1. Scope and our role
This policy covers the Praxa platform operated by Praxa AI, Inc. It describes how we handle three categories of data: information you give us directly (account and billing details), artifacts Praxa observes in systems you connect, and operational data the platform generates (run records and audit logs).
For your account and billing data we act as a controller. For the personal data inside the artifacts we observe on your behalf we act as a processor, and the Data Processing Addendum governs that processing; you (the customer) are the controller and are responsible for the lawful basis and notices owed to the individuals whose work is observed.
2. Data we handle
Account and billing
- Name, work email, company, and workspace role for each user.
- Billing contact and subscription records. Card data is handled by our payment processor (Stripe); Praxa does not store full card numbers.
Observed artifacts
- Emails, messages, tickets, documents, calendar events — and, for technical roles, commits, pull requests, and issues — and similar artifacts from the systems you connect, scoped to the role you ask Praxa to observe.
- Derived material: the distilled job specification, generated Agent manifest, and evaluation suite for your workspace.
Model provider keys (BYOK)
- Your Anthropic, AWS Bedrock, or Google Vertex credentials, stored encrypted and used only to execute your Agents.
Operational data
- Run records and the audit log for each Agent action: input, reasoning, alternatives considered, confidence, and output.
- Standard service logs and metrics needed to operate and secure the platform.
3. How we use data
- To generate, evaluate, run, and audit your Agents.
- To provide the dashboard, including per-Agent transparency metrics.
- To bill your subscription, secure the platform, prevent abuse, and provide support.
We do not sell your data and do not "share" it for cross-context behavioral advertising. We do not use your observed artifacts, prompts, or outputs to train foundation models. With BYOK, prompts and completions are processed by your own model provider account, not stored by Praxa beyond the audit-log fields you choose to retain.
4. Legal bases (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract. To provide the platform and account you asked for, and to bill it.
- Legitimate interests. To secure the platform, prevent abuse and fraud, operate and improve the service, and keep audit records — balanced against your rights.
- Legal obligation. To meet tax, accounting, and other legal requirements.
- Consent. Where we ask for it (for example, certain communications); you may withdraw consent at any time.
For personal data inside observed artifacts, the customer as controller determines and is responsible for the legal basis; Praxa processes it on the customer's instructions under the DPA.
5. Language-model data flow
Because the platform is BYOK, every model call runs against your provider credentials. The content of prompts and completions lands in your provider account under your provider's terms. Praxa retains only the structured audit-log fields described above so you can replay a decision. We never act as a token reseller and do not retain a separate copy of raw model traffic. If you enable Praxa-managed compute, model access is provisioned on your behalf and the underlying provider's terms still apply.
6. Where data lives
- Standard plan. Shared multi-tenant Postgres with workspace-isolated rows, and shared object storage with workspace-isolated keys, in our Cloudflare and AWS
us-east-1deployment. Encrypted at rest. - Enterprise plan. A dedicated tenant in your region of choice, with infrastructure-level isolation (separate database, KMS key, and object store). Optional self-host in your own AWS account.
Tenant isolation is enforced in code: every row, object key, and memory fact carries a workspace_id, and cross-tenant reads are blocked at the query layer. BYOK keys are encrypted with a workspace-scoped key (AES-256-GCM), itself wrapped by a tenant-scoped KMS data key.
7. Retention and deletion
- Audit and run logs are retained for 90 days by default on the standard plan, and for a contracted window on Enterprise.
- Customer-initiated erasure runs a hard delete within 7 days.
- On termination we stop processing and delete workspace data on the same timelines, except where retention is required by law.
8. International data transfers
Standard-plan data is processed in the United States. If you are in the EEA, the UK, or Switzerland, transferring your data to the US means it leaves your region. Where we transfer personal data across borders, we rely on a lawful transfer mechanism — including the European Commission's Standard Contractual Clauses (and the UK Addendum) where applicable, which are incorporated into the DPA when required. Enterprise customers may select a dedicated tenant region (US, EU, or AU) to keep data in-region.
9. Sub-processors and sharing
We share data only with infrastructure sub-processors needed to run the platform — for example our cloud, database, and payment providers — under contracts that require appropriate safeguards. We maintain a current sub-processor list available on request and, for Enterprise customers, provide advance notice of material changes as set out in the DPA. We disclose data to authorities only where legally required, and will tell you first where we are lawfully able to.
10. Cookies
We use a small number of strictly necessary cookies to keep you signed in and to secure the service (for example, the session cookie and rate-limiting state). We do not use advertising cookies or sell cookie data. Any analytics we use are privacy-preserving and used only to operate and improve the product; where local law requires consent for non-essential cookies, we ask for it.
11. Automated decision-making
Agents produce outputs and can take actions you authorize, but they operate under the human oversight and approval controls you configure — they are not designed to make solely automated decisions that produce legal or similarly significant effects on an individual without a human in the loop. Where you configure an Agent to act automatically on personal data, you are the controller for that decision and responsible for the safeguards and notices the law requires.
12. Your rights
Depending on where you live, you may have rights over your personal data. Workspace administrators can export and erase workspace data directly from the platform; for anything else, contact us and we will respond within the timeframes the law requires. Where Praxa acts as a processor, we route individual requests to the relevant customer as controller.
- EEA/UK (GDPR). Access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent — plus the right to lodge a complaint with your supervisory authority.
- California (CCPA/CPRA). The right to know, access, delete, and correct your personal information, and to opt out of sale or sharing — we do not sell or share personal information — with no discrimination for exercising your rights. Praxa acts as a service provider for customer personal data and does not retain, use, or disclose it for any purpose other than providing the service.
13. Children
The platform is a business product not directed to children. We do not knowingly collect personal data from anyone under 16; if you believe a child's data has reached us, contact us and we will delete it.
14. Security
Security controls — bot-user authentication, encryption, tenant isolation, append-only audit logging, and runtime scope enforcement — are described on the Security page. Our SOC 2 Type II program is on the roadmap for late 2026; we will update this policy as that status changes rather than claim it early.
15. Changes
We may update this policy. Material changes are announced to workspace administrators with reasonable notice and reflected in the "last updated" date above.
16. Contact
Privacy questions, data-subject requests, security questions, and questionnaires all reach us through our contact form. If you are in the EEA or UK and need an EU/UK representative or our data-protection contact, ask through the same form and we will provide the current details.