Privacy Policy
Last updated: December 30, 2025
AthenGuard respects your privacy and is committed to protecting the personal and organizational data you entrust to us. This Privacy Policy explains what information we collect, how we use it, how we protect it, your rights regarding your data, and the choices available to you.
This policy applies to all users of the AthenGuard compliance platform, including administrators, compliance officers, auditors, and end users within your organization.
1. Information We Collect
We collect information necessary to provide, secure, and improve the AthenGuard platform and related services.
1.1 Information You Provide Directly
Account and Profile Information:
- Full name, work email address, company name, job title, and department
- Account credentials, authentication details, and security preferences
- Multi-factor authentication settings and recovery information
- User preferences, notification settings, and interface customization
Organizational and Compliance Information:
- Organization structure, business units, and operational locations
- Compliance framework selections (SOC 2, ISO 27001, NDPR, PCI DSS, NIST, etc.)
- Custom policies, procedures, and control implementations
- Risk assessments, compliance gaps, and remediation plans
- Evidence uploads, documentation, and supporting materials
- Asset inventories, system classifications, and data mappings
Communications and Support:
- Support requests, help desk tickets, and troubleshooting information
- Feedback, feature requests, and product suggestions
- Communications via email, chat, or integrated messaging systems
- Training session participation and certification records
1.2 Information Collected Through Platform Use
Usage and Activity Data:
- Login events, session duration, and access patterns
- Feature utilization, dashboard interactions, and workflow completions
- Compliance check executions, evidence collection activities, and report generations
- Search queries, filter applications, and navigation paths
- Policy acknowledgments, control attestations, and approval workflows
System and Technical Data:
- IP addresses, device identifiers, and browser types
- Operating system versions and application configurations
- Connection timestamps, geographic locations, and timezone information
- Performance metrics, error logs, and diagnostic data
Audit and Compliance Tracking:
- Comprehensive audit trails of all system actions
- Policy modifications, access control changes, and configuration updates
- Evidence collection timestamps and validation results
- User actions within the platform, including creates, updates, and deletions
- Integration activities with connected systems and third-party services
Agent and Sensor Data:
- Asset discovery information from connected endpoints
- Configuration baselines and system state snapshots
- Security control validation results
- Vulnerability scan findings and patch status
- Log aggregation from monitored systems (when configured)
Strict Data Boundary: AthenGuard agents and sensors are technically restricted to collecting only metadata, configuration states, and compliance telemetry. Our agents do not—and cannot—access, copy, transmit, or store your underlying proprietary source code, customer database records, or sensitive business file contents.
1.3 Information We Do Not Collect
We are committed to data minimization:
- We do not collect personal information unrelated to platform operation
- We do not access file contents on monitored systems unless explicitly configured as compliance evidence
- We do not collect biometric data, health information, or financial account details
- We do not track your activities outside the AthenGuard platform
- We do not collect information from children under 13 years of age
2. How We Use Your Information
We use collected information solely to provide, secure, and improve our services.
2.1 Core Platform Operations
Service Delivery:
- Authenticate users and enforce role-based access controls (RBAC)
- Execute compliance assessments and automated evidence collection
- Generate compliance reports, audit documentation, and executive dashboards
- Maintain compliance mappings across multiple frameworks
- Support continuous monitoring and real-time compliance status tracking
Platform Performance:
- Monitor system health, availability, and performance metrics
- Optimize query performance and data retrieval operations
- Identify and resolve technical issues proactively
- Scale infrastructure to meet usage demands
2.2 Security and Trust
Security Operations:
- Detect, investigate, and respond to security incidents
- Prevent fraud, abuse, and unauthorized access attempts
- Identify anomalous behavior patterns and potential threats
- Maintain forensic audit trails for security investigations
- Enforce tenant isolation and data segregation
Compliance and Legal:
- Meet regulatory requirements and contractual obligations
- Support legal processes, subpoenas, and lawful requests
- Maintain records required by applicable laws and regulations
- Enable customer audits and third-party assessments
2.3 Communication and Support
Customer Communication:
- Respond to support requests and technical inquiries
- Provide product updates, security notifications, and maintenance alerts
- Share best practices, training materials, and compliance guidance
- Conduct user research and gather product feedback
- Deliver transactional emails related to account activity
2.4 Product Improvement
Analytics and Development:
- Analyze usage patterns to improve user experience
- Develop new features based on customer needs
- Test platform stability and feature functionality
- Optimize automation engines and evidence collection capabilities
- Conduct A/B testing for interface improvements (with user consent)
2.5 What We Do Not Do
Our Commitments:
- We do not sell, rent, or lease your data to third parties
- We do not use your information for advertising or marketing to non-customers
- We do not share data with third parties except as described in this policy
- We do not train AI models on your compliance data
- We do not make automated decisions that produce legal effects without human oversight
3. Data Security
Security is foundational to AthenGuard's design and operations.
3.1 Technical Safeguards
Encryption:
- TLS 1.3 for all data in transit
- AES-256 encryption for data at rest
- Encrypted database connections and internal service communication
- Key management using industry-standard practices (HSM-backed where applicable)
Access Controls:
- Multi-factor authentication (MFA) required for all users
- Role-based access control (RBAC) with principle of least privilege
- Just-in-time (JIT) access for administrative operations
- Session management with automatic timeout and secure token handling
- IP allowlisting and geographic access restrictions (when configured)
Network Security:
- Web application firewall (WAF) protection
- DDoS mitigation and rate limiting
- Network segmentation and tenant isolation
- Intrusion detection and prevention systems (IDS/IPS)
- Regular vulnerability scanning and penetration testing
Application Security:
- Secure software development lifecycle (SSDLC)
- Code review, static analysis, and dependency scanning
- Input validation and output encoding to prevent injection attacks
- CSRF, XSS, and clickjacking protections
- Security headers and content security policies (CSP)
3.2 Organizational Safeguards
Personnel Security:
- Background checks for employees with data access
- Mandatory security awareness training
- Confidentiality agreements and data handling policies
- Strict access controls to production environments
- Separation of duties for critical operations
Vendor Management:
- Security assessments of third-party service providers
- Data processing agreements (DPAs) with all vendors
- Regular vendor security reviews and audits
- Subprocessor transparency and approval processes
Incident Response:
- 24/7 security monitoring and alerting
- Documented incident response procedures
- 72-Hour Breach Notification: In the event of a confirmed data breach affecting your personal or organizational data, we commit to notifying affected account administrators without undue delay, and no later than 72 hours after discovery, aligning with strict global regulatory standards.
- Post-incident analysis and continuous improvement
3.3 Compliance Certifications
AthenGuard maintains security and privacy controls designed to support:
- SOC 2 Type II attestation
- ISO 27001 certification
- Nigeria Data Protection Regulation (NDPR) compliance
- PCI DSS where applicable
- GDPR adequacy for European customers
- Industry-specific frameworks as required by customer agreements
3.4 Physical Security
Our infrastructure partners maintain:
- 24/7 physical security and monitoring
- Biometric access controls to data centers
- Environmental controls and redundancy
- Regular security audits and compliance certifications
4. Data Sharing and Disclosure
We share data only when necessary and with appropriate safeguards.
4.1 Service Providers and Subprocessors
We engage carefully selected third-party service providers to support platform operations:
Infrastructure Providers:
- Cloud hosting services (data center locations disclosed to customers)
- Content delivery networks (CDN) for performance optimization
- Database and storage services
Operational Services:
- Email delivery and communication platforms
- Support ticketing and customer relationship management (CRM)
- Payment processing (we do not store full payment card details)
- Analytics and monitoring tools (with data anonymization where possible)
All service providers:
- Are contractually bound to protect your data
- Process data only as instructed by AthenGuard
- Maintain security standards commensurate with the sensitivity of data
- Are disclosed in our subprocessor list (available upon request)
4.2 Customer-Authorized Integrations
When you configure integrations with third-party services:
- Data is shared only to perform the requested function
- You control which data is shared through integration settings
- Integration partners process data under their own privacy policies
- You can revoke integration access at any time
Common integration categories include:
- Identity providers (SSO, SAML, OAuth)
- Ticketing systems (Jira, ServiceNow, etc.)
- Messaging platforms (Slack, Microsoft Teams, etc.)
- Cloud infrastructure providers (AWS, Azure, GCP)
- Security tools (SIEM, vulnerability scanners, etc.)
4.3 Legal and Regulatory Requirements
We may disclose information when legally required:
- In response to valid legal process (subpoena, court order, warrant)
- To comply with applicable laws and regulations
- To respond to lawful requests from government authorities
- To enforce our Terms of Service or protect our legal rights
- To protect the safety and security of our users or the public
We will:
- Challenge overbroad or inappropriate requests when legally permissible
- Notify affected customers unless prohibited by law
- Disclose only the minimum information necessary
- Document all legal requests in our transparency report (published annually)
4.4 Business Transfers
If AthenGuard is involved in a merger, acquisition, bankruptcy, or sale of assets:
- You will be notified via email and platform notice
- Your data will remain subject to this Privacy Policy unless you consent to changes
- You will have the option to delete your data before the transfer
- The successor entity will be bound by substantially similar privacy commitments
5. Data Retention
We retain data only as long as necessary for legitimate business purposes.
5.1 Retention Periods
Active Account Data:
- Retained throughout your subscription period
- Available for immediate access and compliance reporting
- Subject to customer-configured retention policies
Audit and Security Logs:
- Minimum retention: 1 year for security and compliance purposes
- Extended retention: up to 7 years where required by regulation
- Immutable logging for critical security events
Evidence and Compliance Records:
- Retained according to applicable regulatory requirements
- Configurable by customer based on audit and certification needs
- Typically 3-7 years for most compliance frameworks
Backup and Disaster Recovery:
- Encrypted backups retained for 30-90 days
- Used only for disaster recovery and business continuity
- Subject to same security and access controls as production data
Deleted Account Data:
- Account deletion initiated through platform settings or written request
- Data deletion completed within 90 days of account closure
- Some metadata may be retained for legal and security purposes
- Audit logs preserved as required by law
5.2 Data Deletion Process
Upon data retention period expiration or account deletion:
- Data is securely deleted using industry-standard methods
- Multi-pass overwriting for sensitive data
- Cryptographic erasure where encryption keys are destroyed
- Deletion verified through automated processes
- Certificates of destruction available upon request
5.3 Customer Control
You can manage retention through:
- Platform retention policy settings
- Evidence archival configurations
- Data export tools (before deletion)
- Custom retention schedules for specific data types
6. Your Rights and Choices
We respect your rights regarding your personal data.
6.1 Access and Portability
Right to Access:
- View all personal data we hold about you
- Request copies of your data in structured formats
- Obtain information about how your data is processed
Data Portability:
- Export compliance data in standard formats (CSV, JSON, PDF)
- Transfer data to another service provider
- Download complete audit trails and evidence packages
6.2 Correction and Update
Right to Rectification:
- Correct inaccurate or incomplete personal information
- Update your profile, preferences, and organizational details
- Request corrections through platform interface or support
6.3 Deletion and Restriction
Right to Erasure ("Right to be Forgotten"):
- Request deletion of personal data when no longer necessary
- Remove specific data elements or entire accounts
- Subject to legal retention requirements and legitimate business needs
Right to Restriction:
- Limit processing of your data in certain circumstances
- Object to specific processing activities
- Restrict automated evidence collection for particular systems
6.4 Objection and Withdrawal
Right to Object:
- Object to processing based on legitimate interests
- Opt-out of non-essential communications
- Disable specific features or integrations
Consent Withdrawal:
- Withdraw consent for optional data processing
- Disable cookies and tracking (where applicable)
- Revoke integration permissions
6.5 Automated Decision-Making
AthenGuard uses automated processing for:
- Compliance scoring and risk calculations
- Evidence validation and control assessments
- Alert generation and anomaly detection
You have the right to:
- Understand the logic behind automated decisions
- Request human review of automated assessments
- Challenge and correct automated findings
6.6 Exercising Your Rights
To exercise these rights:
- Use in-platform tools for self-service requests
- Contact our privacy team at
- Submit requests through your Customer Success Manager
We will:
- Respond within 30 days (45 days for complex requests)
- Verify your identity before processing requests
- Provide clear explanations for any limitations or denials
- Notify third parties if we have shared your data and you request deletion
6.7 Regional Privacy Rights
For Nigerian Users (NDPR/NDPA):
- Right to request disclosure of personal data collected
- Right to request deletion after withdrawal of consent
- Right to file complaints with the Nigeria Data Protection Commission (NDPC)
- Data localization options available for public sector entities
For European Users (GDPR):
- All rights outlined above apply
- Right to lodge complaints with supervisory authorities
- Data transfers governed by Standard Contractual Clauses (SCCs)
- EU representative available for direct contact
For California Users (CCPA/CPRA):
- Right to know what personal information is collected and shared
- Right to opt-out of data "sales" (we don't sell data)
- Right to non-discrimination for exercising privacy rights
- Authorized agent requests accepted with verification
7. International Data Transfers
AthenGuard operates globally and may transfer data across borders.
7.1 Data Residency Options
We offer:
- Primary data centers: United States, European Union, Nigeria
- Customer-selectable regions for data storage
- Data localization for customers with specific requirements
- Multi-region deployment for global enterprises
7.2 Transfer Mechanisms
When transferring data internationally, we rely on:
- Standard Contractual Clauses (SCCs) approved by relevant authorities
- Adequacy decisions where available
- Binding Corporate Rules for intra-company transfers
- Explicit consent where required and appropriate
7.3 Security During Transfer
All international transfers include:
- Encryption in transit and at rest
- Access controls and monitoring
- Audit logging of cross-border data flows
- Compliance with destination country requirements
8. Cookies and Tracking Technologies
8.1 Types of Cookies
Essential Cookies:
- Authentication and session management
- Security and fraud prevention
- Load balancing and performance
- Cannot be disabled without affecting platform functionality
Functional Cookies:
- User preferences and settings
- Interface customization
- Language and timezone selections
- Can be managed through platform settings
Analytics Cookies:
- Usage patterns and feature adoption
- Performance monitoring
- Error tracking and diagnostics
- Optional; can be disabled in preferences
8.2 Third-Party Cookies
- Limited to essential service providers
- Subject to same privacy standards
- Listed in our cookie policy (available on request)
- No advertising or tracking cookies
8.3 Managing Cookies
You can control cookies through:
- Browser settings and preferences
- Platform privacy settings
- Third-party cookie management tools
- Opt-out mechanisms provided by analytics services
9. Children's Privacy
AthenGuard is designed for business use and not intended for children under 13 (or applicable age in your jurisdiction).
We do not:
- Knowingly collect information from children
- Market services to children
- Allow children to create accounts
If we discover we have inadvertently collected data from a child:
- We will delete it promptly
- We will notify the organization administrator
- We will implement additional controls to prevent recurrence
10. Privacy by Design
Privacy is embedded in AthenGuard's architecture and operations.
10.1 Technical Measures
- Default privacy settings prioritize data protection
- Data minimization in collection and retention
- Purpose limitation for all processing activities
- Tenant isolation and segregation
- Encryption and pseudonymization where appropriate
10.2 Organizational Measures
- Privacy impact assessments for new features
- Regular privacy training for employees
- Data protection officer oversight
- Privacy-focused vendor selection
- Continuous compliance monitoring
10.3 Transparency
We commit to:
- Clear, accessible privacy communications
- Advance notice of material policy changes
- Regular transparency reports
- Open dialogue with customers and regulators
11. Changes to This Privacy Policy
11.1 Updates and Notifications
We may update this Privacy Policy to reflect:
- Changes in legal requirements
- New features or services
- Evolving industry practices
- Customer feedback and requests
How we notify you:
- Email to account administrators
- In-platform notifications
- Banner notices for material changes
- 30 days advance notice for significant changes
11.2 Acceptance
Continued use after changes constitutes acceptance. If you disagree:
- Contact us to discuss concerns
- Export your data before the effective date
- Terminate your account if necessary
11.3 Version History
- Current version: December 30, 2025
- Previous versions available upon request
- Changelog maintained for transparency
12. Contact Us
12.1 Privacy Inquiries
Email:
Subject line: Privacy Policy Question
Mailing Address:
AthenGuard Privacy Team
BafaTech Consulting
12.2 Data Protection Officer
For privacy-related matters:
Response time: Within 5 business days for acknowledgment
12.3 Complaints and Concerns
If you believe we have not handled your data appropriately:
- Contact our privacy team first. We will investigate and respond within 30 days.
- If unresolved, you may contact:
- United States: Your state's Attorney General (e.g., the Georgia Attorney General's Consumer Protection Division)
- Nigeria: Nigeria Data Protection Commission (NDPC) (www.ndpc.gov.ng)
- EU: Your local Data Protection Authority
- California: California Attorney General
Appendix A: Definitions
- Personal Data: Any information relating to an identified or identifiable individual.
- Processing: Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- Data Controller: The entity that determines purposes and means of processing (typically your organization).
- Data Processor: The entity that processes data on behalf of the controller (AthenGuard).
- Tenant: A distinct organizational instance within the AthenGuard platform with isolated data.
Appendix B: Legal Bases for Processing
We process your data based on:
- Contract Performance: Necessary to provide the service you requested
- Legitimate Interests: For security, fraud prevention, and service improvement
- Legal Obligation: To comply with laws and regulations
- Consent: Where you have given explicit permission (withdrawable at any time)
This Privacy Policy was last updated on December 30, 2025 and is effective immediately.