URD ATLAS
OverviewAPIDocsWikiPlans
AccountGet Started
OverviewAPIDocsWikiPlansChainsExplorerAnalyst KitWorkflowsValidationStatusAboutTrack RecordThresholdsGlossaryFAQ
AccountGet Started
© 2026 Urd Atlas.
AboutLegalTermsPrivacy
No price data · No forecasts · No recommendations
Privacy Policy

How personal data is handled

This notice explains the controller, data categories, purposes, legal bases, processors, retention approach, security safeguards and rights that apply to Urd Atlas users.

1. Controller and contact

The data controller for Urd Atlas is MARTIN BALSTAD, organisation number 937 581 254, Norway.

Privacy, access, deletion, support and legal requests can be sent to support@urdatlas.com.

2. Scope

This notice applies to the public website, subscriber accounts, dashboard, authenticated JSON delivery, billing workflows, support communication and operational/security logging used to provide Urd Atlas.

Public blockchain observations published by Urd Atlas describe blockchain activity and are not collected in order to profile Urd Atlas customers.

3. Data categories

  • Account identifiers, email address and authentication-linked profile data.
  • Subscription, plan, billing-state and entitlement metadata.
  • API-key metadata such as key ID, non-secret prefix/last four characters, status and last-used information; full API-key secrets are not designed to be stored recoverably in plaintext.
  • Request and security metadata needed for delivery, rate limiting, abuse prevention, troubleshooting and incident response.
  • Support, privacy or legal correspondence that you choose to send.
  • Provider-side billing/payment data processed by Stripe; Urd Atlas does not store payment-card details directly.

4. Purposes and legal bases

Contract / steps at your request: account access, subscriber entitlements, API delivery, checkout, billing and customer-portal functionality are processed as necessary to provide the service you request.

Legitimate interests: bounded operational logging, service security, abuse prevention, rate limiting, reliability diagnostics and support investigation are processed to protect and operate the service, balanced against user privacy.

Legal obligation: billing/business records and disclosures may be retained or processed where Norwegian or other applicable law requires it.

Consent: Urd Atlas does not rely on behavioral-advertising consent to operate the product. If an optional feature later requires consent, that purpose should be stated separately rather than silently folded into this notice.

5. Authentication and billing

Clerk provides authentication and session handling. Stripe provides checkout, subscription billing, invoices and customer-portal functions. Their processing is also governed by their own privacy terms.

A current list of production providers and the principal data categories they handle is published at Subprocessors.

6. API access and security logging

Authenticated subscriber delivery requires API keys. Urd Atlas may process key identifiers, status, account linkage, request path, request ID, response status, timing and bounded client/request metadata needed for entitlement enforcement, security, rate limiting and customer support.

Ordinary operational evidence should not retain full API secrets, complete browser sessions, payment-card data, unbounded headers or unnecessary personal content.

7. Retention

Retention is tied to the operational/legal purpose rather than indefinite collection. Active account and entitlement records are kept while the account/service relationship is active and for a reasonable period afterward where needed for billing, dispute handling, security or legal records.

Billing references may be retained for the period required by applicable accounting/tax law. Security and request logs are kept only as long as reasonably needed for service operation, abuse investigation and incident evidence. Support correspondence may be retained while a matter is open and for a reasonable follow-up period.

Where a user has a valid deletion right, data that is not required for an overriding legal/security purpose should be deleted or de-linked after the request is verified.

8. International processing

Some service providers may process data in jurisdictions outside Norway or the EEA as part of their global infrastructure. Where GDPR transfer rules apply, the relevant provider/controller relationship must rely on an applicable transfer mechanism, such as an adequacy decision or contractual safeguards provided by the processor.

9. Security

Urd Atlas uses HTTPS delivery, authentication, entitlement checks, API-key hashing, route protections, rate limiting and provider-managed encryption controls as part of its security model. No internet service can guarantee absolute security.

More detail is available at Security and Responsible Disclosure.

10. Security incidents

Security incidents are assessed separately from ordinary service/data-freshness issues. Where GDPR or other applicable law requires notification to a regulator or affected individuals, Urd Atlas follows the applicable threshold and timing requirements and communicates the nature of the incident, likely consequences and mitigation where required.

11. Your rights

Depending on the applicable law and circumstances, you may have rights to access, rectification, erasure, restriction, objection and data portability, and to withdraw consent where consent is the legal basis.

Requests can be sent to support@urdatlas.com. Identity may need to be verified before account-linked information is disclosed or deleted.

You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority where applicable.

12. Advertising and profiling

Urd Atlas does not require behavioral advertising or sale of user profiles to provide the service. If analytics/diagnostics are used, their intended purpose is product operation, reliability, security and aggregate performance rather than advertising resale.

13. Related documents

See Terms of Service, Subprocessors, Security, Status and the Trust center.