Legal · Privacy

Privacy policy

This is one policy in two halves, because Naxis wears two hats. For this website and your Naxis account (including the live demo), Naxis Technologies is the controller: we decide what is collected and answer for it. For Naxis Assistant deployments, the client company is the controller and Naxis acts, at most, as a processor under a signed Data Processing Agreement. Both halves are written to be checked, not skimmed.

The website

Cookies and tracking. This website runs no analytics and no third-party scripts; fonts and all other assets are served from this domain. The only cookie it can set is the strictly-necessary session cookie that keeps you signed in to your account; browsing signed-out sets none at all. There is nothing to consent to because there is nothing optional running.

Server logs. The hosting provider keeps standard web-server access logs (IP address, requested page, time) for security and operations. We read them when something breaks or someone attacks, not to profile visitors.

Writing to us. The contact form is an account action: your message, name and company travel with your account email to our mailbox at info@naxistechnologies.com and are used only to answer you (legal basis: taking steps at your request before a contract, GDPR art. 6(1)(b), or our legitimate interest in answering correspondence, art. 6(1)(f)). Enquiry mail is kept as ordinary business correspondence and is not added to marketing lists.

Your Naxis account

What it holds. Email, name, company, a password hash and/or your Google identity (see below), your newsletter choice, subscriptions, support threads, document requests and, if you join one, your team workspace membership. We use this to run the service you asked for and to reach you about it (art. 6(1)(b)).

Sign-in with Google. "Continue with Google" sends us exactly three things from Google, over a direct server-to-server exchange: your verified email address, your name and Google's stable account identifier. No Google scripts run on our pages, and we receive no contacts, files or anything else from your Google account.

Newsletter. Product news goes only to accounts that keep the switch on (consent, art. 6(1)(a)); every email carries an unsubscribe, and the switch lives under Settings.

Team workspaces. If you invite colleagues (or accept an invitation), the members of the workspace see each other's names, emails, support threads and document requests. That visibility is the feature; leaving the workspace ends it forward-looking.

Billing. Payments run through Stripe, our payment processor. Your card number never touches our servers; Stripe tells us who paid for what, and we keep the subscription record and invoices (retained as accounting records for as long as tax law requires, art. 6(1)(c)).

Your rights, self-service. Under Settings → Privacy & data you can export everything your account is as one JSON file (arts. 15 and 20) and delete the account (art. 17), both immediate and automatic, no request form and no waiting. Deletion removes the account, its sessions and its demo records; support threads you wrote to our mailbox may survive as our business correspondence. Rectification is Settings too: name, company, email (with confirmation to the new address). For anything the buttons do not cover, write to info@naxistechnologies.com.

The interactive demo

The demo at demo.naxistechnologies.com is entered through this website with your account. You agree to this recording when you create the account (this policy is part of that agreement), and the date of your first entry is recorded. While you use the demo we record, linked to your account: your IP address and country, how you move through the guided tour (steps and time on each), which demo documents you open and for how long, and the exact questions you ask with the answers you receive. Legal basis: your consent, given at account creation (GDPR art. 6(1)(a)).

We use this solely to understand how prospective customers explore the product, never for advertising, never shared with anyone. Chat logs and detailed timings are erased after 90 days, the visit record after 12 months; deleting your account erases all of it immediately. Withdraw consent any time by emailing info@naxistechnologies.com, recording stops with your next visit and past records are erased on request. The demo's documents are fictional; nothing you upload or connect is involved (the demo accepts neither).

Naxis Assistant deployments (the product)

Who answers for what. A deployment processes the client company's documents and its people's questions. For all of that, the client is the controller. Naxis is a processor only where we actually touch something: operating managed hosting, running the Naxis AI service where a deployment uses it, and support access when it is granted. Every deployment is covered by a Data Processing Agreement; each one also generates its own GDPR Article 30 record of processing from its live configuration, so the paperwork cannot drift from reality.

Where the data lives. Each client runs a single-tenant deployment: own instance, own database, own document store, on the client's servers or in an EU data centre under our management. Documents, the search index, conversations and the audit log never leave the deployment. Nobody at Naxis reads inside a client's instance without a consent the client grants per support ticket, and that consent is recorded.

The AI boundary. Indexing runs entirely inside every deployment. The fullest configuration keeps generation home too: a self-hosted deployment answering on a self-hosted, open-weight AI model, where nothing leaves the client's boundary at all. Deployments that use the Naxis AI service instead send only the question and the permission-filtered excerpts needed to answer it, under zero-retention terms: nothing is stored after the answer returns, nothing trains any model, and no personal identity of the asker accompanies the request.

What reaches Naxis from a running deployment. Operational signals only: version, health, and aggregate counters (documents indexed, questions answered, allowance used) so that plans, updates and support work. No document content, no question text, no personal data of the client's people rides a heartbeat.

Rights inside a deployment. The product implements them as mechanisms for the client: self-service data export for every signed-in person, hard-delete erasure that removes records from store and search index alike, and a tamper-evident audit log. If you are an employee of a Naxis client, your controller is your employer; exercise your rights with them, the product gives them the buttons.

The record-keeping

Sub-processors. For the website and accounts: our hosting provider (site and database) and Stripe (payments), plus Google only if you choose to sign in with it. For deployments: at most the Naxis AI service and, for managed hosting, an EU data-centre provider; a self-hosted deployment with self-hosted AI has none. Changes follow the DPA's written notice procedure.

Retention, in one place. Account data lives while the account does. Sessions expire on their own. Demo chat logs: 90 days; demo visit records: 12 months. Invoices: statutory accounting periods. Support threads: while the account or the deployment they belong to lives. Server logs: the hosting provider's standard short window.

Security. The controls are described, in the open, on the Security & Compliance page: single-tenant isolation, permission checks inside every query, a hash-chained audit log, signed releases, throttled sign-in surfaces. This policy inherits all of it.

Complaints. If you believe we handle your data wrongly, tell us first and we will fix it. You also have the right to complain to a supervisory authority; for Greece that is the Hellenic Data Protection Authority (dpa.gr).

Changes. When this policy changes materially, the change is dated here and account holders are notified by email.

Contact. Privacy questions: info@naxistechnologies.com.