Privacy policy
Version 0.1 — 12 August 2026. Status: draft pending review by a Swiss lawyer.
The French version prevails: politique de confidentialité.
This policy describes how AXIONYX.io Sàrl handles personal data in connection with ClaimTrace. It is drafted under the Swiss Federal Act on Data Protection (nFADP, SR 235.1) and, for customers established in the European Union, under the GDPR.
1. Controller and general principle
Controller: AXIONYX.io Sàrl, business identification number CHE-396.139.818, canton of Neuchâtel, Switzerland. Details: legal notice.
All processing is lawful, carried out in good faith and proportionate (art. 6 nFADP). We apply data minimisation: we collect only what the Service needs to operate and to be billed.
2. Our two roles, not to be confused
We are the controller for data relating to your account, your billing and your use of the website.
We are a processor for any personal data you have us process by using the Service. By design, the Service targets factual data about professional entities — company name, address, opening hours, published offers and prices, published business contact details. It builds no profiles of natural persons and collects no private contact details. Where your use nonetheless involves personal data, you are the controller and we act on your instructions, under the data processing annex.
3. Data we process
3.1 Account
| Data | Status | Note |
|---|---|---|
| Email address | Required | Account identifier, verified by link |
| Password | Required | Stored hashed with bcrypt and salt — never in clear |
| Company | Optional | — |
| Use-case description | Optional | Helps us qualify the need |
3.2 API keys
We keep a SHA-256 digest of each key and a display prefix. The full value is shown once, at creation, and is never stored: we are technically unable to retrieve it. Also associated with the key: its plan, credit balance, creation date and, where applicable, its revocation.
3.3 Billing
Purchase history, customer identifier at the payment provider, amounts and dates. No card data passes through or is stored on our servers — entry happens directly with the provider.
3.4 Use of the Service
For each request: the need and location submitted, the number of entities handled, processing duration, an internal cost indicator and the label of the key used. These serve billing, diagnostics and abuse prevention.
The full results of a request (entities, facts, verbatim excerpts and source URLs) are kept temporarily so you can read them again.
3.5 IP address — what we do not do
Your IP address is used in memory only, for the time needed to apply anti-abuse limits at signup and login. It is never written to a database and is linked to no account.
3.6 Website: no cookies, no analytics
We set no cookies. We use no audience measurement tool, no advertising tracker, no social network pixel. There is therefore no consent banner, because there is nothing to consent to.
The site uses your browser's local storage, first-party:
| Key | Purpose |
|---|---|
ct_lang | Remembers your language choice |
ct_api_key | Keeps your key in the client area, on your device only |
ct_requests | Local history of your trials in the client area |
This data stays on your device, is not transmitted to us, and can be erased at any time by clearing the site's storage in your browser. Because ct_api_key keeps your key on the device, avoid the client area on a shared machine.
One reservation, stated plainly: the site's fonts are currently loaded from Google Fonts. Your browser therefore issues a request to Google's servers, which receive your IP address in the process. We intend to self-host these fonts to remove that transfer.
4. Why we process this data
| Purpose | Legal basis |
|---|---|
| Create and manage your account, provide the Service | Performance of the contract |
| Count credits, invoice, produce accounting records | Performance of the contract and legal obligation |
| Prevent abuse, fraud and overload (limits, anti-abuse) | Legitimate interest in protecting the Service and its users |
| Diagnose incidents and improve reliability | Legitimate interest in the proper operation of the Service |
| Send you messages necessary to the Service (verification, activation, incidents, changes to terms) | Performance of the contract |
| Comply with a legal obligation or a competent authority | Legal obligation |
| Establish or defend our rights | Legitimate interest |
We do not use your data for advertising and we neither sell nor rent it to anyone.
5. Retention periods
| Data | Period |
|---|---|
| Account (email, hashed password, company, use case) | For as long as the account exists |
| Client-area session token | 7 days |
| Email verification token | 24 hours, single use |
| Verified-facts cache | 12 hours |
| Re-readable request results | 24 hours |
| Geocoding cache (place → coordinates) | 30 days |
| Technical usage log (need submitted, location, duration, key label) | 12 months |
| Application logs | 90 days |
| Payment provider events | 90 days |
| Accounting and billing records | 10 years, under art. 958f para. 1 of the Swiss Code of Obligations |
6. Deleting your account, and what remains
You can delete your account from the client area. We then revoke all your keys and erase the password, company, use case and payment-provider identifier.
What remains, and why: accounting records relating to your purchases are kept for ten years, as the law requires (art. 958f CO). Technical logs are erased when their own period expires.
Note: after deletion, re-registration with the same email address is not automatic. Write to us if you would like to come back.
7. Who data is shared with
We use the following providers. None is permitted to use your data for its own purposes.
| Provider | Role | Processing location |
|---|---|---|
| Infomaniak | Infrastructure hosting | Switzerland |
| MongoDB | Database | Service region |
| Stripe | Payment, billing | European Union / United States |
| Anthropic | AI model — reading and interpreting sources | United States |
| Serper.dev | Web search (search engine results) | Outside Switzerland |
| Google (Places API) | Business discovery | Outside Switzerland |
| OpenStreetMap (Nominatim, Overpass) | Geocoding and place discovery | European Union |
| DuckDuckGo | Fallback web search | Outside Switzerland |
The full, maintained list is in the data processing annex.
Transfers outside Switzerland. Some of these providers process data abroad. Depending on the country, these transfers rest on an adequacy decision of the Swiss Federal Council or on standard contractual clauses ensuring an appropriate level of protection (art. 16 and 17 nFADP). A copy of the applicable safeguards can be requested.
We may also disclose data to an authority where the law requires it. In the event of a corporate reorganisation, data would follow the transferred business, under the same protection conditions.
8. Security
Under art. 8 nFADP, we take technical and organisational measures proportionate to the risk, including:
- encrypted transport (HTTPS) across the site and the API;
- passwords hashed with bcrypt and salt; API keys stored as SHA-256 digests;
- cryptographic verification of the authenticity of payment notifications;
- anti-abuse limits per IP address at signup and login;
- network protections against diverted outbound requests, with every redirect re-validated;
- access logging, security reviews before production, per-account data partitioning.
No transmission over the internet is 100% secure. We do not claim otherwise; we implement the measures the state of the art calls for.
9. Data security breaches
In the event of a breach likely to cause a high risk to your rights, we notify the Federal Data Protection and Information Commissioner as soon as possible (art. 24 nFADP), and inform you where that is necessary for your protection. Where we act as processor, we report any breach to the controlling customer without delay (art. 24 para. 3 nFADP).
10. Your rights
You may request: access to your data (art. 25 nFADP), its rectification (art. 32 nFADP), its erasure, restriction of or objection to processing based on our legitimate interest, and portability of the data you provided to us. If the GDPR applies to you, you have the equivalent rights and the right to lodge a complaint with your supervisory authority.
Send your request to the address in the legal notice. We reply within a reasonable time, in principle within 30 days. We may ask for an element allowing us to verify your identity, so as not to disclose your data to a third party.
Are you a business whose published information appears in our results? You may request rectification or erasure of the data concerning you in our caches, at the same address. We act within a reasonable time and propagate the erasure.
11. Automated decision-making
We take no decision producing legal effects concerning you based solely on automated processing, and we do not profile natural persons.
12. Changes
We may update this policy. Any material change is announced by email at least 30 days before it takes effect. The version date appears at the top of this document.
Related documents: terms of service · sales terms · data processing · legal notice