Effective [date to be set at launch] · v1.0

Privacy Policy

New Axis Solutions P.C. ("New Axis Solutions", "we", "us") operates Nomoaxis, a legal practice management platform for law firms. This Privacy Policy explains what personal data we process, why, on what legal basis, with whom we share it, and how we keep it safe. Throughout this Policy, "Nomoaxis" means the platform; New Axis Solutions P.C. is the company that operates it and the party bound by this Policy.

1. Controller and contact

The controller is New Axis Solutions P.C., a company incorporated in the Hellenic Republic.

Legal nameNew Axis Solutions P.C.
Registered seat[Registered seat: to be completed on incorporation]
ΓΕΜΗ (General Commercial Registry) no.[ΓΕΜΗ: to be completed on incorporation]
ΑΦΜ (tax registration no.)[ΑΦΜ: to be completed on incorporation]
Contactcontact@nomoaxis.com

New Axis Solutions P.C. is the data controller for the personal data described in §2 of this Policy (account, billing, session, AI usage, and audit data). For all data you enter about clients, matters, documents, and time entries, your firm is the data controller and New Axis Solutions P.C. acts as data processor under the Data Processing Agreement.

2. Personal data we process

For data you enter about clients, matters, documents, and time entries, your firm is the data controller and New Axis Solutions acts as processor — see the DPA.

As data controller in our own right, New Axis Solutions processes the following:

  • Account data: email address and display name, stored in our database and Supabase authentication infrastructure.
  • Subscription and billing data: your plan, subscription status, billing period dates, and Stripe customer and subscription identifiers — mirrored from Stripe into our database. Card details and billing address are held by Stripe only and are never stored by New Axis Solutions.
  • Session and security data: session records including IP address, device label, last active timestamp, and MFA verification time; legal acceptance records (which document version you accepted, when, and from which IP address and device).
  • AI usage data: token consumption counts recorded against the subscription seat that generated them and against the workspace, used for quota enforcement and the owner's usage dashboard. The seat identifies the member who ran the query, so these records are personal data and not anonymous aggregates. No prompt or response content is stored in these records.
  • Audit log: an append-only record of security-relevant actions in your workspace, including actor identifier, IP address, action type, and timestamp.

What is encrypted, and what is not. Client records, matters, documents and their names, notes, communications, fee agreements, task titles and AI conversation history are encrypted in your browser under per-workspace keys that New Axis Solutions never holds, and reach our servers only as ciphertext. The following data is necessarily readable by New Axis Solutions or by the infrastructure providers listed in §4, and is not encrypted end-to-end:

  • Login email addresses and authentication metadata held in the Supabase-managed authentication service. Sign-in requires matching a submitted email address to an account, so this address cannot be encrypted under a key we do not hold.
  • Member names and email addresses in the workspace membership and profile records, so colleagues can be listed, assigned work and invited.
  • Workspace and firm names.
  • Billing data held by Stripe — billing name, billing address, card metadata and invoice line descriptions.
  • Outbound email — recipient addresses and the fully rendered message bodies of notification, invite, digest and billing emails, while they are queued and in transit.
  • Recipient email addresses on secure document-upload links and on client intake invitations.
  • Audit log structural fields — actor identifier, action type, entity type and record identifiers, IP address and timestamp. Descriptive audit detail is not retained in the log.
  • Structural values retained in audit metadata. The log carries the non-descriptive values that make an entry meaningful: amounts, hourly and agreed rates, tax amounts, billed minutes, plan names, roles and access levels, statuses, versions, and internal record identifiers. These are readable by us. Names, email addresses and free text are not written into audit metadata: a denylist enforced in the database rejects those keys at write time, so an entry carrying one is refused rather than stored and cleaned up afterwards.
  • Deadline calculation settings recorded per matter — whether weekends and public holidays count, whether the first day counts, and any excluded dates. They contain no names or narrative text.
  • Conflict-check subject fingerprints — keyed HMAC-SHA-256 values derived from party names. A fingerprint cannot be turned back into a name. It does, however, permit confirming a guess: anyone able to use the keying secret can test a candidate name and learn whether that name is present in a workspace. It is a pseudonymisation measure, not anonymisation, and the fingerprints remain personal data under the GDPR. The searched terms themselves are stored encrypted under your workspace key alongside the fingerprint, so the names you searched for are not readable by us; only the fingerprint, which carries the confirm-a-guess exposure just described, is.
  • Document text and matter context sent to Anthropic for AI features, which is necessarily in plaintext at the point of transmission — see §3a.

The accurate summary is: your case files are end-to-end encrypted under keys New Axis Solutions never holds, qualified by the readable categories listed above — login email addresses and authentication metadata, member names and emails, workspace and firm names, Stripe billing records, outbound email in the queue and its archive, audit structural fields and the structural values retained in audit metadata, deadline calculation settings, and the conflict-check fingerprint. We deliberately do not describe Nomoaxis as "zero-knowledge": login email addresses alone would make that claim false, and document text and matter context are processed in plaintext by Anthropic when you use AI features.

3. Legal basis for processing (GDPR Art. 6)

PurposeLegal basis
Provide the service to your firmArt. 6(1)(b) — performance of contract
Bill subscriptions and process paymentsArt. 6(1)(b) + Art. 6(1)(c) — contract + legal obligation
Security, fraud prevention, audit loggingArt. 6(1)(f) — legitimate interests
Compliance with tax, accounting, AML dutiesArt. 6(1)(c) — legal obligation
Service emails (renewals, security alerts)Art. 6(1)(b) and (f)
AI token quota management (usage counts per seat)Art. 6(1)(b) — performance of contract

We do not perform automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Art. 22).

3a. AI features and data processing

3a.1 How AI features process your data

When you use Nomoaxis AI features, the following data may be processed to generate AI responses:

  • (a) Matter metadata (matter name, type, status, deadlines, and assigned personnel) entered into the Nomoaxis platform.
  • (b) Client metadata (name, contact information, and relationship type) to the extent entered into the platform and relevant to the AI query.
  • (c) The text of your prompt or query submitted to Nomoaxis AI.
  • (d) Document text — both documents you explicitly attach to a query and documents the assistant selects and opens on its own initiative. See §3a.3.
  • (e) For the case-chronology, tabular-review and document-analysis features, the extracted text of the documents in scope, including text recovered from scanned pages by optical transcription (which is itself performed by sending page images to Anthropic).
  • (f) Search strings composed by the model when it uses the web-search capability. See §3a.6.
  • (g) Working-day rules your firm has recorded against a matter — whether weekends and holidays count, whether the first day counts, and any excluded dates — which the assistant reads and applies when it computes a deadline, and may record when you state one.

This data is transmitted over an encrypted connection to Anthropic PBC's API infrastructure solely for the purpose of generating a response to your query. Documents are decrypted and their text extracted in your browser; our servers relay the request but do not retain the prompt or the document text. Conversation history is stored encrypted in your workspace; see §6 for how long.

Assistant answers carry a provenance footer stating which documents were read from your file, what was retrieved from the web, and what was drawn from rules your firm previously recorded. The footer is generated by Nomoaxis code from the record of which tools ran, not written by the model, so it reports what actually happened rather than what the model says happened. It is displayed to you and stored with the conversation; it is not sent anywhere else.

3a.2 Anthropic PBC as sub-processor

Anthropic PBC (160 Eureka Street, San Francisco, CA 94114, United States) acts as a sub-processor when you use Nomoaxis AI features. Anthropic processes data solely on our documented instructions and for no other purpose. Anthropic is bound by a Data Processing Agreement with New Axis Solutions that incorporates:

  • (a) The obligations of Article 28 of Regulation (EU) 2016/679 (GDPR).
  • (b) Standard Contractual Clauses (SCCs) adopted by the European Commission under Decision 2021/914/EU for transfers of personal data to the United States.
  • (c) Anthropic's obligation not to use data submitted via API requests for training its AI models.

3a.3 What the assistant retrieves on its own

The Nomoaxis AI assistant is not limited to what you attach to a question. Within the matter you currently have open, and subject to the same role and assignment checks that govern what you can see in the interface, the assistant decides for itself when to:

  • list and search the documents filed under that matter, and
  • open and read the full text of any of those documents.

When it does so, the documents are decrypted in your browser and their text is extracted on your device; the excerpts the assistant selected are then sent to Anthropic together with your question and a matter context summary. You are not asked to approve each individual read. The assistant is bounded by the matter in scope and by your own access rights — it cannot reach matters you are not assigned to, and it has no direct database access — but within those bounds retrieval is automatic. You should therefore assume that any document filed in a matter may be read by the assistant and transmitted to Anthropic when AI features are used on that matter.

Nothing in the product distinguishes special categories of personal data (Article 9 GDPR) or data relating to criminal offences and proceedings (Article 10 GDPR) from any other document text: if such data is in the matter file, the assistant may read it and transmit it. Whether to use AI features on such a matter is your decision as controller. Nomoaxis AI can be disabled per account from Settings.

3a.4 Logging and audit trail

New Axis Solutions maintains server-side logs of AI feature usage for security, abuse prevention, and billing purposes. These logs record: the timestamp of the query, the subscription seat that initiated it, and the approximate token volume consumed. Logs do not contain the full text of prompts or AI responses. Logs are retained for 90 days and then automatically deleted.

3a.5 Your rights in relation to AI processing

You may exercise the following rights in relation to personal data processed through AI features:

  • (a) Right of access (Article 15 GDPR): You may request confirmation of whether and how your data has been processed by AI features.
  • (b) Right to erasure (Article 17 GDPR / Article 17 N. 5104/2024): Deletion of your account results in the deletion of your account data (email, display name), your session and device records, your notification preferences, your personal key copies, and the AI usage records held by New Axis Solutions as controller. The single exception is the record of your acceptance of these documents — which version you accepted and when. That record is retained after deletion under Article 17(3)(e) GDPR, as evidence for the establishment, exercise or defence of legal claims; the IP address and device string stored alongside it are erased at the same time as the rest of your account, so what remains is the fact of acceptance and nothing further. The timing of each step is set out in §6. For matter, client, and practice data, erasure requests must be directed to your firm as controller. Anthropic retains technical API logs for up to 7 days for security and abuse prevention, after which they are automatically deleted; Anthropic holds no prompt or response content beyond the duration of the API request.
  • (c) Right to object (Article 21 GDPR): You may disable AI features for your account at any time from the Settings panel. Disabling AI features stops all further transmission of your data to Anthropic's infrastructure.

To exercise these rights, submit a request to: contact@nomoaxis.com

3a.6 Web search

The Nomoaxis AI assistant can perform a limited number of web searches per request when your question concerns case law, legislation, official gazettes or recent legal developments. The search is executed server-side by Anthropic as part of the model call, using Brave Search (Brave Software Inc., United States) as Anthropic's search provider. New Axis Solutions does not contact Brave directly and cannot see the search infrastructure.

The search string is composed by the model from the conversation, which includes your prompt and the matter context. It may therefore contain details drawn from your matter, including party names. Do not treat the search path as free of client-identifying content; if that is unacceptable for a given matter, do not use the assistant for research on it.

New Axis Solutions records only the number of searches performed, for usage metering; we do not store the search strings or the results. Retention of the query by Anthropic and Brave is governed by their own terms and is not something New Axis Solutions can verify independently.

4. Sub-processors

Sub-processorRoleRegion
Lovable CloudNomoaxis' hosting platform. Lovable Cloud operates the application runtime, edge functions and CDN, provisions and administers the Supabase database, authentication service and file storage described in the next row, and operates the transactional email delivery pipeline and the AI Gateway used by the support chat. All Nomoaxis data therefore passes through, and is stored on, infrastructure operated by Lovable Cloud — including database rows, uploaded files and audit logs. What Lovable Cloud can read in the clear is exactly the unencrypted set listed in §2; workspace practice data is held as ciphertext. The support-chat AI Gateway additionally receives user-typed support messages and technical context (current URL, user-agent, browser locale, app version, workspace identifier, user role); redacted payloads are retained up to 90 days when capture is enabled. Outbound email passes through this pipeline in rendered plaintext.EU / Global
Supabase (provisioned through Lovable Cloud)Managed PostgreSQL database, authentication service, and object storage for uploaded documents. This is the primary datastore and holds all Nomoaxis application data: account profiles, login credentials and auth metadata, session records, audit logs, subscription data, and the encrypted workspace content. Uploaded files are stored in a private bucket under opaque identifiers.EU
Stripe Payments Europe, Ltd.Subscription billing and card processingIE / US
Anthropic PBC (160 Eureka Street, San Francisco, CA 94114, USA)AI language model inference for the Nomoaxis AI panel, the document assistant, case chronology, tabular review, and optical transcription of scanned pages. Receives user-typed prompts; role-filtered matter and client context summaries (matter titles and references, client names, contact details, opposing party names, deadline titles, team member names, internal record identifiers); the plaintext of document excerpts — both attached by the user and retrieved autonomously by the assistant (§3a.3); page images of scanned documents when optical transcription runs; and model-composed web search strings (§3a.6). Revenue figures are withheld from context for roles that cannot view financials. Processing is ephemeral; Anthropic states that technical API logs are retained up to 7 days for security and abuse prevention and that API inputs are not used to train its models.USA
Brave Software Inc. (engaged by Anthropic, not by New Axis Solutions)Web search provider behind Anthropic's server-side search tool, used for the legal-research capability described in §3a.6. Receives the search string composed by the model. New Axis Solutions has no contractual relationship with Brave; the safeguards are those in Anthropic's own sub-processor arrangements and Standard Contractual Clauses. Retention by Brave is governed by Brave's terms and is not verifiable by New Axis Solutions.USA
Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)Model inference for support chat (a Google Gemini model) via Lovable AI Gateway. Receives user-typed support messages and reportContext (current URL, user-agent, browser locale, app version, workspaceId (pseudonymous), user role). No matter data, client names, documents, or encrypted workspace content is transmitted. Processed under Google Paid Services terms — no product-improvement use. Retained for a limited period for abuse monitoring; that retention is governed by Google's and Lovable Cloud's own terms and is not independently verifiable by New Axis Solutions. Up to 24 hours implicit RAM caching.USA
Sentry (sentry.io)Client-side error monitoring. EU region; no PII, no IP, no session replay, no performance tracing.EU
open.er-api.comPublic FX rate feed for Reports currency conversion. No personal data sent.US

Hosting chain and location. New Axis Solutions does not operate its own servers. The application and the database are hosted by Lovable Cloud, which provisions the Supabase PostgreSQL instance, authentication service and object storage in an EU region; the database and uploaded documents are stored there at rest. Requests may be served from edge locations outside the EU by the hosting CDN, but the datastore of record is the EU instance. Data leaves the EU only for the specific purposes listed above: AI inference and web search (United States), and payment processing (Stripe, Ireland with US onward transfer). Sentry error events are ingested in the EU.

An up-to-date list is maintained at /dpa. We notify customers at least 30 days in advance of adding or replacing a sub-processor; you may object during that window and terminate your subscription if the change is unacceptable.

Our firm-default Article 30 GDPR register, including data categories, legal bases, retention periods and security measures, is published at /legal/record-of-processing.

5. International data transfers

Where personal data leaves the EEA, UK, or Switzerland (for example, to Stripe in the United States) we rely on the European Commission's Standard Contractual Clauses (Module 2: controller to processor; Module 3: processor to sub-processor) supplemented by the UK Addendum and the Swiss-specific addendum. These are supplemented by technical measures: transport encryption for all transfers, and client-side encryption of practice data, so that where practice data is transferred it is transferred as ciphertext the recipient cannot read. That supplementary measure does not apply to the transfers where plaintext is inherent to the purpose, which are — payment data sent to Stripe, and prompts, matter context, document excerpts, page images and search strings sent to Anthropic and, via Anthropic, to Brave (§3a). A copy of the SCCs in force for your tenant is available on request from contact@nomoaxis.com.

6. Retention

We retain controller data (account, session, AI usage, audit, and subscription records) for as long as your account is active. Deletion runs on the following mechanisms, each of which is automated:

  • Workspace content — 30 days after cancellation. When a subscription is cancelled, the workspace is marked for purge and its content, including uploaded documents, is deleted 30 days after the cancellation takes effect.
  • Accounts — 30 days after the last membership ends. A nightly job deletes any account that holds no membership in any workspace and has held none for 30 days, together with the user-scoped records attached to it: session and device records, notification preferences, recovery codes, and that member's own key copies — both their personal keys and the copies of retired workspace keys sealed to them. This removes that member's access to the keys, not the keys themselves: the workspace's retired-key archive is a workspace record and survives until the workspace itself is deleted. See §10a.
  • AI usage records — 90 days. A nightly job deletes individual AI usage events older than 90 days, whether or not the account is still active. Only the monthly totals used for quota enforcement and billing remain.
  • Email delivery log — 90 days. The record of mail we sent you — recipient address, template, delivery status — is deleted by a nightly job 90 days after it is written. It exists for deliverability and abuse investigation, not as a permanent record.
  • Unsubscribe links — 180 days. The one-click unsubscribe token embedded in an email expires 180 days after it is issued, and is deleted immediately when the account is deleted. Expiring the link never reverses the decision made with it: an unsubscribe is recorded separately in the suppression list below.
  • Complimentary access grants — 90 days if unused. A complimentary trial we grant to an email address is deleted 90 days after it is issued if it is never redeemed, and is deleted when the workspace it was applied to, or the account it was granted to, is deleted.
  • Unaccepted invitations — 30 days after expiry. An invitation to join a workspace is valid for 14 days. If it is not accepted, the invitation and the address it was sent to are deleted 30 days after it expires, and immediately if the invited account is deleted.
  • Audit log — the workspace retention period. New workspaces are created with a two-year period. The owner can change it — from 90 days up to seven years — or switch anonymisation off entirely, in which case nothing is anonymised. Workspaces created before this default was introduced have no period set until their owner sets one. Where a period applies, older entries are not deleted — the log is append-only and hash-chained — but the actor identity, IP address and any residual identifiers in them are irreversibly removed, and the entry then reads as having been performed by a former user.
  • Records kept longer. Subscription and payment records are kept for the period tax and accounting law requires. Records of your acceptance of these documents are retained under Article 17(3)(e) GDPR as evidence of agreement, stripped of the IP address and device string.
  • Suppression list — retained, by design. If an address bounces, is reported as spam, or is unsubscribed, we keep a record of that address, the reason and the date, and we keep it even after the account is deleted. Deleting it would restart mail to an address that asked not to receive any — so it is retained under Article 17(3)(b) and (e) GDPR, on the same basis as the acceptance records above. It holds nothing beyond the address, the reason and the timestamp.

You may export or delete your data at any time from Settings → Data & privacy.

AI and document-assistant conversation history is stored in encrypted form in your workspace and is controlled by your firm. Each user sees only their own conversations. Starting a new conversation from the AI panel archives the previous thread rather than deleting it: the encrypted rows remain in the database with an archive timestamp, are no longer loaded into the panel, and are retained for the life of the workspace. There is currently no time-based purge of archived conversations. They are deleted when the workspace or the account is deleted, and can be deleted on request to contact@nomoaxis.com. Because the content is encrypted under your workspace key, New Axis Solutions cannot read an archived conversation in either case.

7. Your rights

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion ("right to be forgotten").
  • Portability — receive your data in a machine-readable format (we provide JSON export in-app).
  • Restriction — limit processing pending verification.
  • Objection — object to processing based on legitimate interests.
  • Lodge a complaint — with your local supervisory authority (in Greece, the HDPA — www.dpa.gr).

8. CCPA (California residents)

The CCPA applies at revenue and volume thresholds that New Axis Solutions does not currently meet. We make the following commitments voluntarily and treat them as binding on us. We do not sell personal information and we do not share it for cross-context behavioural advertising. California residents have the right to know what categories of personal information we collect, to request deletion, to correct inaccuracies, and to be free from retaliation for exercising these rights. To exercise them, email contact@nomoaxis.com.

9. Cookies, local storage and analytics

New Axis Solutions uses only strictly-necessary cookies and browser storage entries required to operate the application you have asked for: keeping you signed in, remembering your selected workspace and interface preferences, holding your session encryption keys, keeping work you have not yet saved — a running timer, an unsent assistant message and its conversation state — and queueing events recorded while you are offline. The authentication session token is held in your browser's local storage and is transmitted as an authorization header with each request, rather than as a cookie. We do not use third-party analytics, advertising, or behavioural tracking cookies, and no storage in your terminal equipment is used for analytics, advertising or behavioural purposes. Every entry listed below is strictly necessary to provide the service you have requested. Stripe's embedded checkout sets its own strictly-necessary cookies on the checkout iframe under Stripe's privacy policy. Under Article 4(5) of Greek Law 3471/2006 storage in your terminal equipment must be disclosed even where it is strictly necessary and no consent is required. The table below discloses, by category, what the application writes to your terminal equipment, the mechanism used in each case, and the retention of each. Several categories are written once per signed-in user or per workspace, so more than one entry may exist. Categories marked "may contain practice content" can hold matter, client or document text you have entered; they stay on your device and are not transmitted to us in that form.

CategoryMechanismSet byPurposeRetention
Authentication session tokenLocal storage (not a cookie)New Axis Solutions (first party)Keeps you signed in and is sent as an authorization header with each requestUntil sign-out or session expiry
Session and device markersLocal and session storageNew Axis Solutions (first party)Session identifier and start time, which signed-in user a tab belongs to, and one-shot markers recording that a client-side encryption migration has run or that the application reloaded itself after an update — used for the session list in Settings, concurrent-session limits, the idle timeout, and to prevent a reload loopUntil sign-out or until the tab is closed
Interface preferencesLocal and session storageNew Axis Solutions (first party)Interface and legal-page language, sidebar state, display density, list filters and sorting, saved report filters, collapsed task groups, dismissed banners, and the record that you acknowledged the AI-features disclaimer. Filter values may reference a colleague or a matter statusUntil cleared by you
Unsaved work in progressLocal and session storage — may contain practice contentNew Axis Solutions (first party)Running time-tracking timers (matter reference, start time, description), draft task templates you have not yet saved, and the unsent message and conversation state of the AI assistant panel, so work survives a reload or navigationUntil the timer is stopped, the draft is saved or cleared, or the tab is closed
Offline event queueLocal storageNew Axis Solutions (first party)Queue of pending application events and a sync marker, so activity recorded while offline is not lostUntil the queue is flushed to the server
Encryption keys for the sessionSession storage, stored encrypted (wrapped)New Axis Solutions (first party)Your personal data-encryption key and your workspace keys, held in wrapped form so the app can decrypt practice data during the session without asking for your passphrase on every page. Never transmitted to us in unwrapped formCleared when the tab is closed or on sign-out
Wrapping key protecting those keysIndexedDB (non-extractable cryptographic key)New Axis Solutions (first party)A wrapping key generated in your browser that encrypts the session-storage keys above. It cannot be exported by any script, including ours, and is destroyed on sign-outUntil sign-out
__stripe_midCookieStripe.js, on the nomoaxis.com originFraud prevention and payment-session integrityApprox. 1 year
__stripe_sidCookieStripe.js, on the nomoaxis.com originFraud prevention and payment-session integrityApprox. 30 minutes

The two Stripe cookies are set only on the signup and billing/checkout pages, where Stripe.js is loaded to complete a payment you have initiated — they are not set during general use of the application. Because they are strictly necessary to carry out that payment, they do not require consent and do not change the position stated above.

10. Security

Workspace practice data — client and matter records, document contents and names, communications, fee agreements, task titles and AI conversation history — is encrypted with XChaCha20-Poly1305 in your browser, under per-workspace data encryption keys that are themselves wrapped to each member's personal keypair. New Axis Solutions never holds those keys in plaintext and cannot decrypt that content. This protection does not extend to the readable categories listed in §2, which exist server-side by design or by necessity. We describe the result as end-to-end encrypted case files with keys we never hold, qualified by that list — not as "zero-knowledge".

Passwords are hashed with bcrypt and checked against the HIBP breached-password database. Multi-factor authentication is supported and may be required by workspace administrators. Database access is gated by row-level security keyed on the workspace; uploaded documents live in a private bucket under opaque identifiers with short-lived signed-URL access. All security-relevant actions are written to an append-only, hash-chained audit log whose integrity is verified on a schedule. Where a compliance redaction has to rewrite entries in that log, the prior chain state is committed to a sealed epoch record first, so the change is provable rather than silent (see §2).

10a. Encryption key lifecycle and the retired-key archive

Each workspace has a data encryption key (DEK). The DEK is generated in the browser and stored only in copies individually sealed to each member's public key; removing a member removes their sealed copy. Workspace administrators can rotate the DEK, which generates a new key and re-encrypts workspace content under it.

Rotation does not destroy the superseded key. Every retired DEK is preserved in a retired-key archive, sealed to the members who held it, and is retained indefinitely for as long as the workspace exists. This is deliberate: the audit log is append-only and hash-chained, so the encrypted audit metadata inside it cannot be re-encrypted after the fact without breaking the chain, and without the archived key that historical detail would become permanently unreadable to you.

The consequence should be stated plainly: because retired keys are kept, ciphertext produced before a rotation remains recoverable by a member who holds an archived key copy. Rotation in Nomoaxis therefore protects future content and removes access for members who are removed or re-keyed; it does not achieve cryptographic erasure of past content. If you rotate keys in response to a suspected compromise, treat pre-rotation data as still exposed and take additional measures.

The retired-key archive is purged when the account holder deletes their account and when the workspace is deleted, and a member's archived key copies are removed when that member is removed from the workspace. Once the archive entries are gone, ciphertext encrypted under those keys is unrecoverable by anyone, including New Axis Solutions.

11. Contact for data requests

Email: contact@nomoaxis.com. Postal address available on request. We respond within 30 days. If you are unhappy with our response you may complain to your supervisory authority (in Greece, the Hellenic Data Protection Authority).

© Nomoaxis — Legal practice management for modern law firms.