Privacy Policy
Last updated: [DATA] — Draft, pending review by a qualified Italian lawyer.
[DATA] below). One international-transfer point is flagged openly in "International transfers" — read it. Do not treat this as a final, legally-binding document until the placeholders are filled and it has had legal review.1. Who we are (data controller)
Axiom is operated by [DATA: legal company name], VAT/P.IVA [DATA], registered at [DATA: registered address] ("we", "us"), the data controller for the personal data described in this policy. For any privacy question, contact us at [DATA: privacy contact email].
2. Controller and processor roles
For account and usage data (see below), we act as data controller. For any personal data contained in the documents and company information you upload or enter, we act as data processor on your behalf, and you (our customer) are the controller. You are responsible for having a lawful basis and the necessary rights to submit that content for processing. If you require a Data Processing Agreement under Article 28 GDPR, contact us.
3. What we collect
- Account information (name, email, organization) via our authentication provider, Clerk.
- The documents you upload for analysis (e.g. Confidential Information Memoranda) and the financial data our system extracts from them.
- Company information you enter directly for sell-side document drafting (CIM/teaser/buyer list projects) and any lists you upload for analysis.
- Billing and payment reference data needed to activate and manage your plan.
- Basic usage and technical data (features used, error and access logs) needed to operate, secure, and support the service.
4. Why we process it, and our legal bases
- To provide the service you have requested — performance of a contract (Art. 6(1)(b) GDPR).
- To secure, maintain, and improve the service and prevent abuse — our legitimate interests (Art. 6(1)(f)).
- To handle billing and comply with accounting/tax obligations — legal obligation (Art. 6(1)(c)).
- To respond to your enquiries (e.g. the contact form) — legitimate interests / pre-contractual steps.
We do not sell your data, and we do not use your Customer Content or Output to train our own or any third party's AI models.
5. Sub-processors we share data with
To operate the service, the following processors handle data on our behalf, each only as needed for its function:
- Supabase — database and storage; data at rest encrypted (AES-256).
- Clerk — authentication and account/organization management.
- Vercel — frontend hosting and basic analytics; Railway — backend hosting.
- Stripe — payment processing (where used).
- Resend — transactional email (e.g. contact and notification emails).
- LlamaParse — document parsing, and DeepSeek — AI extraction, valuation-input drafting, and document generation. These process the text of your documents to power the product's core features.
Per their stated policies, these providers do not train their own models on your data. We may also disclose data where required by law or to protect our legal rights.
6. International transfers
Some Sub-processors are located outside the EU/EEA, which involves transferring data abroad. In particular:
DeepSeek is operated by a China-based provider. If you are in the EU/EEA, this means the text of your documents is transferred outside the EU/EEA for processing, and we have not yet completed a formal international-transfer safeguard assessment (e.g. Standard Contractual Clauses) for that transfer. We flag this openly rather than gloss over it, because it is directly relevant to any GDPR-compliance claim. Do not upload documents whose transfer outside the EU/EEA you are not authorized to permit. We are working to put appropriate safeguards (or an EU-based processing alternative) in place; contact us if you need details before uploading.
7. Retention and deletion
The original PDF you upload is used only transiently to extract its text and is not stored after processing. The extracted financial data, your corrections, valuation results, and any sell-side documents you draft are retained while your account is active so you can keep using them; deleting a deal or project in the app permanently deletes that data. Billing records are kept as long as required by tax/accounting law. We do not currently apply an automatic time-based deletion policy to derived data beyond the above.
8. Security
Data in transit is encrypted via TLS; data at rest in our database is encrypted using AES-256. Access to your data is restricted to your account, or to your organization's members if you use a shared organization workspace, enforced at the application layer. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
9. Automated processing
The service uses AI to assist with extraction and drafting, but it does not make solely automated decisions that produce legal or similarly significant effects about individuals. A human (you) reviews and validates the Output.
10. Your rights
If you are in the EU/EEA, you have the right to access, rectify, erase, restrict, and object to processing of your personal data, and to data portability. You can access, correct, export, or delete much of your data directly in the app, or by contacting us at [DATA: privacy contact email]. Where processing is based on consent, you may withdraw it at any time. You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it). For personal data we process on a customer's behalf, we will direct data-subject requests to that customer (the controller).
11. Cookies
We use cookies and similar technologies that are strictly necessary to run the service, such as authentication/session cookies set by Clerk to keep you logged in. We use privacy-friendly, aggregate analytics to understand usage. We do not use advertising or cross-site tracking cookies.
12. Children
Axiom is a professional B2B tool and is not directed to, or intended for, anyone under 18. We do not knowingly collect personal data from children.
13. Changes to this policy
We will update this page if our practices change and note the date at the top. For material changes we will provide reasonable notice.