Home Privacy Terms Sub-processors DPA Cookies Trust Center
Legal

Privacy Policy

Last Updated: 7 August 2026  ·  Version: 1.0

Contents

  1. Introduction and Scope
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Bases for Processing
  5. Data Subject Rights
  6. Sub-processors
  7. Data Security
  8. Data Retention
  9. International Transfers
  10. Cookies
  11. Children's Privacy
  12. Changes to This Policy
  13. Automated Decision-Making
  14. California Privacy Rights
  15. Australian Privacy Principles
  16. Contact Us

1. Introduction and Scope

This Privacy Policy explains how Axiom Advisory Global ("Axiom Advisory," "we," "us," or "our") collects, uses, discloses, and protects personal data across our products and services, including our flagship platform and any other current or future service we operate (collectively, the "Services").

This policy applies to everyone who interacts with the Services, including customer administrators, invited team members, and personnel who use the Services on behalf of a customer organisation ("Customer," "you," or "your organisation"). It covers data we collect directly as a data controller and data our Customers submit through the Services, for which we act as a data processor.

By creating an account or otherwise accessing the Services, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Services.

Defined terms in this policy, including "personal data," "processing," "data controller," "data processor," "data subject," and "sub-processor," carry the meanings given to them under the EU General Data Protection Regulation (GDPR) and, where applicable, corresponding Australian and Californian privacy legislation.

2. Information We Collect

We collect four categories of information. The first two are collected directly by us as controller. The third is submitted by Customers and processed by us as processor. The fourth category, sensitive personal data, is not collected at all.

2.1 Account Data

  • Full name, company name, business email address, and phone number
  • Billing details, including billing address and tax identification number where provided
  • Password, stored using industry-standard encryption - we never store or have access to plaintext passwords
  • Role and permission level within your organisation's account

2.2 Usage and Technical Data

  • IP address, retained for a limited period for rate limiting, abuse prevention, and security monitoring
  • Browser and device information, used for audit logging and security analysis
  • Feature usage data - which parts of the Services are used, and when - used for platform health monitoring and internal cost management
  • Session identifiers, which are temporary and refreshed regularly for account security

2.3 Customer-Submitted Data

When your organisation uses the Services, your personnel may upload documents, images, and related project records. We process this data solely as instructed by the Customer that controls it. This may include:

  • Uploaded images and documents, stored in encrypted cloud storage
  • Data extracted from those documents, such as supplier names, reference numbers, quantities, materials, locations, dates, and vehicle identifiers
  • Project names and site locations, where a Customer chooses to organise records by project

This category of data may incidentally include names of individual drivers or site personnel recorded on a document by a third party. We do not independently collect, verify, or actively process this incidental data beyond storing and displaying it as submitted by the Customer.

2.4 Sensitive Personal Information

None. We do not collect, request, or knowingly process sensitive personal data of any kind, including health information, biometric data, financial account numbers, precise geolocation, or any other special category of data recognised under applicable law.

3. How We Use Your Information

We use personal data for the purposes below, each mapped to its legal or commercial basis.

PurposeData UsedBasis
Provide, operate, and maintain the ServicesAccount Data, Customer-Submitted DataContract
Authenticate users and secure accountsAccount Data, session identifiersContract / Legitimate Interest
Detect and prevent fraud, abuse, or security incidentsIP address, device data, usage logsLegitimate Interest
Bill and administer subscriptionsBilling detailsContract
Provide customer supportAccount Data, relevant Customer-Submitted DataContract
Send transactional communications (invites, resets, notifications)Email addressContract
Provide AI-assisted document processing features, where enabledSubmitted documents (processed transiently)Contract, on Customer instruction
Monitor platform health and manage costsFeature usage dataLegitimate Interest
Comply with legal obligationsAccount Data, audit recordsLegal Obligation

We do not sell personal data, and we do not use personal data for third-party advertising or behavioural marketing.

4. Legal Bases for Processing

Where the GDPR applies, we rely on the following lawful bases under Article 6(1):

  • Contract (Art. 6(1)(b)): processing necessary to perform our contract with the Customer and deliver the Services.
  • Legitimate Interest (Art. 6(1)(f)): processing of security logs and usage data for fraud prevention, platform security, and service improvement, balanced against data subject rights.
  • Legal Obligation (Art. 6(1)(c)): processing necessary to meet tax, accounting, or regulatory record-keeping requirements.

Because our Services are provided on a business-to-business basis under a commercial contract, explicit consent is not generally required as a legal basis for core account and platform functionality. Where consent is used for optional communications, it may be withdrawn at any time.

5. Data Subject Rights

Subject to applicable law, you may have the following rights over your personal data:

  • Access - request a copy of the personal data we hold about you.
  • Correction - request correction of inaccurate or incomplete personal data.
  • Deletion - request deletion of your personal data, subject to the backup retention period described in Section 8.
  • Restriction - request that we limit how we process your personal data in certain circumstances.
  • Portability - request a structured, machine-readable export of your organisation's data.
  • Objection - object to processing carried out on the basis of legitimate interest.
  • Non-discrimination - you will not be penalised, charged a different price, or denied service for exercising any of these rights.

How to exercise your rights

Email admin@axiomadvisory.org with the subject line "Data Subject Request," and include your organisation name and the email address associated with your account. Where a request relates to Customer-Submitted Data, we may direct you to the Customer organisation that controls that data, as we act only as its processor.

We respond within 30 days for requests governed by the GDPR or the Australian Privacy Act, and within 45 days for requests governed by the CCPA/CPRA, as required by applicable law.

6. Sub-processors

We share personal data only with the sub-processors necessary to operate the Services, each bound by a data processing agreement requiring confidentiality and appropriate security measures. A current list of sub-processors is maintained on our Sub-processors page. We provide at least 30 days' notice before appointing a new sub-processor that will process Customer-Submitted Data.

We do not sell or rent personal data to third parties. We may disclose personal data where required by law, to enforce our agreements, or to protect the rights, property, or safety of Axiom Advisory, our Customers, or others.

7. Data Security

We apply industry-standard technical and organisational measures to protect personal data, including:

  • Encryption of data in transit and at rest using industry-standard encryption protocols
  • Access controls and authentication mechanisms limiting internal access on a least-privilege basis
  • Secure session management with automatic session expiry and rotation
  • Rate limiting and abuse-prevention systems on all customer-facing endpoints
  • Continuous audit logging of access and administrative actions
  • Regular internal security reviews and an established incident response process

No system is completely secure, and we cannot guarantee absolute security. We continually review and improve our security practices as the Services evolve. Further detail is available on our Trust Center.

8. Data Retention

Data CategoryRetention Period
Active account dataFor the duration of the subscription
Cancelled account data (organisation data, files, records, audit logs)90-day grace period, then permanent deletion
Append-only audit records7 years for legal and compliance purposes, then archived
Platform usage and billing-support records2 years, to support billing dispute resolution
System backups7 days, then automatically purged

Backup caveat: when data is deleted from live systems, it may persist in encrypted backups for the backup retention period noted above before being permanently purged. We do not selectively restore individually deleted records from backups except where required for disaster recovery.

9. International Transfers

Personal data may be transferred to, and processed in, countries outside your own. Where we transfer personal data originating from the European Economic Area or the United Kingdom to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, supplemented by additional technical and contractual safeguards, and we maintain data processing agreements with all relevant sub-processors.

Our primary hosting region for infrastructure is Australia, with supporting infrastructure in other regions as needed to provide the Services reliably.

10. Cookies

We use only essential cookies required for authentication and session management. We do not use third-party advertising or analytics tracking cookies. Full detail is available in our Cookie Policy.

11. Children's Privacy

The Services are business tools intended for use by adult professionals. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, contact us at admin@axiomadvisory.org.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. For material changes, we provide at least 30 days' notice by email to the primary contact on each account before the change takes effect. The "Last Updated" date at the top of this page reflects the most recent revision. Continued use of the Services after a change takes effect constitutes acceptance of the revised policy.

13. Contact Us

For any privacy-related question, request, or concern, including all data subject rights requests, contact us:

Axiom Advisory Global
Attn: Privacy Team
Email: admin@axiomadvisory.org
Registered office: Sydney, New South Wales, Australia

If you are located in the European Economic Area or the United Kingdom and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority. Australian residents may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.

14. Automated Decision-Making

Where the Services offer AI-assisted document data extraction, this feature is used to assist Customers in processing their own submitted documents more efficiently. Any resulting output is presented to the Customer for review, and the Customer retains full control over how extracted data is used, corrected, or relied upon. We do not use this feature to make decisions producing legal or similarly significant effects on individuals without human involvement.

15. California Privacy Rights (CCPA/CPRA)

California residents may have additional rights under the California Consumer Privacy Act and California Privacy Rights Act, including the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not collect sensitive personal information as described in Section 2.4. California residents may exercise their rights using the contact details in Section 13.

16. Australian Privacy Principles

To the extent the Australian Privacy Act 1988 applies, we handle personal information in accordance with the Australian Privacy Principles, including principles governing the open and transparent management of personal information, collection of solicited personal information, use and disclosure, data quality, data security, and access and correction. Australian residents may raise a privacy concern using the contact details in Section 13, and may escalate unresolved concerns to the Office of the Australian Information Commissioner.