Privacy Policy
Last updated: August 3, 2026
AXIOM AI TECHNOLOGIES LTDA, enrolled with CNPJ under no. 67.136.348/0001-81 ("Axiom", "we", or "us"), is the controller of personal data processed through Axiom Coworker, except when we act as a processor on behalf of a customer organization.
This Policy explains how we process data on tryaxiom.work, the web console, connected channels, and Axiom Coworker integrations. Questions and requests may be sent to privacy@tryaxiom.ai.
1. Data we process
- Registration and authentication data, such as name, email address, profile picture, account and organization identifiers, and login method.
- Messages, instructions, files, and other content submitted to Coworker, together with outputs required to perform the requested work.
- Data from connected tools, only within the permissions granted by the user or organization.
- Technical and usage data, such as IP address, browser, device, date and time, security events, audit records, and diagnostics.
- Commercial relationship, support, and billing data when applicable to the agreement with the organization.
2. Google user data
When you sign in with Google, we receive the basic information authorized on the consent screen, such as your name, email address, profile picture, and Google account identifier, to authenticate and secure your account.
If you connect Google Drive, Docs, Sheets, Gmail, or another Google service to Coworker, we access only the scopes presented to and authorized by you. We use that data to find, read, create, edit, or send content solely when needed to provide the requested feature or carry out your instruction.
We do not sell Google user data, use it for advertising, or transfer it to build advertising or credit profiles. Human access is limited to cases required for security, user-requested support, legal compliance, or with explicit consent.
OAuth credentials for integrations are kept in managed vaults and are not stored in plain text in Axiom's database. You can revoke access in your Google Account settings or disconnect the integration in Axiom.
Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Google API Services User Data Policy3. How we use data
- Provide, operate, and personalize Coworker for the user and their organization.
- Carry out authorized instructions and actions in connected tools.
- Authenticate users, maintain sessions, and prevent fraud, abuse, and unauthorized access.
- Provide support, diagnose failures, and improve product reliability, security, and experience.
- Maintain audit records and comply with contractual, regulatory, and legal obligations.
- Send operational messages and, where permitted, commercial communications with an unsubscribe option.
4. Legal grounds
We process data under Brazil's Law No. 13,709/2018 (LGPD) based on performance of a contract and preliminary procedures, compliance with legal obligations, regular exercise of rights, legitimate interests, fraud prevention, and consent where required. When a customer organization determines the purposes of processing, it is the controller and Axiom acts as a processor under its instructions.
5. Sharing and service providers
We share data only as needed to deliver the service with contracted providers for authentication, cloud infrastructure, databases, storage, communications, observability, support, and AI processing. Providers receive only the data needed for their function and are subject to contractual security and confidentiality obligations.
We may also share data to comply with law or a valid authority order, protect rights and safety, or complete a corporate transaction with appropriate safeguards. We do not sell personal data.
6. International transfers
Some providers may process data outside Brazil. In those cases, we use contractual mechanisms and safeguards compatible with the LGPD to protect data during transfer and processing.
7. Security
We apply technical and organizational controls proportionate to risk, including access restrictions, encryption in transit, organization-level isolation, audit records, and human confirmation for sensitive actions. No system is completely immune from incidents, so we monitor risks and maintain response processes.
8. Retention and deletion
We retain data for as long as needed to provide the service, perform the agreement, and meet legal, audit, and security obligations. Periods vary by category, organization settings, and legal requirements. Data is then securely deleted or anonymized unless retention is legally required.
When an integration is disconnected, we stop using its credentials for new access. Copies already included in required records may remain for the applicable retention period.
9. Your LGPD rights
You may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, review of automated decisions, and withdrawal of consent where applicable. Send requests to privacy@tryaxiom.ai. We may verify your identity before responding.
10. Cookies and similar technologies
We use cookies and local storage required for authentication, security, preferences, and product operation. Optional analytics or marketing technologies, when used, will be presented as required by applicable law.
11. Children
The service is intended for professionals and organizations and is not directed to children. We do not knowingly collect children's data without an appropriate legal basis and required authorization.
12. Changes and contact
We may update this Policy to reflect changes to the product, law, or our processing practices. The current version will be posted on this page with its update date. Contact: privacy@tryaxiom.ai. Address: Avenida Brigadeiro Faria Lima, 1811, Sala 1119, Jardim Paulistano, São Paulo/SP, postal code 01452-001, Brasil.