Oleo Bone
Schedule Demo

Athena Security Subprocessors and Data Processing Partners

Last updated: 2 October 2026

This page lists every third party that processes personal data on Athena’s behalf, what each one does, where it processes data for US and for EU/UK Customers, and the legal mechanism that covers any transfer outside the EU and UK. It is referenced by our Privacy Policy, Student Data Privacy Policy, Parents’ Bill of Rights, GDPR and UK GDPR page, and Data Processing Agreement, and is incorporated into those documents by reference. For security, privacy and compliance documentation, visit the Athena Security Trust Center at trust.athena-security.com.

We give Customers at least 30 days’ written notice before adding or replacing a subprocessor that handles Customer data, and Customers may object in writing within that period. To receive notices, email [email protected] with the subject “Subprocessor notifications”.

Subprocessors for Customer data (Athena as processor)

Subprocessor Service What Athena uses it for Data it handles US Customers EU and UK Customers EU/UK transfer mechanism
Linode, an Akamai company (Akamai Technologies, Inc.) Cloud infrastructure Application hosting, databases, APIs, logs, reports and backups for the Athena Compliance Platform and apps Incident records, visitor records (including personal and health data a Customer configures), account data, audit logs, reports; encrypted at rest US data centers Frankfurt and Amsterdam (EU); London (UK) None required: hosted in the EU and UK; London covered by the EU adequacy decision for the UK
Amazon Web Services (Amazon Web Services, Inc. / AWS EMEA SARL) Cloud infrastructure Storage of alert images only Alert images encrypted on the screening device with keys Athena cannot access US regions EU regions None required: hosted in the EU
Cloudflare, Inc. Network security, CDN and DNS Protection of athena-security.com and platform endpoints against attack; traffic routing Encrypted traffic in transit and connection metadata such as IP address; nothing stored Global edge network Global edge network, EU traffic served from EU points of presence EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum
Mailgun (Sinch Mailgun, Inc.) Transactional email delivery Account, alert and report emails sent by the platform Recipient email address and message content; never alert images United States United States EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum
Google LLC (Google Workspace, Gmail) Business email Support and business correspondence with Customers Contact details and correspondence content a Customer sends us; never alert images United States United States EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum
Twilio Inc. SMS delivery Text-message alert links where a Customer enables SMS Telephone number and a login-protected link; no images or personal data in message content United States United States EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum
Google LLC (Firebase Cloud Messaging) Push notifications Delivery of alert links to Android devices Device token and a login-protected link; no images or personal data in message content United States United States Not applicable: no personal data transferred
Apple Inc. (Apple Push Notification service) Push notifications Delivery of alert links to iOS devices Device token and a login-protected link; no images or personal data in message content United States United States Not applicable: no personal data transferred

There are no other subprocessors for Customer screening, incident or visitor data.

How data is protected before it reaches a subprocessor

Where each kind of data lives

Retention

The Customer sets retention separately for confirmed-threat records and non-threat records. A common configuration is five years for confirmed threats, to satisfy state violence-record rules, and 30 days for everything else. For K-12 Customers that have not configured retention, both default to five years. Deleted data is purged from every subprocessor’s backups within 30 days.

Student data (K-12 Customers)

No subprocessor receives a roster, student ID or any list of students. A student’s name exists only in an incident record a school staff member creates, held on Linode. Athena acts as a school official under FERPA, and every subprocessor is bound to the same obligations by contract. See the Student Data Privacy Policy for the full commitments.

EU and UK Customers

Screening data for EU and UK Customers is hosted only in Linode’s Frankfurt, Amsterdam and London data centers and in AWS EU regions, and access from US networks is blocked. The US-located services in the table above receive only notification links, email and support correspondence, never alert images, under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. See the GDPR and UK GDPR page and our Data Processing Agreement.

Facial recognition

Athena’s detection systems identify objects, not people. Facial recognition is off by default, is offered only to healthcare Customers, and can be enabled only after the Customer confirms a lawful basis and completes a data protection impact assessment. No subprocessor performs facial recognition on Athena’s behalf.

Processors for Athena’s own website and marketing (Athena as controller)

Processor What it does Location
Google LLC (Google Analytics, Google Ads) Website analytics and advertising measurement, consent-based United States and EU
LinkedIn Corporation (Insight Tag) B2B advertising measurement, consent-based United States and EU
Meta Platforms, Inc. (Meta Pixel) Advertising measurement, consent-based United States and EU
CRM provider Prospect and customer relationship records United States
Payment processor Card payments for purchases; Athena does not store card data United States

Changes to this list

Athena gives Customers at least 30 days’ written notice before adding or replacing a subprocessor that handles Customer data, and Customers may object in writing within that period under their Data Processing Agreement. To receive notices, email [email protected] with the subject “Subprocessor notifications”.

Contact

Questions about subprocessors, data processing, GDPR or FERPA: [email protected]. Data Protection Officer: Garrett Dilmore. Trust Center: trust.athena-security.com.

Download Now