Who we are
Atlas is an AI revenue-retention agent offered under the ZeroOne brand. It is operated by its parent company, FIVESIX LTD (“Atlas”, “we”, “us”, “our”), with operations in Connecticut, United States, and Abuja, Nigeria — the legal entity and data controller responsible for the personal data described in this policy in respect of our own website and business operations.
We are governed by the Nigeria Data Protection Act 2023 (NDPA). Where we serve customers or handle data connected to the European Economic Area or the United Kingdom, we align our practices with the EU General Data Protection Regulation (GDPR) and extend the same core rights — access, rectification, erasure, portability, restriction and objection — to everyone we hold data about, regardless of location.
You can reach us at atlas@fivesix.io about anything in this policy.
Our two roles
How we handle data depends on whose data it is. It matters because it decides who you contact to exercise your rights.
For our website, demo requests, and running our business, we decide why and how data is processed. This policy is our commitment to you as controller.
For the sales and customer records our customers connect to Atlas, the customer is the controller and we act as their processor — we process that data only on their documented instructions to provide the service. If your data was given to a business that uses Atlas (for example, you are one of their distributors or customers), that business is your first point of contact; we will support them in responding to your request.
Data we collect
a. When you visit our site or request a demo
When you submit the demo form, we collect the details you provide and a small amount of technical data with the submission:
- You give us: your name, work email, company, the size band of the account base you serve, and any free-text message you write.
- Captured automatically with the submission: your IP address, browser user-agent string, and the date and time — used to prevent abuse of the public form and to understand where enquiries come from.
Our website sets no advertising or analytics cookies and runs no third-party tracking scripts (see Cookies).
b. Business data you connect to Atlas
When a customer connects Atlas to their sales system — a CRM, ERP, Odoo, QuickBooks, or a CSV/Excel export — we process the records needed to watch account activity. This can include the names and contact details of the customer’s own end-customers or distributors, order and invoice history, product lines, and revenue figures. Each customer’s data is isolated per organization; it is never pooled with, or exposed to, another customer. For this data we act as a processor.
c. WhatsApp and messaging agents
Atlas can operate over Slack and WhatsApp (via the Meta WhatsApp Cloud API). For customers who use the WhatsApp bookkeeping agent, we process the messages, phone numbers, and images of receipts or invoices sent to the agent. These are read to extract accounting entries, which are only written to the customer’s accounting system after a human confirms them. We do not use WhatsApp content for advertising or profiling.
d. Operator console & account data
Operators who log in to the Atlas console have account credentials (an identifier and a securely hashed password) and a session. We also process the queries operators type when they “ask their sales data” a question, in order to return an answer.
How we use data
We use personal data only for these purposes:
- To respond to you — reply to demo requests, set up pilots, and provide support.
- To provide the service — detect quiet accounts, generate recommendations and digests, answer questions about the connected data, and extract bookkeeping entries.
- To secure and operate the platform — authenticate operators, prevent abuse and fraud, keep audit trails, and troubleshoot.
- To improve Atlas — understand how features are used, in aggregate. We do not use customer business data to train third-party AI models.
- To meet legal obligations — accounting, tax, and lawful requests.
Legal bases
Where the GDPR or the NDPA requires a lawful basis, we rely on:
- Consent — when you submit the demo form or opt into messaging over WhatsApp. You can withdraw consent at any time.
- Contract — to deliver the Atlas service to a customer who has signed up or is in a pilot.
- Legitimate interests — to secure our platform, prevent abuse, and understand demand for the product, balanced against your rights.
- Legal obligation — where the law requires us to retain or disclose data.
AI processing
Atlas uses large-language-model AI to read questions, analyse account activity, and extract data from receipts and invoices. To do this, relevant text and images are sent to an AI provider, which processes them on our behalf and returns a result. We use two providers, each for a different part of the product:
- OpenAI — the “ask your sales data” chat assistant. Your question, and the sales records needed to answer it (which can include your customers’ or distributors’ names and revenue figures), are sent to OpenAI. It also produces the plain-English summaries shown alongside forecasts and anomalies, and the short titles and saved facts derived from your chat threads.
- Anthropic (the Claude API) — the WhatsApp bookkeeping assistant, which reads the receipt and invoice images and text you send and turns them into a draft accounting entry. It also writes the plain-English product-health notes in the console (product names, their health scores and coverage) and the guidance attached to upcoming local events (event details and your product lines).
Data sent to either provider is processed to return a result and is handled subject to that provider’s own API terms and privacy policy. We use their business APIs, and we do not send your data to OpenAI, Anthropic, or any provider for the purpose of training AI models. Decisions that carry financial consequence — such as posting an accounting entry — are never taken by AI alone; a person reviews and confirms them first (human-in-the-loop).
International data transfers
Some of our providers process data outside Nigeria — for example in the United States or the European Union. Where personal data is transferred across borders, we rely on appropriate safeguards, such as the providers’ Standard Contractual Clauses and their own adequacy commitments, so that your data keeps a comparable level of protection wherever it is handled.
Data retention
- Demo requests — kept while we are in contact and for a reasonable period after, then deleted or anonymised.
- Customer business data — kept for the life of the customer’s account and deleted after the service ends, per the customer agreement and their instructions.
- Operator accounts & logs — kept while the account is active; security logs kept for a limited period for audit and abuse prevention.
We keep data only as long as needed for the purpose it was collected or as the law requires, then delete or anonymise it.
Security
We protect data with encryption in transit (TLS/HTTPS), access controls and authentication for the console, per-organization isolation so one customer cannot see another’s data, hashed credentials, rate limiting on public endpoints, and human confirmation before any financially consequential action. No system is perfectly secure, but we work to keep the risk low and to respond quickly if something goes wrong.
Your rights
Under the NDPA and GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete.
- Erasure — ask us to delete your data (“right to be forgotten”). See Delete my data for the quickest route.
- Restriction & objection — limit or object to how we use your data.
- Portability — receive your data in a portable, machine-readable format.
- Withdraw consent — at any time, without affecting prior processing.
To exercise any right, email atlas@fivesix.io. We respond within the time the law allows (generally 30 days). If your data was connected to Atlas by a business that uses us, we will point you to that business, as they are the controller of it.
Cookies & similar technologies
- Public website — no advertising, analytics, or tracking cookies.
- Operator console — a single strictly-necessary session cookie to keep you signed in. It carries no tracking and is not shared.
- Fonts — our pages load typefaces from Google Fonts, which receives the visitor’s IP address to serve the font files. No cookie is set by this.
Children
Atlas is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy as Atlas evolves or the law changes. When we do, we revise the “last updated” date above, and for material changes we take reasonable steps to notify customers. Continued use of Atlas after an update means you accept the revised policy.
Contact & complaints
For any privacy question or to exercise a right, contact us:
If you are in Nigeria and believe we have not handled your data lawfully, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC). If you are in the EEA or UK, you may complain to your local data-protection supervisory authority. If you are in the United States, you may have rights under applicable state privacy laws, such as the Connecticut Data Privacy Act. We would appreciate the chance to resolve it with you first.
