AxioPlanPrivacy Policy

Legal & Compliance

Privacy Policy

Effective: June 2, 2026Last updated: June 2, 2026Version 1.0GDPR · CCPA
Important: This Privacy Policy describes how AxioPlan collects, uses, and protects your personal information. It applies to all users of axioplan.io - including visitors, free-tier users, and Pro subscribers. Please read it carefully before using our services.
01

Who We Are

AxioPlan (“AxioPlan”, “we”, “us”, or “our”) provides probabilistic project estimation software accessible at axioplan.io. Our platform enables engineering teams and project managers to plan projects using statistical modelling, T-shirt sizing, Gantt charts, dependency mapping, and resource capacity analysis.

We act as a data controller for personal data processed through our platform. Where we process personal data on behalf of our business customers, we act as a data processor.

ServiceAxioPlan - Probabilistic Project Estimation Software
Registered addressJonažolių g. 15, Lithuania
Privacy contactprivacy@axioplan.io
02

Scope of This Policy

This Policy applies to:

  • All visitors to axioplan.io
  • Registered users of the free tier and Pro subscription
  • Members of teams invited to AxioPlan by an account owner
  • Individuals whose information is entered into the platform by a registered user (e.g., team roster entries)

This Policy does not apply to third-party websites or services that may be linked from our platform. We encourage you to review the privacy policies of any third-party services you use.

03

Personal Data We Collect

3.1 Account and Identity Data

When you create an account or sign in, we collect:

  • Full name and email address
  • Google OAuth authentication token
  • Account preferences and notification settings

3.2 Project and Work Data

To deliver our service, we store the project information you enter, including:

  • Project names and target deadlines
  • Task and epic data: titles, descriptions, start dates, durations, progress, and status
  • Task dependencies and sequencing
  • T-shirt size estimates and confidence levels (low, medium, or high)
  • Team member entries: names, roles, and billing rates

Delivery timelines, cost estimates, and allocation outputs are calculated in real time and are not stored separately in our database.

3.3 Billing and Payment Data

For Pro subscribers, billing is handled by our third-party payment processor (Stripe). We do not store full payment card numbers on our servers. We retain:

  • Subscription tier and status
  • Billing email address and country
  • Invoice history and transaction references

3.4 Usage and Technical Data

We automatically collect technical and usage data when you use our service. Some of this data is collected directly by our infrastructure provider (Vercel) and analytics tools (Vercel Analytics and Google Tag Manager) and may include:

  • Approximate geographic location (country/city level)
  • Browser type and operating system
  • Pages visited and session duration
  • Referral source (how you arrived at axioplan.io)

We also log product usage events such as project creation, features used, and export actions to understand how the service is being used. These events are associated with your user account, not your device. We do not independently collect raw IP addresses or device identifiers beyond what is captured by our infrastructure and analytics providers.

3.5 Communications Data

When you contact us via email or a support channel, we retain your name and email address, the contents of your message and any attachments, and our responses and the history of the correspondence.

04

How We Use Your Personal Data

We use the personal data described above for the following purposes:

PurposeExamplesLegal Basis (GDPR)
Service deliveryCreating accounts, running estimation models, generating Gantt chartsContract performance (Art. 6(1)(b))
Account managementLogin, password reset, subscription management, team invitationsContract performance (Art. 6(1)(b))
Billing & paymentsProcessing subscriptions, issuing invoices, managing renewalsContract performance (Art. 6(1)(b))
Customer supportResponding to enquiries, resolving technical issuesLegitimate interests (Art. 6(1)(f))
Service improvementAnalysing usage patterns, fixing bugs, developing new featuresLegitimate interests (Art. 6(1)(f))
Security & fraud preventionDetecting abuse, preventing unauthorised access, rate limitingLegitimate interests (Art. 6(1)(f))
Legal complianceResponding to lawful requests, maintaining financial recordsLegal obligation (Art. 6(1)(c))
Marketing communicationsProduct updates and newsletters (opt-in only)Consent (Art. 6(1)(a))
05

Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We share data only in the following circumstances:

5.1 Service Providers (Data Processors)

  • Cloud Infrastructure - Hosting and database services (e.g., AWS, Vercel, or equivalent)
  • Payment Processing - Stripe (card data processed under PCI-DSS compliance)
  • Email Delivery - Transactional email providers (e.g., Postmark, Resend, or equivalent)
  • Analytics - Aggregated usage analytics tools (configured with IP anonymisation)
  • Error Monitoring - Application performance tools (e.g., Sentry)

5.2 Business Transfers

If AxioPlan undergoes a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

5.3 Legal Requirements

We may disclose your information where required to do so by law, court order, or regulatory authority - or where we believe in good faith that disclosure is necessary to protect our legal rights, prevent fraud, or protect the safety of users.

06

International Data Transfers

AxioPlan is operated from Lithuania (European Economic Area). Some of our service providers process data outside the EEA, including in the United States. Where this occurs, we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Binding corporate rules or equivalent mechanisms

You may request a copy of the relevant transfer mechanisms by contacting privacy@axioplan.io.

07

Data Retention

We retain personal data for as long as necessary to provide our services and comply with legal obligations:

Data CategoryRetention PeriodReason
Account & identity dataDuration of account + 30 days post-deletionService delivery; recovery window
Project & work dataDuration of account + 30 days post-deletionService delivery
Billing records7 years from transactionLegal/tax obligation
Support correspondence3 years from last interactionLegitimate interests (dispute resolution)
Usage & technical logsUp to 13 monthsService improvement; security monitoring
Marketing consent recordsUntil consent withdrawn + 3 yearsLegal compliance (demonstrating consent)

When we no longer need your data, we securely delete or anonymise it. You may request earlier deletion under your right to erasure (see Section 8).

08

Your Rights

8.1 GDPR Rights (EEA Residents)

If you are located in the European Economic Area, you have the following rights under the GDPR:

Art. 15
Access
Obtain a copy of all personal data we hold about you.
Response: 30 days
Art. 16
Rectification
Correct inaccurate or incomplete personal data.
Response: 30 days
Art. 17
Erasure
Request deletion of your personal data (“right to be forgotten”).
Response: 30 days
Art. 18
Restriction
Restrict how we process your data in certain circumstances.
Response: 30 days
Art. 20
Portability
Receive your data in a structured, machine-readable format (JSON).
Response: 30 days
Art. 21
Objection
Object to processing based on legitimate interests or for direct marketing.
Immediate (marketing)
Art. 7
Withdraw Consent
Revoke any consent previously given without affecting prior lawful processing.
Immediate
Art. 77
Lodge a Complaint
Complain to your national supervisory authority (e.g., VDAI in Lithuania).
N/A
How to Exercise Your Rights

Submit a request to privacy@axioplan.io with your name, email address, and a description of the right you wish to exercise. We may need to verify your identity before acting on the request.

8.2 CCPA Rights (California Residents)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Right to Know - The categories and specific pieces of personal information we collect, use, disclose, and sell
  • Right to Delete - Request deletion of your personal information, subject to certain exceptions
  • Right to Correct - Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing - AxioPlan does not sell personal information or share it for cross-context behavioural advertising
  • Right to Limit Sensitive PI Use - We do not use sensitive personal information beyond what is necessary to provide our service
  • Right to Non-Discrimination - Exercising your rights will not result in denial of service or different pricing

To exercise CCPA rights, contact us at privacy@axioplan.io. Response time: 45 days (extendable by a further 45 days with notice).

09

Security

We implement technical and organisational measures proportionate to the risk associated with your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • All data at rest is encrypted at the infrastructure level by our database provider
  • We authenticate users exclusively via Google OAuth 2.0 - we do not store passwords
  • Sessions are managed using short-lived, HttpOnly, secure cookies
  • Access to project data is restricted to the account owner and users explicitly invited to share a project
  • Access to production systems is restricted to authorised personnel

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Articles 33 and 34.

10

Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our service. You can manage preferences via the cookie banner on your first visit or through your browser settings.

11

Children's Privacy

AxioPlan is a business tool intended for users aged 18 and over. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor has provided us with personal data, please contact privacy@axioplan.io and we will delete the information promptly.

12

Automated Decision-Making

AxioPlan uses statistical algorithms (Monte Carlo simulations, PERT calculations, and critical-path analysis) to generate project estimation outputs. These outputs are tools to assist human decision-makers and do not constitute automated decisions that produce legal or similarly significant effects on individuals within the meaning of GDPR Article 22.

13

Third-Party Links and Integrations

Our platform may contain links to third-party websites or may integrate with external services. These third parties have their own privacy policies, and we are not responsible for their data practices. We encourage you to review their policies before sharing data with them.

14

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the “Last Updated” date at the top of this document
  • Display a notice on axioplan.io for material changes
  • Send an email notification to registered users for significant changes

Your continued use of AxioPlan after the effective date of any update constitutes your acceptance of the revised Policy.

15

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Response timeWe aim to respond to all privacy requests within 5 business days

If you are an EEA resident and we are unable to resolve your concern, you have the right to lodge a complaint with your local supervisory authority. In Lithuania, this is the State Data Protection Inspectorate (VDAI): www.vdai.lrv.lt.

Annex A
A

Legal Bases for Processing (GDPR Reference)

The following table summarises the legal basis relied upon for each category of processing activity, as required by GDPR Articles 13 and 14:

Processing ActivityData CategoriesLegal BasisGDPR Article
Account creation & loginIdentity, credentialsContract performanceArt. 6(1)(b)
Providing the software serviceAll account & project dataContract performanceArt. 6(1)(b)
Billing & subscription managementBilling, identityContract performanceArt. 6(1)(b)
Customer supportIdentity, communicationsLegitimate interestsArt. 6(1)(f)
Service analytics & improvementUsage, technical dataLegitimate interestsArt. 6(1)(f)
Security monitoringUsage, technical dataLegitimate interestsArt. 6(1)(f)
Financial record keepingBilling, identityLegal obligationArt. 6(1)(c)
Marketing emails (opt-in)Identity, preferencesConsentArt. 6(1)(a)
Cookie analytics (non-essential)Cookie, technical dataConsentArt. 6(1)(a)
Annex B
B

Glossary

ControllerThe entity that determines the purposes and means of processing personal data.
Data SubjectThe identified or identifiable natural person whose personal data is being processed.
GDPRGeneral Data Protection Regulation (EU) 2016/679.
CCPA / CPRACalifornia Consumer Privacy Act / California Privacy Rights Act.
Personal DataAny information relating to an identified or identifiable natural person.
ProcessingAny operation performed on personal data (collection, storage, use, disclosure, deletion).
ProcessorAn entity that processes personal data on behalf of a controller.
SCCStandard Contractual Clauses - EU-approved mechanisms for international data transfers.
DPOData Protection Officer - responsible for advising on and monitoring GDPR compliance.
VDAIState Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija).