Privacy
Last updated 16 September 2026. Neptune Atlas is a product of Neptune Labs.
These documents describe how the product actually works, clause by clause, against the code. They have not been reviewed by a lawyer. Neptune Labs holds no SOC 2 report and no ISO 27001 certificate, and nothing here should be read as claiming otherwise. Where a fact belongs in a legal document and this build cannot read it out of the code, it is left as a visible bracket rather than filled in with something plausible. Send this to your own counsel; that is what it is for.
Who is responsible, and for what
Neptune Labs operates Neptune Atlas. Which law applies to a given piece of data depends on whose it is, and this product holds four different populations. Saying so first is not pedantry: it decides who answers a request, and a notice that blurs it sends people to the wrong door.
People with a sign-in. A broker at a desk. Neptune Labs is the controller of the account relationship: your name, your work address, your sign-in history, your billing details.
People inside a desk's own data. A charterer's contact, a name in a fixture note, the sender of a circular, a master named on a statement of facts. The desk is the controller and Neptune Labs is a processor acting on its instructions. If you want to know what a desk holds about you, that desk answers; write to us and we will pass it on, and tell you we have.
People in the shared register. A ship manager whose name, role and address came off a vendor enrichment run or a published source. They have no relationship with anybody here and were never told. Neptune Labs is the controller, the basis is legitimate interests, and the register clause below is written for them specifically.
People who contacted us. A bug report, a marketplace enquiry, a telephone call to our own line. Neptune Labs is the controller and the basis is our interest in answering you.
Privacy requests: support@neptunelabs.ca, handled by [to be supplied: the name or role title of the person answering privacy requests, if it is not to be the support address]. There is no data protection officer; the product does not carry out the large scale monitoring that would require one, and appointing a title nobody holds would be worse than saying so. An EU or UK representative under Article 27 is [to be supplied: an EU Article 27 representative, or a recorded decision that Article 3(2) does not bite] and [to be supplied: a UK Article 27 representative, or the same recorded decision].
What we collect, why, and on what legal basis
Every purpose, what it holds, the lawful basis under the GDPR and how long it lives. Where the basis is legitimate interests you have an absolute right to object to direct marketing and a qualified right to object to the rest; see the rights clause.
Run your account
What is held
Your name, work e-mail, the desk name, your company website if you give one, and a password stored as an Argon2id hashLawful basis
Performance of a contract (Art. 6(1)(b))How long
While the account is liveTake payment
What is held
Billing e-mail, country, phone and a Stripe customer reference. Card brand and last four digits arrive inside Stripe's notifications to us and are not stored anywhere elseLawful basis
Contract (Art. 6(1)(b)) for taking the money; legal obligation (Art. 6(1)(c)) for keeping the recordHow long
7 years for the billing record, because a tax authority may ask about an invoice. Stripe's notifications, and the card brand and last four inside them, 90 daysKeep the account secure
What is held
Sign-ins, failed sign-ins, invitations, plan changes and key creation, each with the IP address and browserLawful basis
Legitimate interests (Art. 6(1)(f)): detecting and answering account compromiseHow long
2 years, then the IP address and browser are stripped and the fact of the event keptKeep a session alive
What is held
A refresh token, and the IP address and browser it was issued toLawful basis
Contract (Art. 6(1)(b))How long
90 days after the session it belongs to has expiredRun the desk
What is held
Everything you enter: positions, cargoes, fixtures, contacts, notes, documentsLawful basis
Your desk decides this and we act on its instruction. We are a processor here, not a controllerHow long
While the desk is live, then per the deletion clause belowShow a broker their own mail
What is held
An index of a connected mailbox: sender, recipients, subject, date, flags, and a 400 character previewLawful basis
Contract (Art. 6(1)(b)), on the instruction of the broker who connected itHow long
2 years, or immediately on disconnecting the mailboxRead mail sent to a desk's intake address
What is held
The message as sent, its sender, its subject and an excerptLawful basis
Processor, on the desk's instructionHow long
The stored message 180 days; the row, sender and excerpt stay with the deskRead a scanned statement of facts
What is held
The document as uploaded, and the transcription that comes backLawful basis
Processor, on the desk's instruction, at the moment a broker presses the buttonHow long
2 years for the cached readingAnswer the telephone at Neptune Labs
What is held
The number, the time, the duration, and where recording is on, audio, a transcript and a summaryLawful basis
Consent for the recording, and legitimate interests (Art. 6(1)(f)) in having a record of a call to our own support lineHow long
Audio 365 days by an S3 lifecycle rule; see the recording clause for the transcriptCheck that a desk is what it says it is
What is held
Certificates of registry, incorporation documents, management agreements, and the reviewer's notesLawful basis
Legitimate interests (Art. 6(1)(f)): a fleet claim and a broker badge are meaningless uncheckedHow long
7 years, as the evidence behind a decision we may have to explainAnswer a bug report
What is held
What you wrote, the screen you were on, and any screenshot you attachedLawful basis
Legitimate interests (Art. 6(1)(f)): answering somebody who asked us for helpHow long
Screenshots and our replies 2 years. What you wrote, 2 years once the report is closed; an open report keeps its description until it isKnow whether the product is working
What is held
Counts: how many searches, how many fixtures, when a desk was last activeLawful basis
Legitimate interests (Art. 6(1)(f)): knowing which desks are in trouble before they leaveHow long
2 years. Counts only. No address, vessel, rate or fixture is copied thereCount visits to the site
What is held
Pages, approximate location from IP, device, and when signed in your account and user numbersLawful basis
Consent (Art. 6(1)(a)), given through the banner and withdrawable at any timeHow long
Google Analytics retention, currently 14 monthsPut a broker in touch with a shipowner
What is held
Business contact details in the shared register: company address, switchboard, role addresses, sometimes a named individualLawful basis
Legitimate interests (Art. 6(1)(f)). See the register clause, which sets out the balanceHow long
2 years from last confirmation, and immediately on requestPost to the marketplace
What is held
The poster's desk name and country, the contact line on a listing, and the text of an enquiryLawful basis
Legitimate interests (Art. 6(1)(f)) in operating a board, on a deliberate act of publication by the posterHow long
2 years
Two things that are deliberately absent. We do not ask your browser for your location and there is no code in the product that could. We do not run an advertising network, do not build advertising profiles, and do not sell personal information to anybody.
Connected mailboxes
If you connect your own e-mail account, the mail itself stays with your provider. We store the credential encrypted, and an index of your messages so the list loads without waiting on your server: sender, recipients, subject, date, size, whether there are attachments, whether it has been read, and a preview of up to 400 characters of the opening text.
Message bodies are fetched by a background sweep, not only when you open a message. The sweep pulls bodies in batches of up to 150 a pass so it can tell a circular or a cargo enquiry from ordinary mail and offer it to the desk. The body is read and discarded; the 400 character preview is kept on every message, opened or not. The earlier version of this notice said a body was fetched when you open a message and is not retained. The second half was true and the first was not.
Where the mailbox is Microsoft 365 or Outlook.com, it is reached through an application Neptune Labs registered with Microsoft, under the Mail.Read and Mail.Send permissions you grant at sign-in, and Microsoft is named as a sub-processor for that reason. An IMAP mailbox at your own provider is a direct connection and adds nobody.
A connected mailbox is private to the person who connected it, including from the owner and administrators of the same desk, and that restriction is applied in the database query rather than by hiding a button. Disconnecting the mailbox deletes the credential and the entire index for it, and where the provider publishes a standard revocation endpoint the grant is handed back to them too. Microsoft does not publish one, so there the product tells you where to remove the application's consent yourself.
A mailbox will contain correspondence from people who never signed up for anything. We do not mine it, profile the senders, or use it for anything beyond showing you your own mail and finding the circulars in it; and only the messages you deliberately send into the desk become desk records.
Separately, a desk can be given its own intake address so brokers and owners can forward circulars and cargo enquiries straight to it. Mail sent there is addressed to the desk rather than to a person, so it is desk business from the moment it arrives. It is received by Amazon SES, queued, and stored. Nothing read out of it is ever accepted automatically: a person reviews and accepts it before it becomes a position or a cargo.
The document reader
This is the section the previous notice did not have, and its absence was the most serious of the gaps that rewrite closed.
When a broker imports a statement of facts, a PDF carrying its own text layer is read on our own machine and nothing leaves it. That path is always tried first because it is free.
A scan or a photograph is sent to Anthropic in the United States, whole, to be transcribed. A statement of facts is a port agent's log of a vessel's time in port. It names the vessel, the port, the charterer, the agent and the master, and it carries the master's handwritten remarks at the foot of the form. The reader is deliberately instructed to transcribe those remarks and to record the master's name, because a demurrage argument frequently turns on exactly that line. What comes back is stored against the laytime record so a broker can check it against the paper in their hand, and is kept for two years.
The same third party is used when a broker researches who owns or manages a hull. That research is about a ship rather than about a customer: the vessel's name and IMO number go, and the model uses a web search tool to look for published answers. Nothing from a desk goes with it.
We do not consent to customer content being used to train models. If that arrangement ever changes, this clause changes before the arrangement does.
Documents you upload to us
Two kinds of file reach Neptune Labs rather than the desk, and are read by our own people. Neither was mentioned in the previous notice.
Verification documents. To claim a hull into a fleet, or to be marked as a verified broking desk, a customer uploads paper: a certificate of registry, a document of compliance, a safety management certificate, a management agreement, a certificate of incorporation, a bill of sale. These are stored in our own shared database rather than in the desk's schema, and a Neptune Labs operator opens and reads them to make the decision. The basis is our legitimate interest in a verification mark that means something, and they are kept for seven years as the evidence behind a decision we may be asked to explain.
Bug report screenshots. A feedback report can carry pictures, and a screenshot of a screen in this product will usually contain live data: a cargo, a counterparty, an e-mail address, a rate. It is stored in the same shared database and is read by an operator answering the report. Kept for two years, and deleted sooner on request. Do not attach a screenshot you would not want a Neptune Labs engineer to read, because a Neptune Labs engineer is going to read it.
The marketplace
Cargo and open tonnage posted to the board are held in a schema shared across every desk on the platform, which is exactly what makes it a board. A listing is a snapshot copy of the fields the poster chose to publish, taken at the moment of posting, and never a live view onto a desk's own record.
Because a desk publishes it and other desks read it, Neptune Labs is closer to a controller here than a processor: we decide the board exists, who may read it, and how long a listing lives. What is published includes the posting desk's name and country and, unless the listing is anonymous, a contact line. The text of an enquiry between two desks passes through us and is stored.
Listings and enquiries are kept for two years. A listing can be withdrawn at any time, and a reported listing is reviewed by us.
Calls to Neptune Labs
The telephone line is our own and is not a feature a desk buys. The previous notice described it as something a desk uses, which it is not; it is gated to Neptune Labs staff and appears in no plan.
Calls run through Amazon Connect in Canada. We hold the number called or calling, the time and duration, and where recording is on, an audio recording, a transcript and a short summary. The transcript and summary are produced by Amazon Contact Lens, which analyses the recording automatically and labels who said what. That is automated processing of the contents of a conversation and it is named here for that reason.
The other party on a call is often not a customer of ours. Recording is announced before anything is recorded, and the announcement says that the call is transcribed and summarised. Press 9 during it and the call goes ahead unrecorded; if the announcement cannot be played, the call is not recorded either. A desk can tell us not to record any call from its people, and then no recording, transcript or summary is kept. If a call was recorded and you would rather it were not kept, say so and the call record, the recording and the transcript are deleted, whether or not you have an account with us. Audio is deleted after 365 days by a rule on the storage bucket. The call record, transcript and summary are held for 180 days.
Because this is our record of our own line rather than a desk's record, it lives in our shared database and is not deleted when a customer's desk is. The previous notice said recordings follow the desk and are deleted with it. That was not true in either half and this clause replaces it.
Who else touches it
Every company that receives personal data in the running of this service. They are used for the purpose listed and nothing else, none of them is permitted to use your data for their own ends, and the current list with its change history is published at neptuneatlas.com/subprocessors.
Amazon Web Services
What they do
The application and its Postgres databaseWhat reaches them
Everything in a desk, and every account recordWhere
Mumbai, India (ap-south-1)Amazon S3
What they do
Raw intake mail bodies, desk documents and attachments, call audioWhat reaches them
Mail as sent, files a desk uploaded, recordings of calls to usWhere
Mumbai, India for documents and attachments; call audio in Canada (ca-central-1); intake mail in a region not yet confirmedAmazon SQS
What they do
The queue a message sits in between arriving and being readWhat reaches them
The recipient token and a pointer to the stored messageWhere
Region not yet confirmedAWS Lambda
What they do
Two small functions on the telephony path: caller lookup, and collecting the transcriptWhat reaches them
A calling number, and a finished call's transcriptWhere
Canada (ca-central-1)AWS Amplify and CloudFront
What they do
Serving the site and its static filesWhat reaches them
Your IP address and the pages you asked forWhere
Global edge networkAmazon Simple Email Service
What they do
Sending e-mail we originate, and receiving mail sent to a desk's intake addressWhat reaches them
Verification codes, password resets, support replies, inbound mailWhere
Canada (ca-central-1)Amazon Connect
What they do
The telephone line Neptune Labs answers onWhat reaches them
Numbers, times, durations, and audio where recording is onWhere
Canada (ca-central-1)Amazon Contact Lens
What they do
Automated analysis of a recorded call: transcription, speaker labels, a summaryWhat reaches them
The words spoken on a call to or from Neptune LabsWhere
Canada (ca-central-1)Anthropic
What they do
Reading a scanned statement of facts, and researching a hull's ownershipWhat reaches them
The whole document as uploaded, including handwriting and namesWhere
United StatesMicrosoft
What they do
Graph and Entra ID, where a broker connects a Microsoft 365 or Outlook.com mailboxWhat reaches them
Listings and message bodies from that mailbox, under Mail.Read and Mail.SendWhere
United States and IrelandGoogle Programmable Search
What they do
Finding a shipping company's own website, so the register can hold a real addressWhat reaches them
A company name and a country. Nothing of a customer'sWhere
United StatesGoogle Analytics
What they do
Counting visits and which screens are used, once analytics is allowedWhat reaches them
Pages, approximate location from IP, device, and your account and user numbersWhere
United States and IrelandZoho Mail (Canadian data centre)
What they do
Our own mailbox, including the address every privacy request arrives atWhat reaches them
Anything you write to us, including a data subject requestWhere
CanadaStripe
What they do
Taking payment and holding card detailsWhat reaches them
Billing name, e-mail, address, country and the card itselfWhere
United States and IrelandOdoo S.A. (Odoo Online)
What they do
Our CRM: customer and prospect records, subscriptions, draft invoices, and the log of calls to our own telephone lineWhat reaches them
Desk and user names, work e-mails and telephone numbers, plan and usage counts, and notes and transcripts of calls to usWhere
Region not yet confirmed with OdooDatalastic
What they do
The vessel register, ownership records and AIS positionsWhat reaches them
Which hull or which sea area was asked for. No customer identityWhere
European UnionCloudflare
What they do
DNS for the domain and the www redirectWhat reaches them
The name your browser looked upWhere
Global edge networkOpenFreeMap and AWS Terrain Tiles
What they do
Map tiles, fetched by your browser when a chart is on screenWhat reaches them
Your IP address and the tile coordinates. Not who you areWhere
Global edge network
Not on that list, and why. Vendors we buy a dataset from rather than send data to: MagicPort's ownership export, an EU MRV import, and public registers. Equasis, which we query one hull at a time by IMO number with no customer information attached. Your own e-mail provider, where you connect an IMAP mailbox directly. Your own data vendor, where your plan lets you supply a key. Our CRM is not in this paragraph any more: it is Odoo Online, run by Odoo S.A., and it is in the list above. An earlier version of this notice said we ran it ourselves, which stopped being true in August 2026.
The two map tile services are on the list even though what reaches them is only your IP address and which square of the sea you asked for, because a request your browser makes to somebody else is exactly the thing you cannot find out for yourself.
Where it goes, and how the transfer is lawful
The application and its database run in Mumbai, India. If you are in the EEA or the UK, your personal data is therefore stored outside it, in a country with no adequacy decision. That is the material fact in this clause and it goes first.
The previous version of this notice said transfers were made under "the provider's standard contractual clauses". That was incoherent, because on the transfer that matters Neptune Labs is itself the importer: there is no provider whose clauses could cover it. The position we intend to rely on is standard contractual clauses offered to any customer who needs them as part of our data processing agreement, supported by an assessment of Indian law and the surveillance powers that could reach data held there. That position is under review by counsel and is not complete. Annex 4 of the data processing agreement says which parts are unsettled. Our own assessment of Indian law concludes that extra safeguards are needed and are only partly in place. Ask and we will tell you where each part stands.
Onward transfers to the companies in the list above are covered by their own clauses and, where they hold it, their EU-US Data Privacy Framework certification. Payment processing is in the United States and Ireland, analytics likewise, document reading in the United States, and e-mail and telephony in Canada.
Neptune Labs is a Canadian company, so PIPEDA applies to it directly, and the Office of the Privacy Commissioner of Canada is a supervisory authority for it. Data stored in India is subject to India's Digital Personal Data Protection Act 2023 as that statute is brought into force. Where two regimes both apply, we apply the stricter.
How long we keep it
Each of these is the number the code uses rather than a round one that reads well. Where a job does something narrower than the sentence used to claim, the sentence has been narrowed.
Your desk
How long, and what actually happens
Kept while the subscription is live. On cancellation it is marked for deletion and held for 30 days so an accidental cancellation is recoverable, then a daily check lists the desk as due and we run the deletion: the schema, its stored files, its mailbox connections, its users' personal data and the IP addresses on its audit records are removed, and a receipt is written recording what was deleted and what was kept.A connected mailbox's index
How long, and what actually happens
Two years, and immediately on disconnecting the mailbox. A message a broker deliberately attached to a fixture is their own work and is never aged out.Mail sent to a desk's intake address
How long, and what actually happens
The stored copy of the message is deleted after 180 days. The row survives with the sender, the subject, the date and a short excerpt, so the desk's review history stays answerable; it goes when the desk goes. This is narrower than the old wording, which said the mail was deleted.A reading of a scanned statement of facts
How long, and what actually happens
Two years for the cached transcription. Deleting the laytime record it belongs to removes it sooner.Call recordings and transcripts
How long, and what actually happens
Audio is deleted after 365 days by a lifecycle rule on the recordings bucket. The call record, its transcript and its summary sit in our own shared schema rather than in a desk, because a call from a stranger is the ordinary case and a closed account must not take the record of its own calls to us with it. They are kept for 180 days and deleted on request at any time.Verification documents
How long, and what actually happens
Seven years. They are the evidence behind a decision to grant a fleet or a broker badge, and a decision we cannot explain is worse than one we cannot revisit.Bug reports and their screenshots
How long, and what actually happens
Screenshots and our replies are deleted two years after they were made. The text of a report is removed two years after it was filed once the report is closed; a report still open keeps its description, because it is still being worked on.Security audit records
How long, and what actually happens
The IP address and browser are stripped after two years. The fact of the event is kept for the life of the account: an audit trail that quietly erases itself is not one.Register contacts
How long, and what actually happens
Two years from the last time the record was confirmed against its source, and immediately on request. An address that has been asked to be left alone goes onto a suppression list that survives the deletion, so the nightly vendor sync cannot restore it.Backups
How long, and what actually happens
A nightly database dump is kept on the same machine for 14 days, so data deleted from the live database can survive in a backup for up to 14 days. This page used to describe a second, offsite copy of our customer records under a 90 day lifecycle. No such copy is made by anything we run, and the sentence is withdrawn. Our CRM is Odoo Online, and Odoo S.A. backs it up on its own schedule, which we do not set.
How it is protected
Each desk lives in its own database schema, and on every request the application checks which desk the signed-in person belongs to before it reads one. That separation is enforced by the application rather than by a separate database login per desk. Passwords are hashed with Argon2id. Mail credentials, vendor API keys, second-factor secrets and other stored credentials are encrypted by the application with a key kept outside the database; that is not a claim that the database or its backups are encrypted as a whole, which we have not confirmed. Everything is served over TLS. Repeated failed sign-ins lock an account, and a reused session token invalidates the session it came from. Access to production is limited to the people who need it, and every destructive action taken through the application writes an audit record before it acts.
What we do not have. No SOC 2 report, no ISO 27001 certificate, no third-party audit programme. An independent penetration test in August 2026 produced 24 findings in the code, all of which are fixed and shipped, and six in the infrastructure, which are open. The largest of the open ones is that the nightly database backup is kept on the same machine as the database. Saying so is uncomfortable and is better than a security page that implies a certification nobody holds.
No system is perfectly secure. If a breach affects your data we will tell you and the relevant authority, promptly and with what we actually know rather than a holding statement.
Your rights
Where the GDPR or the UK GDPR applies to you, you have the right to:
- be told what we hold about you and get a copy of it (Article 15);
- have it corrected (Article 16);
- have it deleted (Article 17);
- have its use restricted while a dispute is resolved (Article 18);
- receive it in a portable form and have it sent to somebody else (Article 20);
- object to processing based on legitimate interests (Article 21(1)), including everything in the register clause above. We stop unless we can show compelling grounds that override your interests, and the burden of showing that is ours;
- withdraw consent at any time, which is as easy to do as it was to give and does not affect what was done before you withdrew it.
We do not make decisions about you by automated means that produce legal or similarly significant effects, so Article 22 does not arise.
Write to support@neptunelabs.ca. We answer within one month and will tell you inside that month if a request is complex enough to need longer, which the law allows by up to two further months. There is no charge for a reasonable request. If we refuse one we will say why and tell you how to complain.
If you are unhappy with how we have handled it you can complain to your data protection authority: in Canada the Office of the Privacy Commissioner, in the United Kingdom the Information Commissioner's Office, and in the EU your national supervisory authority. We would rather you came to us first, but that is your right and not conditional on it.
Your absolute right to object to direct marketing
This is stated on its own, apart from the list above, because the law requires it to be brought to your attention clearly and separately from everything else.
You may object at any time to our using your personal data for direct marketing, including any profiling connected with it, and when you do we must stop. There is no balancing test, we cannot argue, and no reason is required from you.
In practice: every marketing e-mail carries an unsubscribe link that works without signing in, and writing the word "stop" to support@neptunelabs.ca is enough. The address goes onto the platform-wide suppression list described in the register clause, which no desk on this platform can send through and which the nightly vendor sync cannot undo.
California privacy rights
This section is for California residents and is our notice at collection under the CCPA as amended by the CPRA. It is given at or before the point of collection by being linked from every page of the site.
Categories we collect, and why. Identifiers such as name, e-mail, IP address and account number, to run and secure your account. Customer records under Civil Code 1798.80(e) such as name, telephone number and billing address, to bill you. Commercial information such as your plan, your subscription and what you bought. Internet activity such as pages visited, screens used and sign-in history. Professional information such as your employer and your role, which is what the shared register holds. Inferences are not drawn and no protected classifications, biometrics or education records are collected.
Sensitive personal information. Two categories arise here and we would rather name them than let them hide inside a general statement. The contents of communications where we are not the intended recipient: your connected mailbox, mail sent to a desk's intake address, and the recording of a telephone call. And precise geolocation, not of you: we never ask your browser for your location, but a document a desk imports can place a named seafarer at a named berth at a named time, and a statement of facts routinely does exactly that.
Limit the use of my sensitive personal information. We use sensitive personal information only to provide the service you asked for and for the retention periods stated above. We do not use it to infer characteristics about you, and we do not disclose it for any purpose that would give rise to a right to limit under the statute. You may still tell us to limit it and we will honour that: write to support@neptunelabs.ca.
Do not sell or share my personal information. Neptune Labs does not sell personal information and has never sold it. We do not share it for cross-context behavioural advertising: there is no advertising network on this product and no advertising identifier is set. The only advertising-adjacent technology in the product is Google Analytics, whose advertising signals are switched off permanently rather than left to the banner. Global Privacy Control is honoured as an opt-out preference signal regardless.
Requests to know and to delete. Two channels, as the statute requires: write to support@neptunelabs.ca, or, for a copy of the personal data held about you, sign in and use Download a copy under Your personal data in Settings. A request to delete or correct is made by e-mail; there is no form for it in the product today. We verify identity against the account the request concerns, and where a request comes from somebody we have no relationship with we may need more information to be sure who you are. Requests are answered within 45 days, extendable once to 90 with notice to you. An authorised agent may act for you with written permission.
No discrimination. Exercising any of these rights does not change the price you pay, the plan you are on, the features you can reach, or the quality of what you get. We operate no financial incentive programme.
Changes
We will update this page as the product changes, and the date at the top is when it last moved. If a change materially affects how your data is handled we will e-mail the account owner rather than relying on you re-reading the page, and where the change touches anything you consented to, the consent question is asked again.
A new company in the list of who else touches your data is announced before it starts, not after; that is a commitment in the data processing agreement and the dated history is at neptuneatlas.com/subprocessors.
Contact
Questions, requests, or anything on this page that does not match what you have seen the product do: support@neptunelabs.ca.
By post: [to be supplied: a postal address for commercial e-mail, required by CAN-SPAM and CASL].