Legal
Privacy controls built for GDPR work.
AXL supports GDPR-compliant processing with EU hosting, a Data Processing Addendum, SCCs, documented sub-processors and a clear rights process. Your own setup and use still have to follow the law.
What the current notice commits to.
| The question | What the policy says |
|---|---|
| AXL's role | AXL is the controller for its Sites, account administration and direct customer relationships. For learner, lead and contact data placed in AXL by a Customer, the Customer is the controller and AXL is the processor. |
| Legal basis | The Notice maps processing to contract performance, legitimate interests, consent and legal obligations under GDPR Article 6. |
| Where data is hosted | Platform data and backups are hosted in AWS Frankfurt, Germany, in the eu-central-1 region within the EEA. |
| International transfers | Operational access can occur from the United States, United Kingdom and Canada. Transfers are covered by adequacy decisions where available, EU SCCs, the UK Addendum and supplementary safeguards. |
| Sub-processors | AXL publishes a current sub-processor list. Providers are bound by written data-protection obligations. |
| Retention | Active account data is kept for the life of the account plus 30 days. Backups can remain for up to 90 days. Security telemetry is generally kept for up to 12 months, with category-specific periods in the Notice. |
| Sale and advertising | AXL states that it does not sell or share personal data for cross-context behavioural advertising. Mobile numbers and SMS opt-in data are not shared for third-party marketing. |
| Your rights | Access, correction, deletion, restriction, portability, objection and withdrawal of consent are covered. Send a request to privacy@axl.tech. The stated response period is one month, extendable for complex cases. |
| Security measures | TLS 1.2+ in transit, AWS KMS encryption at rest, MFA for personnel with production access, role-based access, logging, monitoring and vendor due diligence. More context is on the security page. |
| EU representation | Prighter Group in Vienna is named as AXL's EU Representative under Article 27 GDPR. The Notice also identifies the AEPD and UK ICO as relevant supervisory authorities. |
Checked against AXL Privacy Notice version 1.2 on 28 August 2026. The published Notice governs.
AXL supports GDPR compliance.
The contract and platform controls cover AXL's side of the controller-processor relationship. Customers remain responsible for lawful collection, notices, consent and how they configure the product.
- •DPA included. It applies automatically where a controller-processor agreement is required. Enterprise customers can request a counter-signed copy.
- •EU data hosting. Platform data and backups are hosted in AWS Frankfurt.
- •Transfer safeguards. The DPA incorporates EU SCCs Module Two and the UK Addendum.
- •Rights workflow. AXL documents how to exercise GDPR rights and gives privacy@axl.tech as the direct contact.
For a DPA, SCCs, a transfer assessment or a privacy request, write to privacy@axl.tech.