AKAXA
ProductSecurityCompany

Privacy Policy

Last updated: August 24, 2026 · Version 2026-08-24 · Supersedes the April 12, 2026 version

AKAXA (“AKAXA,” “we,” “us,” or “our”) is the data user — the data controller, in GDPR terms — for personal information processed through the AKAXA platform (“Services”).

Operator status: AKAXA Limited (Hong Kong SAR) is in formation and has not yet been incorporated. Until incorporation is complete, the Services are operated by AKAXA's founders, who hold the data user role. This policy will be reissued with the registered company particulars, including the Business Registration number and registered office, once incorporation is complete.

Jurisdiction: We apply the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”) and its six Data Protection Principles as our primary data protection framework. Where you are located elsewhere, this policy is additionally designed to comply with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Korea's Personal Information Protection Act (PIPA), and other applicable laws. Where a local law grants you a stronger right than the PDPO, we honour the stronger right.

Privacy contact: privacy@akaxa.io
Escalation contact: dpo@akaxa.io
We have not appointed a statutory Data Protection Officer; the contacts above are the responsible channel for privacy enquiries and requests.

1. Information We Collect

  • Account data: name, email address, phone number, company name, job title, company size
  • Authentication data: password (hashed), SSO provider details, login timestamps
  • Company & analysis data: financial data, industry information, competitive landscape, M&A history, and other data uploaded for analysis
  • Usage data: IP address, browser type, pages visited, features used, session duration, error logs
  • Communication data: support messages, survey responses, feedback

2. Legal Basis for Processing (GDPR)

  • Contractual necessity (Art. 6(1)(b)): account creation, service delivery, billing
  • Legitimate interest (Art. 6(1)(f)): security, fraud prevention, platform improvement
  • Legal obligation (Art. 6(1)(c)): compliance with applicable laws
  • Consent (Art. 6(1)(a)): marketing communications where consent is the applicable basis; otherwise legitimate interest on an opt-out basis, as described in section 7

3. How We Use Your Information

  • Providing and operating the AI-powered analysis Services
  • Account authentication, administration, and customer support
  • Generating Analysis Reports and insights via AI systems
  • Security monitoring, fraud prevention, and abuse detection
  • Platform analytics and optimization using aggregated, de-identified data
  • Legal compliance and dispute resolution

AI Processing and Provider Terms

AKAXA does not use Customer data to train, fine-tune, or improve machine learning models without explicit written consent.

AI providers process data through their commercial APIs, whose published terms do not permit content submitted through those APIs to be used to train the provider's models. Those providers may retain content for a limited period for abuse monitoring in accordance with their own published terms. We do not present zero data retention (ZDR) as an executed commitment. Where a provider-specific zero-retention configuration is in place for AKAXA, we will identify that provider individually rather than describe zero retention as a general property of the platform.

4. Third-Party Data Sharing

We share data with the following sub-processors to operate the Services. Each operates in its own regions, primarily the United States; the per-provider detail is in the Data Processing Agreement and on the Sub-processors page:

  • Anthropic (Claude API): AI analysis processing
  • OpenAI: AI analysis processing
  • Google (Gemini): AI analysis or evidence processing when enabled for a workflow
  • Perplexity: web research enrichment — search queries only
  • Cloudflare: CDN, WAF, R2 object storage
  • Railway: application and database hosting
  • Vercel: web front-end hosting
  • Resend: transactional email delivery
  • Sentry: error monitoring — anonymized stack traces
  • GitHub: source control and CI/CD — the nightly production-database backup runs inside a GitHub-hosted runner

We do not sell or share personal information for targeted advertising. We rely on each sub-processor's published data processing terms, which require them to process data on our instructions, apply appropriate security measures, and notify us of breaches. Changes to sub-processors are notified with 30 days' notice. The current list is maintained at Sub-processors.

5. International Data Transfers and Data Location

Data location: AKAXA does not operate its own data centre and does not guarantee that data is stored in, or restricted to, any single jurisdiction. Processing takes place on the infrastructure of the providers listed above, primarily in the United States. Where a customer requires a specific data residency position, it must be agreed in writing for that deployment before confidential material is accepted.

Transfer safeguards: AKAXA's customer Data Processing Agreement incorporates the EU Standard Contractual Clauses (Module 2: Controller to Processor) for transfers from the EU/EEA. That agreement is offered as a template and takes effect only when executed with a customer; AKAXA has no executed customer DPA at the date of this policy. For onward transfers to US-based sub-processors, the same template carries Standard Contractual Clauses (Module 3: Processor to Processor), effective on execution; the operative protection today is each provider's own published transfer terms.

6. Automated Decision-Making (GDPR Art. 22)

AKAXA's AI-powered analysis provides decision support tools only. We do not engage in automated decision-making that produces legal effects or similarly significant effects on data subjects. All Analysis Reports are advisory in nature and require review by qualified human professionals. Each Customer's data is processed in a logically isolated environment.

7. Your Rights

Hong Kong Users (PDPO, Cap. 486)

  • Data Access Request (s.18): you may request a copy of the personal data we hold about you. We will comply within 40 days of a valid request, or notify you in writing within 40 days and state the reason if we cannot. A request may be made on the PCPD's specified form (OPS003) or in writing to privacy@akaxa.io. Any fee will not be excessive and will be quoted before we proceed.
  • Data Correction Request (s.22): if you believe data we hold is inaccurate, you may request correction. We will comply within 40 days, or give written reasons for refusal.
  • Complaint to the regulator: you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) — www.pcpd.org.hk — in addition to any supervisory authority in your own jurisdiction.

Direct Marketing (PDPO Part VIA)

Where the applicable law requires consent before first use — Hong Kong, the EU/EEA, and Korea — we will not use your personal data in direct marketing without first notifying you of the kinds of data to be used and the classes of goods and services being marketed, and obtaining that consent. Where the applicable law instead permits marketing on an opt-out basis, such as the CAN-SPAM Act in the United States or the UK PECR regime for corporate subscribers, we may send on that basis; every such message identifies us plainly You may require us to stop using your personal data for direct marketing at any time, at no charge, by writing to privacy@akaxa.io or using the unsubscribe link in any marketing message that carries one. We act on an opt-out immediately and treat it as permanent. Today this is done by hand: no automated suppression list exists in the product yet, and AKAXA sends no marketing from an automated pipeline. If you are outside Hong Kong, additional rules may apply — the GDPR and ePrivacy consent regime in the EU/UK, the CAN-SPAM Act in the United States, or the Network Act (정보통신망법) in Korea. We follow the standard that applies where you are.

EU/EEA Users (GDPR)

  • Access (Art. 15): request a copy of your personal data
  • Rectification (Art. 16): correct inaccurate data
  • Erasure (Art. 17): request deletion of your data
  • Portability (Art. 20): receive your data in a machine-readable format (CSV, JSON)
  • Object (Art. 21): object to processing based on legitimate interest
  • Restrict (Art. 18): restrict processing in certain circumstances
  • Withdraw consent at any time without affecting prior processing
  • Lodge a complaint with your national supervisory authority

California Users (CCPA/CPRA)

  • Right to know what personal information is collected and how it is used
  • Right to delete personal information
  • Right to correct inaccurate information
  • Right to opt-out of sale or sharing (AKAXA does not sell data)
  • Right to non-discrimination for exercising privacy rights

Do Not Sell or Share My Personal Information

Korean Users (PIPA)

For users located in the Republic of Korea, AKAXA applies the Personal Information Protection Act (PIPA):

  • 수집 항목: 이름, 이메일, 회사명, 직책, 사용자 유형
  • 수집 목적: 서비스 제공, 계정 관리, AI 분석 서비스
  • 보관 기간: 아래 9항 보관 기간 표를 따릅니다 (계정 정보는 구독 종료 후 1년)
  • 파기 절차: 전자적 파일은 복구 불가능한 방법으로 삭제 (PIPA 제21조)
  • 국외 이전: 처리 위탁 업체와 소재 지역은 위 4항 목록을 따르며, 주로 미국입니다. 특정 국가로의 데이터 소재지는 보장하지 않습니다

불만 신고: 개인정보보호위원회(PIPC) · www.pipc.go.kr

Exercising Your Rights

Write to privacy@akaxa.io. We respond within the shortest applicable statutory period: 40 days for a Hong Kong access or correction request (PDPO s.19/s.23), 30 days under the GDPR (extendable by 60 days for complex requests, with notice), and 45 days under the CCPA (extendable once by 45 days, with notice).

8. Data Security

We implement industry-standard security measures: encryption in transit (TLS 1.2+), encryption at rest applied by our infrastructure providers (AES-256 or equivalent), Fernet symmetric encryption for sensitive fields such as API keys, role-based access controls (RBAC), monitoring, and audit logging. Multi-factor authentication is available in the product; we have no written policy enforcing it on administrative accounts and do not claim one. Breach notification is provided without undue delay and no later than 72 hours of becoming aware.

What we have not done yet: AKAXA is not SOC 2 certified and is not ISO 27001 certified, and no certification date is committed. Independent external security assessment and penetration testing are planned and have not yet been performed. We state this plainly here and in any security questionnaire rather than describing planned controls as operating ones.

9. Data Retention

  • Account data: duration of subscription + 1 year
  • User Data: subscription + 30 days (export) + 90 days (backup)
  • Usage logs: retention follows the hosting platform default; we have not yet set or enforced a defined period, and do not claim one
  • Payment records (none exist today): 7 years from creation, for tax and accounting compliance
  • Support communications: 3 years after final interaction

After retention expires, electronic files are deleted from AKAXA's object storage and database. AKAXA does not operate a cryptographic-erasure scheme and does not claim one; deletion is subject to each provider's own backup and retention behaviour, and audit rows are retained indefinitely today because no deletion task is scheduled.

10. Cookies

We use essential cookies for authentication and security. We do not use advertising or tracking cookies. You can decline non-essential cookies via our cookie banner. See our Cookie Policy.

11. Children

The Services are not directed at individuals under 18. We do not knowingly collect personal information from minors.

12. Changes to This Policy

Material changes that reduce privacy protections require 30 days' notice by email and in-app notification, with a right to terminate without penalty. Continued use constitutes acceptance of the updated policy. This version supersedes the version dated April 12, 2026; previous versions are available on request.

13. Contact

AKAXA — operated by its founders pending incorporation of AKAXA Limited (Hong Kong SAR)
Privacy enquiries: privacy@akaxa.io
Escalation: dpo@akaxa.io (no statutory Data Protection Officer has been appointed)
No acknowledgement service level is offered. Requests are handled by the founders within the statutory periods above; no request-handling process, queue or named owner exists yet, so a shorter commitment would be one AKAXA cannot stand behind.

AKAXA

Governed investment intelligence for private equity

Product

  • Product
  • Security
  • Request access

Company

  • Company

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Sub-processors
  • Cookie Policy
  • Do Not Sell My Info

© 2026 AKAXA. All rights reserved.

AI-generated analysis is for informational purposes only and does not constitute financial advice.