1. Who we are and scope of this policy
ATOM Signatures (the "Service") is a centralized email signature management service for Microsoft 365, operated by ATOM Solutions (NEQ 1182200098) ("we", "us"), available at signatures.atomsolutions.ca, and including an add-in for Microsoft Outlook.
This policy applies to information processed by the Service: information about administrators who manage a client-organization account or a reseller account (a partner that manages its own clients' subscriptions), and information about the staff of those organizations whose directory attributes are used to compose signatures. It does not cover Microsoft's practices, nor those of other websites we link to.
2. Privacy officer
In accordance with Québec's Law 25, the President of ATOM Solutions, acting as the person in charge of the protection of personal information, can be reached at info@atomsolutions.ca. Any question, access request or complaint related to this policy may be addressed to them.
3. Information we collect
a) Administrator account and reseller account
When an administrator — or a reseller partner — signs in to the console with their Microsoft account (Microsoft Entra SSO), we receive their name, work email address and their organization's identifier (Microsoft 365 tenant). A reseller invited to manage an account receives a single-use invitation link, whose token is stored in hashed form.
b) Organization directory (Microsoft Graph)
With an administrator's consent, we read certain attributes of the organization's Microsoft 365 directory on a read-only basis, solely to compose signatures: first and last name, job title, department, phone numbers, email address, office location, group membership and, where applicable, organization-defined extension attributes.
c) Outlook add-in usage
When a user composes or sends an email, the add-in transmits the sender's email address to our service to determine the applicable signature and count the licenses (seats) in use. The platform used (desktop, web browser or mobile) and these calls are timestamped and logged.
d) The "My signature" pane
When an employee opens the "My signature" pane in Outlook and signs in (delegated Microsoft authentication, with no password of ATOM's own), we receive their sign-in identifier. If they choose a signature among the ones offered to them, that choice is kept. If their administrator allows it, they may also override certain contact details shown in their signature (phone number, title, address, etc.); these personalized values are then kept and take precedence over the directory's values.
e) Shared mailboxes and individual targeting
When an employee sends an email on behalf of a shared mailbox, that mailbox's address is transmitted to us in order to apply the right signature; it never uses up a seat. An administrator may also manually record their organization's shared mailboxes, or target a signature to a specific individual address rather than a group; these choices are kept.
f) Support requests
When you write to us through the support form, we receive your name, email address, message and organization name, sent by email to our team.
g) Administrator consents
When an administrator authorizes access to their organization's directory or approves another processing required by the Service, we keep a record of that consent: who gave it, for what, when, and from which IP address.
h) Billing
Billing is processed by Stripe. We keep the subscription identifier, the number of seats and the payment status. We never store payment card numbers.
i) Technical logs
Like any online service, we log technical events (IP address, browser type, timestamp, action performed) for security, troubleshooting and audit purposes. Our audit logs are append-only.
j) Website audience measurement (Google Analytics)
On our public pages (marketing website), we use Google Analytics 4 to measure traffic in aggregate (page views, referral source, device type). This tool sets cookies only after you consent, collected through the banner shown on your first visit (Google Consent Mode v2). Until you accept, no measurement cookie is set. Data is processed by Google LLC, which may involve a transfer outside Canada; we enable no advertising features (no profiling or targeting). You can withdraw or change your choice at any time by clearing your browser cookies or by contacting us. The administration console (authenticated area) does not use Google Analytics.
4. What we never collect
- No email content: we never read, store or transmit the body, subject or recipients of your messages. The add-in inserts the signature locally, within Outlook.
- No passwords: authentication is handled entirely by Microsoft Entra.
- No advertising data: no ad tracking, no sale of personal information, no profiling.
5. Why we use this information (purposes)
- To compose and apply your organization's email signatures;
- To target signatures by group, shared mailbox or individual address, and fill dynamic fields (name, title, phone, etc.);
- To count seats in use and bill the subscription, including the aggregated billing of a reseller account;
- To secure the Service, prevent abuse and diagnose incidents;
- To respond to support requests;
- To comply with our legal obligations.
We do not use this information for any other purpose without your consent.
6. Disclosure to third parties (subprocessors)
We do not sell or rent personal information. Our infrastructure (servers, database, files) is operated directly by ATOM Solutions, in Québec: it is therefore not an outside subprocessor. We rely on a limited number of subprocessors for specific functions:
| Subprocessor | Role | Information involved |
|---|---|---|
| Microsoft (Graph / Entra) | Authentication and directory reads | Accounts, directory attributes |
| Stripe | Payment processing | Billing contact details, payment data |
| Cloudflare | Tunnel connecting our infrastructure to the Internet; terminates encryption (TLS) | Traffic in transit (seen, not stored) |
| Google LLC (Google Analytics 4) | Audience measurement on public pages, only after consent | Aggregated browsing data (public pages) |
These subprocessors are bound by contractual confidentiality obligations and may only use the information for the intended purposes.
7. Hosting and transfers outside Québec
The Service's infrastructure (database, files, application servers) is operated by ATOM Solutions itself, in Québec. Traffic passes through a Cloudflare tunnel: Cloudflare terminates TLS encryption and therefore sees the traffic in transit, but does not store it. Backup copies, encrypted before leaving our servers, are stored in Canada, in Toronto (Ontario). Some subprocessors (Stripe for payment, Google LLC for audience measurement) may process information outside Québec or Canada. Before any communication of information outside Québec, we assess the privacy factors involved and govern it by contract, in accordance with Law 25.
8. Retention
- Your organization's own data (signatures, configuration, directory attributes, employee preferences) is kept for the duration of the subscription, then automatically deleted within 30 days of the cancellation taking effect;
- Exceptions to this deletion: billing records, kept for the periods required by tax laws, and audit logs and consent records, kept for at most 12 months;
- Technical application logs are kept for at most 12 months;
- A signature deleted in the console is first placed in a trash bin, then permanently purged 30 days after its deletion;
- Backup copies are renewed according to their rotation cycle; deleted data disappears from them over the course of that cycle;
- You can request an export of your data before the end of your subscription or before a deletion, by writing to info@atomsolutions.ca.
9. Roles and responsibilities
For your organization's directory and employee information, your organization remains the party responsible under the law; ATOM Solutions acts as its mandatary (section 18.3 of Law 25), following your instructions and within the limits strictly necessary to provide the Service.
In the event of a confidentiality incident affecting this information, we notify your organization without delay and assist it in its steps; it is up to your organization to notify the Commission d'accès à l'information and the individuals concerned. For information we are ourselves responsible for — administrator and reseller accounts, billing, public website data — we directly notify the Commission d'accès à l'information and the individuals concerned, in accordance with Law 25.
10. Security
- TLS encryption for all communications;
- Strict isolation of each organization's data (per-tenant partitioning, database-level controls);
- Least-privilege access; Microsoft directory access is read-only;
- The token used by the Outlook add-in to authenticate with the Service is stored in hashed form, never in the clear;
- Regular backups, encrypted before leaving the server and stored in Canada (Toronto);
- Append-only audit logs;
- Rate limiting and abuse protections.
11. Your rights
Under Law 25 and applicable Canadian laws, you may:
- request access to the personal information we hold about you;
- request its correction if it is inaccurate or incomplete;
- request its deletion (cessation of dissemination) where the law allows;
- withdraw your consent at any time;
- request the portability of the computerized personal information you provided to us;
- file a complaint with the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada.
To exercise these rights, write to info@atomsolutions.ca. If you are a staff member of a client organization, we may redirect you to your employer, which remains responsible for its directory information.
12. Privacy incidents
Any confidentiality incident presenting a risk of serious injury is recorded in our incident register. Depending on the responsibilities described in section 9, it is either reported directly by us to the Commission d'accès à l'information and to the individuals concerned, or your organization is notified without delay so that it can make those notifications itself.
13. Cookies and local storage
The Service uses the following cookies and local storage:
- an essential session cookie to keep you signed in to the console (expires after 8 hours);
- an essential language preference cookie (
atom_lang, 12 months); - browser local storage, on our public pages, to remember your display language (
atom:lang) and your audience-measurement consent choice (atom:analytics-consent); - Google Analytics 4 audience-measurement cookies (
_ga,_ga_*), set only after you consent to the banner shown on our public pages, and never on the administration console.
No advertising cookies are used.
14. Changes to this policy
We may update this policy to reflect changes to the Service or to legal requirements. The update date appears at the top of this page; in the event of a material change, administrators of client organizations will be notified.
15. Contact us
ATOM Solutions (NEQ 1182200098) — info@atomsolutions.ca — atomsolutions.ca