Legal

Data Processing

Last updated 29 September 2026

This page sets out how Praxas AI processes personal data for customers. It forms part of each customer's agreement with us. A signed Data Processing Agreement is available on request and takes priority over this page.

1. Roles

The customer is the Data Fiduciary (controller) for data it connects to Praxas. Praxas AI is the Data Processor and processes that data only to provide the service. Terms follow India's Digital Personal Data Protection Act, 2023, and GDPR terms apply where GDPR does.

2. What we process

CategoryExamplesPeople concerned
User accountsName, work email, role, unit, sign-in recordsCustomer staff
ERP recordsPurchase orders, receipts, issues, stock, supplier masterSupplier contacts, staff named in records
Supplier emailMessages and attachments in connected purchase mailboxesSupplier contacts, customer staff
Activity recordsQuestions, drafts, approvals, rejectionsCustomer staff

Processing continues for the term of the agreement and stops when it ends, apart from any return or deletion work.

3. Instructions

We process customer data only on the customer's documented instructions: the agreement, the settings the customer's admin chooses, and written requests. If we think an instruction breaks the law, we will say so and wait before acting on it.

4. AI processing

Training Praxas's own models

Separately from processing for the customer, Praxas trains its own models on de-identified business figures from the platform, as the customer agrees in our Terms. This data contains no personal data, so it is outside the processing described on this page. It is handled as follows.

5. Security measures

6. People with access

Only Praxas staff who need access to run or support the service can reach customer data. They are bound by confidentiality, and their access is recorded.

7. Sub-processors

We use these kinds of sub-processors. We will give customers at least 30 days' notice before adding or replacing one, so they can object.

ServicePurposeData
Amazon Web ServicesHosting customer servers and backupsAll platform data, encrypted
OpenRouter (zero-retention providers only)AI model gatewayMasked text of emails, documents and questions
AnthropicAI models (Claude)Masked text of emails, documents and questions

8. Location and transfers

For customers in India, platform data is stored in India. Masked content sent to AI models may be processed outside India. We protect such transfers by contract and follow any restrictions the Government of India notifies.

9. Breaches

If we become aware of a personal data breach affecting customer data, we will tell the customer without undue delay, and within 72 hours at the latest. We will explain what happened, what data is affected and what we are doing about it, and help the customer meet its own reporting duties.

10. Helping you meet your duties

We will help customers answer requests from individuals, such as access, correction and deletion, and support any data protection assessments, taking into account what we can reasonably do as processor.

11. Audits

We will give customers the information they reasonably need to confirm we meet these terms. On reasonable written notice, and no more than once a year unless there has been a breach, a customer may audit our compliance, at its own cost and under confidentiality.

12. Return and deletion

When the agreement ends, the customer may export its data. We then delete customer data from the customer's server and backups within 30 days, unless the law requires us to keep it. We confirm deletion in writing on request.

Contact

Praxas AI Private Limited
H34/1, DLF Phase 1, Gurugram, Haryana 122001, India
Email: admin@praxas.ai
Grievance Officer: write to the same address with "Grievance" in the subject line. We acknowledge within 48 hours and resolve within 30 days.