AXION PRIVACY POLICY
Version 2.4 • Effective date: 10 September 2026
Contents
1. Introduction, Controller and Scope
This Privacy Policy explains what personal data may be processed in connection with the Axion Service, the purposes and legal bases of processing, possible recipients and technology providers, retention, and the rights of data subjects. It provides information in particular under Regulation (EU) 2016/679 ("GDPR").
1.1. Controller
Leiter Miklós Patrik, sole proprietor; registered office: 4090 Polgár, Hunyadi utca 3., Hungary; registration number: 62674771; tax number: 92281868-1-29; email: support@axionaiapp.com; website: axionaiapp.com ("Axion", "Controller" or "Service Provider").
1.2. What does this Policy cover?
This Policy applies to processing carried out by Axion as controller for its own purposes, including Account administration and authentication, operation of the Service, Chat, Inputs and Outputs, Projects and Artifacts, AI orchestration, file and document processing, research and web search, Forge/workflow/sandbox execution, Connected Services and Actions, Coin accounting, payments, support, security, analytics and legal administration.
This Policy does not replace a separate Data Processing Agreement ("DPA") that applies where Axion processes Customer Data on behalf of a User as processor.
1.3. Related documents
Related documents include the Terms and Conditions, Cookie Policy, Acceptable Use Policy, Security Overview and Provenance information. Reading this Policy does not itself constitute general consent.
2. Privacy Roles: Axion as Controller and Processor
2.1. Axion as controller
Axion acts as controller where it determines the purposes and essential means of processing for operation of its own Service. This may include Account administration, authentication, service delivery, Coin accounting, support, security logging, abuse prevention, analytics, invoicing administration and legal compliance.
2.2. Axion as processor
In some cases Axion may process personal data on behalf of a User and according to that User's documented instructions. This may occur, in particular, where a User processes personal data of third parties for the User's own purposes through an application, workflow, automation or other system created with Axion or operated using Axion infrastructure.
Where the User determines the purposes and essential means of processing, the User will generally be the controller and Axion will act as processor for the relevant Customer Data. Such processing is subject to a DPA or other data-processing terms compliant with Article 28 GDPR.
2.3. User-operated applications
The fact that an application or system was created with Axion or Forge does not by itself make Axion the controller of the application's end-user data. Where the User determines what personal data the application processes, from whom, for what purpose and under which essential conditions, the User will generally act as controller for that processing.
As controller, the User may be responsible in particular for an appropriate legal basis, privacy notice, consent mechanism where required, retention rules, data-subject rights, access controls and any required data protection impact assessment. Where Axion processes Customer Data from such an application solely on the User's behalf and documented instructions, Axion acts as processor under Article 28 GDPR and the applicable DPA. Separately, Axion may remain controller for its own Account, security, billing, abuse-prevention, legal-compliance and other independent service data.
3. Categories and Sources of Personal Data
The actual data processed depends on the features used; not every category applies to every User.
Certain information may be contractually or legally required to create an Account, authenticate a User, process a payment or provide a requested feature. If required information is not available, Axion may be unable to provide the relevant Account, transaction or feature. Omitting optional information or an optional feature does not by itself prevent use of independent parts of the Service.
- Account and identity data: name or display name, email address, profile data, internal user/account ID, settings, status, and OAuth or login metadata.
- User Content: prompts, chats, instructions, files, documents, images, code, Projects, Artifacts, Outputs and associated metadata.
- AI and Execution data: task description, model and routing metadata, tool or agent actions, intermediate results, research sources, execution status, error and performance data.
- Connected Services: provider account ID, authorised scopes, token/authorisation data, and email, file, calendar or other integration data retrieved or transmitted at the User's request.
- Technical and security data: IP address, timestamps, session/request IDs, device and browser information, system and network metadata, authentication, audit, abuse and security events.
- Coin, purchase and invoicing data: Coin balance, Execution accounting, purchases, amount, currency, transaction ID, payment status, refunds, invoicing name, address and tax information where required.
- Support and communications: support tickets, emails, messages, attachments, complaints and diagnostic information.
- Analytics and consent data: session and feature-usage events, device metadata, and consent or preference status according to applicable settings.
Data may come directly from the User, from the device used by the User, from a service connected by the User, from an authentication or payment provider, or may be generated automatically through operation of Axion. Where Axion obtains personal data indirectly - for example from content uploaded by a User, a Connected Service or data supplied by another person - the source may be the User, the connected external service, a user of that service or another person making the data available. Article 14 GDPR transparency rules and exceptions apply to such processing.
4. Purposes and Legal Bases
4.1. Performance of a contract – Article 6(1)(b) GDPR
Axion may process data to perform the contract, including for Account creation and authentication; Chat, AI, research, document, coding, Forge, workflow, Project and Artifact features; Connected Services and User-requested Actions; Coin balance and Execution accounting; and support related to the contract.
4.2. Legal obligation – Article 6(1)(c) GDPR
Data may be processed to comply with legal obligations, including invoicing, tax, accounting, consumer-protection, regulatory and legal requests, and records that EU or Hungarian law requires to be retained.
4.3. Legitimate interests – Article 6(1)(f) GDPR
Legitimate interests may support processing necessary to protect the Platform, Accounts and Users; prevent fraud, spam, abuse and unauthorised access; troubleshoot errors; conduct audits and incident response; establish, exercise or defend legal claims; and perform limited operational analysis necessary for the Service. Axion considers necessity, proportionality and data-subject rights when relying on legitimate interests.
4.4. Consent – Article 6(1)(a) GDPR
Where applicable privacy or electronic-communications law requires consent - for example for certain optional analytics technologies or marketing - processing takes place on the basis of appropriate consent. Consent can be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
4.5. Special-category data
Axion does not generally require special-category personal data to create an Account. User Content may nevertheless contain health, biometric, religious, political or other special-category data. Where a User processes such data for the User's own purposes through Axion, the User is responsible for ensuring an applicable Article 9 GDPR condition and other required safeguards. Axion processes such data for its own controller purposes only where an appropriate legal basis, Article 9 condition where required, and necessity exist.
5. AI Models, Orchestration and User Content
Axion may use multiple AI models and technology providers, including OpenAI, Anthropic and Google Gemini. The orchestration system may select a model or provider based on the capabilities required for the task, technical availability, security and data-protection considerations.
Only information relevant to performing the task may be sent to a provider, such as the necessary Input, context, document excerpt, tool result, Connected Service data or intermediate processing data. More than one provider may participate in a complex task, but this does not mean that all data is automatically sent to every provider.
Provider-side retention, logging, abuse monitoring and processing location may vary according to the relevant production service, contractual terms and technical configuration. Axion seeks to use appropriate business/API arrangements and data minimisation.
This Policy does not provide general authorisation for technology providers to use User Content transmitted through Axion for their own general model training. Any such use is determined by the specific service arrangement and contractual terms used by Axion.
6. Google Login and Connected Google Services
Registration or sign-in with a Google account is separate from connecting Gmail, Google Drive, Google Calendar or another Google service to Axion. For login, Axion may receive the Google account information necessary to create, identify and authenticate the Axion Account.
A Connected Google Service requires separate authorisation and the OAuth scopes necessary for the relevant feature. Axion may retrieve or transmit data only within the authorised scope and for the task requested by the User.
Axion does not sell Google API User Data, use it for advertising or retargeting, or disclose it to data brokers. Axion handles Google API User Data in accordance with the Google API Services User Data Policy and, where applicable, the Limited Use requirements.
Where a User requests an AI task based on Google data, the relevant data necessary to perform that task may be transmitted to the AI or other technology provider actually participating in the task. Revoking the Google connection stops further access based on that authorisation, but does not necessarily delete Output or Artifacts previously created at the User's request.
7. Processors, Subprocessors and Other Recipients
Axion may use external technology and business providers. The principal provider categories may include Microsoft Azure (hosting, infrastructure and databases), OpenAI, Anthropic and Google (AI), Google (OAuth, supported integrations and certain document-processing functions), Brave (web search), E2B (sandbox/code execution), Cloudinary (media and file handling), PostHog (analytics), Stripe (payments) and Számlázz.hu / KBOSS.hu Kft. (invoicing).
Not every provider receives every category of data. Depending on the particular processing, a provider may act as a processor, subprocessor or, for certain separate activities, an independent controller. The same technical provider may, for example, act as processor in Axion's own controller processing and as Axion's subprocessor in User-controlled processing.
Where Axion acts as processor, subprocessors are engaged in accordance with Article 28 GDPR, the applicable DPA and contractual terms. Current provider or subprocessor information may also be published in a separate public list.
8. International Data Transfers
Axion may use technology providers operating inside and outside the EU/EEA. As a result, some personal data may be transferred outside the EEA or accessed from outside the EEA.
Where this occurs, Axion applies an appropriate transfer mechanism under Chapter V GDPR. This may include an adequacy decision of the European Commission or, where required, Standard Contractual Clauses (SCCs) together with appropriate contractual, technical and organisational supplementary measures.
The actual processing location may vary by provider, service region and feature. Data subjects may request information about applicable safeguards at support@axionaiapp.com, subject to the conditions of the GDPR.
9. Retention and Deletion
Axion does not retain personal data indefinitely. Retention depends on the data type, the existence of the Account and relevant feature, User deletion actions, legal obligations, security needs and provider-side technical cycles.
- Account and profile: generally for the lifetime of the Account and until the deletion process is completed, except for legal or security data that must be retained longer.
- Chats, Projects, Artifacts, files and other deletable User Content: after User deletion, removal from the active environment followed by the technical deletion process; the current system target is completion within a maximum of 30 days, except where legal or security retention applies.
- Account deletion: data not requiring further retention is deleted or anonymised from current active systems with a target completion time of no more than 30 days.
- Backups and disaster recovery: data may remain for a limited period, is not restored to ordinary business use, and is overwritten or deleted according to the backup lifecycle.
- Security and audit logs: for a proportionate period necessary for abuse prevention, incident response, troubleshooting, security evidence and legal claims. The specific period depends on data type, risk and the current internal retention policy; Axion does not retain these logs indefinitely.
- Support and complaint data: for a proportionate period necessary to close the matter, meet contractual or consumer-protection obligations, and manage legal claims. The specific period depends on the nature of the matter and applicable mandatory retention requirements.
- Invoice, tax and accounting data: accounting records and the information necessary to support them are generally retained for at least 8 years, or longer where applicable tax or accounting law requires.
- Provider-side data: according to the relevant provider's contractual and technical retention rules; Axion uses available controls to seek to limit retention beyond what is necessary.
Deletion does not apply to data that must be retained because of a legal obligation or that is necessary for the establishment, exercise or defence of legal claims. In such cases, use of the data may be restricted to the relevant purpose.
10. Security and Personal Data Breaches
Axion applies technical and organisational measures appropriate to the risk. These may include access controls, encrypted transmission, credential and token protection, logging and monitoring, workspace/project/artifact separation, sandbox isolation, input and file checks, backups, incident response, and web and application security controls.
When designing new or materially modified features and systems involving personal data, Axion takes account of the principles of Data Protection by Design and by Default and, according to risk, seeks to apply data minimisation, access restriction and appropriate privacy-protective default settings.
Internal access is limited to what is necessary for the relevant role, such as support, troubleshooting, security incidents, abuse investigations or legal obligations. No internet-connected or AI system can be guaranteed absolutely secure.
Where Axion acts as controller and becomes aware of a personal data breach for which the GDPR requires notification to a supervisory authority or communication to data subjects, Axion acts in accordance with the applicable conditions and deadlines.
11. Cookies, Analytics and Marketing
Axion may use strictly necessary cookies or similar technologies for authentication, sessions, security and privacy preferences. PostHog may be used as an analytics provider. Where applicable law requires consent, optional analytics technology is activated only after appropriate consent.
The Cookie Policy describes relevant categories, purposes, retention and consent management in more detail. Marketing communications are sent only in accordance with applicable privacy and electronic-communications rules.
12. Data-Subject Rights
Subject to the conditions of the GDPR, data subjects have rights of access, rectification, erasure and restriction of processing; where applicable, data portability; and a right to object where processing is based on legitimate interests or a public-interest basis. Consent may be withdrawn at any time.
Requests may be submitted to support@axionaiapp.com. Axion responds without undue delay and generally within one month. For complex or numerous requests, the period may be extended by a further two months under the conditions of the GDPR.
Requests are generally free of charge. Where requests are manifestly unfounded or excessive, particularly because of repetition, Axion may charge a fee permitted by the GDPR or refuse to act. Where there are reasonable doubts about the requester's identity, Axion may request proportionate additional identification.
Where Axion did not obtain personal data directly from the data subject - for example through a Connected Service or User Content - the transparency obligations and exceptions in Article 14 GDPR apply.
13. Automated Processing and AI
Axion uses AI models, routing and automated technical processes to generate results requested by Users and operate the Service. Model selection, tool routing or generation of an AI Output does not necessarily constitute a decision based solely on automated processing that produces legal effects or similarly significantly affects a person within the meaning of Article 22 GDPR.
As a general-purpose system, Axion is not intended for the Service Provider to make solely automated decisions about the User that produce legal or similarly significant effects. If Axion were to introduce such processing as controller in the future, it would first implement the necessary legal basis, transparency and safeguards.
14. User-Controlled Processing and DPA
Where Axion acts as processor for Customer Data, it processes the data on the controller User's documented instructions, applies appropriate confidentiality and security measures, and engages subprocessors in accordance with the DPA.
Taking account of the nature of processing and the information available to it, Axion may provide appropriate assistance to the controller with data-subject rights, personal data breaches, security obligations, data protection impact assessments and, where required, prior consultation with a supervisory authority, to the extent required by the GDPR and the DPA.
On termination of processor services or on an appropriate instruction from the controller, Axion deletes or returns Customer Data in accordance with the DPA and applicable law, unless EU or Member State law requires further retention. Final removal from backups may occur with a controlled delay while the data remains isolated and is not restored to ordinary processing.
Where Customer Data is processed outside the EEA, Axion applies appropriate transfer safeguards under the DPA and Chapter V GDPR.
15. Minors, Third-Party Data and User Responsibility
Axion is intended for persons aged 18 or over. Axion does not ask persons under 18 to create an Account. Content uploaded by a User or processed through a Connected Service may nevertheless contain personal data relating to minors or other third parties.
Where a User supplies another person's data, the User must, within the User's own controller or other legal responsibilities, ensure that processing of that data through Axion is lawful and provide any required transparency, legal basis or consent.
16. Complaints, Contact and Changes
Privacy questions and data-subject requests may be sent to support@axionaiapp.com. A data subject has the right to lodge a complaint with the competent supervisory authority and to seek a judicial remedy.
In Hungary, the supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11., Hungary; postal address: 1363 Budapest, Pf. 9.; email: ugyfelszolgalat@naih.hu; telephone: +36 (1) 391-1400; website: naih.hu.
Axion may update this Policy where processing, the Service, technology providers or applicable law changes. Material changes will be communicated appropriately. To the extent permitted by mandatory law, the Hungarian-language version prevails over translations.
Current public version: https://axionaiapp.com/en/legal/privacy