Privacy, Terms, LGPD and Security

Data, purpose, access, retention and review must be clear before automation.
Privacy Policy
On this site, Axion Spark collects data voluntarily submitted in a contact request: name, work email, company, area of interest and a description of the challenge.
In client projects, processed data, purposes, legal bases, retention, subprocessors and security measures are defined in the contract, DPA or equivalent document.
The form is used to answer a commercial request under explicit consent. The record includes page origin and, only when preferences allow it, limited attribution parameters. Request fields are stored in Azure Table Storage. Azure Communication Services Email sends a plain-text notice to the institutional Microsoft 365 mailbox hello@axionspark.io with the identifier, name, work email, company, area of interest and full description of the challenge.
The validated work email is used as the reply address (Reply-To) so the team can respond to the request. The notice does not include IP, attribution parameters, advertising identifiers, telemetry or the raw consent record; opening and click tracking are disabled.
To prevent abuse and duplication, IP, email, payload and idempotency key are transformed with HMAC before entering temporary technical controls; this mechanism does not persist the raw IP.
Personal data is not sold or rented. After consent, Google, LinkedIn, Meta and TikTok may process the visited URL, referrer, browser/network data, cookies or pseudonymous identifiers and controlled events. Site code does not send them name, email, company, form text or requestId.
You may request confirmation of processing, access, correction, anonymization, portability, information about sharing, review of automated decisions when applicable or deletion of your data through privacidade@axionspark.io.
Retention: data submitted with a request is kept for up to 24 months after receipt, except for legal obligation or active contract; after this period it is anonymized or deleted.
This period and data-subject rights also cover the institutional mailbox copy, with access restricted to authorized staff. Email retention and access, correction or deletion requests are handled manually, including inbox, sent, archived and deleted items. Automatic deletion in Tables does not delete Microsoft 365 messages; no mailbox backup or automated mailbox deletion is promised.
Terms of Use
This site is informational. Content, brands, internal methods (including AxionEthos and AxionCore) and materials displayed here are Axion Spark property and may not be reproduced without written authorization.
Examples, indicators and scenarios shown on the site are initial reading references, not outcome promises. Real metrics depend on baseline, scope, available data and each project contract.
Confidentiality, intellectual property, timelines and deliverables are defined in each proposal or contract when applicable; this website does not create those obligations by itself.
LGPD Compliance
Processing subject to Law No. 13.709/2018 (LGPD) must incorporate purpose, necessity, security and privacy by design according to the service context.
In client projects, Controller and Processor roles are defined according to the processing performed. A DPIA/RIPD or equivalent assessment is adopted when context, risk and applicable obligations justify it, together with legal bases, retention and data-subject channels.
Legal bases and purposes are documented by purpose: commercial contact, contract execution, security, legal compliance and protection of rights.
The contact channel for data-protection matters is dpo@axionspark.io.
Subprocessors
For this site, Microsoft Azure provides hosting, storage and delivery of the notice containing request fields. Microsoft 365 hosts the institutional mailbox receiving this copy for follow-up. Google, LinkedIn, Meta and TikTok operate only within measurement categories authorized by the visitor.
Contact requests are stored in the East US 2 region, in the United States. The email service uses the United States geography for data at rest. This involves international data transfers; the configuration does not mean that all provider processing occurs in a single country.
Active clients receive the subprocessor list applicable to their environment, with purpose, processing region when available and confidentiality obligation.
Security
Projects with automated decision go through governance design before production: automation level, approval point, owner, evidence and fallback.
Technical measures are defined by scope and environment: encryption in transit, access control, permission segregation, sensitive data masking, logs and vulnerability review when applicable.
Vulnerability reports can be sent to security@axionspark.io.