Data processing terms

Last updated 17 September 2026

Purpose

These terms apply when we handle personal information on your behalf inside your workspace. You are the controller of that information; we are the processor and act only on your documented instructions, which are the instructions given through the platform and in our agreement.

What is processed

  • Subject matter: running a medical travel workspace for your organisation.
  • Duration: while your workspace is active, plus 30 days.
  • People: your staff, your patients and their accompanying attendants.
  • Information: contact details, condition and treatment sought, medical reports and images, passport and visa details, travel and booking details, messages exchanged.

Our commitments

  • Process the information only for your workspace, never for our own purposes.
  • Keep everyone with access under a duty of confidentiality.
  • Isolate each organisation’s data at the database level so one client can never read another’s.
  • Encrypt data in transit and at rest, restrict internal access, and log administrative actions.
  • Help you answer requests from patients and, where required, from regulators.
  • Tell you without undue delay if your data is affected by a security incident.

Sub-processors

We use a managed cloud database and hosting provider, an email delivery provider, and AI model providers accessed through a single gateway. Each is engaged under written terms no weaker than these. We will tell you before adding a new category of sub-processor, and you may object on reasonable grounds.

International transfers

Patients and hospitals in this business are in different countries, so information may be processed outside the country where it was collected. Where that happens we rely on recognised transfer safeguards in our contracts with each provider.

Return and deletion

You can export your workspace at any time. On closure we keep the data for 30 days, then delete it from live systems, with backups ageing out within a further 30 days.

Audit

On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will answer a written security questionnaire and share the evidence we hold about our controls.

Contact

Data protection queries: privacy@axiom-ai.in. These terms sit alongside our terms of service and privacy notice.