Taxia

Privacy Policy

This Privacy Policy explains what personal data Taxia (“we”, “us”) processes when you use our website and the “Taxia Constellation Board” application, including when it runs as an app inside a Zoom meeting, the legal bases for that processing, and the rights you have under the GDPR.

1. Data we collect

  • Contact / booking requests: name, email, company, the topic of your request and the fact that you gave consent.
  • Session data: the client request, participant names, analyst notes, representative responses and the movement log. Inside a Zoom meeting this is held transiently and cleared automatically by a timer; on the solo board it is stored locally in the analyst’s own browser (localStorage).
  • Zoom App context: when the board runs as a Zoom App we receive a Zoom-provided meeting and user context (such as the meeting UUID and a user identifier) solely to open and synchronise the shared board during that meeting. We do not access meeting audio, video or chat.
  • Zoom account linking (optional): if you link your Zoom identity to your Taxia account by entering a code shown in the Zoom app, we store the pairing (the Zoom user identifier and your account) so boards you host in meetings appear in your dashboard. The pairing is kept until you unlink it in the dashboard, remove the app in Zoom, or delete your account.
  • Billing data: if you subscribe to Board Pro, we receive limited transaction data (your email, the order or subscription identifier, amount and status) from our payment provider. Full card or bank details are handled by the payment providers and never reach our servers.
  • Technical data: the IP address of a form submission, used only to protect the form from spam.
  • Website analytics: to see how many people visit and which pages they open, we keep our own privacy-preserving counter. For each page view we store the page path, the referring website and a short daily hash of your IP address and browser (never the IP address itself). The hash changes every day, so it cannot identify you or follow you across sites; no cookie is set, the data stays on our EU-hosted server and is deleted after 90 days. This counter runs for every visitor and needs no consent. Separately, and only if you accept cookies in the banner, we also use PostHog on our public pages to record which elements you click and a replay of your visit; see section 3. PostHog never runs on the board, in live sessions or in the dashboard.

2. What we do NOT do

  • We do not use artificial intelligence to process or interpret session data or board content.
  • We do not sell or share session data with third parties or advertising services.
  • We do not store full card or bank details. Payments for Board Pro are processed by our Merchant of Record (Polar) and by Stripe; we only receive limited transaction data.
  • We do not set advertising cookies without your consent. Strictly necessary cookies (the authentication session for signed-in users, your language preference and your cookie choice) always work. Only if you press «Accept» in the cookie banner do we additionally load the Meta Pixel for advertising measurement (see section 3). The board uses localStorage to keep your work.

3. Subprocessors and data recipients

To run the service we rely on a small number of processors:

  • Hosting: the website, server and database run on infrastructure provided by Hostinger, in a data centre in Frankfurt, Germany (EU). No transfer outside the EU is involved for hosting.
  • Email: transactional and sign-in emails are sent, and inbound replies received, through Resend (Resend, Inc., USA), with mail processed in the EU region (AWS eu-west-1). The transfer to the United States relies on Standard Contractual Clauses, and the EU-US Data Privacy Framework where applicable.
  • Zoom: when you use the Zoom App, Zoom Video Communications, Inc. (USA) provides the in-meeting context. Transfers to the United States rely on the EU-US Data Privacy Framework and, as a safeguard, Standard Contractual Clauses. We do not send session content to Zoom beyond what is needed to run the in-meeting board, and we do not access meeting media.
  • Payments: subscription payments are processed by Polar (Polar Software Inc., USA), acting as Merchant of Record and seller of record, with card processing by Stripe, Inc. (USA). They receive your email and transaction data to take payment and issue your invoice. Transfers to the United States rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Operational notifications: when you submit a contact request, booking or facilitator application, a short notification (your name, email and request subject) is delivered to the platform operator through Telegram (Telegram Messenger Inc.). It is used solely so we can respond promptly, is not used for marketing, and the authoritative record stays in our EU-hosted database.
  • Document recognition (only with your consent): when a facilitator uploads diplomas or certificates in the dashboard and ticks the recognition checkbox, the selected document scans are sent to Google (Google Ireland Ltd. / Google LLC, USA) to automatically extract the document type, title, issuer and year via the Gemini API. We use the paid API tier, under which Google acts as a processor and does not use the content to train its models. The scans themselves are stored only in our EU-hosted database; the consent is logged. If you prefer not to use recognition, you can leave the checkbox unticked and enter the details manually after uploading. Transfers to the United States rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Profile translation (facilitators only): to list a facilitator in every language of the site, the free-text fields of a facilitator’s own catalog profile (headline, about, approach, city, formats) are sent to Google (Google Ireland Ltd. / Google LLC, USA) via the same paid Gemini API to be translated into the site languages when the profile is saved. This is done to perform the listing service (Art. 6(1)(b)); Google acts as a processor on the paid tier and does not use the content to train its models. The translations are stored in our EU-hosted database, included in your data export, and deleted with your account. Names and uploaded documents are not sent for translation. Transfers to the United States rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Product analytics and session recording (only with your consent): if you accept cookies in the banner, we load PostHog (PostHog, Inc., USA) on our public pages. It sets cookies and records which pages you open, which elements you click and a replay of your visit, so that we can see where people get stuck and fix it. Everything you type into a form is masked in your browser before anything is sent, so the contents of your inputs never reach PostHog. Our PostHog project is hosted in the European Union (Frankfurt) and your data is stored there; PostHog, Inc. acts as our processor and any access from the United States relies on the EU-US Data Privacy Framework and Standard Contractual Clauses. PostHog is never loaded on the constellation board, in live sessions, on the card table or in the dashboard. Session content, the client request, figure names and uploaded documents are therefore never recorded and never transmitted to PostHog, with or without your consent. You can decline in the banner or withdraw consent at any time via the «Cookies» link in the footer; declining does not limit the service in any way.
  • Advertising measurement (only with your consent): if you accept cookies in the banner, we load the Meta Pixel (Meta Platforms Ireland Ltd.). It sets cookies and sends pseudonymous identifiers, your IP address and the pages you visit to Meta so we can measure how our ads perform and attribute sign-ups and applications to them. We never send session content, board data or form contents. Transfers to the United States rely on the EU-US Data Privacy Framework and Standard Contractual Clauses. You can decline in the banner or withdraw consent at any time via the «Cookies» link in the footer; declining does not limit the service in any way.

4. Legal bases and purposes

Contact requests are processed on the basis of your consent, to reply to you and arrange a meeting. Session data is processed to perform the service. The Zoom App context is processed to provide the in-meeting shared board you have chosen to use. Advertising measurement cookies (Meta Pixel) are used solely on the basis of your consent (Art. 6(1)(a) GDPR), given in the cookie banner and withdrawable at any time via the «Cookies» link in the footer.

5. Your rights (GDPR)

You have the right to request access to your personal data, and its rectification, erasure, restriction of processing, portability and objection, as well as the right to withdraw consent at any time. To exercise any of these rights, email hello@taxia.solutions. The analyst can delete board data from their browser at any time, and in-meeting board data clears automatically. You also have the right to lodge a complaint with a supervisory authority; in Slovenia this is the Information Commissioner (Informacijski pooblaščenec, IP-RS). Processing is also governed by the Slovenian Data Protection Act (ZVOP-2).

6. Retention and deletion

We keep contact requests no longer than necessary to reply and provide the service. In a Zoom meeting the board content and movement log clear automatically by timer (within about ten hours) and are not intended for long-term storage. Recordings, if any, are kept only with separate consent and are deleted on request. Billing and invoice records are retained as required by tax law (typically up to ten years), even after you delete your account, minimised where possible.

When you delete your account from the dashboard, we immediately anonymise the account (name, email and photo removed), delete the sessions you hosted together with their invite links, remove your contact requests and facilitator applications, and anonymise your booking records. Consent records are retained as proof that consent was given (Art. 17(3)(e) GDPR), and minimised billing records as described above. You can download a full copy of your data (account, profile, bookings, hosted sessions, applications, requests, consents and billing history) from the dashboard at any time before deleting.

7. Data controller and contact

The data controller is Mykhailo Koblychenko s.p., Dimičeva ulica 9, 1000 Ljubljana, Slovenia. For any privacy question or request, contact hello@taxia.solutions. This policy is governed by the laws of Slovenia and the European Union (GDPR).

Last updated: July 2026.

Home