AxiLayer AI crestAxiLayerAI
Legal

Privacy Policy

This Privacy Policy explains how AxiLayer AI, Inc. collects, uses, discloses, and protects personal information when you visit our website, request a briefing, apply for a role, or otherwise interact with us.

Effective date
September 14, 2026
Applies to
axilayerai.com and related services
Controller
AxiLayer AI, Inc.

1. Who we are

AxiLayer AI, Inc. ("AxiLayer AI," "we," "us," or "our") is a Delaware corporation headquartered at 300 Colonial Center Parkway, Roswell, Georgia 30076. We provide independent AI system auditing, algorithm assurance, risk assessment, compliance certification, and governance advisory services. This Policy describes our privacy practices for the personal information we collect through this website (axilayerai.com), through client and prospect communications, and through our recruiting process.

2. Information we collect

We collect information in the following ways:

  • Information you provide directly. When you submit a briefing request, contact form, newsletter sign-up, RFP response, or similar inquiry, we collect the information you supply, typically name, business email address, phone number, employer or organization, job title, and the content of your message.
  • Career applications. If you apply for a position with us, we collect the information contained in your application, resume or CV, cover letter, and any other materials you choose to submit, along with information you provide during interviews or reference checks.
  • Website usage information. Like most websites, we automatically collect certain technical information when you visit, including IP address, browser and device type, operating system, referring and exit pages, and pages viewed, typically through server logs and standard analytics tools.
  • Cookies and similar technologies. We use strictly necessary cookies to operate the site (for example, session state and language preference) and may use analytics cookies to understand aggregate site usage. We do not use cookies to sell personal information. Most browsers let you refuse or delete cookies through their settings; doing so may affect some site functionality.
  • Information from third parties. We may receive limited information about you from professional networking platforms (such as LinkedIn), event organizers, or business partners who introduce you to us, consistent with their own privacy disclosures.

We do not knowingly collect government identification numbers, payment card numbers, or other sensitive financial account information through this website.

3. How we use information

We use personal information to:

  • Respond to inquiries and briefing requests, and to scope, deliver, and manage engagements;
  • Evaluate job applications and manage recruiting, subject to any additional notices provided during that process;
  • Operate, secure, and improve this website and understand how it is used;
  • Send communications you have requested, including newsletters or updates about our services, frameworks, and events, with an opt-out available in every such communication;
  • Comply with legal, regulatory, tax, and accounting obligations; and
  • Detect, investigate, and prevent fraud, misuse, or security incidents.

4. Legal bases for processing (EEA, UK, and similar jurisdictions)

Where the General Data Protection Regulation or equivalent UK law applies, we rely on one or more of the following legal bases: performance of a contract or steps requested prior to entering one (for example, scoping an engagement); our legitimate interests in operating and marketing our business, provided those interests are not overridden by your rights; your consent, where required, for example for optional marketing communications or non-essential cookies; and compliance with a legal obligation.

5. How we share information

We do not sell personal information. We may share it with:

  • Service providers who host our website, provide analytics, email delivery, applicant-tracking, or similar operational functions, under contractual confidentiality and data-protection obligations;
  • Professional advisors, such as our accountants, auditors, and legal counsel, as needed;
  • Regulators, courts, or government authorities, where required by law, legal process, or to protect our rights, property, or safety, or that of others; and
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a materially equivalent one.

Because our independence from the AI systems and vendors we assess is central to our work, we do not share client engagement data with the vendors or platforms whose systems we audit, except as the client itself directs.

6. International data transfers

We are headquartered in the United States and may process personal information there and in other jurisdictions where we or our service providers operate. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on recognized transfer mechanisms, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum, together with appropriate technical and organizational safeguards.

7. Data retention

We retain personal information for as long as needed to fulfill the purposes described in this Policy, including to provide services, maintain business records, meet legal, tax, and regulatory retention obligations, and resolve disputes. Retention periods vary by category and context; unsuccessful job applications are generally retained for a limited period to support our recruiting process unless you ask us to delete them sooner.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. California residents have rights under the California Consumer Privacy Act (as amended), including the right to know what personal information we hold and to request its deletion; we do not sell or share personal information for cross-context behavioral advertising as those terms are defined under California law. To exercise any of these rights, contact us using the details in Section 12; we may need to verify your identity before acting on a request.

9. Data security

We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. No system is completely secure, and we cannot guarantee the absolute security of information transmitted to us.

10. Children's privacy

This website and our services are directed to businesses and professionals and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can address it.

11. Third-party links

This website may link to third-party sites, including regulatory bodies, standards organizations, and partners. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies before providing them with information.

12. Contact us

To ask a question about this Policy or to exercise a privacy right, contact us at:

AxiLayer AI, Inc.
300 Colonial Center Parkway
Roswell, Georgia 30076
Phone: (943) 243-0151
Email: contactus@axilayerai.com

13. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or applicable law. The effective date at the top of this page indicates when it was last revised. Material changes will be reflected on this page.