Skip to main content

Privacy Policy

Last updated on 15 Aug 2026

This Privacy Policy explains how Axomaly, a service operated from South Africa, collects, uses, stores, and protects information when you visit our website, join the alpha, or use our anomaly detection services.

Axomaly is not currently operated through an incorporated legal entity. This policy will be updated when the operating entity is established.

1. Scope

This policy applies to the Axomaly website, alpha-access programme, account experience, dashboard, API, and related communications. It does not govern third-party products or websites that may link to or integrate with Axomaly.

2. Information We Collect

2.1. Alpha access information: When you join the alpha, we collect your email address and information associated with delivering and managing alpha communications.

2.2. Account information: If you create an account, we may collect your name, email address, organisation name, account settings, and authentication-related information.

2.3. Customer metric data: When you use the API, we process the metric values, timestamps, and optional metadata that your organisation submits for anomaly detection.

2.4. Service and security data: We may collect API request details, response times, error logs, IP addresses, device or browser information, and security events required to operate, troubleshoot, and protect the service.

2.5. Website analytics and abuse prevention: When enabled, our website uses Google Analytics to understand website usage. The alpha signup uses Google reCAPTCHA to help prevent automated abuse. These services may process technical information according to their own privacy terms.

Please avoid including personal, confidential, or sensitive information in metric metadata unless it is necessary, lawful, and appropriate for your use of Axomaly.

3. How We Use Information

We use collected information to:

  • Provide, maintain, secure, and troubleshoot Axomaly
  • Process submitted metric values and return anomaly detection results
  • Manage alpha access and communicate service information
  • Understand website and service performance
  • Prevent fraud, abuse, and unauthorised access
  • Comply with applicable legal obligations

Depending on the context and applicable law, processing may be necessary to provide the service you requested, support our legitimate operational and security interests, comply with legal obligations, or act with your consent where consent is requested.

4. Customer Data Isolation and Use

Customer metric data is isolated by organisation. One customer’s data is not shared with or exposed to another customer.

For the immediate future, customer metric data is used only to provide and improve the service for the organisation that submitted it. We do not use customer metric data, including anonymised or aggregated derivatives of that data, to train or improve global models shared across customers.

You retain ownership of the data your organisation submits to Axomaly.

5. Sharing and Service Providers

We do not sell or rent personal information or customer metric data.

We may disclose limited information to service providers that help us operate Axomaly, including:

  • Cloud infrastructure and hosting providers
  • Resend for alpha signup and service email delivery
  • Google Analytics, when enabled, for website analytics
  • Google reCAPTCHA for signup abuse prevention

These providers process information to deliver their services to us and may operate under their own privacy terms. We may also disclose information when required by law, to respond to lawful requests, to protect the service or its users, or as part of a future business reorganisation subject to applicable protections.

6. Hosting and International Processing

Axomaly is operated from South Africa. Customer metric data is hosted in the European Union. Other information may be processed in South Africa, the European Union, or locations where our service providers operate.

If Axomaly later adds infrastructure in other regions, this policy will be updated to reflect material changes to where customer data is processed.

7. Security

Axomaly uses HTTPS/TLS to encrypt information in transit. We also use organisation-level data isolation, access controls, and operational safeguards intended to protect information from unauthorised access, loss, or misuse.

No internet transmission or electronic storage method is completely secure. We therefore cannot guarantee absolute security.

8. Retention and Deletion

Customer metric data may be retained for up to 12 months to support behavioural baselines, historical analysis, and anomaly detection. This retention operates on a rolling basis, with data removed as it moves beyond the applicable 12-month period.

Alpha signup information, account information, service logs, and security records are retained only for as long as reasonably required for the purpose for which they were collected, to operate the service, resolve disputes, enforce agreements, or comply with applicable law.

You may request deletion of your personal information by contacting us. Information will be deleted or de-identified when it is no longer required or authorised to be retained, subject to applicable legal obligations.

9. Your Choices and Rights

Depending on applicable law, you may have rights to:

  • Ask whether we hold personal information about you
  • Request access to or correction of your personal information
  • Request deletion or restriction of certain processing
  • Object to certain uses of your personal information
  • Withdraw consent where processing is based on consent
  • Opt out of non-essential communications

To exercise a privacy right or ask a data-handling question, email support@axomaly.com. We may need to verify your identity before completing a request.

10. Third-Party Services

Axomaly may link to or operate alongside third-party services. We are not responsible for the privacy practices of third parties that we do not control. Please review their privacy information before providing data directly to them.

11. Children’s Privacy

Axomaly is a business service and is not intended for children or anyone under 18. We do not knowingly collect personal information directly from children through the service. If you believe a child has provided personal information to Axomaly, contact us so that we can investigate and take appropriate action.

12. Changes to This Policy

We may update this policy when our service, data practices, providers, or legal obligations change. We will publish the updated policy on this page and revise the effective date. Material changes may also be communicated through the service or by email where appropriate.

13. Contact

For privacy questions, access requests, correction requests, or deletion requests, contact:

This Privacy Policy is effective from August 15, 2026.