Privacy Policy & Data Protection

Your privacy is fundamental to our mission. We're committed to protecting your data with enterprise-grade security and complete transparency.

Last Updated: January 1, 2025Version 2.0

GDPR

EU Data Protection

CCPA

California Privacy Rights

ISO 27001

Information Security

SOC 2 Type II

Security Controls

How We Handle Your Data

Six key principles that guide our data practices

Information We Collect

Account, AWS integration, and usage data

  • Account information (name, email, company)
  • AWS credentials (encrypted)
  • Resource metadata and metrics
  • Usage analytics and logs

How We Use Data

Service delivery and platform improvement

  • Infrastructure monitoring and management
  • Cost optimization recommendations
  • Security alerts and notifications
  • Platform enhancement and support

Data Security

Enterprise-grade protection measures

  • AES-256 encryption at rest
  • TLS 1.3 for data in transit
  • ISO 27001 certified processes
  • 24/7 security monitoring

Data Sharing

Transparent third-party policies

  • No selling of personal data
  • Service providers only (AWS, Stripe)
  • Legal compliance when required
  • Your explicit consent for others

Your Rights

Complete control over your data

  • Access and export your data
  • Request corrections or deletion
  • Opt-out of communications
  • Data portability options

Data Retention

Clear retention and deletion policies

  • Active data while subscribed
  • 30-day grace after cancellation
  • 7-year billing record retention
  • Immediate deletion on request

Your Data Rights

Exercise complete control over your personal information

Access

Request a copy of your personal data

Rectification

Correct inaccurate information

Erasure

Request deletion of your data

Portability

Export data in standard format

Detailed Privacy Information

Complete transparency about our data practices

Information Collection

We collect information necessary to provide our services effectively:

**Account Information** When you create an account, we collect your name, email address, company name, and billing information. This information is essential for account management and service delivery.

**AWS Integration Data** To monitor and manage your infrastructure, we securely store encrypted AWS credentials and collect resource metadata, performance metrics, and cost data. All credentials are encrypted using AES-256 encryption.

**Usage Information** We collect usage data to improve our services, including feature usage patterns, error logs, and performance metrics. This helps us optimize the platform and provide better support.

**Device and Browser Information** We automatically collect technical information like IP addresses, browser type, and device information for security and compatibility purposes.

Data Usage

Your data is used exclusively to provide and improve our services:

**Service Delivery** We use your information to monitor AWS resources, generate cost reports, send alerts, process payments, and provide customer support.

**Platform Improvement** Analytics help us understand usage patterns, develop new features, enhance security, and optimize performance.

**Communication** We send service updates, security alerts, and product announcements (with your consent). You can manage communication preferences in your account settings.

**Legal Compliance** We may use information to comply with legal obligations, protect our rights, and ensure platform security.

Security Measures

We implement comprehensive security measures to protect your data:

**Technical Safeguards** • AES-256 encryption for data at rest • TLS 1.3 for all data transmission • Multi-factor authentication support • Regular security audits and penetration testing • Secure key management systems

**Operational Security** • ISO 27001 certified processes • Background checks for all employees • Strict access controls and audit logging • Regular security training programs • Incident response procedures

**Infrastructure Protection** • Secure data centers with redundancy • Real-time threat monitoring • DDoS protection • Regular backups across multiple regions

Third-Party Services

We work with trusted partners to deliver our services:

**AWS Integration** Your AWS resources are accessed using the credentials you provide. We follow AWS security best practices and never store unencrypted credentials.

**Payment Processing** Payment information is processed by PCI-compliant providers (Stripe). We never store credit card details on our servers.

**Analytics Services** We use privacy-focused analytics to understand usage patterns. Data is anonymized and aggregated where possible.

**No Data Sales** We never sell, trade, or rent your personal information to third parties.

International Transfers

Your data may be processed in multiple locations:

**Data Centers** • Primary servers in United States (US-East-1) • Backup servers in EU (eu-west-1) and Asia-Pacific (ap-southeast-1) • CDN edge locations globally for performance

**Compliance Frameworks** • EU-US Data Privacy Framework participant • Standard Contractual Clauses for EU data • GDPR compliance for EU residents • CCPA compliance for California residents

Your Privacy Rights

You have complete control over your personal information:

**Access and Portability** Request a copy of all your personal data in a machine-readable format. Access audit logs showing who accessed your data and when.

**Correction and Deletion** Update incorrect information at any time through your account settings. Request complete deletion of your account and associated data.

**Communication Preferences** Opt-out of marketing emails while maintaining service notifications. Customize alert preferences and notification channels.

**Data Processing** Object to certain data processing activities. Restrict processing while disputes are resolved.

Cookie Policy

We use cookies to improve your experience:

**Essential Cookies** Required for authentication, security, and core functionality. Cannot be disabled while using the service.

**Analytics Cookies** Help us understand usage patterns and improve performance. Can be disabled in cookie preferences.

**Preference Cookies** Remember your settings and preferences across sessions. Enhance user experience without tracking.

You can manage cookie preferences through your browser settings or our cookie preference center.

Updates and Contact

**Policy Updates** We may update this Privacy Policy to reflect changes in our practices or legal requirements. We'll notify you of material changes via email at least 30 days before they take effect.

**Contact Information** For privacy-related questions or to exercise your rights:

**Data Protection Officer** Email: privacy@athenacloud.com Phone: +1 (555) 123-4567

**Mailing Address** Athena Cloud Native Services 123 Cloud Street, Suite 500 San Francisco, CA 94105

**Response Time** We respond to all privacy requests within 48 hours and resolve them within 30 days as required by law.

Have Privacy Questions?

Our Data Protection Officer is here to help

48-hour response time GDPR compliant Your data, your control