This policy explains what data Axiom collects, why, who it is shared with, how long it is kept, and what you can ask us to do with it. It covers the data we hold about you, and the customer records you upload.
Contents
1 / 13
What we collect
How we use it
Keeping and protecting it
Notes in the margin are a plain-language summary, written to help you find what you need. They are not part of this document and have no legal effect. Where a note and a clause differ, the clause governs.
Axiom, a sole proprietorship of Sumansh Gautam, established in Nepal, operates the Axiom platform at axiomvouch.com (the Service). This policy covers the Service, this website, and our email to you.
The policy separates two kinds of data, because our responsibilities differ for each:
Where we act as processor, your organisation's own privacy notice governs the personal data inside its records, and this policy describes what we do with it on their behalf. On request, we will enter into a data processing addendum before the first upload.
Questions, and any request about your data: privacy@axiomvouch.com.
Account data. Your email address and authentication credentials, held by our authentication provider. Passwords are stored only as salted hashes; we never see or store a password in readable form. If you enable two-factor authentication, we store the enrolment factor and hashed single-use recovery codes.
Organisation data. Your organisation's name and the profile details entered during setup, your role within it, and your notification preferences.
Customer Data you upload. Accounts-receivable exports, remittance advices, deduction and chargeback records, and supplier and trade contracts, in CSV, XLSX, or PDF form. These files routinely contain business contact details — names, email addresses, and phone numbers of people at your organisation and at your counterparties — and we treat every one of them as confidential.
Data derived from your uploads. Extracted contract terms, normalised invoice and deduction lines, findings, workpapers, dispute packages and letters, ledger and collection records.
Security and activity data. A record of significant actions in your account — who did what, and when — used for your own audit trail and for investigating misuse. Session timestamps used to enforce idle and absolute session limits. Counters used to rate-limit abusive requests.
Technical data at sign-up and password reset. When you register or request a password reset, we record the request's IP address, an approximate location derived from it by our hosting provider (city, region, country), and a short description of your browser and operating system. This exists so the email we send you can tell you where the request came from — the standard way to notice an account takeover. It is deleted once that email is sent, and in any case within about fifteen minutes.
Error and performance data. When something fails, our error-monitoring provider receives a diagnostic report: the error, where in the code it happened, and limited request context. We configure it to avoid capturing Customer Data, but a diagnostic report is by nature a snapshot of a failure, so we treat these reports as confidential and keep them for a limited period.
Messages you send us. Anything you send by email or through a form on this site, including the email address you give us if you ask to be kept informed about the product.
We do not buy personal data from data brokers, scrape it, enrich your records against third-party datasets, or infer characteristics about you.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We run no advertising network, no advertising pixel, and no third-party marketing tag on this site.
The Service is not built for payment card numbers, government identifiers, health records, or other special-category personal data, and our terms ask you not to upload them. If you send them to us anyway, we will delete them on discovery.
The Service is not directed at children and we do not knowingly collect data from anyone under 18.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account | You asked us to provide the Service | Performance of a contract |
| Process uploads and produce findings | This is the Service | Performance of a contract; for personal data inside Customer Data, on your organisation's instructions |
| Send service email — results, notifications, security alerts | You need to know what happened in your account | Performance of a contract |
| Authenticate, rate-limit, log activity, investigate misuse | Keeping the Service and your data secure | Legitimate interests in securing the Service |
| Diagnose errors and keep the Service working | A product that fails silently cannot be fixed | Legitimate interests in operating a reliable service |
| Invoice and collect fees, keep financial records | Getting paid, and keeping the records we must | Performance of a contract; legal obligation |
| Respond to you when you write to us | You wrote to us | Legitimate interests in answering correspondence |
| Send product updates you asked for | You asked to hear from us | Consent — withdrawable at any time |
| Meet legal, tax, and regulatory obligations, and establish or defend legal claims | The law requires it, or a claim requires it | Legal obligation; legitimate interests in defending claims |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object — see your rights below.
We do not use Customer Data, or any personal data in it, to train, fine-tune, or improve any machine-learning model — ours or a third party's. We do not use it to build benchmarks or datasets, and we do not use it for anyone's marketing.
The Service uses large language models to read uploaded documents and extract contract terms into a structured form. To do that, text from your documents is transmitted to a third-party model provider, processed to produce a structured result, and returned. The reconciliation arithmetic that produces a finding is performed by our own code, not by a model.
We use only providers that offer an enterprise or API tier under which, by contract:
The providers we use are named individually on our subprocessors page, with the location each processes in. That page is the authoritative list, and we update it before adding a provider — not after.
Our engine contains adapters for model providers we do not use for Customer Data and that are not on our subprocessor list. Those adapters cannot be selected in our production environment: a guard in the provider registry refuses any provider not published as a disclosed subprocessor, and it fails the run rather than falling back to one.
Model output is checked against a fixed schema before it is used, and every finding is reviewed by a person before it reaches you. There is no automated decision producing a legal or similarly significant effect on any individual, and no profiling of individuals.
We operate from Nepal, and our personnel access data from there. The infrastructure that stores and processes it — the database, file storage, and application hosting — runs in the United States. AI providers process in the regions named on our subprocessors page.
This means data is transferred internationally, including out of the country where you are located. If you are in the European Economic Area, the United Kingdom, or Switzerland, that includes transfers to countries which have not received an adequacy decision.
Where we make such a transfer, we put appropriate safeguards in place — Standard Contractual Clauses with the receiving party, or the UK Addendum where applicable — and we will provide a copy of the relevant safeguards on request to privacy@axiomvouch.com.
Most of these run as scheduled jobs rather than as a promise to act on request. They happen on their own.
| Data | Kept for |
|---|---|
| Uploaded intake documents — the files you send us | Deleted 30 days after the corresponding deliverables are delivered |
| Findings, workpapers, disputes, and ledger records | For as long as your account is open, so your history stays yours |
| Activity trail, line by line | 90 days |
| Activity trail, as monthly counts per action | 24 months, so year-on-year comparison survives the line-item purge |
| Technical data captured at sign-up or password reset | Until the security email is sent, and no more than about 15 minutes |
| Rate-limiting counters | The length of the rate-limit window |
| Error-monitoring reports | The retention period of our error-monitoring provider |
| Account, organisation, and all associated data after a deletion request | Deleted 30 days after the request, then irreversible |
| Invoices and financial records | As long as tax and accounting law requires, typically seven years |
We may keep data longer where we must to comply with a legal obligation, or to establish, exercise, or defend a legal claim. Where we do, we keep only what is needed for that purpose.
Backups are retained on a rolling schedule and overwritten in the ordinary course. Data deleted from the live system may persist in a backup until that backup rotates out.
The 30-day deletion window is a grace period, not a queue. Once it elapses and the purge runs, your organisation's data cannot be restored — not by you, and not by us. Export anything you need before requesting deletion.
Our measures include:
Axiom has not undergone any third-party security certification or attestation audit, and holds none. We hold no certification under any information-security or privacy standard. Nothing on this site is a certification claim, and we will say so plainly if that ever changes.
This policy describes measures we take. It is not a warranty: no service can be guaranteed secure, and you send data to us at your own risk. If we become aware of a breach affecting your personal data we will notify you without undue delay, and notify regulators where the law requires.
If you believe you have found a vulnerability, please report it to security@axiomvouch.com. We will not pursue good-faith security research conducted under our acceptable use terms.
Subject to the law that applies to you, you may ask us to:
To exercise any of these, email privacy@axiomvouch.com. We will respond within 30 days, and tell you if we need longer and why. We may need to verify your identity first — that verification protects you, and we ask for the least we can.
We will not discriminate against you for exercising these rights. You will not receive a worse service or a different price for asking.
If your request concerns Customer Data, we hold it on behalf of the organisation that uploaded it. We will refer your request to that organisation and support them in answering it, rather than acting on their data ourselves. Contact them directly where you can — it is faster.
Account holders can delete an entire organisation and all of its data from the account settings, without emailing anyone. That starts the 30-day window described above.
If you are in the European Economic Area, the United Kingdom, or Switzerland, the rights above are those given to you by the General Data Protection Regulation and its UK equivalent, and the legal basis for each of our purposes is set out in the table above. You may lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We would rather you came to us first, at privacy@axiomvouch.com, so we can put it right.
If you are a California resident, the California Consumer Privacy Act as amended gives you the right to know what personal information we collect and why, to access and delete it, to correct it, to opt out of its sale or of sharing for cross-context behavioural advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of them. The categories we collect, our purposes, and who we disclose to are set out in the sections above.
We have not sold or shared personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for any purpose that would require an opt-out. There is therefore no sale to opt out of; the deletion, access, and correction rights above are exercised at the same address.
Naming these laws describes which rights you have. It is not a claim to be certified, audited, or approved under any of them, and Axiom holds no such certification.
Browser privacy signals. Some browsers send a Global Privacy Control or Do Not Track signal. Because we do not sell personal information or share it for cross-context behavioural advertising, there is no such processing for the signal to switch off — we do not track you across sites in the first place.
Representatives. We are established outside the European Economic Area and the United Kingdom, and we have not appointed a representative under Article 27 of the GDPR or its UK equivalent, nor a data protection officer — neither is currently required of us given the scale and nature of our processing. We say so plainly rather than leave it to be inferred. Every request and complaint reaches us at privacy@axiomvouch.com, and we answer them ourselves. If the law comes to require an appointment, we will make one and name them here.
If another privacy law applies where you live and gives you rights we have not listed, write to us and we will honour them where the law requires it.
We may update this policy. Every version carries a version number and an effective date, and the change log at the foot of this page records what changed and when.
Where a change materially affects how we handle your data, we will give notice before it takes effect — by email to your account address, or by notice in the Service — and not rely on a silently updated date.
| Topic | Address |
|---|---|
| Privacy, data-subject requests, complaints | privacy@axiomvouch.com |
| Security reports and vulnerability disclosure | security@axiomvouch.com |
| Legal notices | legal@axiomvouch.com |
| Everything else | support@axiomvouch.com |
Postal address for privacy correspondence: Axiom, a sole proprietorship of Sumansh Gautam, Kathmandu, Nepal. The full address is published on our terms of service.
Every published version of this document, and what changed in it.
First complete published version. Replaces two placeholder notices that deferred every substantive term to an unsigned engagement letter and stated that no customer records were processed — which the shipped upload and audit pipeline had already made untrue.