Privacy Policy

Effective Date: May 2, 2026

DRAFT — pending counsel review. Final version to be confirmed before any customer signs the Master Service Agreement and Founding Partner Addendum.

1. Who We Are

AxonIR is an investor relations services platform operated by AxonIR Operations, LLC ("AxonIR", "we", "our", "us"), a Delaware limited liability company that is a wholly-owned subsidiary of Atypical Global Inc, a New York corporation. Our principal address is 1185 Avenue of the Americas, 3rd Floor, New York, NY 10036. You can reach us at [email protected] for any privacy-related inquiry.

This Privacy Policy describes the personal and business information AxonIR collects from visitors to axonir.ai, customers using our subscription service, and individuals who interact with us through email, calendar booking, or other channels.

2. What Information We Collect

2.1 Information You Provide

  • Contact details (name, business email, business phone, role/title, company name) submitted through our signup, free-score, or contact forms
  • Company information (ticker symbol, exchange listing, sector, market capitalization) that you submit or that we derive from public SEC filings
  • Communications you send us (emails, calendar booking responses, monthly call transcripts with consent)
  • Pre-publication content (SEC filing drafts, press release drafts, investor communications) that you submit to AxonIR for scoring or optimization
  • Payment and billing information processed via our payment processor (Stripe) — AxonIR does not store credit card numbers or full bank details

2.2 Information We Collect Automatically

  • Standard web logs (IP address, user agent, referrer URL, timestamp, pages viewed)
  • Cookies and similar technologies (see Section 7)
  • Analytics data via Google Analytics 4 and Cloudflare Web Analytics, including AI-search referrer detection (when an AI search engine such as ChatGPT, Perplexity, Claude, Gemini, or Copilot directs you to our site)
  • Performance metrics (page load times, error events) for site reliability

2.3 Information from Public Sources

  • SEC EDGAR filings of public companies (10-K, 10-Q, 8-K, S-1, S-4, DEFM14A, proxy statements)
  • Public social media activity (Reddit, StockTwits, X) referencing publicly-traded ticker symbols, used in aggregate for sentiment analysis
  • Public corporate websites (for IR website auditing of customer or prospect companies)
  • Public ticker-CIK mappings published by the SEC

We do not collect or process information about consumer purchases, consumer health, biometric data, children, or any data category requiring special consent under HIPAA, FERPA, COPPA, or GLBA.

3. How We Use Information

  • Provide our subscription service: generate Sample Test Reports, Monthly Analysis Reports, draft scoring outputs, peer benchmarks
  • Communicate with you about your account, deliverables, and changes to our service
  • Send marketing emails (newsletter, product updates) only to addresses that have opted in; honor unsubscribe requests within 10 days
  • Improve our scoring methodology by analyzing aggregated, anonymized score outputs (never customer-specific pre-publication content)
  • Detect and prevent fraud, abuse, or security incidents
  • Comply with legal obligations and respond to lawful requests

We do not sell or rent your personal information. We do not use your data for purposes unrelated to providing the AxonIR service.

4. Pre-Publication Content (MNPI Handling)

When you submit pre-publication SEC filing drafts, press release drafts, or other non-public corporate communications to AxonIR for scoring, you may be sharing material non-public information ("MNPI"). We treat this content with the following specific protections:

  • Encryption at rest using AES-256 (or equivalent) for stored drafts
  • Encryption in transit using TLS 1.3 (or equivalent) for submission and delivery
  • 90-day retention from the public publication date of the underlying document; deletion thereafter unless extended by your written consent
  • Strict access controls — drafts are never viewable by AxonIR personnel except as required to deliver scoring output
  • No use for AI training of public models; pre-publication content is excluded from the data sets we use to refine our scoring methodology
  • No disclosure to third parties except as required by law (subpoena, regulatory order)

These provisions are also reflected in our Master Service Agreement and Founding Partner Addendum. Customers who require additional contractual protections (e.g., specific regulatory representations) should contact us before signing.

5. How We Share Information

We share information only in the following limited circumstances:

  • Service providers — vendors that support our operations (e.g., Stripe for billing, Resend for email, Cloudflare for hosting and DDoS protection, Anthropic for LLM-summarized recommendations). Each is contractually bound to use information only to provide their service.
  • Customer-authorized disclosures — if you sign the Founding Partner Addendum, you may grant us rights to use your score outputs in case studies (with your written approval of all quotes).
  • Legal compliance — when required by law, regulation, court order, or government request (e.g., SEC subpoena in a customer's regulatory matter).
  • Business transfer — in connection with a merger, acquisition, or sale of all or substantially all of our assets, in which case successor entities will be bound by this Privacy Policy or a comparable replacement.

6. International Data Transfers

AxonIR primarily operates in the United States. If you access our service from outside the U.S., your information will be transferred to and processed in the United States. By using AxonIR, you consent to this transfer. We do not currently offer data residency outside the United States.

7. Cookies and Tracking

AxonIR uses a limited set of cookies and similar technologies for the following purposes:

  • Strictly necessary — session management, authentication on the customer dashboard, security (CSRF tokens)
  • Analytics — Google Analytics 4 (which uses cookies) and Cloudflare Web Analytics (which uses no cookies)
  • AI-search attribution — when our site detects that you arrived from an AI search engine, we tag the URL with UTM parameters (utm_source=chatgpt, perplexity, claude, gemini, copilot) so we can measure organic AI search performance. No personal data is captured by this attribution.
  • Marketing — pixel-based attribution from Google Ads and LinkedIn Ads (only when you arrive from a paid advertisement)

We honor the Do Not Track browser signal: when DNT is enabled, our GA4 and marketing pixels are suppressed. You can also disable cookies entirely in your browser settings; basic site functionality will continue to work.

8. Your Rights

You have the following rights regarding your personal information:

  • Access — request a copy of the information we hold about you
  • Correction — request that inaccurate information be corrected
  • Deletion — request deletion of your personal information, subject to legal retention requirements
  • Portability — request a machine-readable copy of your information
  • Opt-out of marketing — unsubscribe from marketing emails at any time via the unsubscribe link or by contacting [email protected]
  • Lodge a complaint — contact us first at [email protected]; if your concern is not resolved, you may contact your state attorney general or a relevant data-protection authority

To exercise any of these rights, email [email protected]. We will respond within 30 calendar days.

9. California Residents (CCPA / CPRA)

California residents have the rights described in Section 8 above. Additionally, under the California Consumer Privacy Act and California Privacy Rights Act:

  • We do not "sell" your personal information as defined under CCPA/CPRA.
  • We do not share your personal information for cross-context behavioral advertising.
  • You may submit a request to know, delete, correct, or opt out of any future selling or sharing by emailing [email protected].
  • You may designate an authorized agent to make a request on your behalf, subject to verification.

10. EU/UK Residents (GDPR/UK-GDPR)

If you access AxonIR from the European Union or the United Kingdom, you have additional rights under the GDPR or UK-GDPR, including the right to object to processing, the right to restrict processing, and the right to lodge a complaint with your supervisory authority. Our legal bases for processing are:

  • Contract — to provide the service you have signed up for
  • Legitimate interests — to improve our service, prevent fraud, and operate our business
  • Consent — for marketing communications and non-essential cookies (where consent is required)
  • Legal obligation — to comply with applicable laws

International transfers of EU/UK personal data to the United States rely on Standard Contractual Clauses where applicable. Contact us for a copy of the data transfer addendum.

11. Data Security

AxonIR implements technical and organizational measures appropriate to the sensitivity of the information we hold:

  • Encryption at rest and in transit (per Section 4)
  • Role-based access control on internal systems
  • Cyber liability insurance covering breach response (effective when policy is bound)
  • Vendor security review for all subprocessors
  • Incident response procedures with breach notification within 72 hours where legally required

No method of transmission or storage is perfectly secure, and we do not guarantee absolute security. If you believe your account has been compromised, contact us immediately at [email protected].

12. Retention

We retain personal information for as long as necessary to provide the service and comply with our legal obligations:

  • Customer account data — for the duration of the customer relationship plus 7 years for tax and audit purposes
  • Pre-publication content — 90 days from public publication of the underlying document (per Section 4)
  • Marketing-only contacts — until you unsubscribe
  • Web logs — 90 days for security investigation; aggregated thereafter
  • Backup copies — 30 days rolling, then deleted

13. Children

AxonIR's service is intended for business customers (public companies, SPAC sponsors, and their authorized representatives) and is not directed at children under 13. We do not knowingly collect information from children. If you believe we have inadvertently done so, contact us at [email protected] for prompt deletion.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the email address you provided (for active customers) and posted on this page with a new effective date. The version in effect when you signed up will continue to apply to historical activities unless you accept the new version.

15. Investment-Advisor Disclaimer

AxonIR is not a registered investment advisor, broker-dealer, or proxy solicitor. The algorithmic readability scores, sentiment analyses, and recommendations we provide are informational only, derived from publicly-filed SEC documents and the public-domain Loughran-McDonald financial sentiment dictionary. AxonIR does not guarantee stock price performance, investor outcomes, or regulatory approvals. This disclaimer is repeated in our Master Service Agreement and is binding on all customers.

16. Contact

For any privacy-related question, request, or complaint, contact:

Tejune Kang
Founder, AxonIR Operations, LLC
1185 Avenue of the Americas, 3rd Floor, New York, NY 10036
[email protected]