GDPR Article 28 addendum covering data processing roles, sub-processors, SCCs, breach notification, audit rights, content-free fleet telemetry, and the cryptographic audit chain.
Updated July 2026
Last updated: July 2026
This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement (the "Agreement") between Proxara, Inc. ("Processor" or "Proxara"), and the Customer identified in the applicable Order Form ("Controller" or "Customer").
This DPA applies only to Proxara-Managed Dedicated Account deployments where Proxara processes personal data on behalf of Customer. For Customer-Managed deployments, Proxara acts as a software licensor and does not process personal data; this DPA does not apply to those deployment models.
Terms not defined herein have the meanings set forth in the Agreement. In addition:
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation 2016/679) ("EU GDPR"), the UK General Data Protection Regulation as incorporated by the Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and any other applicable U.S. state privacy laws.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
"Personal Data" means any information relating to a Data Subject that is processed by the Service, including employee metadata, prompt content containing personal identifiers, Microsoft 365 content retrieved through Proxara Connect (mail, messages, calendar items, files, and tasks, which may contain client personal, financial, or tax information), stand-in mappings (the reversible pseudonymization data linking a protected reference to its stand-in), audit records, and classification results that relate to identifiable individuals.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission (Commission Implementing Decision (EU) 2021/914) or the UK International Data Transfer Addendum issued by the ICO, as applicable.
"Subprocessor" means any third party engaged by Proxara to process Personal Data on behalf of Customer.
Customer is the Controller of Personal Data. Proxara is the Processor acting on Customer's documented instructions.
Proxara processes Personal Data solely for the purpose of providing the Service as described in the Agreement and this DPA. The details of processing are set forth in Annex I.
Proxara shall process Personal Data only on documented instructions from Customer, including the instructions set forth in this DPA, the Agreement, and any subsequent written instructions. If Proxara is required by law to process Personal Data for any other purpose, Proxara shall inform Customer of that legal requirement before processing (unless prohibited by law).
Proxara shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Proxara shall ensure that personnel involved in the processing of Personal Data receive appropriate training regarding data protection obligations.
Proxara shall implement and maintain the technical and organizational security measures described in Annex II. These measures are designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing.
Proxara may update the security measures from time to time, provided that the updated measures do not materially decrease the overall level of protection.
Customer hereby provides general authorization for Proxara to engage the Subprocessors listed in Annex III (and at Subprocessor List).
Proxara shall notify Customer at least thirty (30) days in advance of any intended addition or replacement of a Subprocessor, providing the name of the Subprocessor, the processing activities, and the location of processing. Customer may object to the change within fifteen (15) days of receiving notice by providing written grounds for the objection. The parties shall negotiate in good faith to resolve any objection. If no resolution is reached, Customer may terminate the affected Order Form.
Proxara shall impose data protection obligations on each Subprocessor that are no less protective than the obligations set forth in this DPA. Proxara remains liable to Customer for the acts and omissions of its Subprocessors.
Proxara shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures to fulfill Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). There is no automated data-subject request portal; Proxara supports the Customer's (Controller's) DSR obligations through crypto-shredding, configurable short retention, automatic purge on the schedules described in Annex I, and, for Proxara Connect, deletion of the stand-in vault entries and workflow state relating to an individual.
If Proxara receives a request from a Data Subject directly, Proxara shall promptly redirect the Data Subject to Customer and notify Customer of the request, unless prohibited by law.
Proxara shall notify Customer of any confirmed Personal Data Breach without undue delay and in any event within 72 hours of becoming aware of the breach. For deployments subject to HIPAA, breach notification follows the applicable HIPAA standard (up to 60 days under 45 CFR 164.410); the 72-hour contractual commitment applies to all other deployments. The notification shall include:
Proxara shall cooperate with Customer and take reasonable measures to assist Customer in investigating, mitigating, and remediating the breach and in fulfilling Customer's notification obligations under Applicable Data Protection Law.
Proxara shall provide reasonable assistance to Customer in conducting data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Applicable Data Protection Law and taking into account the nature of the processing and the information available to Proxara.
Customer (or its designated independent third-party auditor, subject to reasonable confidentiality obligations) may audit Proxara's compliance with this DPA no more than once per twelve (12) month period, upon at least thirty (30) days' prior written notice and during normal business hours.
Proxara may satisfy audit requests by providing: (a) an independent third-party audit report, when available, not more than twelve (12) months old; (b) written responses to Customer's reasonable security questionnaire; or (c) evidence of relevant certifications.
Proxara shall not transfer Personal Data outside the country or region in which Customer's dedicated environment is deployed, except as necessary to provide the Service and as authorized by this DPA.
Where Personal Data is transferred from the UK or EEA to a country that has not been deemed to provide an adequate level of data protection, the parties agree to rely on the Standard Contractual Clauses (Module Two: Controller to Processor). The SCCs are hereby incorporated by reference. For UK transfers, the UK International Data Transfer Addendum (IDTA) shall apply.
If required by changes in law or guidance, Proxara shall implement supplementary technical or organizational measures to ensure the transferred Personal Data is afforded a level of protection essentially equivalent to that provided within the UK or EEA.
Upon termination or expiration of the Agreement, Proxara shall, at Customer's election:
Proxara shall complete the return or deletion within thirty (30) days of termination, unless applicable law requires longer retention. For Proxara Connect, deletion expressly covers retrieved content, workflow and view state, the stand-in vault (all reversible mappings), and stored Microsoft grant tokens, in addition to the categories in Annex I.
For Proxara-Managed deployments, Customer may elect to take ownership of the dedicated cloud account (which contains all Customer Data), in which case Proxara shall transfer administrative access and revoke its own access within thirty (30) days. If Customer does not elect to take ownership, Proxara shall delete all Customer Data and certify deletion in writing.
To the extent the CCPA/CPRA applies to Personal Data processed under this DPA:
This DPA shall remain in effect for the duration of the Agreement and for as long as Proxara processes Personal Data on behalf of Customer. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.
Questions regarding this DPA or data protection matters should be directed to support@proxara.ai. Security issues and vulnerability disclosures should be directed to security@proxara.ai.
Proxara, Inc.
28 Geary St. Suite 650 PMB 5328
San Francisco, CA 94108
Governing law: California, USA
| Item | Description |
|---|---|
| Subject Matter | Provision of AI data-protection, observability, and governance services |
| Duration | Duration of the Agreement |
| Nature and Purpose | For Proxara Connect: retrieval of Microsoft 365 content (mail, calendar, Teams messages, OneDrive/SharePoint files, tasks) from Customer's own tenant through Microsoft Graph, on Customer's instruction and under each signed-in employee's delegated permissions; resolution of employee identity and organizational context; policy enforcement inside Customer's dedicated environment; replacement of protected references with consistent stand-ins before material reaches Customer's AI assistant, with the reversible mappings held in a KMS-encrypted vault in Customer's environment; delivery of the clear result to the employee's embedded view; execution of approved actions with restoration of exact values only inside Customer's environment; signed, content-free records of each operation. For Endpoint Protection: network-layer interception of HTTPS traffic to covered AI services via the device proxy; TLS interception via a device-proxy root certificate authority whose X.509 Name Constraints exclude sign-in, banking, healthcare, government, and security-tooling domains in the certificate itself, with a connection decrypted only on positive evidence the destination is an AI service; real-time redaction of sensitive values and rehydration for the employee's screen; observation and governance of Model Context Protocol (MCP) tool activity (discovery, signed audit events, and allow/block enforcement); file content extraction for uploaded documents. For both: classification and semantic identification of protected references using Amazon Bedrock inside the customer's environment; cryptographically signed, hash-chained audit logging; compliance monitoring and notification routing to Customer's configured alert channels |
| Categories of Data Subjects | Customer's employees and contractors who are Authorized Users; and, predominantly for Proxara Connect, Customer's clients and other third parties whose personal data appears in retrieved mail, messages, files, and tasks or in submitted prompts |
| Categories of Personal Data | Employee identifiers (name, employee ID, device ID where applicable); device enrollment data (platform, hostname, agent version; Endpoint Protection only); prompt text that may contain names, account numbers, Social Security numbers, medical record numbers, and other identifiers; AI response text; file content uploaded to external AI tools (spreadsheets, PDFs, CSVs, documents); for Proxara Connect: retrieved Microsoft 365 content that may contain client personal, financial, and tax information, stand-in mappings (reversible pseudonymization data), encrypted Microsoft grant tokens, and embedded-view payloads; MCP tool-call records (tool name, server identifier, classification result, resolved egress mode); per-server classification records (egress mode, taxonomy, compliance officer authorization, optional DPA reference); classification results; cryptographically signed audit records |
| Sensitive Data | May include data subject to HIPAA (PHI), financial data subject to GLBA/FINRA, legal data subject to attorney-client privilege, and tax data subject to IRC 7216, depending on Customer's industry |
| Frequency of Transfer | Continuous during Authorized User interactions with covered AI tools |
| Retention Period | Proxara Connect: Proxara does not keep copies of Customer's mail and files; content is fetched when an employee asks, held encrypted in Customer's dedicated environment only as long as the work requires, and the clear result shown in the embedded view is held under a short time-to-live. Stand-in mappings persist in the KMS-encrypted vault in Customer's environment for consistency across the work and are deleted on offboarding, termination, or Customer instruction. Grant tokens persist encrypted until revocation, reconnection, or offboarding. The signed record of operations is content-free and persists as the compliance record. Endpoint Protection: all intercepted interactions (raw events): retained briefly at 7-day default, configurable; automatic purge on schedule. Flagged interactions (audit events): original prompt, redacted prompt, AI response, entity types, and redacted file text retained for compliance review; same 7-day default purge. Signed ingest envelopes (redacted content plus file-evidence hashes): purged from the live database on the same schedule; cryptographic proofs archived to immutable S3 (7 years). Aggregate metrics: 90-day default. Supervision audit log (compliance actions, status changes, reveals): metadata only, no message content; retained as the permanent supervision record. Redaction token maps: held on the device in an encrypted vault, session-scoped and short-lived; removed on agent uninstall; not stored server-side. Raw file bytes: never stored; only redacted text and a hash of the redacted bytes are retained. MCP tool-call raw payloads: never stored; only hashes and signatures. Crypto-shredding: retiring an identity-vault token destroys its AES-256-GCM key; the original value becomes unrecoverable. |
TLS 1.2 minimum, TLS 1.3 supported, on all customer-facing endpoints (ALB and CloudFront). AWS Certificate Manager issues and auto-renews certificates. HTTP redirects to HTTPS enforced. RDS enforces TLS for every connection (rds.force_ssl = 1). Amazon Bedrock inference runs within the customer's own AWS account over TLS. For Proxara Connect, Microsoft Graph retrieval runs over TLS from the customer's environment, and the embedded view's clear payload is delivered over a short-lived, authenticated direct HTTPS fetch with caching disallowed. For Endpoint Protection, the device proxy re-originates each AI connection over a current TLS stack; AI-bound traffic is intercepted via locally issued certificates signed by a root CA whose X.509 Name Constraints exclude sign-in, banking, healthcare, government, and security-tooling domains in the certificate itself; a connection is decrypted only on positive evidence the destination is an AI service, and all other traffic is tunnelled through without decryption.
AES-256 via AWS KMS customer master keys in the customer's dedicated account. Coverage includes: RDS (encrypted, private subnets, not publicly accessible, Multi-AZ in production, deletion-protected); S3 audit bucket (SSE-KMS plus COMPLIANCE-mode Object Lock, 7-year retention, immutable, versioned, insecure-transport denied, Proxara's role holds no DeleteObject right); S3 configuration and console buckets; ElastiCache (at-rest encryption, in-transit encryption, AUTH token); Secrets Manager; CloudWatch log groups. Compute runs as ECS Fargate tasks with no long-lived compute nodes holding Customer Data; secrets are injected from Secrets Manager. The customer owns the KMS keys and may revoke Proxara's use rights at any time; Proxara holds no key-delete or key-disable rights.
Proxara Connect server vault: stand-in mappings, workflow state, view payloads, and Microsoft grant tokens are encrypted at rest under the customer's KMS keys inside the customer's dedicated environment, scoped per tenant, per employee, and per unit of work.
On-device identity vault (Endpoint Protection): each original sensitive value is sealed under its own AES-256-GCM key (HKDF-derived). Retiring a token destroys the key and renders the original unrecoverable.
Each customer environment runs in a dedicated, single-tenant VPC with private subnets. Security groups restrict inbound and outbound traffic to required ports and services. The data tier (RDS, ElastiCache) is not publicly accessible.
Role-based access control for the governance console. API key authentication for the device service. Unique device identifiers for device enrollment. JWT token authentication with configurable expiry for console users. Proxara operational access to Proxara-Managed environments is restricted to authorized personnel. Administrative actions require MFA. AWS Service Control Policies (SCPs) enforce guardrails at the account level (GuardDuty, SecurityHub, and AWS Config are SCP-protected). Instance metadata service is locked to IMDSv2.
Every interaction record and every compliance action is canonicalized (RFC 8785 JCS), signed with Ed25519, and hash-chained per device (interaction leg) and per tenant (supervision leg). Records are batched into an RFC 6962 Merkle tree; the root is signed and anchored by default to the Sigstore Rekor public transparency log (receives only cryptographic hashes, never content or personal data). Evidence packs export as self-contained archives a regulator can verify offline with an open verifier, independently of Proxara. Audit proofs are archived to S3 COMPLIANCE Object Lock for 7 years, meeting the minimums of SEC 17a-4(f), FINRA 4511, and NYDFS 500.6.
Proxara stores only what is necessary for the compliance function. Raw file bytes are never stored. MCP tool-call raw payloads are never stored; only hashes and signatures. Numeric risk scores are stripped server-side and never sent to the console. Aggregate intelligence insights are firm-level and never attributed to a named individual. Non-flagged interactions are retained only for the short default window (7 days) before automatic purge; flagged interactions follow the same schedule unless explicitly preserved by the compliance team.
To operate and support each dedicated environment, Proxara receives a stream of content-free operational telemetry from the environment: schema-bound health, availability, and usage counters (for example, service status, protection-coverage counts, error-template counts, and resource utilization). Every telemetry payload is validated at egress against a fixed schema and a deny-pattern filter, carries no free text, and contains no customer content and no personal data. The telemetry identifies the environment, not any individual. Customer can review every item Proxara receives from the environment in the Telemetry Ledger inside the console.
Service availability targets are set out in the Service Level Agreement. Deployments include multi-AZ database configuration, automated health checks, and monitoring. The device agent fails open: if the Proxara CA is not trusted, traffic passes through to the real origin without interception.
Documented incident response procedures are maintained. Breach notification is provided within 72 hours (or up to 60 days for HIPAA-covered deployments per 45 CFR 164.410).
Proxara runs internal adversarial security reviews and applies least-privilege IAM. Independent third-party penetration testing is planned.
All personnel with access to Customer environments are subject to confidentiality obligations.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (compute on ECS Fargate, database, cache, object storage, key management, Secrets Manager, monitoring); AI classification and semantic identification of protected references (Amazon Bedrock running Anthropic Claude models inside AWS); document text extraction (Amazon Textract) | Customer-selected AWS region (default: US regions); Bedrock uses a managed cross-region US inference profile |
| Google LLC (Google Workspace) | Outbound transactional and notification email (invitations, compliance digests, PDF leave-behinds) via smtp.gmail.com; receives recipient addresses and email content | United States |
| Sigstore Rekor (on by default) | Public transparency log for audit-chain anchoring. Receives only cryptographic hashes (Merkle batch roots) and signatures. No Customer Data or personal data is transmitted. Anchoring runs by default and continues locally if the log is unreachable. | Public service operated under the Linux Foundation |
| Exa | Research on unrecognized MCP server capabilities (Endpoint Protection). Receives server or software metadata and a generated query. Never receives employee content or personal data. | United States |
The Customer's own providers in the Proxara Connect path. Two providers process Customer Data in the Proxara Connect path under the Customer's own agreements and are not Proxara Subprocessors: the Customer's AI assistant provider (for example, Anthropic, under the Customer's own Claude workspace agreement), which receives the policy-approved material with protected references replaced by stand-ins; and Microsoft, the Customer's own Microsoft 365 provider, from whose tenant content is retrieved on the Customer's instruction under each employee's own delegated permissions. The Subprocessor List describes both.
Customer-connected integrations (optional, off by default). The following services are connected at the Customer's election by providing its own account credentials. The data flows are initiated by the Customer's configuration, and these services may be considered the Customer's own processors for that data:
| Service | Purpose |
|---|---|
| Slack (Slack Technologies) | Compliance notifications to the firm's Slack workspace |
| Microsoft (Teams Bot Framework and Microsoft Graph) | Compliance notifications to the firm's Teams workspace; read-only calendar metadata for board-meeting context. This notification channel is separate from Proxara Connect's retrieval, described above. The Endpoint Protection device agent does not intercept Microsoft 365, Copilot, Teams, or Outlook network traffic; it passes through the network layer unmodified. |
| Google Calendar | Read-only event metadata for board-meeting context |
For the current subprocessor list, see Subprocessor List.