AtmyBack to Atmy

Legal information · GLOBAL

Atmy Privacy Policy — Global

Version 1Effective date 2026-08-22
Documents Atmy Terms of ServiceAtmy Privacy Policy — GlobalAtmy Data PolicyAtmy Cookie & Local Storage Policy — GlobalAtmy Subprocessors and Data Recipients — Global
Contents 011. Controller022. Data we may process033. Why we process data044. Legal bases for EEA/UK users055. Private sensors066. Public sensors077. Health data088. Children099. Service providers and recipients1010. International processing and access1111. Retention1212. Security1313. Your rights1414. Export and deletion1515. Cookies/local storage1616. GDPR representative1717. Hong Kong privacy principles1818. Changes1919. Contact 20Controller / operator
01

1. Controller

Nebo Devices Ltd.
ROOM 606, 6/F, HOLLYWOOD CENTRE, NO. 77-91 QUEEN'S ROAD WEST, SHEUNG WAN, Hong Kong

Privacy contact: support@atmy.ai

Primary GLOBAL personal-data hosting is intended to be in Europe. The exact hosting provider and processing locations must be verified before production.

02

2. Data we may process

### Account data

Depending on actual implementation: email, display name, account ID, auth/session identifiers, country/service region, language and preferences.

### Device and sensor data

Sensor IDs, model/firmware, connectivity and diagnostics, account-device relationship and configuration.

### Environmental data

Depending on sensor capabilities: PM1, PM2.5, PM10, TVOC, temperature, humidity, pressure, AQI, timestamps and derived trends/forecasts.

### Location data

Private sensor location you configure; reduced-precision public location if you choose to publish; minimum location context needed for requested features such as weather enrichment.

Atmy should not continuously collect device GPS unless a future feature specifically requires it and this policy is updated.

### Usage and security data

IP address, request metadata, auth events, session information, security/abuse-prevention logs and API metadata as necessary for operation/security.

### Integrations

Only when enabled by you: messaging/notification identifiers and other technical identifiers necessary for a chosen integration.

### Optional health personalization

Where enabled, you may optionally provide health-related preferences/conditions such as asthma, COPD, allergies or heart conditions. They are not required for core Atmy use and must not be stored until the separate explicit-consent flow is completed.

03

3. Why we process data

Purposes may include account creation/security, sensor management, dashboards/history, calculations/forecasts, notifications you enable, public sensor publication you choose, support, abuse/security prevention, legal compliance and service improvement with appropriately aggregated/de-identified information.

04

4. Legal bases for EEA/UK users

Where GDPR/UK GDPR applies, bases depend on purpose:

  • contract — account/core service requested by you;
  • legitimate interests — proportionate service security, fraud/abuse prevention and reliability;
  • legal obligation — where required by law;
  • consent — optional activities where appropriate/required;
  • explicit consent — optional health personalization where required for special-category data.

Atmy must not use consent as a cosmetic universal basis.

05

5. Private sensors

Sensors are private by default. Private account records, identifiers and exact private locations are not intended for public Map/API output.

06

6. Public sensors

When you intentionally publish a sensor, Atmy creates a separate public environmental projection. It should contain only information necessary for the public environmental function and exclude account/authentication data.

You can later make a sensor private again. This stops future publication through Atmy but cannot guarantee removal of copies already obtained by third parties while it was public.

07

7. Health data

Health-profile information is optional, requires separate explicit consent where GDPR applies, is not required for core monitoring, must not be included in public APIs or advertising systems, and should not appear in generic logs.

Atmy is not a medical device and does not provide medical advice.

08

8. Children

Atmy accounts are intended for adults. The current product should not collect a child's identity through the account flow.

09

9. Service providers and recipients

Atmy uses third-party providers only where needed to operate the service. The verified list, purposes, data categories and locations must be published on the Subprocessors page.

Each integration must follow purpose limitation and data minimization.

10

10. International processing and access

GLOBAL personal data is intended to be primarily hosted in Europe. Nebo Devices Ltd. is established in Hong Kong, so support, administration or provider access may involve processing outside the EEA/UK.

Where GDPR/UK GDPR requires transfer safeguards, Atmy will use an applicable lawful mechanism and appropriate supplementary protections.

Before production, Atmy must document actual access patterns and the implemented mechanism; this policy must not claim safeguards that do not exist.

11

11. Retention

Atmy keeps personal data only as long as needed for the described purposes, legal obligations and legitimate security needs.

Production retention periods must come from the verified retention matrix, not guesses. Account deletion removes/de-links data according to that schedule. Backups may expire on a separate cycle.

12

12. Security

Atmy uses technical and organizational measures intended to protect personal data from unauthorized or accidental access, alteration, disclosure, loss or destruction.

The policy must not promise controls that have not been implemented/verified. No internet-connected service can guarantee absolute security.

13

13. Your rights

Depending on applicable law, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a competent authority.

Requests: support@atmy.ai

Where GDPR applies, requests will be handled within applicable legal time limits.

14

14. Export and deletion

Atmy should provide controls to export data in machine-readable form, request/confirm account deletion and manage optional consents.

Deletion cannot require Atmy to erase independent copies of environmental information made by third parties while a sensor was public.

15

15. Cookies/local storage

See the Cookie & Local Storage Policy. Optional tracking/advertising must not be used unless documented and, where required, activated only after appropriate consent.

16

16. GDPR representative

Nebo Devices Ltd. is established outside the EU. Before launch to users for whom Article 27 applies, Atmy must determine whether an EU representative is required and, if required, appoint and identify that representative here:

{{EU_REPRESENTATIVE_IF_REQUIRED}}

17

17. Hong Kong privacy principles

As a Hong Kong company, Nebo Devices Ltd. maintains privacy practices consistent with applicable Hong Kong personal-data requirements, including fair collection, purpose limitation, retention/security and access/correction rights where applicable.

18

18. Changes

Material changes will be reflected in version/effective date and, where required, communicated or accompanied by a renewed choice.

19

19. Contact

Privacy: support@atmy.ai
Legal: support@atmy.ai

20

Controller / operator

Nebo Devices Ltd.
ROOM 606, 6/F, HOLLYWOOD CENTRE, NO. 77-91 QUEEN'S ROAD WEST, SHEUNG WAN, Hong Kong
support@atmy.ai

Version1
Effective date2026-08-22
© 2026 Atmy
Atmy Terms of ServiceAtmy Privacy Policy — GlobalAtmy Data PolicyAtmy Cookie & Local Storage Policy — GlobalAtmy Subprocessors and Data Recipients — Global