Home  /  Privacy

Privacy policy

What we collect, why, how long we keep it, and what you can ask us to do about it. Written to be read rather than to be survived.

Axonifi Inc  ·  2248 Broadway, Suite 2198, New York, NY 10024
Effective 4 September 2026  ·  Last updated 4 September 2026


1. Who we are, and which hat we are wearing

Axonifi Inc is a US company providing consulting, training and platform work in enterprise AI. We handle personal data in two distinct roles, and the difference matters for your rights.

  • As a controller — for our own business. Enquiries, correspondence, contracts, training administration and this website. We decide what is collected and why, and this policy governs it.
  • As a processor — when a client gives us access to their systems during an engagement. Any personal data in there belongs to the client, who remains the controller. We act only on their documented instructions under our contract, and their privacy notice governs it, not this one.

2. What we collect

When you visit this website

Almost nothing. This site sets no cookies, runs no third-party analytics, and carries no advertising or tracking pixels. The downloadable templates are generated in your browser and require no email address, no form, and no identification of any kind.

Our hosting provider records standard server logs — IP address, browser type, page requested, timestamp — as every web server does, for security and to keep the site running.

When you contact us

  • Contact details — name, work email, employer, role, and a phone number if you give one.
  • What you tell us — the content of your enquiry, including anything you choose to share about your workflows, systems or organisation.

During an engagement or training programme

  • Client personnel — names, roles and contact details of the people we work with.
  • Training participants — attendance, and the artifacts produced in a session.
  • Client systems data — where access is granted. We are a processor for this, per section 1.

3. Why we use it

  • To answer you and deliver the work — performing a contract, or taking steps at your request before one exists.
  • To administer training — attendance and materials, and reporting completion to the sponsor who commissioned the programme where that has been agreed.
  • To run the business — invoicing, accounting, tax and statutory records. A legal obligation.
  • To keep our systems secure — detecting and investigating misuse. Our legitimate interest in operating safely, balanced against your interests.

Where we rely on consent — a mailing list, for instance — you can withdraw it at any time without affecting anything we did before you did.

4. What we do not do

Stated plainly, because these are the questions worth asking:

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no opt-out to click because there is nothing to opt out of.
  • We do not train AI models on your data — not on your personal information, not on your organisation's material, not for our own products and not for anyone else's.
  • We do not use material from one client's engagement for another's.
  • We do not make automated decisions that produce legal or similarly significant effects about you. Every consequential decision in the systems we design waits for a named human — that is the whole point of the work.
  • We do not buy contact lists or enrich your details from data brokers.

5. Who else sees it

We disclose personal information only to:

  • Our service providers — Google Cloud for hosting, and Google Workspace for email, documents and storage. Both are bound by contract to process only on our instructions.
  • Model and assistant providers — where an engagement involves them, and only the provider the client has selected under their own contract.
  • Delivery partners — named to you in advance, where they form part of your engagement team, under equivalent confidentiality and data-protection obligations.
  • Professional advisers and authorities — accountants, lawyers, or where we are legally required to disclose.
  • An acquirer — if the business is sold or merged, under confidentiality, and we will tell you.

The full subprocessor position for an engagement is set out on our security and data handling page and confirmed in writing before signature.

6. Where it goes

We are based in the United States and our own systems are hosted there. If you contact us from outside the US, your information will be transferred to and stored in the US.

For personal data originating in the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the parties involved, together with the technical measures described on our security page.

Where a client's sector or jurisdiction imposes data residency or localisation requirements, deployments are designed to keep in-scope data inside that boundary, agreed in writing before work begins.

7. How long we keep it

  • Enquiries that do not become engagements — 24 months, then deleted.
  • Engagement and training records — for the duration of the engagement and 7 years afterwards, to meet contractual, tax and statutory obligations.
  • Client systems data — returned or deleted at the end of the engagement, on the timetable in the contract, with written confirmation. Deletion is a step someone performs and confirms, not an assumption.
  • Server logs — 12 months.

8. Your rights

Everyone

Whoever and wherever you are, you may ask us what we hold about you, ask us to correct it, ask us to delete it, or ask us to stop contacting you. We will not charge you, and we will not treat you differently for asking.

If you are a US resident

Depending on your state — including California, New Jersey, Colorado, Connecticut, Virginia and others with comprehensive privacy laws — you may have the right to:

  • know what personal information we collect, use and disclose, and obtain a copy of it;
  • correct inaccurate personal information;
  • delete personal information we hold about you;
  • opt out of sale, targeted advertising and profiling — none of which we do, as set out in section 4;
  • appeal a refusal, where your state provides for it; and
  • be free from retaliation for exercising any of these.

An authorised agent may make a request on your behalf with proof of authority.

If you are in the EEA, the UK or Switzerland

You have the rights of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent. You may also lodge a complaint with your national supervisory authority — though we would rather you came to us first, and we will take it seriously.

9. Making a request

Write to contact@axonifi.ai with the word "privacy" in the subject line, or to the postal address at the foot of this page.

We will acknowledge within 10 business days and respond substantively within 30 days. Where the law allows an extension for complex requests we will tell you why before taking it, and where the law requires a shorter period we will meet it. We may need to verify your identity first — we will ask for the minimum required to do so, and we will not retain what you send for verification beyond that purpose.

If your request concerns data we hold as a processor for a client, we will refer you to that client and support them in responding.

10. Security

Encryption in transit and at rest, multi-factor authentication, least-privilege access, managed secret storage, and engagement access that is time-bound and revoked on completion. Our practices are set out on our security page.

If a breach affects your personal information, we will notify you and any regulator required, without waiting for the investigation to conclude. Our contractual commitment to clients is notice within 24 hours of becoming aware.

11. Children

This site and our services are for business use by adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.

12. Changes

We will post any revision here and update the date at the top. If a change materially affects how we use information you have already given us, we will contact you directly rather than rely on you noticing.

13. Contact

Axonifi Inc
2248 Broadway
Suite 2198
New York
NY 10024
contact@axonifi.ai


This policy describes our actual practices in plain language. It is not a substitute for legal advice, and we recommend having counsel review it against your obligations before relying on it.