Effective July 2026

Privacy Policy

This policy explains what data Axorea collects, how it is stored and used, and the rights you have over it. We have kept it in plain language on purpose.

1. Who we are

Axorea (“we”, “us”) is a società semplice under Swiss law, based in Lugano, Switzerland. We provide an automated receptionist: a chat widget that businesses embed on their websites to answer customer questions and capture inquiries, plus a dashboard where those businesses manage their answers and leads.

For everything related to axorea.io itself — our website, the contact form, business accounts, and billing — Axorea is the data controller within the meaning of the Swiss Federal Act on Data Protection (nFADP) and the EU GDPR. For questions about this policy or your data, write to info@axorea.io.

2. Two roles: controller and processor

When you chat with the widget on a business’s website, that business decides what the receptionist knows and receives the details you leave. In data-protection terms, the business is the data controller of that data and Axorea is its data processor: we process it only on the business’s behalf, to provide the service, under the data-processing terms in our Terms of Service.

When you use our own website — for example the contact form, the signup flow, or the live demo on axorea.io — Axorea is the controller.

3. What we collect

From visitors who use the widget on a business’s website:

  • Conversation content — the messages you exchange with the widget, so the business can follow up on your inquiry.
  • Contact details you submit — name, email address, and optionally a phone number, when you choose to leave them (for example to request a booking or a quote), together with the address of the page the widget was used on and the language of the conversation.

From the businesses that subscribe to Axorea:

  • Account data — your name, business name, email address, and login credentials (passwords are stored only in securely hashed form).
  • Billing data — handled by Stripe, our payment processor. Card details are entered on Stripe’s pages and never reach our servers; we store only a reference to your Stripe customer and subscription and your plan status.

From visitors of axorea.io:

  • Contact form submissions — the details you type into the form (name, email, business details, your message).
  • Technical data — IP addresses are processed transiently to protect our APIs against abuse (rate limiting) and appear in our hosting provider’s standard request logs. We run no analytics or advertising trackers.

We do not collect data from the widget silently: conversation content exists only because you typed it, and contact details are only saved when you submit them.

4. How we use it, and on what legal basis

  • To generate the widget's replies from the information the business has provided.
  • To notify the business owner by email when you leave your details as an inquiry (a "lead"), including a short summary of what you asked for.
  • To show the business its own conversations and leads in its dashboard.
  • To create and manage business accounts, subscriptions, and payments.
  • To respond to messages you send us through the contact form.
  • To operate, secure, and improve the service.

Our legal bases for this processing are:

  • Performance of a contract — for the account, subscription, and billing data of the businesses that subscribe to Axorea, and for handling inquiries that precede a contract.
  • The business’s instructions — for conversation content and lead details collected through the widget, which we process as the business’s processor. The business’s own legal basis is typically its legitimate interest in answering the inquiries its customers choose to send it.
  • Legitimate interest — for securing the service (such as rate limiting and abuse prevention) and improving it.

We do not sell personal data. We do not share it with third parties for advertising or marketing.

5. Where it is stored

Conversation data, leads, and account data are stored in our database hosted with Supabase on servers located in the European Union (Ireland). Data is encrypted in transit, and each business’s data is isolated from every other business’s at the database level.

Some of our providers may process data outside Switzerland and the EU. Where they do, we rely on their published data-processing terms, which provide recognised safeguards such as the EU Standard Contractual Clauses, and we only pass them the data required for their function.

6. Service providers

We use a small number of providers to run the service, and share with them only what is necessary for their function:

  • Supabase — database, authentication, and storage: conversation content, leads, knowledge bases, and account data live here.
  • Groq — processes conversation text (your message, the recent conversation, and the business’s own information) to generate the widget’s automated replies and lead summaries. We have enabled Groq’s zero-data-retention settings for our account: conversation text is processed only to generate the reply, is not stored by Groq, and under Groq’s terms is never used to train models.
  • Resend — delivers transactional email. Lead notifications (name, contact details, inquiry summary) and contact form messages pass through Resend to reach their recipient.
  • Stripe — payment processing for subscriptions. Stripe receives the billing name, email, and payment details of subscribing businesses and is responsible for card-data (PCI DSS) compliance.
  • Vercel — hosts the website and application, and therefore processes the technical request data (such as IP addresses) needed to serve it.

7. Cookies and local storage

The widget does not use tracking cookies. It stores a single random session identifier in your browser’s sessionStorage, which keeps your conversation together while the tab is open and is deleted automatically when you close it. It is not used to track you across sites or sessions.

The dashboard uses strictly necessary authentication cookies so business users can stay logged in. Our marketing site sets no analytics or advertising cookies. Because we set no cookies that require consent, axorea.io shows no cookie banner — there is nothing to consent to.

8. How long we keep it

Conversations and leads are kept so the business can follow up on them, for as long as the business’s account is active or until the business deletes them or asks us to. Contact form messages are kept as long as needed to handle your request. When an account is closed, its data is deleted; billing records are kept only as long as Swiss commercial and tax law requires.

9. Your rights

Under the Swiss Federal Act on Data Protection (nFADP) and, where it applies, the EU GDPR, you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Have inaccurate data corrected.
  • Have your data deleted.
  • Object to or restrict certain processing.
  • Receive your data in a portable format.

To exercise any of these rights, email info@axorea.io. We respond within 30 days. If your data was collected through a business’s widget, the fastest route is usually to contact that business directly — but you can also write to us and we will help. You can also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.

10. Data breaches

If a data breach occurs that is likely to result in a high risk to the people affected, we notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) as soon as possible, as the nFADP requires — and, where the GDPR applies, the competent supervisory authority within 72 hours where feasible. We also inform the affected businesses, and individuals where required, without undue delay.

11. Changes to this policy

If we change this policy, we will update this page and its effective date. Material changes will be communicated to our clients directly.