Privacy Policy
Last updated: [Insert date before publishing]
This is a draft document. It must be reviewed by a qualified legal professional before being published to real users.
1. Who We Are
Axent is operated by [Founder full legal name / Company name], registered in [England and Wales]. Registered address: [Address]. Contact email: [privacy@axent.app].
We are the data controller for the personal data described in this policy. We operate under UK GDPR and the Data Protection Act 2018.
2. What Data We Collect
We collect and process only the data necessary to deliver the Axent service.
2.1 Account data
Email address: collected at signup. Used to identify your account, send access approval notifications, and deliver Supabase authentication emails (email verification, password reset).
2.2 Session transcript data
Session transcripts: text records of examiner questions and your spoken answers, produced during viva simulation sessions. Generated by converting your speech to text via Groq's speech-to-text API. Transcripts are used to generate AI feedback on your performance and to display your session history in the application.
2.3 Performance data
Session scores and feedback: key point coverage percentages, pass/fail results, and written AI feedback generated for each session. Stored and displayed in your dashboard and session history.
2.4 What we do NOT collect
- •Voice recordings: your audio is processed in real time for transcription and is never stored. Only the resulting text transcript is retained.
- •Payment information: Axent does not process payments at this stage.
- •Sensitive personal data: we do not intentionally collect health information, biometric data, or other special category data beyond what may incidentally appear in your session transcripts as a result of clinical case content.
3. How We Use Your Data
| Data | Purpose | Lawful basis |
|---|---|---|
| Email address | Account authentication; access approval notification email; Supabase auth emails | Performance of contract |
| Session transcripts | Generating AI feedback; displaying session history; producing PDF reports | Performance of contract |
| Session scores and feedback | Displaying performance statistics; producing PDF exports | Performance of contract |
Our lawful basis for all processing is performance of contract (UK GDPR Article 6(1)(b)). We do not use your data for marketing, advertising, profiling, or any purpose beyond what is stated above.
4. Who We Share Your Data With
We do not sell your data. We do not share your data with advertisers or marketing platforms. We use the following third-party processors to deliver the service:
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Database hosting, authentication, file storage | EU (AWS EU-West) | SCCs / UK adequacy |
| Groq | Speech-to-text and text-to-speech processing | USA | SCCs / DPA in place |
| xAI | AI language model processing | USA | SCCs / DPA in place |
| Anthropic | AI language model processing | USA | SCCs / DPA in place |
| Protoface | Avatar video rendering | USA | SCCs / DPA in place |
| LiveKit | Real-time audio/video transport | USA | SCCs / DPA in place |
| Vercel | Application hosting | USA / EU | SCCs / DPA in place |
5. How Long We Keep Your Data
| Data | Retention period |
|---|---|
| Account data (email, status) | Duration of your account + 30 days following deletion request |
| Session transcripts | Duration of your account + 30 days following deletion request |
| Session scores and feedback | Duration of your account + 30 days following deletion request |
Voice recordings are never stored at any point. All personal data is permanently deleted within 30 days of an account deletion request, except where retention is required by law.
6. Your Rights Under UK GDPR
You have the following rights:
- •Right of access: request a copy of the personal data we hold about you
- •Right to rectification: request correction of inaccurate data
- •Right to erasure: request deletion of your personal data
- •Right to restriction of processing: request that we limit how we use your data
- •Right to data portability: request your data in a machine-readable format
- •Right to object: object to any processing based on legitimate interests (none currently applies; we rely solely on performance of contract)
- •Rights related to automated decision-making: Axent does not make solely automated decisions with legal or similarly significant effects
To exercise any right, contact [privacy@axent.app]. We will respond within 30 days.
7. Cookies and Local Storage
Axent uses only:
- •A functional session cookie to maintain your authenticated login (Supabase Auth)
- •localStorage key axent-theme to remember your dark/light mode preference
We do not use analytics cookies, advertising cookies, or any third-party tracking.
8. Security
We implement reasonable technical and organisational measures to protect your data:
- •All data in transit is encrypted via HTTPS/TLS
- •Database access is restricted by Supabase Row Level Security; each user can only access their own data
- •All third-party API keys are stored as server-side environment variables and never exposed to the browser
- •Admin access to user data requires a separately credentialed admin account
9. International Transfers
Several third-party processors are based in the United States. All transfers outside the UK are protected by Standard Contractual Clauses (SCCs) approved for UK international transfers, or by reliance on an adequacy decision where applicable.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will reflect any changes. If changes are material, registered users will be notified by email. Continued use of Axent after changes constitutes acceptance of the updated policy.
11. Contact and Complaints
Email: [privacy@axent.app]
Address: [Legal registered address]
If you are unsatisfied with our response, you may complain to the UK Information Commissioner's Office (ICO): ico.org.uk | Telephone: 0303 123 1113