Security & Trust
Last updated: 2026-09-06
How Axively stores, processes and protects your data. This page summarises the key facts; full legal detail is in our Privacy Policy.
Data residency
Your data stays in the European Union. Our application servers and the PostgreSQL database run on a single dedicated server in the Czech Republic. We do not use a separate managed database or object-storage provider.
AI processing outside the EU
The configured AI provider (OpenAI or Anthropic, USA) receives flagged HTML snippets, URLs and element context for fix suggestions. Statement generation also sends the identity, address, contact and assessment details entered in the form. When an administrator requests an email translation, the selected message or reply is sent to that provider. These inputs may contain personal data. Check the content before sending; do not include secrets.
Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Huko.net | Application servers & PostgreSQL database | Czech Republic (EU) |
| OpenAI | AI fix suggestions and remediation translations | United States |
| Anthropic | AI fix suggestions and remediation translations (standby) | United States |
| Polar | Payment processing (Merchant of Record) | United States |
| efik.cz | Transactional email delivery | Czech Republic (EU) |
Data retention
Account data: kept for the life of your account; after closure we delete it within 90 days. Only data needed to defend legal claims is kept for the 3-year limitation period. Audit data: within 90 days after account closure, or immediately on request. Inactive accounts: after 24 months without a sign-in we notify you and then delete or anonymize the account. Billing and tax records: 10 years (legal obligation). Logs: 90 days.
Responsible disclosure
Found a security issue? Please report it to security@axively.com. We aim to acknowledge reports within 72 hours. Please don't publicly disclose a vulnerability until we have had a chance to address it.