Proxaradocs
Trust Center/Compliance

Proxara Connect DPIA

Article 35 assessment for Proxara Connect: retrieval of Microsoft 365 content under delegated permissions, stand-in processing, the server vault, host-visibility and re-identification risks, and the mitigations behind each.

Updated July 2026

Proxara Connect DPIA

Last updated: July 2026

Controller / Processor: Proxara, Inc.

Assessment Date: July 2026

Assessor: Jex Pearce, Founder

Review Cycle: Annual, or upon material change to processing activities

This Data Protection Impact Assessment ("DPIA") is prepared in accordance with Article 35 of the UK GDPR and EU GDPR. It assesses one processing activity: Proxara Connect, the hosted connector that joins a customer's AI assistant to the customer's Microsoft 365 tenant through the customer's dedicated environment. The Endpoint Protection device service is a separate processing activity with its own assessment, the Data Protection Impact Assessment.


1. Description of Processing

1.1 What Proxara Connect Does

An employee asks the firm's AI assistant (Claude, in the firm's own workspace) for work that lives in the firm's Microsoft 365: mail, calendar, Teams messages, OneDrive and SharePoint files, and tasks. The assistant calls the firm's Proxara connector. Inside the firm's dedicated environment, Proxara retrieves what that employee's own delegated permissions allow, resolves the employee's identity and the organizational context, and applies the firm's policy. Protected references (client names, identifiers, account references, and similar) are replaced with consistent stand-ins before anything reaches the model. The employee reads the clear result in a Proxara view inside the conversation, delivered over a separate authenticated channel. Where the firm enables action features, an approved draft or task is restored to its exact values only inside the firm's environment, immediately before the firm's own Microsoft tenant receives it. Every operation lands on a signed, content-free record.

Firm policy selects one of three outcomes per class of work: Protected Reasoning (the default; the substance of the work reaches the model with stand-ins in place of protected references), Private Analysis (substantive facts stay inside the firm's environment; the model receives only a safe status while the full result is delivered to the employee's view), or Blocked (nothing is retrieved, and the employee sees the plain reason).

Nothing is installed on any device. Deployment is one tenant-wide administrator consent to the verified Proxara Connect application (delegated, read-only permissions) plus the addition of the firm's connector to the firm's Claude workspace.

1.2 Deployment Model

Proxara provisions and manages a dedicated, single-tenant AWS environment for each customer. There is no shared multi-tenant environment holding customer data; the customer owns the encryption keys and all data. This DPIA addresses the Proxara-Managed deployment model, where Proxara acts as a data processor on the customer's documented instructions.

1.3 Data Subjects

  • The customer's clients and their related parties, the dominant category: the individuals whose personal, financial, and tax information appears in the firm's mail, files, messages, and tasks.
  • The customer's employees and contractors who use the connector: their identity, their requests, and their work content.
  • Other third parties appearing in retrieved content (counterparties, vendors, referred contacts).

1.4 Categories of Personal Data

Data CategorySourceHandling
Retrieved Microsoft 365 content (mail, messages, calendar items, file content, tasks), which may contain client names, financial details, identification numbers, and tax return informationThe customer's own tenant, retrieved under the signed-in employee's delegated permissionsFetched when asked; processed inside the customer's environment; held encrypted only as long as the work requires
Stand-in mappings (protected reference to stand-in)Generated by the policy engineReversible pseudonymization data; held in a KMS-encrypted vault in the customer's environment; never transmitted to the model, the conversation, or logs
Employee identity and grant records (Entra identity, granted permissions, connection state)The customer's directory and each employee's sign-inHeld in the customer's environment; grant tokens encrypted
View payloads (the clear result shown to the employee)Generated per requestDelivered over a short-lived authenticated direct fetch; held encrypted under a short time-to-live
The signed operation record (which sources, what decisions, what protection counts, what outcome)Generated per operationContent-free: no retrieved content, no stand-in mappings, no tokens

1.5 Special Category Data

Proxara Connect does not seek special category data (Article 9), but retrieved mailboxes and files can contain anything a client has ever sent the firm, including health information or other special category data. The purpose of the processing is protective: to keep such material from reaching an external model in identifiable form. Firm policy can route designated classes of information to Private Analysis or Blocked, so material of a chosen sensitivity never leaves the environment in any form.

1.6 Recipients of Personal Data

RecipientData ReceivedBasis
AWS (Amazon Web Services)All processing runs inside the customer's dedicated AWS environment. Amazon Bedrock performs classification and the semantic identification of protected references in-account and does not store inputs or outputs.Sub-processor (see Sub-processor List)
The customer's AI assistant provider (for example, Anthropic, under the customer's own Claude workspace agreement)The policy-approved substance of the work with protected references replaced by stand-ins; in Private Analysis, only a safe statusThe customer's own provider, not a Proxara sub-processor
Microsoft (the customer's own Microsoft 365 tenant)The source of retrieved content and the destination of approved actions, under the customer's existing Microsoft agreementThe customer's own provider, not a Proxara sub-processor
Google LLC (Google Workspace)Outbound notification email: recipient addresses and message contentSub-processor
Sigstore Rekor (public transparency log, on by default)32-byte Merkle batch root hashes only; no personal dataPublic service under the Linux Foundation

Proxara does not sell, share, or disclose personal data to any other third party.


2. Necessity and Proportionality

2.1 Lawful Basis

The customer (controller) determines the lawful basis. Typical bases include legitimate interest (Article 6(1)(f)): enabling productive AI use while protecting client confidentiality and meeting professional obligations; and, for regulated firms, legal obligation (Article 6(1)(c)) where rules require control and supervision of how client information is handled. Proxara processes personal data solely on the customer's documented instructions under the Data Processing Addendum.

2.2 Why This Processing Is Necessary

Firms are connecting AI assistants to their internal systems because the assistants are dramatically more useful with the firm's real context. The direct route, a native connector inside the AI host, hands retrieved client information to the model as-is, ungoverned and unrecorded. Proxara Connect exists so the connection can be made with the firm's policy in the path: the model gets the working substance it needs, and the identifying details stay home.

2.3 Why This Processing Is Proportionate

  • Access is bounded by existing permissions. All retrieval is delegated: the connector can only ever see what the signed-in employee can already see. The consent widens no one's access.
  • Retrieval is on request, not bulk. Content is fetched when an employee asks for work that needs it. Proxara does not keep copies of the firm's mail and files, does not build a standing copy of the tenant, and holds working state only as long as the work requires.
  • Minimization before the model. Protected references are replaced with stand-ins before anything reaches the model, and policy can keep whole classes of substance inside the environment (Private Analysis) or refuse the work (Blocked).
  • The record is content-free. Supervision is evidenced through decisions, counts, and outcomes, not retained content.

Less intrusive alternatives considered:

AlternativeWhy Insufficient
Policy-only approach (no technical control on the connected path)Unenforceable; the native connector delivers identifiable client data directly to the model
Blocking AI-to-system connections entirelyPushes usage to manual copy-paste of client data into chats, which is less visible and less protected
Redaction of typed prompts only (device-side)Does not govern the connected path at all; retrieval through a host connector never crosses the device

3. Risk Assessment

RiskLikelihoodImpactOverall RiskMitigation Reference
R1: Unauthorized access to retrieved content or workflow state held in the customer's environmentLowHighMediumM1, M8, M9
R2: Exposure of the stand-in vault, enabling re-identification of protected referencesVery LowHighLowM1, M4
R3: Re-identification through unique substance. A fact whose substance is sufficiently unique identifies its subject even with names replacedMediumMediumMediumM3
R4: Host-vendor visibility. The AI provider retains the conversation (about stand-ins); the embedded view renders inside software the host vendor controlsMediumMediumMediumM3, M5
R5: Prompt injection in retrieved sources. Instructions planted in an email or document attempt to steer the assistant or trigger an actionMediumHighMediumM7
R6: Over-broad internal permissions. An employee's existing Microsoft permissions exceed their actual need, so the connector's ceiling is too highMediumMediumMediumM2, M9
R7: Microsoft grant token theftVery LowHighLowM6
R8: Cross-tenant confusion. A request, token, or reference from one customer's environment acts against another'sVery LowHighLowM6
R9: Employee awareness gap. Employees do not understand what happens to their work content when they use the connectorLowLowLowM11
R10: Client awareness gap. The firm's clients are not told, where required, that the firm uses AI tooling on their informationMediumMediumMediumM11
R11: Erroneous action. A drafted email or task lands on the wrong recipient or with wrong contentLowMediumLowM7, M10
R12: Sub-processor breach (AWS infrastructure)Very LowHighLowM1, M12

Risk ratings use the same scale as the Endpoint Protection DPIA: Very Low (negligible), Low (adequately controlled; monitor), Medium (requires active mitigation), High (unacceptable without additional controls).


4. Mitigation Measures

M1: Dedicated Environment and Customer-Owned Keys

All retrieval, policy, the vault, and the record run in a dedicated, single-tenant AWS environment provisioned for the customer, encrypted under KMS keys the customer owns. No shared multi-tenant plane holds customer data. Proxara's operational access is IAM-scoped, MFA-gated, and logged.

M2: Delegated, Read-Only Access

Every Microsoft permission is delegated and read-only; the connector can only ever see what the signed-in employee can already see. Consent is granted tenant-wide once by the customer's administrator, is inspectable and revocable unilaterally in the customer's own Entra admin center, and grants no application-wide mailbox access. Write capabilities, where the customer enables action features, are a separate explicit permission expansion with a fresh administrator consent.

M3: Policy Modes for Substance, Not Just Identifiers

Because a sufficiently unique fact can identify its subject even with names replaced, stand-in replacement is not treated as sufficient on its own. Firm policy can route designated classes of work to Private Analysis, in which substantive facts stay inside the customer's environment and the model receives only a safe status, or to Blocked, in which nothing is retrieved. This is the assessment's primary answer to R3 and part of its answer to R4: material the firm designates never reaches the host in any form.

M4: The Vault Namespace

Stand-in mappings are held in a KMS-encrypted server vault inside the customer's environment, scoped per customer, per employee, and per unit of work. The same client resolves consistently within a piece of work; a stand-in copied into an unrelated context resolves to nothing; unknown, expired, or cross-context stand-ins fail closed. Restoration of an original value occurs only inside the customer's environment at an approved action. Mappings appear in no log, no record, and no model-visible response.

M5: Channel Separation

The model-visible channel carries only policy-approved material and opaque references. The clear result is delivered to the employee's embedded view over a separate, short-lived, authenticated direct fetch from the customer's environment, marked never-to-cache. The residual risk is stated honestly rather than engineered away: the view still renders inside an application the host vendor controls, and a firm that cannot accept that residual for a class of data can require Private Analysis for it.

M6: Tenant Binding and Token Custody

Each customer's activation is bound to its exact Microsoft tenant, and every request revalidates the employee, tenant, grant, and policy. Grant tokens are encrypted in the customer's own environment; no central service holds customer Graph tokens; the application's own credential is held in Proxara's central hardened custody and is never placed in a customer environment. Cross-tenant use of any token, code, or reference fails closed.

M7: Retrieved Sources Are Untrusted; Actions Require a Person

Content retrieved from mail, messages, and documents is treated as data, never as instructions. An instruction found inside retrieved content cannot trigger a consequential action; actions require the firm's policy outcome and, where configured, explicit human confirmation of the exact final payload shown in the view. The model receives only a protected outcome after execution, never the restored details.

M8: Fail Closed

There is no passthrough mode. If policy, the vault, retrieval, extraction, or context resolution cannot complete, the request returns a bounded, safe error. A failure never resolves to sending unprotected data onward, and partial results are labeled partial.

M9: Content-Free Record and Review

Every operation lands on the signed record in plain language: which sources, what decision, what protection counts, what outcome, attributed to the employee. The firm's compliance owner reviews activity without the record itself holding retrieved content, and over-broad usage patterns (R6) surface in the firm's own analytics.

M10: Retention and Deletion

Proxara does not keep copies of the customer's mail and files: content is fetched when asked and held encrypted only as long as the work requires, clear view payloads expire under a short time-to-live, and offboarding or termination deletes retrieved content, workflow state, the vault, and grant tokens, with deletion certified in writing.

Proxara provides an employee-facing notice for Connect within the Employee Monitoring Disclosure Template and a Client Consent Template for firms whose obligations require client consent. The controller decides and remains responsible; the templates exist so what the firm tells people is accurate.

M12: Sub-Processor Posture

AWS hosts the dedicated environment and performs in-account classification (Bedrock does not store inputs or outputs). The AI assistant provider and Microsoft act under the customer's own agreements and are described, with their honest boundaries, in the Sub-processor List.


5. Consultation

Customers configure scope (who connects, which policy classes route to which mode) and determine lawful basis, employee notice, and client consent. Employees see the connector's behavior directly: the view shows what was retrieved and what an action will do before it happens. Customers with a Data Protection Officer are encouraged to review this DPIA and the Data Processing Addendum as part of vendor assessment.


6. Compliance and Certifications

FrameworkStatus
GDPR / UK GDPRData Processing Addendum with Standard Contractual Clauses available
CCPA/CPRAService Provider obligations documented in DPA
HIPAAScope for Proxara Connect is stated in the HIPAA BAA
AWS ComplianceAWS maintains ISO 27001, SOC 1/2/3, PCI DSS, and FedRAMP certifications; Bedrock does not store model inputs or outputs

7. Conclusion and Residual Risk

This assessment identifies twelve risks. Most are mitigated to Low or Very Low; three carry residual Medium risk, stated plainly:

  • Re-identification through unique substance (R3). Stand-in replacement is real protection, not anonymization. The mitigation is architectural honesty: Private Analysis exists precisely because some substance should not leave in any form, and firm policy, not marketing, decides which.
  • Host-vendor visibility (R4). Conversations the AI provider retains are conversations about stand-ins, and the clear view travels outside the model-visible result; but the host application itself is the vendor's software, and Proxara does not claim protection against a compromised or instrumented host runtime. The customer's contractual relationship with its AI provider, and Private Analysis for designated classes, bound this residual.
  • Prompt injection in retrieved sources (R5). Source-planted instructions are an evolving threat across the industry. Isolation of retrieved content from instructions, the closed set of operations, and human confirmation of consequential actions reduce exposure; the threat surface changes as the ecosystem does, and this assessment's annual review explicitly revisits it.

Overall assessment: the processing is necessary and proportionate to the interests pursued, the dominant data subjects (the firm's clients) are materially better protected with the connector in the path than without it, and the residual risks are visible, bounded, and honestly stated. Processing may proceed.

Next review date: July 2027, or upon material change to processing activities.


8. Contact

For questions about this DPIA:

Proxara, Inc.

28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108

Email: support@proxara.ai

Security inquiries: security@proxara.ai