ClaimTrace by AXIONYX.io Get a key

Privacy policy

Version 0.1 — 12 August 2026. Status: draft pending review by a Swiss lawyer.

The French version prevails: politique de confidentialité.

This policy describes how AXIONYX.io Sàrl handles personal data in connection with ClaimTrace. It is drafted under the Swiss Federal Act on Data Protection (nFADP, SR 235.1) and, for customers established in the European Union, under the GDPR.

1. Controller and general principle

Controller: AXIONYX.io Sàrl, business identification number CHE-396.139.818, canton of Neuchâtel, Switzerland. Details: legal notice.

All processing is lawful, carried out in good faith and proportionate (art. 6 nFADP). We apply data minimisation: we collect only what the Service needs to operate and to be billed.

2. Our two roles, not to be confused

We are the controller for data relating to your account, your billing and your use of the website.

We are a processor for any personal data you have us process by using the Service. By design, the Service targets factual data about professional entities — company name, address, opening hours, published offers and prices, published business contact details. It builds no profiles of natural persons and collects no private contact details. Where your use nonetheless involves personal data, you are the controller and we act on your instructions, under the data processing annex.

3. Data we process

3.1 Account

DataStatusNote
Email addressRequiredAccount identifier, verified by link
PasswordRequiredStored hashed with bcrypt and salt — never in clear
CompanyOptional
Use-case descriptionOptionalHelps us qualify the need

3.2 API keys

We keep a SHA-256 digest of each key and a display prefix. The full value is shown once, at creation, and is never stored: we are technically unable to retrieve it. Also associated with the key: its plan, credit balance, creation date and, where applicable, its revocation.

3.3 Billing

Purchase history, customer identifier at the payment provider, amounts and dates. No card data passes through or is stored on our servers — entry happens directly with the provider.

3.4 Use of the Service

For each request: the need and location submitted, the number of entities handled, processing duration, an internal cost indicator and the label of the key used. These serve billing, diagnostics and abuse prevention.

The full results of a request (entities, facts, verbatim excerpts and source URLs) are kept temporarily so you can read them again.

3.5 IP address — what we do not do

Your IP address is used in memory only, for the time needed to apply anti-abuse limits at signup and login. It is never written to a database and is linked to no account.

3.6 Website: no cookies, no analytics

We set no cookies. We use no audience measurement tool, no advertising tracker, no social network pixel. There is therefore no consent banner, because there is nothing to consent to.

The site uses your browser's local storage, first-party:

KeyPurpose
ct_langRemembers your language choice
ct_api_keyKeeps your key in the client area, on your device only
ct_requestsLocal history of your trials in the client area

This data stays on your device, is not transmitted to us, and can be erased at any time by clearing the site's storage in your browser. Because ct_api_key keeps your key on the device, avoid the client area on a shared machine.

One reservation, stated plainly: the site's fonts are currently loaded from Google Fonts. Your browser therefore issues a request to Google's servers, which receive your IP address in the process. We intend to self-host these fonts to remove that transfer.

4. Why we process this data

PurposeLegal basis
Create and manage your account, provide the ServicePerformance of the contract
Count credits, invoice, produce accounting recordsPerformance of the contract and legal obligation
Prevent abuse, fraud and overload (limits, anti-abuse)Legitimate interest in protecting the Service and its users
Diagnose incidents and improve reliabilityLegitimate interest in the proper operation of the Service
Send you messages necessary to the Service (verification, activation, incidents, changes to terms)Performance of the contract
Comply with a legal obligation or a competent authorityLegal obligation
Establish or defend our rightsLegitimate interest

We do not use your data for advertising and we neither sell nor rent it to anyone.

5. Retention periods

DataPeriod
Account (email, hashed password, company, use case)For as long as the account exists
Client-area session token7 days
Email verification token24 hours, single use
Verified-facts cache12 hours
Re-readable request results24 hours
Geocoding cache (place → coordinates)30 days
Technical usage log (need submitted, location, duration, key label)12 months
Application logs90 days
Payment provider events90 days
Accounting and billing records10 years, under art. 958f para. 1 of the Swiss Code of Obligations

6. Deleting your account, and what remains

You can delete your account from the client area. We then revoke all your keys and erase the password, company, use case and payment-provider identifier.

What remains, and why: accounting records relating to your purchases are kept for ten years, as the law requires (art. 958f CO). Technical logs are erased when their own period expires.

Note: after deletion, re-registration with the same email address is not automatic. Write to us if you would like to come back.

7. Who data is shared with

We use the following providers. None is permitted to use your data for its own purposes.

ProviderRoleProcessing location
InfomaniakInfrastructure hostingSwitzerland
MongoDBDatabaseService region
StripePayment, billingEuropean Union / United States
AnthropicAI model — reading and interpreting sourcesUnited States
Serper.devWeb search (search engine results)Outside Switzerland
Google (Places API)Business discoveryOutside Switzerland
OpenStreetMap (Nominatim, Overpass)Geocoding and place discoveryEuropean Union
DuckDuckGoFallback web searchOutside Switzerland

The full, maintained list is in the data processing annex.

Transfers outside Switzerland. Some of these providers process data abroad. Depending on the country, these transfers rest on an adequacy decision of the Swiss Federal Council or on standard contractual clauses ensuring an appropriate level of protection (art. 16 and 17 nFADP). A copy of the applicable safeguards can be requested.

We may also disclose data to an authority where the law requires it. In the event of a corporate reorganisation, data would follow the transferred business, under the same protection conditions.

8. Security

Under art. 8 nFADP, we take technical and organisational measures proportionate to the risk, including:

  • encrypted transport (HTTPS) across the site and the API;
  • passwords hashed with bcrypt and salt; API keys stored as SHA-256 digests;
  • cryptographic verification of the authenticity of payment notifications;
  • anti-abuse limits per IP address at signup and login;
  • network protections against diverted outbound requests, with every redirect re-validated;
  • access logging, security reviews before production, per-account data partitioning.

No transmission over the internet is 100% secure. We do not claim otherwise; we implement the measures the state of the art calls for.

9. Data security breaches

In the event of a breach likely to cause a high risk to your rights, we notify the Federal Data Protection and Information Commissioner as soon as possible (art. 24 nFADP), and inform you where that is necessary for your protection. Where we act as processor, we report any breach to the controlling customer without delay (art. 24 para. 3 nFADP).

10. Your rights

You may request: access to your data (art. 25 nFADP), its rectification (art. 32 nFADP), its erasure, restriction of or objection to processing based on our legitimate interest, and portability of the data you provided to us. If the GDPR applies to you, you have the equivalent rights and the right to lodge a complaint with your supervisory authority.

Send your request to the address in the legal notice. We reply within a reasonable time, in principle within 30 days. We may ask for an element allowing us to verify your identity, so as not to disclose your data to a third party.

Are you a business whose published information appears in our results? You may request rectification or erasure of the data concerning you in our caches, at the same address. We act within a reasonable time and propagate the erasure.

11. Automated decision-making

We take no decision producing legal effects concerning you based solely on automated processing, and we do not profile natural persons.

12. Changes

We may update this policy. Any material change is announced by email at least 30 days before it takes effect. The version date appears at the top of this document.

Related documents: terms of service · sales terms · data processing · legal notice