Legal
Privacy.
What we collect, what we do not, and what happens to the data your fleet produces. Two things up front: this site sets no cookies and runs no analytics (section 3 lists the few things your own browser keeps), and we delete raw fleet data after three months.
daXos LLC · Greensboro, North Carolina · version 2026.09, effective 12 September 2026 · permanent link to this version
1 · Who we are
daXos LLC, a North Carolina limited liability company in Greensboro, North Carolina, operates daxosdigit.com and the daXos service. For anything on this page, or to exercise a right described in section 10, write to info@daXosdigit.com.
The person responsible for the protection of personal information at daXos is the Chief Executive Officer, reachable at the same address.
daXos sells in the United States and Canada, to businesses.
2 · Two different kinds of data
Keeping these apart is the whole of this policy.
Data about you — what you type into a form, and what you give us when you order. We decide what happens to it, so we are responsible for it. Sections 3 and 4.
Data from a customer’s fleet — the measurements our devices capture from assets and the goods they carry. That data belongs to the customer, not to us. In the language of privacy law, the customer is the controller and daXos is the processor: we handle it on their documented instructions and for nothing else. Sections 5 to 8.
Business customers can sign a Data Processing Agreement with us that sets all of this out in contractual form, including standard clauses for international transfers. Ask us for it. Where a signed DPA and this page differ, the DPA governs.
3 · No cookies, no tracking — but your browser does hold some of this
No analytics. No advertising or cross-site tracking. No pixels, no session recording, no fingerprinting. We do not follow you between sites, and we do not build a profile of you.
The site does keep a few things in your own browser's local storage, so that a page you are part-way through survives a reload. This is not a cookie and none of it is sent to us automatically, but it is on your device and you are entitled to know what it is:
- daxos-market
- the country and currency you chose, so the prices stay right.
- daxos-cart
- the kit you configured, so your cart survives a reload.
- daxos-lead
- what you typed into the trial form — name, work email, company, phone and your description of the problem — so the order page does not ask you twice. It is removed as soon as an order completes.
- daxos_last_checkout
- a reference to your most recent order, so you can open your billing without waiting for an email. It expires one hour after checkout.
Clearing site data for daxosdigit.com in your browser removes all of it, and nothing on this site stops working afterwards — you would simply fill the form in again.
Two things are stored by your browser, on your device, and never sent to us:
daxos-market— the country, language and currency you picked, so the site remembers it on your next page.daxos-cart— the kit you configured, so your cart survives a reload.
Clearing your browser data for this site removes both. There is no banner to click because there is nothing to consent to.
One thing to be straight about: our typefaces are served by Google Fonts, so Google receives your IP address when a page loads, as it would on most of the web. Everything else on the page comes from our own host.
4 · What we collect when you contact us or order
Free-trial request. Name, work email, company, phone if you give it, fleet size, region, asset mix, and the problem you describe. It reaches us through Google Forms and is stored in a Google Sheet we control.
Quote request. The button opens your own email client with the message prepared. We receive an ordinary email — nothing passes through a form processor.
Order. Company, your name, work email and billing address. We use them to raise the subscription, invoice it, and reach you about the service.
Payment. Card details go straight to Stripe on Stripe’s own page. daXos never sees, handles or stores a card number. Stripe tells us a payment succeeded, and the card brand and last four digits for your receipt.
We do not buy contact lists, and we do not add you to a mailing list because you asked for a quote.
5 · Fleet data, and the people driving
What the devices capture is the cargo and the asset: temperature and humidity, tilt and roll, shock and handling, position, movement and trip data, vehicle health and fault codes.
daXos does not capture driver identity, in-cab audio, or video. No daXos device carries a camera or a microphone. Our devices read from the vehicle; they have no write access to any vehicle system.
Even so, where a vehicle’s location and movement can be linked to the person driving it, that is personal data. So is any driver or personnel identifier a customer chooses to attach to a vehicle, and any platform account. In every case the customer is responsible for it and we act on their instructions. Telling drivers what is collected, and having a proper legal basis — including anything an employment agreement or works council requires — is the employer’s job. If a driver comes to us directly, we do not answer on the merits: we pass the request to the customer and help them answer it.
The service is not built for sensitive categories of personal data, and customers must not configure it to send any.
6 · How long fleet data lives
Raw data is kept for three months, on a rolling basis. Telemetry, sensor readings, location and event data are deleted or de-identified three months after they are captured. That window is a deliberate limit, not a storage constraint.
Dashboards, summaries and statistics a customer has generated inside the service can outlive the raw readings behind them. A longer raw-data window can be agreed in an order form where a customer needs one.
When a subscription ends, a customer can export what is still held, through the service or by asking us, for thirty days. We then delete or return the personal data at their choice, and in any event within ninety days. Two exceptions: records the law requires us to keep, and routine backups, which are overwritten on their ordinary cycle rather than reached into. We will confirm deletion in writing on request.
Account and billing records are kept for the term of the agreement and for as long as tax and accounting law requires.
7 · Artificial intelligence, and the line we do not cross
Fleet data powers dashboards, alerts and the AI agents you use — anomaly detection, road-condition and energy analytics, and anything you connect through your own MCP endpoint. Tuning a model to your own fleet is part of running the service for you.
We do not use customer data to train AI agents or models that the customer does not use. Not by default, and not on the strength of a line in these terms. It takes a separate signed addendum naming the data, the purpose and the de-identification standard. We may ask; a customer may decline, for any reason or none, and declining changes nothing about their service, their fees or their support. An email does not count as agreement.
Separately, we do create de-identified, aggregated data that cannot reasonably be linked back to a customer, its people, its customers or its vehicles. We do not attempt to re-identify it, and anyone we give it to is contractually barred from trying.
8 · Who else touches the data
Only providers who help us run the service, each bound by a written contract no less protective than our own commitments, and each with only what it needs:
- Cloud hosting and storage — where the platform runs.
- Telematics gateway — the platform that receives data from the devices.
- Cellular connectivity — the network the devices use to report.
- Stripe — payments, subscriptions and invoices.
- Netlify — website hosting and security logs.
- Google — Forms and Sheets for trial requests, Gmail to reply to you, Fonts for typefaces.
Our current providers are named in the DPA, and we will name them on request. Customers get at least fifteen days’ notice before we add one, and can object on reasonable data-protection grounds.
We do not sell or share personal data, in the sense US state privacy laws give those words, and we never use it for cross-context behavioural advertising, our own marketing, or profiling. We disclose data to anyone else only where the law requires it, and we tell the customer unless we are forbidden to.
9 · Where the data is, and how it is protected
daXos and its providers process data in the United States. If you are in Canada, using the service means your data crosses the border, where it is subject to US law and to lawful access requests by US authorities. If you are in the EU or the UK, daXos has no establishment or representative there; where the GDPR applies to a customer’s data, our DPA carries the European Commission’s Standard Contractual Clauses.
Data is encrypted in transit and at rest. Access inside daXos is role-based, least-privilege and need-to-know, with multi-factor authentication on administrative and production systems and logging of administrative access. Each customer’s API and MCP endpoint can reach that customer’s data and no one else’s. Device updates are signed. Payment card data never reaches our systems.
No system is perfect. If a breach affects personal data we hold for a customer, we tell them within seventy-two hours of becoming aware, with what we know at the time, and we help them meet their own notification duties.
10 · Your rights
Whatever your location, you can ask us to show you the personal data we hold about you, correct it, delete it, or stop using it — and you can withdraw consent at any time. Write to info@daXosdigit.com and we will answer within thirty days.
In Canada, your rights come from PIPEDA and, in Québec, from the Act respecting the protection of personal information in the private sector, including the right to receive your data in a structured, portable form. If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada, or in Québec to the Commission d’accès à l’information.
In the United States, the comprehensive privacy laws of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states give residents rights over their personal data. We apply the rights above to everyone rather than checking which state you are in.
If a request concerns fleet data belonging to one of our customers, section 5 applies: we pass it to that customer and help them answer.
11 · Children
This is a business service. It is not directed at children, and we do not knowingly collect data from anyone under 16.
12 · Changes
We update this policy when what we do changes. Every version carries the date above, and we write to customers before a change that matters to them.
13 · Reaching us
daXos LLC, Greensboro, North Carolina, United States.
info@daXosdigit.com
See also the daXos Sales Terms. A French version of this policy is published at privacy-fr.html.
