Back to home
Legal

Privacy Policy

How AXXEM AI collects, uses, stores, and protects your information.

AXXEM AI · Last updated 10 August 2026

Public summary, written to be consistent with AXXEM AI's internal Data Protection & Privacy Policy.

AXXEM AI Solutions LLC ("AXXEM AI," "we," "us") runs a real, formally-led data-protection program. This policy explains what we collect through this website and our services, why, where it is stored, how we protect it, and the choices you have.

Scope

This policy covers the AXXEM AI website, our assessments, and our marketing. Our services are directed to businesses in the United States, and this policy is written to United States federal and state privacy law. We do not offer our services to individuals in the European Economic Area, the United Kingdom, or Switzerland.

Who we are

Data controller: AXXEM AI Solutions LLC, an Ohio limited liability company, Toledo, Ohio, USA. Our privacy program is led by Dr. Emmanuel Gonzalez, our Chief Technology Officer and Data Protection Officer (CTO/DPO). For any privacy question or to exercise your rights, contact support@axxem.ai.

Controller or processor? For information collected through this website and our marketing, AXXEM AI is the data controller. When we handle a client's data to deliver a paid engagement, we act as a processor under a separate data-processing agreement with that client.

What we collect

  • Information you give us: name, email, company, and anything you submit through a contact form, an AI Readiness or AI Fluency assessment, or a booked call.
  • Assessment responses: the answers you provide to an AI Readiness Snapshot or an AI Fluency Assessment, used to produce and explain your result.
  • Scheduling: if you book a call, we collect your name, email, and chosen time through our scheduling provider (Calendly).
  • Usage data: limited, privacy-respecting analytics (pages visited, device/browser type) to run and improve the site. We minimize what we collect.

We do not ask for, and our assessments have no fields for, sensitive personal information such as government identifiers, health data, precise geolocation, or financial account numbers.

Why we use it

  • To respond to your enquiry and deliver what you requested.
  • To produce and explain your assessment result.
  • To improve our content and services, and for limited security and analytics.

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months.

Where it is stored and how we protect it

We store data only on vetted platforms, under access control, encrypted in transit and at rest, including Google Workspace, Microsoft 365, and our company-controlled GitHub organization, plus approved application, database, and hosting services where a project requires them. Our safeguards include:

  • Multi-factor authentication (MFA) enforced across company accounts.
  • No credentials or secrets in code: secrets are held in a dedicated manager and kept out of the repositories.
  • Least-privilege access, limited to AXXEM AI's founders and any approved subcontractor under a signed data-protection (subcontractor) agreement.
  • Client data held in private repositories and locations only.

How AI is used

AI is core to what we do, and we're transparent about it. In our assessments, your scores and result tier are calculated directly from your answers — not by AI. Where a report includes written analysis, that analysis is generated by AI working within AXXEM AI's expert-built, research-backed framework: it draws only on guidance our team authored and fact-checked, is given none of your free-text (our assessments have no free-text fields), and cannot add advice or statistics of its own. That analysis is produced automatically and is not individually reviewed before delivery. When we use third-party AI services (for example, Anthropic or OpenAI), we minimize and, where practical, anonymize the data in prompts and use them under terms where your content is not used to train their models. We never sell your data or feed it to AI for unrelated purposes.

Our assessments produce an automated result, but that result has no legal or similarly significant effect on you. It is guidance for a business decision you remain free to make.

Subprocessors

We maintain a subprocessor register of the third parties that store or process data on our behalf: cloud storage and hosting (Google Workspace, Microsoft 365, GitHub, Supabase, Replit), AI/LLM APIs (Anthropic, OpenAI, OpenRouter), email (Resend), scheduling (Calendly), and automation, communications, and CRM tools. For each, we work to hold a Data Processing Agreement (DPA), a current security report (e.g. SOC 2 or ISO 27001), and a no-training or retention confirmation where relevant. A current list is available on request.

Children's data

Our website and services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has given us personal information, email support@axxem.ai and we will delete it. No current product involves children's data. If one ever does, we will handle it in line with applicable children's-privacy law (including COPPA) and apply additional safeguards, including a current written information-security program.

Retention

We keep personal data only as long as needed for the purpose collected, then delete or anonymize it. Assessment responses are retained for the period needed to deliver and discuss your result, and business-contact records for as long as we have an active or prospective relationship with you.

Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data; request a portable copy of the data you gave us; object to or restrict certain processing; and withdraw consent at any time. To make a request, email support@axxem.ai.

If you live in a US state with a privacy law

Residents of states with consumer privacy laws have specific rights, which we extend to all our users regardless of where they live:

  • Know and access — what personal information we have collected about you, and confirm whether we process it.
  • Delete — ask us to delete the personal information we hold about you.
  • Correct — ask us to fix inaccurate personal information.
  • Portability — receive a copy in a portable, readily usable format.
  • Opt out of sale, sharing, targeted advertising, and profiling — we do none of these, so there is nothing to opt out of, but the right stands if that ever changes.
  • Non-discrimination — we will not deny you service, charge you a different price, or give you a lower quality of service for exercising any of these rights.

We will verify your request against the information we already hold, and respond within 45 days. If we need more time, we will tell you within that period and explain why. You may use an authorized agent where your state's law allows it. If we deny your request, you may appeal by replying to our decision; if we deny the appeal, you may complain to your state Attorney General, or in California to the California Privacy Protection Agency.

Data breaches

We maintain a documented incident-response and breach-notification plan. In the event of a personal-data breach, we will act promptly to contain it and will notify affected parties and authorities as required by law.

Where your data is processed

We and our providers process data in the United States. Some providers may process or store data in other countries; where they do, we rely on appropriate contractual safeguards.

Cookies

We use only the cookies needed to run the site and, where applicable, privacy-respecting analytics. You can control cookies through your browser settings. Because we do not sell or share personal data and use no advertising or cross-site tracking cookies, the outcome an opt-out preference signal such as Global Privacy Control asks for is already every visitor's default.

Changes

We may update this policy; the "last updated" date above reflects the latest version, and it is kept consistent with our internal Data Protection & Privacy Policy. Material changes will be highlighted on this page.

Contact

Privacy questions or requests: support@axxem.ai · Data Protection Officer, AXXEM AI Solutions LLC, Toledo, Ohio, USA.