Data Processing Addendum
For creators who need one. How we process personal data on your behalf, and the list of every provider that processes it for us.
Last updated
This addendum is part of the Terms of Service. It applies when you use athna to process personal data (your team's, your audience's, anyone's) and the GDPR, the UK GDPR, the CCPA or a similar law makes you responsible for that data. It says what we do with it as your processor, and it lists every company that touches it on our behalf.
If you need a signed copy for your own records, email hello@athna.ai and we'll send one.
Who's who
- You are the controller (under the CCPA, the business): you decide what data goes into your workspace and why.
- Athna, Inc. is the processor (the service provider): we handle that data only to run athna for you.
- Subprocessors are the companies we use to run athna, listed below. They handle data only on our instructions.
For the data we collect about you as our customer (your account, your billing, your use of the product) we're the controller, and the Privacy Policy applies instead.
What we process, and why
The data: whatever you and your team put in your brand workspace (posts, scripts, notes, messages, files, ideas), the profile and performance data copied from the accounts you connect, and the account details of the people you add. It may include the personal data of your teammates, your editors, your audience (in comments and messages) and anyone who appears in your content.
Why: to provide the service described in the terms. Storing it, showing it to the people you've scoped, publishing it where you tell us to, and running athna AI over it for you. Nothing else.
How long: for as long as you have an account, then deleted on the Data deletion schedule.
What we promise
- Only on your instructions. We process the data to provide the service and as you direct through the product. If the law requires us to do something else, we'll tell you first unless the law forbids it.
- Confidentiality. Everyone at athna who can reach the data is bound to keep it confidential. Today that's the two founders.
- Security. The measures in the Security policy (encryption in transit and at rest, access tokens encrypted with a separate key, every table locked down, least-privilege access, monitoring, tested backups) are the technical and organizational measures for this addendum.
- Subprocessors. We use the ones listed below, under written contracts that bind them to protections at least as strong as these. We'll list a new one on this page at least 30 days before it starts handling data; if you object and we can't resolve it, you can end your subscription and we'll refund the unused part.
- Helping with rights requests. If someone in your data asks you to see, correct or delete it, the product lets you do it yourself. Where it doesn't, we'll help within a reasonable time.
- Helping with your obligations. We'll give you what you reasonably need for a data protection impact assessment or a consultation with a regulator, given what we know.
- Breaches. If we learn of a breach affecting your data, we'll tell you without undue delay and no later than 72 hours after confirming it, with what we know and what we're doing.
- Deletion. When you delete your account, or on your written request, we delete or return the data as described in Data deletion, except what the law requires us to keep.
- Showing our work. Once a year, on request, we'll answer a reasonable written security questionnaire and share the compliance reports our subprocessors give us. If a regulator or your own obligations require an audit, we'll cooperate with an independent auditor at your cost, on 30 days' notice, no more than once a year unless a breach has happened.
Where the data goes
We're in the United States and our subprocessors are mostly there too. For data covered by the GDPR or the UK GDPR, transfers to us and to our subprocessors rest on the EU Standard Contractual Clauses (and the UK Addendum) in each provider's terms, or on the EU-US Data Privacy Framework where the provider is certified. Ask and we'll point you at the specific document for any provider below.
Subprocessors
Every company that processes data on our behalf today. Each one is used for exactly what the table says.
| Company | What it does for athna | Where |
|---|---|---|
| Supabase | The database and file storage behind athna | United States |
| Vercel | Hosts the website and the product; runs our server code | United States, with a global edge network for serving pages |
| Cloudflare | DNS for athna.ai | Global |
| Resend | Sends our email: confirmations, invites, notifications | United States |
| Upstash | Rate limiting and short-lived caches (Redis) | United States |
| Inngest | Runs background jobs: scheduled publishing, transcription, imports | United States |
| Anthropic | The language models behind athna AI | United States |
| Voyage AI | Turns text into embeddings so athna AI can search your workspace by meaning | United States |
| Deepgram | Speech-to-text for footage and voice captures | United States |
| fal | Image generation for thumbnails | United States |
| PostHog | Product analytics: which features are used | United States |
| Sentry | Error reports, scrubbed of content before they're sent | United States |
The AI providers receive only the content a request needs, only when you use the feature, and are not allowed to train on it. The AI terms say more.
CCPA
If the CCPA applies to you, we're your service provider: we don't sell or share the personal data, we don't keep, use or disclose it for any purpose other than providing the service, and we don't combine it with data from anyone else except to provide the service. We'll tell you if we can no longer meet these obligations.
The rest
This addendum lasts as long as we process data for you. If it conflicts with the terms, this addendum wins on the subject of personal data. The liability limits in the terms apply to it. It's governed by the same law as the terms.