Legal
Privacy Policy
Last updated: September 21, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to run the Service and to support Your calibration program. Where the law requires Your consent for something, We ask for it separately and You can say no. Using the Service is not by itself Your consent.
This notice describes what the software does and what CaliTech LLC commits to. We hold no privacy certification and We have not been audited against one. Nothing here is a claim that We have been.
Where Your data is stored
Axiospec runs in Amazon Web Services in the us-east-1 region, Northern Virginia, United States. The database, the uploaded evidence files, the application secrets and the application itself are all in that one region. If You use Axiospec from outside the United States then Your personal data is transferred to the United States and processed there.
The content delivery network in front of the site is a global edge network. It terminates the connection at an edge location that may be outside the United States and forwards the request to us-east-1. API responses are not cached at the edge.
The third parties We use process data in their own locations. Our Subprocessors page lists every one of them and says what each receives and why.
When We are the controller, and when We are a processor
Axiospec holds two different kinds of personal data, and Our role is not the same for both.
-
Your account and Our relationship with You. Your name, Your email address, Your sign-in records, Your billing details and Our marketing to You. We decide why and how that data is processed, so We are the controller for it.
-
What Your workspace puts into the product. Instrument records, calibration events, custody entries, vendor contacts, uploaded certificates and photographs, and any name a member of Your team types into a free-text field. Your organization decides what goes in and why. We hold it and act on Your organization's instructions, so Your organization is the controller and We are a processor.
If You work for an Axiospec customer and You want a record about You changed or removed, ask Your workspace administrator first. We will help them. If We cannot act without them We will say so rather than leave You waiting.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
-
Account means a unique account created for You to access our Service or parts of our Service.
-
Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
-
Application refers to Axiospec, the software program provided by the Company.
-
Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information, or on behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers' personal information, that does business in the State of California.
-
CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").
-
Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to CaliTech LLC d/b/a Axiospec, 313 Agnes Rd, STE 200, Knoxville TN 37919.
-
Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the USA for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the USA who is outside the USA for a temporary or transitory purpose.
-
Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
-
Controller means the party that decides why and how personal data is processed.
-
Country refers to: Tennessee, United States
-
Data Subject means the living individual a piece of personal data is about.
-
Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
-
Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
-
Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual.
For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.
We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.
-
Service refers to the Application or the Website or both.
-
GDPR refers to the EU General Data Protection Regulation (Regulation (EU) 2016/679) and, where We are writing about the United Kingdom, to the UK GDPR and the Data Protection Act 2018.
-
Processor means a party that processes personal data on a controller's instructions.
-
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
-
Supervisory Authority means a public authority set up by an EEA member state or by the United Kingdom to enforce data protection law.
-
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
-
Website refers to Axiospec, accessible from https://axiospec.com.
-
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Your workspace or company name. For a one-person workspace that name is usually a personal name.
- The address, city, state, postal code and country of each site where Your instruments are kept. For a home workshop that is a home address.
- Your role in the workspace, the sites You are granted access to, and Your display preferences
- Sign-in records, including the time of Your current and previous sign-in
- If You turn on two-factor authentication: a sealed authenticator secret, hashed recovery codes, the IP address that confirmed the factor, and a label for each device You mark as trusted. That label is the browser or app identification string the device sent.
- Billing contact details. You enter those directly into Stripe's payment form and We never hold Your card number.
- A push notification token for each mobile device You sign in on and allow notifications for
- Campaign information captured when You first arrive from a link: the campaign tags on the URL, a Google click identifier if the link carries one, the address of the page that referred You, and the first page You landed on
The product also holds personal data about people who have no Axiospec account, because Your team types it in. See "People who are not Our users" below.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit Our Service or when You access the Service by or through a mobile device.
Information Collected while Using the Application
While using Our Application, in order to provide features of Our Application, We may collect, with Your prior permission:
- Pictures and other information from your Device's camera and photo library
We use this information to provide features of Our Service, to improve and customize Our Service. The information may be uploaded to the Company's servers and/or a Service Provider's server or it may be simply stored on Your device.
You can enable or disable access to this information at any time, through Your Device settings.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies We use include beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
- Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
- Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of a certain section and verifying system and server integrity).
Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on Your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close Your web browser.
Where required by law, we use non-essential cookies (such as analytics, advertising, and remarketing cookies) only with Your consent. You can withdraw or change Your consent at any time by selecting "Cookie settings" in the footer of Our website or in the sidebar of the application, or through Your browser/device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use both Session and Persistent Cookies for the purposes set out below:
-
Strictly necessary storage
Type: browser local storage, held on Your device
Administered by: Us
Purpose: Your session token is issued by Our own API and held in Your browser's local storage. It is what keeps You signed in. The same storage holds Your workspace identifier, Your role and Your display preferences so the app can render correctly. Clearing this site's stored data in Your browser signs You out and removes all of it.
-
Your cookie choice
Type: browser local storage, held on Your device
Administered by: Us
Purpose: records whether You chose Accept or Decline on the banner, so You are not asked again on every page.
-
Trusted device token
Type: browser local storage, held on Your device
Administered by: Us
Purpose: if You turn on two-factor authentication and mark a device as trusted, this token is what lets that device skip the second factor. It is a persistent identifier for the device. You can revoke it from Settings, and You should on any shared computer.
-
Analytics
Type: cookies set by Google, plus campaign information in local storage
Administered by: Google (Google Analytics 4) and Us
Purpose: to understand how people find the site and which parts of the product get used. We run no advertising tag. Google Ads was discontinued on 15 September 2026 and no ad tag, ad conversion or remarketing pixel ships on the site today.
How to change Your choice today: clear this site's stored data in Your browser. The banner then asks again and no previous choice is remembered. There is currently no in-page control that reopens the banner once You have answered it. We would rather write that down than describe a button that does not exist.
For more information about the cookies we use and your choices regarding cookies, please visit our Cookies Policy or the Cookies section of Our Privacy Policy.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
-
To provide and maintain our Service, including to monitor the usage of our Service.
-
To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
-
For the performance of a contract: the development, compliance and undertaking of the purchase contract for the products, items or services You have purchased or of any other contract with Us through the Service.
-
To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application's push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
-
To provide You with news, special offers, and general information about other goods, services and events which We offer that are similar to those that you have already purchased or inquired about unless You have opted not to receive such information.
-
To manage Your requests: To attend and manage Your requests to Us.
-
For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.
-
For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service, products, services, marketing and your experience.
We may share Your Personal Data in the following situations:
- With Service Providers: We may share Your Personal Data with Service Providers to monitor and analyze the use of our Service, for payment processing, to contact You.
- For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your Personal Data with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
- With business partners: We may share Your Personal Data with Our business partners to offer You certain products, services or promotions.
- With other users: If Our Service offers public areas, when You share Personal Data or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside.
- With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Where possible, We apply shorter retention periods and/or reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods ("up to") and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose. We apply different retention periods to different categories of Personal Data based on the purpose of processing and legal obligations:
-
Your account
- Kept for as long as the account is open. There is no age rule that deletes an account for being quiet, and an account that is never closed is kept indefinitely. That is deliberate, because a calibration register is a compliance record a customer may need years later.
- When You ask Us to close the account, sign-in stops at once and billing is cancelled at once. The data is then kept for 730 days, about 24 months, so You can sign back in, export Your records, or change Your mind. After that window it is purged.
- If You want it erased sooner than 730 days, say so and We will do it by hand. See "How to exercise Your rights".
-
Calibration and instrument records, and the names attached to them
- Kept for as long as the workspace exists, then purged with the workspace at the end of the 730-day window. We apply no age rule to them. They are Your organization's compliance evidence and an assessor may ask for history going back years.
-
Support and feedback correspondence
- Support runs by email. Messages You send Us live in Our mailbox and are kept until We clear them out. We have set no automatic expiry, and the in-product feedback form is emailed rather than stored in the product, so the system itself cannot find it later. If You want a message You sent Us deleted, ask and We will delete it.
-
Application and server logs
- These are kept in Amazon CloudWatch with no expiry date set today, so they persist. Some of them contain an email address recorded at sign-up, and a log line cannot be picked out and deleted on request. Setting an explicit retention period is open work, and this notice will state the period once it is set. Our infrastructure audit trail is separate and expires after 365 days.
-
Website analytics
- Held by Google under the retention setting on Our Google Analytics property. We have not published that setting here because We have not confirmed it, and We would rather leave it blank than print a number We have not checked.
-
Marketing contacts
- If You give Us Your email address to receive something from Us, We keep it until You ask Us to delete it. Unsubscribing stops the sending and keeps a record of the address, because that record is how We avoid writing to You again. Ask Us to delete it outright and We will remove it by hand. There is no self-service control for that today, and nothing removes a marketing address on a schedule.
-
Payments and tax
- Card details are never stored on Our servers. They are entered directly into Our payment processor. We keep transaction records, invoices and purchase history for up to 10 years to meet tax and accounting obligations.
- Where We owe a commission or a tax filing to a referral partner, the records that prove it are kept for the same reason, including the partner's legal name and contact address. Closing a workspace does not remove those, because they are Our own financial records rather than the workspace's.
Usage Data is retained in accordance with the retention periods described above, and may be retained longer only where necessary for security, fraud prevention, or legal compliance.
We may retain Personal Data beyond the periods stated above for different reasons:
- Legal obligation: We are required by law to retain specific data (e.g., financial records for tax authorities).
- Legal claims: Data is necessary to establish, exercise, or defend legal claims.
- Your explicit request: You ask Us to retain specific information.
- Technical limitations: Data exists in backup systems that are scheduled for routine deletion.
You may request information about how long We will retain Your Personal Data by contacting Us.
When retention periods expire, We securely delete or anonymize Personal Data according to the following procedures:
- Deletion: Personal Data is removed from Our systems and no longer actively processed.
- Backup retention: Residual copies may remain in encrypted backups for a limited period consistent with our backup retention schedule and are not restored except where necessary for security, disaster recovery, or legal compliance.
- Anonymization: In some cases, We convert Personal Data into anonymous statistical data that cannot be linked back to You. This anonymized data may be retained indefinitely for research and analytics.
Transfer of Your Personal Data
CaliTech LLC is a United States company and the Service runs in the United States, in AWS us-east-1. Using Axiospec from anywhere else means Your personal data is transferred to the United States and processed there. Several of Our subprocessors operate globally and may process data in other countries. Our Subprocessors page names each one.
Be clear about what that means today for a transfer out of the European Economic Area, the United Kingdom or Switzerland. See the section below for people in those places, which sets out what is in force and what is not.
Delete Your Personal Data
You can delete Your account from inside the product. Sign in, then open Settings and the Profile tab, or use the Delete Account link in the footer. The page is at /account/delete. You confirm with Your password. If You own the workspace You also type the workspace name, because that request closes the workspace for everybody in it.
What happens next: sign-in stops immediately, billing is cancelled immediately, and the data is held for 730 days so You can come back and export it. After that it is purged. Signing back in during the window cancels the deletion.
Be exact about what the purge reaches, because the easy sentence here would be wider than the truth. It removes the workspace records from the database, and it removes three kinds of uploaded file from storage: the documents attached to an instrument, the attachments on a calibration record, and the files You uploaded for an import. Other stored files are left behind today. Issued certificate PDFs, extra photographs added to a calibration beyond the first attachment, instrument photographs, the workspace logo and any audit archive You generated all stay in storage after the purge, with no record pointing at them. Files You sent Us for a white-glove migration are removed by a separate 90-day storage rule rather than by the purge. Extending the purge to cover the rest is open work, and this notice will say so when it is done.
You can also correct most of Your own details from Settings. Ask Us and We will do it for You.
Some things survive a deletion on purpose. Billing and tax records, records of money We owe a referral partner, and the names frozen into completed calibration records are all kept, and the section below for the European Economic Area and the United Kingdom explains the calibration one in full. Backups roll off on their own schedule and are not restored except for recovery or a legal requirement.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
Detailed Information on the Processing of Your Personal Data
The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.
Analytics
We may use third-party Service Providers to monitor and analyze the use of our Service.
-
Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity.
You may opt-out of certain Google Analytics features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy
-
Firebase
Firebase is a Google service. We use Firebase Cloud Messaging to deliver push notifications to Your device. Our own servers send those messages, so Your device push token and the text of the notification are processed by Google. That text can name an instrument that is due or overdue. We also use Firebase Analytics in our Android application. We do not use Firebase to sign You in or to hold Your account credentials.
You may opt-out of certain Firebase features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy
We also encourage You to review Google's policy for safeguarding Your data: https://support.google.com/analytics/answer/6004245
For more information on what type of information Firebase collects, please visit the How Google uses data when you use our partners' sites or apps webpage: https://policies.google.com/technologies/partner-sites
Email Marketing
We may use Your Personal Data to contact You with newsletters, marketing or promotional materials and other information that may be of interest to You. You may opt-out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us.
We may use Email Marketing Service Providers to manage and send emails to You.
-
Amazon Web Services (AWS)
Their Privacy Policy can be viewed at https://aws.amazon.com/privacy/
Error and performance monitoring
-
Sentry
We use Sentry to catch application errors on the website, in the app and in the mobile apps. Sentry receives the error, the stack trace and the request path. Sending personal data with an error is switched off, and every event passes through a scrubbing step before it leaves. Two things We will not overstate: Your IP address reaches Sentry simply because Your browser makes the request, and an identifier can still appear inside an error message that no scrubber predicted. Where You are signed in, Sentry is given Your internal user identifier and nothing else, so no name or email is attached.
Their Privacy Policy can be viewed at https://sentry.io/privacy/
Voice dictation in the mobile apps
The mobile apps let You dictate calibration readings instead of typing them. That uses the speech recognition built into Your phone. On Android the audio is sent to Google, and on iOS it is sent to Apple. It is not processed on the device. We receive only the text that comes back. Nothing is sent unless You press the microphone button.
Payments
We may provide paid products and/or services within the Service. In that case, we may use third-party services for payment processing (e.g. payment processors).
We will not store or collect Your payment card details. That information is provided directly to Our third-party payment processors whose use of Your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
-
Stripe
Their Privacy Policy can be viewed at https://stripe.com/us/privacy
Notice for the European Economic Area, the United Kingdom and Switzerland
This section applies if You are in the European Economic Area, the United Kingdom or Switzerland. It sits alongside the rest of this notice. Where the two disagree, this section governs for people in those places.
Who is responsible
See "When We are the controller, and when We are a processor" near the top of this notice. In short, We are the controller for Your account and Our relationship with You, and a processor for what Your workspace records in the product.
CaliTech LLC is not required to appoint a data protection officer and has not appointed one. Privacy questions sent to support@axiospec.com reach the owner of the company directly.
What We process, why, and on what legal basis
This table covers the data We process as controller. The last row covers the data Your organization controls.
| What We process | Why | Legal basis |
|---|---|---|
| Name, email address, password hash, role, site grants, sign-in records | To open and run Your account and keep it working | Performance of a contract, Article 6(1)(b) |
| Two-factor secret and recovery codes, the IP address that confirmed the factor, trusted device labels, sign-in failure counters | To stop someone else getting into Your account | Legitimate interests in securing the Service, Article 6(1)(f) |
| Billing contact details and transaction records | To take payment and to meet tax and accounting rules | Performance of a contract, Article 6(1)(b), and legal obligation, Article 6(1)(c) |
| Service email: team invitations, calibration reminders, email verification, account notices | To deliver the Service You asked for | Performance of a contract, Article 6(1)(b) |
| Marketing email where You gave Us Your address without opening an account | To tell You about Axiospec | Consent, Article 6(1)(a). One click unsubscribes. |
| Website analytics | To see how people find the site and which parts get used | Consent, Article 6(1)(a), given on the banner. Nothing is requested from Google and nothing is stored until You accept. |
| The campaign information stored on Your device when You arrive from a link, including a Google click identifier and the address You came from | To see which links and campaigns bring people to the site | Consent, Article 6(1)(a). The capture runs only after You accept on the banner. No answer is treated as a refusal. |
| Application error and crash reports | To find and fix faults | Legitimate interests in a working, secure product, Article 6(1)(f) |
| Server and access logs, including IP addresses | To keep the Service running and to investigate abuse | Legitimate interests in security and availability, Article 6(1)(f), with the qualification set out below the table |
| Mobile push notification tokens | To send the alerts You turned on | Consent, given at the device prompt, Article 6(1)(a) |
| Dictated audio in the mobile apps | To turn speech into a reading when You press the microphone | Consent, Article 6(1)(a) |
| Instrument records, calibration events, custody entries, vendor contacts, uploaded files, and any name typed into a free-text field | Whatever Your organization records it for | Your organization sets the basis. We process it on their instructions. |
Where We rely on legitimate interests We have written down the interest, why the processing is necessary for it, and whether it overrides You. Those assessments sit in Our internal record of processing activities and We will share the relevant part on request.
One of them does not come out in Our favour as things stand, and it would be dishonest to publish the table without saying so. The assessment for server and application logs concludes that the interest is legitimate but that the current implementation goes further than the interest needs. An email address given at sign-up is written into log lines in readable form, those logs have no expiry set, and a single log line cannot be picked out and deleted on request. Taking the addresses out of those lines and setting a retention period is open work. Until it is done We do not rest on that assessment.
Nothing reaches Google before You answer the banner. The analytics tag is not requested, no connection to Google is opened, and no campaign information is written to Your device until You select "Accept". There is no regional starting position: analytics storage is off everywhere, whatever Your location, until You turn it on. No answer is treated as a refusal. If You later withdraw, We tell Google Your choice has changed and delete the analytics cookies already on Your device, though We cannot recall information sent before You withdrew. The section "Tracking Technologies and Cookies" above sets it out in full.
International transfers
Your personal data is transferred to the United States and held in AWS us-east-1. State the position plainly:
- CaliTech LLC has not executed Standard Contractual Clauses with its customers, and offers no EU or UK data region.
- CaliTech LLC is not certified under the EU-US Data Privacy Framework or its UK extension.
- A data processing agreement and transfer terms are being prepared with legal advice. They will be published here when they are in force, and not before.
We would rather tell You that now than let You assume otherwise from a page of reassuring language.
Your rights
If the GDPR applies to You then You have the right to:
- Be told what We hold about You and why. That is what this notice is for.
- Get a copy of Your personal data.
- Have it corrected if it is wrong or incomplete.
- Have it erased, subject to the limits set out below.
- Restrict how We use it while a dispute about it is being worked out.
- Take it with You in a machine-readable form, where We process it by consent or under a contract and by automated means.
- Object to processing We base on legitimate interests, and to direct marketing at any time.
- Withdraw consent where consent is what We relied on. That does not make the earlier processing unlawful.
- Complain to a supervisory authority.
You will never be charged for exercising a right and You will never be treated worse for it.
How to exercise Your rights
-
Deleting Your account. Sign in and go to /account/delete, reachable from Settings and from the footer. The section "Delete Your Personal Data" above sets out exactly what happens and when.
-
Getting a copy of Your workspace's records. Managers, administrators and auditors can generate a complete audit archive from inside the product at any time. It is a ZIP of open-format files: a CSV manifest, a PDF report, Your original uploaded evidence, and written instructions for verifying the record chain without Us.
-
Getting a copy of Your own data as an individual. Sign in and go to /account/data, reachable from Settings. Confirm Your password and the download starts. It is a ZIP of open-format files covering the personal data We hold about You. You do not need to ask Us, and You will not be asked why. A technician still cannot run the WORKSPACE archive, by design, because that is a bulk export of everybody's records.
-
Erasure sooner than the 730-day window. Sign in and go to /account/data, confirm Your password, and erase it yourself. The page lists what goes and what stays before You confirm. If You are the last remaining administrator of a workspace the page says so, because erasing You would leave it with nobody who can run it. Email support@axiospec.com in that case.
-
Anything else. Email support@axiospec.com. Tell Us what You want and give Us enough detail to find Your records.
We will verify who You are before We act, because handing someone else's data to the wrong person is the worse failure. We answer within one month of verifying You. If a request is complicated We may take up to two further months, and if We do We will tell You why inside the first month.
What We keep even after an erasure request
Some things survive, and each has a reason. This is the whole list as We understand it today.
-
Names frozen into completed calibration records. When a calibration is committed, the name of the person who performed it and the name of anyone who reviewed it are written into an append-only ledger and folded into a SHA-256 chain, where each record's hash covers the one before it. That chain is what makes the record tamper-evident, and tamper-evidence is the whole point of the register. Removing a name from a committed record breaks the chain for every record after it.
We treat this as processing that is necessary for the establishment, exercise or defence of legal claims and for compliance with a legal obligation resting on the workspace, which is the limit on erasure in Article 17(3). That position has not been tested by a regulator, and We say so rather than present it as settled. If You ask, We will tell You exactly which records carry Your name and We will stop using them for anything beyond keeping the record intact.
-
Your name and email inside a workspace that carries on without You. If You leave a team and Your user account is deleted, that removes Your sign-in, Your password, Your API keys, Your linked sign-in providers, Your calendar feed link and Your device tokens. It does not by itself clear Your details from the workspace's own records. A custody entry records the name of whoever held an instrument. A message log records the address a reminder was sent to. An administrative record of Your invitation or of a change to Your email address holds the address as it was. An audit archive records the email of whoever asked for it, and a gage study records the email of whoever created it.
Ask Us and We will tell You which records carry Your details, and remove the ones that can be removed without breaking a committed calibration record. Today that is done by hand.
-
Billing, tax and partner payment records. Kept because the law requires it. Up to 10 years.
-
Backups. Residual copies sit in encrypted backups until they roll off the backup schedule. They are not restored except for disaster recovery or a legal requirement.
Automated decisions
Axiospec makes no automated decision that produces a legal effect on You or affects You in a similarly significant way, and does no profiling of that kind. A calibration due date is arithmetic on the interval Your workspace set. It is a calculation about an instrument, not a judgement about a person.
People who are not Our users
A workspace can record personal data about people who have no Axiospec account. In practice that means:
- a named contact at an outside calibration laboratory, with their work email address and phone number
- extra email addresses a workspace adds so that calibration reminders reach someone beyond the account holders
- a person named in a free-text field, such as an instrument's assignee, its department, or a note on a custody entry
- a person who happens to be visible in an uploaded photograph of a bench or an instrument
That data is entered by the workspace, not by Us. The workspace decided to collect it and is the controller for it. We are the processor.
If You think an Axiospec workspace holds data about You and You want it corrected or removed, write to support@axiospec.com with enough detail to find the record. We will identify the workspace, pass Your request to it, and tell You what happened. We will not hand Your request to a workspace that has nothing about You in it.
Complaining
You can complain to the data protection authority for the place You live or work, or where You think the problem happened. In the United Kingdom that is the Information Commissioner's Office. We would rather You came to Us first, at support@axiospec.com, so We can fix it. Coming to Us first is not a condition of complaining.
CCPA/CPRA Privacy Notice (California Privacy Rights)
This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California.
Categories of Personal Information Collected
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information which We may collect or may have been collected from California residents within the last twelve (12) months.
Please note that the categories and examples provided in the list below are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact collected by Us, but reflects our good faith belief to the best of Our knowledge that some of that information from the applicable category may be and may have been collected. For example, certain categories of Personal Information would only be collected if You provided such personal information directly to Us.
-
Category A: Identifiers.
Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, driver's license number, passport number, or other similar identifiers.
Collected: Yes.
-
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
Examples: A name, signature, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.
Some personal information included in this category may overlap with other categories.
Collected: Yes.
-
Category C: Protected classification characteristics under California or federal law.
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Collected: No.
-
Category D: Commercial information.
Examples: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Collected: Yes.
-
Category E: Biometric information.
Examples: Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
Collected: No.
-
Category F: Internet or other similar network activity.
Examples: Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.
Collected: Yes.
-
Category G: Geolocation data.
Examples: Approximate physical location, physical location or movements.
Collected: No.
-
Category H: Sensory data.
Examples: Audio, electronic, visual, thermal, olfactory, or similar information.
Collected: No.
-
Category I: Professional or employment-related information.
Examples: Current or past job history or performance evaluations.
Collected: No.
-
Category J: Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
Examples: education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
Collected: No.
-
Category K: Inferences drawn from other personal information.
Examples: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Collected: No.
-
Category L: Sensitive personal information.
Examples: Government-issued identifying numbers, financial account details, genetic data, precise geolocation, race or ethnicity, religious or philosophical beliefs, union membership, mail, email, text messages, biometric data, health data, and sexual orientation or sex life.
Collected: No.
Under CCPA/CPRA, Personal Information does not include:
- Publicly available information from government records
- Deidentified or aggregated consumer information
- Information excluded from the CCPA/CPRA's scope, such as:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data
- Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from You. For example, from the forms You complete on our Service, preferences You express or provide through our Service, or from Your purchases on our Service.
- Indirectly from You. For example, from observing Your activity on our Service.
- Automatically from You. For example, through cookies We or our Service Providers set on Your Device as You navigate through our Service.
- From Service Providers. For example, third-party vendors to monitor and analyze the use of our Service, third-party vendors for payment processing, or other third-party vendors that We use to provide the Service to You.
Use of Personal Information
We may use or disclose personal information We collect for "business purposes" or "commercial purposes" (as defined under the CCPA/CPRA), which may include the following examples:
- To operate our Service and provide You with Our Service.
- To provide You with support and to respond to Your inquiries, including to investigate and address Your concerns and monitor and improve our Service.
- To fulfill or meet the reason You provided the information. For example, if You share Your contact information to ask a question about our Service, We will use that personal information to respond to Your inquiry. If You provide Your personal information to purchase a product or service, We will use that information to process Your payment and facilitate delivery.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to You when collecting Your personal information or as otherwise set forth in the CCPA/CPRA.
- For internal administrative and auditing purposes.
- To detect security incidents and protect against malicious, deceptive, fraudulent or illegal activity, including, when necessary, to prosecute those responsible for such activities.
- Other purposes consistent with the context in which the information was collected, or as otherwise disclosed to You at the time of collection.
Please note that the examples provided above are illustrative and not intended to be exhaustive. For more details on how we use this information, please refer to the "Use of Your Personal Information" section.
If We decide to collect additional categories of personal information or use the personal information We collected for materially different, unrelated, or incompatible purposes, We will update this Privacy Policy.
Disclosure of Personal Information
We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:
- Category A: Identifiers
- Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e))
- Category D: Commercial information
- Category F: Internet or other similar network activity
Please note that the categories listed above are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact disclosed, but reflects our good faith belief to the best of our knowledge that some of that information from the applicable category may be and may have been disclosed.
When We disclose Personal Information for a business purpose or a commercial purpose, We enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
Sharing of Personal Information
We may share, and have shared in the last twelve (12) months, Your personal information identified in the above categories with the following categories of third parties:
- Service Providers
- Payment processors
- Our affiliates
- Our business partners
- Third-party vendors to whom You or Your agents authorize Us to disclose Your personal information in connection with products or services We provide to You
Sale of Personal Information
As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the Business to a third party for valuable consideration. This means that We may have received some kind of benefit in return for sharing personal information, but not necessarily a monetary benefit.
We do not "sell" or "share" information as most people would commonly understand these terms, meaning We do not, and will not, disclose Your Personal Information in direct exchange for money or some other form of payment.
We do not run advertising on the Service and We do not use it for cross-context behavioral advertising. Google Ads was discontinued on 15 September 2026 and every ad tag was removed from the site and the app. What remains is Google Analytics, which receives page paths and interaction events and sets its own cookies once You allow it. We take the view that this does not amount to a sale, and We describe it so that You can judge it for Yourself rather than take Our word.
An earlier version of this notice declared a "sale" and "sharing" for cross-context behavioral advertising. That was written when advertising tags were in use. It is no longer true and it has been removed.
Retention of Personal Information
We retain California residents' Personal Information for as long as reasonably necessary to achieve the purposes described in this Privacy Policy (including the purposes disclosed in this CCPA/CPRA notice), taking into account: (i) how long we need the information to provide and maintain the Service and Your Account; (ii) whether You have requested deletion (subject to applicable exceptions); (iii) Our legal, tax, accounting, and regulatory obligations; (iv) security, fraud prevention, and abuse monitoring needs; and (v) the time periods needed to resolve disputes and enforce Our agreements.
Specific retention periods for major data categories are described in the "Retention of Your Personal Information" section of Our Privacy Policy, and We may retain certain information longer where required or permitted by law (for example, to comply with recordkeeping obligations or to establish, exercise, or defend legal claims).
Sale of Personal Information of Minors Under 16 Years of Age
We do not knowingly collect personal information from minors under the age of 16 through our Service, although certain third party websites that we link to may do so. These third-party websites have their own terms of use and privacy policies and We encourage parents and legal guardians to monitor their children's Internet usage and instruct their children to never provide information on other websites without their permission.
We do not sell the Personal Information of Consumers We actually know are less than 16 years of age, unless We receive affirmative authorization (the "right to opt-in") from the parent or guardian of a Consumer less than 16 years of age. Consumers who opt-in to the sale of personal information may opt-out of future sales at any time. To exercise the right to opt-out, You (or Your authorized representative) may submit a request to Us by contacting Us.
If You have reason to believe that a child under the age of 16 has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information.
Your Rights under the CCPA/CPRA
The CCPA/CPRA provides California residents with specific rights regarding their personal information. If You are a resident of California, You have the following rights:
- The right to notice. You have the right to be notified which categories of Personal Information are being collected and the purposes for which the Personal Information is being used.
- The right to know/access. Under CCPA/CPRA, You have the right to request that We disclose information to You about Our collection, use, sale, disclosure for business purposes and share of personal information. Once We receive and confirm Your request, We will disclose to You:
- The categories of personal information We collected about You
- The categories of sources for the personal information We collected about You
- Our business or commercial purposes for collecting or selling that personal information
- The categories of third parties with whom We share that personal information
- The specific pieces of personal information We collected about You
- If we sold Your personal information or disclosed Your personal information for a business purpose, We will disclose to You:
- The categories of personal information categories sold
- The categories of personal information categories disclosed
- The right to say no to the sale or sharing of Personal Information (opt-out). You have the right to direct Us to not sell Your personal information. To submit an opt-out request, please see the "Do Not Sell or Share My Personal Information" section or contact Us.
- The right to correct Personal Information. You have the right to correct or rectify any inaccurate personal information about You that We collected. Once We receive and confirm Your request, We will use commercially reasonable efforts to correct (and direct our Service Providers to correct) Your personal information, unless an exception applies.
- The right to limit use and disclosure of sensitive Personal Information. You have the right to request to limit the use or disclosure of certain sensitive personal information We collected about You, unless an exception applies. To submit, please see the "Limit the Use or Disclosure of My Sensitive Personal Information" section or contact Us.
- The right to delete Personal Information. You have the right to request the deletion of Your Personal Information under certain circumstances, subject to certain exceptions. Once We receive and confirm Your request, We will delete (and direct Our Service Providers to delete) Your personal information from our records, unless an exception applies. We may deny Your deletion request if retaining the information is necessary for Us or Our Service Providers to:
- Complete the transaction for which We collected the personal information, provide a good or service that You requested, take actions reasonably anticipated within the context of our ongoing business relationship with You, or otherwise perform our contract with You.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information's deletion may likely render impossible or seriously impair the research's achievement, if You previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on Your relationship with Us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which You provided it.
- The right not to be discriminated against. You have the right not to be discriminated against for exercising any of Your consumer's rights, including by:
- Denying goods or services to You
- Charging different prices or rates for goods or services, including the use of discounts or other benefits or imposing penalties
- Providing a different level or quality of goods or services to You
- Suggesting that You will receive a different price or rate for goods or services or a different level or quality of goods or services
Exercising Your CCPA/CPRA Data Protection Rights
Please see the "Do Not Sell or Share My Personal Information" section and "Limit the Use or Disclosure of My Sensitive Personal Information" section for more information on how to opt out and limit the use of sensitive information collected.
Additionally, in order to exercise any of Your rights under the CCPA/CPRA, and if You are a California resident, You can contact Us:
- By email: support@axiospec.com
Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information.
Your request to Us must:
- Provide sufficient information that allows Us to reasonably verify You are the person about whom We collected Personal Information or an authorized representative
- Describe Your request with sufficient detail that allows Us to properly understand, evaluate, and respond to it
We cannot respond to Your request or provide You with the required information if We cannot:
- Verify Your identity or authority to make the request
- And confirm that the personal information relates to You
We will disclose and deliver the required information free of charge within 45 days of receiving Your verifiable request. The time period to provide the required information may be extended once by an additional 45 days when reasonably necessary and with prior notice.
Any disclosures We provide will only cover the 12-month period preceding the verifiable request's receipt.
For data portability requests, We will select a format to provide Your personal information that is readily usable and should allow You to transmit the information from one entity to another entity without hindrance.
Do Not Sell or Share My Personal Information
As defined in the CCPA/CPRA, "sell" and "sale" mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's personal information by the Business to a third party for valuable consideration. This means that We may have received some kind of benefit in return for sharing personal information, but not necessarily a monetary benefit.
You have the right to opt-out of the "sale" of Your personal information. Once We receive and confirm a verifiable consumer request from You, We will stop "selling" Your Personal Information. To exercise Your right to opt-out, please contact Us or follow the below instructions.
Website
Select Decline on the cookie banner. That turns Google Analytics storage off and stops the campaign information being written to Your device. Your choice is stored on the device You made it on, so You need to make it in each browser You use. To change a choice You have already made, clear this site's stored data in Your browser and the banner will ask again.
The industry opt-out platforms run by the NAI, the EDAA and the DAA apply to interest-based advertising. We do not run any, so there is nothing of Ours for them to opt You out of.
Mobile Devices
The mobile apps carry no advertising identifier and serve no ads. You can turn off push notifications in Your device settings. Android also runs Firebase Analytics inside the Axiospec app, which You can limit through Your device's Google settings.
Limit the Use or Disclosure of My Sensitive Personal Information
If You are a California resident, You have the right to limit the use and disclosure of Your sensitive personal information to that use which is necessary to perform the services or provide the goods reasonably expected by an average consumer who requests such services or goods.
We collect, use and disclose sensitive personal information in ways that are necessary to provide the Service. For more information on how We use Your personal information, please see the "Use of Your Personal Information" section or contact us.
To submit a request to limit the use or disclosure of sensitive personal information, please contact Us using the methods listed in the "Contact Us" section of Our Privacy Policy.
"Do Not Track" Policy as Required by California Online Privacy Protection Act (CalOPPA)
Our Service does not respond to Do Not Track signals.
However, some third-party websites do keep track of Your browsing activities. If You are visiting such websites, You can set Your preferences in Your web browser to inform websites that You do not want to be tracked. You can enable or disable DNT by visiting the preferences or settings page of Your web browser.
Your California Privacy Rights (California's Shine the Light law)
Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with Us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes.
If you'd like to request more information under the California Shine the Light law, and if You are a California resident, You can contact Us using the contact information provided below.
California Privacy Rights for Minor Users (California Business and Professions Code Section 22581)
California Business and Professions Code Section 22581 allows California residents under the age of 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted.
To request removal of such data, and if You are a California resident, You can contact Us using the contact information provided below, and include the email address associated with Your Account.
Be aware that Your request does not guarantee complete or comprehensive removal of content or information posted online and that the law may not permit or require removal in certain circumstances.
Children's Privacy
Our Service does not address anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent's consent before We collect and use that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Translation Interpretation
This Privacy Policy may have been translated if We have made it available to You on our Service. You agree that the original English text shall prevail in the case of a dispute.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, or You want to exercise a right under it, You can contact us:
- By email: support@axiospec.com. That address reaches the owner of the company and is answered within one business day.
- By post: CaliTech LLC d/b/a Axiospec, 313 Agnes Rd, STE 200, Knoxville TN 37919, United States.