Privacy Policy

What Axonplane collects, why, and what you can ask us to do about it.

This document is a draft awaiting legal review. It was prepared from what the platform technically does. Every item marked [CONFIRM] needs a decision from Axonplane before this is published.

Axonplane takes two different roles with personal data, and which one applies changes what you should do about it.

  • Your account — your name, email and sign-in details. Axonplane decides how these are used, so Axonplane is the controller.
  • What your workspace holds — employee records, customer contacts, support tickets, files. Your employer decides what goes in and why. Axonplane is the processor, acting on their instructions. If you want that data changed or removed, ask them; we act on their instruction, not directly on yours.

What we collect

To give you an account

Name, email address, password (stored hashed, never in readable form), profile picture if you add one, and multi-factor settings if you turn them on. If you sign in with Google or GitHub we receive your name and email from them, not your password.

Because the service runs

Audit records of security-relevant actions — signing in, changing a role, removing a member — each with an IP address and browser identifier. Product analytics about which features are used. Both are kept per workspace.

What your workspace puts in

This is the widest category and it is worth being specific, because some of it is sensitive:

KindExamples
WorkProjects, tasks, comments, time logs, files
PeopleEmployee records, time off, performance reviews, onboarding
Pay and benefitsPayroll runs, payslips, benefit enrolments
DocumentsContracts, NDAs, certifications, identity documents
RecruitmentCandidates, applications, interview notes
CustomersCRM contacts, deals, support tickets and their correspondence

Payroll, identity documents and benefit records are sensitive. They are held because a workspace administrator chose to put them there.

Who else sees it

Axonplane does not sell personal data and does not share it for advertising. It reaches these processors because the service needs them to work:

WhoWhat forWhat reaches them
Amazon Web ServicesFile storage and hostingUploaded files, database contents
PolarSubscriptions and paymentBilling email, plan, subscription state. Card details go to their processor and never touch Axonplane
ResendSending emailRecipient address and message contents
SentryError diagnosticsTechnical error data, which can incidentally include a user identifier
AnthropicAI features, only if a workspace enables themThe text submitted to that feature
Google, GitHubSign-in, only if you use itYour name and email, from them to us
Slack, Microsoft Teams, JiraIntegrations, only if a workspace connects oneThe notifications and records that integration is set up to send

[CONFIRM] Where the data is hosted, and the transfer mechanism for anyone outside that region.

How long it is kept

Account data is kept while the account exists. Workspace data is kept while the workspace exists; deleting a workspace removes its data.

[CONFIRM] Retention periods for audit logs, analytics, backups, and how long a deleted workspace is recoverable.

Keeping it safe

Passwords are hashed. Traffic is encrypted in transit. Stored credentials for third-party services are encrypted. Access is controlled by role, and every record is confined to its own workspace at the database level. Multi-factor authentication is available and can be required.

No system is perfect, and saying otherwise in a document like this would be a promise nobody can keep.

What you can ask for

Depending on where you live you may have the right to see a copy of your data, correct it, delete it, take it elsewhere, or object to some uses. Axonplane can act directly on these for your account. For anything inside a workspace, ask whoever runs it — we will help them, but the instruction has to come from them.

[CONFIRM] Which regimes are being claimed — UK GDPR, EU GDPR, CCPA — and the response window.

Cookies

Axonplane sets the cookies it needs to keep you signed in and to remember preferences such as your theme and language. It does not use advertising cookies.

[CONFIRM] Whether analytics counts as strictly necessary in your jurisdiction, and whether a consent banner is required.

Contact

[CONFIRM] Legal entity name, registered address, privacy contact address, and a data protection officer or EU/UK representative if one is required.

Changes

Material changes will be announced before they take effect.

[CONFIRM] How — in-product notice, email, or both — and the notice period.