Skip to main content
AiAx
TrustPrivacyTerms

Privacy policy

Effective: 13 August 2026

AiAx interviews an organization's employees, maps its processes and systems, and records the results in a living knowledge base. This work involves personal data. This policy explains what we handle, why we handle it, and what rights you have. Each section starts with a plain-language summary.

Contents
  1. 01Who we are and our roles
  2. 02What we collect
  3. 03How we use data
  4. 04Legal bases
  5. 05Subprocessors
  6. 06Retention
  7. 07Your rights
  8. 08Changes and contact

01Who we are and our roles

In short

AiAx runs this service. For interview content we process data on behalf of your organization; for your account we are the controller.

AiAx (“we”) operates aiaxagents.ai. We have two roles under data-protection law.

For account data, including your name, email address, and sign-in events, we are the data controller and this policy applies directly.

For interview content and organizational data imported by your employer, we act as a data processor on behalf of the organization that engaged AiAx. That organization decides why and how the content is used. Its agreement with us and its privacy commitments to you govern that content.

02What we collect

In short

Account details, interview audio and transcripts, organizational data, security logs, and optional public professional facts you expressly ask us to research.

Account data: your name and email address from your sign-in provider, plus preferences such as language and theme.

Interview data: while a session is live we process your microphone audio to run the conversation, and we store the transcript as a draft that only you can see until you decide what happens to it.

Organizational data: people, roles, teams and employment percentages that your administrator imports to plan and run the mapping.

Optional public professional research: only after you tick the separate box when booking, we may look for publicly available facts about your current role, career experience and professional topics you have explicitly posted. Name and company matching can be wrong, so every result remains a source-linked hypothesis until you confirm or correct it live. We do not use this option to look for private, sensitive or personal-life information.

Security and usage logs: IP addresses and request metadata used for rate limiting and abuse prevention.

03How we use data

In short

To run and tailor interviews, build your organization's knowledge base, and keep the service secure. Optional person research can be skipped without losing the live demo.

We use interview data to conduct the conversation and produce the transcript, process maps and documentation your organization engaged us for. Publishing is consent-gated: the transcript remains a private draft until you have reviewed and approved it, and you can reject it instead.

If you expressly opt in to public professional research, we use the limited findings to tailor the demo and the opening interview questions. The findings are hypotheses, not confirmed facts; you confirm or correct them live. Leave the option unchecked to prevent person-specific lookup and still receive the same live demo.

We use account data to operate sign-in, localisation and support. We use security logs to protect the service.

We do not sell personal data, and we do not use your organization's content to train shared models.

04Legal bases

In short

Contract for delivering the service, separate consent for interviews and optional person research, and legitimate interest for security.

Where we are the controller, we process account data to perform our contract with you and your organization. We process security logs under our legitimate interest in keeping the service safe.

Participation in interviews is based on consent collected before the session starts. You can decline, stop a session at any point, and withdraw consent for unpublished material. You decide whether to approve or reject the transcript.

Public professional person research uses a separate, versioned, optional consent. The box starts unchecked. If it remains unchecked, we do not run a person-specific lookup. You can withdraw that consent for future processing by contacting us.

05Subprocessors

In short

We openly list our small set of infrastructure providers. Each receives only the data it needs.

We use Supabase (database, authentication, storage), Vercel (web hosting), Google Cloud Run (voice service), OpenAI (speech and language processing during live interviews and transcript analysis, with Google Gemini as the fallback), OpenRouter/xAI (Company Brain answers, review assistance and source-linked research synthesis), Resend (transactional email), Anthropic (optional visual analysis), Tavily (public-source discovery) and Firecrawl (public-page extraction).

For optional professional person research, Tavily, Firecrawl and OpenRouter/xAI may receive your name, company and submitted role as search hints, plus bounded excerpts from public pages. This happens only after the separate opt-in. Our Trust page maintains the current provider list, purpose and region. We review provider activation and the applicable data-processing terms before routing data to a service.

06Retention

In short

Drafts live until you approve or discard them. Optional person-research findings are purged when the booking completes or is canceled. Deletion requests are honored.

Interview drafts are kept while you decide; if you reject a draft it is removed from the publishing flow. Published content is retained under your organization's instructions, since it is part of the knowledge base they commissioned.

Transcripts from sales demos (booked on the website) follow a separate rule: they are deleted automatically after 90 days. Public person-research sources and assertions are purged when the booking is completed or canceled. The consent receipt on the access grant is retained only as long as needed to document your choice and meet applicable business or legal obligations.

Account data is kept while your account is active and removed after the account is closed, except where law requires longer. Security logs are kept only as long as needed for their purpose.

07Your rights

In short

You can request access, correction, deletion, portability or withdrawal of optional research consent, object to processing, and complain to Datatilsynet.

You can ask for access to the personal data we hold about you, have it corrected or deleted, receive a copy in a portable format, object to processing based on legitimate interest, and withdraw optional person-research consent for future processing. Public-source name and company matches can be wrong; tell us or correct the hypothesis live.

For interview content, your review screen is usually the fastest option because you control what gets published. For optional research or anything else, contact privacy@aiaxagents.ai and we will respond without undue delay. You can also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

08Changes and contact

In short

We update the effective date when this policy changes. Questions go to privacy@aiaxagents.ai.

When we change this policy we update the effective date at the top, and for material changes we notify your organization's administrators.

Questions, requests and complaints: privacy@aiaxagents.ai.

AiAx
Privacy·Terms
© 2026 AiAx