Atlayo
Legal hub AtlayoNET Terms EU Addendum
← AtlayoNET legal documents

AtlayoNET Privacy Policy

Last updated: 17 August 2026 · Effective: 17 August 2026

This policy explains how Atlayo Overseas s.r.o. processes personal data when you register AtlayoNET names, pay fees, run the tunnel agent, issue certificates, or visit AtlayoNET sites in the Atlayo Browser. It is the privacy notice for AtlayoNET, which is a separate service from the Atlayo chat app. If a translation differs from the English text, the English text is authoritative.

Contents
  1. Summary
  2. Who we are
  3. Data we collect
  4. How we use data
  5. Legal bases (GDPR)
  6. WHOIS and visibility
  7. Sharing and processors
  8. International transfers
  9. Retention
  10. Security
  11. Your rights
  12. Your origin (your website)
  13. Minors
  14. Cookies
  15. Changes
  16. Contact & DPO

1. Summary

  • Atlayo Overseas s.r.o. is the controller for AtlayoNET registry, billing metadata, pairing, gateway operation, certificates and WHOIS.
  • We need an Atlayo ID, the name you register, payment confirmation (via Stripe), and technical pairing data so the tunnel can work.
  • WHOIS may publish limited registrant and name data so others can see who holds a name.
  • We relay visits; we do not generally store the files of your origin website on the gateway.
  • We do not sell personal data.
  • EU/EEA users have GDPR rights — see section 11 and the EU Addendum.

2. Who we are

Data controller: Atlayo Overseas s.r.o., Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic
Company ID: 29645433 · VAT ID: CZ29645433
Parent company: Atlayo spol. s r.o. (Atlayo group)
Email: privacy@atlayo.com
Data Protection Officer: dpo@atlayo.com

3. Data we collect

3.1 Account and registry

  • Atlayo ID identifiers (for example subject, display name, and the hash/token used to bind a registration).
  • Registered name and ending, creation time, paid expiry, status (active, expired, deleted).
  • Portal login events and support messages about your names.

3.2 Billing

  • Payment amount, currency, time, Stripe customer/payment identifiers, and whether the charge succeeded.
  • Billing email or name Stripe provides to complete the purchase, where applicable.
  • Full card numbers are processed by Stripe, not stored by Atlayo.

3.3 Pairing and agent

  • Pairing public keys (for example Ed25519), pairing timestamps, and whether an agent is currently paired.
  • Agent version and similar technical fields needed to operate and secure the tunnel.
  • We do not need the content of websites sitting on your origin in order to pair the agent.

3.4 Gateway and visits

  • Hostname / SNI used to route a visit, gateway identifier, session timestamps, and volume or error counters.
  • IP addresses of the agent and, where logged, of the visiting Atlayo Browser — for routing, abuse handling and security.
  • We do not operate AtlayoNET as a general archive of page content. Payload may pass through a gateway in memory to relay the connection.

3.5 Certificates

  • Certificate requests, public certificates we issue, serial numbers, validity window, and revocation status.
  • You hold the private key on your origin; we should not receive that private key.

3.6 Browser lookups

  • When you use the Atlayo Browser, name lookups on AtlayoNET (including DNS-over-HTTPS to Atlayo resolvers) may create operational logs of queried hostnames, resolver IP and time.

3.7 Abuse and legal

  • Reports you or others send about a name or origin, and records we keep to handle them or to comply with law.

4. How we use data

We use AtlayoNET personal data to:

  • Allocate, renew, display and delete names in the registry.
  • Take payment and keep accounting and tax records.
  • Pair agents, issue and revoke certificates, and route visits to the correct origin.
  • Publish WHOIS as described in section 6.
  • Detect abuse, phishing, malware, infrastructure attacks and illegal activity.
  • Provide support and improve reliability.
  • Comply with law and valid legal requests — see Law Enforcement Guidelines.

5. Legal bases (GDPR)

PurposeLegal basis
Registry, pairing, certificates, tunnel routing you requestContract (Art. 6(1)(b))
Payment and invoicingContract / Legal obligation (tax and accounting)
Security, fraud, abuse, 90-day inactivity enforcementLegitimate interests (Art. 6(1)(f)) / Contract
WHOIS publication of limited registrant fieldsLegitimate interests (transparency and abuse handling) / Contract
Browser resolver logs (security and operation)Legitimate interests (Art. 6(1)(f))
Responding to authoritiesLegal obligation (Art. 6(1)(c)) where applicable

Where we rely on legitimate interests, we balance them against your rights. You may object as described in section 11; some processing is required to provide AtlayoNET at all.

6. WHOIS and visibility

The portal may show a public or semi-public WHOIS record for a name, such as the name itself, dates, whether an agent is paired, and a registrant display name or transaction reference. Do not put data in display fields that you do not want associated with the name.

Other AtlayoNET users who type your name in the Atlayo Browser will reach your origin if it is online; that is the purpose of the service, not a hidden disclosure by Atlayo of page content.

7. Sharing and processors

  • Stripe — payment processing, as an independent controller or processor according to the checkout flow.
  • Hosting and infrastructure providers — for the authority, gateways, portal and logs, under data-processing terms.
  • WHOIS visitors — limited fields described above.
  • Authorities — when required by law.
  • Professional advisers — under confidentiality, where needed.

We do not sell AtlayoNET personal data to advertisers or data brokers.

8. International transfers

We store and process data primarily in the European Union. If data is transferred outside the EU/EEA (for example a payment or infrastructure sub-processor), we use appropriate safeguards such as Standard Contractual Clauses (2021/914) and transfer impact assessments where required.

9. Retention

  • Registry row: for the life of the registration, then deleted or anonymised after expiry or the 90-day unpaired deletion, plus a short backup window.
  • Pairing keys and last-pair timestamps: while the name exists, and as needed to enforce the 90-day rule.
  • Billing records: as required by Czech accounting and tax law (typically several years).
  • Gateway / resolver logs: generally up to 90 days, longer if needed for security investigations or legal holds.
  • Certificates: until expiry or revocation, plus limited records of issuance/revocation.

10. Security

Pairing uses cryptographic keys and tokens. Gateways use encrypted sessions (typically QUIC/TLS). You must protect your Atlayo ID, pairing token, agent host and origin private keys. No online service is perfectly secure; report suspected compromise to privacy@atlayo.com or legal@atlayo.com.

11. Your rights

If GDPR applies, you may have the right to access, rectify, erase, restrict, object, or receive a portable copy of data you provided, and to lodge a complaint with a supervisory authority — see the EU Addendum.

Exercise rights via in-app Settings → Privacy or privacy@atlayo.com. We may verify your identity (including via Atlayo ID) before responding. Erasure of a registration will usually release the name.

12. Your origin (your website)

If you collect personal data on the site or service you host behind AtlayoNET, you are the controller of that processing (unless you identify another controller). You must provide your own privacy information to those visitors. Atlayo is not the host of that content in the ordinary hosting sense and is not the controller of forms, analytics or accounts you run on the origin.

13. Minors

AtlayoNET is not directed at children under 16 in the EU/EEA without parental consent. See the Children’s Privacy Statement. Do not publish a child’s personal data in WHOIS or on an origin reachable via AtlayoNET.

14. Cookies

The domain portal may use essential cookies or local storage for login (Atlayo ID) and language. Payment pages may set cookies from Stripe. Non-essential analytics cookies are used only with consent where required.

15. Changes

We will post material changes on this page. If changes require new consent under law, we will obtain it before applying them to your data.

16. Contact & DPO

Atlayo Overseas s.r.o.
Company ID: 29645433
VAT ID: CZ29645433
File C 152275 at the Regional Court in Brno
Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic

Parent company: Atlayo spol. s r.o. (Atlayo group)
Privacy requests: privacy@atlayo.com
DPO: dpo@atlayo.com

© 2026 Atlayo spol. s r.o. Legal hub