here, within the European Union.

- Google Analytics (Google Ireland Limited) — website traffic analysis, loaded only with your consent.

We will update this list when a processor is added or replaced.

Product usage data and security records from the desktop application are never shared with any third party, and are never sent to an external analytics or logging service.

Legal Requirements

We may disclose information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers

If AtlasEQ is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

6. Data Security

We implement industry-standard security measures to protect your information:

- Encryption of data in transit (TLS/SSL)

- Secure password hashing

- Two-factor authentication on all accounts

- Encryption at rest of authentication secrets

- Limits on repeated password, reset-code and two-factor attempts, to prevent guessing

- Access controls limiting administrative access to personal data

- Recording and monitoring of authentication activity, as described in section 2.4

- Regular security assessments

- Hosting with a reputable European infrastructure provider

While we take reasonable precautions, no system is completely secure. We cannot guarantee absolute security of your data.

Data Breach Notification

If a personal data breach occurs, we will notify the CNIL within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will notify you directly and without undue delay, as required by Article 34.

7. Data Retention

We retain your personal information based on the following criteria:

- Account Data: Retained while your account is active, plus 30 days after deletion request

- Support Communications: Retained for 2 years to provide context for ongoing support

- Product Usage Data: Automatically deleted after 12 months

- Crash and Error Reports: IP address and browser/device identifiers erased after 90 days; the technical report deleted after 12 months

- Product Feedback: Retained for the duration of the beta programme and deleted within 12 months of its close

- Security and Authentication Records: Sign-in records, authentication events and administrative action logs retained for 24 months to investigate unauthorised access

- Expired Sign-in Codes and Tokens: Deleted 30 days after they expire

These periods are enforced automatically by a scheduled job, not by manual review.

Where we become subject to accounting or tax record-keeping obligations — for example if paid plans are introduced — the relevant records will be retained for the period the law requires, and this policy will be updated to say so.

You can request deletion of your personal data at any time (see Your Rights below). Where a security record concerns an attempt to access an account that we need to keep for the protection of that account or of the service, we may retain it for the remainder of its retention period; in that case it is disconnected from your account, and we will tell you when we respond to your request.

8. Your Rights Under GDPR

As a data controller established in the European Union, we are committed to upholding your rights under the General Data Protection Regulation (GDPR). You have the following rights:

- Right of Access — Request a copy of the personal data we hold about you (Article 15)

- Right to Rectification — Request correction of inaccurate or incomplete data (Article 16)

- Right to Erasure — Request deletion of your personal data ("right to be forgotten") (Article 17)

- Right to Data Portability — Receive your data in a structured, machine-readable format (Article 20)

- Right to Object — Object to processing based on legitimate interests or for direct marketing (Article 21)

- Right to Restriction — Request limitation of processing in certain circumstances (Article 18)

Right to Object to Product Usage Collection

Product usage data is collected on the basis of our legitimate interest in understanding and improving the product. You may object to this at any time, and you do not need to give a reason or contact us to do so: switching the setting off in the application's settings, under Privacy, gives full effect to that objection. If you prefer to exercise the right in writing, contact us at info@atlas-eq.com and we will disable it for your account and delete what has already been collected.

Right to Withdraw Consent

Where processing is based on your consent (such as analytics cookies, product feedback, or optional marketing communications), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. For AtlasEQ, the relevant authority is the CNIL (Commission Nationale de l'Informatique et des Libertés) in France. You may also lodge a complaint with the supervisory authority in your country of residence.

How to Exercise Your Rights

To exercise any of these rights, contact us at info@atlas-eq.com. We will respond within one month of receiving your request, as required by GDPR Article 12. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

We will verify your identity before processing your request. There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive.

Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

- Contract Performance (Article 6(1)(b)): Processing necessary to provide our services, manage your account, and fulfill our contractual obligations

- Legitimate Interests (Article 6(1)(f)): Product usage data, as described in section 2.3, for the purpose of understanding and improving the product; and security and authentication records, as described in section 2.4, for the purpose of protecting accounts against unauthorised access. We have considered your interests and rights in reaching this assessment: the usage data is limited to a fixed list of events, excludes what you research and everything you write, and can be switched off at any time; the security records are the minimum needed to detect an attack on an account and are used for no other purpose.

- Consent (Article 6(1)(a)): Analytics cookies, product feedback and optional marketing communications, which you can withdraw at any time

- Legal Obligation (Article 6(1)(c)): Processing required to comply with applicable laws

9. International Data Transfers

AtlasEQ is established in France, and our servers are hosted by OVHcloud in the European Union. Your account data, saved work, crash reports, product usage data, security records and feedback are stored within the European Economic Area (EEA) and benefit from the protections of GDPR and French data protection law.

Transfers Outside the EEA

The one processor that may transfer data outside the EEA is Google Analytics, and only where you have consented to analytics cookies. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place as required by GDPR Chapter V, including:

- EU-US Data Privacy Framework: Google LLC, which may process Google Analytics data in the United States, is certified under this framework, which the European Commission recognises as providing adequate protection

- Adequacy Decisions: Transfers to countries the European Commission has deemed to provide adequate data protection

- Standard Contractual Clauses (SCCs): EU-approved contractual terms that bind recipients to protect your data

- Additional Safeguards: Where necessary, supplementary measures to ensure equivalent protection

You may request information about the specific safeguards applied to transfers of your data by contacting us at info@atlas-eq.com.

Users Outside the EEA

If you access our services from outside the European Economic Area, please note that your data will be processed in accordance with GDPR and French law. By using our services, you acknowledge this processing.

10. Policy Updates

We may update this Privacy Policy periodically. When we make material changes:

- We will update the "Effective Date" at the top of this page

- For significant changes, we will notify you via email or a prominent notice on our website

- We encourage you to review this policy periodically

Continued use of our services after changes constitutes acceptance of the updated policy.

Changes in this version

This version adds section 2.3, which lists in full the product usage events the desktop application records and states what it deliberately does not record, and section 2.4, which describes the authentication and security records our servers keep. It also states the legal basis for each, and describes how to switch product usage collection off.

11. Contact Us

If you have questions about this Privacy Policy, want to exercise your data protection rights, or have concerns about our data practices, please contact us:

Matheo Menges (AtlasEQ)

France

Email: info@atlas-eq.com

Contact Form: atlas-eq.com/contact

We aim to respond to all data protection inquiries within one month, as required by GDPR.

If you are not satisfied with our response, you have the right to lodge a complaint with the CNIL or your local data protection authority.

Questions

Questions about how we handle your data? Contact us.

Cookies

With your consent, we use Google Analytics cookies to measure how the site is used. Nothing is sent to Google if you decline. You can change your choice any time from Cookie settings at the foot of the page. Learn more

Product

Overview Methodology Download Blog Documentation

Company

About Contact

Legal

Privacy Terms Cookie settings

AtlasEQ provides financial data and research tools for informational and educational purposes only and does not constitute investment, financial, legal, or tax advice. Data is aggregated from official sources and may contain errors or delays. Verify independently before making any decision. Some images, illustrations and visual elements on this site were created or edited with the help of generative AI. Use of this site is subject to our Terms of Service and Privacy Policy.

Follow

© 2026 AtlasEQ. All rights reserved.

Address

AtlasEQ8B rue Abel, 75012 Paris, France
AtlasEQ