Legal

Privacy policy

Last updated June 22, 2026. This policy explains how Axovern collects, uses, shares, and protects personal data when you visit our website, request a demo, partner with us, or use the Axovern platform. Enterprise customers may also have a data processing agreement (DPA) that supplements this page.

Axovern is a compliance platform. We collect only what we need to operate the service, respond to you, keep workspaces secure, and meet our legal obligations. We do not sell personal data.

Who we are

Axovern (“Axovern,” “we,” “us,” or “our”) provides compliance workspace software. For personal data described in this policy, Axovern is the data controller unless we process data solely on behalf of a customer as described in Our roles below.

Privacy and data protection inquiries: [email protected].

Our roles

Axovern acts in different roles depending on context:

  • Controller for website visitors, demo and partner form submissions, account administration for our direct relationship with you, billing contacts, and our own marketing and security operations.
  • Processor for personal data our customers upload or sync into workspaces (for example employee records, vendor contacts, or audit evidence). In those cases, the customer is the controller and Axovern processes data under the customer's instructions and any DPA in effect.

If you are an employee or contact of an Axovern customer, contact that customer's administrator first for workspace related requests. Where this policy and a customer DPA differ for workspace content, the DPA controls for that customer relationship.

Scope

This policy applies to personal data processed by Axovern when you:

  • Visit axovern.com or related marketing pages;
  • Submit a demo request, partner inquiry, or other form on our site;
  • Use the hosted platform at app.axovern.com (including workspaces, integrations, and optional Axo AI features);
  • Access the auditor portal at auditor.axovern.com when provisioned by a customer;
  • Use the Axovern desktop application with hosted or local workspaces; or
  • Communicate with us by email or during sales, support, or security reviews.

Workspace data regions

Hosted workspaces are provisioned in a data region chosen when the workspace is created:

  • United States (Oregon), default for new workspaces unless another region is selected; or
  • Canada (Montreal) for customers who require Canadian storage of workspace program data.

Primary workspace content (controls, evidence, audit logs, integration tokens, and related artifacts) is stored in the selected region. Optional features such as AI assisted tools, transactional email, and SSO may involve sub processors in other countries as listed on our Sub processors page.

Information we collect

We collect information in three broad ways: data you provide, data generated through use of the service, and data from integrations you connect.

CategoryExamplesTypical source
Account & profileName, work email, role, organization, authentication identifiers (including SSO subject IDs when enabled)You or your admin
Workspace contentControls, evidence, policies, vendor records, questionnaires, audit artifacts, and configuration you store in AxovernYou and your team
Marketing & salesDemo requests, partner program inquiries (auditor, MSP, consultancy), company name, message content, meeting preferencesForms and email
Integration signalsMetadata and configuration pulled from connected systems (for example cloud, identity, code, or endpoint providers) needed to run control tests and evidence collectionIntegrations you authorize
Usage & deviceIP address, browser type, pages viewed, timestamps, session and audit log events, error diagnosticsAutomatic when you use the site or app
CommunicationsSupport tickets, security reports, and correspondence with our teamYou

We do not intentionally collect sensitive categories of personal data (such as health or biometric data) through the marketing site. Customers choose what they upload to workspaces and are responsible for ensuring appropriate lawful basis and notices for their end users.

We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about individuals.

How we use information

We use personal data to:

  • Provide, maintain, and improve the Axovern platform and website;
  • Authenticate users, enforce access controls, and detect abuse or security incidents;
  • Run integration backed control tests, monitoring, notifications, and audit ready workflows you configure;
  • Respond to demo, partner, support, and security inquiries;
  • Send service related notices (product updates, security alerts, billing where applicable);
  • Analyze aggregated or de identified usage to improve reliability and UX; and
  • Comply with law and enforce our Terms of Service.

Where the GDPR or UK GDPR applies, we rely on the following bases depending on context:

  • Contract to provide the platform and process workspace data under our agreement with you or your organization;
  • Legitimate interests to secure the service, prevent fraud, improve the product, and respond to commercial inquiries, balanced against your rights;
  • Consent: where required for optional cookies, certain marketing, or specific integration or AI features you enable; and
  • Legal obligation: where we must retain or disclose data to comply with applicable law.

You may object to processing based on legitimate interests where applicable. Contact [email protected] to exercise that right.

How we share information

We share personal data only as needed to operate Axovern:

  • Service providers listed on our Sub processors page (for example cloud hosting, email delivery, and optional AI providers when enabled);
  • Integration vendors you connect directly: under your agreements with those vendors;
  • Professional advisers (legal, accounting) under confidentiality obligations;
  • Business transfers in connection with a merger, acquisition, or asset sale, with notice where required; and
  • Legal and safety when required by law, regulation, legal process, or to protect rights, safety, and security.

We do not sell personal data. We do not share customer workspace content with advertisers.

AI features

Axovern offers optional AI assisted features (Axo) that can help draft questionnaires, propose control updates, and investigate monitoring findings. When enabled by a customer:

  • Relevant workspace context may be sent to our AI sub processor (Anthropic) to generate responses;
  • Customer workspace content is not used to train public or general purpose AI models;
  • Customers control whether AI features are used and should review outputs before relying on them for compliance decisions; and
  • Details of AI providers appear on our Sub processors page.

Learn more on our Axo AI page. AI use is also described in our Terms of Service.

Cookies & analytics

Our website and app use cookies and similar technologies to keep sessions secure, remember preferences, and understand how pages are used.

  • Essential cookies: required for sign in, security, and form submission (including fraud prevention such as reCAPTCHA on demo and partner forms).
  • Functional cookies: optional preferences such as Axo chat listen to reply settings (browser speech). Only set if you allow functional cookies in our banner.
  • Analytics. We may use privacy conscious analytics to measure traffic and improve content. Non essential analytics cookies are only set after you consent.

You can change your choices anytime via in the site footer, or through your browser settings. Blocking essential cookies may limit sign in or form functionality. We do not respond to Do Not Track signals in a uniform way across all browsers; essential security cookies may still be set.

Marketing communications

We may send product updates, event invitations, or other commercial messages where permitted by law and your preferences. You can opt out of promotional email at any time using the unsubscribe link in a message or by contacting [email protected].

Opting out of marketing does not affect service related or security notices we must send to active accounts.

International transfers

Axovern is operated from the United States. Hosted workspaces may store primary customer data in the United States or Canada depending on the data region selected at provisioning.

If you access the service from outside those regions, or if you enable features that use sub processors in other countries, your data may also be processed in the United States or other locations where those providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses and, for UK transfers, the UK addendum) for cross border transfers. Enterprise customers may request transfer details through their DPA.

Retention

We retain personal data for as long as needed to provide the service and fulfill the purposes described in this policy:

  • Active accounts: workspace and account data is kept while your subscription or trial is active.
  • After termination. We delete or anonymize customer workspace data within a reasonable period after contract end, unless a longer period is required by law or agreed in writing. Export may be available for a limited window as described in our Terms of Service.
  • Marketing leads: retained while relevant to our relationship and applicable law, then deleted or anonymized.
  • Logs & backups: security and audit logs may be retained for a limited period for integrity, incident response, and legal compliance.

Security

We apply technical and organizational measures designed to protect personal data, including encryption in transit, access controls, MFA support, and hash chained audit logging. A summary of our practices is on our Security page. No method of transmission or storage is completely secure; report concerns to [email protected].

Incident notification

We maintain procedures to detect, investigate, and respond to security incidents. Where required by law or contract, we will notify affected customers and, where applicable, individuals or regulators within the timeframes required by applicable law.

Your privacy rights

Depending on your location, you may have the right to:

  • Access, correct, or delete personal data we hold about you;
  • Object to or restrict certain processing;
  • Port data you provided in a structured, commonly used format;
  • Withdraw consent where processing is consent based; and
  • Lodge a complaint with your local supervisory authority.

Workspace users should contact their organization's administrator first for requests related to data in a customer workspace. For requests directed to Axovern as controller, email [email protected]. We will verify your identity and respond within the timeframe required by applicable law (typically within 30 days for GDPR requests, subject to extension where permitted).

U.S. state notices

Residents of certain U.S. states (including California, Colorado, Connecticut, Utah, and Virginia) may have additional rights to know, delete, correct, and opt out of certain processing.

Categories collected (last 12 months). In the preceding 12 months we may have collected identifiers (name, email), commercial information (subscription and demo interest), internet or network activity (usage logs), and professional information (job title, company) as described in Information we collect.

Sale and sharing. Axovern does not sell personal data and does not share it for cross context behavioral advertising as defined by those laws.

Exercising rights. Contact [email protected]. We will not discriminate against you for exercising privacy rights. Authorized agents may submit requests where permitted by law with appropriate verification.

Children

Axovern is a business service not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes affecting customers will be communicated through the app, email, or your account team where appropriate.

Contact

Questions about this policy or our privacy practices:

Related documents: Terms of Service · Security · Sub processors · Trust Center

Questions about privacy?

We respond to data subject requests and security questionnaires promptly. Reach out, or see the platform in action.