Privacy Policy
ATMOSPHERIK INC.
Privacy Policy
Effective Date: September 30, 2026
Last Reviewed: September 30, 2026
Version: 3.5
Supersedes: Version 3.2 (September 9, 2026)
1. Introduction and Scope
Atmospherik Inc. ("Atmospherik," "we," "us," or "our") is a Delaware corporation and the AI company for new customer creation. We build and operate Rik, our AI system for performance marketing, and deliver it to business clients through our Rik Works full-service model, in which our own team operates Rik and executes campaigns on the client’s behalf. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with Rik and our related business operations.
We have written this Policy to describe what we actually do, not a narrower or more flattering version of it. Where our practices are evolving, we say so.
1.1 Services Covered
This Privacy Policy applies to:
- Our corporate websites, including atmospherik.ai, atmospherik.io, and related domains.
- Rik (including its memory and shared-evidence system, Borealis, described in Section 7) and the surfaces through which authorized users access it.
- Atmospherik’s Rik Works delivery, in which our own team operates Rik and executes campaigns on behalf of business clients.
- Marketing artifacts (briefs, proposals, simulations, audiences, and creative) and the data used to produce and activate them.
- Email, support, and business-development communications initiated by or directed to us.
Where this Policy names Atmospherik products (Rik, Rik Works, Borealis, RikID), the same treatment applies to versioned variants of those products, including numbered releases, generation labels, and successor names identified as such by Atmospherik.
1.2 What Rik Does, and What Atmospherik Does
It is important to be precise about the division of labor, because it shapes our data-handling commitments throughout this Policy.
Rik is Atmospherik’s AI system for new customer creation. Rik resolves and sizes audiences, produces briefs, proposals, simulations, and creative, applies confidence and compliance tagging, and compounds what it learns for each client inside that client’s private memory. Where authorized under our Borealis governance policy (Section 7), disclosure-reviewed aggregate evidence about campaign outcomes may inform Rik’s starting hypotheses for other clients; it never includes client-specific assets, offer economics, audience membership, or identifiers. Rik’s recommendations are reviewed by a human before any campaign goes live.
Atmospherik’s Rik Works team, our own personnel, executes approved campaigns on the client’s behalf. In a Rik Works engagement, our team operates the activation: pushing resolved, hashed audiences into channel platforms, deploying email and other messaging through third-party sending and activation providers, and managing the campaign through to measurement.
We want to be clear about two things this implies:
- Atmospherik is an active participant in execution, not merely an advisor. When we run a Rik Works campaign, we are processing personal information for activation, and we do so in the role defined by applicable law (processor or service provider), under our written client agreement, which includes data-processing terms.
- Atmospherik does not own the sending or media infrastructure. Email is sent, and media is delivered, through third-party platforms (our subprocessors) under the client’s contractual permissions. We operate those platforms on the client’s behalf; we do not run our own sending infrastructure. Where this changes, we will update this Policy before the change takes effect.
1.3 Geographic Scope (Today)
Rik currently operates in the United States only. We do not use Rik or Rik Works to build audiences of, or run campaigns directed to, individuals located outside the United States. Our websites are intended for persons and businesses located in the United States and for business visitors from the United Kingdom who want to learn about Atmospherik or request a demo (see Section 10.1). If we begin offering Rik in another jurisdiction, we will update this Policy before doing so.
1.4 Our Role as Controller and Processor
Depending on the activity, Atmospherik operates as:
- Controller when we collect personal information for our own business purposes, for example, when a prospective client visits our website, requests a demo, or corresponds with us.
- Processor / Service Provider when we process personal information on behalf of a business client pursuant to a written Master Services Agreement that includes data-processing terms. In those cases, including Rik Works campaign execution, the client is the controller and determines the purposes and means of processing.
Where applicable US state laws use a different term (e.g., "Processor" under VCDPA/CPA/CTDPA/MODPA), we honor the role and obligations defined by the controlling statute.
1.5 Data-Minimization Commitment
We collect and process only the personal information necessary to deliver Rik’s outputs, execute approved campaigns, and run our business. We review our collection practices on an ongoing basis, and we implement technical and organizational measures, including row-level security, role-based access control, hashed-identity standards, and an "injection, not export" doctrine (Section 4), to keep processing tight.
2. Information We Collect
This Section, together with Sections 3 (purposes), 5 (disclosure) and 6 (retention), serves as our notice at collection for California residents. Where we collect personal information through a form on our websites, a link to this Section appears at the point of collection.
2.1 Information You Provide Directly
When you visit our websites, request a demo, attend a meeting, or otherwise interact with us, you may provide:
- Name, business email address, phone number
- Company name, role, and business contact information
- Demographic or firmographic information you share in a conversation
- Free-text content you submit through a form or to our team
2.2 Information We Collect Automatically From Our Websites
When you interact with atmospherik.ai, atmospherik.io, or related domains, we may automatically collect:
- Device and Browser Information: IP address, browser type, operating system, screen size
- Usage Information: Pages viewed, links clicked, referring URLs, time on page, scroll depth
- Approximate Location: Country and region derived from IP.
- Precise Geolocation: We do not process precise geolocation by default. Where a feature requires it (for example, a location-aware form), we collect and process it only with your explicit opt-in consent, and we treat precise geolocation as sensitive personal information under Section 2.5.
- Cookies and Similar Technologies: As of the effective date of this Policy, our websites run no advertising cookies, pixels, or third-party tracking tags. We use a first-party, cookieless analytics service that anonymizes your IP address and does not load until you accept it, and we store a record of your cookie-banner choice. See Section 11 and our Cookie Policy.
We honor Global Privacy Control (GPC) signals as a valid opt-out of "sale" or "sharing" of personal information where required by applicable law.
2.3 Information We Receive From, and Process For, Business Clients
When a client engages Atmospherik through Rik Works, the client may share or grant us access to personal information about its customers, prospects, or campaign audiences, including:
- Hashed or plain-text contact identifiers (email, phone, postal address) for the client’s own marketing audiences
- First-party event data and CRM exports the client supplies to plan and run campaigns
- Read-only access to client data planes (e.g., Databricks or Snowflake) under the client’s authentication and authorization
We process such information as a processor, only for the purposes set out in the client’s service agreement, including its data-processing terms, and including resolving audiences, producing creative, executing the campaign through approved channels, and measuring results.
2.4 Information We Receive From Licensed Identity and Audience Data Partners
To build, size, and compose audiences, Rik reads from licensed third-party identity and audience-data partners. Our default consumer-graph and business-graph partners include providers of person-level and firm-level identity resolution operating under commercial agreements with Atmospherik. Our agreements with these partners require them to comply with applicable law in providing their data to us and, where a partner obtains data from other sources, to use commercially reasonable efforts to obtain assurances that those sources collected it lawfully. We apply the opt-out and suppression lists our partners make available to us. Categories obtained may include:
- Identity Data: Consumer and business identifiers compiled from publicly available sources, commercial data providers, and cooperative databases
- Demographic and Firmographic Data: Age, gender, marital status, education level, household composition (including the presence and age ranges of children in the household), business characteristics, professional attributes
- Behavioral and Interest Data: Purchase patterns, lifestyle indicators, voter registration status, political affiliation, donor behavior, inferred interests
- Contact Information: Email and postal addresses, phone numbers obtained through permissioned data partnerships
- Financial and Property Data: Estimated income, wealth, and credit indicators; home ownership and value; vehicle information
- Online Identifiers and Activity Data: Hashed email addresses, mobile advertising identifiers, IP addresses, device information, and interest or intent signals derived from website and mobile-app interactions
A current list of identity and audience partners is available on request at privacy@atmospherik.ai.
2.5 Sensitive Personal Information
We are deliberately restrictive about sensitive categories. We do not knowingly collect, process, or use the following for marketing purposes:
- Protected Health Information (PHI) as defined under HIPAA
- Nonpublic Personal Information (NPI) as defined under GLBA
- Consumer Health Data as defined under the Washington My Health My Data Act, Nevada SB 370, or analogous laws
- Biometric data for identification purposes
- Genetic data
- Precise geolocation without explicit consent
- Social Security numbers, government IDs, or financial account numbers
- Contents of private communications not directed to us
- Information concerning sex life or sexual orientation
- Religious or philosophical beliefs
- Trade union membership
- Citizenship or immigration status
- Personal information of known minors (see Section 13)
We may collect a small amount of sensitive personal information incidentally and only for security, fraud-prevention, and account-administration purposes, including authentication credentials, IP address (for fraud and abuse detection), and information necessary to verify a privacy request. We do not use such information to infer characteristics about you for advertising. Where California law applies, you have the right to limit the use and disclosure of sensitive personal information, see Section 9.1.
2.6 Information We Do Not Receive From Clients
Business clients should not transmit PHI, NPI, contents of private communications, or other sensitive personal information to Atmospherik. Clients in regulated verticals are responsible for their own HIPAA, GLBA, and analogous compliance programs.
3. How We Use Information
3.1 Planning and Execution
We use information to:
- Generate marketing artifacts (briefs, proposals, simulations, creative) for human review by the client
- Identify, size, and characterize audiences using licensed identity and audience-graph data
- Execute approved campaigns on the client’s behalf, including activating resolved audiences into channel platforms and deploying messaging through approved third-party providers
- Surface applicable regulatory considerations (CAN-SPAM, TCPA, CCPA/CPRA, HIPAA marketing provisions, etc.) inline for the client’s review
- Maintain suppression and do-not-contact lists used during planning and execution
- Measure campaign performance and write results back so that future planning compounds
- Improve the accuracy, relevance, and quality of Rik’s outputs
3.2 Automated Processing and Profiling
Rik uses automated systems as part of its function. Specifically:
- Audience composition models assemble candidate audiences from licensed identity data based on parameters supplied by the client.
- Confidence tagging is applied to each output so reviewers can see how trustworthy Rik considers a given recommendation.
- Compliance triage classifies outputs against a library of regulatory benchmarks and surfaces applicable considerations inline.
- Memory consolidation distills session content into structured atoms that compound across that user’s future sessions inside the client’s private memory. Any cross-client use is governed by Section 7 and requires explicit authorization.
These automated processes inform recommendations that are reviewed by a human before any campaign goes live. Because a human approves each campaign, including audience, creative, spend, and go/no-go, Rik itself does not make solely automated decisions about individuals. We assess, on a use-case-by-use-case basis and before deployment, whether a specific Rik output could produce legal or similarly significant effects on an individual. Where an assessment identifies a covered use case, we apply the notice and opt-out rights required by the controlling law before deploying it.
Where Rik draws on shared findings under the Borealis governance policy, those findings may inform a human-reviewed recommendation but do not authorize execution absent the client’s own operational approval.
3.3 Business Purposes
We also use information to:
- Communicate with prospective and existing business clients
- Operate, secure, and improve our websites, Rik, and Borealis
- Conduct internal analytics and develop new product capabilities
- Comply with legal obligations and enforce our agreements
- Detect, prevent, and address fraud, security incidents, and abuse
- Protect the rights, property, and safety of Atmospherik, our clients, our personnel, and the public
3.4 AI and Model-Training Posture
- Foundation models. We do not sell personal information to AI model developers.
- Rik and Borealis. We use operational telemetry (including latency, quality metrics, and benchmark statistics) derived from engagements to evaluate and improve Rik and Borealis, including Atmospherik-owned or Atmospherik-hosted components of Rik. Where any such signal is derived from client-attributable campaign outcomes rather than pure telemetry, it is produced only through the governed Borealis contribution pipeline described in Section 7, which includes disclosure-risk review addressing narrow cells and dominant contributors, not identifier removal alone.
- Client-specific models. Where a client engagement contemplates it, we build, tune, or fine-tune models specific to that client using the client’s data, under the client’s Master Services Agreement, including its data-processing terms. Client-specific models are logically isolated to the client’s engagement. We do not train, tune, or evaluate a client’s model on another client’s data, and we do not share, sell, or repurpose model weights across clients. Where a client has specifically authorized it in writing, disclosure-reviewed aggregate evidence about campaign outcomes may contribute to shared findings that inform Rik’s starting hypotheses for other clients, subject to the Borealis governance policy. Shared findings are evidence, not authority to execute, and never include client-specific assets, offer economics, audience membership, or identifiers.
- Licensed reach and measurement data. We use third-party licensed identity, audience, and measurement data to size audiences, compute reach, and calculate measurement and incrementality. Where licensed data is used as input to a client-specific model, it is used only for that client’s engagement. When we perform measurement or reach calculations that touch more than one client’s audience through a common identity graph, those calculations use hashed or otherwise pseudonymized identifiers and are engineered so that no client’s audience file is exposed to any other client. Separately, and governed by Section 7, specifically authorized aggregate campaign evidence may be contributed to Borealis’s shared-evidence layer and used to inform Rik’s starting hypotheses for other clients. No audience file, identifier, or client-specific asset is exposed to another client in that process.
- Prompts and identifier discipline. Personal identifiers are not placed into model prompts without a documented business need; where they are needed, they are minimized, hashed where possible, and logged for audit.
- No third-party training use. We do not license, sell, or otherwise make Rik outputs, client-specific model outputs, or Borealis shared-evidence findings available to any third party for use as training, fine-tuning, or evaluation data for that third party’s models. We further do not authorize any third party to use content published on our websites, including architectural, technical, or design documents relating to Rik or Borealis, to develop, promote, or market any product or service competitive with our offerings; those uses are addressed by our Website Terms of Use.
4. How We Handle Audience Data (the Injection Doctrine)
This section describes a specific, load-bearing privacy commitment in how Rik is built and how our Rik Works team runs campaigns.
4.1 Hashed-Identity Standard
Wherever a person-level identifier moves between Atmospherik and a downstream partner or platform, it is hashed using industry-standard one-way hashing (e.g., SHA-256) before transmission, except where a regulator or platform contractually requires a different format, and except that email addresses and telephone numbers are provided in plain text to the email and messaging providers that deliver client-approved messages, because a message cannot be delivered to a hashed address.
4.2 RikID, Internal, Persistent, Not Shared
Rik mints an internal identifier, RikID, used to correlate observations about a resolved individual across sessions and campaigns so that learning compounds over time inside the client’s private memory. RikID is persistent and postal-anchored, it is designed to remain stable for a given individual across engagements. RikID is not a marketing identifier exposed to advertising platforms, is not sold, and is not exposed in raw form to clients. It exists inside Atmospherik’s tenant-isolated infrastructure and is governed by row-level security. Where RikID relates to an identifiable individual, it is personal information subject to the rights described in this Policy.
4.3 Injection, Not Export
When a client approves a Rik-produced plan and our Rik Works team activates it, the resolved audience is pushed ("injected") into the channel platforms or partner systems through match APIs, it is not exported as a raw file to the buyer. The client sees lift, curve shape, and decile coverage; the platform sees a hashed-identity match; the resolved person-level file stays inside Atmospherik’s controlled environment. Where Atmospherik derives aggregate evidence from a resolved audience file for use in the Borealis shared-evidence layer, it does so only through the governed contribution pipeline described in Section 7. The underlying resolved file is not exported in any form. This is both a privacy commitment and an intellectual-property commitment. For campaigns that a reseller partner sells to its own customers and we execute on the partner’s data, campaign results (delivery, response, and opt-out records for the partner’s own records) are returned to that partner as the client of record.
4.4 Invite-Only Access
Rik is invite-only. There is no public self-service signup. Each user account is provisioned by an Atmospherik administrator, and every database table that holds personal, audience, or planning data enforces row-level security so users see only data they are authorized to access.
5. Information Sharing and Disclosure
5.1 With Business Clients
We share information with our business clients as necessary to deliver and execute the campaigns they have contracted for, including briefs, proposals, simulations, creative, activation, and measurement. Such sharing is governed by client service agreements that impose confidentiality, security, and data-protection obligations.
5.2 With Service Providers and Subprocessors
We engage service providers (subprocessors) to operate Rik, execute campaigns, and run our business, including:
- Cloud hosting and infrastructure providers
- Database and backend platform providers
- AI model providers used by Rik’s reasoning, classification, extraction, and synthesis tiers
- Identity-graph, audience-graph, and data-enrichment partners
- Email-sending, messaging, and media-activation platforms used to execute campaigns on a client’s behalf
- Communication, helpdesk, and analytics providers
- Security, fraud-prevention, logging, and monitoring providers
- Legal, accounting, and professional-services providers
Our service providers are engaged under written terms, and the subprocessors listed at atmospherik.ai/subprocessors are engaged under written data-processing terms. A current list of our website subprocessors, with the purpose and location of each, is published at atmospherik.ai/subprocessors and is updated when a subprocessor is added or removed.
5.3 With Data Partners
We obtain data from licensed identity and audience-data partners for resolution, enrichment, and suppression management. We return to those partners only what our agreements with them require: usage reports and, for campaigns a partner resells to its own customers, campaign results for the partner’s own records. All data-partner relationships are governed by written agreements that specify permitted uses, security requirements, and compliance with applicable laws.
5.4 For Legal and Safety Purposes
We may disclose information:
- To comply with applicable laws, regulations, legal process, or governmental requests
- To enforce our agreements, including investigation of potential violations
- To detect, prevent, or address fraud, security, or technical issues
- To protect against harm to the rights, property, or safety of Atmospherik, our personnel, our clients, or the public
5.5 Business Transfers
In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, personal information may be transferred to a successor or affiliate as part of that transaction. We will provide reasonable advance notice and continue to honor this Policy (or a successor policy that provides comparable protections) until the transition is complete.
5.6 Sale and Sharing of Personal Information
We do not sell personal information. Our websites. Our websites run no advertising technologies, and we do not sell or share personal information collected through our websites. Rik and campaign activation. When our team pushes a client’s hashed audience into an advertising platform, we do so on the client’s behalf and only through platform settings that limit the platform’s use of the audience to the requested match. We do not treat that activity as a sale or sharing by Atmospherik. Contributions to the Borealis shared-evidence layer, as described in Sections 3.4 and 7, are governed by written client authorization, use disclosure-reviewed aggregate evidence rather than personal identifiers, and are not treated as sales; where a specific contribution scenario raises a "sale" or "share" question under a controlling statute, we resolve that question in favor of the more protective treatment before contribution occurs.
6. Data Retention
We retain information only as long as needed for the purposes described in this Policy, unless a longer period is required or permitted by law. Our standard retention periods are:
| DATA CATEGORY | RETENTION PERIOD | BASIS |
|---|---|---|
| Distilled "memory atoms" derived from sessions | Until deletion is requested or the originating account is closed | Continuity of planning value across sessions |
| Per-user preference memory (Borealis user-memory) | Until the user deletes it or the account is closed | Personal control over personalized memory |
| Shared-evidence findings contributed under the Borealis governance policy | Retained and versioned per finding; withdrawal handled per contract as described in Section 7 | Governed contribution and evidence lifecycle |
| Campaign and planning artifacts (briefs, proposals, simulations, creative) | Length of the client engagement plus 3 years | Client contract + dispute period |
| Audience composition records | 13 months | Industry standard + consent-refresh cycle |
| Cookie-banner consent record | 13 months | Industry standard; see Cookie Policy |
| Suppression / opt-out lists | Indefinite | Ongoing compliance obligation, used only to honor opt-outs |
| Website analytics | 13 months | Standardized with the cookie-banner consent record; analytics are aggregated and cookieless |
| Website inquiries and demo requests (contact-form submissions) | 13 months | Responding to inquiries and related business correspondence |
| Security logs | 13 months | Security and incident response |
| Client contract records | 7 years | Tax + legal requirements |
When the applicable period ends, we securely delete or anonymize the information unless retention is required for ongoing legal proceedings, regulatory investigations, or other binding obligations.
7. Memory, Profiling, and the Borealis Layer
Rik’s memory and shared-evidence system, Borealis, is the architecture that lets Rik compound learning across sessions and, under authorized conditions, across clients. We disclose it explicitly because we believe users and clients should understand how their interactions are remembered.
- Two-part architecture. Borealis operates a private memory layer that is scoped to each client and its authenticated users, and a shared-evidence layer that carries authorized, disclosure-reviewed aggregate findings across clients. The private memory maintains three classes of long-term content: semantic (benchmarks, definitions, structured knowledge), procedural (flows and prompt templates), and episodic (distilled session atoms and per-user preferences).
- Row-level security. Every Borealis read and write is scoped to the user’s authenticated identity. Personal memory is not visible to other users or other tenants.
- Right to be forgotten. Authorized users can view, edit, and delete their personal Borealis memory through the Rik Profile surface. Deletion requests are also accepted at privacy@atmospherik.ai; see Section 14.
- Governed contribution pipeline. Personal episodic atoms are not promoted to shared memory except through a governed contribution pipeline that verifies contribution rights, reviews the release for disclosure risk (including narrow-cell and dominant-contributor risk, not identifier removal alone), and applies the promotion criteria set by our Borealis governance policy. Where a shared finding is published, it is evidence used to inform recommendations, not authority to execute on any client’s behalf.
- Withdrawal doctrine. A client may withdraw authorization for future contributions to the shared-evidence layer at any time. Withdrawal controls future use going forward; it does not retroactively erase findings that other clients or Rik surfaces have already consumed. The distinction is described further in the applicable client agreement.
8. Your Rights and Choices
Every control described in this Section is reachable from Your Privacy Choices, a link that appears in the persistent footer on every page of atmospherik.ai. You do not need to scroll through page content, dismiss an animation, or return to the homepage to reach it. Your Privacy Choices links to this Policy, our Cookie Policy, and our Website Terms of Use, and contains the "Do Not Sell or Share My Personal Information" request form, which we operate as a universal US opt-out (Section 9), and a button that reopens our cookie banner. We also honor Global Privacy Control site-wide.
8.1 Opt-Out of Marketing Communications
You may opt out of our marketing emails at any time by using the unsubscribe link in any such email or by contacting privacy@atmospherik.ai. Transactional and administrative communications may continue where they relate to a service you receive.
8.2 Interest-Based Advertising Opt-Outs
You may opt out of interest-based advertising through industry mechanisms:
- Digital Advertising Alliance: optout.aboutads.info
- Network Advertising Initiative: thenai.org/how-to-opt-out
- DAA AppChoices (mobile): youradchoices.com/appchoices
8.3 Mobile Device Controls
Your mobile device may offer settings to limit ad tracking or reset your advertising identifier (e.g., "Allow Apps to Request to Track" on iOS, "Ads Personalization" on Android).
8.4 Global Privacy Control and Do Not Track
We honor Global Privacy Control (GPC) signals as a valid opt-out of "sale" or "sharing" where required by law. We do not currently respond to browser "Do Not Track" headers because no industry consensus on their meaning exists; please use the opt-outs above.
8.5 Rik Account Memory Controls
If you have a Rik user account, you may view, edit, and delete your personal Borealis memory through the Rik Profile surface, including the ability to clear individual memory rows, clear by type, or clear all. Deletions are honored subject to any overriding legal-retention requirement (Section 6).
9. United States State Privacy Rights
We honor all applicable state privacy rights. The universal opt-out mechanism described in Section 8 and on our Your Privacy Choices page (atmospherik.ai/privacy-choices) is available to every US visitor, not only residents of states that require it: submitting the universal opt-out, or sending a Global Privacy Control signal, stops the sale or sharing of your personal information, the use of your personal information for targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects, site-wide.
The list below identifies the additional state-specific rights that go beyond the universal opt-out and is current as of the effective date of this Policy. It includes comprehensive state privacy laws now in force and states with confirmed near-term effective dates.
9.1 California (CCPA / CPRA)
California residents have the right to:
- Know the categories and specific pieces of personal information we have collected, the sources of collection, the business purposes, and the categories of third parties with whom we share information.
- Delete personal information we have collected, subject to statutory exceptions.
- Correct inaccurate personal information.
- Opt out of Sale or Sharing of personal information, including for cross-context behavioral advertising. You may exercise this right through Your Privacy Choices, via GPC, or by contacting us. Where applicable, a "Do Not Sell or Share My Personal Information" link is available on our website.
- Limit the Use and Disclosure of Sensitive Personal Information to purposes necessary to provide the goods or services you requested. We do not use or disclose sensitive personal information for purposes that would require this control; if that changes, we will post a "Limit the Use of My Sensitive Personal Information" link before doing so.
- Non-Discrimination for exercising privacy rights.
Our disclosures regarding sale and sharing appear in Section 5.6. In the preceding 12 months we have collected the categories of personal information described in Section 2, for the purposes described in Section 3, from the sources described in Section 2, and have disclosed them for business purposes to the categories of recipients described in Section 5.
9.2 Virginia (VCDPA)
Virginia residents have rights to access, correct, delete, obtain a portable copy of, and opt out of targeted advertising, sale, and certain profiling decisions.
9.3 Colorado (CPA)
Colorado residents have rights to access, correct, delete, obtain a portable copy of, and opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects.
9.4 Connecticut (CTDPA)
Connecticut residents have rights to access, correct, delete, obtain a portable copy of, and opt out of targeted advertising, sale, and profiling.
9.5 Utah (UCPA)
Utah residents have rights to access, correct, delete, obtain a portable copy of, and opt out of targeted advertising and sale.
9.6 Other States With Comprehensive Privacy Laws Now in Force
Residents of the following states have the rights described below and may exercise them through the same universal opt-out and the same request mechanisms as California and Virginia residents. In force as of the effective date of this Policy:
Texas (TDPSA, effective 7/1/2024), Oregon (OCPA, effective 7/1/2024), Montana (MCDPA, effective 10/1/2024), Delaware (DPDPA, effective 1/1/2025), Iowa (ICDPA, effective 1/1/2025), Nebraska (NDPA, effective 1/1/2025), New Hampshire (RSA 507-H, effective 1/1/2025), New Jersey (NJDPA, effective 1/15/2025), Tennessee (TIPA, effective 7/1/2025), Minnesota (MCDPA, effective 7/31/2025), Maryland (MODPA, effective 10/1/2025), Indiana (Ind. Code art. 24-15, effective 1/1/2026), Kentucky (KCDPA, effective 1/1/2026), Rhode Island (DTPPA, effective 1/1/2026).
Residents of these states have the rights to access, delete, correct (except in Iowa), and obtain a portable copy of their personal information, and to opt out of sale, targeted advertising, and (except in Utah and Iowa) profiling in furtherance of decisions producing legal or similarly significant effects. Sensitive personal data is processed only with opt-in consent in every state above except Utah and Iowa, which use a notice-and-opportunity-to-opt-out model. Maryland separately prohibits the sale of sensitive personal data, and we do not sell sensitive personal data anywhere.
State-specific items we honor as of the effective date:
- Rhode Island. As of the effective date of this Policy, we do not sell personal information subject to the DTPPA to any third party.
- Texas. Atmospherik Inc. is registered as a data broker with the Texas Secretary of State under Chapter 510 of the Texas Business and Commerce Code. The following notice is required by Tex. Bus. and Com. Code sec. 510.004 and 1 Tex. Admin. Code sec. 106.5: THE ENTITY MAINTAINING THIS WEBSITE IS A DATA BROKER UNDER TEXAS LAW. TO CONDUCT BUSINESS IN TEXAS, A DATA BROKER MUST REGISTER WITH THE TEXAS SECRETARY OF STATE (TEXAS SOS). INFORMATION ABOUT DATA BROKER REGISTRANTS IS AVAILABLE ON THE TEXAS SOS WEBSITE. Texas residents may exercise their rights under the Texas Data Privacy and Security Act (Chapter 541) — to access, correct, delete, and obtain a copy of their personal data, and to opt out of the sale of personal data, targeted advertising, and certain profiling — through the Your Privacy Choices page, by email to privacy@atmospherik.ai, or as described in Section 14; appeals are described in Section 14.3. Where applicable, we display the verbatim notices required by Tex. Bus. and Com. Code sec. 541.102 at the point of collection. As of the effective date of this Policy, Atmospherik does not engage in the sale of sensitive personal data or biometric personal data.
- Montana. Our privacy notice is reachable from a conspicuous hyperlink using the word "privacy" on our homepage, and our opt-out mechanism is reachable outside the privacy notice through the persistent-footer "Your Privacy Choices" link, in line with MCA sec. 30-14-2812.
- Delaware, Connecticut, Oregon, Maryland, Nebraska. A clear and conspicuous opt-out link is posted in the persistent footer on every page of atmospherik.ai.
Data Protection Assessments. Colorado and Connecticut both require a documented data protection assessment before we engage in targeted advertising, sale, or profiling that presents a heightened risk of harm to consumers, and before processing sensitive data. Atmospherik will complete and document any required assessment before engaging in a covered processing activity.
Universal Opt-Out Mechanism. As of the effective date of this Policy, we honor Global Privacy Control site-wide. Statutory duties to recognize a universal opt-out preference signal are in force in California, Colorado (7/1/2024), Connecticut (1/1/2025), Texas (1/1/2025), Montana (1/1/2025), New Hampshire (1/1/2025), New Jersey (7/15/2025), Minnesota (7/31/2025), Maryland (10/1/2025), Delaware (1/1/2026), and Oregon (1/1/2026); Vermont (1/1/2028) will follow when its law takes effect.
Enacted, Not Yet in Force. Oklahoma (SB 546, effective 1/1/2027), Louisiana (SB 386, effective 1/1/2027), Alabama (HB 351, effective 5/1/2027), and Vermont (Act 145 / S.71, effective 1/1/2028) will add residents to the universal opt-out and to the rights described above when their statutes take effect. We will update this Policy on or before each effective date.
Maryland (MODPA) note. MODPA imposes the strictest data-minimization standard among current US state laws and broadly prohibits the sale of sensitive personal data. We do not sell sensitive personal data, and our processing of Maryland residents’ data is limited to what is reasonably necessary and proportionate to provide the product or service requested.
9.7 Consumer Health Data Laws (Washington MHMDA, Nevada SB 370, Connecticut)
We do not knowingly collect or process "consumer health data" as defined by the Washington My Health My Data Act, Nevada SB 370, or analogous regimes. Clients in healthcare-adjacent verticals are responsible for their own compliance and should not transmit consumer health data to Atmospherik.
9.8 How to Submit a State Privacy Request
See Section 14. We verify identity proportionate to the sensitivity of the request. Authorized agents must provide written proof of authorization.
10. Visitors Outside the United States
10.1 Visitors in the United Kingdom
This Section applies to personal data we collect about individuals in the United Kingdom through our websites, demo requests, product demonstrations, and related business correspondence, for example when someone at a UK business contacts us or requests a demo. Atmospherik Inc. is the controller of that personal data. Where the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 apply to that processing, this Section describes how we handle it and the rights you have. Rik and Rik Works are not offered in the United Kingdom, and we do not use Rik to process personal data of individuals in the United Kingdom.
What we collect. The information you give us described in Section 2.1 (such as your name, business contact details, company, role, and the content of your inquiry) and the website information described in Section 2.2.
Why we use it, and our legal bases.
- Responding to your inquiry, arranging and conducting demos, and related business correspondence: our legitimate interest in responding to people who contact us and in developing business relationships (UK GDPR Article 6(1)(f)).
- Sending you information about our products and events: our legitimate interests or, where the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) require it, your consent. We send marketing email to individuals, sole traders, and partnerships only with their consent or where PECR otherwise permits it, and every marketing email includes a free and simple way to unsubscribe.
- Website analytics: your consent, given through our cookie banner (Article 6(1)(a)). Our analytics service does not run unless you choose "Accept."
- Operating and securing our websites, including server logs and the record of your banner choice: our legitimate interest in keeping our websites available and secure (Article 6(1)(f)).
- Complying with law and establishing, exercising, or defending legal claims: compliance with a legal obligation (Article 6(1)(c)) or our legitimate interests (Article 6(1)(f)).
Who receives it. Our service providers listed at atmospherik.ai/subprocessors, and others only as described in Sections 5.4 and 5.5. We do not sell personal data of UK visitors, and we do not provide it to our data partners or to advertising platforms.
Where it is processed. We are based in the United States and process UK visitors’ personal data in the United States. Our website analytics provider hosts its data in the European Union, and some of our service providers may process data in other countries.
How long we keep it. For the periods stated in Section 6.
Your rights. You have the right to access, correct, and erase your personal data, to restrict or object to our processing of it, and, where applicable, to receive it in a portable format. You may object at any time to our use of your personal data for direct marketing, and if you do, we will stop using it for that purpose (UK GDPR Article 21(2)–(3)). Where we rely on your consent, you may withdraw it at any time; withdrawal does not affect processing that took place before it. To exercise any of these rights, email privacy@atmospherik.ai or use the unsubscribe link in any marketing email. We will respond within one month, which we may extend by up to two further months where necessary because of the complexity or number of your requests; if we extend, we will tell you why within the first month (UK GDPR Article 12A).
Complaints. If you have a concern about how we handle your personal data, please contact us first at privacy@atmospherik.ai. We will acknowledge your complaint within 30 days and respond without undue delay (Data Protection Act 2018, section 164A). You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).
Other information. Providing personal data to us is voluntary, but we need your contact details to respond to your inquiry or arrange a demo. We do not make decisions about UK visitors based solely on automated processing.
10.2 Other Visitors Outside the United States
Other than as described in Section 10.1, our websites and services are intended for persons and businesses located in the United States, and we process personal information in the United States. We do not currently offer Rik or Rik Works outside the United States and, other than UK business visitors as described in Section 10.1, do not target individuals located outside the United States. If you contact us from outside the United States, the information you provide will be processed in the United States as described in this Policy. If we begin offering Rik in another jurisdiction, we will update this Policy before doing so.
11. Cookies and Similar Technologies
As of the effective date of this Policy, our websites set no cookies other than a record of your cookie-banner choice, and run no advertising tags, pixels, session-replay tools, chat widgets, or A/B testing tools. Our web analytics service is first-party and cookieless, anonymizes your IP address, and does not load until you choose "Accept" on our banner; choosing "Reject" keeps it off. You can change your choice at any time from the "Your Privacy Choices" link in the footer of every page of atmospherik.ai.
The technologies we use fall into two categories:
- Strictly Necessary: the record of your banner choice and the server logs our hosting provider keeps to operate and secure the site.
- Analytics: aggregated page-view and referrer statistics from our cookieless analytics service, collected only after you accept.
If we add advertising, measurement, or other third-party technologies to our websites, we will update our Cookie Policy and this Section before the technology loads, list each provider at atmospherik.ai/subprocessors, obtain any consent that applicable law requires, and make the "Do Not Sell or Share My Personal Information" opt-out and Global Privacy Control effective against those technologies. Our Cookie Policy describes each technology in use and how long it retains data.
12. Industry-Specific Compliance
12.1 Healthcare
Atmospherik is not a HIPAA covered entity or business associate. We do not process Protected Health Information (PHI). Healthcare and Medicare marketing uses non-PHI demographic and interest data only. Healthcare clients are responsible for HIPAA compliance and for not transmitting PHI to Atmospherik. We similarly do not knowingly process "consumer health data" as defined by state health-data laws.
12.2 Financial Services
Financial-services marketing complies with the Gramm-Leach-Bliley Act (GLBA) in that Atmospherik does not process Nonpublic Personal Information (NPI). Financial-services clients are responsible for GLBA compliance, FINRA Rule 2210 review (where applicable), CFPB UDAAP standards, and TILA / Regulation Z disclosure requirements in their advertising.
12.3 Legal Advertising
Legal-advertising campaigns are delivered subject to applicable state bar advertising rules and ethics opinions. Content approval and jurisdiction-specific compliance are the responsibility of the law firm or legal-services provider.
12.4 Insurance
Insurance marketing complies with state insurance-commissioner advertising and marketing requirements; insurance clients are responsible for state-specific disclosures.
12.5 Telecommunications (TCPA / 10DLC)
Where a Rik Works campaign uses SMS or call-based channels, those channels are executed through third-party providers under the client’s registrations and consent records. We surface applicable TCPA, A2P 10DLC, and revocation-rule considerations, and we honor suppression and revocation instructions in the audiences we activate. The client remains responsible for maintaining lawful consent for the contacts in its audiences.
12.6 Children’s Advertising (COPPA)
We do not knowingly create audience segments designed to reach children, and we do not transact in child-directed inventory. See Section 13.
13. Children’s Privacy
Our services are designed for businesses and adults, not children. In the United States, the Children’s Online Privacy Protection Act (COPPA) governs the online collection of personal information from children under 13, and several US state privacy laws (including California, Connecticut, Maryland, and others) impose additional protections for minors under 16 or under 18.
We do not knowingly collect, use, or disclose personal information from any child covered by those laws. Consistent with the updated COPPA Rule, we additionally:
- Do not knowingly use child-directed inventory in campaigns;
- Do not knowingly create audience segments designed to reach children;
- Treat any identifier or contact information that we learn relates to a child as subject to immediate deletion;
- Honor parental rights and requests as required by the COPPA Rule and state-level laws raising protections for minors under 18.
If you believe we may have collected personal information from a child, please contact us immediately at privacy@atmospherik.ai. We will take prompt steps to delete it.
14. Contact Information and Privacy Requests
To submit a privacy request, exercise your rights, or ask a question about this Policy, please contact us:
Atmospherik Inc.
Attn: Privacy Team
5 Greenwich Office Park, Suite 100
Greenwich, CT 06831
United States
Email: privacy@atmospherik.ai
Privacy Portal: atmospherik.ai/privacy-choices
14.1 Response Times
We will respond to verifiable consumer requests within the timeframes required by the controlling law:
- CCPA / CPRA: 45 days, extendable by 45 days with notice
- Other US state laws: 45 days (or as the controlling statute requires), with extensions where permitted
- UK GDPR (see Section 10.1): one month, extendable by up to two further months where permitted
14.2 Verification
We may need to verify your identity before processing certain requests. The verification we require will be proportionate to the sensitivity of the data and the risk of unauthorized disclosure. Authorized agents must provide written proof of authorization, and we may contact the underlying consumer to confirm.
14.3 Appeals
Where required by state law (e.g., Virginia, Colorado, Connecticut, Texas), you have a right to appeal a denial of a privacy request. Appeal instructions will be included in any denial we issue. If you remain dissatisfied, you may contact the applicable state Attorney General.
14.4 Data Breach Notification
If we experience a personal-data breach, we will notify affected parties and regulators within the timeframes required by applicable law, including applicable US state-law timelines.
15. Data Security
We implement technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, and destruction, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security (RLS) enforced on every table that holds personal, audience, or planning data
- Three-tier authentication model (user JWT, service-role, admin) with role-based access control and multi-factor authentication on administrative accounts
- Audited configuration changes for sensitive system tables with full before/after snapshots
- Invite-only access, no self-service signup; new users are provisioned by administrators
- Secrets management through a managed vault, no hardcoded secrets in deployment SQL
- Regular vulnerability scanning, penetration testing, and security assessments
- Audit logging of system access and configuration changes
No method of transmission or storage is perfectly secure. We commit to addressing security incidents promptly and to notifying affected parties and regulators as required by law.
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or business operations. When we make changes, we will:
- Update the Effective Date and Last Reviewed date at the top of this Policy
- Provide prominent notice on our website for material changes
- Where required by law, obtain renewed consent before applying material changes
- Maintain an archive of prior versions, available on request
We review this Policy at least annually, even when no material changes are required.
Version 3.5 supersedes Version 3.2. A summary of the changes made in each version is available on request to privacy@atmospherik.ai.
17. Additional Disclosures
17.1 Regulatory Compliance Posture
Atmospherik’s outputs surface considerations under, and our operations are governed by, applicable advertising and marketing laws, including:
- CAN-SPAM Act
- Telephone Consumer Protection Act (TCPA), including FCC revocation and consent rules
- A2P 10DLC carrier registration framework
- FTC Act Section 5 (unfair or deceptive acts or practices) and the FTC Endorsement Guides
- FDA FDCA advertising provisions
- NAD Advertising Standards (BBB National Programs)
- FINRA Rule 2210, CFPB UDAAP, TILA / Regulation Z (financial services)
- HIPAA marketing provisions (healthcare; advisory-only, Atmospherik is not a covered entity)
- State insurance-code advertising frameworks
- Department of Education gainful employment regulations and the FTC Guides for Private Vocational and Distance Education Schools (for-profit education)
- COPPA (children)
- CCPA / CPRA and other US state privacy laws (see Section 9)
- UK GDPR, the Data Protection Act 2018, and PECR, for UK website visitors and business contacts (see Section 10.1)
17.2 Accessibility
If you need this Privacy Policy in an alternative format due to a disability, please contact us and we will work with you to provide accessible content. We are working toward WCAG 2.2 AA conformance for our privacy materials.
17.3 No Reliance / No Legal Advice
The compliance considerations Rik surfaces are advisory and informational. They are not legal advice and are not a substitute for review by qualified counsel or by the client’s compliance program. Architectural, technical, or governance documents Atmospherik publishes on its websites, including material relating to Borealis, describe proposed or in-development capabilities where they are so marked and are not commitments; use of Atmospherik products is governed by the applicable Master Services Agreement, order form, or statement of work.
18. Acknowledgment
By using our websites or services, or by interacting with campaigns delivered by Atmospherik, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services or provide us with personal information.
© 2026 Atmospherik Inc. All rights reserved.