Athena BDA Ltd — Website Privacy Notice
Last updated: September 2026
September 2026 update: We have stopped using third-party website visitor identification (RB2B) and removed it from our website. We have added a disclosure covering our own first-party email campaign click tracking.
Athena BDA Ltd (known as Athena BDA) respects your privacy and is committed to protecting your personal data. This privacy notice will inform you as to how we process your personal data on our website (https://athenabda.com/) for clients, website visitors and professional contacts. This privacy notice also tells you about your privacy rights pursuant to UK Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR) and the EU GDPR, collectively known as Data Protection Laws.
Unless we notify you otherwise, Athena BDA Ltd (Company No. 15477746), 129 Tavistock Ave, St Albans, Hertfordshire, AL1 2NL is the controller of your personal data for the purposes described in this privacy notice and where we directly have a relationship with you.
This privacy notice applies to the processing of personal data by us in connection with:
Personal data or personal information means any information about an individual from which that person can be identified. Athena BDA may collect, use, store and transfer different kinds of personal data, including:
We do not collect or process sensitive personal data (e.g. health/ethnicity), personal email or home information, or information about family members.
Athena BDA will only use your personal data where UK data protection law allows. Depending on your relationship with us, we process your data based on:
Directly from you (Clients and Website Visitors): When you register, fill in forms, request a demo, send us correspondence, feedback or support requests.
From third parties and public sources (Professional Contacts in our database):
The processing tables explain why we process personal data and the lawful basis for doing so. Depending on your relationship with us, you may need to refer to different tables relevant to your specific interactions or services.
| Processing activity | Categories of personal data | Lawful basis |
|---|---|---|
| Registration and account setup | Identity Data, Contact Data, Account Data | Performance of a contract |
| Manage fees and payment | Identity Data, Contact Data, Financial Data | Performance of a contract |
| Provision and maintenance of services | Identity Data, Contact Data, Usage Data, Account Data | Performance of a contract; Legitimate interest (operate business/improve service) |
| Handling enquiries, demos & support | Identity Data, Contact Data, Communications Data | Performance of a contract; Legitimate interest |
| Sending service updates and notices | Identity Data, Contact Data | Performance of a contract; Legal obligation |
| Processing feedback and survey responses | Identity Data, Contact Data, Communications Data | Legitimate interest (improve service and user experience) |
| Managing your rights requests | Identity Data, Contact Data | Legal obligation |
| Platform improvement, troubleshooting or statistical analysis | Technical Data, Usage Data | Legitimate interest (business operation & improvement) |
| Processing activity | Categories of personal data | Lawful basis |
|---|---|---|
| Responding to messages, demo requests or online forms | Identity Data, Contact Data | Legitimate interest (respond to you/support/service enquiries) |
| Website and platform analytics | Technical Data, Usage Data | Legitimate interest (business improvement, troubleshooting, operation & improvement) or statistical analysis |
| Use of non-essential cookies (where the jurisdiction applies and consent is required) | Technical Data | Consent |
| Website visitor identification via third-party matching service (US visitors only) and associated B2B marketing follow-up | Identity Data, Contact Data, Profile Data, Technical Data, Usage Data | Legitimate interests (understanding demand and conducting proportionate B2B outreach) |
| Processing activity | Categories of personal data | Lawful basis |
|---|---|---|
| Obtain, maintain and enrich business contact data | Identity Data, Contact Data, Profile Data, Professional information | Legitimate interests: operating a business intelligence platform for B2B pharmaceutical sector use |
| Provide your professional contact information to Athena BDA's business clients (as data controllers) | Identity Data, Contact Data, Profile Data, Professional information | Legitimate interests (B2B context) |
| Record your opt-out/suppression request | Identity Data, Contact Data | Legitimate interests (not to import your data) |
Where we send you a business email that links to our website, that link may contain a short reference code. If you open the page in a browser, our own software records that the link was visited, together with the page path and the time of the visit. The reference code corresponds to a contact record we already hold, so the visit is associated with your existing record.
This is first-party processing. The information is sent to our own secure database, which is the same infrastructure that runs our customer relationship management system. It is not shared with a third-party advertising or analytics provider, and it is not used to build profiles of your activity across other websites. No cookie is set for this purpose and the reference code is removed from the address bar after the visit is recorded.
We do not identify anonymous visitors to our website. We only record a visit in this way where you have followed a link from a business email we sent to you.
We rely on legitimate interests as our lawful basis, specifically our interest in understanding whether our business-to-business communications are relevant and in following up proportionately with professional contacts. The categories of personal data processed are Identity Data, Contact Data, Technical Data and Usage Data, as defined earlier in this notice.
Your choices:
Our clients act as independent data controllers and determine how they use the information we provide. They are solely responsible for ensuring that their use of such information complies with applicable Data Protection Laws and for providing their own privacy notices to data subjects. Once a client receives the information they are responsible for any communications they send and for their own legal compliance in relation to such communications. We require our clients to respect data subjects' rights and to inform data subjects of processing activities through a privacy notice.
Our clients are independent data controllers:
By remaining in our database, you may be contacted by the client when they are conducting their business-to-business sales, marketing and recruiting activities. Communications you receive from our client may be relevant to your profession or employment role, but we cannot guarantee that you will find such communications to be relevant or of interest to you.
We have conducted a Data Protection Impact Assessment (DPIA) considering the limited visibility of the processing to the individuals concerned to ensure that appropriate safeguards are implemented to protect their rights and interests. The information we process relates strictly to an individual in their professional capacity and is used solely within a B2B business context primarily for business intelligence in the pharmaceutical and life science sector.
We do not process data relating to children or vulnerable individuals. These safeguards ensure that the impact on your privacy is minimal and that our business use of your data remains fair, relevant and lawful.
We have established a Data Compliance Centre where you can exercise your data rights. You can submit two types of request:
We aim to complete all requests within 24 hours of receipt. In all cases, your request will be fulfilled within one month in accordance with applicable legal requirements. We may need to verify your identity before processing your request as a security measure to ensure personal data is not disclosed to any person who has no right to receive it.
You can also contact us directly at adrian@athenabda.com if you prefer to submit your request by email or have any questions about the process.
In certain circumstances, we may disclose your personal information to third parties for contract fulfilment purposes, legitimate purposes and other reasons subject to this privacy notice. Such circumstances include:
We may send prospective clients or clients marketing communications. You have the right to object to processing of your personal data for direct marketing purposes. You can unsubscribe from receiving marketing communications from us by using the unsubscribe methods contained in communications we send to you or by contacting us at adrian@athenabda.com. Where you opt out of receiving marketing communications this will not apply to personal data provided to us as a result of registering for or using our service, your service experience or other interactions with this website.
We may transfer and process your personal data outside of the United Kingdom (UK) / European Union (EU) to countries where data protection laws are less stringent than those in the UK/EU. When we transfer your personal data outside of the UK/EU we only do so to entities that offer the same level of data protection as that afforded by the UK Data Protection Act 2018 (including the UK GDPR) and the EU GDPR / Data Protection Laws. Specifically:
For other countries we will use local law guidance to ensure personal data is transferred securely where there is a requirement in law to do so.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
The transmission of information via the internet is not completely secure. Although we will take reasonable measures to protect your personal data, we cannot guarantee the security of your information transmitted and any transmission is at your own risk.
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
Client and Website Visitor Data: We retain this information for as long as you maintain an account with us plus up to 3 years after account closure for legal and business purposes.
Business Contact Data: We retain professional contact information for up to 3 years from the date of last verification or update unless:
Suppression List (Exception): If you opt out or request deletion, we retain your contact details on a suppression list indefinitely to ensure we do not re-import or re-process your information from future data refreshes.
Under certain circumstances, you have rights under Data Protection Laws. Not all rights are absolute and depending on where you are located, not all rights are given to you. You can:
You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than one month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
To exercise any of the rights set out above, please visit our Data Compliance Centre or contact us directly at adrian@athenabda.com.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us. Please contact us if you wish to update your personal data.
We would appreciate the chance to deal with your concerns in the first instance — please contact us at adrian@athenabda.com. If you have unresolved issues, you have the right to complain at any time to a data protection supervisory authority such as the UK data protection regulator — the Information Commissioner's Office (ICO). You may also lodge a complaint with a supervisory authority if you live or work outside the UK or you have a complaint concerning our personal data processing activities.
This privacy notice may be changed from time to time in response to legal, technical or business developments. We will take appropriate measures to inform you when we update our privacy notice. We will obtain your consent to any material privacy notice changes if and where this is required by applicable Data Protection Laws.
If you would like more information about the way we manage personal information that we hold about you, please contact us at: adrian@athenabda.com
Version last updated: April 2026