Last updated
How information moves through Atlas5, why it is needed, and the choices available to you.
Service operator: TPixel, Inc.
Contact: support@trustpixel.ai
Who this policy covers
This policy describes personal information handled in connection with the Atlas5 website and business travel service, operated by TPixel, Inc. It covers visitors, people who contact us, customer representatives, administrators, travel arrangers and travelers. “Atlas5,” “we” and “us” refer to TPixel, Inc. Atlas5 is powered by TrustPixel.
Your company decides how to operate its travel program, including who can book, the rules that apply and who can review travel records. When we handle information on your company’s instructions, your company is responsible for those decisions and its own privacy notice. We handle website inquiries, administration of our business relationship and our own legal obligations for our own purposes. A customer data processing agreement governs processing performed on the customer’s behalf.
Airlines, hotels, payment providers and connected services can have separate responsibilities for information they receive. Their privacy notices apply to their own processing. This policy does not replace your employer’s notice or a supplier’s notice.
Information used by the service
The information involved depends on the features you and your company use. It can include:
- Account and work details. Your name, work email, company, team, role, work sign-in identifier, permissions and contact details.
- Travel requests and preferences. Messages to the assistant, destinations, dates, seat or room preferences, loyalty details and information needed to plan or change a trip.
- Booking information. Traveler details required by a supplier, itinerary, reservation references, tickets, hotel stays, cancellations, changes and refund records. Required identity or travel-document details depend on the booking.
- Company policy and decisions. Travel rules, spending limits, approvers, authorization decisions and the people and times associated with those decisions.
- Payment and transaction information. Billing details, amounts, currencies, payment references, transaction status and reconciliation records. A payment provider may collect additional information in its own checkout or verification flow.
- Communications. Information you choose to include in sales, support, privacy or security correspondence.
- Technical information. IP address, browser and device information, request times, service activity, error reports and security events generated when you access the website or service.
Where information comes from
Information can come directly from you; from an authorized colleague, administrator or travel arranger; from your work identity provider; and from booking, payment or communication services involved in your request. Activity and technical records are generated through use of the service.
If you provide another person’s information, do so only with the authority needed for the task and make this policy available to them. Do not put passwords, full card details, health information or other sensitive information into general chat or a website inquiry. If a supplier needs sensitive information for a particular request, use the designated collection process and provide only what is required.
How information is used
- Create and administer company workspaces, authenticate people and apply access permissions.
- Understand travel requests, find and compare options, apply company rules, route approvals and complete authorized booking actions.
- Coordinate payments, booking changes, cancellations and refunds with the relevant providers.
- Maintain trip records, support company oversight and resolve questions about what happened.
- Respond to inquiries, provide service communications and administer customer relationships.
- Diagnose errors, secure the service, investigate misuse and improve its operation.
- Meet legal obligations, establish or defend legal claims and maintain records required for those purposes.
AI, conversations and company oversight
Atlas5 uses AI to interpret requests and help coordinate travel. Relevant conversation content, trip context and company instructions are processed by the systems used to deliver that assistance. Do not assume a work conversation is private from your company: authorized people can review information needed for their role, including booking and approval records.
Company rules and authorization checks govern booking actions. AI-generated text can be incorrect; a suggestion is not a confirmed reservation. Review traveler details, dates, price and applicable supplier conditions before authorizing a transaction. Your company can explain its approval and review process.
A marketing description of AI does not specify model-provider retention or training terms. Any processing restrictions your company requires must be covered by its applicable service and data processing arrangements.
When information is shared
Information is shared with authorized people in your company as needed to operate its travel program. This can include travelers, arrangers, approvers, Finance and administrators. Access depends on the role and permissions assigned by the company.
Travel suppliers and booking services receive information needed to provide a requested trip or handle a change or refund. Payment providers receive information needed to process and reconcile transactions and perform applicable checks. Coinflow is our listed payment subprocessor; see the subprocessor notice. A provider may also process information for its own legal or regulatory purposes.
Services your company connects, such as work sign-in and chat tools, receive information necessary for the integration you use. Those services also operate under their own terms and privacy notices.
Information may be disclosed where required by law, to respond to a valid legal request, to protect rights and safety, or to investigate fraud or misuse. If a business transaction changes the operator of Atlas5, relevant information may be transferred subject to applicable confidentiality and data protection requirements.
Website cookies and contact forms
The current marketing website does not load advertising or analytics trackers and serves fonts from its own assets. Ordinary hosting requests still involve technical information such as an IP address and requested URL. The app and external services may use technologies needed for authentication and operation. See our cookie notice for the website’s current setup.
An email link opens your own email application. Information is sent only when you send that email. If a website form is connected to a submission service, it identifies the action as sending a request; if it prepares an email, you must send the draft yourself. Do not use an inquiry form for payment credentials or identity documents.
Legal bases where required
Where applicable data protection law requires a legal basis, processing for our own purposes depends on the activity: taking steps you request or performing a contract with you; complying with a legal obligation; legitimate interests in operating, securing and administering the service and responding to business inquiries, balanced against your rights; or consent when required. Where we act for your company, it determines the legal basis for its instructions.
If processing depends on consent, you can withdraw it for future processing. Withdrawal does not make earlier lawful processing unlawful. Some information is necessary to authenticate an account, make a booking or meet a legal requirement; without it, the relevant action may not be possible.
Retention and deletion
Retention depends on the type of information and why it is needed. Relevant factors include the active customer relationship, the trip and any change or refund still in progress, customer instructions, applicable accounting and legal requirements, disputes, security investigations and legal holds.
Removing a profile or closing access does not necessarily remove booking, payment or audit records that must be kept for another valid purpose. Retention and return or deletion of customer-controlled data are governed by the applicable customer agreement and data processing terms. Ask your company about its travel-record retention requirements.
International travel and processing
Travel can require information to be sent to suppliers and service providers in other countries, including the destination of a trip. Data protection laws can differ between countries. This policy does not promise that all information stays in one region.
Where the law requires safeguards for an international transfer, the applicable transfer arrangement must provide those safeguards. Customer-specific location and transfer commitments are set out in the relevant data processing agreement. Coinflow’s public privacy notice identifies entities in the United States and Malta; this is not a statement that every Atlas5 transaction is processed in those two locations.
Your choices and privacy rights
Depending on your location and the law that applies, you may have rights to access or obtain a copy of your information, correct it, request deletion, restrict or object to processing, receive portable data, withdraw consent, or appeal a decision on a request. These rights are subject to applicable exceptions, including obligations to retain certain records. You may also complain to the relevant data protection authority.
For a company-managed account or trip, start with your company’s administrator or privacy contact. They control the travel program and can direct requests relating to their records. For information Atlas5 handles for its own purposes, contact us using the details below. State the type of request and the email or company associated with it; do not send identity documents unless a secure verification process is specifically requested.
We may need to verify your identity and authority before disclosing or changing information. Authorized-agent requests require evidence of authority where applicable. You can ask about the basis for a response or request further review. Applicable rights and statutory response periods are not reduced by this policy.
Security and age requirements
The security overview describes access controls, company separation, booking checks and the current compliance status. No service can guarantee that every security risk is eliminated. Keep work-account credentials secure and tell your administrator promptly about suspected unauthorized access.
Atlas5 is a business service for adults acting for a company and is not directed to children under 18. Do not create an account for a child. If you believe a child has provided personal information through the service, contact us so the circumstances can be reviewed.
Updates to this policy
The date above identifies this version. Changes will be published on this page. Where required, material changes will be communicated through the service or the customer contact, and consent will be sought when applicable. A policy update does not remove rights that apply to information already collected.
Privacy inquiries
For a company-managed account, contact your company’s administrator or privacy team about its travel records. Existing customers can also use the Atlas5 contact identified in their service agreement.
For a direct inquiry, email support@trustpixel.ai. Include your company and the subject of your request; do not send passwords, full card details or identity documents.