Aixa Privacy & Cookie Policy
Last updated: 22 August 2025
Controller: Aixa LTD ("Aixa", "we", "us"), Rainstrasse 17, 8808 Pfäffikon SZ, Switzerland
Contact: privacy@iamaixa.com
We protect your personal data in line with the Swiss Federal Act on Data Protection (revDSG 2023) and the EU General Data Protection Regulation (GDPR). This notice explains what we collect, why, and your rights.
1. What data we collect
- Account information: name, email address.
- Login via Microsoft Entra ID (Azure AD B2B): when you sign in, Microsoft provides us with limited identity claims (first name, last name, display name, email, and a technical identifier such as an object ID). During setup, we also ask for your country.
- Account metadata: account ID, account creation date, last sign-in time.
- Authentication and security logs: Microsoft Entra ID automatically collects sign-in data, including IP addresses, device details, and risk assessments. These logs are stored securely by Microsoft on our behalf. Aixa does not duplicate full sign-in/IP logs in its own systems but may access them via Azure for security and compliance purposes.
- Usage data: basic technical diagnostics (e.g. error messages, request IDs) necessary to operate and troubleshoot the service.
- Analytics (only with consent): Google Analytics cookies (e.g. pages visited, time spent, aggregated usage). GA anonymises IP addresses, and analytics are disabled until you opt in.
- Support data: any information you provide when contacting us.
2. Why we process data (legal bases)
- Contractual necessity: to provide you with an account, authenticate logins, and deliver our services.
- Legitimate interests: to secure our systems, prevent misuse, and troubleshoot technical issues.
- Consent: for analytics tracking and for optional marketing communications.
3. Data sharing
- Hosting: Microsoft Azure (servers in Switzerland/EU).
- Authentication: Microsoft Entra ID (Azure AD B2B) logs and processes sign-in events.
- Analytics: Google Analytics (only with consent).
- We do not sell or rent personal data to third parties.
4. International transfers
- Data is primarily processed in Switzerland and the EU.
- Transfers outside these regions occur only if providers (e.g. Google, Microsoft) are subject to EU/Swiss adequacy decisions or bound by Standard Contractual Clauses.
- Some personal data may be processed outside Switzerland and the EU/EEA (e.g. in India, by our contracted development partner), under Standard Contractual Clauses and equivalent safeguards to ensure your rights are protected.
5. Data retention
- Account data: while account is active + up to 24 months after inactivity.
- Analytics data: max. 12 months (as configured in GA).
- Email data: until you unsubscribe.
- Authentication/security logs (Azure): retained by Microsoft according to their standard policies; Aixa does not extend or duplicate these logs.
6. Your rights
Under GDPR and the Swiss FADP you have the right to:
- Access, rectify, or erase your data.
- Restrict or object to processing.
- Withdraw consent at any time (for analytics or marketing).
- Request data portability.
- File a complaint with the FDPIC (Switzerland) or your local EU Data Protection Authority.
To exercise these rights, contact privacy@iamaixa.com.
7. Cookies & tracking
- Strictly necessary cookies: session cookies required for secure login — always active.
- Analytics cookies: Google Analytics — only set with your explicit consent via the cookie banner.
- 支付与欺诈防范 Cookie: Stripe — 仅在您打开账单或定价界面时加载,绝不会在一般浏览页面加载。Stripe.js 可能设置 __stripe_mid、__stripe_sid 和 m,并可能处理您的 IP 地址、设备和浏览器标识符、来源网址及活动信号,以保障支付安全并防范欺诈。
Changing your preferences:
您可以随时通过网站页脚的“Cookies”链接更改您的 Cookie 偏好设置,该链接会重新打开此选项。清除浏览器中的 Cookie 同样会使横幅重新出现。
8. Contact
For any privacy-related questions or requests, email privacy@iamaixa.com.