Skip to main content

Privacy Policy

Last updated:

About This Policy

aXai ("we", "our", "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data.

This policy complies with:

  • +Australian Privacy Principles (APP) under the Privacy Act 1988 (Cth)
  • +General Data Protection Regulation (GDPR) (EU) 2016/679
  • +Web Content Accessibility Guidelines (WCAG) 2.2 Level AA

1. Information We Collect

1.1 Information You Provide

  • +Account Information: Name, email address, password (encrypted)
  • +Contact Information: Details you provide when contacting us
  • +Project Information: Details about your projects when engaging our services

1.2 Automatically Collected Information

  • +Usage Data: Pages visited, features used, time spent
  • +Device Information: Browser type, operating system, device type
  • +Log Data: IP address (anonymized), access times
  • +Cookies: Session cookies, preference cookies (with consent)

2. How We Use Your Information

We use your information for the following purposes:

  • +Service Provision: Delivering our consulting and development services
  • +Communication: Responding to inquiries, sending project updates
  • +Improvement: Analyzing usage to improve our services
  • +Security: Protecting against fraud and security incidents
  • +Compliance: Meeting legal obligations

3. Data Sharing & Disclosure

3.1 Third-Party Service Providers

We share data with trusted third parties who assist in operating our service:

  • +Cloud Infrastructure: Google Cloud Platform (hosting, storage)
  • +Analytics: Privacy-friendly analytics (anonymized data only)
  • +AI assistants (the Axel avatar and aXread): the questions you type or speak are sent to a third-party AI provider to generate the reply, and are not used to train that provider's models.
  • +Bot protection (Cloudflare Turnstile) on the avatar.

The AI provider and the bot-protection service may process this data outside Australia; section 8 sets out the safeguards that apply to those transfers.

3.2 Legal Requirements

We may disclose information if required by law or in response to:

  • +Valid legal process (subpoena, court order)
  • +Protection of our rights, property, or safety
  • +Emergency situations involving danger to persons

4. Your Rights

Under Australian Privacy Principles and GDPR, you have the following rights:

Access & Portability

Request a copy of all your personal data in a portable format.

Rectification

Update or correct your personal information at any time.

Erasure

Request deletion of your data ("right to be forgotten").

Consent Withdrawal

Withdraw consent for data processing at any time.

Lodge a Complaint

If you believe we have breached your privacy rights:

  • +Australia: Office of the Australian Information Commissioner (OAIC) - www.oaic.gov.au
  • +EU/EEA: Your local Data Protection Authority

5. Data Security

We implement industry-standard security measures:

  • +Encryption: HTTPS/TLS for data in transit, encryption at rest
  • +Access Controls: Role-based access, secure authentication
  • +Monitoring: Security monitoring and intrusion detection
  • +Data Minimization: We collect only necessary data

6. Data Retention

We retain your data for the following periods:

  • +Contact Data: Duration of business relationship + 7 years
  • +Project Data: Duration of engagement + 7 years (legal compliance)
  • +Analytics: 26 months (anonymized)

7. Cookies & Tracking

Essential Cookies (No Consent Required)

  • +Session Cookies: Authentication, security
  • +CSRF Tokens: Security protection

Functional Cookies (With Consent)

  • +Preference Cookies: Theme settings, language
  • +Analytics Cookies: Usage analytics (anonymized)

8. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards:

  • +Standard Contractual Clauses (SCCs) for EU data transfers
  • +Data Processing Agreements (DPAs) with all processors
  • +Compliance with cross-border data transfer laws

9. Changes to This Policy

We may update this Privacy Policy from time to time. We tell you about material changes by:

  • +Posting the updated policy with a new "Last updated" date
  • +Sending email notification for significant changes
  • +Displaying a prominent notice on our site

10. Contact Us

If you have questions about this Privacy Policy or our data practices:

Email: privacy@axai.com.au

We will respond to your inquiry within 30 days.