AXSYS LLC (“AXSYS,” “we,” “us,” or “our”) creates, operates, and supports software products, SaaS applications, APIs, and deployments and provides commissioned engineering services. This Privacy Policy describes how we process personal information through axsysllc.com, api.axsysllc.com, the AXSYS customer portal and dashboard, and any AXSYS-operated product or service that links to this policy (collectively, the “Services”). It also covers business, project, support, and billing interactions with AXSYS.
A product that identifies a separate privacy policy is governed by that policy. When AXSYS processes personal information solely on behalf of a customer, that customer may control the information and its privacy notice or a separate data-processing agreement may also apply. External websites and portfolio links are governed by their own privacy practices.
1. Personal information we collect
Information provided to us
Depending on the interaction, we may collect:
- Contact and professional information, such as name, email address, company, role, telephone number, and billing or mailing details;
- Account and authentication information, such as an account email address, password submitted for authentication, account identifier, access permissions, and account settings;
- Project and relationship information, such as project requirements, status, milestones, deliverables, approvals, support history, customer contacts, and other information used to maintain an ongoing customer relationship;
- Billing and transaction information, such as subscription plan, invoice, payment status, transaction identifier, tax information, and billing-contact information;
- Communications, including contact-form submissions, support requests, attachments, correspondence, privacy requests, and feedback; and
- Customer Content, including files, instructions, credentials, data, or other materials a customer or authorized user submits to a Service or provides through a customer relationship.
Please do not provide regulated, highly sensitive, or legally restricted information unless AXSYS has agreed in writing to receive and process it.
Information from other sources
We may receive information from a customer organization that authorizes a user, from payment and infrastructure providers, from an integration a customer directs us to use, from professional advisers, or from public sources when reasonably necessary for a business relationship, security, compliance, or due diligence.
Information collected automatically
When a person uses a Service, we and our infrastructure providers may automatically collect technical and activity information such as IP address, browser and device type, operating system, request and response metadata, referring page, pages or endpoints requested, timestamps, general location derived from IP address, login and session events, security events, and diagnostic or network-error logs.
The public corporate website stores a theme preference in browser local storage. Authenticated areas use the secure session technology described below and in our Cookie Notice.
Payments
AXSYS uses payment processors, including Stripe. Payment-card and bank-account information entered in a processor-hosted flow is collected by the processor. AXSYS generally receives transaction, status, and billing details rather than a complete payment-card number or security code. The processor handles payment information under its own terms and privacy notice.
3. How we use personal information
We may use personal information to:
- Provide, operate, maintain, and secure the Services;
- Authenticate users and maintain authorized sessions;
- Administer customer accounts, ongoing projects, deliverables, support, business relationships, subscriptions, invoices, payments, and cancellations;
- Respond to business, support, billing, privacy, legal, and security inquiries;
- Communicate service, project, billing, account, and security information;
- Detect, investigate, and prevent fraud, abuse, unauthorized access, and other harmful or unlawful activity;
- Diagnose problems and improve the reliability, security, and functionality of the Services;
- Enforce agreements and protect AXSYS, customers, users, and third parties;
- Complete a corporate transaction or evaluate one; and
- Comply with legal obligations and valid legal requests.
We may create aggregated or de-identified information that does not reasonably identify a person or customer. We may use that information for security, reliability, service improvement, and lawful business analysis. We do not attempt to reidentify de-identified information except to test whether de-identification measures work as intended or as otherwise permitted by law.
4. How we disclose personal information
We may disclose personal information to:
- Service providers supporting hosting, content delivery, application infrastructure, security, communications, support, document delivery, and other business operations. Cloudflare supports website delivery, security, email-address protection, request handling, and network reporting;
- Payment processors, including Stripe, for billing, payment, fraud prevention, and transaction administration;
- Customer organizations and authorized users when information relates to their account, project, contract, billing, or authorized use;
- Integrations and third parties directed by a customer when the customer enables, requests, or authorizes a connection or disclosure;
- Professional advisers, such as legal, accounting, insurance, and financial advisers, when reasonably necessary and subject to appropriate duties;
- Authorities and other parties when reasonably necessary to comply with law or legal process, enforce agreements, prevent harm, investigate wrongdoing, or protect rights, safety, security, and the integrity of a Service; and
- Transaction participants in connection with an actual or proposed financing, merger, acquisition, reorganization, sale of assets, insolvency, or transfer of a product or business.
AXSYS does not sell personal information for money. AXSYS does not share personal information for cross-context behavioral advertising, use it for targeted advertising, or disclose it to data brokers.
5. Retention
The axsess session token remains valid for no more than seven days after it is issued or renewed. Other retention periods vary by the nature of the information and relationship. We generally retain account, project, communication, and Customer Content information while needed to provide the applicable Service or maintain the customer relationship; billing and transaction records for applicable accounting, tax, fraud-prevention, and legal periods; and technical or security records for the period reasonably necessary to protect and diagnose the Services.
We consider the amount, nature, and sensitivity of the information; the purposes for processing it; security and fraud risks; contractual requirements; and applicable law. When information is no longer reasonably required, we may delete it, de-identify it, or isolate it from further use. Backup copies and records subject to a legal hold may remain for a limited additional period.
6. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information and the size and operations of the business. Authentication sessions use a secure HTTP-only token cookie so ordinary browser scripts cannot read the token. No system, storage method, or transmission can be guaranteed to be completely secure.
Users are responsible for protecting their credentials, using only authorized accounts, signing out or securing their devices when appropriate, and promptly reporting suspected unauthorized access to support@axsysllc.com.
7. International processing
AXSYS is based in the United States. Information may be processed in the United States or another location where AXSYS or a service provider operates. Privacy laws in those locations may differ from the laws where a person lives. Where applicable law requires a transfer mechanism or additional protection, we will use an appropriate mechanism for the applicable processing.
8. Choices and state privacy rights
A person may unsubscribe from a non-transactional email by using the instructions in that email. We may continue to send account, project, billing, security, legal, and other service-related messages.
Depending on applicable law, a person may have rights to request information about our processing; access or obtain a copy of personal information; correct inaccurate information; delete information; obtain portable information; opt out of certain processing; limit certain uses of sensitive information; or appeal a decision concerning a request. These rights are not absolute and may not apply to every person or every type of information.
We do not use personal information for targeted advertising, sell it, share it for cross-context behavioral advertising, or use it for profiling that produces legal or similarly significant effects. We do not use sensitive personal information to infer characteristics about a person.
A request may be sent to support@axsysllc.com. Please describe the requested action and the Service or relationship involved. We may verify identity, authority, account ownership, or residency before acting. Where applicable law permits an authorized agent, we may request evidence of the agent’s identity and authority and may confirm the request directly with the person concerned. An appeal of a denied request may be sent to the same address with “Privacy Appeal” in the subject line.
We do not discriminate against a person for exercising a privacy right protected by law. AXSYS may retain information when permitted or required by law, including for security, fraud prevention, recordkeeping, dispute resolution, and legal compliance.
9. Customer-controlled information
An AXSYS customer organization may administer authorized users, project participants, billing contacts, and information submitted for its account or project. A request concerning information controlled by that organization may need to be directed to the organization. When AXSYS acts as its service provider or processor, we may refer the request to the customer or assist the customer as required by the applicable agreement and law.
10. Other sites and services
The Services may link to websites, applications, products, or integrations operated by third parties. A link does not mean AXSYS controls or endorses the third party. The third party’s terms and privacy practices govern its service, and we encourage users to review them.
11. Children
The Services covered by this policy are not intended for anyone under 18 years of age, and AXSYS does not knowingly collect personal information from children. We do not knowingly sell or share the personal information of anyone under 16. A parent or guardian who believes a child provided personal information contrary to this policy may contact us. If we learn that we collected information from a child in a manner prohibited by law, we will take appropriate steps to delete it.
12. Changes to this policy
We may update this policy to reflect changes in the Services, our practices, or legal obligations. We will post the revised policy and update the effective date. If a change is material, we may provide additional notice through the applicable Service, account, dashboard, or email when appropriate. A revised policy applies prospectively from its stated effective date unless the notice says otherwise.
13. Contact us
Privacy questions, requests, and concerns may be sent to support@axsysllc.com. To help us route a request, include “Privacy” in the subject line and identify the relevant product, account, project, or interaction without sending a password, complete payment-card number, or other unnecessary sensitive information.