Privacy Policy

    Athena BDA Ltd — Website Privacy Notice

    Last updated: September 2026

    September 2026 update: We have stopped using third-party website visitor identification (RB2B) and removed it from our website. We have added a disclosure covering our own first-party email campaign click tracking.

    Purpose

    Athena BDA Ltd (known as Athena BDA) respects your privacy and is committed to protecting your personal data. This privacy notice will inform you as to how we process your personal data on our website (https://athenabda.com/) for clients, website visitors and professional contacts. This privacy notice also tells you about your privacy rights pursuant to UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR) and the EU GDPR, collectively known as Data Protection Laws.

    Controller for Personal Data

    Unless we notify you otherwise, Athena BDA Ltd (Company No. 15477746), 129 Tavistock Ave, St Albans, Hertfordshire, AL1 2NL is the controller of your personal data for the purposes described in this privacy notice and where we directly have a relationship with you.

    Scope

    This privacy notice applies to the processing of personal data by us in connection with:

    • Clients: Individuals and companies who use Athena BDA's services and platform.
    • Website visitors: Anyone browsing our website or interacting with us online.
    • Professional contacts: Individuals whose professional business contact information is included in our business database which is provided to clients.

    Types of Personal Data

    Personal data or personal information means any information about an individual from which that person can be identified. Athena BDA may collect, use, store and transfer different kinds of personal data, including:

    • Identity Data: Name, job title, seniority level, employer/company name.
    • Contact Data: Business email address, business address, location (work).
    • Financial Data: Payment details, for example where you are a client.
    • Profile Data: Professional networking data (connection counts, employment start dates if publicly available), conference speaking engagements, professional activities, therapy/brand/disease area focus.
    • Technical Data: IP address, browser type and device information, country/location.
    • Account Data: Username, password, login credentials.
    • Usage Data: Pages visited, time spent, referral sources, support enquiries, demo requests, feedback, survey responses.
    • Communications Data: Information provided when requesting demos, client support or submitting surveys.

    We do not collect or process sensitive personal data (e.g. health/ethnicity), personal email or home information, or information about family members.

    Lawful Bases: How We Use Your Personal Data

    Athena BDA will only use your personal data where UK data protection law allows. Depending on your relationship with us, we process your data based on:

    • Consent: Only if and where we ask and you choose to give it. You can withdraw consent at any time.
    • Performance of a contract: To provide, register and support your account and service.
    • Legal obligation: To comply with our legal obligations e.g. retention and accounting.
    • Legitimate interests: For business intelligence database operation, B2B data provision, platform, service operation, improvement and sales and related support, and for the identification of US-based business visitors to our website for B2B outreach (see "Website Visitor Identification" below).

    How We Collect Your Personal Data

    Directly from you (Clients and Website Visitors): When you register, fill in forms, request a demo, send us correspondence, feedback or support requests.

    From third parties and public sources (Professional Contacts in our database):

    • Licensed business intelligence providers
    • Publicly available professional networking platforms
    • Public business sources: company websites, event/conference lists, professional directories
    • Email validation services or generated using standard business naming conventions
    • Website visitor identification services (for US visitors only), which match anonymous website activity against business contact databases

    Processing Tables

    The processing tables explain why we process personal data and the lawful basis for doing so. Depending on your relationship with us, you may need to refer to different tables relevant to your specific interactions or services.

    Client Processing Information

    Processing activityCategories of personal dataLawful basis
    Registration and account setupIdentity Data, Contact Data, Account DataPerformance of a contract
    Manage fees and paymentIdentity Data, Contact Data, Financial DataPerformance of a contract
    Provision and maintenance of servicesIdentity Data, Contact Data, Usage Data, Account DataPerformance of a contract; Legitimate interest (operate business/improve service)
    Handling enquiries, demos & supportIdentity Data, Contact Data, Communications DataPerformance of a contract; Legitimate interest
    Sending service updates and noticesIdentity Data, Contact DataPerformance of a contract; Legal obligation
    Processing feedback and survey responsesIdentity Data, Contact Data, Communications DataLegitimate interest (improve service and user experience)
    Managing your rights requestsIdentity Data, Contact DataLegal obligation
    Platform improvement, troubleshooting or statistical analysisTechnical Data, Usage DataLegitimate interest (business operation & improvement)

    Website Visitor Processing Information

    Processing activityCategories of personal dataLawful basis
    Responding to messages, demo requests or online formsIdentity Data, Contact DataLegitimate interest (respond to you/support/service enquiries)
    Website and platform analyticsTechnical Data, Usage DataLegitimate interest (business improvement, troubleshooting, operation & improvement) or statistical analysis
    Use of non-essential cookies (where the jurisdiction applies and consent is required)Technical DataConsent
    Website visitor identification via third-party matching service (US visitors only) and associated B2B marketing follow-upIdentity Data, Contact Data, Profile Data, Technical Data, Usage DataLegitimate interests (understanding demand and conducting proportionate B2B outreach)

    Professional Contacts (Database) Processing Information

    Processing activityCategories of personal dataLawful basis
    Obtain, maintain and enrich business contact dataIdentity Data, Contact Data, Profile Data, Professional informationLegitimate interests: operating a business intelligence platform for B2B pharmaceutical sector use
    Provide your professional contact information to Athena BDA's business clients (as data controllers)Identity Data, Contact Data, Profile Data, Professional informationLegitimate interests (B2B context)
    Record your opt-out/suppression requestIdentity Data, Contact DataLegitimate interests (not to import your data)

    Email Campaign Click Tracking

    Where we send you a business email that links to our website, that link may contain a short reference code. If you open the page in a browser, our own software records that the link was visited, together with the page path and the time of the visit. The reference code corresponds to a contact record we already hold, so the visit is associated with your existing record.

    This is first-party processing. The information is sent to our own secure database, which is the same infrastructure that runs our customer relationship management system. It is not shared with a third-party advertising or analytics provider, and it is not used to build profiles of your activity across other websites. No cookie is set for this purpose and the reference code is removed from the address bar after the visit is recorded.

    We do not identify anonymous visitors to our website. We only record a visit in this way where you have followed a link from a business email we sent to you.

    We rely on legitimate interests as our lawful basis, specifically our interest in understanding whether our business-to-business communications are relevant and in following up proportionately with professional contacts. The categories of personal data processed are Identity Data, Contact Data, Technical Data and Usage Data, as defined earlier in this notice.

    Your choices:

    • Do not follow the link: Nothing is recorded unless you open the linked page in a browser.
    • Object or request erasure: Contact us at adrian@athenabda.com or use our Data Compliance Centre to object to this processing, ask us to stop using tracked links for you, or exercise any of your other rights set out in this notice.

    Data Protection and Client Responsibilities

    Our clients act as independent data controllers and determine how they use the information we provide. They are solely responsible for ensuring that their use of such information complies with applicable Data Protection Laws and for providing their own privacy notices to data subjects. Once a client receives the information they are responsible for any communications they send and for their own legal compliance in relation to such communications. We require our clients to respect data subjects' rights and to inform data subjects of processing activities through a privacy notice.

    Our clients are independent data controllers:

    • They are responsible for their own compliance with Data Protection Laws.
    • They make their own decisions about how to use the information.
    • They have their own privacy policies and opt-out mechanisms.
    • Athena BDA is not responsible for how they use the information once accessed.
    • Athena BDA does not act as a data processor for its clients.

    By remaining in our database, you may be contacted by the client when they are conducting their business-to-business sales, marketing and recruiting activities. Communications you receive from our client may be relevant to your profession or employment role, but we cannot guarantee that you will find such communications to be relevant or of interest to you.

    Data Protection Impact Assessment (DPIA)

    We have conducted a Data Protection Impact Assessment (DPIA) considering the limited visibility of the processing to the individuals concerned to ensure that appropriate safeguards are implemented to protect their rights and interests. The information we process relates strictly to an individual in their professional capacity and is used solely within a B2B business context primarily for business intelligence in the pharmaceutical and life science sector.

    We do not process data relating to children or vulnerable individuals. These safeguards ensure that the impact on your privacy is minimal and that our business use of your data remains fair, relevant and lawful.

    Exercising Your Opt-Out and Data Access Rights

    We have established a Data Compliance Centre where you can exercise your data rights. You can submit two types of request:

    • Opt Out of Our Database (labelled 'Do Not Sell My Information' on our website) — If you do not want your professional information to be included in our contact database or shared with our clients, submit an opt-out request via the Data Compliance Centre. You will need to provide your email address and country. You may also provide your LinkedIn profile URL, which helps us ensure we do not re-import your details if you change employer in the future. Once processed:
      • We will add you to our suppression list and ensure you are not re-imported in future data refreshes.
      • Your data will be removed from future provision to our clients but may remain with third parties who obtained it previously or from other sources.
      • Your suppression record is retained indefinitely so we can honour your opt-out on an ongoing basis.
    • Access, Correct or Delete My Data — If you wish to request a copy of the personal data we hold about you, have inaccurate information corrected, or request deletion of your data, you can submit a request via the Data Compliance Centre. You will need to provide your email address, country and the type of request you are making. You may also provide your name, company, job title and any additional context to help us locate your records and process your request efficiently.

    We aim to complete all requests within 24 hours of receipt. In all cases, your request will be fulfilled within one month in accordance with applicable legal requirements. We may need to verify your identity before processing your request as a security measure to ensure personal data is not disclosed to any person who has no right to receive it.

    You can also contact us directly at adrian@athenabda.com if you prefer to submit your request by email or have any questions about the process.

    Who We Share Your Information With

    In certain circumstances, we may disclose your personal information to third parties for contract fulfilment purposes, legitimate purposes and other reasons subject to this privacy notice. Such circumstances include:

    • Internally: Your personal data will be used by our employees and contractors who are working on providing our services on a need-to-know basis.
    • With our affiliates: We may share information within our corporate group to operate and manage our business effectively and to provide you with the services you request.
    • Our service partners: With vendors or other third parties who perform services on our behalf (for example IT management, client support, and cloud storage).
    • Legal advisors: To enforce any applicable terms of service and to protect or defend our rights and the rights of our users or others.
    • Professional advisers: Including bankers, auditors and insurers who provide consultancy, banking, insurance and accounting services.
    • Payment Service Intermediaries: These providers help facilitate payment to us.
    • Business transactions (M&A): In connection with a business transaction such as a merger or acquisition. Where this is the case, your personal data shall continue to be processed in accordance with this privacy notice.

    Marketing Communications

    We may send prospective clients or clients marketing communications. You have the right to object to processing of your personal data for direct marketing purposes. You can unsubscribe from receiving marketing communications from us by using the unsubscribe methods contained in communications we send to you or by contacting us at adrian@athenabda.com. Where you opt out of receiving marketing communications this will not apply to personal data provided to us as a result of registering for or using our service, your service experience or other interactions with this website.

    International Transfers (UK/EU)

    We may transfer and process your personal data outside of the United Kingdom (UK) / European Union (EU) to countries where data protection laws are less stringent than those in the UK/EU. When we transfer your personal data outside of the UK/EU we only do so to entities that offer the same level of data protection as that afforded by the UK Data Protection Act 2018 (including the UK GDPR) and the EU GDPR / Data Protection Laws. Specifically:

    1. We will only transfer your personal information to countries that have been deemed to provide an adequate level of protection for personal information; or
    2. We will use specific contracts approved for use in the UK or EU which give personal information the same protection it has in the UK/EU. For example, the use of Article 46 UK and EU GDPR safeguard mechanisms endorsed by the UK Government or European Commission.

    For other countries we will use local law guidance to ensure personal data is transferred securely where there is a requirement in law to do so.

    Data Security

    We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

    The transmission of information via the internet is not completely secure. Although we will take reasonable measures to protect your personal data, we cannot guarantee the security of your information transmitted and any transmission is at your own risk.

    Data Retention

    We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

    Client and Website Visitor Data: We retain this information for as long as you maintain an account with us plus up to 3 years after account closure for legal and business purposes.

    Business Contact Data: We retain professional contact information for up to 3 years from the date of last verification or update unless:

    • You request deletion earlier.
    • The information becomes demonstrably inaccurate or outdated.
    • Our legitimate interest basis no longer applies.

    Suppression List (Exception): If you opt out or request deletion, we retain your contact details on a suppression list indefinitely to ensure we do not re-import or re-process your information from future data refreshes.

    Data Subject Rights

    Under certain circumstances, you have rights under Data Protection Laws. Not all rights are absolute and depending on where you are located, not all rights are given to you. You can:

    • Request access to your personal data: Known as a "subject access request" — enables you to receive a copy of the personal data we hold about you.
    • Request correction of your personal data: This enables you to have any incomplete or inaccurate information we hold about you corrected.
    • Request erasure of your personal data: This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. We may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you at the time of your request.
    • Object to processing of your personal data: Where we are processing your personal data based on a legitimate interest and you may challenge this. We may be entitled to continue processing your information based on our legitimate interests or where this is relevant to any legal claims.
    • Request restriction of processing: This enables you to ask us to suspend the processing of your personal data in certain scenarios, for example if you want us to establish the information's accuracy or where our use of the information is unlawful but you do not want us to erase it.
    • Request transfer of your personal information (data portability): In some circumstances we will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format.
    • Right to withdraw consent: Where we are relying on consent to process your personal data. This will not affect the lawfulness of any processing carried out before you withdraw your consent.
    • Automated decision making: We do not carry out automated decision making.

    You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.

    We try to respond to all legitimate requests within one month. Occasionally it may take us longer than one month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

    To exercise any of the rights set out above, please visit our Data Compliance Centre or contact us directly at adrian@athenabda.com.

    Keeping Personal Information Accurate and Current

    It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. Please contact us if you wish to update your personal data.

    Concerns and Complaints

    We would appreciate the chance to deal with your concerns in the first instance — please contact us at adrian@athenabda.com. If you have unresolved issues, you have the right to complain at any time to a data protection supervisory authority such as the UK data protection regulator — the Information Commissioner's Office (ICO). You may also lodge a complaint with a supervisory authority if you live or work outside the UK or you have a complaint concerning our personal data processing activities.

    Changes to Our Privacy Notice

    This privacy notice may be changed from time to time in response to legal, technical or business developments. We will take appropriate measures to inform you when we update our privacy notice. We will obtain your consent to any material privacy notice changes if and where this is required by applicable Data Protection Laws.

    Contact Us

    If you would like more information about the way we manage personal information that we hold about you, please contact us at: adrian@athenabda.com

    Version last updated: April 2026