Privacy Policy

    Effective Date: 1 November 2025

    Last Updated: 21 November 2025

    Introduction

    Athena Consulting Group, LLC ("Athena," "we," "our," "us") operates the Athena CMMC Omniverse™ available at https://www.cmmc-level2compliance.com ("Service").

    This Privacy Policy explains how we collect, use, store, share, and protect personal information, including data accessed through Google APIs.

    If you have any questions, contact us at: info@athenaconsultinggroup.com

    1. Information We Collect

    1.1 Information You Provide

    • Account registration information (name, email, organization)
    • Uploaded assessment data (policies, evidence, gap analysis details)
    • User roles, workflows, and preferences

    1.2 Information Collected Automatically

    • IP addresses, browser type, and device metadata
    • Activity logs and audit trails
    • Technical performance metrics
    • Authentication-related metadata

    1.3 Information Received From Google APIs (OAuth)

    If you sign in using Google, we may access:

    • Basic profile information (name, email, profile image)
    • Organization domain (Google Workspace users)

    We request only the minimum OAuth scopes necessary for login and account association.

    We do NOT request or access:

    • Gmail content
    • Google Drive files
    • Calendar events
    • Contacts
    • Sensitive Google Workspace data

    Unless explicitly required and approved by you during the OAuth consent flow.

    2. How We Use Google User Data

    Your Google user data is used solely to:

    • Authenticate your identity
    • Create and maintain your account
    • Associate you with your organizational workspace
    • Provide core CMMC workflow functionality

    We do NOT:

    • Sell Google user data
    • Share it with unauthorized third parties
    • Use it for advertising
    • Train AI/ML models with your data
    • Use it for any unapproved purpose

    This complies with Google's User Data Policy and AI/ML training restrictions.

    3. Data Storage and Security

    We employ industry-standard security controls aligned with the U.S. Department of Defense cybersecurity requirements.

    3.1 Technical Protections

    • Encryption in transit (TLS 1.2+)
    • Encryption at rest
    • Role-based access control (RBAC)
    • Multi-factor authentication
    • Continuous monitoring
    • Audit logging

    3.2 Framework Alignment

    Our platform aligns with:

    • NIST SP 800-171 Rev 2
    • CMMC Level 2 requirements
    • DFARS 252.204-7012 cybersecurity principles

    3.3 Data Segregation

    Customer data is logically separated by tenant and isolated from other customer environments.

    4. Data Retention

    We retain information only as long as necessary for:

    • Providing the Service
    • Maintaining account functionality
    • Fulfilling legal or contractual obligations

    Examples:

    • Account data → retained while account is active
    • Assessment content → retained until subscription termination
    • Logs → retained up to ~90 days unless needed for security or diagnostics

    You may request deletion at any time (see Section 8).

    5. When We Share Information

    We may share personal data only with:

    • Infrastructure service providers (e.g., Supabase, AWS, Google Cloud)
    • Security monitoring and threat detection partners

    All such partners operate under strict confidentiality and security requirements.

    We never:

    • Sell personal information
    • Share data for marketing purposes
    • Transfer data to unauthorized third parties

    6. Children's Privacy

    Our Service is intended for users aged 18 and older. We do not knowingly collect information from children.

    7. Your Rights & Choices

    You may have the right to:

    • Access your personal data
    • Request correction
    • Request deletion
    • Restrict certain processing
    • Export your data
    • Revoke Google OAuth permissions

    Revoke OAuth access at:

    https://myaccount.google.com/permissions

    You may also contact us directly at: info@athenaconsultinggroup.com

    8. Data Deletion Requests

    You may request account deletion and associated data removal at any time.

    We will:

    • Remove your account
    • Delete your content, assessments, and evidence
    • Purge personal identifiers from logs
    • Confirm deletion within thirty (30) days

    Submit requests to: info@athenaconsultinggroup.com

    9. Global Privacy Compliance

    We comply with generally recognized privacy principles, including:

    • Data minimization
    • Lawful basis for processing
    • User transparency
    • Right to deletion
    • No sale of personal information

    These principles support GDPR, CCPA, and other global standards.

    10. Changes to This Policy

    We may update this Privacy Policy as needed. Any changes will be posted at:

    https://www.cmmc-level2compliance.com/privacy-policy

    Continued use of the Service constitutes acceptance of updated terms.

    11. Contact Information

    Athena Consulting Group, LLC

    5895 Core Rd, Suite 407

    North Charleston, SC 29406

    Email: info@athenaconsultinggroup.com