Legal

Privacy policy

How the axelion.ai website and the Axelion service process personal data under the EU General Data Protection Regulation (GDPR).

Last updated: 14 September 2026

In short.

  • The operator of axelion.ai is responsible for the personal data described in this policy.
  • We use personal data to run the website, answer enquiries, provide the Service and meet legal obligations.
  • We use analytics cookies; you can switch them off at any time by clicking "Decline" (section 5). We do not use advertising cookies.
  • We do not sell personal data.
  • When businesses use Axelion to talk to their customers, those businesses decide how that data is used (section 9).

You can exercise your rights, including your right to object, as described in section 15.

1. Who is responsible

1.1 The controller within the meaning of Article 4(7) GDPR for the processing described in this Privacy Policy is the operator of the website at https://axelion.ai and provider of the Axelion service ("Axelion", "we", "us", "our"). Our contact details are set out in section 15.

1.2 We have not appointed a data protection officer, as we are not required to do so under Article 37 GDPR. All data protection enquiries are handled as set out in section 15.

1.3 This Privacy Policy applies to visitors of axelion.ai, to people who request a demo or contact us, and to representatives, employees and users of our business customers, prospects, partners, suppliers and investors. It does not apply to personal data we process on behalf of our customers as a processor, which is described in section 9.

2. Personal data we process

CategoryExamplesSource
Technical and log dataIP address, date and time of the request, requested URL, referrer, browser and operating system, device type, language, error and security logsAutomatically from your device when you visit the website
Cookie choice recordYour choice regarding analytics cookies and the date of that choiceStored on your device when you click "OK" or "Decline"
Statistics dataAggregated counts of pages requested, referrers, browser types and countriesDerived from our server request logs
Analytics dataOnline identifiers stored in analytics cookies, pages viewed, interactions, session information, approximate location derived from the IP address, device and browser informationAnalytics cookies on your device, unless you click "Decline"
Enquiry dataName, business email address, company, preferred channel, monthly lead volume, message and any other information you provideYou, through our forms or by email
Account dataName, business email address, role, company, login credentials, settings and preferencesYou or the business you work for
Billing dataCompany name, billing address, VAT number, invoices and payment history. Card details are processed by our payment provider and are not stored by usYou, the business you work for, our payment provider
Service usage and security dataLog-ins, IP addresses, actions performed in the Service, feature usage, device information and audit logsAutomatically when you use the Service
CommunicationsEmails, call and meeting notes, support requests, feedback and survey responsesYou

3. Purposes, legal bases and retention

PurposeDataLegal basisRetention
(a) Providing, securing and troubleshooting the websiteTechnical and log dataArt. 6(1)(f) GDPR — our legitimate interest in operating a secure, available and functioning websiteUp to 30 days; longer where needed to investigate a specific security incident
(b) Recording your cookie choiceCookie choice recordArt. 6(1)(f) GDPR — our legitimate interest in respecting your choice6 months, after which we ask again
(c) Website statistics based on server logsTechnical and log data, statistics dataArt. 6(1)(f) GDPR — our legitimate interest in understanding how the website is usedAggregated statistics only
(d) Website analytics with cookiesAnalytics dataArt. 6(1)(f) GDPR — our legitimate interest in understanding how the website is used; you can object at any time by clicking "Decline"Cookies up to 13 months; analytics data up to 14 months
(e) Responding to enquiries and demo requests, and pre-contractual discussionsEnquiry data, communicationsArt. 6(1)(b) GDPR — steps taken at your request before entering into a contract; Art. 6(1)(f) GDPR — our legitimate interest in communicating with business customers and prospects3 years after our last contact with you
(f) Providing the Service, managing accounts and providing supportAccount data, service usage and security data, communicationsArt. 6(1)(b) GDPR — performance of a contract with you; where the contract is with the business you work for, Art. 6(1)(f) GDPR — our legitimate interest in performing that contractFor the term of the contract and the data retrieval period; then deleted or anonymised, unless needed for purposes (g), (j) or (k)
(g) Invoicing, accounting and taxBilling dataArt. 6(1)(c) GDPR — legal obligations under accounting and tax laws10 years after the end of the financial year, or longer where required by law
(h) Business-to-business marketing, such as product news and invitationsName, business email address, company, interaction historyArt. 6(1)(f) GDPR — our legitimate interest in direct marketing (Recital 47 GDPR), or your consent where required by electronic marketing rules. You can unsubscribe at any timeUntil you object or unsubscribe, and no longer than 3 years after the last interaction; we keep a suppression record to respect your opt-out
(i) Improving the Service, including creating anonymised and aggregated statisticsService usage dataArt. 6(1)(f) GDPR — our legitimate interest in developing and improving our productsPersonal data is anonymised or deleted; anonymised data is no longer personal data
(j) Preventing fraud and abuse, enforcing our Terms, complying with sanctions, and establishing, exercising or defending legal claimsAll categories, as necessaryArt. 6(1)(f) GDPR — our legitimate interest in protecting our business and rights; Art. 6(1)(c) GDPR where required by lawFor the applicable limitation period (generally up to 10 years) or until proceedings are finally concluded
(k) Complying with legal obligations and requests from public authoritiesAll categories, as necessaryArt. 6(1)(c) GDPR — legal obligationAs required by law
(l) Corporate transactions, such as financing, merger or acquisitionRelevant categories, in aggregated or pseudonymised form where possibleArt. 6(1)(f) GDPR — our legitimate interest in developing our businessFor the duration of the transaction and as required afterwards

Where we rely on legitimate interests, we have balanced those interests against your interests, rights and freedoms. You can request information about this balancing test (section 15).

4. Is providing data required?

Technical data is necessary to deliver the website to your device. In our forms, fields marked with an asterisk are required to handle your request; without them we cannot respond. For customers, account and billing data are required to conclude and perform the contract and to comply with our legal obligations.

5. Cookies and similar technologies

We use strictly necessary technologies and analytics cookies. We do not use advertising cookies.

TechnologyPurposeCategoryDuration
Cookie choice record (local storage)Stores your choice regarding analytics cookiesStrictly necessary6 months
Analytics cookiesDistinguish visitors and sessions to produce statistics on how the website is usedAnalytics — until you click "Decline"Up to 13 months
Security cookies (set only when triggered)Distinguish humans from bots and protect the website against attacksStrictly necessaryUp to 30 minutes

You can switch off analytics cookies at any time by clicking "Decline" in the bar at the bottom of the page or change my cookie choice. We then delete the analytics cookies from your browser. For visitors who have declined, website statistics are derived only from our server request logs. You can also block or delete cookies in your browser settings.

The fonts used on this website are hosted on our own infrastructure; no request is made to third-party font services.

6. Recipients

We do not sell personal data and do not share it for cross-context behavioural advertising. We disclose personal data only to the following categories of recipients, and only to the extent necessary:

  • Hosting, content delivery and security providers, including for website statistics, acting as our processors.
  • Web analytics providers, acting as our processors.
  • Form and email delivery providers, which store form submissions and forward them to our mailbox, acting as our processors.
  • Other service providers acting as our processors: email and productivity, customer relationship management, support, cloud infrastructure and AI model providers, bound by data processing agreements and our instructions.
  • Payment service providers, which may act as independent controllers for fraud prevention and regulatory purposes.
  • Professional advisers and auditors, such as lawyers, accountants and tax advisers, bound by confidentiality.
  • Public authorities, courts and law enforcement bodies, where required by law or necessary to establish, exercise or defend legal claims.
  • Potential acquirers, investors and their advisers, in connection with an actual or proposed financing, merger, acquisition or sale of assets, subject to confidentiality.
  • Connected Platforms that our customers choose to connect, such as WhatsApp, Telegram, email services or CRMs, at the customer's direction.

An up-to-date list of our processors is available on request.

7. International transfers

Some of our service providers, such as hosting, security, web analytics, form delivery and AI model providers, may process personal data outside the European Economic Area, including in the United States and India. We transfer personal data outside the EEA only in compliance with Chapter V GDPR, in particular on the basis of (a) an adequacy decision of the European Commission, including the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795) for certified recipients, or (b) the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with supplementary measures where necessary. You can request a copy of the relevant safeguards (section 15).

8. Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. Automated security tools may temporarily block traffic that appears malicious; if you are affected, you may contact us to request human review.

9. Data we process for our customers

Businesses use Axelion to communicate with their own customers and prospects ("End Users"), for example through WhatsApp, Telegram or email. When we process End Users' messages, contact details, order and quote information for a business customer, that business is the controller and we act as its processor under Article 28 GDPR and our Data Processing Addendum.

The business is responsible for having a legal basis, for informing End Users — including that they are interacting with an AI system — and for handling End User rights requests. If you are an End User, please contact the business you communicated with. If you send a request to us, we will forward it to that business where we can identify it, and will not respond to it ourselves unless the business instructs us to or the law requires it.

Where the Service improves a customer's AI agent based on that customer's conversations, this is done on the customer's behalf and only for that customer. We do not use End Users' personal data to train AI models for other customers or for general purposes; we may use data that has been anonymised so that it no longer identifies any person.

10. Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy of it (Article 15);
  • have inaccurate personal data rectified (Article 16);
  • have your personal data erased (Article 17);
  • restrict the processing of your personal data (Article 18);
  • receive your personal data in a portable format (Article 20);
  • object to processing (Article 21 — see below);
  • withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal (Article 7(3)); and
  • lodge a complaint with a supervisory authority (Article 77).

Your right to object (Article 21 GDPR)

Where we process your personal data on the basis of our legitimate interests (Article 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We will then stop processing your data for that purpose, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary to establish, exercise or defend legal claims.

You may object to the use of your personal data for direct marketing at any time and without giving reasons, for example by using the unsubscribe link in our emails or by contacting us (section 15). We will then no longer use your data for direct marketing.

How to exercise your rights. Send your request as set out in section 15, preferably using the email address you used with us. To protect your data, we may ask for information necessary to confirm your identity before acting on a request (Article 12(6)). We respond within one month of receipt; where requests are complex or numerous, this period may be extended by two further months, in which case we will inform you of the reasons (Article 12(3)).

Requests are free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee based on administrative costs or refuse to act on it (Article 12(5)). Your rights are subject to the conditions and exceptions set out in the GDPR: for example, we may retain data that we are required to keep by law or that is necessary to establish, exercise or defend legal claims (Article 17(3)), and a copy of your data may not adversely affect the rights and freedoms of others (Article 15(4)).

Complaints. You can lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt. We would appreciate the opportunity to address your concern first (section 15).

11. Security

We implement technical and organisational measures appropriate to the risk in accordance with Article 32 GDPR, including encryption in transit (TLS), access controls based on the least-privilege principle, multi-factor authentication for administrative access where supported, the use of established infrastructure providers, logging and monitoring, and confidentiality obligations for personnel. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the competent supervisory authority and affected individuals where required by Articles 33 and 34 GDPR.

12. Children

The website and the Service are intended for businesses and are not directed at persons under 18. We do not knowingly collect personal data from children. If you believe that a child has provided personal data to us, please contact us and we will delete it.

13. Third-party websites and platforms

Our website and the Service may link to, or integrate with, third-party websites and platforms such as WhatsApp, Telegram, HubSpot or Salesforce. Their providers process personal data under their own privacy policies, for which we are not responsible.

14. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing, the Service or the law. The current version is always published on this page with the date of the last update. Where changes are material, we will inform customers by email or in the Service and, where required, ask for consent again.

15. Contact

For all questions about this Privacy Policy and to exercise your rights, use our contact form.