1. Introduction and Scope
This Privacy Policy explains how Axiom Advisory Global ("Axiom Advisory," "we," "us," or "our") collects, uses, discloses, and protects personal data across our products and services, including our flagship platform and any other current or future service we operate (collectively, the "Services").
This policy applies to everyone who interacts with the Services, including customer administrators, invited team members, and personnel who use the Services on behalf of a customer organisation ("Customer," "you," or "your organisation"). It covers data we collect directly as a data controller and data our Customers submit through the Services, for which we act as a data processor.
By creating an account or otherwise accessing the Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.
Defined terms in this policy, including "personal data," "processing," "data controller," "data processor," "data subject," and "sub-processor," carry the meanings given to them under the EU General Data Protection Regulation (GDPR) and, where applicable, corresponding Australian and Californian privacy legislation.
2. Information We Collect
We collect four categories of information. The first two are collected directly by us as controller. The third is submitted by Customers and processed by us as processor. The fourth category, sensitive personal data, is not collected at all.
2.1 Account Data
- Full name, company name, business email address, and phone number
- Billing details, including billing address and tax identification number where provided
- Password, stored using industry-standard encryption - we never store or have access to plaintext passwords
- Role and permission level within your organisation's account
2.2 Usage and Technical Data
- IP address, retained for a limited period for rate limiting, abuse prevention, and security monitoring
- Browser and device information, used for audit logging and security analysis
- Feature usage data - which parts of the Services are used, and when - used for platform health monitoring and internal cost management
- Session identifiers, which are temporary and refreshed regularly for account security
2.3 Customer-Submitted Data
When your organisation uses the Services, your personnel may upload documents, images, and related project records. We process this data solely as instructed by the Customer that controls it. This may include:
- Uploaded images and documents, stored in encrypted cloud storage
- Data extracted from those documents, such as supplier names, reference numbers, quantities, materials, locations, dates, and vehicle identifiers
- Project names and site locations, where a Customer chooses to organise records by project
This category of data may incidentally include names of individual drivers or site personnel recorded on a document by a third party. We do not independently collect, verify, or actively process this incidental data beyond storing and displaying it as submitted by the Customer.
2.4 Sensitive Personal Information
3. How We Use Your Information
We use personal data for the purposes below, each mapped to its legal or commercial basis.
| Purpose | Data Used | Basis |
|---|---|---|
| Provide, operate, and maintain the Services | Account Data, Customer-Submitted Data | Contract |
| Authenticate users and secure accounts | Account Data, session identifiers | Contract / Legitimate Interest |
| Detect and prevent fraud, abuse, or security incidents | IP address, device data, usage logs | Legitimate Interest |
| Bill and administer subscriptions | Billing details | Contract |
| Provide customer support | Account Data, relevant Customer-Submitted Data | Contract |
| Send transactional communications (invites, resets, notifications) | Email address | Contract |
| Provide AI-assisted document processing features, where enabled | Submitted documents (processed transiently) | Contract, on Customer instruction |
| Monitor platform health and manage costs | Feature usage data | Legitimate Interest |
| Comply with legal obligations | Account Data, audit records | Legal Obligation |
We do not sell personal data, and we do not use personal data for third-party advertising or behavioural marketing.
4. Legal Bases for Processing
Where the GDPR applies, we rely on the following lawful bases under Article 6(1):
- Contract (Art. 6(1)(b)): processing necessary to perform our contract with the Customer and deliver the Services.
- Legitimate Interest (Art. 6(1)(f)): processing of security logs and usage data for fraud prevention, platform security, and service improvement, balanced against data subject rights.
- Legal Obligation (Art. 6(1)(c)): processing necessary to meet tax, accounting, or regulatory record-keeping requirements.
Because our Services are provided on a business-to-business basis under a commercial contract, explicit consent is not generally required as a legal basis for core account and platform functionality. Where consent is used for optional communications, it may be withdrawn at any time.
5. Data Subject Rights
Subject to applicable law, you may have the following rights over your personal data:
- Access - request a copy of the personal data we hold about you.
- Correction - request correction of inaccurate or incomplete personal data.
- Deletion - request deletion of your personal data, subject to the backup retention period described in Section 8.
- Restriction - request that we limit how we process your personal data in certain circumstances.
- Portability - request a structured, machine-readable export of your organisation's data.
- Objection - object to processing carried out on the basis of legitimate interest.
- Non-discrimination - you will not be penalised, charged a different price, or denied service for exercising any of these rights.
How to exercise your rights
Email admin@axiomadvisory.org with the subject line "Data Subject Request," and include your organisation name and the email address associated with your account. Where a request relates to Customer-Submitted Data, we may direct you to the Customer organisation that controls that data, as we act only as its processor.
We respond within 30 days for requests governed by the GDPR or the Australian Privacy Act, and within 45 days for requests governed by the CCPA/CPRA, as required by applicable law.
6. Sub-processors
We share personal data only with the sub-processors necessary to operate the Services, each bound by a data processing agreement requiring confidentiality and appropriate security measures. A current list of sub-processors is maintained on our Sub-processors page. We provide at least 30 days' notice before appointing a new sub-processor that will process Customer-Submitted Data.
We do not sell or rent personal data to third parties. We may disclose personal data where required by law, to enforce our agreements, or to protect the rights, property, or safety of Axiom Advisory, our Customers, or others.
7. Data Security
We apply industry-standard technical and organisational measures to protect personal data, including:
- Encryption of data in transit and at rest using industry-standard encryption protocols
- Access controls and authentication mechanisms limiting internal access on a least-privilege basis
- Secure session management with automatic session expiry and rotation
- Rate limiting and abuse-prevention systems on all customer-facing endpoints
- Continuous audit logging of access and administrative actions
- Regular internal security reviews and an established incident response process
No system is completely secure, and we cannot guarantee absolute security. We continually review and improve our security practices as the Services evolve. Further detail is available on our Trust Center.
8. Data Retention
| Data Category | Retention Period |
|---|---|
| Active account data | For the duration of the subscription |
| Cancelled account data (organisation data, files, records, audit logs) | 90-day grace period, then permanent deletion |
| Append-only audit records | 7 years for legal and compliance purposes, then archived |
| Platform usage and billing-support records | 2 years, to support billing dispute resolution |
| System backups | 7 days, then automatically purged |
Backup caveat: when data is deleted from live systems, it may persist in encrypted backups for the backup retention period noted above before being permanently purged. We do not selectively restore individually deleted records from backups except where required for disaster recovery.
9. International Transfers
Personal data may be transferred to, and processed in, countries outside your own. Where we transfer personal data originating from the European Economic Area or the United Kingdom to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, supplemented by additional technical and contractual safeguards, and we maintain data processing agreements with all relevant sub-processors.
Our primary hosting region for infrastructure is Australia, with supporting infrastructure in other regions as needed to provide the Services reliably.
10. Cookies
We use only essential cookies required for authentication and session management. We do not use third-party advertising or analytics tracking cookies. Full detail is available in our Cookie Policy.
11. Children's Privacy
The Services are business tools intended for use by adult professionals. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, contact us at admin@axiomadvisory.org.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. For material changes, we provide at least 30 days' notice by email to the primary contact on each account before the change takes effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Services after a change takes effect constitutes acceptance of the revised policy.
13. Contact Us
For any privacy-related question, request, or concern, including all data subject rights requests, contact us:
Axiom Advisory Global
Attn: Privacy Team
Email: admin@axiomadvisory.org
Registered office: Sydney, New South Wales, Australia
If you are located in the European Economic Area or the United Kingdom and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority. Australian residents may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.
14. Automated Decision-Making
Where the Services offer AI-assisted document data extraction, this feature is used to assist Customers in processing their own submitted documents more efficiently. Any resulting output is presented to the Customer for review, and the Customer retains full control over how extracted data is used, corrected, or relied upon. We do not use this feature to make decisions producing legal or similarly significant effects on individuals without human involvement.
15. California Privacy Rights (CCPA/CPRA)
California residents may have additional rights under the California Consumer Privacy Act and California Privacy Rights Act, including the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not collect sensitive personal information as described in Section 2.4. California residents may exercise their rights using the contact details in Section 13.
16. Australian Privacy Principles
To the extent the Australian Privacy Act 1988 applies, we handle personal information in accordance with the Australian Privacy Principles, including principles governing the open and transparent management of personal information, collection of solicited personal information, use and disclosure, data quality, data security, and access and correction. Australian residents may raise a privacy concern using the contact details in Section 13, and may escalate unresolved concerns to the Office of the Australian Information Commissioner.