Proxaradocs
Trust Center/Policies

Product Privacy Policy

How the Proxara products process data inside the customer environment. Covers Proxara Connect (retrieval, stand-ins, the view, actions) and the Endpoint Protection device agent, plus data isolation, retention, and the cryptographic audit chain.

Updated July 2026

Product Privacy Policy

Last updated: July 2026

This Product Privacy Policy describes how personal data is processed by the Proxara products (together, the "Service"): Proxara Connect, which joins the Customer's AI assistant to the Customer's own systems through the Customer's dedicated environment, and Endpoint Protection, the device agent. This policy is intended for enterprise customers ("Customers"), their employees and authorized users ("End Users"), and their compliance and legal teams.

This policy does not cover the Proxara marketing website (proxara.ai). For that, see our Website Privacy Policy.


1. Proxara's Role

Proxara lets a firm adopt AI without protected client information reaching the model. With Proxara Connect, an employee asks the firm's AI assistant for work held in the firm's own systems; Proxara retrieves and classifies it inside the firm's dedicated environment, releases only a payload assembled from the claims the firm's policy admitted with stand-ins in place of protected references, and renders the real result in a first-party workspace under the firm's own single sign-on, with nothing installed on any device. With Endpoint Protection, a signed agent deployed through the firm's MDM redacts sensitive data from AI requests at the network layer before they leave the firm. Both record a cryptographically signed audit trail.

Proxara's role depends on the deployment model:

Deployment ModelProxara's RoleData Access
Proxara-Managed (default)Data processor (under Customer instruction). Proxara provisions and manages a dedicated, single-tenant AWS account for the Customer.Operational access for deployment and maintenance. Customer receives read-only access.
Customer-Managed DeploymentSoftware licensor only; not a data processor.No access to Customer data; Customer deploys and operates the Service independently.
MSP-Managed DeploymentSoftware licensor only; not a data processor.No access; a Managed Service Provider operates on the Customer's behalf.

In the default Proxara-Managed model, Proxara provisions a dedicated, single-tenant AWS account for each Customer. No shared, multi-tenant environment holds Customer Data. Data belongs to the Customer at all times. Upon termination, the Customer may take ownership of the environment or Proxara will delete all data and provide written certification of deletion.

In Customer-Managed and MSP-Managed deployments, Customer Data resides within the Customer's (or their designated provider's) own cloud infrastructure.


2. What the Service Does

Proxara runs in a dedicated, single-tenant AWS account for each customer, provisioned and managed by Proxara, or in the customer's own account where preferred. Each deployment has its own network, encryption keys, database, and audit store.

The Service operates through the following surfaces, as purchased and configured by the Customer:

2.1 Proxara Connect: the connected path

Proxara Connect requires no software on any device. Deployment is one tenant-wide administrator consent to the Proxara Connect application in the Customer's Microsoft tenant, plus the addition of the Customer's connector in the Customer's AI assistant. Each End User then signs in with their own Microsoft account; all retrieval runs under delegated, read-only permissions bounded by what that End User can already access.

Retrieval and context. When an End User asks the AI assistant for work held in the firm's systems, Proxara retrieves the relevant records inside the Customer's dedicated environment from the systems the Customer has connected: Microsoft 365 (mail, calendar, Teams messages, OneDrive and SharePoint files, tasks) and, where connected, practice management, selected tax systems, document stores, and a CRM. Proxara resolves the employee's identity and the organizational context so the firm's policy applies to the actual situation.

Where the work runs. Parsing, classification, identity resolution, correlation, and exact computation over raw material run inside the Customer's environment. The customer-contained inference plane that performs the semantic part of that has no internet route, no route to an external model, no provider credentials, and no independent access to a source system. A managed model endpoint reached over a private network link is still a managed external processor.

What reaches the model. The payload is constructed rather than filtered: it starts empty and carries only the typed claims the firm's policy admitted for that work, with consistent stand-ins for protected references. The reversible mapping between a stand-in and its original value is held in a KMS-encrypted vault inside the Customer's environment and travels on no channel. Firm policy selects one of three outcomes per class of work: Protected Reasoning (the default), Private Analysis (the substance stays inside the Customer's environment and the model receives only a safe status), or Blocked (nothing is retrieved, and the End User sees the plain reason).

The private workspace. The clear result, with real names and records, renders only in a first-party, customer-authorized origin under the firm's own single sign-on, bound to the exact recipient and artifact revision. A host adapter may open or deep-link to it. No clear value enters host tool output, host-visible structured content, host-controlled messaging, the URL, the referrer, client telemetry, or support logs.

Actions. Where the Customer enables action features, the assistant may propose a draft or a task against stand-ins; the End User reviews the real final version in the workspace and confirms, edits, or declines. On confirmation, exact values are restored only inside the Customer's environment, immediately before the Customer's own system receives the action, and the model is told only a protected outcome.

Retention. Proxara does not keep copies of the Customer's mail and files. Content is fetched when asked, held encrypted only as long as the work requires, and the record of each operation is content-free. Section 3.3 states the lifecycle.

Boundary. Proxara Connect governs the connected path. Text typed or files uploaded directly into an AI assistant are visible to that assistant and are not processed by Proxara Connect; a native connector inside the AI host also bypasses Proxara unless the Customer disables it in the host's settings.

The remaining subsections of this Section 2 describe Endpoint Protection, the device agent, and the shared platform surfaces.

2.2 Device Proxy (Endpoint Protection)

The Endpoint Protection agent reaches employee laptops through the firm's MDM (Jamf, Intune, Kandji, and compatible platforms) as a signed package assigned to a device group. Employees install nothing and see no prompt; CA trust is established through an MDM configuration profile.

It is a native background service for macOS and Windows that operates as a local TLS-inspecting proxy for AI destinations, intercepting AI-bound HTTPS traffic at the operating system network layer across every application on the device, including browsers, desktop AI applications, coding tools, and command-line interfaces. It decrypts a connection only on positive evidence the destination is AI; connections without that evidence are tunnelled through undecrypted. It trusts a per-tenant root certificate authority minted server-side at enrollment and delivered over the authenticated enrollment envelope, carrying X.509 Name Constraints (RFC 5280) that exclude sign-in, banking, healthcare, government, and security-tooling domains in the certificate itself.

When an employee uses an AI tool, Proxara classifies the request inside the customer's own environment and replaces sensitive values with reversible tokens on the device, so only the redacted request reaches the third-party AI provider; original values are restored on the employee's own screen. Original text is processed inside the customer's environment and, for interactions flagged for review, retained there for a short, configurable window (seven days by default) before automatic deletion.

Covered destinations include ChatGPT, Claude, Google Gemini, Perplexity, DeepSeek, Grok, Azure OpenAI, Amazon Bedrock, and Google Vertex AI, along with the AI features in the firm's connected business applications, and the agent observes Model Context Protocol (MCP) activity from AI clients. It does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic; that passes through unmodified. Proxara Connect's server-side retrieval, described in Section 2.1, is retrieval on the Customer's instruction rather than interception. Sign-in pages and traffic to banking, healthcare, and government services are never intercepted.

If the agent's CA is not trusted by the OS, the agent passes traffic straight through to the real origin without presenting a Proxara certificate; the employee never sees a certificate error. If CA trust is lost, interception turns off and the firm is alerted. Sites keep working.

2.3 Monitoring Mode (Endpoint Protection)

The Service captures interactions between End Users and covered external AI tools and sends them to a classification engine running within the Customer's dedicated environment, which analyzes each interaction against the Customer's industry profile and flags those that may contain sensitive data for compliance review.

When End Users upload files (spreadsheets, PDFs, CSVs, documents) to external AI tools, the Service captures the file content with the prompt text, extracts readable text, and analyzes both together. For flagged events involving files, a secondary review confirms whether the content genuinely warrants compliance attention before the designated compliance officer is notified, filtering out personal files, generic templates, and data unrelated to the firm's clients.

2.4 Redaction Mode (Endpoint Protection)

The Service intercepts prompts before they are sent to external AI tools. The classification engine performs semantic redaction, replacing sensitive identifiers (names, account numbers, Social Security numbers, medical record numbers, and similar identifiers) with context-preserving semantic tags (e.g., "[Client_A]", "[Account_Num_1]"). The sanitized prompt is forwarded to the external AI. When the AI responds, the Service restores original values from a session-scoped mapping on the device, for the employee's own screen only. A second-pass scan detects any new sensitive entities introduced by the AI's response.

2.5 Local Inference

For Proxara Connect, the customer-contained inference plane is part of the architecture rather than an option: raw and sensitive material is classified there, inside the Customer's environment, with no external API call. For Endpoint Protection, Customers may optionally deploy a self-hosted language model on GPU-equipped instances in the dedicated environment or their own infrastructure in place of AWS Bedrock for classification.

2.6 Real-Time Notification Routing

When the Service flags an interaction as potentially containing sensitive data, notification summaries may be routed to the Customer's configured alert channels. Supported channels include Slack, Microsoft Teams, generic webhooks, and email digests. Summaries carry the event severity, risk category, employee identifier, AI provider name, and a brief excerpt of the flagged interaction, and go only to destinations the Customer configures and controls within its own platforms. Proxara does not select or operate those platforms.

2.7 Compliance Archive Integration

Proxara is a processing and execution boundary, not a long-term archive. The firm's existing compliance archive (for example, Smarsh, Global Relay, or an equivalent recordkeeping platform) remains the regulatory system of record for purposes such as SEC Rule 17a-4 and FINRA supervision. The Service can be configured to forward interaction records to it, and where that integration is enabled the archive provider's own agreement and retention policy govern the archived records. Proxara holds flagged interactions only for the short review window, then purges them.

2.8 MCP Observability and Governance (Endpoint Protection)

The embedded MCP component observes MCP activity from AI clients: it discovers the servers and connectors in use, records signed audit events for tool activity observed via the network proxy, and lets the compliance officer classify a server and block or quarantine it through the governance console. The user's MCP clients connect to their own servers directly; Proxara does not sit in the request path for MCP tool calls.

Where Proxara can inspect an MCP request, it applies the same redaction as for other AI traffic before the request reaches the downstream server. Every governed action is recorded in the signed audit chain. Raw tool-call payloads and original values are never stored; only hashes, counts, and signatures are retained.

2.9 Cryptographic Audit Chain

Every signed audit event is encoded in canonical JSON (RFC 8785 JCS), signed with Ed25519, and linked into a per-tenant hash chain.

For Endpoint Protection, batches are Merkle-rooted and each batch root is anchored by default to Sigstore Rekor, a public-internet transparency log; if the log is unreachable, the anchor is recorded locally and the chain continues. Anchoring transmits only the Merkle root hash; no Customer Data is sent. A bundled offline verifier lets an auditor confirm signatures, chain continuity, and the public-log timestamp without contacting any Proxara service.

The Proxara Connect record is not anchored to a transparency log and carries no inclusion proofs, and Proxara ships no verifier program for it. An export carries the verbatim signed bytes, the signatures, and the public keys, so a reviewer can verify it with their own tools.


3. Data Processed by the Service

3.1 Data Categories

Data CategoryDescriptionControlled By
Prompt TextText submitted by End Users to external AI toolsCustomer
Response TextText returned by external AI toolsCustomer
Employee MetadataEmployee identifier, employee name, device identifierCustomer
Device Enrollment DataDevice identifier, operating system, hostname, and agent version, collected during device service registrationCustomer
Session MetadataProvider name, page URL, timestamp, session identifierCustomer
Classification ResultsSeverity, risk category, data types detected, flag reasonGenerated by Service, stored by Customer
Redaction MappingsMapping of original values to semantic tags (e.g., "John Smith" to "[Client_A]")Generated by Service; ephemeral (see Data Lifecycle below)
Audit RecordsFlagged interaction excerpts, classification details, reviewer actions, notesGenerated by Service, stored by Customer
File ContentText extracted from files uploaded by End Users to external AI tools, including spreadsheets, PDFs, CSVs, and documents. Captured and stored temporarily for compliance review. Raw file bytes are not stored; only redacted text and a hash of the redacted bytes.Customer
Notification SummariesEvent severity, risk category, employee identifier, provider name, brief excerpt, sent to Customer's configured Slack, Teams, webhook, or email channelsGenerated by Service, delivered to Customer's own platforms
MCP Tool-Call RecordsTool name, MCP server identifier, hash of the tool-call payload, classification result, resolved egress mode (Protected or Live), signed audit event. Raw payloads are not stored.Generated by Service, stored by Customer
Classification Records (per MCP server)The (tenant, MCP server) mode mapping, the seed taxonomy version, the compliance officer who set the override, the timestamp, and any Customer-supplied DPA reference. Editable by the Customer's compliance officer.Customer
Cryptographic Audit EventsCanonical JSON-encoded events, each Ed25519-signed and hash-chained per tenantGenerated by Service, stored by Customer
Retrieved Source Content (Proxara Connect)Mail, calendar items, Teams messages, OneDrive/SharePoint files, tasks, and records from other systems the Customer has connected, retrieved under the signed-in End User's delegated permissions; may contain client personal, financial, and tax informationCustomer
Stand-in Mappings (Proxara Connect)The reversible mapping between a protected reference and its stand-in, held in a KMS-encrypted vault in the Customer's environment. This is the reversible pseudonymization data referred to in the Data Processing Addendum.Generated by Service, held in Customer's environment
Grant Tokens (Proxara Connect)Per-employee delegated access and refresh tokens, encrypted in the Customer's environmentCustomer
Workspace Artifacts (Proxara Connect)The clear result rendered in the End User's first-party workspace, held encrypted under its retention classGenerated by Service, held in Customer's environment

3.2 Where classification runs

Endpoint Protection uses AWS Bedrock (running Anthropic Claude models hosted by AWS) for classification. Prompt text, extracted file text, and an industry-specific system prompt are sent to Bedrock for analysis. That inference runs within the Customer's dedicated AWS account; Bedrock processes data under AWS's terms and does not use Customer data for model training. The data agreement for it is with AWS, not with Anthropic directly.

Proxara Connect does not route raw or sensitive material to a managed external model for classification. That work runs on the customer-contained inference plane inside the Customer's environment, which has no internet route and no route to an external model. Network privacy is not the same property as customer-contained inference: a managed endpoint reached over a private link remains a managed external processor. Where the Customer has separately configured an explicitly authorized raw external route for one purpose, processor, data class, and destination, that route is used only as configured and never as a fallback.

Separately, under Proxara Connect, the Customer's own AI assistant receives the constructed release package described in Section 2.1. That provider is the Customer's own, not a Proxara sub-processor; the Sub-processor List describes the relationship.

3.3 Data Lifecycle

DataStorage LocationRetention
Retrieved source content (Proxara Connect)Customer's dedicated environment, encryptedFetched when asked and held only as long as the work requires; Proxara does not keep copies of the Customer's mail and files. Workspace artifacts are held under their own retention class.
Stand-in mappings (Proxara Connect)KMS-encrypted vault in the Customer's dedicated environmentHeld with an explicit expiry for as long as the work, target binding, recovery, verification, or repair requires, then cryptographically erased; also deleted on offboarding, termination, or Customer instruction. Never transmitted to the AI assistant, the conversation, or logs.
Grant tokens (Proxara Connect)Encrypted in the Customer's dedicated environmentUntil revocation, reconnection, or offboarding.
Redaction mappings, device-side (Endpoint Protection)Application memory and, for session continuity, a local encrypted database on the employee's deviceSession-scoped and short-lived; purged when the conversation session ends and removed entirely when the agent is uninstalled. The device-side mappings are not stored in the Customer's cloud environment; the Proxara Connect vault above is the separate, server-side mapping store.
All intercepted interactions (flagged and non-flagged)Customer's dedicated AWS account (raw_events table)Stored briefly; default 7 days then automatically purged. Configurable by the Customer.
Flagged interactions (full record)Customer's dedicated AWS account (audit_events table)Same 7-day default retention, purged on the same schedule. For interactions transmitted to a compliance archive provider, content is purged from Proxara's environment once archived or dismissed.
File content (attachments)Customer's dedicated AWS accountRaw file bytes are not stored. Only redacted text and a hash of the redacted bytes are retained. Purged on the same 7-day schedule. File metadata retained in the supervision audit log.
Signed audit envelopesCustomer's dedicated AWS account (S3, COMPLIANCE Object Lock)Cryptographic proofs archived for 7 years; immutable.
Aggregate metricsCustomer's dedicated AWS accountDefault 90 days.
Supervision audit log (compliance actions: status changes, reveals, shares)Customer's dedicated AWS accountRetained as the permanent supervision record; carries metadata only, no message content; not purged.
Records forwarded to the firm's archive (where the integration is enabled)The firm's designated compliance archive provider (Smarsh, Global Relay, or equivalent)Governed by the archive provider's own retention policy (for example, 7 years for FINRA-regulated firms).
Classification model inputs/outputs (Endpoint Protection)Not retained by AWS BedrockAWS Bedrock does not store inputs or outputs per AWS's data privacy documentation.
MCP audit eventsAppend-only CBOR + JSONL index files in the device's data directory (embedded) or PostgreSQL in the Customer's environment (service mode)Retained per Customer's configured retention. Batch Merkle roots are anchored to Sigstore Rekor by default (hashes only).

4. Data Isolation and Security

4.1 Infrastructure Isolation

  • In the default Proxara-Managed model, the Service runs within a dedicated, single-tenant AWS account provisioned by Proxara for the Customer, isolated with its own VPC, subnets, database, and encryption keys. No Customer Data is commingled with another customer's.
  • In Customer-Managed and MSP-Managed deployments, the Service runs within the Customer's own infrastructure and Proxara has no access to Customer Data.

4.2 Encryption

In transit. All communications between the Service and the classification API use TLS 1.2 or higher (TLS 1.3 supported). When the device proxy is deployed, it intercepts HTTPS traffic to covered AI destinations by generating per-domain certificates signed by the per-tenant root CA. Interception is opened only for destinations with positive AI evidence, and the root CA's X.509 Name Constraints exclude sign-in, banking, healthcare, government, and security-tooling domains; non-AI traffic is never decrypted, and Bedrock API calls use TLS with inference running within the Customer's own AWS account. For Proxara Connect, the clear artifact is served to the first-party workspace over an authenticated, recipient-bound session with caching disallowed.

At rest. Customer databases (PostgreSQL on RDS), audit log storage (Amazon S3 with COMPLIANCE Object Lock), ElastiCache, Secrets Manager, and CloudWatch log groups are all encrypted with AWS KMS using customer-managed keys (CMKs) in the Customer's own account; compute runs as ECS Fargate tasks with no long-lived nodes holding Customer Data. The Proxara Connect stand-in vault, workflow state, and grant tokens are encrypted under the same keys. Isolation and control are separate facts, and the deployment record names who administers those keys: in the customer-owned mode the Customer administers them, Proxara holds use rights only with no delete or disable rights, and the Customer can revoke that access at any time.

When the device proxy is deployed, the root CA private key and session continuity data are stored locally on the employee's device in a system-protected directory (macOS: /Library/Application Support/Proxara; Windows: C:\ProgramData\Proxara). All local data is removed on uninstall.

Identity vault. Each redacted value's original is sealed under its own AES-256-GCM key. Retiring a token destroys the key; the original becomes unrecoverable. This constitutes genuine GDPR Article 17 crypto-erasure, initiated by the compliance team and audit-logged.

4.3 Access Controls

  • Role-based access control for the governance console; API keys for the device service and JWT tokens for the dashboard.
  • Audit records include reviewer identity, timestamps, and status changes.
  • Console insights are firm-level only. Individual numeric risk scores are stripped server-side and never sent to the console, which displays qualitative risk bands only.

5. Employee Notice

5.1 Endpoint Protection: Monitoring Disclosure

Endpoint Protection enables Customers to monitor End User interactions with covered external AI tools. Proxara does not determine whether, how, or to what extent monitoring occurs. The Customer is solely responsible for:

  • Complying with all applicable employee monitoring laws, including the Electronic Communications Privacy Act (ECPA), state-specific notification requirements (including but not limited to Connecticut, Delaware, New York, and California), and any applicable labor agreements.
  • Providing advance notice to End Users that their AI interactions may be monitored and reviewed.
  • Obtaining any required consent.
  • Implementing the Employee Monitoring Disclosure (a template is available at Employee Monitoring Disclosure Template).

Proxara provides a notice page that the device proxy presents to End Users on first use. Customers may customize the notice with their firm name and compliance contact information. Customers must inform End Users that AI interactions from all applications on the device, not only web browsers, are subject to monitoring and redaction.

5.2 Proxara Connect: What Happens When You Use It

Proxara Connect is not a monitoring product: it runs when the End User asks the AI assistant for something, and it processes the work content of that request. For the End User, the accurate description is: your request retrieves only what your own account can already access; the AI service receives only the claims the firm's policy admitted, with stand-ins in place of protected client references; you read the real result in the firm's own workspace, under the firm's sign-in; anything the assistant does on your behalf is shown to you for confirmation first; and each request lands on the firm's record with your identity attached, which is the same accountability the firm's other systems carry. The Customer remains responsible for any notice it owes its personnel about the processing of their work content; the Employee Monitoring Disclosure Template includes a Proxara Connect notice for that purpose.


6. Subprocessors

6.1 Proxara-Managed Deployments

When Proxara manages the deployment, the following subprocessors are engaged:

SubprocessorPurposeLocation
Amazon Web Services, Inc.Cloud infrastructure (compute, database, storage, key management, secrets management, networking), CloudWatch monitoring, CloudFront; and, for Endpoint Protection, AI classification (Amazon Bedrock, Anthropic Claude models running within AWS) and document text extraction (Amazon Textract)Customer-selected AWS region (typically US)
Google LLC (Google Workspace)Outbound transactional and notification email (invitations, compliance digests, PDF leave-behinds) via smtp.gmail.com. Receives recipient addresses and email content.United States
Sigstore Rekor (Endpoint Protection; on by default)Public-internet transparency log for anchoring the device agent's audit chain. Receives only cryptographic hashes (Merkle roots) and signatures. No Customer Data is transmitted.Public service operated by the Linux Foundation's Sigstore project
Exa (Endpoint Protection)Used only to research an unrecognized MCP server's capabilities. Receives server/software metadata and a generated query. Never receives employee content or personal data.United States

Customer-connected integrations (optional, off by default). Customers may connect their own Slack workspace, Microsoft Teams environment, or Google Calendar account for compliance notifications or board-meeting calendar context. The Customer's own credentials and accounts are used, and the Customer maintains its own relationship with each provider; these are not Proxara sub-processors.

The Customer's own providers. Under Proxara Connect, the Customer's own AI assistant receives the constructed release package, and the systems Proxara retrieves from (Microsoft 365 and any practice-management, tax, document-store, or CRM system the Customer connects) are the Customer's own providers rather than Proxara sub-processors. The Teams and Outlook integration listed above is a notification channel, separate from that retrieval.

Not sub-processors. OpenAI is not a Proxara sub-processor and no AI inference calls are made to OpenAI. Where a Customer connects ChatGPT as its AI assistant, OpenAI stands in the position described above.

Customers will be notified of any changes to subprocessors in accordance with the Data Processing Addendum. The current subprocessor list is maintained at Subprocessor List.

6.2 Customer-Managed Deployments

In Customer-Managed and MSP-Managed deployments, AWS is the Customer's own subprocessor, not Proxara's. Proxara acts solely as a software licensor and has no access to Customer Data.


7. Compliance Posture

The Service is designed to support Customers' compliance obligations across regulated industries. Proxara does not provide legal advice and does not guarantee compliance with any particular regulation. Customers are responsible for configuring the Service appropriately for their regulatory requirements.

The product tags each interaction record against controls across ISO 27001, GDPR/UK GDPR, the EU AI Act, NIST AI RMF, HIPAA, SEC Reg S-P, and FINRA as a built-in product feature supported by the signed control library.

7.1 Financial Services (FINRA, SEC)

The Service supports FINRA Rule 3110 (Supervision) and SEC Regulation S-P requirements by providing AI interaction monitoring, inline policy enforcement, and data protection controls. Section 2.7 describes the archive relationship.

Cryptographic audit proofs are archived to S3 COMPLIANCE Object Lock for 7 years, meeting the minimums under SEC Rule 17a-4(f), FINRA Rule 4511, and NYDFS 500.6.

7.2 Healthcare (HIPAA)

For healthcare Customers, a HIPAA Business Associate Agreement is available for Proxara-Managed deployments. The Service's redaction capabilities address HIPAA's 18 identifier categories. In the event of a breach involving Protected Health Information, Proxara will notify the affected Customer within 60 days in accordance with 45 CFR 164.410. For all other breach notifications, the 72-hour standard applies (see Section 9). In Customer-Managed deployments, Proxara is not a Business Associate because it does not create, receive, maintain, or transmit Protected Health Information.

The Service supports attorney-client privilege protection by preventing inadvertent disclosure of privileged information to external AI tools.

7.4 Accounting and Tax (IRC Section 7216)

The Service supports the firm's handling of tax return information by replacing taxpayer identifiers with stand-ins before material reaches external AI services, and, under Proxara Connect, by letting firm policy keep designated classes of substance inside the firm's environment entirely. Proxara enforces the firm's counsel-approved policy and narrows disclosure; it does not create or ensure compliance with Section 7216.

7.5 UK Data Protection

For UK-based Customers, the Service supports compliance with the UK GDPR and the Data Protection Act 2018. A Data Processing Addendum incorporating the UK International Data Transfer Addendum (IDTA) is available for international data transfers where applicable.


8. Data Subject Rights

8.1 End User Rights

End Users seeking to exercise data protection rights (access, correction, deletion, portability, objection) regarding data processed by the Service should contact their employer (the Customer), who is the data controller. Proxara will assist Customers in responding to data subject requests as described in the Data Processing Addendum, including through crypto-erasure of individual identity vault tokens (which destroys the key and makes the original unrecoverable) and automatic purge via the configured retention window.

There is no employee self-service data request portal in the Service. The Customer's compliance team initiates crypto-erasure and deletion on the End User's behalf.

8.2 California Residents

The Customer is the "business" under the CCPA/CPRA with respect to employee data processed by the Service. Proxara acts as a "service provider" in Proxara-Managed deployments. Proxara does not sell personal information. Proxara does not use personal information for purposes other than those specified in agreements with Customers.


9. Data Breach Response

In the event of a confirmed data breach involving Customer Data in a Proxara-Managed deployment:

  • Proxara will notify the affected Customer without undue delay and in any event within 72 hours of becoming aware of the breach (or, for breaches involving Protected Health Information, within 60 days per 45 CFR 164.410).
  • Proxara will provide all information reasonably necessary for the Customer to assess the breach and fulfill its own notification obligations.
  • The Customer remains responsible for notifying affected individuals and supervisory authorities as required by applicable law.

In Customer-Managed deployments, the Customer is responsible for breach detection and notification, as Proxara does not have access to the Customer's infrastructure.


10. Changes to This Policy

Proxara may update this Product Privacy Policy from time to time. Customers will be notified of material changes via email to the designated contact and by posting the revised policy on the website. Changes will not retroactively reduce the protections provided to data already processed.


11. Contact

For questions about this Product Privacy Policy, data subject requests, or privacy inquiries:

Proxara, Inc.

28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108

Email: support@proxara.ai

For security or vulnerability disclosures:

Email: security@proxara.ai