Privacy at axsept
How we collect, protect, and give you control over your data.
Our Privacy Commitment
Axsept is designed with privacy at its core. We collect only the data necessary to deliver verifiable proof of your skills, store it with encryption at rest and in transit, and apply strict role-based access controls so you see only your own data.
We never sell your data, and we give you full control over your information — including the right to access, correct, restrict processing, or delete it on request, as detailed below.
What Data We Collect
Account information — Your email address, display name, and authentication credentials (passwords are hashed with Argon2id and never stored in plaintext).
Activity logs — Descriptions of your daily work that you submit, from which the system extracts skill mentions. Activities are append-only and form the basis of your skill profile.
Skill records & vectors — Computed from your activities, referrals, and certifications. Each skill is stored as a multi-dimensional vector derived from its taxonomy position, proficiency, and recency, so we can compare and rank capabilities.
Referrals — Peer endorsements you give or receive, including optional comments and skill nodes endorsed.
Free-text fields — Activity descriptions and referral comments may contain information you choose to share. You control what you write — we store it as-is and never log it externally.
How We Protect Your Data
Encryption at rest — All data is encrypted with AES-256 via AWS KMS-managed keys. OAuth tokens receive an additional layer of application-level envelope encryption.
Encryption in transit — All communication uses TLS 1.2 or higher. Internal service-to-service traffic is encrypted within our VPC.
Access control — Strict role-based access control (RBAC) ensures you see only your own data. Administrators cannot access your data without audited permissions.
Password security — Passwords are hashed with Argon2id, the current industry best practice. They are never stored in plaintext or reversible form.
Logging controls — Your email, name, activity text, referral comments, and credentials are never written to application logs. Audit logs capture security events by user ID and action type only.
Your Rights
Right to access — You may request a copy of the personal data we hold about you. Verified requests are fulfilled within 30 days, consistent with GDPR Article 15 and CCPA §1798.100.
Right to deletion — You can request account deletion. After a 30-day recovery window (in case of accidental deletion), your data is permanently anonymized: display names become "[deleted]", free-text is redacted, and skill vectors are removed.
Right to rectification — You can update your profile information at any time. Skill records follow an append-only model: corrections are new records that supersede old ones, preserving integrity.
Right to object — You can opt out of employer search visibility and analytics inclusion at any time through your profile settings.
Right to restrict processing — You can freeze your account, pausing all processing of your data while maintaining your records.
Data Retention
Active accounts — Your data is retained while your account is active. Activity logs and referrals are kept for 5 years from their date to support long-term skill verification.
After deletion — You have a 30-day window to recover your account. After that, personal data is anonymized and skill vectors and snapshots are deleted.
Operational logs — Authentication logs are kept for 1 year, API access logs for 90 days, and admin/impersonation audit logs for 2 years. These logs never contain your personal information.
Backups — Database backups are retained for up to 14 days. If a backup is restored after your deletion, the deletion process runs again automatically.
Cross-Border Data Handling
Regional data residency — Your data is stored in the region where you registered. All your skill records, activities, and vectors stay within your regional database.
Cross-region referrals — When you refer someone in a different region, only structured metadata (skill nodes, strength scores) crosses borders. Free-text comments stay in the subject's home region.
Employer search — Cross-region searches return only anonymized results. Your real identity is never revealed across regional boundaries without your explicit consent.
Region transfer — You can request a transfer of your data to a different region (e.g., if you relocate). The process takes up to 30 days and is protected by Standard Contractual Clauses.
Last updated: May 2026
If you have questions about our privacy practices, use the in-app chat or contact us through your account settings.