Privacy notice

Last updated 17 September 2026

Two different roles

For our own visitors, signups and clients, we decide how information is used — we are the controller. For patient information inside a client’s workspace, the agency or hospital decides; we only process it on their instructions. If you are a patient, contact the organisation whose branded page you used; we will pass on any request we receive directly.

What we collect

  • Account details: name, work email, organisation, role.
  • Workspace content your team enters: enquiries, cases, messages, documents, prices, bookings.
  • Patient details a patient gives an organisation: contact details, condition described, reports, passport and visa information.
  • Usage records: pages opened, actions taken, AI credits spent, emails sent — used to run and secure the service.

Why we use it

To provide the workspace, send the alerts and notifications you ask for, prepare estimates and summaries, take payment for credits, prevent abuse, and improve the product. We do not sell personal information, and we do not use patient information to advertise to anyone.

Artificial intelligence

Some features — the intake assistant, document reading, case summaries and comparisons — send the relevant text to an AI model to produce a draft. Those drafts are reviewed by your team before a patient sees them. The model providers we use do not train their models on this content. Where a case does not need it, patient identifiers are left out of the request.

Who else sees it

Only the service providers we need to run the platform: our cloud hosting and database provider, our email sending provider, and our AI model provider. Each is bound by contract to use the information only to provide their service. We do not share workspace content between client organisations, ever.

Where it is kept and for how long

Data is hosted on managed cloud infrastructure with encryption in transit and at rest. Workspace content is kept while the workspace is active, and for 30 days after closure so it can be exported, then deleted. Notification and audit records are kept for up to 24 months for security and dispute handling.

Your choices

You can ask for a copy of your information, ask us to correct it, ask us to delete it, or object to a particular use. Client admins can export their workspace themselves. Marketing emails always carry an unsubscribe link, and unsubscribing is permanent.

Contact

Privacy questions: privacy@axiom-ai.in. See also our data processing terms.