1. Who we are
Axivana is a trading name of Dibos BV, registered at Camiel Verstraetenstraat 1d, 9150 Beveren-Kruibeke-Zwijndrecht, Belgium. Dibos BV operates axivana.com and is the controller of the personal data described in this policy.
You can reach our privacy team at privacy@axivana.com, by email at hello@axivana.com or info@dibos.be, or by WhatsApp at +32456730108.
2. Which laws apply
We apply one global standard, built on the strictest applicable rules, and add local rights where the law requires it:
- European Economic Area and Switzerland — the General Data Protection Regulation (GDPR) and national implementing laws.
- United Kingdom — the UK GDPR and the Data Protection Act 2018.
- Australia — the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme.
- United States — state privacy laws such as the CCPA/CPRA (California), and comparable laws in Virginia, Colorado, Connecticut, Utah and Texas.
- Canada — PIPEDA; New Zealand — the Privacy Act 2020; Japan — the APPI; South Korea — PIPA; Brazil — the LGPD.
3. What we collect
- Account data — name, email address and password credentials when you create an account.
- Content and library data — the books, guides and courses you open, save or download.
- Purchase data — order history and billing details. Card details are handled by our payment provider; we never store full card numbers.
- Technical data — IP address, device and browser type, language, and pages visited.
- Communications — messages, support requests and newsletter preferences.
- AI interactions — prompts and answers when you use Axivana AI, used to deliver and improve the feature.
4. Why we use it and our legal basis
- To provide your account, library access and purchases — performance of a contract.
- To keep the platform secure and prevent fraud or abuse — legitimate interests.
- To measure and improve the platform with analytics — consent where required, otherwise legitimate interests.
- To send newsletters and marketing — consent, which you can withdraw at any time.
- To meet tax, accounting and other legal obligations — legal obligation.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as defined by US state privacy laws.
5. Who we share data with
We share data only with processors who work on our instructions and under a written data processing agreement: hosting and database providers, payment processors, email delivery services, analytics providers and AI model providers. We may also disclose data where required by law or to protect our legal rights.
6. International transfers
Axivana serves readers worldwide, so your data may be processed outside your country, including in the European Union, the United Kingdom, the United States and Australia. Where data leaves the EEA or UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant). For Australian users, we take reasonable steps under APP 8 to ensure overseas recipients handle your data consistently with the Australian Privacy Principles.
7. How long we keep data
- Account data — for as long as your account is active, then up to 12 months after closure.
- Order and invoice records — up to 7 to 10 years, as required by tax law.
- Analytics data — normally up to 14 months, in aggregated or pseudonymised form.
- Support messages — up to 24 months after your request is resolved.
8. Your rights
Depending on where you live, you can ask us to:
- Access the personal data we hold about you and receive a copy.
- Correct data that is inaccurate or incomplete.
- Delete your data, where no legal obligation requires us to keep it.
- Restrict or object to processing, including profiling and direct marketing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting processing that already took place.
- Not be discriminated against for exercising your privacy rights (US state laws).
Email privacy@axivana.com and we will respond within 30 days (or one month under the GDPR, extendable by two months for complex requests).
9. Security and data breaches
We use encryption in transit, access controls, role-based permissions and regular backups. If a breach is likely to result in serious harm, we notify the competent supervisory authority within 72 hours (GDPR) and the Office of the Australian Information Commissioner as soon as practicable under the Notifiable Data Breaches scheme, and we inform affected users directly where required.
10. Children
Axivana is not intended for children under 16. We do not knowingly collect data from children under 16 (or under 13 in the United States). If you believe a child has given us personal data, contact us and we will delete it.
11. Cookies and tracking
We place strictly necessary cookies to run the platform. Functional, analytics and marketing cookies are only used after you agree through our cookie banner, where refusing is exactly as easy as accepting. You can change or withdraw your choice at any time via “Cookie settings” in the footer, and we honour Global Privacy Control and similar opt-out signals as a refusal of non-essential cookies and of any sale or sharing of personal information. Full details are in our cookie policy.
12. Region-specific rights
- EEA and Switzerland (GDPR, national implementing laws, Swiss FADP) — access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and the right not to be subject to solely automated decisions with legal effects. Complaints go to your national supervisory authority (or the Swiss FDPIC).
- United Kingdom (UK GDPR and Data Protection Act 2018) — the same rights, with complaints to the Information Commissioner's Office.
- Australia (Privacy Act 1988 (Cth) and the Australian Privacy Principles) — access and correction under APP 12 and 13, anonymity or pseudonymity where practicable under APP 2, an opt-out of direct marketing under APP 7, overseas-disclosure safeguards under APP 8, and notification of eligible data breaches to you and to the OAIC under the Notifiable Data Breaches scheme.
- United States (CCPA/CPRA in California, plus Virginia, Colorado, Connecticut, Utah and Texas) — the right to know, access, delete, correct and port, to limit the use of sensitive personal information, to opt out of sale, sharing and targeted advertising, and to be free from discrimination for exercising these rights. We do not sell or share personal information, and we treat Global Privacy Control as a valid opt-out. Authorised agents may submit requests with proof of authority; appeals of a refused request can be sent to our privacy team.
- Canada (PIPEDA and provincial equivalents) — access, correction, withdrawal of consent and complaints to the Office of the Privacy Commissioner of Canada.
- New Zealand (Privacy Act 2020) — access and correction under Information Privacy Principles 6 and 7, overseas-disclosure safeguards under IPP 12, and notification of privacy breaches to the Privacy Commissioner and to you where serious harm is likely.
- Japan (APPI) — disclosure, correction, suspension of use and third-party-transfer records; we obtain consent for transfers to third parties abroad as required.
- South Korea (PIPA) — separate, itemised consent for collection, marketing and overseas transfer, plus access, correction, suspension and deletion rights, and destruction of data once its purpose ends.
- Brazil (LGPD) — confirmation of processing, access, correction, anonymisation or deletion, portability, information on sharing, and the right to review automated decisions; complaints go to the ANPD.
Where a local law grants you a stronger right than this policy describes, that stronger right applies to you.
13. Complaints
You can lodge a complaint with your local supervisory authority — for example your national data protection authority in the EEA, the Information Commissioner's Office in the UK, the Office of the Australian Information Commissioner in Australia, the Office of the Privacy Commissioner of Canada, the New Zealand Privacy Commissioner, Japan's Personal Information Protection Commission, Korea's PIPC or Brazil's ANPD. We would appreciate the chance to resolve your concern first.
14. Changes to this policy
We may update this policy as the platform evolves. Material changes will be announced on this page and, where required, by email before they take effect.
