Privacy Policy
This policy explains what personal data Praxas AI collects, why, and the choices you have. We wrote it in plain language. We follow India's Digital Personal Data Protection Act, 2023 and are designed to meet GDPR expectations for customers outside India.
1. Who we are and what this covers
Praxas AI Private Limited ("Praxas", "we", "us"), with its registered office at H34/1, DLF Phase 1, Gurugram, Haryana 122001, builds a multi-agent system that helps manufacturers see their stock, plan demand and manage suppliers. This policy covers two situations.
- This website. When you visit praxas.ai or send us a demo request, we decide how your data is used. For this data we are the Data Fiduciary (controller).
- The Praxas platform. When a company uses Praxas, it connects its ERP and purchase mailboxes. That company decides what data is processed and why. For that data we act as a Data Processor on the company's instructions, under our Data Processing terms and the contract with that company.
2. What we collect
From the website
- Demo requests: your name, company, work email, phone number (optional), role, the ERP you use and anything you write in the message box. The form is sent from our own web hosting straight to our email inbox.
- Emails you send us and our replies.
- Basic technical data that any web server receives: IP address, browser type and pages requested. We do not use advertising trackers or sell this data.
On the platform, for our customers
- Account data: names, work emails, roles and units of the people the customer invites, and their two-factor sign-in setup.
- Business records read from the customer's ERP: items, stock, purchase orders, goods receipts, issues, production and supplier records. These are mainly business data, but they can include names and contact details of employees and supplier contacts.
- Supplier email from mailboxes the customer connects, including attachments such as quotes and invoices.
- Activity records: what each user viewed, asked, drafted, approved or rejected, kept in a permanent audit record.
3. How we use it
| Purpose | Data used | Basis |
|---|---|---|
| Reply to a demo request and arrange a call | Demo request details, emails | Your consent, given when you submit the form |
| Run the platform for a customer: rebuild numbers, answer questions, draft supplier messages | Account data, ERP records, supplier email | The customer's instructions under contract |
| Keep the platform secure and working: sign-in, health checks, backups, audit record | Account and activity data, technical logs | Legitimate use to provide a secure service |
| Improve forecasts and agents for that customer | That customer's records, on that customer's server | The customer's instructions under contract |
| Train Praxas's own models to give every customer a better service | De-identified dashboard figures only. No personal data. | The customer's agreement to our Terms |
| Meet legal duties | Only what the law requires | Legal obligation |
We do not sell personal data, and we never use personal data to train models. We do use de-identified business figures, the kind shown on the dashboard, to train Praxas's own models, as explained in section 4.
4. AI and your information
- Business numbers on the dashboard are calculated by fixed formulas, not by AI.
- AI models are used to read emails and documents, answer questions and prepare drafts. Requests go through a private gateway to model providers that do not keep or train on the content we send.
- Bank account numbers, tax identifiers (such as PAN) and phone numbers are masked before content is sent to an AI model.
- AI output is a draft. A person reviews and approves before anything is sent to a supplier. Praxas does not make automated decisions that have legal or similar effects on individuals.
Training our own models
Praxas is a self-improving system. To make it better for every customer, we train our own models on de-identified business data from the platform.
- What we use: the kind of business figures shown on the dashboard, such as stock levels, usage, lead times, order timings, forecast results and how accurate they were.
- What we remove first: names, email addresses, phone numbers, bank and tax details, the text of emails and documents, and anything that identifies your company, your units, your suppliers or your customers.
- What we never use: personal data of any kind.
- How it is kept: only on systems Praxas controls, never sold, never shared with other companies, and never used by an AI provider to train its own models.
- Why: to make forecasts and agents more accurate for every customer. A model trained this way never shows one customer's figures to another.
5. Who we share it with
We share personal data only with service providers that help us run Praxas, under contracts that limit their use of it:
- Cloud hosting for customer servers and backups.
- AI model providers, reached through our private gateway, with sensitive fields masked and no retention of content.
- Email and web hosting providers we use to receive demo requests and reply to you.
The current list of sub-processors is in our Data Processing terms. We may also disclose data if the law requires it, or to protect the rights and safety of our users.
6. Where it is stored
Each customer's platform data lives on a server dedicated to that customer, with no database shared between companies. For customers in India we host in India. Some service providers, such as AI model providers, may process masked content in other countries. When that happens we use contractual safeguards and follow any transfer restrictions notified under Indian law.
7. How long we keep it
- Demo requests: up to 24 months after our last contact, unless you become a customer or ask us to delete them sooner.
- Platform data: for as long as the customer's contract runs. At the end, we return or delete it as the contract says, normally within 30 days, except where the law requires us to keep it.
- Audit records: kept for the period agreed with the customer, because their purpose is to show what happened.
8. How we protect it
- Read-only access to customer ERPs. Praxas never writes to an ERP and never makes payments.
- One private server per customer, nightly backups kept on that server, and a permanent, tamper-evident audit record.
- Two-factor sign-in and role-based access, so people see only what their role allows.
- Changes to a server are signed and applied only after a person approves them.
No system is perfectly secure. If a breach affects your personal data, we will inform you and the Data Protection Board of India as the law requires, and our customers without undue delay.
9. Your rights
You can ask us to:
- tell you what personal data we hold about you and how we use it;
- correct, complete or update it;
- delete it, or withdraw consent you gave;
- name someone to exercise these rights for you if you cannot;
- explain how to raise a grievance.
If your data came to us through a customer's systems, such as their ERP or mailbox, we will pass your request to that customer and help them answer it. Write to admin@praxas.ai. If you are not satisfied with our answer, you may complain to the Data Protection Board of India, or to your local data protection authority if you are outside India.
10. Cookies and local storage
This website does not use advertising or tracking cookies. It saves one setting in your browser, your light or dark theme choice, so the site remembers it. The site loads fonts from Google Fonts and a 3D graphics library from jsDelivr. Those services receive your IP address when your browser fetches the files. The platform uses cookies only to keep you signed in securely.
11. Children
Praxas is a business service. It is not meant for anyone under 18, and we do not knowingly collect their data.
12. Changes
We will update this page when our practices change and change the date at the top. If a change is significant, we will tell customers directly before it takes effect.
13. Contact and grievances
H34/1, DLF Phase 1, Gurugram, Haryana 122001, India
Email:
admin@praxas.aiGrievance Officer: write to the same address with "Grievance" in the subject line. We acknowledge within 48 hours and resolve within 30 days.