Privacy Policy
Last updated: September 2026
1. General Information
The protection of personal data is important to ATL IT Consulting LLC (“ATL”, “we”, “us”, or “our”).
This Privacy Policy explains how we collect, use, store, and protect personal information when you visit our website, contact us, request information about our services, or otherwise interact with us.
ATL provides IT consulting and professional services to clients internationally, including Cloud consulting, SAP and SAP RISE-related services, IT project coordination, technical consulting, and AI and workflow automation.
Our processing of personal data is carried out in accordance with applicable data protection and privacy laws, including, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable U.S. federal privacy and data-security requirements, and applicable U.S. state privacy laws.
The identity and contact details of ATL IT Consulting LLC are provided in our Impressum / Legal Notice and are not repeated here.
2. Personal Data We Process
We process personal data only where necessary for operating our website, communicating with prospective and existing clients, providing our consulting services, maintaining business relationships, and fulfilling legal or contractual obligations.
Depending on how you interact with ATL, this may include:
- name and business contact information;
- company name and professional position;
- email address and telephone number;
- information submitted through our contact forms;
- information contained in correspondence with us;
- project requirements and information relating to requested consulting services;
- contractual and business relationship information;
- technical information generated when accessing our website, such as IP address, browser information, device information, date and time of access, and server logs; and
- other information you voluntarily provide in connection with an inquiry or consulting engagement.
Please do not submit passwords, authentication credentials, production-system credentials, sensitive personal data, or confidential client information through our general website contact forms.
3. Contact and Service Inquiries
When you contact ATL through our website, by email, telephone, or another communication channel, we process the information you provide in order to respond to your inquiry and, where applicable, discuss or establish a consulting relationship.
The information processed may include your name, company, business email address, telephone number, requested service, project requirements, and the contents of your communication.
For persons to whom the GDPR applies, the legal basis may be:
- Article 6(1)(b) GDPR, where processing is necessary to take steps at your request before entering into a contract or to perform an existing contract;
- Article 6(1)(f) GDPR, where processing is necessary for our legitimate interests in responding to business inquiries, developing business relationships, and operating our consulting business; or
- Article 6(1)(a) GDPR, where we specifically request your consent for a particular processing activity.
Information submitted in connection with an inquiry is retained only for as long as reasonably necessary to process the inquiry and any resulting business relationship, subject to applicable contractual, accounting, tax, compliance, and legal retention requirements.
4. Processing in Connection with Consulting Services
In the course of providing IT consulting services, ATL may receive or have access to personal data belonging to clients, their employees, contractors, customers, suppliers, or other individuals.
Depending on the circumstances, ATL may process such information as an independent data controller/business or as a processor/service provider acting on behalf of a client.
Where ATL processes personal data on behalf of a client, the processing is governed primarily by the applicable consulting agreement, statement of work, data processing agreement, and the documented instructions of the client.
Where required by applicable data protection law, appropriate contractual and organizational safeguards will be established between ATL and the client.
Clients remain responsible for ensuring that personal data provided to ATL for processing in connection with an engagement has been collected and disclosed lawfully and that appropriate notices, permissions, or other legal bases exist.
5. Cloud, SAP and Technical Environments
ATL’s consulting activities may involve access to Cloud platforms, SAP environments, IT infrastructure, project-management systems, development environments, or other technical systems controlled by our clients or their technology providers.
Any access to such environments is limited to what is reasonably necessary for the agreed consulting engagement and is subject to the applicable contractual, technical, security, and access-control requirements.
Where ATL acts as a processor or service provider, personal data contained in client systems is processed only for the purposes of performing the agreed services and according to the client’s documented instructions, except where otherwise required by law.
6. AI and Automation Consulting
ATL may provide consulting services involving artificial intelligence, process automation, workflow automation, or related technologies.
Personal data will not intentionally be submitted to an AI system as part of a client engagement unless such processing is appropriate for the agreed purpose and is permitted under the applicable contractual and legal framework.
Where third-party AI or automation platforms are used, their use may be subject to additional contractual, privacy, security, and data-processing requirements.
ATL does not use personal information submitted through its general website contact forms for the purpose of training publicly available artificial intelligence models.
Clients should not provide sensitive personal data, confidential production data, access credentials, or other restricted information for AI processing unless this has been expressly agreed and appropriate safeguards are in place.
7. Server Log Files and Website Security
When you access our website, our hosting or infrastructure providers may automatically process technical information required to deliver and secure the website.
This may include:
- IP address;
- date and time of the request;
- requested page or file;
- browser type and version;
- operating system;
- referring URL;
- device information; and
- technical status or error information.
This information may be processed to ensure reliable website operation, detect technical problems, prevent misuse, investigate security incidents, and protect our IT systems.
Where the GDPR applies, such processing is generally based on our legitimate interest in providing a secure, reliable, and technically functional website pursuant to Article 6(1)(f) GDPR.
Server and security logs are retained only for as long as reasonably necessary for operational, security, diagnostic, and legal purposes.
8. Cookies and Similar Technologies
Our website may use cookies or comparable technologies necessary for its technical operation, security, and functionality.
Technically necessary cookies may be used where they are required to provide a service requested by the visitor or maintain the security and functionality of the website.
If ATL uses analytics, marketing, advertising, or other non-essential tracking technologies that require consent under applicable law, such technologies will be activated only after the required consent has been obtained.
Where applicable, users may withdraw or modify their cookie consent through the cookie settings provided on the website.
Browser settings may also allow users to block or delete cookies. Blocking technically necessary cookies may affect certain website functions.
9. Service Providers and Recipients
ATL may use third-party providers to support the operation of its website and business.
Depending on the services used, these may include providers of:
- website hosting and infrastructure;
- Cloud computing;
- business email and communications;
- cybersecurity and IT administration;
- customer and project management;
- business productivity software;
- analytics, where enabled;
- accounting and professional services; and
- other technical services necessary for operating our business.
Personal data is disclosed to such providers only where reasonably necessary for the relevant service.
Where required by applicable law, ATL enters into appropriate contractual arrangements with service providers regarding confidentiality, data protection, security, and permitted processing.
ATL may also disclose information where required by applicable law, regulation, legal process, or lawful governmental request, or where necessary to establish, exercise, or defend legal claims.
10. International Data Transfers
ATL is a U.S.-based company providing services internationally. Personal data may therefore be processed in the United States or in other countries outside the country in which the individual is located.
Where personal data protected by the GDPR is transferred from the European Economic Area to a country that is not recognized as providing an adequate level of data protection, ATL will use an appropriate transfer mechanism where required.
Such mechanisms may include the European Commission’s Standard Contractual Clauses, an applicable adequacy decision, or another transfer mechanism recognized under applicable data protection law.
Where an applicable service provider participates in a legally recognized international data-transfer framework, that mechanism may also be used where appropriate.
11. Data Retention
ATL does not retain personal data longer than reasonably necessary for the purposes for which it was collected.
The applicable retention period depends on the type of information and the context in which it is processed.
In determining appropriate retention periods, we consider:
- the duration of the client or prospective client relationship;
- the purpose for which the information was collected;
- contractual requirements;
- applicable accounting and tax requirements;
- legal and regulatory obligations;
- applicable limitation periods;
- information-security requirements; and
- the establishment, exercise, or defense of legal claims.
When personal data is no longer required, it will be deleted, anonymized, or otherwise disposed of in accordance with applicable requirements.
12. Data Security
ATL takes reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
The measures applied depend on the nature of the information, the relevant processing activity, available technology, and the risks associated with the processing.
Where ATL accesses client systems as part of a consulting engagement, access is limited according to the agreed scope of work and applicable client security requirements.
Nevertheless, no electronic communication, Internet transmission, Cloud platform, or information-storage system can be guaranteed to be completely secure.
13. No Sale of Personal Data
ATL operates as an IT consulting and professional services company and does not sell personal data for monetary consideration as part of its ordinary business activities.
ATL does not use information submitted through its website contact forms for third-party cross-context behavioral or targeted advertising.
If ATL’s processing practices change in a way that constitutes a “sale,” “sharing,” or targeted advertising under an applicable U.S. state privacy law, ATL will implement the notices and opt-out mechanisms required by that law.
14. Privacy Rights
Depending on your location and the laws applicable to the processing of your personal data, you may have certain privacy rights.
These may include the right to:
- request information about whether and how your personal data is processed;
- obtain access to your personal data;
- request correction of inaccurate or incomplete information;
- request deletion of personal data;
- request restriction of certain processing;
- object to certain processing;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent;
- opt out of qualifying sale, sharing, targeted advertising, or profiling where applicable; and
- lodge a complaint with an appropriate privacy or data protection authority.
These rights are not absolute and may be subject to statutory exceptions, verification requirements, contractual obligations, or other limitations under applicable law.
Privacy requests may be submitted using the contact details provided in the Impressum / Legal Notice.
We may request reasonable information necessary to verify your identity and protect personal information from unauthorized disclosure.
15. Rights of Individuals in the European Economic Area
Where the GDPR applies, data subjects have the rights provided under Articles 15–22 GDPR, subject to the conditions and limitations established by law.
These include, where applicable:
- Article 15 – Right of access
- Article 16 – Right to rectification
- Article 17 – Right to erasure
- Article 18 – Right to restriction of processing
- Article 20 – Right to data portability
- Article 21 – Right to object
- Article 22 – Rights concerning certain automated individual decision-making
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Individuals also have the right to lodge a complaint with the competent data protection supervisory authority in the EEA country of their habitual residence, place of work, or place of the alleged infringement, where applicable.
16. Privacy Rights in the United States
Privacy rights in the United States vary depending on the state in which an individual resides and whether the relevant privacy law applies to ATL and the particular processing activity.
Where applicable, U.S. state privacy laws may provide rights to:
- know or confirm whether personal information is being processed;
- access personal information;
- correct inaccurate personal information;
- request deletion;
- obtain a portable copy of certain information;
- opt out of certain sales or sharing of personal information;
- opt out of targeted advertising or certain profiling;
- limit certain uses of sensitive personal information; and
- appeal certain decisions regarding privacy requests.
For example, where the California Consumer Privacy Act, as amended (“CCPA”) applies, California residents may have rights to know, access, correct, delete, opt out of qualifying sale or sharing, limit certain uses of sensitive personal information, and exercise their rights without unlawful discrimination.
ATL will honor rights provided by applicable U.S. privacy laws where ATL and the relevant processing activity are subject to those laws.
17. Automated Decision-Making
ATL does not currently use personal data collected through its public website to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning website visitors.
If such processing is introduced in the future, ATL will provide the information and rights required by applicable law.
This does not prevent ATL from providing consulting services concerning AI and automation technologies to its clients. Processing performed in client environments is governed by the relevant client engagement and applicable data-processing arrangements.
18. Children’s Data
ATL’s website and consulting services are directed toward businesses and professional users and are not intended for children.
ATL does not knowingly use its website to solicit personal information from children.
If we become aware that personal information relating to a child has been collected in circumstances contrary to applicable law, we will take appropriate steps to delete or otherwise lawfully handle that information.
19. Changes to this Privacy Policy
We may update this Privacy Policy when necessary to reflect changes to our website, consulting services, technologies, data-processing activities, or applicable legal requirements.
The version published on our website is the current version.
Where required by applicable law, material changes will be communicated through an appropriate notice.
