Axon/Systems

Privacy Policy

Effective Date: 20 August 2026 Version: 1.1

1. Who we are

Axon Systems LLC ("Axon Systems", "we", "us") is a limited liability company formed under the laws of the State of Wyoming, United States, on 24 April 2026. We are the controller of the personal information described in this Policy.

We serve business clients worldwide, including in the United States, the United Kingdom, and the European Economic Area.

We have not appointed a Data Protection Officer. We are not a public authority, we do not monitor individuals systematically as a core activity, and we do not process special-category data at scale, so on our current assessment the mandatory triggers in Article 37 GDPR and UK GDPR are not met. We keep that assessment under review as the practice grows. The privacy contact above is the single point of contact for all data-protection matters, including requests from individuals in the EEA and the United Kingdom.

2. Scope

This Policy covers personal information we handle in three situations:

It does not cover personal information we process on behalf of a client during an engagement. There, the client is the controller and we act as their processor under the data-processing terms in the engagement contract. If you are an individual whose data a client of ours holds, contact that client directly.

3. What we collect, why, and on what basis

a) Site visitors

We run no analytics, no advertising pixels, and no tracking cookies on axonsystems.co. The site writes one item to your browser's local storage, axon-theme, recording whether you chose the light or dark version of the page. It never leaves your device, it is never sent to us, and it identifies nobody. Because it is strictly necessary to deliver a feature you asked for, no consent banner is required. If we ever add analytics or advertising tags, we will put a consent mechanism in place and update this Policy before doing so.

b) Enquiries and correspondence

c) Client and prospect records

We do not buy contact lists, we do not run cold outreach against purchased data, and we do not sell personal information.

Is providing any of this required?

You can read axonsystems.co without giving us anything. To get a reply from us we need a working email address and enough of your question to answer it; your name, company, and role are optional and help us judge fit. Once an engagement starts, the billing and contact details in (c) are needed to invoice you and to keep the accounting records the law requires, and we cannot proceed without them. Nothing else is a condition of talking to us.

4. Who we share it with

We share personal information only with providers who help us operate, and only as far as they need it. The categories of recipient are:

CategoryRoleLocation
Infrastructure and content delivery (Cloudflare, Inc.)Site hosting, DNS, TLS, DDoS protection, request logsUnited States, global edge network
Email provider (Google LLC, consumer Gmail)Receiving and sending our business correspondence. This is a standard Gmail mailbox, not a Google Workspace account, so Google's consumer terms and privacy policy govern itUnited States, and other countries in Google's network
Subcontracted technical delivery partnersPerforming engagement work under written contract and confidentiality obligations, on our instructionsEuropean Union
Professional advisers (accountants, lawyers)Tax, accounting, and legal adviceUnited States

We also disclose personal information where the law requires it, and where necessary to establish, exercise, or defend legal claims.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended by the CPRA.

5. Where your information goes

We are established in the United States, and information you send us is stored and processed there.

When you contact us directly from the EEA or the UK. You are providing your information to us yourself. Under EDPB Guidelines 05/2021, and the equivalent ICO guidance, a direct submission by the individual is not a restricted transfer under Chapter V, because there is no separate exporter established in the EEA or the UK. It does mean your information sits in the United States, and you should read this Policy knowing that. US law gives public authorities powers of access that have no exact equivalent in EU or UK law.

When a client sends us personal data. Where we receive personal information from a client established in the EEA or the UK, we enter the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 or Module 4 as appropriate, or the UK International Data Transfer Addendum, before the data moves. We support the client's transfer impact assessment on request.

Onward transfers to our own providers. Where a provider listed in Section 4 is outside the EEA or the UK, we rely on a European Commission adequacy decision where one covers the recipient, and otherwise on Standard Contractual Clauses or the UK Addendum under that provider's data-processing agreement.

Supplementary measures. For all of the above we apply encryption in transit and at rest, access controls, minimisation of what is transferred, and contractual limits on onward disclosure and on responding to foreign authority requests, consistent with EDPB Recommendations 01/2020. A copy of the clauses executed with a specific provider is available on written request to the privacy contact in Section 1.

6. How long we keep it

InformationRetention
Server and security logsUp to 30 days, then deleted or aggregated beyond identification
Enquiries that do not become engagements24 months from last contact, then deleted
Client engagement records and correspondenceTerm of the engagement plus 6 years, for limitation-period and audit reasons
Invoices and accounting recordsFor as long as the applicable federal and Wyoming tax and corporate rules require for the record in question. Where no shorter period applies we keep them for 7 years, which covers the longest IRS assessment period we are realistically exposed to

7. Your rights

If you are in the European Economic Area or the United Kingdom, you have the right to ask us for access to your personal data (Article 15), to have it corrected (Article 16) or erased (Article 17), to have processing restricted (Article 18), to receive it in a structured, commonly used, machine-readable format (Article 20), and to object to processing we carry out on the basis of legitimate interests, including any direct marketing (Article 21). Where we rely on consent, you may withdraw it at any time under Article 7, without affecting the lawfulness of what we did beforehand. We do not carry out automated decision-making of the kind Article 22 covers.

We respond within one month of receiving your request, extendable by a further two months for complex or numerous requests, in which case we will tell you inside the first month.

Complaints. You may lodge a complaint with a supervisory authority under Article 77. In the EEA that is the authority in the Member State where you live, where you work, or where the issue arose; the list is published by the European Data Protection Board at edpb.europa.eu. In the United Kingdom it is the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but it is your right either way.

If you are a California resident. Axon Systems is a small business, and it may not meet the revenue and processing-volume thresholds that make a business subject to the California Consumer Privacy Act as amended by the CPRA. We therefore do not claim that the CCPA necessarily applies to us. What follows is offered to you either way.

You may ask us what personal information we have collected about you, where it came from, why we collected it, and the categories of third party we disclosed it to; ask us to correct it; and ask us to delete it. We will not treat you differently for asking. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no opt-out for you to exercise. You may use an authorized agent. Where the CCPA does apply to us, you have these rights as a matter of law and we will honour them on the statute's terms.

Residents of other US states. A number of states, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, have comprehensive privacy laws. Those laws differ from one another in the rights they grant, in their exemptions, and in whether they provide an appeal route, and each applies only where a business meets that state's own applicability thresholds. Where a state law applies to us, we will honour the rights it gives you, including any right of appeal it provides. Utah, for example, does not grant a general right of correction, so what we can offer follows the statute rather than a single common list.

Separately, and whether or not any statute requires it, we will accept a request from anyone in the United States to see what we hold about them, correct it, or have it deleted. The same contact address works for all of these.

To exercise any right, write to axonsystems.co@gmail.com. We respond within 30 days, or one month where UK GDPR applies, and we do not charge. We may ask you for enough information to confirm who you are, purely so we do not hand your data to somebody else.

8. Security

The site is deliberately static and dependency-light. There is no database behind axonsystems.co, no login, and no user-generated content. Business correspondence and engagement records sit in access-controlled accounts. We enable multi-factor authentication where the provider offers it, and the providers we use encrypt data in transit and at rest as part of their own service. We require written confidentiality terms from subcontractors before they touch anything of yours. We do not operate our own servers or databases for this. No system is perfectly secure and we will not pretend otherwise.

9. Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.

10. Children

We sell to businesses. The site is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to the address above and we will delete it.

11. Changes

We update this Policy when our processing changes. The Effective Date and Version at the top always reflect the current text. Material changes will be called out on this page rather than made quietly.

12. Contact

Axon Systems LLC 75 E 3rd St, Sheridan, WY 82801, United States axonsystems.co@gmail.com


Change history

VersionDateSummary
1.020 August 2026Initial publication.
1.120 August 2026Corrections following an independent adversarial review, before any real traffic. Article 6(1)(b) no longer claimed for employees of corporate clients; Article 6(1)(f) used instead. US state privacy rights now conditioned on each statute actually applying, with the Utah correction-right difference called out, and the rights we offer voluntarily stated separately. California section no longer asserts that the CCPA necessarily applies to a business of this size. Required-versus-optional data section added per Article 13(2)(e). Email provider described accurately as consumer Gmail rather than implying Workspace. Security wording narrowed to what we can evidence. Accounting retention no longer asserts a universal seven-year legal requirement.