Skip to content
Legal · Axion Spark

Privacy, Terms, LGPD and Security

Legal review desk with documents, anonymized data flows and access controls
privacy as an architecture requirement

Data, purpose, access, retention and review must be clear before automation.

Privacy Policy

On this site, Axion Spark collects data voluntarily submitted in a contact request: name, work email, company, area of interest and a description of the challenge.

In client projects, processed data, purposes, legal bases, retention, subprocessors and security measures are defined in the contract, DPA or equivalent document.

The form is used to answer a commercial request under explicit consent. The record includes page origin and, only when preferences allow it, limited attribution parameters. Request fields are stored in Azure Table Storage. Azure Communication Services Email sends a plain-text notice to the institutional Microsoft 365 mailbox hello@axionspark.io with the identifier, name, work email, company, area of interest and full description of the challenge.

The validated work email is used as the reply address (Reply-To) so the team can respond to the request. The notice does not include IP, attribution parameters, advertising identifiers, telemetry or the raw consent record; opening and click tracking are disabled.

To prevent abuse and duplication, IP, email, payload and idempotency key are transformed with HMAC before entering temporary technical controls; this mechanism does not persist the raw IP.

Personal data is not sold or rented. After consent, Google, LinkedIn, Meta and TikTok may process the visited URL, referrer, browser/network data, cookies or pseudonymous identifiers and controlled events. Site code does not send them name, email, company, form text or requestId.

You may request confirmation of processing, access, correction, anonymization, portability, information about sharing, review of automated decisions when applicable or deletion of your data through privacidade@axionspark.io.

Retention: data submitted with a request is kept for up to 24 months after receipt, except for legal obligation or active contract; after this period it is anonymized or deleted.

This period and data-subject rights also cover the institutional mailbox copy, with access restricted to authorized staff. Email retention and access, correction or deletion requests are handled manually, including inbox, sent, archived and deleted items. Automatic deletion in Tables does not delete Microsoft 365 messages; no mailbox backup or automated mailbox deletion is promised.

Cookie Policy

The site uses essential local storage to remember privacy preferences. This category remains active so the same choice is not requested on every visit.

Google Analytics loads only after analytics permission. Google Ads, LinkedIn, Meta and TikTok load only after marketing permission; no request is made to these providers before that choice.

You may accept, reject or configure categories separately and reopen the panel through “Manage preferences” in the footer. The choice expires after 180 days or is requested again when this policy version changes.

The event facade does not add name, email, company, process description or an internal request identifier. Tags may process URL, referrer, browser, network, cookies and identifiers under each provider policy.

Terms of Use

This site is informational. Content, brands, internal methods (including AxionEthos and AxionCore) and materials displayed here are Axion Spark property and may not be reproduced without written authorization.

Examples, indicators and scenarios shown on the site are initial reading references, not outcome promises. Real metrics depend on baseline, scope, available data and each project contract.

Confidentiality, intellectual property, timelines and deliverables are defined in each proposal or contract when applicable; this website does not create those obligations by itself.

LGPD Compliance

Processing subject to Law No. 13.709/2018 (LGPD) must incorporate purpose, necessity, security and privacy by design according to the service context.

In client projects, Controller and Processor roles are defined according to the processing performed. A DPIA/RIPD or equivalent assessment is adopted when context, risk and applicable obligations justify it, together with legal bases, retention and data-subject channels.

Legal bases and purposes are documented by purpose: commercial contact, contract execution, security, legal compliance and protection of rights.

The contact channel for data-protection matters is dpo@axionspark.io.

Subprocessors

For this site, Microsoft Azure provides hosting, storage and delivery of the notice containing request fields. Microsoft 365 hosts the institutional mailbox receiving this copy for follow-up. Google, LinkedIn, Meta and TikTok operate only within measurement categories authorized by the visitor.

Contact requests are stored in the East US 2 region, in the United States. The email service uses the United States geography for data at rest. This involves international data transfers; the configuration does not mean that all provider processing occurs in a single country.

Active clients receive the subprocessor list applicable to their environment, with purpose, processing region when available and confidentiality obligation.

Security

Projects with automated decision go through governance design before production: automation level, approval point, owner, evidence and fallback.

Technical measures are defined by scope and environment: encryption in transit, access control, permission segregation, sensitive data masking, logs and vulnerability review when applicable.

Vulnerability reports can be sent to security@axionspark.io.

Last updated: September 5, 2026. Material changes will be indicated on this page and, when applicable, communicated to active clients.