Trust & Security – Axilero
Last updated: 31-08-2026
This page collects everything a privacy officer, IT department, or careful customer needs to evaluate Axilero in one place: where your data is processed, who touches it, how long it lives, and which agreements apply.
The short version
- All AI runs on our own EU infrastructure. Speech-to-text and AI summarization are performed on servers operated by Axilero in the EU. Your audio and transcripts are never sent to third-party AI providers such as OpenAI or Google.
- Audio is deleted automatically after transcription completes. Only the transcript and summary remain, in your account, until you delete them.
- A GDPR Article 28 Data Processing Agreement applies automatically to every customer — no signature or enterprise plan required. See the DPA.
Where your data lives
- Application and database: hosted with Contabo GmbH in Germany (EU).
- AI processing (transcription and summaries): GPU servers operated by Axilero in Denmark (EU).
- Backups: encrypted, stored within the EU, and rotated so deleted content is gone from backups within 35 days.
Data lifecycle
- Uploaded audio and video files are processed and then deleted automatically — they are not retained after the job finishes.
- Transcripts and summaries are stored in your account until you delete them, and can be exported at any time.
- Deleting your account erases all your content. Billing records are anonymised and retained only as required by Danish bookkeeping law.
Security measures
- All data in transit is encrypted with TLS.
- Database backups are encrypted with modern public-key encryption (age).
- Access to production systems is restricted to authorised personnel.
- Internal access to customer content is need-based only — support and abuse investigations, never routine browsing.
- Bot protection on signup keeps automated abuse out.
Sub-processors
The complete, current list is maintained in the Data Processing Agreement. In summary:
- Contabo GmbH (Germany, EU) — hosting and storage.
- Paddle.com Market Ltd (UK) — payments; never sees your content.
- Resend (US) — transactional email; never sees your content.
- Cloudflare, Inc. (US) — bot protection on signup and contact form; never sees your content.
Agreements and policies
- Data Processing Agreement (GDPR art. 28, incl. sub-processors and audit rights)
- Privacy Notice
- Terms & Conditions
- Refund Policy · Cookie Policy
Company
Axilero
CVR: 46418689
Damstræde 5
3630 Jægerspris
Denmark
contact@axilero.com
Questions a DPO would ask are welcome — write us and we will answer concretely, including about audit rights under the DPA.