Privacy policy
How the axelion.ai website and the Axelion service process personal data under the EU General Data Protection Regulation (GDPR).
Last updated: 14 September 2026
In short.
- The operator of axelion.ai is responsible for the personal data described in this policy.
- We use personal data to run the website, answer enquiries, provide the Service and meet legal obligations.
- We use analytics cookies; you can switch them off at any time by clicking "Decline" (section 5). We do not use advertising cookies.
- We do not sell personal data.
- When businesses use Axelion to talk to their customers, those businesses decide how that data is used (section 9).
You can exercise your rights, including your right to object, as described in section 15.
1. Who is responsible
1.1 The controller within the meaning of Article 4(7) GDPR for the processing described in this Privacy Policy is the operator of the website at https://axelion.ai and provider of the Axelion service ("Axelion", "we", "us", "our"). Our contact details are set out in section 15.
1.2 We have not appointed a data protection officer, as we are not required to do so under Article 37 GDPR. All data protection enquiries are handled as set out in section 15.
1.3 This Privacy Policy applies to visitors of axelion.ai, to people who request a demo or contact us, and to representatives, employees and users of our business customers, prospects, partners, suppliers and investors. It does not apply to personal data we process on behalf of our customers as a processor, which is described in section 9.
2. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Technical and log data | IP address, date and time of the request, requested URL, referrer, browser and operating system, device type, language, error and security logs | Automatically from your device when you visit the website |
| Cookie choice record | Your choice regarding analytics cookies and the date of that choice | Stored on your device when you click "OK" or "Decline" |
| Statistics data | Aggregated counts of pages requested, referrers, browser types and countries | Derived from our server request logs |
| Analytics data | Online identifiers stored in analytics cookies, pages viewed, interactions, session information, approximate location derived from the IP address, device and browser information | Analytics cookies on your device, unless you click "Decline" |
| Enquiry data | Name, business email address, company, preferred channel, monthly lead volume, message and any other information you provide | You, through our forms or by email |
| Account data | Name, business email address, role, company, login credentials, settings and preferences | You or the business you work for |
| Billing data | Company name, billing address, VAT number, invoices and payment history. Card details are processed by our payment provider and are not stored by us | You, the business you work for, our payment provider |
| Service usage and security data | Log-ins, IP addresses, actions performed in the Service, feature usage, device information and audit logs | Automatically when you use the Service |
| Communications | Emails, call and meeting notes, support requests, feedback and survey responses | You |
3. Purposes, legal bases and retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| (a) Providing, securing and troubleshooting the website | Technical and log data | Art. 6(1)(f) GDPR — our legitimate interest in operating a secure, available and functioning website | Up to 30 days; longer where needed to investigate a specific security incident |
| (b) Recording your cookie choice | Cookie choice record | Art. 6(1)(f) GDPR — our legitimate interest in respecting your choice | 6 months, after which we ask again |
| (c) Website statistics based on server logs | Technical and log data, statistics data | Art. 6(1)(f) GDPR — our legitimate interest in understanding how the website is used | Aggregated statistics only |
| (d) Website analytics with cookies | Analytics data | Art. 6(1)(f) GDPR — our legitimate interest in understanding how the website is used; you can object at any time by clicking "Decline" | Cookies up to 13 months; analytics data up to 14 months |
| (e) Responding to enquiries and demo requests, and pre-contractual discussions | Enquiry data, communications | Art. 6(1)(b) GDPR — steps taken at your request before entering into a contract; Art. 6(1)(f) GDPR — our legitimate interest in communicating with business customers and prospects | 3 years after our last contact with you |
| (f) Providing the Service, managing accounts and providing support | Account data, service usage and security data, communications | Art. 6(1)(b) GDPR — performance of a contract with you; where the contract is with the business you work for, Art. 6(1)(f) GDPR — our legitimate interest in performing that contract | For the term of the contract and the data retrieval period; then deleted or anonymised, unless needed for purposes (g), (j) or (k) |
| (g) Invoicing, accounting and tax | Billing data | Art. 6(1)(c) GDPR — legal obligations under accounting and tax laws | 10 years after the end of the financial year, or longer where required by law |
| (h) Business-to-business marketing, such as product news and invitations | Name, business email address, company, interaction history | Art. 6(1)(f) GDPR — our legitimate interest in direct marketing (Recital 47 GDPR), or your consent where required by electronic marketing rules. You can unsubscribe at any time | Until you object or unsubscribe, and no longer than 3 years after the last interaction; we keep a suppression record to respect your opt-out |
| (i) Improving the Service, including creating anonymised and aggregated statistics | Service usage data | Art. 6(1)(f) GDPR — our legitimate interest in developing and improving our products | Personal data is anonymised or deleted; anonymised data is no longer personal data |
| (j) Preventing fraud and abuse, enforcing our Terms, complying with sanctions, and establishing, exercising or defending legal claims | All categories, as necessary | Art. 6(1)(f) GDPR — our legitimate interest in protecting our business and rights; Art. 6(1)(c) GDPR where required by law | For the applicable limitation period (generally up to 10 years) or until proceedings are finally concluded |
| (k) Complying with legal obligations and requests from public authorities | All categories, as necessary | Art. 6(1)(c) GDPR — legal obligation | As required by law |
| (l) Corporate transactions, such as financing, merger or acquisition | Relevant categories, in aggregated or pseudonymised form where possible | Art. 6(1)(f) GDPR — our legitimate interest in developing our business | For the duration of the transaction and as required afterwards |
Where we rely on legitimate interests, we have balanced those interests against your interests, rights and freedoms. You can request information about this balancing test (section 15).
4. Is providing data required?
Technical data is necessary to deliver the website to your device. In our forms, fields marked with an asterisk are required to handle your request; without them we cannot respond. For customers, account and billing data are required to conclude and perform the contract and to comply with our legal obligations.
5. Cookies and similar technologies
We use strictly necessary technologies and analytics cookies. We do not use advertising cookies.
| Technology | Purpose | Category | Duration |
|---|---|---|---|
| Cookie choice record (local storage) | Stores your choice regarding analytics cookies | Strictly necessary | 6 months |
| Analytics cookies | Distinguish visitors and sessions to produce statistics on how the website is used | Analytics — until you click "Decline" | Up to 13 months |
| Security cookies (set only when triggered) | Distinguish humans from bots and protect the website against attacks | Strictly necessary | Up to 30 minutes |
You can switch off analytics cookies at any time by clicking "Decline" in the bar at the bottom of the page or change my cookie choice. We then delete the analytics cookies from your browser. For visitors who have declined, website statistics are derived only from our server request logs. You can also block or delete cookies in your browser settings.
The fonts used on this website are hosted on our own infrastructure; no request is made to third-party font services.
6. Recipients
We do not sell personal data and do not share it for cross-context behavioural advertising. We disclose personal data only to the following categories of recipients, and only to the extent necessary:
- Hosting, content delivery and security providers, including for website statistics, acting as our processors.
- Web analytics providers, acting as our processors.
- Form and email delivery providers, which store form submissions and forward them to our mailbox, acting as our processors.
- Other service providers acting as our processors: email and productivity, customer relationship management, support, cloud infrastructure and AI model providers, bound by data processing agreements and our instructions.
- Payment service providers, which may act as independent controllers for fraud prevention and regulatory purposes.
- Professional advisers and auditors, such as lawyers, accountants and tax advisers, bound by confidentiality.
- Public authorities, courts and law enforcement bodies, where required by law or necessary to establish, exercise or defend legal claims.
- Potential acquirers, investors and their advisers, in connection with an actual or proposed financing, merger, acquisition or sale of assets, subject to confidentiality.
- Connected Platforms that our customers choose to connect, such as WhatsApp, Telegram, email services or CRMs, at the customer's direction.
An up-to-date list of our processors is available on request.
7. International transfers
Some of our service providers, such as hosting, security, web analytics, form delivery and AI model providers, may process personal data outside the European Economic Area, including in the United States and India. We transfer personal data outside the EEA only in compliance with Chapter V GDPR, in particular on the basis of (a) an adequacy decision of the European Commission, including the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) for certified recipients, or (b) the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with supplementary measures where necessary. You can request a copy of the relevant safeguards (section 15).
8. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Automated security tools may temporarily block traffic that appears malicious; if you are affected, you may contact us to request human review.
9. Data we process for our customers
Businesses use Axelion to communicate with their own customers and prospects ("End Users"), for example through WhatsApp, Telegram or email. When we process End Users' messages, contact details, order and quote information for a business customer, that business is the controller and we act as its processor under Article 28 GDPR and our Data Processing Addendum.
The business is responsible for having a legal basis, for informing End Users — including that they are interacting with an AI system — and for handling End User rights requests. If you are an End User, please contact the business you communicated with. If you send a request to us, we will forward it to that business where we can identify it, and will not respond to it ourselves unless the business instructs us to or the law requires it.
Where the Service improves a customer's AI agent based on that customer's conversations, this is done on the customer's behalf and only for that customer. We do not use End Users' personal data to train AI models for other customers or for general purposes; we may use data that has been anonymised so that it no longer identifies any person.
10. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it (Article 15);
- have inaccurate personal data rectified (Article 16);
- have your personal data erased (Article 17);
- restrict the processing of your personal data (Article 18);
- receive your personal data in a portable format (Article 20);
- object to processing (Article 21 — see below);
- withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)); and
- lodge a complaint with a supervisory authority (Article 77).
Your right to object (Article 21 GDPR)
Where we process your personal data on the basis of our legitimate interests (Article 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then stop processing your data for that purpose, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.
You may object to the use of your personal data for direct marketing at any time and without giving reasons, for example by using the unsubscribe link in our emails or by contacting us (section 15). We will then no longer use your data for direct marketing.
How to exercise your rights. Send your request as set out in section 15, preferably using the email address you used with us. To protect your data, we may ask for information necessary to confirm your identity before acting on a request (Article 12(6)). We respond within one month of receipt; where requests are complex or numerous, this period may be extended by two further months, in which case we will inform you of the reasons (Article 12(3)).
Requests are free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee based on administrative costs or refuse to act on it (Article 12(5)). Your rights are subject to the conditions and exceptions set out in the GDPR: for example, we may retain data that we are required to keep by law or that is necessary to establish, exercise or defend legal claims (Article 17(3)), and a copy of your data may not adversely affect the rights and freedoms of others (Article 15(4)).
Complaints. You can lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt. We would appreciate the opportunity to address your concern first (section 15).
11. Security
We implement technical and organisational measures appropriate to the risk in accordance with Article 32 GDPR, including encryption in transit (TLS), access controls based on the least-privilege principle, multi-factor authentication for administrative access where supported, the use of established infrastructure providers, logging and monitoring, and confidentiality obligations for personnel. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the competent supervisory authority and affected individuals where required by Articles 33 and 34 GDPR.
12. Children
The website and the Service are intended for businesses and are not directed at persons under 18. We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, please contact us and we will delete it.
13. Third-party websites and platforms
Our website and the Service may link to, or integrate with, third-party websites and platforms such as WhatsApp, Telegram, HubSpot or Salesforce. Their providers process personal data under their own privacy policies, for which we are not responsible.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in our processing, the Service or the law. The current version is always published on this page with the date of the last update. Where changes are material, we will inform customers by email or in the Service and, where required, ask for consent again.
15. Contact
For all questions about this Privacy Policy and to exercise your rights, use our contact form.