GDPR and UK GDPR Compliance
Athena Security’s weapons detection and screening systems are designed to meet the EU General Data Protection Regulation (GDPR) and the UK GDPR. For hospitals, schools, government buildings, venues, and workplaces in the EU and UK, Athena acts as a data processor under Article 28: you decide what is collected and why, and Athena processes it only on your instructions.
Your data stays in the EU and UK
Data from EU and UK customers is hosted exclusively in Linode data centers in Frankfurt, Amsterdam and London and in Amazon Web Services regions inside the European Union. Athena’s infrastructure is configured so that screening data cannot leave the EU and UK. Access from United States networks is blocked, and no US-based subprocessor hosts EU or UK screening data. Because there is no international transfer of screening data, no Standard Contractual Clauses or adequacy mechanism is required for the core service. Data held in London is covered by the European Commission’s adequacy decision for the United Kingdom.
Email, SMS and support correspondence are handled by Mailgun, Twilio and Google Workspace in the United States, and network traffic passes through Cloudflare, each under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum; none of them ever receives alert images. The full list is at athena-security.com/compliance/subprocessors.
Built for data minimization
- Images optional. The system can run without storing images of people, or without capturing images at all. You choose.
- You define every field. Incident records contain only the fields you create. Nothing is collected by default that you have not configured.
- Encrypted on the device. Where personal data or health data is captured, it is encrypted on the screening tablet with keys held only on that device. Athena cannot decrypt it.
- Detection on the device. AI analysis runs on the screening device at your site, not on our servers; only the resulting alert is sent to the platform.
- No AI training on your data. Your alert data is never used to train or improve Athena’s detection models.
- No facial recognition by default. Athena’s detection systems do not identify individuals. Any optional identification feature is disabled by default and can be enabled only by you, after you have confirmed it is lawful for your organization.
Control and accountability
- Your retention rules. Set retention separately for confirmed-threat and non-threat records.
- Your delete button. Request deletion of any record, or all records for a named individual, at any time through a support ticket; the ticket gives you an audit trail of every deletion request. Backups purge within 30 days.
- Audited access. Athena staff cannot access your data without a support ticket you have raised. Access uses two-factor authentication and is audited and fully logged; you can view every log entry.
- No remote access. Athena never has remote control of your systems. Remote viewing for troubleshooting happens only after you approve the request in-product, and your screen shows when it is active.
- Data subject requests. Export or erase all records for a named individual to answer access and erasure requests within the one-month deadline.
- 72-hour breach notification to your organization, within the Article 33 deadline, with all incidents published at status.athena-security.com.
- Human decision on every alert. AI flags a possible threat; a trained person makes the decision.
- SOC 2 Type II audited security program.
Documents for your Data Protection Officer
- Article 28 Data Processing Agreement
- DPIA Support Document — the technical input for your Data Protection Impact Assessment
- Record of Processing Activities summary
- Subprocessor List
The DPIA Support Document and Record of Processing Activities are available on request from [email protected].
Frequently asked questions
Is Athena GDPR certified? There is no general GDPR certification scheme in force for vendors. Athena meets its processor obligations under Article 28, and our Data Processing Agreement, Record of Processing Activities, and SOC 2 Type II report let your DPO verify it.
Does any of our data go to the United States? Screening data does not. EU and UK customer screening data is hosted only in Linode’s Frankfurt, Amsterdam and London data centers and AWS EU regions, and Athena blocks access from US networks. Email, SMS and support correspondence, and network traffic through Cloudflare, are the only exceptions; they are covered by Standard Contractual Clauses and never contain alert images.
Does the system identify people? Not by default. Weapons detection identifies objects, not people. Where an image of a person is captured, it is not linked to a name unless your staff create an incident record. Any optional identification feature is off by default and enabled only by you.
Do we need a DPIA? Probably yes: entrance screening is systematic monitoring of a publicly accessible area under Article 35(3)(c). You own the DPIA; Athena provides the technical half in our DPIA Support Document.
Who is Athena’s Data Protection Officer? Garrett Dilmore, [email protected].
Does Athena have an EU or UK representative under Article 27? Appointment is in progress. Until it is complete, EU and UK data subjects and supervisory authorities may contact our Data Protection Officer, Garrett Dilmore, directly at [email protected].
Does Athena comply with the EU AI Act? Athena is preparing for the AI Act’s obligations for AI systems used in safety and security settings, including technical documentation, logging, and human oversight, which is already built into every product. See our AI Act statement.
Contact [email protected] with any question about data protection.
