1. Introduction
This Privacy Notice describes how Elemental Insights LLC ("Athena", "we", "us") collects, uses, shares, and protects your personal information when you use the Athena Forms™ platform ("Platform") on behalf of your employer ("Customer").
For most of the data you submit through the Platform (observations, incident reports, photos, CAPAs, chat messages), your employer is the data controller (they decide what gets collected and why), and Athena is the data processor (we host and process it on their behalf, governed by the Data Processing Agreement signed with them).
For data about you specifically as a user (your account, your sign-in metadata, your individual usage of AI features), this Notice describes what Athena does directly. Where your employer's contract differs, that contract controls.
2. What data we collect
Account data. Name and email address (required for sign-in); your role within your organization (worker, observer, admin, owner); workplace assignments (location, department, shift) set by your admin; last sign-in timestamp, IP address at sign-in, and session metadata. Account data is provided by you or your admin at the time of account creation.
Operational data you generate by using the Platform: safety checklist observations (including behavior-based safety, BBS) with comments and assessments; incident reports including OSHA classifications, narratives, and body fields (body part, nature of injury); corrective and preventive actions (CAPAs) including titles, descriptions, due dates, and status; photos and other file attachments; chat conversations with our AI assistant (Athena); and help-desk tickets and feedback.
Technical data. HTTP request logs (URL, user-agent, IP address) held by our hosting provider (Vercel); database query logs held by our database provider (Supabase); and AI interaction logs (which feature, timestamp, token usage, cost) held by us.
We do not collect any frontend telemetry today. We do not use Google Analytics, Sentry, PostHog, or similar tools. If we add such tools in the future, this policy will be updated and you will be re-prompted to accept.
3. How we use your data
- Provide the Platform's core functionality (observations, incidents, CAPAs, chat, and so on).
- Authenticate you and protect your account.
- Send transactional emails (password resets, notifications, scheduled reports).
- Send transactional SMS to operators (optional; off unless explicitly configured).
- Process Customer Data through AI features, with a person making every final determination.
- Diagnose and fix bugs, and comply with legal obligations.
We do not sell your data. We do not use your data for advertising. We do not allow our sub-processors to use your data for their own product improvement (no training on your data).
4. Who we share your data with: sub-processors
We use a small, disclosed set of infrastructure providers (currently Supabase for the database, authentication, and storage; Vercel for hosting; Modal for self-hosted AI compute; and a transactional email/SMS provider for notifications). Because our AI runs on a model we host ourselves, there is no third-party AI vendor in the chain. Our current list is on our sub-processors page, and each sub-processor is contractually bound to use your data only to deliver services to us. We notify you by email at least 30 days before adding a new one.
5. Where your data lives
Primary storage. Your Customer Data is stored in a database dedicated to your employer (one project per customer; data never crosses customer boundaries). The hosting region is pinned by your employer's Order Form. New customers can pick from the available regions; EU customers should select an EU region to keep data resident. Backups are managed by our database provider per their standard policy.
Frontend hosting. The Platform's frontend code is served from Vercel's edge network. HTTP request metadata is retained by Vercel per their default policy (about 30 days). No Customer Data passes through Vercel; the browser fetches data directly from the database.
AI processing. Our AI runs on infrastructure we operate, in the United States. The prompt and response content of each AI call lives in the regular application database under the same retention, access-control, and deletion policies as the rest of your Customer Data.
6. Retention
- Active account data: retained while your account is active.
- Closed accounts: retained for 90 days after closure to support reactivation, then deleted, unless we have a legal obligation to retain longer.
- Customer Data (general): retained until your organization terminates its agreement; then deleted within 90 days of termination, unless we have a legal obligation to retain longer.
- OSHA recordkeeping data (incidents classified as OSHA 300 / 301 / 300A): retained for the OSHA-mandated five (5) year period after the calendar year each record covers, even after termination, unless your employer's contract specifies otherwise. The retention period under 29 CFR 1904 is longer than our standard deletion timeline, and the platform is often the customer's primary record of these.
- Deleted records: the Platform supports delete and restore for many record types; deleted records are permanently removed 90 days after deletion.
- System logs: retained per Vercel and Supabase defaults (about 30 days).
- AI operational monitoring: inputs and outputs retained to monitor the AI features for abuse, misuse, or malfunction are deleted within 30 days.
7. Your rights
Privacy laws vary by jurisdiction. Rather than enumerate a brittle state-by-state map, Athena commits to honor the following set of rights for every user, regardless of where you live. This set is designed to meet or exceed the strictest comprehensive privacy law that applies to the Platform, including European data protection law.
- Access: a copy of the personal data we hold about you, including categories, sources, processing purposes, retention period, and the sub-processors who received it.
- Correction: correction of inaccurate or incomplete data.
- Deletion: deletion of personal data, subject to retention required by law (for example OSHA recordkeeping; see section 6).
- Portability: a copy of your personal data in a structured, commonly used, machine-readable format.
- Restriction: pause processing of your data while a dispute or correction request is resolved.
- Objection: object to processing based on legitimate interests, including profiling.
- Withdraw consent: where consent is the legal basis, withdraw it at any time (this does not affect the lawfulness of prior processing).
- Automated decision-making: be informed of, and not be subject to, solely automated decisions producing legal or similarly significant effects without human review. Athena's AI features are advisory; human review remains the determining step, and your employer's qualified safety personnel make all final safety decisions.
- Non-discrimination: exercise these rights without retaliation; your employer's use of the Platform is not contingent on you waiving these rights.
- Appeal: if we deny a rights request, you may appeal to a senior reviewer within 45 days; we respond within 60 days of the appeal.
- Complain to a regulator: contact your local data protection authority directly at any time.
Athena does not sell or share personal data, so no opt-out is required, but the right is preserved. Athena does process a special category of sensitive personal data, workplace injury and illness information (OSHA classifications, body part, nature of injury), but only to deliver the safety and OSHA recordkeeping service your employer engaged us for, never to infer characteristics about you or for advertising. It is collected only when your employer records incidents, and it is data the employer is legally required to record and publicly report (the annual OSHA 300A summary). Athena does not collect precise geolocation or biometric data. EU/UK/EEA users are covered by GDPR Articles 12 to 22. Canadian users are covered by PIPEDA and Quebec Law 25; cross-border transfers to our US sub-processors are assessed before engagement and reassessed on material changes, and you may contact the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec directly.
How to exercise a right: email the address in section 10. We respond to verifiable requests within 30 days (60 for complex requests; we will notify you within 30 if we need the extension). Employee requests may be routed through your organization's admin where appropriate, since your employer is the data controller for most data and we are the processor.
8. Children
The Platform is a workplace tool provisioned by employers and is not directed to children. We do not knowingly collect personal data from anyone under the age of sixteen (16). Accounts are created by or at the direction of your employer, who must confirm each user meets this minimum age. If we learn we have collected data from a person under sixteen, we will delete it and disable the account promptly.
9. Security
We use commercially reasonable technical and organizational measures to protect your data: encryption in transit (TLS 1.2+); database storage encrypted at rest; authentication with hashed passwords or magic-link passwordless flows; row-level security policies enforced at the database layer and verified by automated scripts; and production access limited to authorized personnel and logged. No system is perfectly secure; if you suspect a breach, contact us immediately at the address below. See our security overview for more.
10. Contact
Elemental Insights LLC, Kansas City, MO. For data subject requests and privacy questions, email privacy@athenaforms.ai with the subject line "Data Subject Request". For general questions, email info@athenaforms.ai.
Governing law: this Notice is governed by Missouri law, matching your employer's agreement with Athena, except where the privacy law of your place of residence applies by its own force.
11. Changes
We may update this Notice from time to time. Material changes will require re-acceptance via the in-app sign-off flow; non-material changes are noted in the version history.
Version 1.0
Effective 12 June 2026
Owner Elemental Insights LLC
