Privacy notice

Effective 2026-07-31.

axonia is a place for software engineering communities of practice. To do that it holds information about the people in those communities. This notice says what it holds, why, who else touches it, and what you can do about it. It describes what the product actually does. The categories below are tied to the product by an automated check, so a new kind of data cannot be added to axonia without a section here that names it. The rest of this notice, including the list of companies further down, is written and kept current by hand.

Who is responsible

For people who sign up to axonia directly, the controller of personal data is Gabriel Dinant.

Where an organisation connects axonia to its own identity provider, that organisation is the controller of its members’ data and axonia is its processor. This is not only a legal distinction. It is why a member of an enterprise organisation cannot delete their own axonia account, and is asked to go to their employer instead.

Written enquiries about anything in this notice go to privacy@axonia.dev.

Why axonia is allowed to hold this

The operator of axonia is established in Switzerland, so Swiss data protection law applies to what follows. Where you are in the European Union, the GDPR applies as well, and this notice is written to hold under both.

For people who sign up directly, almost everything below is held in order to provide the product you asked for. That is the contract between you and axonia, and it is the basis for the person record, what you contribute, how you take part, what you know, what you saved, and what you send axonia.

A narrow remainder rests on axonia’s own legitimate interest in keeping the service working and safe from abuse, which is what the access and security records are for, and on axonia’s legal obligations, which is why a record that an erasure happened is kept at all.

Where your employer connects axonia to its identity provider, your employer decides why your data is processed and on what basis, and axonia acts on its instructions. Ask your employer for their own notice.

axonia does not rely on consent for any of this. It does not sell data, and it does not use it to advertise.

Who you are

The person record: the identifier your identity provider gives you, your display name, email address, any directory attributes your employer synchronises, and your avatar.

This is the smallest set axonia can work with. There is no profile questionnaire, no demographic field, and nothing axonia asks for that the product does not use.

What you contribute

What you write or produce for your community: topics you propose, artifacts you publish, sessions you run, resources you attach.

Anything you post to a community is visible to the people in that community. That is the point of the product, and it is worth being deliberate about: a community is an audience, not a private notebook.

How you take part

Attendance, session sign-ups, votes, and appreciation given and received.

Your community sees that you took part. This is what lets a community leader see whether the community is alive, and it is the only reason axonia records it.

What you know

Expertise signals derived from what you contribute, and the tags behind them.

Nothing here is a judgement about you. Each signal is a consequence of something you did, and it points back at the contribution it came from.

What you saved

Bookmarks and saved items, which are yours alone and visible to nobody else.

When you contact us

Messages you send axonia through the product, and what was recorded about answering them.

Access and security

Credentials and grants: personal access tokens, role assignments, single sign-on configuration, and records of any occasion an axonia operator signed in on a member’s behalf.

Rights you exercised

When an account is erased, axonia keeps a short record that the erasure was carried out: when it ran, which organisation it ran in, and how many rows were removed, emptied or rewritten.

That record holds no identifier that can be linked back to you. It carries no name, no email address and no account. It carries one surrogate, minted at the moment of erasure, which is the same surrogate your surviving anonymised rows now carry. No mapping from that surrogate back to you is kept anywhere, so it cannot be resolved, and a surrogate minted in one organisation cannot be tied to one minted in another.

The record exists so that the fact an erasure happened survives the erasure itself, which is what lets axonia show it did what it was asked to do.

Cookies and what is stored in your browser

axonia does not set cookies, and it does not use analytics or tracking of any kind. There is no Google Analytics, no advertising pixel, no session recorder, and no third-party script on any page. Fonts are served from axonia’s own servers rather than from a font provider.

What axonia does store in your browser is the following, all of it necessary for the product to work at all. Your sign-in tokens, kept so that you stay signed in across tabs. Which organisation you are currently working in. Three interface preferences, being your light or dark theme, whether your sidebar is collapsed, and whether you prefer the schedule as a timeline or a calendar. And a small number of markers that live only until you close the tab: a couple that keep a sign-in from looping, and one that supports an operator support session, described under Access and security.

None of that is used to track you, and none of it is shared. This is why you have not been shown a cookie banner. Consent is required for storage that is not necessary for the service you asked for, and axonia has none. A banner asking permission for cookies that do not exist would tell you nothing true.

Signing in takes you to axonia’s own login service, which sets its own session cookies. Those are what keep you signed in, and nothing else.

Who else touches your data

axonia does not run on its own hardware, so a small number of other companies necessarily handle data on its behalf. This is the whole list.

Railway hosts the application, its database, and axonia’s own sign-in service, in Railway’s Amsterdam region. The shared store behind axonia’s rate limits, a Redis instance, runs there too.

Cloudflare sits in front of axonia: every request you make reaches the application through it, and it also serves the files people upload, such as avatars and images, from Cloudflare R2 object storage.

Resend delivers the mail axonia sends, including sign-in and invitation messages and anything you send axonia from inside the product. It sees the address a message goes to and what the message says.

Microsoft is involved only where an organisation has connected axonia to Microsoft Entra. For those organisations, axonia asks Microsoft Graph for members’ profile photos and for the directory groups it has been given permission to read.

Separately, if you sign in with Google or with GitHub, axonia fetches your profile picture from that provider once and then keeps its own copy.

Nothing in the build checks this list. The categories above are held to the product automatically; this list is not, because no test can see who axonia buys infrastructure from. It is maintained by hand, which makes it the part of this notice most likely to fall behind a change in the infrastructure. If something looks missing, write to the address above and it will be corrected.

Where your data is, and where it can be reached from

The application, its database and axonia’s own sign-in service run in Amsterdam, so the data axonia stores lives in the European Union. The operator of axonia is established in Switzerland and reaches that data from there in order to run the product. Switzerland holds an adequacy decision from the European Commission, so personal data moving between the European Union and Switzerland needs no additional safeguard such as standard contractual clauses.

Where the servers are is not the whole answer. Railway, Cloudflare, Resend and Microsoft are all companies incorporated in the United States, including the one that holds the database. Railway keeps axonia’s data on European infrastructure, which is what the paragraph above means, but that is residency and not jurisdiction: data these companies handle for axonia can be processed by a US company, or reached from outside the European Union, even where the machines doing the work are not. axonia claims no particular transfer mechanism here beyond the data protection terms each of those providers publishes, because claiming one it had not put in place would be worse than saying nothing.

The honest summary is that axonia is hosted in the European Union but is not sovereign against a jurisdiction argument. If your organisation needs the second and not just the first, say so before you adopt axonia, not after.

How long it is kept

While you have an account, axonia keeps what is listed above, because that is what the product runs on.

When an account is erased, it happens at once rather than on a schedule. Inside a single database transaction per organisation, the rows that exist only to describe you are deleted, live pointers to you on rows that survive are emptied, and the rows that are community history are rewritten to carry the surrogate instead of you. If a stored file cannot be deleted at that moment because object storage refused, the receipt records that one was left behind, so it can be found and removed rather than quietly forgotten.

Two things outlast that moment, and it is better to say so than to promise otherwise. Database backups roll on a continuous window of roughly four weeks, so a copy of a row can survive inside that window until the window passes it. And the record that an erasure happened is kept indefinitely, which is only safe because, as described above, it identifies nobody.

What you can do

Get a copy of your data. If you signed up to axonia yourself, there is a download in the profile menu inside the product. It covers the organisation you are currently working in rather than every organisation at once, so if you belong to more than one, switch and download again. If you reached axonia through your employer, that download is refused, because your employer is the controller of your data: an access request goes to them, and this is a deliberate limit rather than an oversight.

Delete your account. If you signed up yourself, the profile menu will erase your account across every community hub you belong to. It is irreversible. Two things stop it, and the product tells you which apply before you confirm rather than failing halfway. The first is an enterprise membership: your employer is the controller, so that data leaves with them and not through you. The second is being the only owner of a community, because handing a community over is not built yet; give it another owner or delete it first, and then erasure will proceed.

What you contributed to a community stays where it is, no longer carrying your name, so that the community’s own history and counts do not silently change around the people still in it.

Your other rights. You can also ask axonia to correct data that is wrong, to restrict what it does with your data, to object to processing that rests on its legitimate interest, and to give you your data in a portable form.

Correction is worth being precise about, because axonia is not where most of it lives. Your name, your email address and your picture come from the identity provider you sign in with, and axonia has no screen that edits them: correcting them means correcting them there, and if you reach axonia through your employer, that means your employer’s directory. What you can change inside the product is narrower than it sounds. You can hide your expertise areas from other members, one at a time or all of them at once, though axonia goes on deriving them from what you did. You can edit or remove artifacts you published. And you can unsave anything you saved.

For anything else, write to the address at the top of this notice.

If your organisation connects axonia to its identity provider, all of the above goes to your employer instead: they are the controller, and their request removes the whole organisation’s data at once.

If you think axonia has this wrong

Write to the contact address above first, because most of it can be fixed that way.

You also have the right to complain to a data protection supervisory authority. For axonia that is the Federal Data Protection and Information Commissioner in Switzerland, and you may instead go to the authority in the country where you live or work.

Changes

The effective date at the top says when this text last changed.