ClaimTrace by AXIONYX.io Get a key

Data processing annex

Version 0.1 — 12 August 2026. Status: draft pending review by a Swiss lawyer.

The French version prevails: sous-traitance des données.

This annex forms an integral part of the terms of service. It applies whenever you have us process personal data using ClaimTrace. It rests on art. 9 nFADP (processing by a processor) and, for customers subject to the GDPR, reflects its usual requirements.

A signed counterpart can be issued on request for customers who need one.

1. Roles

You are the controller. AXIONYX.io Sàrl is the processor, for the sole operations needed to provide the Service: receiving your need, collecting publicly accessible content, structuring, verifying, caching and returning the result.

We process this data only to provide the Service, in accordance with the terms of service and this annex. We carry out only processing that you would be entitled to carry out yourself (art. 9 para. 1 let. a nFADP).

2. Subject matter, duration, nature

  • Subject matter: provision of an API of verified facts with provenance.
  • Duration: that of the contractual relationship, extended by the retention periods in article 5.
  • Nature of operations: collection, reading, extraction, structuring, verification, caching, communication of the result.

3. Data and data subjects

Categories concerned: factual data about professional entities — company name, address, opening hours, published offers and prices, business contact details, official accounts.

Possible data subjects: operators and staff of businesses, only to the extent their business contact details are published by the entity itself.

Exclusions by design:

  • no sensitive data within the meaning of art. 5 let. c nFADP — religious, philosophical, political or trade-union views, health, intimate sphere, racial or ethnic origin, genetic data, biometric data, prosecutions or sanctions, social assistance measures;
  • no profiling of natural persons;
  • no collection behind authentication;
  • no private contact details.

Any request manifestly aimed at a private individual is refused (see acceptable use).

4. Our obligations

  • Instructions. Process only to provide the Service. Inform you if an instruction appears to us to breach applicable law.
  • Security (art. 8 nFADP). Encryption in transit, hashed passwords (bcrypt), API keys as SHA-256 digests, access control, per-account partitioning, access logging, network protections against diverted outbound requests, security reviews before production.
  • Confidentiality. Persons authorised to process the data are bound by a confidentiality undertaking.
  • Assistance. Reasonable cooperation in responding to data subject requests (access, rectification, erasure), including propagating an erasure through the caches.
  • Breach notification. In the event of a data security breach, we inform you as soon as possible (art. 24 para. 3 nFADP), with the nature of the breach, its consequences and the measures taken or contemplated.
  • Sub-processors. List maintained in article 6, prior information on any change, with a reasonable right of objection on your side.
  • Documentation. On reasonable written request, at most once a year, we document our security measures.

5. Retention periods

DataPeriod
Verified-facts cache12 hours
Re-readable request results24 hours
Geocoding cache30 days
Technical usage log12 months
Application logs90 days
Accounting records10 years (art. 958f para. 1 CO)

6. Sub-processors

As at 12 August 2026.

ProviderRoleProcessing location
InfomaniakInfrastructure hostingSwitzerland
MongoDBDatabaseService region
AnthropicAI model — reading and interpreting sourcesUnited States
Serper.devWeb search (search engine results)Outside Switzerland
Google (Places API)Business discoveryOutside Switzerland
OpenStreetMap (Nominatim, Overpass)Geocoding and place discoveryEuropean Union
DuckDuckGoFallback web searchOutside Switzerland
StripePayment and billingEuropean Union / United States

Note on Google Places. This service is used for internal discovery of businesses. Fields derived from it — rating, review count, price level, photographs, review excerpts, Google identifiers — are excluded from the response served. The facts you receive come from the entity's own publications and, for geography, from OpenStreetMap.

Note on evaluation benches. Alternative AI models may be evaluated offline, in parallel, for internal comparison. Their outputs are never served to a customer.

Transfers outside Switzerland. Depending on the country, these rest on an adequacy decision of the Swiss Federal Council or on standard contractual clauses (art. 16 and 17 nFADP).

7. Pooling of verified facts

You are informed of, and accept, that verified facts — the factual datum and its provenance — are cached and served to several customers during their validity period. This pooling covers exclusively information published by the entities concerned.

Never pooled: the text of your requests, your parameters, your usage metadata and your billing.

8. End of contract

At the end of the contract we delete the data specific to you — keys, usage logs at the expiry of their period — subject to statutory retention obligations (art. 958f CO for accounting records). Pooled facts, which are independent of you and come from third-party publications, are not affected by that deletion.

9. Governing law

Swiss law. Jurisdiction: canton of Neuchâtel. This annex is subordinate to the terms of service and follows their fate.

Related documents: privacy policy · terms of service · legal notice