Privacy policy
AiAx interviews an organisation's employees, maps its processes and systems, and records the results in a living knowledge base. This work involves personal data. This policy explains what we handle, why we handle it, and what rights you have. Each section starts with a plain-language summary.
01Who we are and our roles
AiAx runs this service. For interview content we process data on behalf of your organisation; for your account we are the controller.
AiAx (“we”) operates aiaxagents.ai. We have two roles under data-protection law.
For account data, including your name, email address, and sign-in events, we are the data controller and this policy applies directly.
For interview content and organisational data imported by your employer, we act as a data processor on behalf of the organisation that engaged AiAx. That organisation decides why and how the content is used. Its agreement with us and its privacy commitments to you govern that content.
02What we collect
Account details, interview audio and transcripts, organisational data your administrator imports, and security logs.
Account data: your name and email address from your sign-in provider, plus preferences such as language and theme.
Interview data: while a session is live we process your microphone audio to run the conversation, and we store the transcript as a draft that only you can see until you decide what happens to it.
Organisational data: people, roles, teams and employment percentages that your administrator imports to plan and run the mapping.
Security and usage logs: IP addresses and request metadata used for rate limiting and abuse prevention.
03How we use data
To run interviews, build your organisation's knowledge base, and keep the service secure. Nothing is published without the interviewee's approval.
We use interview data to conduct the conversation and produce the transcript, process maps and documentation your organisation engaged us for. Publishing is consent-gated: the transcript remains a private draft until you have reviewed and approved it, and you can reject it instead.
We use account data to operate sign-in, localisation and support. We use security logs to protect the service.
We do not sell personal data, and we do not use your organisation's content to train shared models.
04Legal bases
Contract for delivering the service, consent for interview participation, legitimate interest for security.
Where we are the controller, we process account data to perform our contract with you and your organisation. We process security logs under our legitimate interest in keeping the service safe.
Participation in interviews is based on consent collected before the session starts. You can decline, stop a session at any point, and withdraw consent for unpublished material. You decide whether to approve or reject the transcript.
05Subprocessors
We openly list our small set of infrastructure providers. Each receives only the data it needs.
We use Supabase (database, authentication, storage), Vercel (web hosting), Google Cloud Run (voice service), OpenAI (speech and language processing during live interviews and transcript analysis, with Google Gemini as the fallback), OpenRouter/xAI (Company Brain answers and the review assistant), Resend (transactional email), and optional Anthropic, Tavily and Firecrawl services for visual analysis and onboarding research.
Our Trust page maintains the current list, including each provider's purpose and region. We review provider activation and the applicable data-processing terms before routing customer data to a service.
06Retention
Drafts live until you approve or discard them. Account data lives while your account does. Deletion requests are honoured.
Interview drafts are kept while you decide; if you reject a draft it is removed from the publishing flow. Published content is retained under your organisation's instructions, since it is part of the knowledge base they commissioned.
Transcripts from sales demos (booked on the website) follow a separate rule: they are deleted automatically after 90 days.
Account data is kept while your account is active and removed after the account is closed, except where law requires longer. Security logs are kept only as long as needed for their purpose.
07Your rights
You can request access, correction, deletion, or portability, object to processing, and complain to Datatilsynet.
You can ask for access to the personal data we hold about you, have it corrected or deleted, receive a copy in a portable format, and object to processing based on legitimate interest.
For interview content, your review screen is usually the fastest option because you control what gets published. For everything else, contact us and we will respond without undue delay. You can also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
08Changes and contact
We update the effective date when this policy changes. Questions go to privacy@aiaxagents.ai.
When we change this policy we update the effective date at the top, and for material changes we notify your organisation's administrators.
Questions, requests and complaints: privacy@aiaxagents.ai.