Legal

Privacy Policy

How AxiomWeb collects, uses, stores, and protects information across all of our services, websites, and client engagements.

Effective DateJune 4, 2026
Last RevisedJune 4, 2026
Version2.0
JurisdictionUnited States
ControllerAxiomWeb LLC
Section 01

Overview & Scope

This Privacy Policy (“Policy”) describes the practices of AxiomWeb LLC (“AxiomWeb,” “we,” “our,” or “us”) regarding the collection, use, disclosure, and protection of personal information obtained through:

  • Our public website at www.axiomweb.net and all subdomains
  • Client portals, dashboards, and project management tools operated by AxiomWeb
  • Email, telephone, and written communications initiated by or with AxiomWeb
  • Software products, SaaS platforms, and applications developed or operated by AxiomWeb on behalf of clients
  • Marketing communications, forms, and lead capture mechanisms

This Policy applies to all visitors, prospective clients, active clients, former clients, job applicants, and any other natural persons whose personal information comes into the possession of AxiomWeb. It does not apply to personal information processed by AxiomWeb on behalf of clients as a data processor — those processing activities are governed by the applicable Data Processing Agreement (DPA) between AxiomWeb and the client.

Plain language summary: We only collect what we need. We don’t sell your data. We don’t use surveillance ad networks. We protect client information with the same rigor we apply to our own systems.

Section 02

Information We Collect

2.1 — Information You Provide Directly

CategoryExamplesWhen Collected
Contact InformationName, email address, phone number, company nameContact forms, email inquiries, phone calls
Business InformationCompany size, industry, project description, budget rangeProject intake forms, discovery calls
Account CredentialsUsername, hashed password, multi-factor authentication dataClient portal registration
Payment InformationBilling name, address; card data processed by Stripe (never stored by AxiomWeb)Invoice payment, subscription setup
Communications ContentEmails, messages, meeting notes, project briefsOngoing engagement
Employment InformationRésumé, work history, references, portfolio linksJob applications

2.2 — Information Collected Automatically

CategoryExamplesPurpose
Log DataIP address, browser type, referring URL, pages visited, timestampsSecurity monitoring, abuse prevention
Device InformationOperating system, screen resolution, device typeCompatibility and UX improvement
Usage AnalyticsPage views, session duration, click paths, scroll depthSite performance and content improvement
Security EventsFailed login attempts, bot signals, honeypot triggersFraud and abuse detection

AxiomWeb does not use fingerprinting, cross-site tracking pixels, behavioral ad profiling, or any technology designed to build persistent behavioral profiles of individuals across unrelated websites.

2.3 — Information from Third Parties

We may receive limited information from third parties in the following circumstances:

  • Referral partners who introduce prospective clients may share contact names and email addresses.
  • Public sources such as LinkedIn or professional directories when researching prospective business relationships.
  • Payment processors (Stripe) who confirm transaction status without sharing full card data.
  • Identity verification services used in connection with certain high-security client engagements.
Section 03

How We Use Your Information

AxiomWeb uses personal information for the following purposes, each tied to a specific legal basis outlined in Section 04:

  • Service Delivery: Scoping, building, deploying, and supporting software products and engineering engagements contracted by clients.
  • Client Communication: Project updates, technical support, billing notifications, and contract administration.
  • Security Operations: Protecting our infrastructure, detecting unauthorized access, blocking malicious actors, and maintaining audit logs.
  • Business Development: Responding to inquiries, preparing proposals, and conducting discovery conversations with prospective clients.
  • Financial Administration: Invoicing, payment processing, tax compliance, and accounting.
  • Legal Compliance: Meeting obligations under applicable law, responding to lawful legal process, and enforcing our agreements.
  • Site Improvement: Analyzing anonymized usage patterns to improve website performance, content, and user experience.
  • Recruitment: Evaluating job applications, conducting interviews, and maintaining applicant records in compliance with employment law.

We do not: sell personal information, rent mailing lists, use personal data for behavioral advertising, share client information with competitors, or process personal information for any purpose materially incompatible with the purposes stated at the time of collection.

Section 05

Data Sharing & Disclosure

AxiomWeb does not sell, trade, or rent personal information to third parties. We disclose information only in the following limited circumstances:

5.1 — Service Providers

We engage carefully vetted third-party service providers who process data on our behalf under written data processing agreements:

ProviderPurposeData Shared
Stripe, Inc.Payment processingBilling name, address, card data (Stripe-hosted; AxiomWeb never receives raw card numbers)
SMTP / Email RelayTransactional email deliveryRecipient email address, message content
Backblaze B2Encrypted backup storageEncrypted database and file backups
Domain / DNS RegistrarDomain name servicesRegistrant contact data (ICANN-required)
Legal CounselContract review, complianceAs minimally necessary for legal advice
Accountants / AuditorsFinancial reporting, tax filingTransaction records, client names for invoicing

5.2 — Legal Compulsion

We may disclose personal information if we have a good-faith belief that disclosure is necessary to: (a) comply with applicable law or a valid legal order, subpoena, or court order; (b) protect the rights, property, or safety of AxiomWeb, our clients, or the public; or (c) detect, prevent, or address fraud, security, or technical issues. Where legally permitted, we will notify affected individuals of such requests.

5.3 — Business Transfers

In the event of a merger, acquisition, asset sale, or transfer of substantially all of AxiomWeb’s business, personal information may be transferred to the acquiring entity. We will provide notice before personal information is transferred and becomes subject to a materially different privacy policy, and affected individuals will have the opportunity to opt out where required by law.

5.4 — With Your Consent

We may share information for other purposes with your explicit prior consent, which will be obtained through a clear affirmative action. Consent may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.

Section 06

Data Retention

We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:

Data TypeRetention PeriodRationale
Active client project filesDuration of engagement + 7 yearsContract compliance, dispute resolution
Financial / billing records7 years from transaction dateIRS and state tax law requirements
Security / access logs90 days rollingIncident response and abuse investigation
Inquiry / lead communications3 years from last contactBusiness development records
Job applicant records2 years from application dateEqual employment opportunity compliance
Marketing opt-in recordsUntil opt-out + 2 yearsCAN-SPAM / anti-spam compliance proof
Website analytics (anonymized)26 months rollingTrend analysis; no individual identifiers retained
Backup snapshots (encrypted)30 days rolling; annual snapshot 1 yearDisaster recovery

When data is no longer required under these schedules, it is securely deleted using industry-standard methods. Encrypted backups are purged on the same schedule. Physical documents, where applicable, are shredded.

Section 07

Security Measures

AxiomWeb maintains a security-first architecture across all systems that handle personal information. Our controls include:

7.1 — Technical Controls

  • Encryption in transit: TLS 1.2+ enforced across all web properties and APIs; HSTS headers deployed site-wide.
  • Encryption at rest: Database and backup storage encrypted using AES-256. Backblaze B2 server-side encryption enabled on all buckets.
  • Access control: Role-based access control (RBAC) enforced on all systems. Principle of least privilege applied. Service accounts isolated per project using dedicated credentials.
  • Authentication: Multi-factor authentication required for all administrative access. Brute-force protection with progressive lockout and IP-based blocking.
  • Intrusion detection: mod_evasive deployed for DoS mitigation; automated security audits run weekly; diagnostic files purged on schedule.
  • Patch management: Server software, PHP runtimes, and dependencies updated on a defined cadence with critical patches applied within 24 hours of disclosure.
  • Network segmentation: Production environments isolated from development and staging environments.

7.2 — Organizational Controls

  • All team members with access to personal data operate under confidentiality obligations.
  • Third-party vendors are evaluated for security posture before onboarding and subject to written DPAs.
  • Security incidents are documented, investigated, and remediated with root-cause analysis.
  • We conduct internal security reviews on a defined schedule and engage independent penetration testing for critical systems.

No system is impenetrable. While we implement industry-leading controls, no transmission over the internet or electronic storage method is 100% secure. If you believe a security incident has occurred involving your information, contact us immediately at admin@axiomweb.net.

7.3 — Breach Notification

In the event of a data breach that poses a risk to individuals’ rights and freedoms, AxiomWeb will: (a) investigate and contain the breach within 72 hours of discovery; (b) notify affected individuals without undue delay when the breach is likely to result in high risk to their rights; (c) notify applicable regulatory authorities where legally required; and (d) maintain a documented breach log regardless of severity.

Section 08

Cookies & Tracking Technologies

AxiomWeb uses a minimal, privacy-respecting approach to cookies. We do not deploy third-party advertising cookies, social media tracking pixels, or cross-site behavioral tracking of any kind.

Cookie Name / TypePurposeDurationFirst or Third Party
ax-style, ax-toneStores your visual theme preference (localStorage)Persistent (localStorage)First party
Session cookiesMaintains login state in client portalsSession (expires on browser close)First party
CSRF tokensCross-site request forgery protection on formsSessionFirst party
Analytics (anonymized)Aggregated page view and session data; no individual identifiersUp to 26 monthsFirst party

You can control cookies through your browser settings. Disabling cookies may affect the functionality of client portal features. For localStorage preferences, you can clear them via your browser’s developer tools or site data settings.

We do not honor third-party “Do Not Track” signals because we do not engage in the cross-site tracking those signals are designed to prevent. Our analytics are first-party and anonymized by design.

Section 09

Third-Party Services & Integrations

Our website loads resources from the following third-party domains. These are limited to functional dependencies with no behavioral tracking components:

ServiceResource LoadedPrivacy Policy
Google FontsInter & JetBrains Mono font filespolicies.google.com/privacy
StripeSecure payment form (client portals only)stripe.com/privacy

We do not load Facebook Pixel, Google Ads tags, LinkedIn Insight Tag, TikTok Pixel, or any other behavioral advertising technology on our public site or client portals.

Links from our site to external websites are provided for convenience. AxiomWeb has no control over and assumes no responsibility for the content or privacy practices of any third-party sites. We encourage you to review the privacy policy of any external site you visit.

Section 10

Your Privacy Rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information. We honor these rights for all individuals regardless of location, to the extent technically and legally feasible.

📄 Right to Access
Request a copy of the personal information we hold about you, including the categories, purposes, and sources of that data.
✏ Right to Rectification
Request correction of inaccurate or incomplete personal information. We will correct or complete records within 30 days.
🗑 Right to Erasure
Request deletion of your personal information where no legal obligation requires us to retain it. Also known as the “right to be forgotten.”
⏸ Right to Restriction
Request that we restrict processing of your data in certain circumstances, such as while a rectification request is being resolved.
📦 Right to Portability
Receive your data in a structured, machine-readable format (JSON or CSV) and transfer it to another controller where technically feasible.
🚫 Right to Object
Object to processing based on legitimate interests, including direct marketing. We will stop unless we can demonstrate compelling grounds.
📧 Withdraw Consent
Where processing is based on consent, withdraw that consent at any time. Withdrawal does not affect prior lawful processing.
⚖ Right to Complain
Lodge a complaint with a supervisory authority. US residents may contact the FTC; EU residents may contact their national Data Protection Authority.

To exercise any of these rights, submit a written request to admin@axiomweb.net with “Privacy Request” in the subject line. We will respond within 30 calendar days. We may need to verify your identity before fulfilling certain requests. There is no fee for standard requests.

Section 11

Children’s Privacy

AxiomWeb’s website and services are directed exclusively toward business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age through our public-facing website or business services.

If you are a parent or guardian and believe your child has provided personal information to us, contact us immediately at admin@axiomweb.net and we will promptly delete that information.

Note: Client engagements where AxiomWeb builds software that may interact with minors are governed by separate Data Processing Agreements that include appropriate COPPA, FERPA, and CCPA minor-specific provisions as applicable.

Section 12

International Data Transfers

AxiomWeb is based in the United States. All primary data processing and storage infrastructure operates on US-based servers. If you are accessing our services from outside the United States, your information will be transferred to and processed in the United States.

For individuals in the EU/EEA or UK, the United States does not have an adequacy decision equivalent to the EU-US Data Privacy Framework for all transfers. Where we transfer personal data from the EU/EEA or UK to the US, we rely on:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission, incorporated into our client Data Processing Agreements.
  • Explicit consent where appropriate and obtained through a clear affirmative action with full disclosure of the transfer and its risks.

You may request a copy of the applicable transfer mechanism documentation by contacting us at the address in Section 15.

Section 13

California Residents — CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), effective January 1, 2023, provides you with additional rights. This section supplements the rights described in Section 10.

13.1 — Categories of Personal Information Collected

In the preceding 12 months, AxiomWeb has collected the following CCPA categories of personal information:

  • Identifiers (name, email, IP address, account credentials)
  • Commercial information (services purchased, payment records)
  • Internet / network activity (log data, site usage analytics)
  • Professional / employment information (job applications, business context)
  • Communications content (emails, project correspondence)

13.2 — California-Specific Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected, sold (we do not sell), or disclosed for a business purpose.
  • Right to Delete: Request deletion of personal information subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: AxiomWeb does not sell or share personal information as defined by the CCPA/CPRA. No opt-out mechanism is required, but we honor requests regardless.
  • Right to Limit Use of Sensitive Personal Information: We do not process sensitive personal information beyond what is necessary for the primary purpose of our services.
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

California residents may submit requests by emailing admin@axiomweb.net with “CCPA Request” in the subject line. We will respond within 45 calendar days (extendable by an additional 45 days with notice).

Section 14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The “Last Revised” date at the top of this page indicates when the most recent changes were made.

For material changes — those that meaningfully expand how we use personal information or reduce your rights — we will provide at least 30 days’ advance notice via:

  • A prominent notice on this page and the AxiomWeb homepage
  • Direct email notification to active clients and opted-in contacts

Non-material changes (corrections, clarifications, formatting) take effect upon posting. Your continued use of our website or services after the effective date of changes constitutes acceptance of the updated Policy.

Prior versions of this Privacy Policy are archived and available upon request.

Section 15

Contact & Privacy Requests

For all privacy-related inquiries, requests to exercise your rights, data breach reports, or questions about this Policy, contact our Privacy point of contact directly:

AxiomWeb Privacy Contact

@ Email: admin@axiomweb.net — use subject line “Privacy Request”
Written correspondence: AxiomWeb LLC, United States (mailing address available on request)

We will acknowledge receipt of your request within 3 business days and provide a substantive response within 30 calendar days. If we require an extension, we will notify you with the reason and expected completion date before the 30-day period expires.

If you are unsatisfied with our response to a privacy complaint, you have the right to escalate to the relevant regulatory authority in your jurisdiction.