How the Proxara products process data inside the customer environment. Covers Proxara Connect (retrieval, stand-ins, the view, actions) and the Endpoint Protection device agent, plus data isolation, retention, and the cryptographic audit chain.
Updated July 2026
Last updated: July 2026
This Product Privacy Policy describes how personal data is processed by the Proxara products (together, the "Service"): Proxara Connect, the hosted connector that joins the Customer's AI assistant to the Customer's Microsoft 365 tenant through the Customer's dedicated environment, and Endpoint Protection, the device agent. This policy is intended for enterprise customers ("Customers"), their employees and authorized users ("End Users"), and their compliance and legal teams.
This policy does not cover the Proxara marketing website (proxara.ai). For that, see our Website Privacy Policy.
Proxara lets a firm adopt AI without protected client information reaching the model. With Proxara Connect, an employee asks the firm's AI assistant for work held in the firm's Microsoft 365; Proxara retrieves it inside the firm's dedicated environment, replaces protected references with consistent stand-ins before anything reaches the model, and shows the employee the real result in a view inside the conversation, with nothing installed on any device. With Endpoint Protection, a signed agent deployed through the firm's MDM redacts sensitive data from AI requests at the network layer before they leave the firm. Both record a cryptographically signed audit trail for compliance.
Proxara's role depends on the deployment model:
| Deployment Model | Proxara's Role | Data Access |
|---|---|---|
| Proxara-Managed (default) | Data processor (under Customer instruction). Proxara provisions and manages a dedicated, single-tenant AWS account for the Customer. | Operational access for deployment and maintenance. Customer receives read-only access. |
| Customer-Managed Deployment | Software licensor only; not a data processor. | No access to Customer data; Customer deploys and operates the Service independently. |
| MSP-Managed Deployment | Software licensor only; not a data processor. | No access; a Managed Service Provider operates on the Customer's behalf. |
In the default Proxara-Managed model, Proxara provisions a dedicated, single-tenant AWS account for each Customer. No shared, multi-tenant environment holds Customer Data. Data belongs to the Customer at all times. Upon termination, the Customer may take ownership of the environment or Proxara will delete all data and provide written certification of deletion.
In Customer-Managed and MSP-Managed deployments, Customer Data resides within the Customer's (or their designated provider's) own cloud infrastructure.
Proxara runs in a dedicated, single-tenant AWS account for each customer, provisioned and managed by Proxara, or in the customer's own account where preferred. Each deployment has its own network, encryption keys, database, and audit store.
The Service operates through the following surfaces, as purchased and configured by the Customer:
Proxara Connect requires no software on any device. Deployment is one tenant-wide administrator consent to the verified Proxara Connect application in the Customer's Microsoft tenant, plus the addition of the Customer's connector to the Customer's Claude workspace. Each End User then signs in with their own Microsoft account; all retrieval runs under delegated, read-only permissions bounded by what that End User can already access.
Retrieval and context. When an End User asks the AI assistant for work held in the firm's systems, Proxara retrieves the relevant mail, calendar items, Teams messages, OneDrive/SharePoint files, and tasks from the Customer's own tenant through Microsoft Graph, inside the Customer's dedicated environment. Proxara resolves the employee's identity and the organizational context (which client, which matter, which participants) so the firm's policy can be applied to the actual situation.
Protection before the model. Proxara's policy engine reads the retrieved material in context and replaces protected references (client names, identifiers, account references, and similar) with consistent stand-ins before anything reaches the AI assistant. The reversible mapping between a stand-in and its original value is held in a KMS-encrypted vault inside the Customer's environment and travels on no channel. Firm policy selects one of three outcomes for each class of work: Protected Reasoning (the default: the substance of the work reaches the model with stand-ins in place of protected references), Private Analysis (the substantive facts stay inside the Customer's environment; the model receives only a safe status while the full result is delivered to the End User's view), or Blocked (nothing is retrieved, and the End User sees the plain reason).
The embedded view. The clear result, with real names and records, is delivered to a Proxara view inside the conversation over a short-lived, authenticated direct fetch from the Customer's environment, with caching disallowed. The clear payload is not placed in the model-visible result.
Actions. Where the Customer enables action features, the assistant may propose a draft or a task against stand-ins; the End User sees the real final version in the view and confirms, edits, or declines. On confirmation, exact values are restored only inside the Customer's environment, immediately before the Customer's own Microsoft tenant receives the action, and the model is told only a protected outcome.
Retention. Proxara does not keep copies of the Customer's mail and files. Content is fetched when asked, held encrypted only as long as the work requires, and the record of each operation is content-free. Section 3.3 states the lifecycle in detail.
Boundary. Proxara Connect governs the connected path. Text typed or files uploaded directly into an AI assistant are visible to that assistant and are not processed by Proxara Connect; a native connector inside the AI host also bypasses Proxara unless the Customer disables it in the host's settings. Endpoint Protection is the product that extends coverage to the device.
The remaining subsections of this Section 2 describe Endpoint Protection, the device agent, and the shared platform surfaces.
The Endpoint Protection agent reaches employee laptops through the firm's MDM (Jamf, Intune, Kandji, and compatible platforms); employees install nothing themselves. When an employee uses an AI tool, Proxara classifies the request inside the customer's own environment and replaces sensitive values with reversible tokens on the device. Only the redacted request reaches the third-party AI provider. The original text is processed inside the customer's environment and, for interactions flagged for review, retained there for a short, configurable window (seven days by default) before automatic deletion. The original values are restored only on the employee's own screen.
A native background service for macOS and Windows that operates as a local TLS-inspecting proxy for AI destinations. The service intercepts AI-bound HTTPS traffic at the operating system network layer, covering all applications on the device, including browsers, desktop AI applications, coding tools, and command-line interfaces. The service decrypts a connection only on positive evidence the destination is AI; connections without that evidence are tunnelled through without decryption. The device proxy trusts a per-tenant root certificate authority (CA), minted server-side at enrollment and delivered over the authenticated enrollment envelope, carrying X.509 Name Constraints (RFC 5280) that exclude sign-in, banking, healthcare, government, and security-tooling domains in the certificate itself.
Deployment is via MDM. A signed package is assigned to a device group; it installs in the background; the employee does nothing. CA trust is established through an MDM configuration profile, without any employee prompt.
The device proxy inspects interactions with external AI assistants and AI features, including ChatGPT, Claude, Google Gemini, Perplexity, DeepSeek, Grok, Azure OpenAI, Amazon Bedrock, and Google Vertex AI, along with the AI features in the firm's connected business applications, and it observes Model Context Protocol (MCP) activity from AI clients. The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic; it passes through unmodified. (Proxara Connect's server-side retrieval of Microsoft 365 content, under each employee's own delegated permissions, is a separate surface described in Section 2.1; it is retrieval on the Customer's instruction, not interception.) Sign-in pages and traffic to banking, healthcare, and government services are never intercepted.
If the agent's CA is not trusted by the OS, the agent passes traffic straight through to the real origin without presenting a Proxara certificate; the employee never sees a certificate error. If CA trust is lost, interception turns off and the firm is alerted. Sites keep working.
The Service captures interactions between End Users and covered external AI tools. Interactions are sent to a classification engine running within the Customer's dedicated environment. The classification engine analyzes each interaction for potential compliance risks based on the Customer's industry profile and flags interactions that may contain sensitive data for compliance review.
When End Users upload files (spreadsheets, PDFs, CSVs, documents) to external AI tools, the Service captures the file content along with the prompt text. The classification engine extracts readable text from these files and analyzes both the prompt and file content together for compliance risks. For flagged events involving files, a secondary review confirms whether the content genuinely warrants compliance attention before notifying the designated compliance officer. This secondary review is designed to eliminate false positives: personal files, generic templates, and data unrelated to the firm's clients are filtered out.
The Service intercepts prompts before they are sent to external AI tools. The classification engine performs semantic redaction, replacing sensitive identifiers (names, account numbers, Social Security numbers, medical record numbers, and similar identifiers) with context-preserving semantic tags (e.g., "[Client_A]", "[Account_Num_1]"). The sanitized prompt is forwarded to the external AI. When the AI responds, the Service restores original values from a session-scoped mapping on the device, for the employee's own screen only. A second-pass scan detects any new sensitive entities introduced by the AI's response.
Customers may optionally deploy a self-hosted language model (running on GPU-equipped instances within the dedicated environment or their own on-premises infrastructure) as an alternative to AWS Bedrock for classification. This keeps all inference local with no external API calls.
When the Service flags an interaction as potentially containing sensitive data, notification summaries may be routed to the Customer's configured alert channels. Supported channels include Slack, Microsoft Teams, generic webhooks, and email digests. Notification summaries contain the event severity, risk category, employee identifier, AI provider name, and a brief excerpt of the flagged interaction. These summaries are sent to destinations configured and controlled by the Customer within the Customer's own communication platforms. Proxara does not select or operate these platforms; the Customer maintains its own relationship with each provider.
Proxara is a processing layer, not a long-term archive. The firm's existing compliance archive (for example, Smarsh, Global Relay, or an equivalent recordkeeping platform) remains the regulatory system of record for purposes such as SEC Rule 17a-4 and FINRA supervision. The Service can be configured to forward interaction records to the firm's designated archive provider. Where that integration is enabled, the archive provider's own agreement and retention policy govern the archived records. Proxara holds flagged interactions only for the short review window, then purges them.
The embedded MCP component observes MCP activity from AI clients. It discovers MCP servers and connectors in use, records signed audit events for tool activity observed via the network proxy, and allows the compliance team to block or quarantine a server. The user's MCP clients connect to their own servers directly; Proxara does not sit in the request path for MCP tool calls. Tool-call raw payloads are never stored; only hashes and signatures are retained.
Where Proxara can inspect an MCP request, it applies the same redaction as for other AI traffic before the request reaches the downstream server. The compliance officer can classify each MCP server and can block or quarantine one through the governance console. Every governed action is recorded in the signed audit chain. Original values never enter the audit log; only entity hashes and counts are retained.
Every signed audit event is encoded in canonical JSON (RFC 8785 JCS), signed with Ed25519, and linked into a per-tenant hash chain. Batches are Merkle-rooted, and each batch root is anchored by default to Sigstore Rekor, a public-internet transparency log; if the log is unreachable, the anchor is recorded locally and the chain continues. Anchoring transmits only the cryptographic hash (the Merkle root); no Customer Data is sent. An offline verifier lets an auditor confirm signatures, chain continuity, and the public-log timestamp without contacting any Proxara service.
| Data Category | Description | Controlled By |
|---|---|---|
| Prompt Text | Text submitted by End Users to external AI tools | Customer |
| Response Text | Text returned by external AI tools | Customer |
| Employee Metadata | Employee identifier, employee name, device identifier | Customer |
| Device Enrollment Data | Device identifier, operating system, hostname, and agent version, collected during device service registration | Customer |
| Session Metadata | Provider name, page URL, timestamp, session identifier | Customer |
| Classification Results | Severity, risk category, data types detected, flag reason | Generated by Service, stored by Customer |
| Redaction Mappings | Mapping of original values to semantic tags (e.g., "John Smith" to "[Client_A]") | Generated by Service; ephemeral (see Data Lifecycle below) |
| Audit Records | Flagged interaction excerpts, classification details, reviewer actions, notes | Generated by Service, stored by Customer |
| File Content | Text extracted from files uploaded by End Users to external AI tools, including spreadsheets, PDFs, CSVs, and documents. Captured and stored temporarily for compliance review. Raw file bytes are not stored; only redacted text and a hash of the redacted bytes. | Customer |
| Notification Summaries | Event severity, risk category, employee identifier, provider name, brief excerpt, sent to Customer's configured Slack, Teams, webhook, or email channels | Generated by Service, delivered to Customer's own platforms |
| MCP Tool-Call Records | Tool name, MCP server identifier, hash of the tool-call payload, classification result, resolved egress mode (Protected or Live), signed audit event. Raw payloads are not stored. | Generated by Service, stored by Customer |
| Classification Records (per MCP server) | The (tenant, MCP server) mode mapping, the seed taxonomy version, the compliance officer who set the override, the timestamp, and any Customer-supplied DPA reference. Editable by the Customer's compliance officer. | Customer |
| Cryptographic Audit Events | Canonical JSON-encoded events, each Ed25519-signed and hash-chained per tenant | Generated by Service, stored by Customer |
| Retrieved Microsoft 365 Content (Proxara Connect) | Mail, calendar items, Teams messages, OneDrive/SharePoint files, and tasks retrieved from the Customer's tenant under the signed-in End User's delegated permissions; may contain client personal, financial, and tax information | Customer |
| Stand-in Mappings (Proxara Connect) | The reversible mapping between a protected reference and its stand-in, held in a KMS-encrypted vault in the Customer's environment; reversible pseudonymization data | Generated by Service, held in Customer's environment |
| Microsoft Grant Tokens (Proxara Connect) | Per-employee delegated access and refresh tokens, encrypted in the Customer's environment | Customer |
| View Payloads (Proxara Connect) | The clear result delivered to the End User's embedded view, held encrypted under a short time-to-live | Generated by Service, held in Customer's environment |
The Service uses AWS Bedrock (running Anthropic Claude models hosted by AWS) for classification and for the semantic identification of protected references. Prompt text, and for Proxara Connect the retrieved Microsoft 365 content, together with an industry-specific system prompt, are sent to Bedrock for analysis. All Bedrock inference runs within the Customer's dedicated, isolated AWS account provisioned and managed by Proxara. Bedrock processes data under AWS's terms and does not use Customer data for model training. The data agreement for this classification inference is with AWS, not with Anthropic directly.
Separately, under Proxara Connect, the Customer's own AI assistant (for example, Claude under the Customer's own workspace agreement with Anthropic) receives the policy-approved material with protected references replaced by stand-ins, as described in Section 2.1. That provider is the Customer's own, not a Proxara sub-processor; the Sub-processor List describes the relationship.
| Data | Storage Location | Retention |
|---|---|---|
| Retrieved Microsoft 365 content (Proxara Connect) | Customer's dedicated environment, encrypted | Fetched when asked and held only as long as the work requires; Proxara does not keep copies of the Customer's mail and files. Clear view payloads are held under a short time-to-live. |
| Stand-in mappings (Proxara Connect) | KMS-encrypted vault in the Customer's dedicated environment | Persist for consistency across the work; deleted on offboarding, termination, or Customer instruction. Never transmitted to the AI assistant, the conversation, or logs. |
| Microsoft grant tokens (Proxara Connect) | Encrypted in the Customer's dedicated environment | Until revocation, reconnection, or offboarding. |
| Redaction mappings, device-side (Endpoint Protection) | Application memory and, for session continuity, a local encrypted database on the employee's device | Session-scoped and short-lived; purged when the conversation session ends and removed entirely when the agent is uninstalled. The device-side mappings are not stored in the Customer's cloud environment; the Proxara Connect vault above is the separate, server-side mapping store. |
| All intercepted interactions (flagged and non-flagged) | Customer's dedicated AWS account (raw_events table) | Stored briefly; default 7 days then automatically purged. Configurable by the Customer. |
| Flagged interactions (full record) | Customer's dedicated AWS account (audit_events table) | Same 7-day default retention, purged on the same schedule. For interactions transmitted to a compliance archive provider, content is purged from Proxara's environment once archived or dismissed. |
| File content (attachments) | Customer's dedicated AWS account | Raw file bytes are not stored. Only redacted text and a hash of the redacted bytes are retained. Purged on the same 7-day schedule. File metadata retained in the supervision audit log. |
| Signed audit envelopes | Customer's dedicated AWS account (S3, COMPLIANCE Object Lock) | Cryptographic proofs archived for 7 years; immutable. |
| Aggregate metrics | Customer's dedicated AWS account | Default 90 days. |
| Supervision audit log (compliance actions: status changes, reveals, shares) | Customer's dedicated AWS account | Retained as the permanent supervision record; carries metadata only, no message content; not purged. |
| Records forwarded to the firm's archive (where the integration is enabled) | The firm's designated compliance archive provider (Smarsh, Global Relay, or equivalent) | Governed by the archive provider's own retention policy (for example, 7 years for FINRA-regulated firms). |
| Classification model inputs/outputs | Not retained by AWS Bedrock | AWS Bedrock does not store inputs or outputs per AWS's data privacy documentation. |
| MCP audit events | Append-only CBOR + JSONL index files in the device's data directory (embedded) or PostgreSQL in the Customer's environment (service mode) | Retained per Customer's configured retention. Batch Merkle roots are anchored to Sigstore Rekor by default (hashes only). |
In transit. All communications between the Service and the classification API use TLS 1.2 or higher (TLS 1.3 supported). When the device proxy is deployed, it intercepts HTTPS traffic to covered AI destinations by generating per-domain certificates signed by the per-tenant root CA. Interception is opened only for destinations with positive AI evidence, and the root CA's X.509 Name Constraints exclude sign-in, banking, healthcare, government, and security-tooling domains; non-AI traffic is never decrypted. Bedrock API calls use TLS, and inference runs within the Customer's own AWS account.
At rest. Customer databases (PostgreSQL on RDS), audit log storage (Amazon S3 with COMPLIANCE Object Lock), ElastiCache, Secrets Manager, and CloudWatch log groups are all encrypted with AWS KMS using customer-managed keys (CMKs) in the Customer's own account; compute runs as ECS Fargate tasks with no long-lived nodes holding Customer Data. The Proxara Connect stand-in vault, workflow state, and grant tokens are encrypted under the same customer-owned keys. The Customer owns the KMS keys; Proxara has use-only rights and no delete or disable rights. The Customer can revoke Proxara's access at any time.
When the device proxy is deployed, the root CA private key and session continuity data are stored locally on the employee's device in a system-protected directory (macOS: /Library/Application Support/Proxara; Windows: C:\ProgramData\Proxara). All local data is removed on uninstall.
Identity vault. Each redacted value's original is sealed under its own AES-256-GCM key. Retiring a token destroys the key; the original becomes unrecoverable. This constitutes genuine GDPR Article 17 crypto-erasure, initiated by the compliance team and audit-logged.
Endpoint Protection enables Customers to monitor End User interactions with covered external AI tools. Proxara does not determine whether, how, or to what extent monitoring occurs. The Customer is solely responsible for:
Proxara provides a notice page that the device proxy presents to End Users on first use. Customers may customize the notice with their firm name and compliance contact information. Customers must inform End Users that AI interactions from all applications on the device, not only web browsers, are subject to monitoring and redaction.
Proxara Connect is not a monitoring product: it runs when the End User asks the AI assistant for something, and it processes the work content of that request. For the End User, the accurate description is: your request retrieves only what your own Microsoft account can already access; protected client references are replaced with stand-ins inside the firm's environment before anything reaches the AI service; you see the real result in the Proxara view inside the conversation; anything the assistant does on your behalf is shown to you for confirmation first; and each request lands on the firm's record with your identity attached, which is the same accountability the firm's other systems carry. The Customer remains responsible for any notice it owes its personnel about the processing of their work content; the Employee Monitoring Disclosure Template includes a Proxara Connect notice for that purpose.
When Proxara manages the deployment, the following subprocessors are engaged:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (compute, database, storage, key management, secrets management, networking), AI classification (Amazon Bedrock, Anthropic Claude models running within AWS), document text extraction (Amazon Textract), CloudWatch monitoring, CloudFront | Customer-selected AWS region (typically US) |
| Google LLC (Google Workspace) | Outbound transactional and notification email (invitations, compliance digests, PDF leave-behinds) via smtp.gmail.com. Receives recipient addresses and email content. | United States |
| Sigstore Rekor (on by default) | Public-internet transparency log for audit-chain anchoring. Receives only cryptographic hashes (Merkle roots) and signatures. No Customer Data is transmitted. | Public service operated by the Linux Foundation's Sigstore project |
| Exa (Endpoint Protection) | Used only to research an unrecognized MCP server's capabilities. Receives server/software metadata and a generated query. Never receives employee content or personal data. | United States |
Customer-connected integrations (optional, off by default). Customers may connect their own Slack workspace, Microsoft Teams environment, or Google Calendar account to receive compliance notifications or provide board-meeting calendar context. When enabled, the Customer's own credentials and accounts are used; Proxara acts as an integration layer between the Service and the Customer's own platform accounts. These integrations are not Proxara sub-processors in the traditional sense; the Customer maintains its own relationship with each provider.
Note on Microsoft. The Teams and Outlook integration listed above is a compliance notification channel, not AI traffic interception. The Endpoint Protection device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic; it passes through unmodified. Proxara Connect's retrieval of Microsoft 365 content is a separate surface (Section 2.1): retrieval from the Customer's own tenant, on the Customer's instruction, under each employee's own delegated permissions, with Microsoft acting as the Customer's own productivity-suite provider rather than a Proxara sub-processor.
The Customer's own AI assistant. Under Proxara Connect, the Customer's own AI assistant (for example, Claude under the Customer's Claude workspace agreement with Anthropic) receives the policy-approved material with protected references replaced by stand-ins. That relationship is the Customer's own; the provider is not a Proxara sub-processor.
Not sub-processors. OpenAI is not a Proxara sub-processor; no AI inference calls are made to OpenAI. The OpenAI/ChatGPT platform appears only as an intercepted destination (the external AI the employee is using), not as a Proxara processing service.
Customers will be notified of any changes to subprocessors in accordance with the Data Processing Addendum. The current subprocessor list is maintained at Subprocessor List.
In Customer-Managed and MSP-Managed deployments, AWS is the Customer's own subprocessor, not Proxara's. Proxara acts solely as a software licensor and has no access to Customer Data.
The Service is designed to support Customers' compliance obligations across regulated industries. Proxara does not provide legal advice and does not guarantee compliance with any particular regulation. Customers are responsible for configuring the Service appropriately for their regulatory requirements.
The product tags each interaction record against controls across ISO 27001, GDPR/UK GDPR, the EU AI Act, NIST AI RMF, HIPAA, SEC Reg S-P, and FINRA as a built-in product feature supported by the signed control library.
The Service supports FINRA Rule 3110 (Supervision) and SEC Regulation S-P requirements by providing AI interaction monitoring, inline policy enforcement, and data protection controls. It can be configured to forward interaction records to the firm's existing compliance archive (for example, Smarsh or Global Relay), which remains the regulatory system of record. Proxara is a processing layer, not the archive: it holds flagged interactions only for the short review window, then purges them.
Cryptographic audit proofs are archived to S3 COMPLIANCE Object Lock for 7 years, meeting the minimums under SEC Rule 17a-4(f), FINRA Rule 4511, and NYDFS 500.6.
For healthcare Customers, a HIPAA Business Associate Agreement is available for Proxara-Managed deployments. The Service's redaction capabilities address HIPAA's 18 identifier categories. In the event of a breach involving Protected Health Information, Proxara will notify the affected Customer within 60 days in accordance with 45 CFR 164.410. For all other breach notifications, the 72-hour standard applies (see Section 9). In Customer-Managed deployments, Proxara is not a Business Associate because it does not create, receive, maintain, or transmit Protected Health Information.
The Service supports attorney-client privilege protection by preventing inadvertent disclosure of privileged information to external AI tools.
The Service supports the firm's handling of tax return information by replacing taxpayer identifiers with stand-ins before material reaches external AI services, and, under Proxara Connect, by letting firm policy keep designated classes of substance inside the firm's environment entirely. Proxara enforces the firm's counsel-approved policy and narrows disclosure; it does not create or ensure compliance with Section 7216.
For UK-based Customers, the Service supports compliance with the UK GDPR and the Data Protection Act 2018. A Data Processing Addendum incorporating the UK International Data Transfer Addendum (IDTA) is available for international data transfers where applicable.
End Users seeking to exercise data protection rights (access, correction, deletion, portability, objection) regarding data processed by the Service should contact their employer (the Customer), who is the data controller. Proxara will assist Customers in responding to data subject requests as described in the Data Processing Addendum, including through crypto-erasure of individual identity vault tokens (which destroys the key and makes the original unrecoverable) and automatic purge via the configured retention window.
There is no employee self-service data request portal in the Service. The Customer's compliance team initiates crypto-erasure and deletion on the End User's behalf.
The Customer is the "business" under the CCPA/CPRA with respect to employee data processed by the Service. Proxara acts as a "service provider" in Proxara-Managed deployments. Proxara does not sell personal information. Proxara does not use personal information for purposes other than those specified in agreements with Customers.
In the event of a confirmed data breach involving Customer Data in a Proxara-Managed deployment:
In Customer-Managed deployments, the Customer is responsible for breach detection and notification, as Proxara does not have access to the Customer's infrastructure.
Proxara may update this Product Privacy Policy from time to time. Customers will be notified of material changes via email to the designated contact and by posting the revised policy on the website. Changes will not retroactively reduce the protections provided to data already processed.
For questions about this Product Privacy Policy, data subject requests, or privacy inquiries:
Proxara, Inc.
28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108
Email: support@proxara.ai
For security or vulnerability disclosures:
Email: security@proxara.ai