Privacy Policy

How we handle personal data on this website, in the Axiomera console, and in our business relationships.

Effective August 3, 2026

01Who we are

Axiomera is operated by Axiomera AI Inc., a Delaware corporation ("we," "us," "our"). We are the controller for the personal data described in this policy.

Axiomera AI Inc.
10258 Hardin Valley Rd, Suite 2
Knoxville, TN 37932, United States
info@axiomera.com

02What this policy covers

This policy covers personal data we handle in our own right: visitors to axiomera.com, people who request a briefing or contact us, named users of the Axiomera console, business contacts at customers and partners, and job applicants.

It does not cover the records our platform processes for a customer. Axiomera deploys inside a customer's own cloud environment, and where the platform works on records belonging to that customer, the customer decides how they are used and remains responsible for them. Our handling of those records is governed by our written agreement with that customer, along with a data processing agreement and, where protected health information is involved, a business associate agreement.

If you are an individual whose records may have been processed by an organization using Axiomera, that organization holds your data and is the right place to direct a request. If you contact us, we will point you to them.

03Personal data we collect

Briefing and contact requests. Your name, business email address, employer, job title, country, and anything you write in the message. We use this to respond and to evaluate whether there is a fit.

Console account data. Where you are given an account in the Axiomera console, the name and business email address your administrator provided, your role and permissions, your organization and any client accounts you are assigned to, authentication events, and a record of who issued your invitation and when.

Business relationship data. Contact details and correspondence for people at customers, prospective customers, partners, platform marketplaces, and research collaborators, together with records of meetings, agreements, and commercial discussions.

Billing data. Billing contact details and account records. Payment card details are handled by our payment processor and do not reach our servers.

Website and platform technical data. IP address, browser and device type, operating system, referring page, pages viewed, and timestamps, used to operate the service, diagnose faults, and protect against abuse.

Cookies and similar technologies. We use four categories, and you control the last three from the cookie settings on this site.

Essential.
Strictly necessary to operate and secure the site and to keep console users signed in. These are always on.
Analytics and measurement.
Persistent identifiers that let us count visits, see which pages are read, and understand how people move through the site. Off until you allow them.
Advertising measurement.
Tags from an advertising platform that let us attribute a visit to a campaign and build audiences for future campaigns. Off until you allow them.
Organization identification.
We use a third-party service to match the IP address in our server logs to the organization it belongs to, so we can see which businesses are interested in our products. It identifies organizations, not individuals. It returns no name, email address, or phone number, and we do not deploy any tool that resolves an anonymous visit to a named individual.

Nothing outside the essential category runs until you allow it. Visitors in the European Economic Area, the United Kingdom, and Switzerland are asked before anything non-essential is set, consent can be withdrawn at any time and is as easy to withdraw as it was to give, and we honor the Global Privacy Control browser signal as an opt-out everywhere.

04Information we do not collect

We do not knowingly collect sensitive or special category personal data through this website, a briefing request, or email. That includes genetic data, biometric data used to identify a person, health or medical information, precise geolocation, and information about religious or political beliefs.

Do not send us patient data or sample records containing real personal data. If an evaluation requires sample data, we will agree the appropriate legal terms first and arrange a secure route. Unsolicited material of that kind will be deleted.

05Why we handle it, and on what basis

PurposeBasis under GDPR and UK GDPR
Providing and securing the console, authenticating users, and sending account, security, and status notificationsPerformance of a contract, legitimate interests
Responding to briefing requests and enquiriesLegitimate interests, or steps preparatory to a contract
Managing customer, partner, and collaborator relationships and performing agreementsPerformance of a contract
Billing, usage metering, and collectionsPerformance of a contract
Business development correspondence with named business contactsLegitimate interests, or consent where local law requires it
Operating, securing, and improving the website and platformLegitimate interests
Meeting legal, tax, accounting, and regulatory obligations, and defending legal claimsLegal obligation, legitimate interests

Where we rely on legitimate interests, we have weighed those interests against the effect on you and limited what we do accordingly. You may object, and Section 9 explains how.

We do not use personal data collected through this website or the console to train models.

06Who we share it with

We do not sell personal data. We do disclose identifiers and online activity data to an advertising platform for campaign measurement and for building audiences, and under California law that activity can count as sharing for cross-context behavioral advertising. We treat it that way rather than argue about it, which is why the opt-out described in Section 9 exists and why we honor the Global Privacy Control browser signal. Otherwise we disclose personal data only as follows.

Service providers. Vendors who process on our behalf under contract, limited to what their function requires: cloud hosting and infrastructure, transactional email delivery, payment processing through Stripe, customer relationship management, scheduling, document management, website analytics, an advertising platform for campaign measurement, an organization-identification provider, and professional services. A current list of these sub-processors is available on request.

Within your organization. Administrators at your organization can see its console users, roles, activity, and billing status. Each customer organization sees only its own.

Affiliates. We may share with entities that control us, are controlled by us, or are under common control with us, for the purposes described here and consistent with this policy. We do not transfer customer workspace or record content to an affiliate for that affiliate's own separate purposes.

Professional advisers. Lawyers, accountants, auditors, and insurers, where needed and under confidentiality obligations.

Legal and safety. Where legally required, or where reasonably necessary to establish or defend legal claims or to protect the rights, safety, or property of any person.

Corporate transactions. In connection with a financing, merger, acquisition, or sale of assets, subject to confidentiality and to this policy continuing to apply.

07International transfers

We operate in the United States, and our team is distributed across the United States, Europe, and Latin America. Personal data may therefore be transferred to and accessed from countries other than your own, including the United States.

For transfers out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, and supplementary technical and organizational measures including encryption in transit and at rest and access controls. A copy of the relevant clauses is available on request from info@axiomera.com.

08How long we keep it

We keep personal data for as long as needed for the purpose it was collected for, then for as long as reasonably necessary to meet legal, tax, accounting, and dispute-resolution obligations. Console account records are kept for the life of the customer relationship and a period afterward. Briefing requests that do not lead to a relationship are kept for a limited period and then deleted. Suppression list entries are kept indefinitely so that we do not email someone who asked us not to. When data is no longer needed, we delete or anonymize it.

09Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a portable copy, to object to or ask us to restrict how we use it, and to withdraw consent where we relied on consent. Email info@axiomera.com. We may need to verify your identity first and will not use verification information for anything else. You may use an authorized agent with proof of authorization.

If we deny your request, we will tell you why and you may appeal by replying to the same address. We will review the appeal and respond with our decision and the reasons for it. We will not treat you differently for exercising any of these rights.

If you are in the European Economic Area, the United Kingdom, or Switzerland, you may complain to your local supervisory authority. We would appreciate the chance to address your concern first.

If you are in California, we do not sell personal information, and you may request disclosure of the categories and specific pieces we have collected, the sources, the purposes, and the categories of recipients, as well as deletion and correction. You also have the right to opt out of sharing for cross-context behavioral advertising, which as Section 6 explains is how California law may characterize our use of advertising measurement. To opt out, decline the analytics and advertising categories in the cookie settings on this site. We also honor the Global Privacy Control signal automatically, so if your browser sends it you are already opted out and no further action is needed. California residents are not treated differently for exercising any of these rights.

Email preferences. Console notifications about your account, security, and pipeline activity are part of the service and cannot be unsubscribed from while your account is active, though you can adjust preferences where the product offers them. Any business development correspondence includes a way to opt out, and we honor opt-outs promptly.

10Security

We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, per-organization isolation of console data, authentication controls including multi-factor authentication, access limited to personnel who need it for their role, logging of security-relevant events, vendor diligence, and staff confidentiality obligations.

11Children

This website and the Axiomera console are directed to business audiences. We do not knowingly collect personal data from anyone under eighteen.

12Changes

We may update this policy. The date at the top shows when the current version took effect. Where a change materially affects how we handle personal data, we will give notice on this page, in the console, or by contacting account administrators before it takes effect.

13Contact

Questions, requests, and complaints:

info@axiomera.com

Axiomera AI Inc.
10258 Hardin Valley Rd, Suite 2
Knoxville, TN 37932
United States