Axovern is a compliance platform. We collect only what we need to operate the service, respond to you, keep workspaces secure, and meet our legal obligations. We do not sell personal data.
Who we are
Axovern (“Axovern,” “we,” “us,” or “our”) provides compliance workspace software. For personal data described in this policy, Axovern is the data controller unless we process data solely on behalf of a customer as described in Our roles below.
Privacy and data protection inquiries: [email protected].
Our roles
Axovern acts in different roles depending on context:
- Controller for website visitors, demo and partner form submissions, account administration for our direct relationship with you, billing contacts, and our own marketing and security operations.
- Processor for personal data our customers upload or sync into workspaces (for example employee records, vendor contacts, or audit evidence). In those cases, the customer is the controller and Axovern processes data under the customer's instructions and any DPA in effect.
If you are an employee or contact of an Axovern customer, contact that customer's administrator first for workspace related requests. Where this policy and a customer DPA differ for workspace content, the DPA controls for that customer relationship.
Scope
This policy applies to personal data processed by Axovern when you:
- Visit axovern.com or related marketing pages;
- Submit a demo request, partner inquiry, or other form on our site;
- Use the hosted platform at app.axovern.com (including workspaces, integrations, and optional Axo AI features);
- Access the auditor portal at auditor.axovern.com when provisioned by a customer;
- Use the Axovern desktop application with hosted or local workspaces; or
- Communicate with us by email or during sales, support, or security reviews.
Workspace data regions
Hosted workspaces are provisioned in a data region chosen when the workspace is created:
- United States (Oregon), default for new workspaces unless another region is selected; or
- Canada (Montreal) for customers who require Canadian storage of workspace program data.
Primary workspace content (controls, evidence, audit logs, integration tokens, and related artifacts) is stored in the selected region. Optional features such as AI assisted tools, transactional email, and SSO may involve sub processors in other countries as listed on our Sub processors page.
Information we collect
We collect information in three broad ways: data you provide, data generated through use of the service, and data from integrations you connect.
| Category | Examples | Typical source |
|---|---|---|
| Account & profile | Name, work email, role, organization, authentication identifiers (including SSO subject IDs when enabled) | You or your admin |
| Workspace content | Controls, evidence, policies, vendor records, questionnaires, audit artifacts, and configuration you store in Axovern | You and your team |
| Marketing & sales | Demo requests, partner program inquiries (auditor, MSP, consultancy), company name, message content, meeting preferences | Forms and email |
| Integration signals | Metadata and configuration pulled from connected systems (for example cloud, identity, code, or endpoint providers) needed to run control tests and evidence collection | Integrations you authorize |
| Usage & device | IP address, browser type, pages viewed, timestamps, session and audit log events, error diagnostics | Automatic when you use the site or app |
| Communications | Support tickets, security reports, and correspondence with our team | You |
We do not intentionally collect sensitive categories of personal data (such as health or biometric data) through the marketing site. Customers choose what they upload to workspaces and are responsible for ensuring appropriate lawful basis and notices for their end users.
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about individuals.
How we use information
We use personal data to:
- Provide, maintain, and improve the Axovern platform and website;
- Authenticate users, enforce access controls, and detect abuse or security incidents;
- Run integration backed control tests, monitoring, notifications, and audit ready workflows you configure;
- Respond to demo, partner, support, and security inquiries;
- Send service related notices (product updates, security alerts, billing where applicable);
- Analyze aggregated or de identified usage to improve reliability and UX; and
- Comply with law and enforce our Terms of Service.
Legal bases (EEA & UK)
Where the GDPR or UK GDPR applies, we rely on the following bases depending on context:
- Contract to provide the platform and process workspace data under our agreement with you or your organization;
- Legitimate interests to secure the service, prevent fraud, improve the product, and respond to commercial inquiries, balanced against your rights;
- Consent: where required for optional cookies, certain marketing, or specific integration or AI features you enable; and
- Legal obligation: where we must retain or disclose data to comply with applicable law.
You may object to processing based on legitimate interests where applicable. Contact [email protected] to exercise that right.
How we share information
We share personal data only as needed to operate Axovern:
- Service providers listed on our Sub processors page (for example cloud hosting, email delivery, and optional AI providers when enabled);
- Integration vendors you connect directly: under your agreements with those vendors;
- Professional advisers (legal, accounting) under confidentiality obligations;
- Business transfers in connection with a merger, acquisition, or asset sale, with notice where required; and
- Legal and safety when required by law, regulation, legal process, or to protect rights, safety, and security.
We do not sell personal data. We do not share customer workspace content with advertisers.
AI features
Axovern offers optional AI assisted features (Axo) that can help draft questionnaires, propose control updates, and investigate monitoring findings. When enabled by a customer:
- Relevant workspace context may be sent to our AI sub processor (Anthropic) to generate responses;
- Customer workspace content is not used to train public or general purpose AI models;
- Customers control whether AI features are used and should review outputs before relying on them for compliance decisions; and
- Details of AI providers appear on our Sub processors page.
Learn more on our Axo AI page. AI use is also described in our Terms of Service.
Cookies & analytics
Our website and app use cookies and similar technologies to keep sessions secure, remember preferences, and understand how pages are used.
- Essential cookies: required for sign in, security, and form submission (including fraud prevention such as reCAPTCHA on demo and partner forms).
- Functional cookies: optional preferences such as Axo chat listen to reply settings (browser speech). Only set if you allow functional cookies in our banner.
- Analytics. We may use privacy conscious analytics to measure traffic and improve content. Non essential analytics cookies are only set after you consent.
You can change your choices anytime via in the site footer, or through your browser settings. Blocking essential cookies may limit sign in or form functionality. We do not respond to Do Not Track signals in a uniform way across all browsers; essential security cookies may still be set.
Marketing communications
We may send product updates, event invitations, or other commercial messages where permitted by law and your preferences. You can opt out of promotional email at any time using the unsubscribe link in a message or by contacting [email protected].
Opting out of marketing does not affect service related or security notices we must send to active accounts.
International transfers
Axovern is operated from the United States. Hosted workspaces may store primary customer data in the United States or Canada depending on the data region selected at provisioning.
If you access the service from outside those regions, or if you enable features that use sub processors in other countries, your data may also be processed in the United States or other locations where those providers operate. Where required, we use appropriate safeguards (such as Standard Contractual Clauses and, for UK transfers, the UK addendum) for cross border transfers. Enterprise customers may request transfer details through their DPA.
Retention
We retain personal data for as long as needed to provide the service and fulfill the purposes described in this policy:
- Active accounts: workspace and account data is kept while your subscription or trial is active.
- After termination. We delete or anonymize customer workspace data within a reasonable period after contract end, unless a longer period is required by law or agreed in writing. Export may be available for a limited window as described in our Terms of Service.
- Marketing leads: retained while relevant to our relationship and applicable law, then deleted or anonymized.
- Logs & backups: security and audit logs may be retained for a limited period for integrity, incident response, and legal compliance.
Security
We apply technical and organizational measures designed to protect personal data, including encryption in transit, access controls, MFA support, and hash chained audit logging. A summary of our practices is on our Security page. No method of transmission or storage is completely secure; report concerns to [email protected].
Incident notification
We maintain procedures to detect, investigate, and respond to security incidents. Where required by law or contract, we will notify affected customers and, where applicable, individuals or regulators within the timeframes required by applicable law.
Your privacy rights
Depending on your location, you may have the right to:
- Access, correct, or delete personal data we hold about you;
- Object to or restrict certain processing;
- Port data you provided in a structured, commonly used format;
- Withdraw consent where processing is consent based; and
- Lodge a complaint with your local supervisory authority.
Workspace users should contact their organization's administrator first for requests related to data in a customer workspace. For requests directed to Axovern as controller, email [email protected]. We will verify your identity and respond within the timeframe required by applicable law (typically within 30 days for GDPR requests, subject to extension where permitted).
U.S. state notices
Residents of certain U.S. states (including California, Colorado, Connecticut, Utah, and Virginia) may have additional rights to know, delete, correct, and opt out of certain processing.
Categories collected (last 12 months). In the preceding 12 months we may have collected identifiers (name, email), commercial information (subscription and demo interest), internet or network activity (usage logs), and professional information (job title, company) as described in Information we collect.
Sale and sharing. Axovern does not sell personal data and does not share it for cross context behavioral advertising as defined by those laws.
Exercising rights. Contact [email protected]. We will not discriminate against you for exercising privacy rights. Authorized agents may submit requests where permitted by law with appropriate verification.
Children
Axovern is a business service not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes affecting customers will be communicated through the app, email, or your account team where appropriate.
Contact
Questions about this policy or our privacy practices:
- Privacy & data requests: [email protected]
- Security reports: [email protected]
- Legal notices: [email protected]
- General inquiries: [email protected]
Related documents: Terms of Service · Security · Sub processors · Trust Center
Questions about privacy?
We respond to data subject requests and security questionnaires promptly. Reach out, or see the platform in action.