Athena Security Subprocessors and Data Processing Partners
Last updated: 2 October 2026
This page lists every third party that processes personal data on Athena’s behalf, what each one does, where it processes data for US and for EU/UK Customers, and the legal mechanism that covers any transfer outside the EU and UK. It is referenced by our Privacy Policy, Student Data Privacy Policy, Parents’ Bill of Rights, GDPR and UK GDPR page, and Data Processing Agreement, and is incorporated into those documents by reference. For security, privacy and compliance documentation, visit the Athena Security Trust Center at trust.athena-security.com.
We give Customers at least 30 days’ written notice before adding or replacing a subprocessor that handles Customer data, and Customers may object in writing within that period. To receive notices, email [email protected] with the subject “Subprocessor notifications”.
Subprocessors for Customer data (Athena as processor)
| Subprocessor | Service | What Athena uses it for | Data it handles | US Customers | EU and UK Customers | EU/UK transfer mechanism |
|---|---|---|---|---|---|---|
| Linode, an Akamai company (Akamai Technologies, Inc.) | Cloud infrastructure | Application hosting, databases, APIs, logs, reports and backups for the Athena Compliance Platform and apps | Incident records, visitor records (including personal and health data a Customer configures), account data, audit logs, reports; encrypted at rest | US data centers | Frankfurt and Amsterdam (EU); London (UK) | None required: hosted in the EU and UK; London covered by the EU adequacy decision for the UK |
| Amazon Web Services (Amazon Web Services, Inc. / AWS EMEA SARL) | Cloud infrastructure | Storage of alert images only | Alert images encrypted on the screening device with keys Athena cannot access | US regions | EU regions | None required: hosted in the EU |
| Cloudflare, Inc. | Network security, CDN and DNS | Protection of athena-security.com and platform endpoints against attack; traffic routing | Encrypted traffic in transit and connection metadata such as IP address; nothing stored | Global edge network | Global edge network, EU traffic served from EU points of presence | EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum |
| Mailgun (Sinch Mailgun, Inc.) | Transactional email delivery | Account, alert and report emails sent by the platform | Recipient email address and message content; never alert images | United States | United States | EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum |
| Google LLC (Google Workspace, Gmail) | Business email | Support and business correspondence with Customers | Contact details and correspondence content a Customer sends us; never alert images | United States | United States | EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum |
| Twilio Inc. | SMS delivery | Text-message alert links where a Customer enables SMS | Telephone number and a login-protected link; no images or personal data in message content | United States | United States | EU Standard Contractual Clauses (Module Two) and UK International Data Transfer Addendum |
| Google LLC (Firebase Cloud Messaging) | Push notifications | Delivery of alert links to Android devices | Device token and a login-protected link; no images or personal data in message content | United States | United States | Not applicable: no personal data transferred |
| Apple Inc. (Apple Push Notification service) | Push notifications | Delivery of alert links to iOS devices | Device token and a login-protected link; no images or personal data in message content | United States | United States | Not applicable: no personal data transferred |
There are no other subprocessors for Customer screening, incident or visitor data.
How data is protected before it reaches a subprocessor
- Encrypted on the device. Alert images, and any personal or health data captured by an Athena application, are encrypted on the screening device before transmission. Keys are held only on that device; Athena and its subprocessors cannot decrypt them.
- Images and application data are kept apart. AWS holds only encrypted alert images. Linode holds all other platform data. No single provider holds both.
- Encrypted in transit and at rest. TLS 1.3 in transit, AES-256 at rest, at every provider.
- Notifications carry links, not data. Push, SMS and email alerts contain a login-protected link that expires after a Customer-set period, typically 12 hours. Images never leave the platform.
- Retention is the Customer’s. Confirmed-threat and non-threat records carry separate retention periods set by the Customer; backups purge within 30 days of deletion.
- No AI training. Customer data is never used to train or improve Athena’s detection models, and detection runs on the screening device, not at any subprocessor.
Where each kind of data lives
- Alert images are encrypted on the screening device and stored in AWS. Nothing else is stored there.
- Incident records, visitor records, account data, audit logs and reports are stored on Linode. No alert images are stored there.
- Notifications reach staff through Apple, Google, Twilio and Mailgun as a login-protected link. The image itself stays in the platform and is viewed only after sign-in; links expire after a Customer-set period, typically 12 hours.
- Website and API traffic passes through Cloudflare’s edge network, encrypted; Cloudflare stores no Customer data.
- Support and business email runs on Google Workspace.
Retention
The Customer sets retention separately for confirmed-threat records and non-threat records. A common configuration is five years for confirmed threats, to satisfy state violence-record rules, and 30 days for everything else. For K-12 Customers that have not configured retention, both default to five years. Deleted data is purged from every subprocessor’s backups within 30 days.
Student data (K-12 Customers)
No subprocessor receives a roster, student ID or any list of students. A student’s name exists only in an incident record a school staff member creates, held on Linode. Athena acts as a school official under FERPA, and every subprocessor is bound to the same obligations by contract. See the Student Data Privacy Policy for the full commitments.
EU and UK Customers
Screening data for EU and UK Customers is hosted only in Linode’s Frankfurt, Amsterdam and London data centers and in AWS EU regions, and access from US networks is blocked. The US-located services in the table above receive only notification links, email and support correspondence, never alert images, under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. See the GDPR and UK GDPR page and our Data Processing Agreement.
Facial recognition
Athena’s detection systems identify objects, not people. Facial recognition is off by default, is offered only to healthcare Customers, and can be enabled only after the Customer confirms a lawful basis and completes a data protection impact assessment. No subprocessor performs facial recognition on Athena’s behalf.
Processors for Athena’s own website and marketing (Athena as controller)
| Processor | What it does | Location |
|---|---|---|
| Google LLC (Google Analytics, Google Ads) | Website analytics and advertising measurement, consent-based | United States and EU |
| LinkedIn Corporation (Insight Tag) | B2B advertising measurement, consent-based | United States and EU |
| Meta Platforms, Inc. (Meta Pixel) | Advertising measurement, consent-based | United States and EU |
| CRM provider | Prospect and customer relationship records | United States |
| Payment processor | Card payments for purchases; Athena does not store card data | United States |
Changes to this list
Athena gives Customers at least 30 days’ written notice before adding or replacing a subprocessor that handles Customer data, and Customers may object in writing within that period under their Data Processing Agreement. To receive notices, email [email protected] with the subject “Subprocessor notifications”.
Contact
Questions about subprocessors, data processing, GDPR or FERPA: [email protected]. Data Protection Officer: Garrett Dilmore. Trust Center: trust.athena-security.com.
