Skip to content

Legal

Subprocessors

Last updated: September 21, 2026

This page lists every third party that can see personal data held by Axiospec, what each one receives, and why. It is derived from the code that runs in production rather than from a template, and it is kept current with the site.

Axiospec is built by CaliTech LLC d/b/a Axiospec, 313 Agnes Rd, STE 200, Knoxville TN 37919, United States. Questions go to support@axiospec.com and are answered within one business day.

Read this with the Privacy Policy, which explains when We are the controller of personal data and when Your own organization is.

Where the service runs

Axiospec runs in Amazon Web Services in the us-east-1 region, Northern Virginia, United States. The database, the uploaded evidence files, the application secrets and the application itself are all in that one region. The subprocessors below process data in their own locations, which for most of them means several countries.

Subprocessors

PartyWhat it does for UsPersonal data it receives
Amazon Web Services
us-east-1, United States
Hosting, the PostgreSQL database, file storage, secrets, application logs, the message queue, the content delivery network, and outbound email All of it. Every record in Axiospec sits on AWS, and every email We send goes out through Amazon Simple Email Service. The content delivery network is a global edge network, so it terminates connections at edge locations that may be outside the United States before forwarding to us-east-1. API responses are not cached at the edge.
Stripe Payment processing for paid plans The billing email address, a workspace identifier, and the cardholder name and billing address You type into Stripe's own form. Card numbers go straight to Stripe and never reach Axiospec servers. Closing a workspace cancels the subscription. It does not delete the customer record Stripe holds.
Sentry Application error and performance monitoring, on the website, in the app and in both mobile apps Error events, stack traces and request paths. Sending personal data with an event is switched off and every event passes through a scrubbing step first. Two honest caveats: Your IP address reaches Sentry because Your browser makes the request, and an identifier can still appear inside an error message no scrubber predicted. When You are signed in, Sentry is given Your internal user identifier and nothing else.
Google
Firebase Cloud Messaging
Delivering push notifications to the mobile apps The device push token, and the text of the notification. That text can name an instrument and, for a quarantine alert, the person who quarantined it.
Google
Firebase Analytics
Product analytics inside the Android app only App usage events such as screen views and calibrations logged, plus Your internal user identifier, which is set when You sign in and cleared when You sign out. The iOS app does not link this SDK and sends nothing.
Google
Google Analytics 4
Website and in-product analytics on the web Page paths, interaction events, a client identifier Google assigns to the browser, and Your IP address. Nothing is sent to Google, and no tag is requested from Google, until You accept on the cookie banner. Your IP address reaches Google only once You have accepted and the tag is loaded. Declining, or not answering, means no request is made at all. No calibration readings or instrument data are sent.
Google
Google Identity Services
The Google sign-in button on the sign-in and sign-up pages Google handles the sign-in step only. Your Axiospec session token is issued by Our own API and stays with Us. The button script loads from Google when the page renders, which discloses Your IP address to Google whether or not You choose Google sign-in.
Google
Android speech recognition
Voice dictation of calibration readings in the Android app The audio You dictate. It is sent to Google rather than processed on the device, and We receive only the text that comes back. Nothing is sent unless You press the microphone.
Apple
iOS speech recognition
Voice dictation of calibration readings in the iOS app The audio You dictate, on the same terms as the Android entry above.
GitHub Source control and the deployment pipeline Source code and build logs. No customer data.

Recipients that are Yours, not Ours

Three destinations receive personal data because You chose them. They are not Our subprocessors and We have no contract with them on Your behalf.

  • Outbound webhooks. If Your workspace configures a webhook, Axiospec posts calibration events to the address You gave Us. That payload includes the full name of the technician who performed the calibration and any free-text notes on the record. Delivery is retried for about three days. Choose that destination carefully, because once the payload arrives it is out of Our hands.

  • Your own identity provider. If Your workspace turns on single sign-on, the sign-in step runs against the OIDC or SAML provider You configured. Your Axiospec session token is still issued by Our own API.

  • Anyone You send an export to. The audit archive is Yours to generate and Yours to share. It contains the names on every calibration record in scope.

What is not here

Some absences are worth stating, because a reader will otherwise wonder.

  • There is no advertising vendor. Google Ads was discontinued on 15 September 2026 and every ad tag, ad conversion and remarketing pixel was removed from the site and the app.
  • There is no customer support desk, no live chat tool and no session replay tool. Support runs by email.
  • There is no third-party email marketing platform. Marketing email goes out through Amazon Simple Email Service, the same sender as everything else.
  • No identity provider holds Your Axiospec session. That token is issued by Our own API.
  • Microsoft social sign-in is built but is switched off in production, so Microsoft receives nothing today. If that changes this page changes first.

Translation Interpretation

This list of Subprocessors may have been translated if We have made it available to You on our Service. You agree that the original English text shall prevail in the case of a dispute.

Changes to this list

We update this page when a subprocessor is added or removed. If You want to be told when it changes, email support@axiospec.com and ask, and We will write to You before the change takes effect where We reasonably can.

Contract status

State this plainly rather than imply it. CaliTech LLC has not yet executed a data processing agreement or Standard Contractual Clauses with its customers, and offers no EU or UK data region. Those documents are being prepared with legal advice and will be published when they are in force. Contracts with the subprocessors above are the standard terms each of them publishes.