Privacy Policy
How AXQA handles personal, technical, operational, account, and service information across our website, platform, and Smart Agent workflows.
Effective date: September 5, 2026
Last updated: September 5, 2026
This Privacy Policy explains how AXQA TECHNOLOGY LTDA collects, uses, stores, shares, protects, and otherwise processes personal data when you visit our website, create or use an AXQA account, participate in a workspace, use the AXQA platform or Smart Agent, purchase a subscription, contact us, or otherwise interact with AXQA services.
This Privacy Policy is a notice describing our data-processing practices. It is not intended to treat consent as the legal basis for every processing activity. Depending on the context, AXQA may rely on contract performance, legitimate interests, compliance with legal or regulatory obligations, exercise of rights, consent where appropriate, fraud and security prevention, or another legal basis permitted by applicable law.
1. Who We Are
AXQA is operated by AXQA TECHNOLOGY LTDA, a company based in São Paulo, SP, Brazil, registered under CNPJ 68.755.091/0001-09. For privacy, data-protection, support, or legal questions, contact [email protected].
2. Scope of This Policy
This Policy applies to personal data processed through the AXQA public website, accounts, hosted platform, workspaces, dashboards, APIs, Smart Agent, local execution workflows, subscriptions, support, sales interactions, security systems, and related AXQA services.
This Policy does not govern third-party websites or services that are independently controlled by another organization, even if AXQA links to or integrates with them.
3. AXQA as Controller and as Operator or Processor
AXQA may act in different data-protection roles depending on the processing activity. AXQA generally acts as a controller for personal data used to manage our own website, accounts, authentication, subscriptions, billing records, customer relationships, support, security, fraud prevention, legal compliance, product administration, and business operations.
When a Customer places personal data inside an AXQA workspace and determines why and how that data should be used, AXQA may act as an operator or processor on behalf of that Customer. In those circumstances, the Customer is generally responsible for its instructions, legal basis, notices, user permissions, and decisions regarding the Customer-controlled data, while AXQA processes the data to provide the contracted service and according to applicable agreements and law.
The legal role depends on the facts of the specific processing activity and cannot be changed merely by the label used in a contract or this Policy.
4. Sources of Information
We may receive information directly from you, from your employer or organization, from Customer administrators, from devices and browsers that connect to AXQA, from Smart Agent and authorized execution environments, from configured integrations and APIs, from payment or communications providers, and from security or technical systems used to operate AXQA.
5. Account and Contact Information
- Name, business email address, username, company or organization name, role, job title, and contact details.
- Account identifiers, login activity, authentication status, multi-factor authentication information, password-reset events, security settings, and session information.
- Customer administrator assignments, workspace membership, roles, permissions, invitations, and account status.
6. Subscription, Billing, and Transaction Information
- Subscription plan, billing cycle, invoices, transaction status, amounts, currency, renewal status, payment references, tax-related information, and commercial records.
- Payment information may be processed by third-party payment providers. AXQA may receive transaction identifiers, payment status, limited payment-method information, or billing metadata and does not necessarily receive or store complete payment-card numbers.
7. Platform, Workspace, and QA Information
- Projects, teams, test plans, test cases, test steps, preconditions, expected results, actual results, execution records, defects, comments, attachments, tags, priorities, categories, groups, assignments, builds, environments, reports, dashboards, exports, and related QA workflow information.
- Client-facing or shared workspace information, visibility settings, project membership, and other information configured by authorized Customer administrators.
- Revision history, timestamps, activity history, audit trails, and records of actions performed within the platform.
8. API, Integration, and Execution Information
- API names, endpoints, request methods, headers, parameters, payload structures, authentication configuration, validation rules, expected responses, actual responses, response metadata, status codes, timing information, execution history, and comparison results.
- Integration identifiers, configuration information, technical errors, connectivity information, and other data necessary to operate integrations selected by a Customer.
9. Smart Agent and Local Execution Information
- Device, operating-system, application-version, environment, pairing, authorization, and technical information needed to authenticate and operate Smart Agent.
- Execution status, selected targets, allowed or blocked requests, policy results, logs, timing information, response metadata, technical diagnostics, and information reasonably necessary to report execution results to AXQA.
- Security information used for allowlists, access controls, version checks, encryption, integrity controls, trusted execution policies, abuse prevention, and incident investigation.
10. Website, Device, and Usage Information
- IP address, browser type, operating system, device type, language, pages visited, referring page, date and time of access, session activity, cookie or similar identifiers, and technical request information.
- Performance measurements, errors, application events, feature usage, security events, and aggregated or statistical usage information.
11. Communications and Support Information
- Support requests, messages, emails, demo requests, sales inquiries, feedback, survey responses, attachments, technical troubleshooting details, and other information you choose to provide to AXQA.
12. Information We Do Not Intentionally Require
AXQA is designed for professional QA and business workflows and generally does not require sensitive personal data such as health information, biometric data, personal financial-account credentials, government identification documents, or other highly sensitive personal information for ordinary use.
Customers and Users should not place sensitive personal data, unnecessary production personal data, confidential third-party information, or regulated data into AXQA unless they have a lawful basis, appropriate authorization, a legitimate business need, and suitable safeguards. Customers remain responsible for data they choose to include in test data, API payloads, files, comments, reports, or other Customer-controlled content.
13. How We Use Personal Data
Depending on the context, AXQA may process personal data to:
- provide, operate, maintain, secure, administer, and improve AXQA;
- create and manage accounts, workspaces, roles, permissions, sessions, authentication, and access controls;
- execute test-management, API, automation, Smart Agent, local-execution, reporting, dashboard, audit, and related product functions;
- process subscriptions, invoices, payments, renewals, cancellations, taxes, and commercial records;
- provide support, troubleshoot issues, communicate with Customers, and respond to requests;
- send service-related, security, billing, legal, administrative, or product communications;
- detect, prevent, investigate, and respond to fraud, abuse, unauthorized access, security threats, policy violations, and technical incidents;
- monitor service health, reliability, performance, capacity, and technical operation;
- understand product usage and improve usability, documentation, reliability, features, and service quality;
- establish, exercise, or defend legal rights and comply with legal, regulatory, contractual, tax, accounting, audit, or law-enforcement obligations;
- carry out other purposes disclosed at the time of collection or otherwise permitted by applicable law.
14. Legal Bases for Processing
Where the Brazilian General Data Protection Law applies, AXQA may rely on legal bases permitted by the LGPD according to the specific activity, including performance of a contract or preliminary procedures related to a contract, compliance with legal or regulatory obligations, legitimate interests subject to applicable requirements, regular exercise of rights, protection against fraud and security risks where permitted, consent when appropriate, and other bases available under applicable law.
Consent is used only where it is an appropriate legal basis. When processing is based on consent, applicable law may allow you to withdraw that consent, without affecting the lawfulness of processing performed before withdrawal or processing supported by another lawful basis.
15. Customer Instructions and Responsibility for Customer-Controlled Data
When AXQA processes personal data on behalf of a Customer, the Customer is responsible for determining the permitted purpose of the processing, selecting authorized Users, configuring access, and ensuring that its instructions and data are lawful. AXQA may refuse or suspend an instruction that AXQA reasonably believes is unlawful, unsafe, technically abusive, or inconsistent with the contracted service.
If a privacy request concerns personal data controlled by an AXQA Customer, AXQA may direct the requester to that Customer or assist the Customer according to applicable law and contractual obligations.
16. Cookies and Similar Technologies
AXQA may use cookies and similar technologies that are necessary for authentication, session management, security, preferences, fraud prevention, and operation of the website and platform. AXQA may also use analytics or performance technologies where permitted by law and configured for the service.
You may be able to control non-essential cookies through available consent settings or browser controls. Disabling necessary cookies may prevent login, authentication, security, or other platform functionality from working correctly.
17. Analytics and Product Improvement
AXQA may analyze service usage, performance, errors, navigation, and feature interaction to improve the service, understand operational patterns, prevent abuse, and plan product development. Where reasonably possible, AXQA may use aggregated, de-identified, or limited information for these purposes.
If AXQA later deploys additional analytics or interaction-measurement technologies that require consent or additional notice under applicable law, AXQA will configure the relevant notice or consent mechanism as required.
18. AI-Assisted and Automated Processing
Some AXQA features may use automated or AI-assisted processing to organize, suggest, classify, compare, summarize, generate, detect, or otherwise assist with QA and operational workflows. Outputs may be reviewed by authorized Users and should not be treated as guaranteed facts or as a substitute for professional judgment.
Where applicable law provides rights relating to decisions made solely through automated processing of personal data that affect a person's interests, AXQA will handle applicable requests according to its legal role and may coordinate with the relevant Customer where the Customer controls the processing.
19. How We Share Information
AXQA does not sell personal data. We may disclose or make information available only as reasonably necessary for the purposes described in this Policy, including to:
- authorized Users, Customer administrators, and other persons within the same Customer organization or workspace according to configured permissions;
- hosting, infrastructure, security, content-delivery, communications, email, payment, analytics, support, monitoring, backup, and other service providers that help operate AXQA;
- professional advisers such as lawyers, accountants, auditors, insurers, or consultants where reasonably necessary;
- government authorities, regulators, courts, law enforcement, or other persons where disclosure is required by law, legal process, or necessary to establish, exercise, or defend legal rights;
- a buyer, investor, successor, affiliate, or other relevant party in connection with a merger, financing, acquisition, corporate restructuring, or sale of business or assets, subject to applicable confidentiality and legal safeguards;
- other recipients when you or the relevant Customer directs or authorizes the disclosure.
20. Service Providers and Subprocessors
AXQA may engage third-party service providers to perform functions necessary to provide and secure the service. The categories of providers may include cloud and hosting providers, security and network providers, communications and email providers, payment processors, monitoring and analytics providers, support tools, and other technical vendors.
Where AXQA acts as an operator or processor and uses subprocessors for Customer-controlled personal data, applicable contractual terms may provide additional information, safeguards, or notification rights.
21. International Data Transfers
AXQA is based in Brazil, but AXQA, Customers, authorized Users, infrastructure, and service providers may operate in more than one country. As a result, personal data may be accessed, stored, or processed outside Brazil when necessary to provide the service.
Where the LGPD applies to an international transfer of personal data, AXQA will use a transfer mechanism permitted by applicable law and the regulations of the Brazilian National Data Protection Authority, as appropriate to AXQA's role and the specific transfer. Depending on the transfer, safeguards may include an adequacy decision, contractual safeguards, standard contractual clauses, or another mechanism permitted by law.
The form, duration, purpose, destination, recipients, responsibilities, and safeguards for a particular international transfer may vary according to the service provider, Customer configuration, and processing activity. Additional information may be made available through this Policy, a data processing agreement, a subprocessor disclosure, contractual documentation, or upon a valid privacy request, subject to commercial and security confidentiality.
22. Security
AXQA uses technical, organizational, and administrative safeguards designed to protect personal data and Customer Data against unauthorized access, destruction, loss, alteration, misuse, or disclosure. Depending on the system and risk, safeguards may include access controls, authentication, encryption, audit logging, network restrictions, monitoring, secure development practices, backup controls, environment isolation, version controls, and internal security procedures.
No internet service, software, network, storage method, encryption method, or security control can guarantee absolute security. Users and Customers are also responsible for protecting their credentials, devices, networks, permissions, and data.
23. Security Incidents
If AXQA becomes aware of a security incident involving personal data, AXQA may investigate, contain, remediate, preserve evidence, and take other reasonable protective measures. Where notification to a Customer, affected person, regulator, or authority is legally required, AXQA will provide the required notification according to its legal role and applicable law.
24. Data Retention
AXQA retains information for periods reasonably necessary for the purposes described in this Policy, including providing the service, maintaining account and commercial records, complying with legal and tax obligations, resolving disputes, enforcing agreements, protecting security, preventing fraud, maintaining audit evidence, and supporting legitimate business operations.
Retention periods vary by data type, Customer settings, subscription status, contractual requirements, legal obligations, security needs, and backup cycles. When information is no longer required, AXQA may delete, anonymize, aggregate, or securely archive it as permitted or required by law.
Customer Data in backups may remain for a limited period until overwritten through ordinary backup rotation. AXQA may retain information where preservation is required by law, legal hold, dispute, fraud prevention, security investigation, or exercise of rights.
25. Data Deletion and Account Closure
Cancelling a subscription does not necessarily mean that all data is deleted immediately. Access, retention, export, and deletion after cancellation may depend on the applicable subscription, Order, Customer instruction, legal requirements, backup cycles, and technical limitations.
Customers should export information they wish to retain before their access ends. AXQA may retain limited account, billing, security, audit, or legal records after service termination where permitted or required.
26. Your Privacy Rights
Depending on applicable law and AXQA's role in the relevant processing, you may have rights including confirmation of processing, access, correction of incomplete or inaccurate information, anonymization, blocking or deletion of unnecessary or unlawfully processed data, portability where legally available, information about data sharing, deletion of data processed on the basis of consent where legally applicable, information about the possibility of refusing consent and the consequences, withdrawal of consent, opposition in circumstances provided by law, and rights relating to qualifying automated decisions.
Privacy rights are not absolute. A request may be limited or denied where applicable law permits or requires retention, where AXQA does not control the relevant data, where identity cannot reasonably be verified, where the request affects the rights of others, or where another lawful exception applies.
27. How to Exercise Privacy Rights
To make a privacy request, contact [email protected] and describe the request and the relevant AXQA account or relationship. AXQA may request information reasonably necessary to verify identity, authority, prevent fraud, identify the relevant data, or determine whether AXQA or a Customer is responsible for the request.
Where AXQA is the controller, AXQA will respond as required by applicable law. Where an AXQA Customer is the controller, AXQA may direct the request to the Customer or assist the Customer as appropriate.
28. Brazilian LGPD and ANPD
AXQA TECHNOLOGY LTDA is established in Brazil and processes personal data subject to the Brazilian General Data Protection Law where applicable. Individuals may first exercise applicable rights through the responsible controller. Where legal requirements are met, a data subject may also have the right to submit a petition or complaint to the Brazilian National Data Protection Authority, ANPD.
For AXQA privacy matters, the first contact channel is [email protected].
29. Other Privacy Laws
Depending on the location of a Customer or data subject and the circumstances of processing, additional privacy laws may apply. References to laws such as the LGPD, GDPR, or other privacy regimes do not mean that every law applies to every AXQA User, Customer, or processing activity.
30. Children and Minors
AXQA is intended for professional and business use and is not designed as a service for children. AXQA does not knowingly seek to collect personal data from children through ordinary account registration. If you believe that personal data relating to a child has been submitted to AXQA without proper authorization or legal basis, contact [email protected] so the matter can be reviewed.
31. Customer Monitoring and Employee Data
Customers may use AXQA audit, execution, assignment, activity, or reporting features in connection with their own workforce or contractors. The Customer is responsible for determining whether its monitoring, management, or use of employee or contractor information is lawful and for providing any notices or obtaining any approvals required by applicable employment, privacy, or labor law.
32. Legal Requests and Preservation
AXQA may preserve or disclose information where reasonably necessary to comply with valid legal process, regulatory requirements, court orders, lawful government requests, tax or accounting obligations, or to establish, exercise, or defend legal rights. AXQA may challenge or limit a request where legally appropriate.
33. Business Transfers
If AXQA is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be disclosed to relevant parties under appropriate confidentiality and legal safeguards and may be transferred to a successor as permitted by law.
34. Changes to This Privacy Policy
AXQA may update this Privacy Policy from time to time to reflect changes in the service, data-processing activities, security practices, service providers, legal requirements, or business operations. Unless applicable law requires otherwise, an updated version becomes effective when posted on the AXQA website or on the effective date stated in the updated Policy.
AXQA is not required to provide individual notice for routine, administrative, clarifying, non-material, security-related, or legally required updates where individual notice is not required by applicable law. If a change materially affects how personal data is processed or materially affects applicable privacy rights, AXQA may provide additional notice or obtain consent when required by law.
35. Contact Information
For questions about this Privacy Policy, personal data, privacy rights, or data protection, contact:
AXQA TECHNOLOGY LTDA
CNPJ: 68.755.091/0001-09
São Paulo, SP, Brazil
Privacy and support contact: [email protected]