This policy explains what personal data Topiax collects through topiax.xyz and during client work, why we use it, who receives it, how long we keep it, and the choices and rights you have. It also covers cookies and similar browser storage. It sits alongside our Terms of service and our Refund and guarantee policy.
1. Who is responsible for your data
Topiax is the trading name of Cyprian Tinashe Aarons, a sole trader based in Harare, Zimbabwe. In this policy, “Topiax”, “we” and “us” mean Cyprian Tinashe Aarons trading as Topiax. Topiax is not a company or any other separate legal entity. For the personal data described in this policy, Cyprian Tinashe Aarons decides how and why it is used. Data protection law calls this role the “controller”.
For any question about this policy or your data, write to cyprian@topiax.xyz.
One exception applies. When a client gives us access to their own app or systems, the personal data of that client’s users remains the client’s responsibility. We handle it only to deliver the engagement and on the client’s instructions. Section 2.7 explains how.
2. What we collect
We collect only what each activity needs. We do not ask for sensitive personal data such as health, biometric or financial account details, and we ask you not to send any.
2.1 Browsing the site
- Our hosting provider processes your IP address, your browser type and the pages you request in order to deliver the site and keep server logs.
- To limit abuse of our forms, each form request stores a one-way hash of your IP address with a request count that resets every hour. Our database does not store the IP address itself.
- For the length of your visit, your browser keeps the first page you landed on, the site that referred you, any campaign tags in the link you followed, and a random visit ID. This stays in your browser unless you submit a form.
- If you allow analytics, we also record pages viewed, buttons clicked, the referring site, campaign tags and random visitor and visit IDs. The analytics events we send do not contain your name or email address. Section 4 lists the tools.
2.2 The free 5-minute profile
- You give us answers about your app or AI workflow: its stage, what it does, what a failure would cost, the controls and evidence you already have, and why you are checking now. Some answers are in your own words.
- To receive the result you give your name, work email address, company, country and how soon you need to decide. Your role is optional.
- Your answers are sent to an AI model provider, Featherless AI, to write two follow-up questions and the written part of your result. This happens part-way through the form and again when you ask for your result. Your name, email address and company are not sent to the model.
- Please do not put passwords, keys, customer records or other confidential information into the free-text answers.
- We store your answers, your score and your details, email the result to you, and receive a notification ourselves. If you tick the box to receive emails, we also send a short series of follow-up emails. If you leave it unticked, you receive the result email only.
2.3 Downloading a resource or joining a waiting list
A resource form asks for your name and work email address, and sometimes your company and role. We store the request, open the download, and for some resources email you a copy. The Outpost waiting list form asks for your name, email address, company, role and the stage of your AI agent. Marketing emails are sent only if you tick the box that asks for them, or where the form itself is a request to be contacted.
2.4 Subscribing to the newsletter
We collect your email address and the page and campaign you subscribed from. Your email address is passed to beehiiv, which sends the newsletter, and is kept in our own records. Every issue has an unsubscribe link.
2.5 Booking a call
The booking calendar is provided by Cal.com and is shown inside our page in a frame that Cal.com serves directly. What you type into it (your name, email address, time zone and any notes) goes to Cal.com, which also receives your IP address and browser details and sets its own cookies. Cal.com then sends us the booking details, which we store so that we can prepare for the call and stop any scheduled follow-up emails.
2.6 Enquiring or becoming a client
When you email us, reply to one of our emails or start an engagement, we keep your contact details, your business name, our messages, the signed authorisation and scope, invoices and payment records. Card and bank payments are handled by the payment provider named on your invoice or payment link. We do not receive or store full card numbers.
2.7 What clients share during an engagement
We access client systems only under a signed authorisation and the engagement terms in our Terms of service. Depending on the engagement this can include test accounts, the code, settings and read-only views of a database or hosting dashboard, screenshots, prompts, and example questions from real users. Some of this may contain personal data about the client’s own users.
- Client data stays in client systems. We work through the access the client gives us and do not export databases or user records.
- Nothing is copied into public AI tools.
- The only material we hold outside client systems is what the work needs: a working copy of the code where the client gives us one, and evidence such as screenshots and notes for the report.
- Findings are shared only with the named client contact.
- Reports describe findings and may include screenshots as evidence. We avoid including personal data beyond what is needed to show a finding.
- Walkthrough and handover calls are recorded so that the client has a copy, unless the client asks us not to record.
- In Reliability Continuity, real AI conversations are reviewed only with the client’s permission and with personal data hidden.
- Case studies are published only with written consent and are anonymised by default. Exploitable details are never published.
If you need a written data processing agreement for an engagement, ask before work starts and we will agree one with you.
3. Why we use it and our legal bases
Where the law requires a legal basis for using personal data, these are the ones we rely on. Where we rely on legitimate interests, you can object (see section 8). Where we rely on consent, you can withdraw it at any time.
| What we do | Data used | Legal basis |
|---|---|---|
| Deliver the website, keep it secure and limit abuse of our forms | Data used: IP address, browser details, pages requested, hashed IP address with a request count | Legal basis: Legitimate interests: running a working, secure website |
| Remember your cookie choice and other on-page preferences | Data used: The browser storage listed in section 4 | Legal basis: Legitimate interests, and our legal duty to record your cookie choice |
| Optional analytics | Data used: Pages viewed, buttons clicked, referring site, campaign tags, random visitor and visit IDs | Legal basis: Consent. Off until you switch it on, and you can switch it off again at any time |
| Produce and send your free profile result | Data used: Your answers, name, work email, company, role, country and timing | Legal basis: Contract: taking the steps you asked for. Sending your answers to the AI model provider is part of producing the result |
| Send a resource you asked for | Data used: Name, work email, and company and role where a form asks for them | Legal basis: Contract: taking the steps you asked for |
| Newsletter and follow-up emails | Data used: Email address, name, the form you used, whether emails were sent | Legal basis: Consent. Every marketing email has an unsubscribe link |
| Arrange and hold a call | Data used: Name, email, time zone, what you tell us in the booking form | Legal basis: Contract: steps before a possible engagement. Otherwise legitimate interests in answering enquiries |
| See which page or campaign led to a form or booking | Data used: Landing page, referring site, campaign tags, random visit ID | Legal basis: Legitimate interests: understanding which of our pages and channels are useful |
| Scope, deliver and support a client engagement | Data used: Contact details, the signed authorisation, access you grant, messages, call recordings, reports | Legal basis: Contract |
| Invoices, payments, refunds and tax records | Data used: Name, business and billing details, payment records | Legal basis: Contract and legal obligation |
| Testimonials and case studies | Data used: Your words, and your name or company only if you agree | Legal basis: Consent, given in writing |
| Handle complaints and disputes, and meet legal requests | Data used: Whatever is relevant from the records above | Legal basis: Legitimate interests and legal obligation |
We do not use your data for advertising, and we do not build advertising profiles.
4. Cookies and similar storage
The site uses a small number of cookies and browser storage entries. Optional analytics load only after you allow them. We set no advertising cookies. The “Marketing” switch in the cookie settings is saved with your choice, but no marketing cookie is currently set whichever way you leave it.
To change your choice at any time, open the cookie settings here or from the “Cookie preferences” link in the footer of every page.
Switching analytics off stops further collection straight away. Cookies that an analytics tool has already set stay in your browser until they expire or you delete them. Optional analytics are off until you switch them on. The site does not respond separately to Do Not Track or Global Privacy Control signals.
4.1 Storage that does not depend on your analytics choice
| Name and type | Purpose | Lifetime | Waits for consent |
|---|---|---|---|
topiax_cookie_consentCookie and local storage | Purpose: Records the choice you made in the cookie settings, and when, so that we do not ask on every page. Set when you make a choice. | Lifetime: Cookie: 12 months. Local storage: until you clear your browser storage. | Waits for consent: No. Strictly necessary: it is how your choice is remembered. |
topiax_attribution_v1Session storage | Purpose: Holds the first page you landed on, the site that referred you, any campaign tags in the link you followed, and the random visit ID below. It stays in your browser unless you submit a form, when it is sent with the form. If you allow analytics, it is also included with analytics events. | Lifetime: Until you close the tab | Waits for consent: No. |
topiax_growth_sessionSession storage | Purpose: A random ID for this visit. It does not contain your name or email address. It is sent with a form you submit and, if you allow analytics, with analytics events. | Lifetime: Until you close the tab | Waits for consent: No. |
topiax_newsletter_dismissedLocal storage | Purpose: Records that you closed or completed the newsletter prompt, and when, so that it is not shown again for 7 days, or at all once you have subscribed. | Lifetime: Until you clear your browser storage | Waits for consent: No. |
gridkeep-onboarding-seenLocal storage | Purpose: Only on the GridKeep demonstration page. Remembers that you have already seen its introduction. | Lifetime: Until you clear your browser storage | Waits for consent: No. |
4.2 Set only after you allow analytics
| Name and type | Purpose | Lifetime | Waits for consent |
|---|---|---|---|
ph_<project>_posthog__ph_opt_in_out_<project>Cookie, local storage and session storage (PostHog) | Purpose: PostHog analytics. Holds a random visitor ID, visit and window IDs, your opt-in, and PostHog settings. Related entries that begin with ph_ are stored alongside it. | Lifetime: Cookie: 12 months. Local storage: until cleared. Session storage: until you close the tab. | Waits for consent: Yes. Analytics. |
_ga_ga_<property>Cookies (Google Analytics 4, where it is switched on) | Purpose: Google Analytics. Random IDs that tell one visitor and one visit from another. | Lifetime: Up to 2 years. Most browsers shorten this to about 13 months. | Waits for consent: Yes. Analytics. |
Vercel Web AnalyticsNo cookie or browser storage | Purpose: Counts page views and the site they came from. It loads only after you allow analytics, even though it stores nothing in your browser. | Lifetime: Not applicable | Waits for consent: Yes. Analytics. |
As currently configured, PostHog also measures page speed, records errors, and can record a replay of how a page was used. A replay shows the page as you saw it, so it can include text that was displayed on the page. PostHog masks what is typed into form fields by default, and we have not changed that setting.
4.3 Set by Cal.com on the booking page
The booking page loads the Cal.com calendar without waiting for a cookie choice, because the calendar cannot work without it. Cal.com sets these cookies on its own domain. We do not control them, and Cal.com may change them. This list reflects what we observed on 30 September 2026.
| Name and type | Purpose | Lifetime | Waits for consent |
|---|---|---|---|
__cf_bmCookie set by cal.com | Purpose: Bot protection used by Cal.com to keep its booking form available. | Lifetime: About 30 minutes | Waits for consent: No. It loads with the booking calendar. |
__Secure-next-auth.csrf-token__Secure-next-auth.callback-urlCookies set by cal.com | Purpose: Security tokens that Cal.com uses to protect its booking form. | Lifetime: Until you close the browser | Waits for consent: No. They load with the booking calendar. |
5. Who we share it with
We do not sell personal data. We share it only with the service providers that run the site and our work, each for the purpose shown.
| Provider | What it does for us | Based in |
|---|---|---|
| Vercel | What it does for us: Hosts the website and runs its server code, so it processes your IP address and the pages you request. Provides page-view analytics if you allow analytics. | Based in: United States |
| Neon | What it does for us: The database that stores form submissions, email schedules, booking records and our own analytics events. | Based in: United States |
| Resend | What it does for us: Sends your profile result, resources you request, follow-up emails, and notifications to us. | Based in: United States |
| beehiiv | What it does for us: Runs the newsletter. Holds your email address and the campaign source, and sends each issue. | Based in: United States |
| Cal.com | What it does for us: Runs the booking calendar and form, and sends us the details of each booking. | Based in: United States |
| Featherless AI | What it does for us: Runs the AI model that writes the follow-up questions and the written part of the free profile. It receives your answers, not your name, email address or company. | Based in: United States |
| PostHog | What it does for us: Page and funnel analytics, only if you allow analytics. | Based in: United States |
| What it does for us: Google Analytics 4, only if you allow analytics and only where we have switched it on. | Based in: United States and Ireland |
We may also share personal data with:
- the payment provider named on your invoice or payment link, to take a payment or make a refund;
- the email and messaging services we use to talk to you, including a shared Slack channel if you choose one for an engagement;
- our own customer records system, which receives the details you submit through the site’s forms;
- professional advisers such as an accountant or lawyer, where they need it to advise us;
- a court, regulator or authority, where the law requires it or where we need to establish or defend a legal claim;
- a successor, if the Topiax business is ever transferred. We would tell you before your data moved.
6. International transfers
We are based in Zimbabwe, and our service providers operate in the United States and other countries. Your data will therefore be processed outside the country where you live, in places whose data protection laws may differ from yours.
We use established providers that publish data processing terms. Where the law requires a safeguard for a transfer, we rely on the contractual commitments in those terms, such as standard data protection clauses, or on another route the law allows. You can ask us which safeguard applies to a particular provider.
7. How long we keep it
We keep personal data only for as long as the purpose needs, then delete it or make it anonymous.
| Data | How long we keep it |
|---|---|
| Browser storage and cookies | How long we keep it: As listed for each item in section 4. |
| Hashed IP address used to limit form abuse | How long we keep it: The count resets every hour. The entries are cleared at least once every 12 months. |
| Analytics events | How long we keep it: Up to 24 months. |
| Free profile answers and results, resource requests, and enquiries that do not lead to an engagement | How long we keep it: 24 months after our last contact with you, then deleted or made anonymous. |
| Newsletter and marketing emails | How long we keep it: Until you unsubscribe. After that we keep only your email address and the fact that you unsubscribed, so that we do not email you again. |
| Booking records | How long we keep it: 24 months after the call. |
| Reports, call recordings, and the working notes and evidence behind them | How long we keep it: 12 months after delivery, then deleted unless you ask us to delete them sooner or keep them longer. |
| Access you gave us (test accounts, logins, keys) and working copies of your code | How long we keep it: We ask you to remove our access when the engagement ends. Any login, key or working copy of code we still hold is deleted within 30 days of the end of the engagement. |
| Contracts, signed authorisations, invoices and payment records | How long we keep it: 6 years after the engagement ends, for tax records and in case of a legal claim. |
We may keep data for longer where the law requires it or while a dispute is open. Our providers keep their own server logs and backups for the periods set out in their own policies.
8. Your rights
Wherever you live, you can ask us to do any of the following, and we will act on it unless the law gives us a reason not to, which we will explain.
- Access: get a copy of the personal data we hold about you.
- Correction: have inaccurate or incomplete data put right.
- Deletion: have your data deleted.
- Objection: object to a use that relies on legitimate interests, and to any direct marketing.
- Restriction: ask us to pause a use of your data while a question is settled.
- Portability: receive data you gave us in a common electronic format.
- Withdraw consent: change your cookie choice or stop marketing emails at any time. This does not affect what was done before you withdrew.
8.1 How to make a request
Email cyprian@topiax.xyz and tell us what you would like. We may ask for enough information to confirm who you are. We reply within 30 days. If a request is complex and the law allows more time, we will tell you within those 30 days. Requests are free unless they are clearly unfounded or excessive.
To stop marketing emails, use the unsubscribe link in any marketing email or newsletter issue, or email us. Emails you asked for, such as a profile result, a requested resource or messages about an engagement, are not marketing and are sent once as needed.
8.2 If you are in the European Union, the EEA or the United Kingdom
The rights above are your rights under the GDPR and the UK GDPR. You also have the right to complain to the data protection authority in the country where you live or work. In the United Kingdom that is the Information Commissioner’s Office.
8.3 If you are in Zimbabwe
You have rights over your personal information under the Cyber and Data Protection Act [Chapter 12:07], including the rights above. You can complain to the Data Protection Authority, which is the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).
8.4 If you are in the United States, including California
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Whether or not the California Consumer Privacy Act applies to a business of our size, California residents can ask us what personal information we hold about them, ask us to correct or delete it, and will not be treated differently for doing so. Section 2 lists the categories we collect, section 3 the purposes, and section 5 who receives it.
Nothing in this policy limits any right you have under the data protection or consumer law of the country where you live.
9. Security
We take reasonable steps to protect personal data. The site is served over an encrypted connection. Form endpoints are rate limited. Unsubscribe links and incoming booking notifications are cryptographically signed. Service credentials are kept on the server and out of the pages your browser loads. Access to our records is limited to the people who need it to do the work.
No website or business can promise complete security, and we do not. If a breach of personal data is likely to put you at risk, we will tell you, and the relevant authority, as the law requires.
10. Children
Topiax provides services to businesses. The site is not directed at anyone under 16, and we do not knowingly collect their personal data. If you believe a child has sent us personal data, email us and we will delete it.
11. Automated decisions
The free profile is produced automatically. Your score is calculated by fixed rules from your answers, the written commentary is drafted by an AI model, and the suggested next step follows fixed rules. The result is directional guidance based only on what you told us. It is not a test of your app, and it produces no decision with legal or similarly significant effect. You can ask for a person to look at your result by replying to the result email.
We make no other automated decisions about you, and we do not use your data to train AI models.
12. Changes to this policy
We will update this policy when what we do with personal data changes, and the date at the top of the page will change with it. If a change materially affects data we already hold about you and we have your email address, we will tell you by email before it takes effect.
13. Contact
Cyprian Tinashe Aarons, trading as Topiax, Harare, Zimbabwe.
Email: cyprian@topiax.xyz
See also our Terms of service and our Refund and guarantee policy.