Legal & compliance
How Axon collects and protects personal data
This policy explains our data practices for customers, users, and website visitors.
Last updated: August 19, 2026 · 12 sections
Scope
Axon is operated by HERSTELLUNG SRL, a company registered in Romania, trading as XDBX Europe. This Privacy Policy describes how Axon handles personal data when you visit our website, create an account, use our platform, or contact us.
For data you give us directly (website visits, account sign-up, support and privacy requests), HERSTELLUNG SRL is the controller. For data processed inside a customer organization's workspace, that organization is the controller and we act as its processor under our Data Processing Addendum.
This policy applies to Axon's public website, dashboard, product modules (Orbis, Locus, Atlas, and Civitas), and the Axon mobile apps for iOS and Android.
Data We Collect
Depending on how you use Axon, we may process account data (name, work email, organization), authentication/security data (session, MFA state, login events, device identifiers for active sessions), and product data needed to operate bookings, schedules, maps, and people workflows.
Where your organization uses single sign-on (SAML/OIDC) or directory provisioning (SCIM), we process the identity and group attributes your identity provider sends us to create, update, and deactivate accounts.
Where your organization enables the Civitas module, we store the employee record fields it chooses to complete. Those fields can include identity details (legal and maiden name, gender, date of birth, national identification number), personal contact details (home address, personal email address, phone number), a bank account number kept as a payroll reference, employment and contract details (position, department, contract type and dates, employing entity, country of origin and residence, seniority), leave balances and requests, benefit entries, and documents uploaded to the employee file. Your organization decides which of these fields it uses and is the controller of that data. Axon stores and displays it on your organization's behalf and does not use it for any purpose of its own; the bank account field is a record entry only and is not connected to any payment system.
If you enable notifications, we store push subscription endpoints and device tokens so we can deliver notifications to your browser or mobile device.
We may also process billing and subscription data through Stripe, support and privacy inquiries you submit to us, and technical telemetry and security logs used to keep the service reliable and secure. Audit records for privileged actions include the IP address and browser user agent used to perform them.
How We Use Data
We process personal data to provide and secure the service, manage user access and permissions, support customer requests, process billing, and prevent abuse or fraud.
We also use data to meet legal obligations, maintain audit records, and improve service quality.
Legal Bases (EEA/UK/Switzerland)
Where GDPR or equivalent laws apply, we process data based on one or more legal bases: contract performance, legitimate interests, legal obligations, and consent where required.
If we rely on consent, you can withdraw it at any time for future processing.
Data Location and International Transfers
Customer data is stored in the European Union: our database and file storage run in Google Cloud's eur3 European multi-region, and the web application is served from Frankfurt.
Some subprocessors (for example payment, email, and abuse-prevention providers) may process limited data outside the EEA. Where that happens we apply the safeguards required by applicable law, such as Standard Contractual Clauses and security controls.
Retention
We retain personal data for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods vary by data category, account status, and legal requirements. Some records are deleted automatically on a fixed schedule: privacy requests, support requests and their message history, and security audit logs are retained for two years and then expire automatically.
Security
Axon uses administrative, technical, and organizational safeguards designed to protect personal data, including access controls, encryption in transit, and audit-focused security practices.
No method of transmission or storage is completely risk-free, but we continuously improve our controls to reduce risk.
Your Privacy Rights (EU/US)
Depending on your location, you may have rights to access, correct, delete, or export your data, and to object to or restrict certain processing.
U.S. state privacy laws may also provide rights related to data portability, correction, deletion, and opt-out choices. We honor applicable rights requests in line with legal requirements.
Signed-in users can export their account data and request account deletion directly from account settings. Website and browser-app users can also change analytics and marketing consent there at any time. You can submit a request through the data rights page.
Children
Axon is intended for business and organizational use and is not directed to children under the age threshold defined by applicable law.
Policy Changes and Contact
We may update this policy periodically. When material changes occur, we will update the date above and provide notice as required by law.
For privacy requests or questions, contact us using the details below.
Contact
For legal, privacy, or compliance requests
Email: [email protected]
Product URL: https://axon.xdbx.eu
Related docs: Terms of Service, Cookie Policy, Data Rights Requests, Subprocessor List.
This page is a product-facing legal summary and should be reviewed by your legal counsel for jurisdiction-specific requirements.