Privacy notice
Last updated 17 September 2026
Two different roles
For our own visitors, signups and clients, we decide how information is used — we are the controller. For patient information inside a client’s workspace, the agency or hospital decides; we only process it on their instructions. If you are a patient, contact the organisation whose branded page you used; we will pass on any request we receive directly.
What we collect
- Account details: name, work email, organisation, role.
- Workspace content your team enters: enquiries, cases, messages, documents, prices, bookings.
- Patient details a patient gives an organisation: contact details, condition described, reports, passport and visa information.
- Usage records: pages opened, actions taken, AI credits spent, emails sent — used to run and secure the service.
Why we use it
To provide the workspace, send the alerts and notifications you ask for, prepare estimates and summaries, take payment for credits, prevent abuse, and improve the product. We do not sell personal information, and we do not use patient information to advertise to anyone.
Artificial intelligence
Some features — the intake assistant, document reading, case summaries and comparisons — send the relevant text to an AI model to produce a draft. Those drafts are reviewed by your team before a patient sees them. The model providers we use do not train their models on this content. Where a case does not need it, patient identifiers are left out of the request.
Who else sees it
Only the service providers we need to run the platform: our cloud hosting and database provider, our email sending provider, and our AI model provider. Each is bound by contract to use the information only to provide their service. We do not share workspace content between client organisations, ever.
Where it is kept and for how long
Data is hosted on managed cloud infrastructure with encryption in transit and at rest. Workspace content is kept while the workspace is active, and for 30 days after closure so it can be exported, then deleted. Notification and audit records are kept for up to 24 months for security and dispute handling.
Your choices
You can ask for a copy of your information, ask us to correct it, ask us to delete it, or object to a particular use. Client admins can export their workspace themselves. Marketing emails always carry an unsubscribe link, and unsubscribing is permanent.
Contact
Privacy questions: privacy@axiom-ai.in. See also our data processing terms.