Legal

Privacy policy

How we handle the personal information you send us through this website, under the Protection of Personal Information Act, 2013.

Last updated 2026-09-01

Who is responsible

Athena Advisors SA 786 (Pty) Ltd (registration 2013/032888/07), trading as Athena, is the responsible party for the personal information collected through this site. We are in McCoy Street, Stellenbosch, Western Cape 7600.

What we collect, and why

When you send us an enquiry

  • Your name and email address, so we can reply. Both are required.
  • Your phone number and company, optional, used only to reach you about your enquiry.
  • Project type, budget range and timeline, optional, used to scope a realistic response.
  • The message you write.
  • When you send the form, we check that the domain of your email address, the part after the “@”, is able to receive mail, and we turn away known throwaway addresses. That check is a public mail-record lookup of the domain, typically gmail.com or your company’s domain, not of you: your name, your message and the rest of your enquiry are never sent anywhere to make it. Its only purpose is to catch a mistyped or fake address so your request does not vanish.
  • Technical detail attached automatically: your IP address, browser user-agent, the page you submitted from and the referring page. This is kept to detect and block automated abuse of the form, and is not used to profile you.

When you fill in the enquiry form but don’t send it

Our own analytics record the enquiry form field by field as you complete it, and this includes the text you entered, not merely the fact that a field was filled. We do this so that an enquiry you began but were interrupted before sending is not simply lost to us, and so we can see which questions make people hesitate and improve them. In plain terms: if you type your name and email and then close the tab without pressing send, we may hold what you entered against that visit.

  • This applies to the public enquiry form only. Password fields are never recorded, in your browser or on our server, and no sign-in form is ever captured this way.
  • It runs only while optional engagement analytics run. If your browser sends Do Not Track or Global Privacy Control, this form-progress content is not recorded. The minimum server-side visitor/IP security relationship described above is still retained under our legitimate interest in security, fraud prevention and reliable data-quality controls.
  • Whatever you entered is stored beside the rest of that visit and is deleted on the same analytics schedule set out below, never kept for longer. We can also switch this capture off across the whole site from our console.
  • If you would like anything you typed removed, write to us and we will delete the records relating to you.

When you apply for a job

If you apply through our careers page, we collect what you give us for that purpose: your name and contact details, your CV and any cover letter or portfolio you attach, your answers to the role’s screening questions, and details such as your current role, notice period, salary expectation and availability. We process this to consider you for the role, on the basis of the consent you give by ticking the box on the application form and in order to take steps at your request before a possible contract of employment.

  • Your CV and documents are stored on our own server, outside the public website, and are reachable only by the people at Athena handling hiring. They are never published or shared for marketing.
  • We keep a record of how your application progresses — stages, interview notes and internal scorecards — so the hiring team has a shared, fair picture. This is kept with your application.
  • We use a lightweight in-browser check on the application form to keep out automated bots, and we confirm your email domain can receive mail, exactly as described above for enquiries.
  • If you are not successful, we keep your application for a limited retention period (twelve months by default) in case a more suitable role opens up, and then delete it and its files automatically. If you are hired, your details become part of your employee record. You can ask us to delete your application at any time and we will erase it and the documents you sent.

When you simply browse the site

We run our own analytics on our own server, and we also use Google Analytics. Our own records stay on our machine. Google Analytics is a third-party service: it sets its own cookies, records the pages you visit, and sends that information to Google, whose servers are outside South Africa. We do not use it for advertising, and we have not enabled Google Signals, advertising features or cross-device tracking. For each visit our own records keep:

  • The pages you viewed, when, how long the page took to render, how far down you scrolled and how long you stayed.
  • How you arrived: the referring website, or the campaign tags on the link you followed.
  • Your device type, browser, operating system, screen size, language and time zone.
  • Interactions with the page: which portfolio projects you opened, which filters you used, whether you clicked a phone number or email address, and whether you started the contact form.
  • Country, region and city where the installed local GeoIP dataset can resolve the captured network address. This is approximate network location, never a household or precise device location.

What we keep of your IP address

We record your full IP address against each visit. We do this so we can investigate abuse of the site and fraudulent enquiries, maintain reliable visitor and conversion records, and distinguish one browser record from another. The address is captured by the server, not supplied by browser script. Forwarding headers are accepted only from an approved CDN or reverse proxy; otherwise the network socket address is used. Distinct address observations are encrypted with AES-256-GCM in the visitor history ledger, full values are restricted to authorised administrator roles, and other roles see a masked value. It is deleted with the visit record at the retention period below and is never sold or used for advertising.

If you would rather we did not hold it, write to us and we will delete the records relating to you.

How we check and repair visitor-data integrity

Automated controls check that every completed visit has a valid server-captured IPv4 or IPv6 relationship, that its page views and events belong to the same visitor, and that derived totals, conversion links and location states agree with the retained evidence. A missing optional value such as city, ASN or time zone is labelled unavailable and is not treated as corruption. Repairs use only existing parent, session, address or enquiry evidence; they do not guess an address or location.

Each repair produces a signed, hash-chained receipt containing control counts and the number of rows reconciled. The separately signed chain head makes amendment and deletion detectable. These receipts do not contain the visitor’s full IP address or form content and are retained as administrative security and accountability evidence.

How we tell one visit from another

A first-party, random browser identifier is placed in an HttpOnly cookie and converted to a one-way keyed hash before storage. It contains no username, hostname or IP address and cannot be read by page JavaScript. It lets Athena associate visits, page views, form activity and conversions with the same browser until the cookie expires or is cleared. Clearing it creates a new visitor record; the site does not claim that a sandboxed browser can reveal an operating-system username or machine hostname. Security device fingerprinting is separate and runs only on the consent basis described below.

If you send an enquiry, we do record which visit produced it, so we know which marketing channel is working. That link exists only for enquiries you chose to send.

Where we work out your location from

Location comes from a database held on our own server, or from a header set by the content delivery network in front of the site. No request about you is made to any third-party lookup service, so your address is not shared with another company in order to place you on a map. The result is approximate, typically the town of your internet provider's exchange, not where you are sitting.

How to switch analytics off

If your browser sends a Do Not Track or Global Privacy Control signal, optional engagement page views and events are not recorded. A minimal server-side visitor, session and validated address relationship is still retained for security, fraud prevention and data-integrity purposes under legitimate interest. Most browsers and privacy extensions can send one or both of these; in Firefox it is under Privacy & Security, and extensions such as Privacy Badger or DuckDuckGo send GPC by default.

Known search-engine crawlers and monitoring bots are classified separately and excluded from human analytics totals.

Cookies

This site sets first-party session and visitor-identity cookies. The session cookie makes the contact form's anti-forgery token and authenticated areas work and expires when the browser closes. The random visitor cookie retains the continuity described above for the same period as raw analytics. Both are Secure and HttpOnly, contain no name or address, and are not readable by page JavaScript or another site.

Google Analytics sets its own cookies, typically named _ga and _ga_<id>, which last up to two years and let Google recognise a returning browser. These are analytics cookies set by a third party, and we ask before any of them is set.

Your choice

The first time you arrive we ask whether Google Analytics may run. Nothing from Google loads until you say yes, so declining is not a matter of switching something off after the fact: it never starts. Both answers are one click, and the site behaves identically either way. We record what you chose, when, and which version of this policy you were shown.

If your browser sends Do Not Track or Global Privacy Control we take that as your answer, do not load Google Analytics, and do not interrupt you with the question at all. Your own analytics record is kept regardless, because it never leaves our server.

Changed your mind? Clearing your choice below brings the question back.

Google also publishes a browser add-on that blocks it everywhere, at tools.google.com/dlpage/gaoptout.

If you use the client portal

Clients signing in to the project portal have an account holding a name, email address, a hashed password and the projects they are attached to. Portal activity, documents opened, issues raised, approvals given, invoices viewed, is recorded against that account so both sides have a shared record of what happened and when. Payment card details are never stored on our systems: card payments are processed by our payment provider, and we receive only the outcome and a reference.

Security monitoring and device checks

We protect this site, its clients and its records on the basis of our legitimate interests in security, fraud prevention, incident response and maintaining evidence of attempted or successful unauthorised access. Ordinary browsing is minimised. A full forensic dossier is created only when a security control fires, an authentication fails or succeeds, an anomaly is detected, a protected administrator action occurs, or code/configuration integrity changes.

For one of those security-relevant events, the server records only values it actually receives:

  • The public or trusted-edge IP address, socket address, complete forwarding-header chain, approximate local-GeoIP result, ASN/network operator, reverse DNS where it resolves, and whether installed reputation data confirms a Tor exit, VPN or proxy. Hosting infrastructure on its own is labelled as possible proxy use, not proof of a VPN.
  • The request line, exposed request headers, presented cookie names and values, and a capped copy of the request body. Passwords, session identifiers, authorisation values and other credentials are replaced by a redacted marker and one-way hash. Payloads that caused the alert remain available within the configured size cap.
  • TLS version, cipher, JA3 or JA4 only if the hosting server or trusted edge supplies it. If it does not, the dossier says unavailable.
  • The signed-in Athena username and role, if an account was authenticated. A website cannot obtain the remote operating-system username or NetBIOS/machine hostname, so those fields always say unavailable; Athena never substitutes an invented value.

With your explicit choice, a first-party browser beacon also supplies UA Client Hints, screen and viewport dimensions, device-pixel ratio, colour depth, timezone and offset, languages, processor and memory buckets exposed by the browser, touch points, network information, automation signals and canvas, WebGL, audio and installed-font measurements. These measurements are reduced to a SHA-256 device hash. It is designed to be stable when cookies are cleared, although browser and hardware changes can alter it and identical configurations can collide; it is security evidence, not a civil identity. WebRTC gathering is attempted. A private IP is kept only if the browser genuinely exposes one; an mDNS result is stored as obfuscated, without inventing or claiming a LAN address.

The full browser measurements are encrypted with AES-256-GCM at rest. Security events and administrator audit rows are append-only and HMAC-signed in a hash chain. Expired event dossiers are removed by the retention job; a signed non-personal purge receipt preserves the chain position so an unauthorised deletion is distinguishable from a lawful purge.

Security device checks for this browser: not enabled. Public pages remain available either way. Administrator access requires this check because of the sensitivity and privileges of an admin session.

Our lawful basis

We process your enquiry on the basis of your consent, which you give by ticking the consent box before sending the form, and because processing is necessary to take steps at your request before entering into a contract. You may withdraw consent at any time.

Security event processing is based on our legitimate interests in preventing and investigating attacks, fraud, unauthorised access and data loss, balanced against the limited and risk-triggered collection described above. The optional browser beacon is collected only after an explicit choice. Administrative access is conditional on that device check because an administrator can alter protected business and personal information.

Who else sees it

Enquiries are stored in our own database on our own hosting and are read by the people at Athena who would respond to you. We do not sell, rent or share your details with third parties for marketing. Our email provider necessarily processes the notification and acknowledgement messages in transit. The only automated check that reaches beyond our own server is the mail-record lookup described above: it asks the public domain name system whether your email provider’s domain can receive mail, and it carries nothing about you or your message.

Where it is stored, and for how long

Our own records are held on our servers in South Africa. Google Analytics is the exception: the visit information it collects is processed by Google on infrastructure outside South Africa, under Google's own terms and retention settings rather than ours.

  • Enquiries, three years from the last contact, so we have a record of what was discussed and quoted. Records flagged as automated spam are deleted within 30 days.
  • Analytics and visitor IP history, raw visit records, encrypted address evidence and associated data-quality exceptions are deleted after 400 days by an automated job. Only non-identifying aggregate daily totals are kept beyond that.
  • Job applications, kept for twelve months from the decision if you are not successful, then deleted automatically together with your CV and documents. Successful applications become part of the employee record.
  • Client portal records, kept for the life of the engagement and then for five years afterwards, which is the period South African tax and company law requires us to retain records of work done and invoiced.
  • Security attack dossiers, 365 days; authentication failures and anomalies, 180 days; successful administrator authentication, 90 days; confirmed honeypot and file-integrity events, two years; administrator actions and retention/backup evidence, seven years. Device fingerprints with no sighting are deleted after 365 days. These are configured windows, purged automatically, and every purge is audited.

Your rights

Under POPIA you may ask us to confirm what personal information we hold about you, correct anything that is wrong, delete it, object to how we are using it, or ask for it in a portable format. Write to info@athena-sa.com and we will respond within 30 days. There is no charge for a reasonable request.

If you are not satisfied with how we have handled a request, you may complain to the Information Regulator (South Africa) at inforegulator.org.za.

Security

The site runs over HTTPS. Form submissions carry an anti-forgery token, are rate limited by IP address, and security-module database queries use native prepared statements. To keep automated bots out of the enquiry and referral forms, your browser quietly completes a small mathematical puzzle when you submit, proving a real person is filling the form in; this runs entirely on your device and gathers no additional information about you. Administrative access requires a hashed password and TOTP multi-factor authentication, uses progressive lockout and strict, time-limited cookies, and every administrator action enters a signed hash-chained audit log. No security is absolute, but these controls are explicit rather than framework defaults.

Changes

If this policy changes materially we will update the date at the top of this page. Enquiries already submitted continue to be handled under the policy that applied when you sent them.

Contact

Questions about this policy: info@athena-sa.com or +27 (0)72 220 8741.