Privacy Policy
Effective Date: 20 August 2026 Version: 1.1
1. Who we are
Axon Systems LLC ("Axon Systems", "we", "us") is a limited liability company formed under the laws of the State of Wyoming, United States, on 24 April 2026. We are the controller of the personal information described in this Policy.
- Registered office: 75 E 3rd St, Sheridan, WY 82801, United States
- Privacy contact: axonsystems.co@gmail.com
We serve business clients worldwide, including in the United States, the United Kingdom, and the European Economic Area.
We have not appointed a Data Protection Officer. We are not a public authority, we do not monitor individuals systematically as a core activity, and we do not process special-category data at scale, so on our current assessment the mandatory triggers in Article 37 GDPR and UK GDPR are not met. We keep that assessment under review as the practice grows. The privacy contact above is the single point of contact for all data-protection matters, including requests from individuals in the EEA and the United Kingdom.
2. Scope
This Policy covers personal information we handle in three situations:
- Visitors to axonsystems.co.
- People who contact us by email or through any enquiry form we operate.
- Client and prospect contacts, meaning the individuals we deal with at companies that engage us or are considering it.
It does not cover personal information we process on behalf of a client during an engagement. There, the client is the controller and we act as their processor under the data-processing terms in the engagement contract. If you are an individual whose data a client of ours holds, contact that client directly.
3. What we collect, why, and on what basis
a) Site visitors
- What: IP address, request metadata, user agent, referrer, pages requested, and approximate location derived from IP.
- Why: Serving the site, protecting it from attack and abuse, and understanding aggregate traffic volume.
- Basis (where GDPR or UK GDPR applies): Article 6(1)(f) legitimate interests, being the security and operational integrity of our own website.
We run no analytics, no advertising pixels, and no tracking cookies on axonsystems.co. The site writes one item to your browser's local storage, axon-theme, recording whether you chose the light or dark version of the page. It never leaves your device, it is never sent to us, and it identifies nobody. Because it is strictly necessary to deliver a feature you asked for, no consent banner is required. If we ever add analytics or advertising tags, we will put a consent mechanism in place and update this Policy before doing so.
b) Enquiries and correspondence
- What: Your name, business email address, company, role, and whatever you put in your message.
- Why: Replying to you, working out whether we are a fit for the work, and preparing a proposal.
- Basis (where GDPR or UK GDPR applies): Article 6(1)(b), steps taken at your request before entering a contract. For continued follow-up after an enquiry goes quiet, Article 6(1)(f) legitimate interests in business development. Tell us to stop and we will stop.
c) Client and prospect records
- What: Business contact details, engagement correspondence, notes on scope and requirements, and billing contact data.
- Why: Delivering the engagement, invoicing, and keeping the records we are required to keep.
- Basis (where GDPR or UK GDPR applies): Where you are personally our client, Article 6(1)(b) performance of that contract. Where you are an employee or officer of a client company, the contract is with your company and not with you, so we rely on Article 6(1)(f), our legitimate interest in administering and performing that engagement. Article 6(1)(c) applies to tax and accounting records. Article 6(1)(f) also covers our own business records and the defence of legal claims.
We do not buy contact lists, we do not run cold outreach against purchased data, and we do not sell personal information.
Is providing any of this required?
You can read axonsystems.co without giving us anything. To get a reply from us we need a working email address and enough of your question to answer it; your name, company, and role are optional and help us judge fit. Once an engagement starts, the billing and contact details in (c) are needed to invoice you and to keep the accounting records the law requires, and we cannot proceed without them. Nothing else is a condition of talking to us.
4. Who we share it with
We share personal information only with providers who help us operate, and only as far as they need it. The categories of recipient are:
| Category | Role | Location |
|---|---|---|
| Infrastructure and content delivery (Cloudflare, Inc.) | Site hosting, DNS, TLS, DDoS protection, request logs | United States, global edge network |
| Email provider (Google LLC, consumer Gmail) | Receiving and sending our business correspondence. This is a standard Gmail mailbox, not a Google Workspace account, so Google's consumer terms and privacy policy govern it | United States, and other countries in Google's network |
| Subcontracted technical delivery partners | Performing engagement work under written contract and confidentiality obligations, on our instructions | European Union |
| Professional advisers (accountants, lawyers) | Tax, accounting, and legal advice | United States |
We also disclose personal information where the law requires it, and where necessary to establish, exercise, or defend legal claims.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended by the CPRA.
5. Where your information goes
We are established in the United States, and information you send us is stored and processed there.
When you contact us directly from the EEA or the UK. You are providing your information to us yourself. Under EDPB Guidelines 05/2021, and the equivalent ICO guidance, a direct submission by the individual is not a restricted transfer under Chapter V, because there is no separate exporter established in the EEA or the UK. It does mean your information sits in the United States, and you should read this Policy knowing that. US law gives public authorities powers of access that have no exact equivalent in EU or UK law.
When a client sends us personal data. Where we receive personal information from a client established in the EEA or the UK, we enter the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 or Module 4 as appropriate, or the UK International Data Transfer Addendum, before the data moves. We support the client's transfer impact assessment on request.
Onward transfers to our own providers. Where a provider listed in Section 4 is outside the EEA or the UK, we rely on a European Commission adequacy decision where one covers the recipient, and otherwise on Standard Contractual Clauses or the UK Addendum under that provider's data-processing agreement.
Supplementary measures. For all of the above we apply encryption in transit and at rest, access controls, minimisation of what is transferred, and contractual limits on onward disclosure and on responding to foreign authority requests, consistent with EDPB Recommendations 01/2020. A copy of the clauses executed with a specific provider is available on written request to the privacy contact in Section 1.
6. How long we keep it
| Information | Retention |
|---|---|
| Server and security logs | Up to 30 days, then deleted or aggregated beyond identification |
| Enquiries that do not become engagements | 24 months from last contact, then deleted |
| Client engagement records and correspondence | Term of the engagement plus 6 years, for limitation-period and audit reasons |
| Invoices and accounting records | For as long as the applicable federal and Wyoming tax and corporate rules require for the record in question. Where no shorter period applies we keep them for 7 years, which covers the longest IRS assessment period we are realistically exposed to |
7. Your rights
If you are in the European Economic Area or the United Kingdom, you have the right to ask us for access to your personal data (Article 15), to have it corrected (Article 16) or erased (Article 17), to have processing restricted (Article 18), to receive it in a structured, commonly used, machine-readable format (Article 20), and to object to processing we carry out on the basis of legitimate interests, including any direct marketing (Article 21). Where we rely on consent, you may withdraw it at any time under Article 7, without affecting the lawfulness of what we did beforehand. We do not carry out automated decision-making of the kind Article 22 covers.
We respond within one month of receiving your request, extendable by a further two months for complex or numerous requests, in which case we will tell you inside the first month.
Complaints. You may lodge a complaint with a supervisory authority under Article 77. In the EEA that is the authority in the Member State where you live, where you work, or where the issue arose; the list is published by the European Data Protection Board at edpb.europa.eu. In the United Kingdom it is the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but it is your right either way.
If you are a California resident. Axon Systems is a small business, and it may not meet the revenue and processing-volume thresholds that make a business subject to the California Consumer Privacy Act as amended by the CPRA. We therefore do not claim that the CCPA necessarily applies to us. What follows is offered to you either way.
You may ask us what personal information we have collected about you, where it came from, why we collected it, and the categories of third party we disclosed it to; ask us to correct it; and ask us to delete it. We will not treat you differently for asking. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out for you to exercise. You may use an authorized agent. Where the CCPA does apply to us, you have these rights as a matter of law and we will honour them on the statute's terms.
Residents of other US states. A number of states, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, have comprehensive privacy laws. Those laws differ from one another in the rights they grant, in their exemptions, and in whether they provide an appeal route, and each applies only where a business meets that state's own applicability thresholds. Where a state law applies to us, we will honour the rights it gives you, including any right of appeal it provides. Utah, for example, does not grant a general right of correction, so what we can offer follows the statute rather than a single common list.
Separately, and whether or not any statute requires it, we will accept a request from anyone in the United States to see what we hold about them, correct it, or have it deleted. The same contact address works for all of these.
To exercise any right, write to axonsystems.co@gmail.com. We respond within 30 days, or one month where UK GDPR applies, and we do not charge. We may ask you for enough information to confirm who you are, purely so we do not hand your data to somebody else.
8. Security
The site is deliberately static and dependency-light. There is no database behind axonsystems.co, no login, and no user-generated content. Business correspondence and engagement records sit in access-controlled accounts. We enable multi-factor authentication where the provider offers it, and the providers we use encrypt data in transit and at rest as part of their own service. We require written confidentiality terms from subcontractors before they touch anything of yours. We do not operate our own servers or databases for this. No system is perfectly secure and we will not pretend otherwise.
9. Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.
10. Children
We sell to businesses. The site is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to the address above and we will delete it.
11. Changes
We update this Policy when our processing changes. The Effective Date and Version at the top always reflect the current text. Material changes will be called out on this page rather than made quietly.
12. Contact
Axon Systems LLC 75 E 3rd St, Sheridan, WY 82801, United States axonsystems.co@gmail.com
Change history
| Version | Date | Summary |
|---|---|---|
| 1.0 | 20 August 2026 | Initial publication. |
| 1.1 | 20 August 2026 | Corrections following an independent adversarial review, before any real traffic. Article 6(1)(b) no longer claimed for employees of corporate clients; Article 6(1)(f) used instead. US state privacy rights now conditioned on each statute actually applying, with the Utah correction-right difference called out, and the rights we offer voluntarily stated separately. California section no longer asserts that the CCPA necessarily applies to a business of this size. Required-versus-optional data section added per Article 13(2)(e). Email provider described accurately as consumer Gmail rather than implying Workspace. Security wording narrowed to what we can evidence. Accounting retention no longer asserts a universal seven-year legal requirement. |