Data Processing
This page sets out how Praxas AI processes personal data for customers. It forms part of each customer's agreement with us. A signed Data Processing Agreement is available on request and takes priority over this page.
1. Roles
The customer is the Data Fiduciary (controller) for data it connects to Praxas. Praxas AI is the Data Processor and processes that data only to provide the service. Terms follow India's Digital Personal Data Protection Act, 2023, and GDPR terms apply where GDPR does.
2. What we process
| Category | Examples | People concerned |
|---|---|---|
| User accounts | Name, work email, role, unit, sign-in records | Customer staff |
| ERP records | Purchase orders, receipts, issues, stock, supplier master | Supplier contacts, staff named in records |
| Supplier email | Messages and attachments in connected purchase mailboxes | Supplier contacts, customer staff |
| Activity records | Questions, drafts, approvals, rejections | Customer staff |
Processing continues for the term of the agreement and stops when it ends, apart from any return or deletion work.
3. Instructions
We process customer data only on the customer's documented instructions: the agreement, the settings the customer's admin chooses, and written requests. If we think an instruction breaks the law, we will say so and wait before acting on it.
4. AI processing
- Content sent to AI models passes through our private gateway to providers that do not retain or train on it.
- Bank account numbers, tax identifiers and phone numbers are masked first.
- AI output is a draft. The customer's people approve every outgoing message. Praxas never writes to the ERP or makes payments.
- Personal data is never used to train models.
Training Praxas's own models
Separately from processing for the customer, Praxas trains its own models on de-identified business figures from the platform, as the customer agrees in our Terms. This data contains no personal data, so it is outside the processing described on this page. It is handled as follows.
- What we use: the kind of business figures shown on the dashboard, such as stock levels, usage, lead times, order timings, forecast results and how accurate they were.
- What we remove first: names, email addresses, phone numbers, bank and tax details, the text of emails and documents, and anything that identifies your company, your units, your suppliers or your customers.
- What we never use: personal data of any kind.
- How it is kept: only on systems Praxas controls, never sold, never shared with other companies, and never used by an AI provider to train its own models.
- Why: to make forecasts and agents more accurate for every customer. A model trained this way never shows one customer's figures to another.
5. Security measures
- A dedicated server for each customer, with no database shared between customers.
- Read-only connections to ERP systems and mailboxes.
- Two-factor sign-in and role-based access, with approval separated from request.
- Access keys kept on the customer's server only, signed updates that a person approves, and automatic health checks every two minutes.
- Nightly backups kept on the customer's server.
- An append-only, hash-chained audit record of every action and approval.
6. People with access
Only Praxas staff who need access to run or support the service can reach customer data. They are bound by confidentiality, and their access is recorded.
7. Sub-processors
We use these kinds of sub-processors. We will give customers at least 30 days' notice before adding or replacing one, so they can object.
| Service | Purpose | Data |
|---|---|---|
| Amazon Web Services | Hosting customer servers and backups | All platform data, encrypted |
| OpenRouter (zero-retention providers only) | AI model gateway | Masked text of emails, documents and questions |
| Anthropic | AI models (Claude) | Masked text of emails, documents and questions |
8. Location and transfers
For customers in India, platform data is stored in India. Masked content sent to AI models may be processed outside India. We protect such transfers by contract and follow any restrictions the Government of India notifies.
9. Breaches
If we become aware of a personal data breach affecting customer data, we will tell the customer without undue delay, and within 72 hours at the latest. We will explain what happened, what data is affected and what we are doing about it, and help the customer meet its own reporting duties.
10. Helping you meet your duties
We will help customers answer requests from individuals, such as access, correction and deletion, and support any data protection assessments, taking into account what we can reasonably do as processor.
11. Audits
We will give customers the information they reasonably need to confirm we meet these terms. On reasonable written notice, and no more than once a year unless there has been a breach, a customer may audit our compliance, at its own cost and under confidentiality.
12. Return and deletion
When the agreement ends, the customer may export its data. We then delete customer data from the customer's server and backups within 30 days, unless the law requires us to keep it. We confirm deletion in writing on request.
Contact
H34/1, DLF Phase 1, Gurugram, Haryana 122001, India
Email:
admin@praxas.aiGrievance Officer: write to the same address with "Grievance" in the subject line. We acknowledge within 48 hours and resolve within 30 days.