Record of Processing Activities

GDPR Article 30(2) — Processor Record
Version 1.0 | March 29, 2026

1. Processor Details

Processor nameLamb and Flag TopCo Corp (dba AtlanticM&A)
Registered address159 N Wolcott St, Ste 133, Casper, WY 82601, United States
Data protection contactprivacy@atlanticma.com
Representative in the EUTo be appointed when required under Article 27

2. Categories of Processing

#Processing ActivityCategories of Data SubjectsCategories of Personal DataTransfers to Third CountriesRetention
1User account managementCustomer employees and contractorsName, email, hashed password, MFA config, session tokens, login timestampsN/A — processed in US-East-1. SCCs apply for EEA controllers.While account active + 30 days post-termination
2Project managementCustomer employees, project team members, governance participantsNames, email addresses, job titles, project role assignments, task assignments, workstream ownershipN/A — processed in US-East-1. SCCs apply for EEA controllers.While subscription active + 30 days
3Meeting transcript analysis (AI)Meeting attendees, individuals discussed in meetingsNames, statements attributed to individuals, action item assignments, opinions expressedTranscript → AWS Bedrock (US-East-1) via VPC private endpoint. Not used for model training.While subscription active + 30 days. Transcript stored in S3 (encrypted).
4AI dependency analysisN/A — processes task titles, not personal dataTask titles and workstream names (may incidentally contain personal names if used in task titles)Task data → AWS Bedrock (US-East-1) via VPC private endpoint. Not used for model training.AI results are ephemeral (session state). Task data follows project retention.
5Report generation & distributionReport recipients (email addresses), individuals named in report contentEmail addresses of distribution list members, project data included in generated reportsEmail sent via AWS SES (US-East-1)Distribution config while subscription active. Generated reports not retained server-side.
6Document storageIndividuals named in uploaded documents (TSA addendums, templates)Document content (may contain personal data uploaded by Controller)N/A — stored in AWS S3 (US-East-1), encrypted AES-256While subscription active + 30 days
7Governance & team managementSteering committee members, IMO members, workstream leadsNames, roles, organisational side (acquirer/target), governance positionsN/A — processed in US-East-1While subscription active + 30 days
8Payment processingAccount billing contactsProcessed entirely by Paddle (Merchant of Record). AtlanticM&A does not receive or store payment card data.Paddle processes in UK/Global (PCI DSS Level 1)Managed by Paddle per tax regulations
9Customer feedbackUsers submitting feedbackEmail address, feedback text, browser info, page URLN/A — processed in US-East-1Until resolved or deleted by administrator
10Audit loggingAll platform usersUser ID, action performed, timestamp, IP addressN/A — processed in US-East-1. CloudTrail logs in same region.Application logs: while subscription active. CloudTrail: 90 days.

3. Sub-Processors

A complete list of sub-processors with processing purposes, data locations, and certifications is maintained in the Security Technical Addendum (Section 7).

Sub-ProcessorProcessingLocationSafeguards
AWS (multiple services)Compute, database, storage, AI, email, auth, monitoringUS-East-1SOC 2 II, ISO 27001, SCCs, EU-US DPF
AWS Bedrock (Claude)AI transcript analysis, work plan generation, dependency analysisUS-East-1SOC 2 II, ISO 27001, no model training
PaddlePayment processing (MoR)UK / GlobalPCI DSS Level 1
GitHubCI/CD pipeline triggerUSSOC 2 II, no customer data

4. Technical and Organisational Security Measures

A description of the technical and organisational security measures implemented pursuant to GDPR Article 32 is provided in the Security Technical Addendum and the Data Protection Impact Assessment.

Key measures include:

5. International Transfers

All processing occurs in AWS US-East-1 (N. Virginia, United States). For transfers from the EEA/UK/Switzerland, the following safeguards are in place:

Full details of the international transfer mechanism are set out in the Data Processing Agreement (Section 5).

6. Document Control

Version1.0
DateMarch 29, 2026
Next reviewMarch 2027 or upon material change in processing
Approved byRichard Parry, Director

Lamb and Flag TopCo Corp (dba AtlanticM&A) · 159 N Wolcott St, Ste 133, Casper, WY 82601, United States
For enquiries: privacy@atlanticma.com

Article 30 — Record of Processing Activities | MA Integration