Oleo Bone
Schedule Demo

GDPR and UK GDPR Compliance

Athena Security’s weapons detection and screening systems are designed to meet the EU General Data Protection Regulation (GDPR) and the UK GDPR. For hospitals, schools, government buildings, venues, and workplaces in the EU and UK, Athena acts as a data processor under Article 28: you decide what is collected and why, and Athena processes it only on your instructions.

Your data stays in the EU and UK

Data from EU and UK customers is hosted exclusively in Linode data centers in Frankfurt, Amsterdam and London and in Amazon Web Services regions inside the European Union. Athena’s infrastructure is configured so that screening data cannot leave the EU and UK. Access from United States networks is blocked, and no US-based subprocessor hosts EU or UK screening data. Because there is no international transfer of screening data, no Standard Contractual Clauses or adequacy mechanism is required for the core service. Data held in London is covered by the European Commission’s adequacy decision for the United Kingdom.

Email, SMS and support correspondence are handled by Mailgun, Twilio and Google Workspace in the United States, and network traffic passes through Cloudflare, each under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum; none of them ever receives alert images. The full list is at athena-security.com/compliance/subprocessors.

Built for data minimization

Control and accountability

Documents for your Data Protection Officer

The DPIA Support Document and Record of Processing Activities are available on request from [email protected].

Frequently asked questions

Is Athena GDPR certified? There is no general GDPR certification scheme in force for vendors. Athena meets its processor obligations under Article 28, and our Data Processing Agreement, Record of Processing Activities, and SOC 2 Type II report let your DPO verify it.

Does any of our data go to the United States? Screening data does not. EU and UK customer screening data is hosted only in Linode’s Frankfurt, Amsterdam and London data centers and AWS EU regions, and Athena blocks access from US networks. Email, SMS and support correspondence, and network traffic through Cloudflare, are the only exceptions; they are covered by Standard Contractual Clauses and never contain alert images.

Does the system identify people? Not by default. Weapons detection identifies objects, not people. Where an image of a person is captured, it is not linked to a name unless your staff create an incident record. Any optional identification feature is off by default and enabled only by you.

Do we need a DPIA? Probably yes: entrance screening is systematic monitoring of a publicly accessible area under Article 35(3)(c). You own the DPIA; Athena provides the technical half in our DPIA Support Document.

Who is Athena’s Data Protection Officer? Garrett Dilmore, [email protected].

Does Athena have an EU or UK representative under Article 27? Appointment is in progress. Until it is complete, EU and UK data subjects and supervisory authorities may contact our Data Protection Officer, Garrett Dilmore, directly at [email protected].

Does Athena comply with the EU AI Act? Athena is preparing for the AI Act’s obligations for AI systems used in safety and security settings, including technical documentation, logging, and human oversight, which is already built into every product. See our AI Act statement.

Contact [email protected] with any question about data protection.

Download Now