Privacy Policy
Last updated: July 2026
This policy explains how Axis-Scale ("we", "us") collects, uses, shares, and protects personal information when you visit axis-scale.com, use the Axis-Scale platform at app.axis-scale.com, or communicate with us. The short version: we collect only what we need to run the service, we do not sell your data, and we do not run advertising trackers.
1. Who we are and what this policy covers
Axis-Scale provides a compliance readiness platform and related expert services. Contact for anything privacy-related: hello@axis-scale.com.
We act in two different roles, and your rights run differently in each:
- As a controller for this website, access requests, your account details, billing, and our communications with you. This policy governs that data.
- As a processor for the compliance content our customers put into the platform (risk registers, policies, evidence, vendor records, and any personal data these contain). The customer controls that data; we process it only on their instructions. If your data appears in a customer's workspace, contact that customer first; we will support their response.
2. Information we collect
| Context | What we collect |
|---|---|
| Website visitors | Standard technical logs: IP address, browser and device type, pages viewed, referrer, timestamps. Used for security and to keep the site working. |
| Access requests | Name, work email, company, and anything you write in the form. The form is processed by Formspree on our behalf. |
| Platform accounts | Name, work email, role, hashed password, two-factor authentication settings, sign-in and session records, and actions recorded in audit logs. |
| Platform content | Whatever your organization enters: risk registers, policies, evidence files, vendor records. Processed on your organization's instructions (see Section 1). |
| Auditor users | Name, email, engagement scope, access window, and an audit log of what was accessed. |
| Billing | Company details, billing contact, invoicing records. We do not store full payment card numbers. |
| Correspondence | Emails and messages you exchange with us, including support requests. |
We collect no special categories of personal data, and we do not want any: please do not put health, biometric, or similar sensitive personal data into free-text fields.
3. How we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide the platform and expert services, manage accounts, respond to access requests | Performance of a contract, or steps taken at your request before a contract |
| Secure the service: authentication, session management, abuse prevention, audit logging | Legitimate interests (keeping the service and our customers' data safe) |
| Service communications: onboarding, renewal, security, and change notices | Performance of a contract, or legitimate interests |
| Marketing emails | Consent (opt-in only, unsubscribe in every email) |
| Optional analytics, if you allow them in the cookie banner | Consent |
| Billing, accounting, and tax records | Legal obligation |
| Establishing or defending legal claims | Legitimate interests |
We do not use your data to train AI models, we do not profile you, and we make no automated decisions that produce legal or similarly significant effects on individuals. The platform's automated risk scoring evaluates organizational risks, not people.
4. Your platform data belongs to you
Compliance content you enter into the platform is yours. We process it only to provide the service, access it only when needed for support (or as required by law), never use it for marketing, and never share it with other customers. You can export it at any time during your subscription. Auditor access to your workspace happens only through engagements you create, with the scope and expiry you set, and every access is logged. A data processing agreement is available on request at hello@axis-scale.com.
5. Cookies and local storage
Everything the service stores in your browser:
| Item | Type | Purpose | Lifetime |
|---|---|---|---|
| Cookie banner choice | Local storage (this site) | Remembers your Accept / Essential-only choice | Until you clear it |
| Session cookies | Essential, httpOnly (platform) | Keep you signed in securely | Short-lived access token, refresh token rotated regularly |
| Trusted device | Essential (platform, optional) | Lets you skip two-factor prompts on a device you verified | About 14 days |
| Analytics | None today | If we add privacy-respecting analytics, they load only after you choose "Accept", and this table will be updated | n/a |
We use no advertising cookies, ad pixels, or cross-site trackers. Fonts are served by Google Fonts, which receives your IP address when the page loads its stylesheet. You can change your cookie choice at any time via the "Cookie preferences" link in the footer.
6. Who we share it with
We do not sell or rent personal information. We share it only with the providers that run the service, under contracts that restrict them to processing on our instructions:
| Provider | What they do | Location |
|---|---|---|
| Vercel | Website and application hosting, content delivery | US / EU edge |
| Railway | Application backend and database hosting | US / EU |
| Formspree | Processes the access-request form on this site | US |
| Google Fonts | Font delivery for this site | Global |
| Email delivery | Sending transactional and service email | US / EU |
Beyond that, we disclose personal information only: to auditors you invite into your own workspace; when required by law or a valid legal process (we will notify you unless legally barred); or as part of a merger or acquisition, in which case this policy continues to apply until it is updated and you are notified.
7. International transfers
Our providers process data in the United States and the European Union. Where personal data covered by GDPR is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses or the provider's participation in recognized adequacy frameworks. Israel is recognized by the European Commission as providing adequate data protection.
8. Security
Security is the product we sell, and we hold ourselves to the same standard. Measures include:
- Encrypted connections (TLS) everywhere; encryption at rest via our hosting providers
- Role-based access control with least-privilege roles, enforced on every endpoint
- Two-factor authentication, with optional organization-wide enforcement
- Short-lived sessions with rotating refresh tokens and httpOnly cookies
- Scoped, time-boxed, read-only auditor access that locks after first use
- Audit logging of security-relevant actions, including access-scope changes
No system is perfectly secure. If we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law, without undue delay.
9. Retention
| Data | Kept for |
|---|---|
| Access requests that do not become accounts | Up to 12 months, then deleted |
| Account and platform data | Life of the subscription, plus a 30-day export window after termination, then deletion in the ordinary course |
| Security and audit logs | Up to 12 months, longer if needed for an investigation |
| Billing and tax records | As required by law (typically 7 years) |
| Correspondence | As long as relevant to the relationship |
10. Your rights
Depending on where you live (including under the GDPR, UK GDPR, and Israel's Privacy Protection Law), you can:
- Access the personal information we hold about you, and get a copy
- Correct inaccurate information
- Request deletion
- Object to or restrict certain processing
- Receive data you provided in a portable format
- Withdraw consent at any time (for example, unsubscribe from marketing or change your cookie choice), without affecting processing that happened before
Email hello@axis-scale.com; we respond within 30 days and may ask you to verify your identity. Exercising your rights never costs anything and never affects your service. If you are unsatisfied, you can complain to your local data protection authority. Remember: for personal data inside a customer's workspace, the customer is the controller, and we will route your request to them.
11. Marketing
We send marketing email only if you opted in, every message has a working unsubscribe link, and unsubscribing never affects service communications like security notices or invoices.
12. Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect information from children; if you believe we have, contact us and we will delete it.
13. Changes
We will post changes here and update the date at the top. For material changes we will notify you by email or in the service before they take effect.
14. Contact
Privacy questions, rights requests, or our data processing agreement: hello@axis-scale.com.