Privacy Policy

    Last updated: December 30, 2025

    AthenGuard respects your privacy and is committed to protecting the personal and organizational data you entrust to us. This Privacy Policy explains what information we collect, how we use it, how we protect it, your rights regarding your data, and the choices available to you.

    This policy applies to all users of the AthenGuard compliance platform, including administrators, compliance officers, auditors, and end users within your organization.

    1. Information We Collect

    We collect information necessary to provide, secure, and improve the AthenGuard platform and related services.

    1.1 Information You Provide Directly

    Account and Profile Information:

    • Full name, work email address, company name, job title, and department
    • Account credentials, authentication details, and security preferences
    • Multi-factor authentication settings and recovery information
    • User preferences, notification settings, and interface customization

    Organizational and Compliance Information:

    • Organization structure, business units, and operational locations
    • Compliance framework selections (SOC 2, ISO 27001, NDPR, PCI DSS, NIST, etc.)
    • Custom policies, procedures, and control implementations
    • Risk assessments, compliance gaps, and remediation plans
    • Evidence uploads, documentation, and supporting materials
    • Asset inventories, system classifications, and data mappings

    Communications and Support:

    • Support requests, help desk tickets, and troubleshooting information
    • Feedback, feature requests, and product suggestions
    • Communications via email, chat, or integrated messaging systems
    • Training session participation and certification records

    1.2 Information Collected Through Platform Use

    Usage and Activity Data:

    • Login events, session duration, and access patterns
    • Feature utilization, dashboard interactions, and workflow completions
    • Compliance check executions, evidence collection activities, and report generations
    • Search queries, filter applications, and navigation paths
    • Policy acknowledgments, control attestations, and approval workflows

    System and Technical Data:

    • IP addresses, device identifiers, and browser types
    • Operating system versions and application configurations
    • Connection timestamps, geographic locations, and timezone information
    • Performance metrics, error logs, and diagnostic data

    Audit and Compliance Tracking:

    • Comprehensive audit trails of all system actions
    • Policy modifications, access control changes, and configuration updates
    • Evidence collection timestamps and validation results
    • User actions within the platform, including creates, updates, and deletions
    • Integration activities with connected systems and third-party services

    Agent and Sensor Data:

    • Asset discovery information from connected endpoints
    • Configuration baselines and system state snapshots
    • Security control validation results
    • Vulnerability scan findings and patch status
    • Log aggregation from monitored systems (when configured)

    Strict Data Boundary: AthenGuard agents and sensors are technically restricted to collecting only metadata, configuration states, and compliance telemetry. Our agents do not—and cannot—access, copy, transmit, or store your underlying proprietary source code, customer database records, or sensitive business file contents.

    1.3 Information We Do Not Collect

    We are committed to data minimization:

    • We do not collect personal information unrelated to platform operation
    • We do not access file contents on monitored systems unless explicitly configured as compliance evidence
    • We do not collect biometric data, health information, or financial account details
    • We do not track your activities outside the AthenGuard platform
    • We do not collect information from children under 13 years of age

    2. How We Use Your Information

    We use collected information solely to provide, secure, and improve our services.

    2.1 Core Platform Operations

    Service Delivery:

    • Authenticate users and enforce role-based access controls (RBAC)
    • Execute compliance assessments and automated evidence collection
    • Generate compliance reports, audit documentation, and executive dashboards
    • Maintain compliance mappings across multiple frameworks
    • Support continuous monitoring and real-time compliance status tracking

    Platform Performance:

    • Monitor system health, availability, and performance metrics
    • Optimize query performance and data retrieval operations
    • Identify and resolve technical issues proactively
    • Scale infrastructure to meet usage demands

    2.2 Security and Trust

    Security Operations:

    • Detect, investigate, and respond to security incidents
    • Prevent fraud, abuse, and unauthorized access attempts
    • Identify anomalous behavior patterns and potential threats
    • Maintain forensic audit trails for security investigations
    • Enforce tenant isolation and data segregation

    Compliance and Legal:

    • Meet regulatory requirements and contractual obligations
    • Support legal processes, subpoenas, and lawful requests
    • Maintain records required by applicable laws and regulations
    • Enable customer audits and third-party assessments

    2.3 Communication and Support

    Customer Communication:

    • Respond to support requests and technical inquiries
    • Provide product updates, security notifications, and maintenance alerts
    • Share best practices, training materials, and compliance guidance
    • Conduct user research and gather product feedback
    • Deliver transactional emails related to account activity

    2.4 Product Improvement

    Analytics and Development:

    • Analyze usage patterns to improve user experience
    • Develop new features based on customer needs
    • Test platform stability and feature functionality
    • Optimize automation engines and evidence collection capabilities
    • Conduct A/B testing for interface improvements (with user consent)

    2.5 What We Do Not Do

    Our Commitments:

    • We do not sell, rent, or lease your data to third parties
    • We do not use your information for advertising or marketing to non-customers
    • We do not share data with third parties except as described in this policy
    • We do not train AI models on your compliance data
    • We do not make automated decisions that produce legal effects without human oversight

    3. Data Security

    Security is foundational to AthenGuard's design and operations.

    3.1 Technical Safeguards

    Encryption:

    • TLS 1.3 for all data in transit
    • AES-256 encryption for data at rest
    • Encrypted database connections and internal service communication
    • Key management using industry-standard practices (HSM-backed where applicable)

    Access Controls:

    • Multi-factor authentication (MFA) required for all users
    • Role-based access control (RBAC) with principle of least privilege
    • Just-in-time (JIT) access for administrative operations
    • Session management with automatic timeout and secure token handling
    • IP allowlisting and geographic access restrictions (when configured)

    Network Security:

    • Web application firewall (WAF) protection
    • DDoS mitigation and rate limiting
    • Network segmentation and tenant isolation
    • Intrusion detection and prevention systems (IDS/IPS)
    • Regular vulnerability scanning and penetration testing

    Application Security:

    • Secure software development lifecycle (SSDLC)
    • Code review, static analysis, and dependency scanning
    • Input validation and output encoding to prevent injection attacks
    • CSRF, XSS, and clickjacking protections
    • Security headers and content security policies (CSP)

    3.2 Organizational Safeguards

    Personnel Security:

    • Background checks for employees with data access
    • Mandatory security awareness training
    • Confidentiality agreements and data handling policies
    • Strict access controls to production environments
    • Separation of duties for critical operations

    Vendor Management:

    • Security assessments of third-party service providers
    • Data processing agreements (DPAs) with all vendors
    • Regular vendor security reviews and audits
    • Subprocessor transparency and approval processes

    Incident Response:

    • 24/7 security monitoring and alerting
    • Documented incident response procedures
    • 72-Hour Breach Notification: In the event of a confirmed data breach affecting your personal or organizational data, we commit to notifying affected account administrators without undue delay, and no later than 72 hours after discovery, aligning with strict global regulatory standards.
    • Post-incident analysis and continuous improvement

    3.3 Compliance Certifications

    AthenGuard maintains security and privacy controls designed to support:

    • SOC 2 Type II attestation
    • ISO 27001 certification
    • Nigeria Data Protection Regulation (NDPR) compliance
    • PCI DSS where applicable
    • GDPR adequacy for European customers
    • Industry-specific frameworks as required by customer agreements

    3.4 Physical Security

    Our infrastructure partners maintain:

    • 24/7 physical security and monitoring
    • Biometric access controls to data centers
    • Environmental controls and redundancy
    • Regular security audits and compliance certifications

    4. Data Sharing and Disclosure

    We share data only when necessary and with appropriate safeguards.

    4.1 Service Providers and Subprocessors

    We engage carefully selected third-party service providers to support platform operations:

    Infrastructure Providers:

    • Cloud hosting services (data center locations disclosed to customers)
    • Content delivery networks (CDN) for performance optimization
    • Database and storage services

    Operational Services:

    • Email delivery and communication platforms
    • Support ticketing and customer relationship management (CRM)
    • Payment processing (we do not store full payment card details)
    • Analytics and monitoring tools (with data anonymization where possible)

    All service providers:

    • Are contractually bound to protect your data
    • Process data only as instructed by AthenGuard
    • Maintain security standards commensurate with the sensitivity of data
    • Are disclosed in our subprocessor list (available upon request)

    4.2 Customer-Authorized Integrations

    When you configure integrations with third-party services:

    • Data is shared only to perform the requested function
    • You control which data is shared through integration settings
    • Integration partners process data under their own privacy policies
    • You can revoke integration access at any time

    Common integration categories include:

    • Identity providers (SSO, SAML, OAuth)
    • Ticketing systems (Jira, ServiceNow, etc.)
    • Messaging platforms (Slack, Microsoft Teams, etc.)
    • Cloud infrastructure providers (AWS, Azure, GCP)
    • Security tools (SIEM, vulnerability scanners, etc.)

    4.3 Legal and Regulatory Requirements

    We may disclose information when legally required:

    • In response to valid legal process (subpoena, court order, warrant)
    • To comply with applicable laws and regulations
    • To respond to lawful requests from government authorities
    • To enforce our Terms of Service or protect our legal rights
    • To protect the safety and security of our users or the public

    We will:

    • Challenge overbroad or inappropriate requests when legally permissible
    • Notify affected customers unless prohibited by law
    • Disclose only the minimum information necessary
    • Document all legal requests in our transparency report (published annually)

    4.4 Business Transfers

    If AthenGuard is involved in a merger, acquisition, bankruptcy, or sale of assets:

    • You will be notified via email and platform notice
    • Your data will remain subject to this Privacy Policy unless you consent to changes
    • You will have the option to delete your data before the transfer
    • The successor entity will be bound by substantially similar privacy commitments

    5. Data Retention

    We retain data only as long as necessary for legitimate business purposes.

    5.1 Retention Periods

    Active Account Data:

    • Retained throughout your subscription period
    • Available for immediate access and compliance reporting
    • Subject to customer-configured retention policies

    Audit and Security Logs:

    • Minimum retention: 1 year for security and compliance purposes
    • Extended retention: up to 7 years where required by regulation
    • Immutable logging for critical security events

    Evidence and Compliance Records:

    • Retained according to applicable regulatory requirements
    • Configurable by customer based on audit and certification needs
    • Typically 3-7 years for most compliance frameworks

    Backup and Disaster Recovery:

    • Encrypted backups retained for 30-90 days
    • Used only for disaster recovery and business continuity
    • Subject to same security and access controls as production data

    Deleted Account Data:

    • Account deletion initiated through platform settings or written request
    • Data deletion completed within 90 days of account closure
    • Some metadata may be retained for legal and security purposes
    • Audit logs preserved as required by law

    5.2 Data Deletion Process

    Upon data retention period expiration or account deletion:

    • Data is securely deleted using industry-standard methods
    • Multi-pass overwriting for sensitive data
    • Cryptographic erasure where encryption keys are destroyed
    • Deletion verified through automated processes
    • Certificates of destruction available upon request

    5.3 Customer Control

    You can manage retention through:

    • Platform retention policy settings
    • Evidence archival configurations
    • Data export tools (before deletion)
    • Custom retention schedules for specific data types

    6. Your Rights and Choices

    We respect your rights regarding your personal data.

    6.1 Access and Portability

    Right to Access:

    • View all personal data we hold about you
    • Request copies of your data in structured formats
    • Obtain information about how your data is processed

    Data Portability:

    • Export compliance data in standard formats (CSV, JSON, PDF)
    • Transfer data to another service provider
    • Download complete audit trails and evidence packages

    6.2 Correction and Update

    Right to Rectification:

    • Correct inaccurate or incomplete personal information
    • Update your profile, preferences, and organizational details
    • Request corrections through platform interface or support

    6.3 Deletion and Restriction

    Right to Erasure ("Right to be Forgotten"):

    • Request deletion of personal data when no longer necessary
    • Remove specific data elements or entire accounts
    • Subject to legal retention requirements and legitimate business needs

    Right to Restriction:

    • Limit processing of your data in certain circumstances
    • Object to specific processing activities
    • Restrict automated evidence collection for particular systems

    6.4 Objection and Withdrawal

    Right to Object:

    • Object to processing based on legitimate interests
    • Opt-out of non-essential communications
    • Disable specific features or integrations

    Consent Withdrawal:

    • Withdraw consent for optional data processing
    • Disable cookies and tracking (where applicable)
    • Revoke integration permissions

    6.5 Automated Decision-Making

    AthenGuard uses automated processing for:

    • Compliance scoring and risk calculations
    • Evidence validation and control assessments
    • Alert generation and anomaly detection

    You have the right to:

    • Understand the logic behind automated decisions
    • Request human review of automated assessments
    • Challenge and correct automated findings

    6.6 Exercising Your Rights

    To exercise these rights:

    • Use in-platform tools for self-service requests
    • Contact our privacy team at
    • Submit requests through your Customer Success Manager

    We will:

    • Respond within 30 days (45 days for complex requests)
    • Verify your identity before processing requests
    • Provide clear explanations for any limitations or denials
    • Notify third parties if we have shared your data and you request deletion

    6.7 Regional Privacy Rights

    For Nigerian Users (NDPR/NDPA):

    • Right to request disclosure of personal data collected
    • Right to request deletion after withdrawal of consent
    • Right to file complaints with the Nigeria Data Protection Commission (NDPC)
    • Data localization options available for public sector entities

    For European Users (GDPR):

    • All rights outlined above apply
    • Right to lodge complaints with supervisory authorities
    • Data transfers governed by Standard Contractual Clauses (SCCs)
    • EU representative available for direct contact

    For California Users (CCPA/CPRA):

    • Right to know what personal information is collected and shared
    • Right to opt-out of data "sales" (we don't sell data)
    • Right to non-discrimination for exercising privacy rights
    • Authorized agent requests accepted with verification

    7. International Data Transfers

    AthenGuard operates globally and may transfer data across borders.

    7.1 Data Residency Options

    We offer:

    • Primary data centers: United States, European Union, Nigeria
    • Customer-selectable regions for data storage
    • Data localization for customers with specific requirements
    • Multi-region deployment for global enterprises

    7.2 Transfer Mechanisms

    When transferring data internationally, we rely on:

    • Standard Contractual Clauses (SCCs) approved by relevant authorities
    • Adequacy decisions where available
    • Binding Corporate Rules for intra-company transfers
    • Explicit consent where required and appropriate

    7.3 Security During Transfer

    All international transfers include:

    • Encryption in transit and at rest
    • Access controls and monitoring
    • Audit logging of cross-border data flows
    • Compliance with destination country requirements

    8. Cookies and Tracking Technologies

    8.1 Types of Cookies

    Essential Cookies:

    • Authentication and session management
    • Security and fraud prevention
    • Load balancing and performance
    • Cannot be disabled without affecting platform functionality

    Functional Cookies:

    • User preferences and settings
    • Interface customization
    • Language and timezone selections
    • Can be managed through platform settings

    Analytics Cookies:

    • Usage patterns and feature adoption
    • Performance monitoring
    • Error tracking and diagnostics
    • Optional; can be disabled in preferences

    8.2 Third-Party Cookies

    • Limited to essential service providers
    • Subject to same privacy standards
    • Listed in our cookie policy (available on request)
    • No advertising or tracking cookies

    8.3 Managing Cookies

    You can control cookies through:

    • Browser settings and preferences
    • Platform privacy settings
    • Third-party cookie management tools
    • Opt-out mechanisms provided by analytics services

    9. Children's Privacy

    AthenGuard is designed for business use and not intended for children under 13 (or applicable age in your jurisdiction).

    We do not:

    • Knowingly collect information from children
    • Market services to children
    • Allow children to create accounts

    If we discover we have inadvertently collected data from a child:

    • We will delete it promptly
    • We will notify the organization administrator
    • We will implement additional controls to prevent recurrence

    10. Privacy by Design

    Privacy is embedded in AthenGuard's architecture and operations.

    10.1 Technical Measures

    • Default privacy settings prioritize data protection
    • Data minimization in collection and retention
    • Purpose limitation for all processing activities
    • Tenant isolation and segregation
    • Encryption and pseudonymization where appropriate

    10.2 Organizational Measures

    • Privacy impact assessments for new features
    • Regular privacy training for employees
    • Data protection officer oversight
    • Privacy-focused vendor selection
    • Continuous compliance monitoring

    10.3 Transparency

    We commit to:

    • Clear, accessible privacy communications
    • Advance notice of material policy changes
    • Regular transparency reports
    • Open dialogue with customers and regulators

    11. Changes to This Privacy Policy

    11.1 Updates and Notifications

    We may update this Privacy Policy to reflect:

    • Changes in legal requirements
    • New features or services
    • Evolving industry practices
    • Customer feedback and requests

    How we notify you:

    • Email to account administrators
    • In-platform notifications
    • Banner notices for material changes
    • 30 days advance notice for significant changes

    11.2 Acceptance

    Continued use after changes constitutes acceptance. If you disagree:

    • Contact us to discuss concerns
    • Export your data before the effective date
    • Terminate your account if necessary

    11.3 Version History

    • Current version: December 30, 2025
    • Previous versions available upon request
    • Changelog maintained for transparency

    12. Contact Us

    12.1 Privacy Inquiries

    Email:

    Subject line: Privacy Policy Question

    Mailing Address:
    AthenGuard Privacy Team
    BafaTech Consulting

    12.2 Data Protection Officer

    For privacy-related matters:

    Response time: Within 5 business days for acknowledgment

    12.3 Complaints and Concerns

    If you believe we have not handled your data appropriately:

    • Contact our privacy team first. We will investigate and respond within 30 days.
    • If unresolved, you may contact:
      • United States: Your state's Attorney General (e.g., the Georgia Attorney General's Consumer Protection Division)
      • Nigeria: Nigeria Data Protection Commission (NDPC) (www.ndpc.gov.ng)
      • EU: Your local Data Protection Authority
      • California: California Attorney General

    Appendix A: Definitions

    • Personal Data: Any information relating to an identified or identifiable individual.
    • Processing: Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
    • Data Controller: The entity that determines purposes and means of processing (typically your organization).
    • Data Processor: The entity that processes data on behalf of the controller (AthenGuard).
    • Tenant: A distinct organizational instance within the AthenGuard platform with isolated data.

    Appendix B: Legal Bases for Processing

    We process your data based on:

    • Contract Performance: Necessary to provide the service you requested
    • Legitimate Interests: For security, fraud prevention, and service improvement
    • Legal Obligation: To comply with laws and regulations
    • Consent: Where you have given explicit permission (withdrawable at any time)

    This Privacy Policy was last updated on December 30, 2025 and is effective immediately.