← Back to Axiom

Privacy Policy

Last updated: [DATA] — Draft, pending legal review.

This is a working draft describing our actual current practices. It has not been reviewed by a lawyer and does not yet include our registered company name, VAT number, or registered address (see the placeholders marked [DATA] below). Do not treat this as a final, legally-binding document until those are filled in and it has had legal review.

Who we are

Axiom is operated by [DATA: legal company name], [DATA: VAT/company registration number], registered at [DATA: registered address]. For any privacy question, contact us at [DATA: privacy contact email].

What we collect

  • Account information (name, email) via our authentication provider, Clerk.
  • The documents you upload for analysis (Confidential Information Memoranda) and the financial data our system extracts from them.
  • Company information you enter directly for sell-side document drafting (CIM/teaser/buyer list projects).
  • Basic usage data (which features you use, error logs) needed to operate and support the service.

How we use it, and who we share it with

Your documents and data are processed solely to provide the extraction, valuation, Q&A, and document-drafting features you use. We do not sell your data. To provide the service, the following processors handle data on our behalf:

  • Supabase (database and storage) — data at rest is encrypted (AES-256).
  • Clerk (authentication and, where enabled, billing).
  • LlamaParse (document parsing) and DeepSeek (AI extraction, valuation input drafting, and document generation) — these process the text of your documents to power the product's core features. DeepSeek is operated by a China-based provider; if you are in the EU/EEA, this means your document text is transferred outside the EU/EEA for processing. We have not yet completed a formal international-transfer safeguard assessment (e.g. Standard Contractual Clauses) for this — flagged honestly here rather than glossed over, since it's directly relevant to any GDPR-compliance claim we make. None of these providers train their own models on your data, per their stated policies.

Retention and deletion

The original PDF you upload is used only transiently to extract its text and is not stored after processing. The extracted financial data, your corrections, valuation results, and any sell-side documents you draft are retained for as long as your account is active, so you can keep using them — deleting a deal or project in the app permanently deletes this data. We do not currently have an automatic time-based deletion policy for this derived data beyond that.

Security

Data in transit is encrypted via TLS. Data at rest in our database is encrypted using AES-256. Access to your data is restricted to your account (or your organization's members, if you use a shared organization workspace).

Your rights

You can access, correct, export, or delete your data at any time from within the app, or by contacting us at [DATA: privacy contact email]. If you are in the EU/EEA, you have rights under the GDPR including access, rectification, erasure, and data portability.

Changes to this policy

We will update this page if our practices change and note the date at the top.