Last Updated: August 7, 2026
ITHENA ("ITHENA," "we," "us," or "our") operates the website ithena.ai and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our Service, or interact with us via SMS/text messaging.
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
When you register for an account, sign up for our services, or contact us, we may collect:
When you use our Service, we may automatically collect:
When you opt in to receive SMS/text messages from ITHENA, we collect:
We use the information we collect for the following purposes:
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile information will not be sold, rented, loaned, traded, leased, or otherwise transferred to any third parties, including but not limited to lead generators, data brokers, or any other entity, for marketing or promotional purposes at any time. This applies to all mobile subscriber data collected as part of our SMS messaging program.
If you opt in to our SMS messaging program, you may receive the following types of text messages from ITHENA:
Message frequency varies based on your account activity and the message categories you have opted into. You can expect to receive approximately 5–10 messages per month, though transactional messages (such as OTPs) may be sent more frequently depending on your usage of the Service.
We obtain your consent to receive SMS messages through our website sign-up form at ithena.ai. Consent is not a condition of purchase or use of the Service. By providing your mobile phone number and checking the opt-in checkbox, you expressly consent to receive text messages from ITHENA at the number provided.
Consent for marketing and promotional messages is collected separately from transactional message consent. You may opt in to transactional messages without opting in to marketing messages.
Consent to receive messages is not transferable or assignable to any other party.
You may opt out of receiving SMS messages at any time by replying STOP to any message you receive from us. You may also text HELP for assistance. Upon receiving your opt-out request, we will send a single confirmation message acknowledging that you have been unsubscribed, and you will receive no further messages from ITHENA unless you re-subscribe.
You may also opt out by contacting us at support@ithena.ai.
Message and data rates may apply depending on your mobile carrier and plan. ITHENA is not responsible for any charges incurred from your carrier related to SMS messaging.
Our SMS messaging program is supported on all major US carriers. Carriers are not liable for delayed or undelivered messages.
We may share your information in the following circumstances:
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
We retain your personal information for as long as your account is active or as needed to provide the Service. We also retain information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. SMS opt-in consent records are retained for the duration of the messaging relationship and for a reasonable period thereafter to document compliance.
We implement industry-standard technical and organizational security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Our security program includes:
Our encryption and key-management practices are described in detail in our Encryption and Cryptographic Key Management Policy.
Where ITHENA manages hosting on AWS, Azure, or Google Cloud, we operate this full stack. Where the Service runs in your own cloud tenant or on your own servers, it operates under your security operations center and tooling.
However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
ITHENA maintains an information security and privacy program measured against recognized industry frameworks:
| Framework | Status |
|---|---|
| SOC 2 Type II | Completed |
| ISO 27001 | Aligned |
| GDPR (EU) and UK GDPR | Compliant — see Section 8 |
| IEC 62443 | Aligned, for operational technology (OT) connectivity |
| PCI-DSS | Payment card data is handled solely by our payment processors; ITHENA never stores raw cardholder data |
ITHENA has completed a SOC 2 Type II audit covering access controls and audit logging. Our SOC 2 report, Data Processing Agreement, and other compliance documentation are available to customers under a non-disclosure agreement upon request at support@ithena.ai.
Payment processing terms, including PCI-DSS responsibilities, are set out in the Addendums to our End User License Agreement at https://eula.ithena.io/addendum.
This section applies where we process personal data of individuals located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland.
ITHENA acts as a controller in respect of personal data we collect directly for our own purposes, such as account registration, billing, marketing, and website analytics. Where we process personal data on behalf of a business customer through the Service, ITHENA acts as a processor and that customer is the controller. Processor engagements are governed by a Data Processing Agreement ("DPA"), which is available upon request and incorporates the obligations required by Article 28 of the GDPR.
Where the GDPR applies, we rely on the following legal bases:
Subject to applicable conditions and exemptions, you have the right to request access to, rectification of, or erasure of your personal data; to restrict or object to processing; to data portability; and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with your local supervisory authority (or, in the United Kingdom, the Information Commissioner's Office).
To exercise these rights, contact us at support@ithena.ai. We respond to verified requests within one month, extendable by a further two months for complex requests as permitted by the GDPR. Where ITHENA acts as a processor, we will forward requests to the relevant controller and assist them in responding.
ITHENA is headquartered in the United States and may transfer personal data outside the EEA, the United Kingdom, or Switzerland. Where we do so, we rely on an appropriate safeguard under applicable law, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by technical and organizational measures such as encryption in transit and at rest.
For deployments of our Service, customers may select the hosting region and cloud provider. Where a region is selected, application data and telemetry are retained in that geography to support data-sovereignty and retention requirements.
We engage sub-processors to help deliver the Service, including cloud infrastructure providers (Amazon Web Services, Microsoft Azure, Google Cloud), payment processors, and communications providers. Each sub-processor is bound by written terms imposing data protection obligations no less protective than those in our DPA. A current list of sub-processors is available on request, and we provide notice of material changes as set out in the DPA.
We maintain an incident response process for security incidents affecting personal data. Where ITHENA acts as a processor, we will notify the affected controller without undue delay after becoming aware of a personal data breach and will cooperate in good faith on containment, remediation, and any required regulatory or individual notifications. Where ITHENA acts as a controller, we will notify the competent supervisory authority and affected individuals where required by applicable law.
Questions about our data protection practices, or requests for our DPA, may be sent to support@ithena.ai.
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another US state with a comprehensive privacy law, you may have the right to confirm whether we process your personal information, to access and obtain a copy of it, to correct inaccuracies, to request deletion, and to opt out of targeted advertising, the sale of personal information, and certain profiling.
ITHENA does not sell personal information and does not share personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding twelve (12) months. We do not knowingly sell or share the personal information of individuals under 16 years of age.
We will not discriminate against you for exercising any of these rights. To submit a request, contact us at support@ithena.ai. We will verify your request using the information associated with your account. You may use an authorized agent to submit a request on your behalf, subject to proof of authorization. If we deny your request, you may appeal by replying to our response with the subject line "Privacy Request Appeal."
Depending on your jurisdiction, you may have the following rights regarding your personal information:
To exercise any of these rights, please contact us at support@ithena.ai.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@ithena.ai.
We use cookies and similar technologies to enhance your experience, analyze usage, and deliver personalized content. You can manage your cookie preferences through your browser settings. For more information, please refer to our Cookie Policy, if applicable.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ITHENA
Email: support@ithena.ai
Website: https://ithena.ai