Version
2026-07-19.1
Sign inLEGAL / UNITED KINGDOM
Draft — pending external legal review
2026-07-19.1
Not effective. External legal approval has not been recorded.
Brazhelp Solutions, operating the ATH3NA software service
External UK financial-services legal review required before commercial use.
Brazhelp Solutions is intended to act as controller for ATH3NA account, service, support and operational data. Registered-address and representative details remain subject to external review before launch. Privacy enquiries may be directed to the contact shown above.
The service may process identity and account data, authentication metadata, customer journal and performance records, targets, non-medical behavioural observations, uploads, billing metadata, support communications, consent records, acquisition data if forms are enabled later, device and security logs, and audit events.
Purposes include providing and securing the service, administering subscriptions, measuring the customer's own records, responding to requests, meeting accounting duties, preventing misuse and preserving governance evidence. Proposed lawful bases include contract, legal obligation, legitimate interests and consent where required. The lawful-basis register remains subject to legal review.
ATH3NA behaviour observations are descriptive and based on recorded events. They are not medical, clinical or diagnostic assessments and must not infer addiction, mental illness, capacity, creditworthiness, employability or a personality disorder. They are not used to deny service automatically.
Service providers may include Supabase for authentication and database infrastructure, Vercel for hosting, and Stripe for payment administration. Market-data providers process market rather than customer data in the current design. Contracts, roles and subprocessor terms require verification before launch.
Some providers may process data outside the United Kingdom. ATH3NA does not claim that transfers never occur. Transfer destinations, safeguards, contractual mechanisms and risk assessments must be recorded before commercial launch.
Retention is controlled by data category, purpose and legal basis. Operational customer records should be deleted or anonymised when no longer needed, subject to legal holds, backup expiry and justified audit or suppression records. Proposed periods are recorded in the retention schedule and require external review.
Depending on the circumstances, individuals may have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent without affecting earlier lawful processing. Identity and scope checks protect other people. Individuals may complain to the UK Information Commissioner's Office and should also be able to contact ATH3NA first.
ATH3NA does not use behavioural observations for solely automated decisions producing legal or similarly significant effects. Analytical calculations may be automated but do not replace customer decisions. Material changes to an effective notice must be versioned and communicated appropriately.
Contact: legal@ath3na.cloud (operational mailbox verification pending)