Last updated: 12 July 2026
This policy explains how Hyperflect processes personal data when you use Athena QMS (“the Service”). We provide the Service to your organisation under a subscription agreement; for most data processed in the Service, your organisation is the data controller and we act as a processor on its behalf.
To operate the Service we process account information (your name, work email address and authentication credentials), records of the actions you take in the Service (such as document reviews, approvals and electronic signatures, which form part of your organisation’s regulated audit trail), and technical data necessary to secure the Service (such as session identifiers and IP addresses).
Controlled documents managed through the Service are stored in your organisation’s own Microsoft SharePoint environment. The Service accesses them only with the permissions your organisation has granted and only to provide document management and approval functionality.
All data is encrypted in transit. Passwords are stored using modern, memory-hard hashing (Argon2id) and are never logged. Tenant data is segregated at the database level using row-level security. Access to production systems is restricted and audited.
Because the Service supports regulated quality processes, audit trail and electronic signature records are retained in line with your organisation’s regulatory retention obligations and cannot be deleted by individual users. Account data is retained for as long as your organisation maintains your access to the Service.
Depending on your jurisdiction, you may have rights to access, correct or erase personal data we hold about you. Requests should be made in the first instance to your organisation administrator, who controls the data processed in the Service; we will support your organisation in fulfilling them.
Privacy questions can be sent to support@hyperflect.com.