Data Retention & Deletion Policy

Website: axis.inc

Owner: Axis Platforms, Inc. ("Company", "we", "us")

Effective Date: September 16, 2026

Important: This Data Retention & Deletion Policy explains how long Axis Platforms, Inc. keeps data and how it is deleted. For End User data, Axis acts on behalf of Operators, who decide how long their End Users' data is kept, subject to applicable law. It should be read together with our Privacy Policy.

1) Purpose & Scope

This Data Retention & Deletion Policy ("Policy") describes how long Axis Platforms, Inc. keeps personal data and business records, how that data is deleted or anonymized when it is no longer needed, and how deletion requests are handled. It supplements our Privacy Policy and Information Security Policy.

This Policy applies to data in any format that is held in the Platform, in Axis's business systems, or in systems operated for Axis by its service providers.

2) Definitions

  • Company, Axis, we, us: Axis Platforms, Inc.
  • Platform: The software, templates, dashboards, APIs, and infrastructure Axis provides to Operators.
  • Operator: A business that uses the Platform to launch and run an Operator Platform (a "Customer" under our Terms of Service).
  • Operator Platform: An online gaming, betting, prediction-market, or related site or application that an Operator runs using the Platform.
  • End User: A player, customer, or visitor of an Operator Platform.
  • Retention Period: How long a category of data is kept before it is deleted or anonymized.
  • Deletion: Permanently removing data so that it can no longer be read or recovered in the normal course of business.
  • Anonymization: Irreversibly changing data so that it can no longer be linked to an identifiable person.
  • Legal Hold: An instruction to preserve data that would otherwise be deleted, because of litigation, an investigation, an audit, or a request from a regulator or law enforcement authority.

3) Our Role & Operator Responsibilities

Axis is a technology provider. We do not operate gaming services, and we are not the house under any circumstances. Our role depends on the type of data:

  • End User Data: Axis processes End User data on behalf of the Operator, which controls that data. The Operator decides how long its End Users' data is kept, subject to applicable law and its license conditions. The default periods in the Retention Schedule apply only where the Operator has not instructed otherwise.
  • Axis Business Data: Axis controls Operator account data, billing records, its own compliance records, security logs, and website data, and sets the Retention Periods for that data.

Each Operator is responsible for:

  • Setting Retention Periods that meet the requirements of its licenses and of the laws of every jurisdiction where it operates, including anti-money laundering, gambling, tax, and data protection laws.
  • Telling its End Users, in its own privacy notice, how long their data is kept.
  • Responding to End User requests to access or delete their data.
  • Exporting and keeping any records it is legally required to keep before its agreement with Axis ends.

4) Retention Principles

  • Necessity: Data is kept only as long as it is needed for the purpose it was collected for, or as long as the law requires.
  • Longest Requirement Applies: Where more than one requirement applies to the same data, the longest applicable Retention Period is used.
  • Minimization: Where only part of a record must be kept, the rest is deleted or anonymized.
  • Legal Holds Come First: Data subject to a Legal Hold is not deleted until the hold is released.
  • Automation: Wherever practical, deletion happens automatically when a Retention Period ends.

5) Retention Schedule

The Retention Periods below are Axis's standard periods. Where a period runs from account closure and the account is never closed, it runs from the End User's last activity instead.

Operator & Business Data

  • Operator Account Data: For the term of the Operator's agreement with Axis, plus 2 years.
  • Operator Due Diligence & Sanctions Screening Records: 5 years after the Operator relationship ends.
  • Contracts & Legal Records: 7 years after the contract ends.
  • Invoices, Billing & Tax Records: 7 years after the end of the tax year they relate to.
  • Support Communications: 2 years after the last message.

End User Data (Defaults Unless the Operator Instructs Otherwise)

  • Account & Profile Data: 2 years after account closure.
  • Identity Verification (KYC) Records: 5 years after account closure. Includes copies of identity documents and verification results.
  • Transaction, Wagering & Market Records: 5 years after the transaction. Includes deposits, withdrawals, bets, market positions, settlements, and the written justification for any manual balance adjustment.
  • Responsible Gaming Records: 5 years after account closure, and for as long as any self-exclusion remains in effect. Includes limits, cooling-off periods, and self-exclusions.
  • Marketing Consent & Opt-Out Records: For as long as needed to respect the End User's choice.
  • Device, IP & Session Data: 2 years after collection.
  • One-Time Verification Codes: Deleted within 30 days after they are used or expire.
  • Access Tokens for Connected Financial Accounts: Deleted within 30 days after the End User disconnects the account, the Operator relationship ends, or the token is no longer needed.
  • Biometric Data: Where collected through an identity verification integration, kept only as long as needed to complete verification, and never longer than applicable biometric privacy laws allow.

Security, Compliance & System Data

  • Security & Audit Logs: 2 years.
  • Operational Application Logs: Only as long as needed for troubleshooting, and generally no more than 90 days.
  • Security Incident Records: 5 years after the incident is closed.
  • Anti-Money Laundering Investigation & Reporting Records: 5 years after the investigation is closed or the report is filed.

Website Data

  • Contact & Demo Requests: 2 years.
  • Cookies: For the lifetime of each cookie, as described in our Privacy Policy.
  • Anonymized Analytics: May be kept indefinitely.

6) Self-Exclusion & Suppression Records

Some records must outlast an End User's account so that the protections they support keep working:

  • Self-exclusion records are kept for as long as the exclusion is in effect, even after the account is closed or a deletion request is made, so the Operator can stop the End User from opening a new account and stop marketing to them. Permanent self-exclusions are kept indefinitely.
  • Marketing opt-out records are kept so that the End User is not contacted again.
  • Only the minimum information needed to recognize the End User is kept for these purposes, and it is not used for anything else.

8) How Data Is Deleted

  • Active Systems: When a Retention Period ends, the data is permanently deleted or anonymized in the Platform and in Axis's business systems.
  • Anonymized Data: Anonymized data may be kept for analytics and product improvement. Axis will not attempt to re-identify it.
  • Service Providers: Axis requires its service providers to delete or return data when their services end, under our agreements with them.
  • Physical Media: Storage media is sanitized or destroyed by our cloud providers in line with recognized industry standards, such as NIST SP 800-88.

9) Backups

Deleted data may remain in encrypted backups until those backups expire under their normal rotation cycle, after which it is permanently overwritten. Backups are used only to restore systems after data loss or a disaster. If a backup is restored, Axis re-applies any deletions made after the backup was taken before the restored data is put back into normal use.

10) Deletion Requests

  • End Users: Because each Operator controls its End Users' data, End Users should send access and deletion requests to the Operator of the site they use. If Axis receives a request directly, we will forward it to the relevant Operator and help the Operator respond.
  • Operators & Their Staff: Operators and their personnel can request deletion of data Axis controls by emailing support@axis.inc with "Privacy Rights Request" in the subject line. We will respond within the time required by applicable law.
  • Exceptions: A deletion request does not require Axis to delete data that must be kept to meet a legal or regulatory obligation, prevent fraud or money laundering, maintain a self-exclusion, establish or defend legal claims, or comply with a Legal Hold. Data kept for these reasons is restricted to those purposes and deleted when the need ends.

11) End of an Operator Relationship

  • Export Window: When an Operator's agreement with Axis ends, the Operator may request an export of its data for 30 days, unless its agreement says otherwise.
  • Deletion: After the export window closes, End User data processed for that Operator is deleted from active systems within 90 days, and from backups as they expire, unless Axis is required by law to keep specific records.
  • Operator Obligations: Before the export window closes, the Operator is responsible for exporting and keeping any records it must keep under its licenses or applicable law.
  • Axis Records: Axis keeps its own records about the Operator, such as account, billing, and due diligence records, for the periods set out in the Retention Schedule.

12) Compliance & Review

  • This Policy and its Retention Schedule are reviewed at least annually, and whenever relevant laws or the Platform change.
  • Any exception to a Retention Period must be documented and approved, and must state the reason for the exception and how long it will last.
  • If this Policy conflicts with a signed data processing agreement between Axis and an Operator, the data processing agreement controls for that Operator's data.

13) Changes to This Policy

We may update this Policy from time to time by posting a revised version on this page with a new effective date. We will notify Operators of material changes by email or through the Platform.

14) Contact

For questions about this Policy, or requests about data Axis controls, email support@axis.inc with "Privacy Rights Request" in the subject line.

Axis Platforms, Inc.

Website: https://axis.inc

U.S. Legal Notice / Registered Agent Address:

Legalinc Corporate Services Inc.

131 Continental Dr, Suite 305

Newark, DE 19713, United States

Support: support@axis.inc