INTREXA AXIS

Legal

Privacy Policy

Last updated: September 25, 2026

INTREXA AXIS is a product of INTREXA TECHNOLOGIES (OPC) PRIVATE LIMITED ("INTREXA", "we", "us"). This policy covers this website (axis.intrexa.in) and the INTREXA AXIS service (dashboard, API, and billing). It explains what data we collect, why, and your rights over it.

1. Scope

Sections 2–3 describe what happens when you visit this website. Sections 4–5 describe data we handle when you create an organisation, register agents, and use the authorization service. The remaining sections apply to both.

2. This website — what we collect

Analytics — We use Google Analytics (GA4) to understand aggregate site traffic. It only activates if you accept cookies in the banner. Until you accept, analytics and advertising storage are set to denied by default (Google Consent Mode v2) and no analytics events are sent.

Server logs — Our web servers automatically record IP addresses, browser user agents, and request timestamps as part of normal operation. We do not analyse these logs for marketing purposes.

Emails you send us — If you contact us, we receive your email address and message content and use them only to respond.

3. This website — cookies & consent

If analytics are enabled on this site, a banner asks on your first visit whether you accept optional analytics cookies. If you decline, or make no choice, analytics and advertising storage stay set to denied and no tracking cookies are set. Accepting lets Google Analytics record aggregate traffic (page views, referrers).

You can withdraw consent at any time; this takes effect immediately for future page views (it does not delete data already sent before withdrawal).

4. The service — what we collect

Account & organisation — name, email address, organisation name, and a hashed password. We never store passwords in plaintext.

Team members — when you invite a teammate, we collect their email address and assigned role for the invitation.

Agent & governance data — agent identities, public keys, delegation chains, policies, authorization decisions, and audit artifacts you create or generate while using the service.

Federation data — if you enable federation with another organisation, we exchange and store the peer organisation's public registry information needed to establish trust.

Billing data — subscription tier, billing history, and payment provider credentials (encrypted before storage). Card and bank details are handled directly by our payment processors; we do not store raw card numbers.

Sandbox data — test organisations, agents, and decisions created in sandbox mode are isolated from production data and are not counted as billable usage.

5. How we use data

  • To create and operate your account, organisation, and team
  • To evaluate and record authorization decisions and produce audit artifacts
  • To process subscription payments and manage billing
  • To send account, security, and service notifications by email
  • To establish federation/trust relationships you explicitly configure
  • To respond to messages you send us, and (only if you accept cookies) to understand aggregate website traffic
  • We do not sell your data or use it for advertising

6. Legal basis (GDPR / India DPDP Act)

We process account and billing data under contractual necessity (to provide the service you signed up for) and agent/governance data under your instruction as the data controller for your own organisation. For the website we rely on legitimate interests (operating the site, responding to your message) and consent (optional analytics cookies).

For users in India, we comply with the Digital Personal Data Protection Act, 2023 (DPDP Act). You have the right to access, correct, and erase your personal data by contacting us.

7. Data retention

Account and organisation data is retained for as long as your account is active. Audit artifacts are retained as signed, immutable records to support compliance use cases and are not deleted on request, consistent with their purpose.

Sandbox data may be automatically purged or suspended after a period of inactivity. Emails you send us are retained in our inbox until deleted; we review and purge old messages periodically.

To close your account and request deletion of your personal and billing data, contact us as described in Section 12. We process deletion requests manually and remove the data within a reasonable period, except where retention is required by law or by our audit-artifact obligations above.

8. Data storage and security

Data is encrypted in transit (TLS) and at rest. Passwords are hashed using industry-standard techniques; we never store or transmit plaintext passwords.

Payment provider credentials are encrypted before storage. Audit artifacts are cryptographically signed and immutable.

9. Third-party processors

10. Your rights

You have the right to:

  • Access — request a copy of personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — request deletion of your account and personal data by contacting us (Section 12); handled manually, subject to legal and audit-retention obligations
  • Portability — export your organisation's data in a machine-readable format
  • Object — object to processing based on legitimate interests, and withdraw analytics consent at any time

11. Cookies in the service

The service sets one strictly-necessary session cookie used to keep you signed in. It does not use tracking, advertising, or third-party analytics cookies.

12. Changes and contact

We may update this policy as the product evolves. Material changes will be noted with an updated "Last updated" date above. Continued use after changes constitutes acceptance.

For privacy-related requests or questions, contact INTREXA TECHNOLOGIES (OPC) PRIVATE LIMITED at contact@intrexa.in, or via your account settings.