Axent

Privacy Policy

Last updated: [Insert date before publishing]

This is a draft document. It must be reviewed by a qualified legal professional before being published to real users.

1. Who We Are

Axent is operated by [Founder full legal name / Company name], registered in [England and Wales]. Registered address: [Address]. Contact email: [privacy@axent.app].

We are the data controller for the personal data described in this policy. We operate under UK GDPR and the Data Protection Act 2018.

2. What Data We Collect

We collect and process only the data necessary to deliver the Axent service.

2.1 Account data

Email address: collected at signup. Used to identify your account, send access approval notifications, and deliver Supabase authentication emails (email verification, password reset).

2.2 Session transcript data

Session transcripts: text records of examiner questions and your spoken answers, produced during viva simulation sessions. Generated by converting your speech to text via Groq's speech-to-text API. Transcripts are used to generate AI feedback on your performance and to display your session history in the application.

2.3 Performance data

Session scores and feedback: key point coverage percentages, pass/fail results, and written AI feedback generated for each session. Stored and displayed in your dashboard and session history.

2.4 What we do NOT collect

  • •Voice recordings: your audio is processed in real time for transcription and is never stored. Only the resulting text transcript is retained.
  • •Payment information: Axent does not process payments at this stage.
  • •Sensitive personal data: we do not intentionally collect health information, biometric data, or other special category data beyond what may incidentally appear in your session transcripts as a result of clinical case content.

3. How We Use Your Data

DataPurposeLawful basis
Email addressAccount authentication; access approval notification email; Supabase auth emailsPerformance of contract
Session transcriptsGenerating AI feedback; displaying session history; producing PDF reportsPerformance of contract
Session scores and feedbackDisplaying performance statistics; producing PDF exportsPerformance of contract

Our lawful basis for all processing is performance of contract (UK GDPR Article 6(1)(b)). We do not use your data for marketing, advertising, profiling, or any purpose beyond what is stated above.

4. Who We Share Your Data With

We do not sell your data. We do not share your data with advertisers or marketing platforms. We use the following third-party processors to deliver the service:

ProcessorPurposeLocationSafeguard
SupabaseDatabase hosting, authentication, file storageEU (AWS EU-West)SCCs / UK adequacy
GroqSpeech-to-text and text-to-speech processingUSASCCs / DPA in place
xAIAI language model processingUSASCCs / DPA in place
AnthropicAI language model processingUSASCCs / DPA in place
ProtofaceAvatar video renderingUSASCCs / DPA in place
LiveKitReal-time audio/video transportUSASCCs / DPA in place
VercelApplication hostingUSA / EUSCCs / DPA in place

5. How Long We Keep Your Data

DataRetention period
Account data (email, status)Duration of your account + 30 days following deletion request
Session transcriptsDuration of your account + 30 days following deletion request
Session scores and feedbackDuration of your account + 30 days following deletion request

Voice recordings are never stored at any point. All personal data is permanently deleted within 30 days of an account deletion request, except where retention is required by law.

6. Your Rights Under UK GDPR

You have the following rights:

  • •Right of access: request a copy of the personal data we hold about you
  • •Right to rectification: request correction of inaccurate data
  • •Right to erasure: request deletion of your personal data
  • •Right to restriction of processing: request that we limit how we use your data
  • •Right to data portability: request your data in a machine-readable format
  • •Right to object: object to any processing based on legitimate interests (none currently applies; we rely solely on performance of contract)
  • •Rights related to automated decision-making: Axent does not make solely automated decisions with legal or similarly significant effects

To exercise any right, contact [privacy@axent.app]. We will respond within 30 days.

7. Cookies and Local Storage

Axent uses only:

  • •A functional session cookie to maintain your authenticated login (Supabase Auth)
  • •localStorage key axent-theme to remember your dark/light mode preference

We do not use analytics cookies, advertising cookies, or any third-party tracking.

8. Security

We implement reasonable technical and organisational measures to protect your data:

  • •All data in transit is encrypted via HTTPS/TLS
  • •Database access is restricted by Supabase Row Level Security; each user can only access their own data
  • •All third-party API keys are stored as server-side environment variables and never exposed to the browser
  • •Admin access to user data requires a separately credentialed admin account

9. International Transfers

Several third-party processors are based in the United States. All transfers outside the UK are protected by Standard Contractual Clauses (SCCs) approved for UK international transfers, or by reliance on an adequacy decision where applicable.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will reflect any changes. If changes are material, registered users will be notified by email. Continued use of Axent after changes constitutes acceptance of the updated policy.

11. Contact and Complaints

Email: [privacy@axent.app]

Address: [Legal registered address]

If you are unsatisfied with our response, you may complain to the UK Information Commissioner's Office (ICO): ico.org.uk | Telephone: 0303 123 1113