Privacy policy

Last updated 18 September 2026.

Draft — not yet reviewed by a lawyer. What this page says about how the software works is accurate. The commercial and legal clauses, and the highlighted gaps, need completing and reviewing before launch.

This describes what aXios Books stores, why it is stored, and who else can see it. It is written to Singapore’s Personal Data Protection Act, because the product keeps books for Singapore companies.

What we hold

About the people who sign in. A name, an email address, an optional profile image, and which companies they belong to and in what role. Sign-in is by a one-time code, so there are no passwords — we have nothing to store and nothing to leak. Codes are stored as a hash, never as the code itself, and expire after ten minutes.

About sessions. A session token, when it expires, and the IP address and browser user-agent it was created from, so that somebody can recognise a session that is not theirs.

The books themselves. Everything you record: customers and suppliers with their contact details, invoices, bills, credit notes, payments, journal entries, imported bank statement lines, and the company’s own registration and tax details. Bank statement lines often carry a counterparty name, which can be a person.

An audit trail. Who did what, and when, for every action in the books — including the before and after values of anything changed. It records people by name, and it cannot be edited or deleted, by you or by us. That is what makes it worth having.

What we do not hold

  • No passwords, because sign-in does not use them.
  • No card or bank credentials. Statements are imported from a file you upload; the app never connects to a bank.
  • No analytics or advertising trackers, and no third-party scripts in the signed-in application.

Why we hold it

To run the service you asked for: to keep your books, produce your reports and returns, let the right people in and keep the wrong people out, and to send the emails the app needs to send — a sign-in code, an invitation, an invoice you chose to share.

We do not sell it. We do not use it to train machine-learning models.

Who else sees it

The service runs on a small number of suppliers, and only these:

  • Amazon Web Services — hosting and the database. Your records live there, encrypted in transit.
  • Resend — sending email. A message we send passes through Resend, so it sees the recipient address and the contents of that message. It does not have access to your books.

[ to be completed: the AWS region, the sub-processor list with locations, and any cross-border transfer basis required under the PDPA ]

We will disclose data if the law requires it. If we are ever compelled to, we will tell you unless we are forbidden from doing so.

How long we keep it

Sign-in codes expire after ten minutes. Sessions expire on their own schedule and when you sign out.

Your books are kept for as long as the account exists. Singapore requires company records to be kept for five years, and the app is built so that accounting records are corrected rather than erased — a posted entry is reversed, never deleted, and the audit trail is append-only. This means some things genuinely cannot be removed on request without destroying the integrity of the books.

[ to be completed: what happens to the data after an account is closed, and how long backups are kept ]

Your rights

Under the PDPA you may ask what personal data we hold about you and how it has been used, and ask us to correct anything that is wrong. Write to support@axiosglobal.co.

You can export any report in the app as a CSV file yourself, at any time, without asking us.

Correction has a limit worth being straight about: we will correct your name, your email address and your contact records. We will not alter a posted accounting entry or an audit trail record, because those are a record of what happened. A wrong transaction is fixed by reversing it, which the app does and which leaves both entries visible.

Security

Data is encrypted in transit. Permissions are enforced on the server, and the rules that protect the integrity of the books — that debits equal credits, that a payment cannot exceed the invoice, that the audit trail cannot be rewritten — are enforced by the database itself, so they hold even against a mistake in our own code.

[ to be completed: encryption at rest, access controls on the production database, and the breach-notification process ]

Contact

support@axiosglobal.co. [ to be completed: the data protection officer’s name and contact details, as the PDPA requires ]