Privacy Policy
This Privacy Policy describes how we collect, use, and protect information when you use our website (axionsystemsco.com) and our software platform, Novum by Axion Automation Systems ("Novum" or the "Service"), available at app.axionsystemsco.com.
1. Who we are
Axion Automation Systems LLC is a Pennsylvania limited liability company. Novum is a business-intelligence and workflow platform for small businesses. For privacy questions, contact us at legal@axionsystemsco.com.
2. Information we collect
Account information. When you or your organization creates a Novum account, we collect your name, email address, organization name, role within the organization, and authentication credentials (managed by our authentication provider; we never store plaintext passwords).
Organization business data you choose to connect. Novum works by connecting to business systems you authorize. Depending on what your organization connects, this may include:
- Accounting data from QuickBooks Online (via Intuit's API): customers, invoices, bills, payments, accounts, and related records. Novum reads this data to produce dashboards, briefings, and prepared work product. Novum does not write to your QuickBooks company file.
- Calendar data from Microsoft 365 or Google Calendar: events, times, titles, and attendees. Novum reads this data to produce schedules and briefings, and creates calendar events only when a human user explicitly approves a proposed action.
- Documents you upload: files you provide to Novum for analysis or as reference material, and the text extracted from them.
- Content you create in Novum: tasks, questions, chat messages, notes, playbooks, and the approvals or rejections you record.
Usage and technical information. Log data such as IP address, browser type, pages visited, timestamps, and error reports, used to operate and secure the Service.
We do not knowingly collect information from children under 13, and the Service is not directed to them.
3. How we use information
We use information to:
- Provide, operate, and improve the Service, including generating briefings, dashboards, drafted documents, and proposed actions for your review;
- Authenticate users and enforce organization-level access controls;
- Send transactional email you or your organization have configured (for example, emails you approve Novum to send on your behalf, and your daily briefing);
- Provide customer support and respond to your requests;
- Monitor for security, abuse, and reliability;
- Comply with legal obligations.
Human approval by design. Novum's AI features draft, analyze, and propose. Actions that affect systems outside Novum — sending an email, creating a calendar event — occur only after a human user in your organization approves them, and every approved action is recorded in an audit log.
4. Artificial intelligence and your data
Novum uses large language models provided by Anthropic, PBC to process your content and connected business data in order to generate outputs for you. Your data is not used to train AI models — not by us, and, under our commercial agreement, not by our AI provider. Data is transmitted to the AI provider only to generate the responses you request and is processed under contractual confidentiality and data-protection terms.
AI outputs may contain errors. Novum presents AI-generated content for human review and does not take autonomous actions on your behalf.
5. Google API Services — Limited Use disclosure
Novum's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google Calendar data to provide user-facing features within Novum (schedules, briefings, and calendar events the user explicitly approves).
- We do not transfer Google user data to third parties except as necessary to provide or improve these features, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use Google user data for serving advertisements.
- We do not allow humans to read Google user data unless we have your affirmative agreement, it is necessary for security purposes, it is required by law, or the data has been aggregated and anonymized.
- We do not use Google user data to train or develop generalized AI or machine-learning models.
6. How we share information
We do not sell personal information. We share information only with:
- Service providers (subprocessors) who process data on our behalf under contract: Supabase (database, authentication, and file storage), Vercel (application hosting), Anthropic (AI processing), Resend (transactional email delivery), and the connected-system providers you authorize (Intuit, Microsoft, Google). A current list of subprocessors is available on request.
- Your organization. Information within a Novum organization is visible to that organization's authorized users according to their roles. Organizations are isolated from one another at the database level.
- Legal and safety. When required by law, subpoena, or to protect the rights, property, or safety of Axion, our users, or the public.
- Business transfers. In connection with a merger, acquisition, or sale of assets, with notice to you.
7. Data retention and deletion
We retain account and organization data for as long as your organization maintains an active subscription and for a limited period afterward to allow reactivation. Upon written request, or when an organization is deleted, we delete or de-identify the organization's business data, documents, and connected-system tokens. Immutable audit records of approved actions may be retained in de-identified form as required for security and compliance. Connected-system access can be revoked at any time from Novum's Settings or from the provider's own account settings.
8. Security
We protect information using industry-standard measures, including encryption in transit (TLS) and at rest, encrypted storage of connected-system access tokens, database-level tenant isolation with row-level security, role-based access controls, and logging of administrative and action-approval events. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise these rights, contact legal@axionsystemsco.com. You may disconnect any connected system at any time. If you are located in the European Economic Area, the United Kingdom, or a jurisdiction with similar rights, we will honor requests consistent with applicable law.
10. International transfers
Our Service is operated in the United States. If you access it from outside the United States, your information will be processed and stored in the United States.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new effective date and, for material changes, notify organization administrators by email.
12. Contact
Axion Automation Systems LLC
Chester County, Pennsylvania
legal@axionsystemsco.com