Proxo Ltd · Legal

Proxo — Privacy Policy

Last Updated: 2026-08-02

What this means for you (plain-language summary)

This Privacy Policy describes what Proxo collects, why, who we share it with, and what you can do about it. The short version:

  • We run two surfaces: the marketing website (proxo.ai), and the authenticated Platform (where your financial data lives). Different practices apply to each.

  • We use some third-party services. On the marketing website, we use third-party analytics, advertising, and mapping services (named in Sections 4 and 6) — only after you accept cookies. On the authenticated Platform, third-party telemetry is limited to our error-monitoring and aggregate operational-metrics providers. Customer financial data never reaches a marketing pixel.

  • We don't sell your personal data and we don't share it for advertising targeting.

  • AI processing runs primarily on models Proxo operates on its own or hosted infrastructure, and data processed by those models does not go to any third-party AI provider. Where a third-party AI provider is used, your data is handled under that provider's own terms, which may allow it to retain your data and use it for its own purposes — including to train and improve its models — for as long as it decides. We don't control that and we make no promises about it. Using the AI Features is how you authorize it; if that isn't acceptable, don't use them and talk to us instead (see Section 7.1). Proxo may develop and improve its own models using only de-identified, aggregated data — never data that identifies you or your organization. We also refine our prompts based on observed document patterns; that doesn't change model weights.

  • We retain data for at least one year after you close your account unless you request deletion; beyond that is at our discretion. You can request deletion where applicable law (GDPR / CCPA / etc.) gives you the right.

  • We are building in-app tools that will let you export and request deletion of your data; until they are available, email privacy@proxo.ai.

  • We're hosted in the United States. Cross-border transfers from the UK use the UK IDTA (or the UK Addendum to EU SCCs); from Canada, PIPEDA-compliant safeguards.

  • More detail is provided below.

1. Who We Are; Contact

This Privacy Policy is published by Proxo Ltd, a Cayman Islands exempted company ("Proxo," "we," "us," or "our"), the operator of the Proxo Platform.

  • Postal address: 103 South Church Street, PO Box 472, Grand Cayman KY1-1106, Cayman Islands

General contact:

  • Privacy / data-subject requests: privacy@proxo.ai (subject line: "Privacy")

  • Security: security@proxo.ai (subject line: "Security")

2. Scope

This Privacy Policy applies to (a) Proxo's marketing website at proxo.ai and related subdomains and pages (the "Marketing Website"); (b) the authenticated Proxo software-as-a-service platform (the "Platform"); (c) Proxo's mobile applications when available; (d) email communications between Proxo and you, including the receipts@proxo.ai pipeline when authorized by a customer; and (e) Proxo's presence on third-party social-media platforms.

This Privacy Policy does not apply to (a) data collected by third-party websites or services, including but not limited to those we link to but do not operate; (b) information collected by your employer (the customer organization); or (c) data collected by third parties that you or the customer organization independently authorizes to integrate with the Platform, as that collection and use is governed by their own privacy policies.

For a customer-authorized integration, the partner has two roles that both apply: it acts as an independent controller for its own purposes (governed by its own privacy policy), and, separately, as a sub-processor (listed in Section 6) for the specific data Proxo routes to it to operate the integration on the customer's behalf (governed by this Policy and our data-processing terms).

For Proxo's processing of personal data on behalf of customer organizations, the agreement between Proxo and the customer organization (including the Terms of Use) governs.

3. The Two Surfaces — and Why They Matter

Proxo operates two distinct surfaces with different data flows. Understanding the difference is the single most important thing in this Policy.

Marketing Website (proxo.ai) Authenticated Platform
Who visits Anyone, including prospective customers Authorized Users signed in to a customer account
What we collect Browsing analytics, conversion events, IP address, marketing-cookie preferences Customer Data (financial transactions, vendor records, uploaded documents), authentication events, in-product activity
Third-party telemetry Analytics, advertising, and mapping providers (subject to cookie consent) Error-monitoring and aggregate operational-metrics providers
Cookies Essential + analytics + marketing (banner-controlled) Essential session cookies only
Marketing tracking Yes, with your consent No, never

Customer financial data submitted to the Platform is never disclosed to a Marketing & Distribution subprocessor.

4. What We Collect

4.1 From visitors to the Marketing Website

When you visit the Marketing Website, we may collect:

  • Direct input through online forms (sign-up, contact, support, newsletter, demo request).

  • First-party cookies and local storage required for site navigation, sign-in session management, and user-interface preferences.

  • Server logs and error reports generated when your browser interacts with our servers, including HTTP request metadata (path, status code, response time, user-agent) and exception traces (via our error-monitoring provider).

  • IP address, used (a) to provide the site, (b) for security anomaly detection, and (c) for approximate (city/region) geolocation via a third-party IP-geolocation service. We do not collect device-precise GPS coordinates.

  • Device and browser metadata (operating system, browser, browser version).

  • Marketing analytics, with your consent: Meta Pixel events, Google Analytics 4 events, Google Ads conversion events.

  • Embedded Google Maps: standard browser-Google interactions when a page contains a map (subject to Google's own privacy policy).

4.2 From Authorized Users of the authenticated Platform

When you (an Authorized User of a customer organization) use the Platform:

  • Identification and contact data: name (encrypted at rest), email address (encrypted at rest), phone number (encrypted), profile photo, organization, job title, role assignment.

  • Account credentials: OAuth identity references (Google or Microsoft), encrypted TOTP secret, optional WebAuthn public-key references. Proxo does not store user-managed passwords.

  • In-product activity: actions you take within the Platform (creating, editing, archiving cash flows, etc.); navigation paths within the Platform.

  • Audit-log data: actor, timestamp, action, entity affected, before/after field values (for change-tracking).

  • Authentication events: sign-in, sign-out, 2FA events, security-key challenges.

  • Customer Data (entered by you or your colleagues) — as defined in the Terms of Use: cash-flow records, recurring-transaction templates, vendor / counterparty records, approval-chain configurations, uploaded financial documents (receipts, invoices, bank statements), email contents and attachments forwarded to receipts@proxo.ai (when that pipeline is enabled by the customer organization), AI-feature prompt and response content.

  • Banking and financial-account details: For accounts linked via Plaid, we receive institution name, account type, and a last-four mask only — never the full account number; Plaid handles credential authentication and provides Proxo with metadata and transactions as authorized. For bank-account, vendor, and counterparty details you enter directly into the Platform, we store the full bank account numbers, routing numbers, and tax identification numbers (which for some counterparties may be a personal tax identifier), encrypted at rest using strong, industry-standard encryption and displayed masked to the last four digits in the interface. We do not store full payment-card numbers or card security codes (see §4.3).

  • Integration data (when the customer organization authorizes a third-party integration): OAuth tokens (encrypted), accounting-system identifiers, integration-cursor metadata.

  • Technical data: IP address (stored in session records), browser type, operating system, session metadata.

4.3 What we do NOT collect

  • We do not collect biometric data — no facial recognition, no fingerprints, no voice prints. Plaid (when authorized by a customer to link bank accounts) does not collect biometric data on Proxo's behalf; Proxo does not use Plaid Identity Verification.

  • We do not collect device-precise GPS coordinates.

  • We do not store full payment-card numbers (only the last four digits, for display); payment processing is handled by our third-party payment processor, Stripe, Inc.

  • We do not collect health information, genetic data, or other "special category" data under EU GDPR Article 9.

  • We do not knowingly collect personal data from children under 18.

5. How We Use Your Information

5.1 To provide and operate the Platform

  • Account administration, authentication, and access management.

  • Ingesting, storing, retrieving, and displaying Customer Data.

  • AI-assisted extraction of structured data from uploaded documents.

  • AI-assisted conversational interaction with Customer Data (subject to the preview-then-confirm protocol).

  • Integration with Customer-authorized third-party services.

  • Transactional communications (email, in-product notifications).

  • Subscription billing.

5.2 To secure the Platform

  • Security monitoring, anomaly detection, incident response.

  • Audit-log generation and retention.

  • Rate limiting and abuse prevention.

  • Fraud and abuse investigation.

5.3 To improve the Platform

  • Aggregated analytics about Platform usage for capacity planning, billing, and product improvement.

  • Refinement of prompts, instructions, few-shot examples, and post-processing logic for AI Features, based on observed patterns in Customer Documents and on Authorized-User feedback. (Prompt refinement does not change model weights; model training is governed by Section 7.)

  • Development and improvement of Proxo's own self-hosted AI models, using only de-identified Customer Data and aggregated usage patterns (see Section 7).

  • Beta and pre-release features (optional). An Authorized User may opt in to a private beta program to use experimental features before general release. When you opt in, we may collect additional usage data and feedback about those specific features to evaluate and improve them. Participation is voluntary, is off by default, requires your explicit opt-in, and may be withdrawn at any time in your account settings. Opting in does not change how your Customer Data is stored, secured, retained, or disclosed, and beta-feature usage data is never disclosed to a Marketing & Distribution subprocessor.

5.4 To market our service

  • Paid customer acquisition (Google Ads, Meta Ads), based on the marketing-side analytics described in Section 4.1.

  • Outbound product marketing emails (if you opt in or are a customer; you can unsubscribe at any time).

  • Conversion tracking for paid campaigns.

5.5 To meet our legal obligations

  • Compliance with applicable financial-record retention laws (applied to Proxo's own books and records — not as a customer-data-archive service; see Section 9).

  • Response to legal process (subpoenas, court orders) and regulatory requests.

  • Enforcement of the Terms of Use and other agreements.

5.6 Lawful bases (EU GDPR and UK GDPR)

Where EU GDPR or UK GDPR applies to our processing, our lawful bases are:

  • Performance of a contract (Article 6(1)(b)) for processing necessary to provide the Platform to the customer organization or to take steps at the data subject's request.

  • Legitimate interests (Article 6(1)(f)) for security, fraud prevention, network and information security, internal administration, and product improvement — balanced against the data subject's interests.

  • Legal obligation (Article 6(1)(c)) for compliance with applicable law.

  • Consent (Article 6(1)(a)) for marketing communications, for marketing cookies, and for participation in the optional beta-features program; consent may be withdrawn at any time.

6. Marketing & Distribution Subprocessors vs Authenticated Platform Subprocessors

We use third-party sub-processors in two groups: those loaded on our public Marketing Website, and those used inside the authenticated Platform. Marketing-Website trackers are named below (they run in your browser and are identified in our cookie notice). For the authenticated Platform, we disclose the categories of sub-processors below; a current named list is available to customers on request, under NDA or their data-processing agreement.

6.1 Marketing & Distribution subprocessors

Loaded on the Marketing Website and in our mobile apps. Never loaded on authenticated Platform routes. Customer Data is never disclosed to them.

  • Meta Platforms, Inc. — Meta Pixel for marketing-site conversion tracking; Meta Ads for paid customer acquisition; Facebook and Instagram organic social presence. Loaded after cookie-banner consent.

  • Google LLC — Google Analytics 4 — aggregated marketing-website analytics. Loaded after cookie-banner consent.

  • Google LLC — Google Ads — paid customer acquisition and conversion tracking. Loaded after cookie-banner consent.

  • Google LLC — Google Maps — embedded maps showing office, event, and partner locations.

  • Apple Inc. — App Store and Google LLC — Google Play — distribution channels for the Proxo mobile apps (when available).

6.2 Authenticated Platform subprocessors

Used inside the Platform. We disclose these by category; the current named list is available to customers on request, under NDA or their data-processing agreement. No marketing-analytics tool is loaded inside the Platform. Our error-monitoring and operational-metrics providers receive error reports and aggregate telemetry — never transactional financial data — and may capture a small sample of masked browser-session replays for debugging as described in Section 6.3.

  • Cloud hosting & managed database — application hosting and managed PostgreSQL.

  • Object storage & transactional email — encrypted file/object storage and outbound + inbound transactional email.

  • Payment processing — subscription billing and credit top-ups.

  • AI extraction & assistant — AI-assisted document extraction and conversational features. Where a third-party AI provider is used, Customer Data sent to it is processed, retained, and used under that provider's own terms, which may permit the provider to retain that data and use it for its own purposes, including training and improving its models, for periods Proxo does not control. To that extent the provider acts as an independent controller of that data, not solely as our processor. Some AI processing runs on Proxo's own self-hosted models and never leaves Proxo-controlled infrastructure (see §7).

  • Bank connectivity — customer-authorized bank-account connection.

  • Identity / OAuth — sign-in identity providers.

  • Error monitoring & operational metrics — aggregate telemetry only; no Customer Data.

  • Security & compliance tooling — e.g., IP-address geolocation for security anomaly detection and security-compliance automation; no Customer Data.

  • Customer-authorized integrations — accounting, expense-management, and messaging tools you choose to connect.

6.3 Tools NOT in use anywhere

We do not use PostHog, Hotjar, FullStory, Adobe Analytics, LinkedIn Insights, or any marketing-analytics tool inside the authenticated Platform. Our error-monitoring provider may record a small sample of browser-session replays solely to help us diagnose errors and usability problems; replays are captured with all text masked and all media blocked before leaving your browser, are governed by the provider's processing terms (see Section 6), and are never used for advertising, profiling, or audience building. We do not maintain a relationship with any data broker, advertising network, or audience-resale platform that would receive Customer Data.

6.4 Subprocessor change notice

Enterprise customers are notified at least thirty (30) days before a new Authenticated Platform subprocessor goes live, and may object on data-protection grounds (with the right to terminate if the objection is reasonable and unresolved). The current named list of Authenticated Platform subprocessors is available to enterprise customers on request or through their data-processing agreement. Other customers can subscribe to change notifications by emailing privacy@proxo.ai.

7. Artificial Intelligence

The Platform includes AI Features (document extraction; conversational interaction; bulk actions on Customer Data). These rules apply:

7.1 First-party processing. AI processing runs primarily on models Proxo itself operates on infrastructure Proxo controls — its own hardware or hosted compute capacity it provisions. Customer Data processed by those models does not leave that infrastructure and is not made available to any third-party AI provider.

Third-party AI providers. Proxo may also use one or more third-party AI providers — for example, as a fallback for capacity or capability, or to deliver a specific AI Feature. Where Proxo does so, the data sent to that provider is processed, retained, and used in accordance with that provider's own terms and policies. Those terms may permit the provider to retain that data and to use it for the provider's own purposes, including to develop, train, and improve the provider's models, for periods that provider determines. Proxo does not control those practices, and makes no promise that data sent for inference is deleted after the request completes, is withheld from training, or is retained for any particular period. To the extent a provider uses that data for its own purposes, it acts as an independent controller of it rather than solely as our processor.

How this is authorized, and how to avoid it. By using the AI Features, the customer organization authorizes and instructs us to send Customer Data — including personal data within it — to third-party AI providers on this basis, and confirms it has the rights and permissions needed to do so. If your organization cannot permit that, do not use the AI Features and contact us at privacy@proxo.ai about a configuration that does not rely on a third-party AI provider. Enterprise customers may address zero-data-retention, no-training, or first-party-only processing in a Master Services Agreement.

7.2 Proxo first-party model development. Proxo may develop, train, fine-tune, evaluate, and improve models that Proxo itself operates, using only (a) de-identified Customer Data — Customer Data from which direct identifiers (including names, email addresses, phone numbers, bank-account and routing numbers, and tax identification numbers) have been removed, masked, or pseudonymized such that the data no longer identifies you, your organization, or any individual; (b) aggregated usage statistics; and (c) Authorized-User feedback on AI Outputs. De-identified training data is never shared with any third-party model provider, and we maintain technical and organizational safeguards designed to prevent a Proxo-operated model from reproducing one customer's data in output shown to another customer. We do not use Customer Data that has not been de-identified to train, fine-tune, or update the weights of any Proxo-operated model. This Section 7.2 describes what Proxo does; a third-party AI provider's use of data sent to it is governed by Section 7.1.

7.3 Prompt refinement is permitted. We may refine the prompts, instructions, few-shot examples, and post-processing logic that drive the AI Features, based on observed patterns in Customer Documents (such as common receipt layouts, statement formats, merchant naming conventions, and common extraction errors) and on Authorized-User feedback on specific AI Outputs (e.g., a corrected value submitted via an in-product feedback control). Prompt refinement improves how we invoke existing models; it does not change model weights and is not "training."

7.4 Preview-then-confirm. When an AI Feature is asked to create, update, or archive data on your behalf, the Platform shows you a preview of the proposed action and requires your explicit confirmation before executing. The Authorized User confirming the preview is responsible for the action. Every AI-initiated action is recorded in our audit log.

7.5 Automated decisions and autonomous operation. By default, AI Features act only after the preview-then-confirm step in Section 7.4 — a human decides. Your organization may expressly opt in to fully-autonomous operation of designated financial workflows within limits it defines; that consent is explicit, scoped, revocable at any time, and every autonomous action is recorded in the audit log — until it is given, every AI-initiated action requires human confirmation. Where an automated decision would produce legal or similarly significant effects concerning you as an individual, we ensure meaningful human involvement or rely on explicit consent together with your right to obtain human intervention, express your point of view, and contest the decision (see Section 12 for your rights).

7.6 AS IS. AI Outputs are generated probabilistically and may contain errors, omissions, or biases. You are responsible for evaluating AI Outputs before relying on them. AI Outputs do not constitute legal, financial, accounting, tax, medical, or other professional advice.

7.7 Operational telemetry. We may collect de-identified, aggregated operational telemetry about AI Feature usage (counts of extraction calls, model error rates, latency, throughput) to evaluate and improve operational reliability.

8. Cookies and Similar Technologies

8.1 On the Marketing Website

We use three categories of cookies on the Marketing Website, controlled by our Consent Management Platform (cookie banner):

  • Essential cookies — always on. Required for site navigation and basic functionality.

  • Analytics cookies — Google Analytics 4. On only after you accept analytics cookies via the cookie banner.

  • Marketing cookies — Meta Pixel, Google Ads conversion pixels. On only after you accept marketing cookies via the cookie banner.

You may withdraw or modify your consent at any time from the cookie preferences link in the site footer. Disabling essential cookies will prevent the Marketing Website from functioning.

8.2 On the authenticated Platform

The authenticated Platform uses only essential session cookies required for sign-in session management and user-interface preferences (active organization, display-currency toggle, sidebar collapse, theme). No marketing or analytics cookies are loaded on the authenticated Platform.

8.3 Do Not Track signals

We do not respond to browser "Do Not Track" signals because there is no industry-standard interpretation. You can control cookie behavior through your browser settings and through our cookie banner.

8.4 California "Do Not Sell or Share" / Global Privacy Control

We do not sell or share personal information for advertising. If you transmit a Global Privacy Control (GPC) signal, we will treat that signal as a request to opt out of any sharing that would otherwise occur under California's CCPA / CPRA — although as noted, we don't engage in such sharing.

9. Retention

9.1 Default retention

Our default retention is approximately 500 days after account closure or termination of the customer organization's subscription, with a warning sent to the organization's owners roughly 30 days before permanent deletion. Retention for backups, archives, audit logs, security investigations, or legal holds is at our discretion and not a customer-facing commitment.

Specific defaults:

  • Customer Data (cash flows, recurring transactions, vendors, attachments) — retained while the subscription is active, plus approximately 500 days after account closure. A warning is sent 30 days before permanent purge.

  • Authorized-User account profiles — same as Customer Data.

  • Audit logs — at least one (1) year.

  • Server logs and error-monitoring telemetry — 90 days.

  • Inbound and outbound email metadata (subject, sender, recipient, timestamps; no email bodies) — one (1) year.

  • Marketing-site analytics (cookie-based) — per Google / Meta's respective default retention periods.

9.2 Customer responsibility for records retention

Many of our customers are subject to financial-record retention requirements (Sarbanes-Oxley, IRS, equivalent rules) that exceed the defaults above. We provide in-app and API data-export tools so that customers can maintain their own long-term records archive. Customers needing long-term records retention should export their data periodically and before account closure if they need it for their own compliance.

9.3 Customer-initiated deletion

We honor customer-initiated deletion requests where required by applicable law (including GDPR Article 17, CCPA section 1798.105, equivalent US-state laws, UK GDPR, PIPEDA). We will fulfill in-scope deletion requests within thirty (30) days (forty-five (45) days for complex requests under GDPR / CCPA). Outside those legal triggers, we are not obligated to delete on request.

9.4 Self-service export and deletion (in-app)

The Platform is being developed to include in-app self-service tools allowing Customer Administrators to (a) export their organization's data in a machine-readable format, and (b) submit deletion requests for the legally-required categories described above. Until those tools are released, requests are processed via privacy@proxo.ai.

9.5 Proxo's own records

Our own books and records (Proxo's internal accounting, tax records, employment records, vendor contracts) are retained separately for the period required by applicable law. These are Proxo's own records and are distinct from Customer Data.

10. Disclosure of Your Information

We share personal data with the following categories of recipients, and only as needed for the purpose described:

  • Within the customer organization — Customer Data is visible to other Authorized Users of the same customer organization in accordance with the role-based access controls the organization itself configures.

  • Subprocessors — the subprocessors listed in Section 6, each strictly to provide the operational service described.

  • Integration partners chosen by the customer — when the customer organization authorizes an integration, we share with that partner the data the integration requires.

  • Professional advisors — our outside legal counsel, accountants, auditors, and other professional advisors, subject to confidentiality obligations.

  • Legal compliance and protection of rights — when required by law, regulation, legal process, or governmental request, or when reasonably necessary to protect the rights, property, or safety of Proxo, our customers, or the public.

  • Corporate transactions — in the event of a merger, acquisition, financing, reorganization, sale of assets, or insolvency, personal data may be transferred to the successor entity. The customer organization will be notified.

  • With consent — with any other party at the customer organization's direction.

We do not sell or share personal data for advertising. We do not sell personal data, share personal data for cross-context behavioral advertising, or otherwise disclose personal data to third parties for their independent marketing purposes.

11. International Transfers

The Platform is hosted in the United States. If you access the Platform from outside the United States, your personal data will be transferred to, stored in, and processed in the United States.

  • United Kingdom: For personal data transferred from the United Kingdom to the United States, we rely on the UK International Data Transfer Agreement (IDTA) issued by the UK Information Commissioner, or on the UK Addendum to the European Commission's Standard Contractual Clauses.

  • Canada: For transfers from Canada to the United States, we rely on the contractual safeguards required under PIPEDA.

  • European Economic Area and Switzerland: We do not actively offer the Platform to customers established in the EEA or Switzerland. Where an EEA- or Swiss-established customer nonetheless accesses the Platform, we will rely on the European Commission's Standard Contractual Clauses (Module 2 — Controller-to-Processor) on a case-by-case basis.

A copy of the relevant transfer instrument is available on request from privacy@proxo.ai.

12. Your Rights

Subject to the laws applicable to you, you may have the following rights:

  • Access the personal data we hold about you.

  • Correct inaccurate or incomplete personal data.

  • Delete your personal data (where applicable law gives you the right; see Section 9.3).

  • Restrict or object to processing.

  • Portability — receive a copy of your personal data in a machine-readable format.

  • Withdraw consent (where consent is the lawful basis).

  • Opt out of certain processing (e.g., marketing communications, marketing cookies, sale or sharing of personal information).

  • Not be subject to automated decision-making producing legal or similarly significant effects (see Section 7.5 — we don't do this).

  • Complain to a supervisory authority (e.g., the UK ICO, the Office of the Privacy Commissioner of Canada, your US state attorney general).

  • Not be discriminated against for exercising your rights.

12.1 Specific US-state rights

US state privacy laws apply based on where you reside, not where Proxo is incorporated. Because Proxo offers the Platform to customers and Authorized Users located in the United States, these laws apply to our processing of covered US residents' personal data even though Proxo is a Cayman Islands company. Residents of the following US states have additional rights under their respective comprehensive privacy laws. The full list of US state privacy laws applicable to our processing (as effective from time to time) includes:

  • California — CCPA / CPRA

  • Virginia — VCDPA

  • Colorado — CPA

  • Connecticut — CTDPA

  • Utah — UCPA

  • Texas — TDPSA

  • Oregon — OCPA

  • Florida — FDBR

  • Montana — MCDPA

  • Iowa — ICDPA

  • Tennessee — TIPA

  • Delaware — DPDPA

  • Nebraska — NDPA

  • New Jersey — NJDPA

  • Minnesota — MCDPA

  • Maryland — MODPA

  • Kentucky — KYCDPA

  • Rhode Island — RIDPA

  • Indiana — INCDPA

In each case, the rights you have are those granted by the applicable state law; not every right is available in every state. We will respond to a verifiable consumer request from a covered resident within the time period required by the applicable law (typically 30–45 days).

12.2 UK GDPR

When we process personal data of individuals in the United Kingdom in connection with the Platform, we do so as a processor on behalf of the customer organization (which is the data controller). To exercise your rights, you may contact the customer organization that uses Proxo on your behalf, or contact us directly at privacy@proxo.ai and we will forward your request to the relevant customer organization where required.

The UK Information Commissioner's Office (https://ico.org.uk) is the supervisory authority for UK personal data.

12.3 PIPEDA

When we process personal data of individuals in Canada, you have rights under the Personal Information Protection and Electronic Documents Act. You may exercise those rights by contacting us at privacy@proxo.ai. The Office of the Privacy Commissioner of Canada is the federal supervisory authority.

12.4 EU GDPR (out of scope for primary market)

We do not actively target the EU as a primary market. Where EU GDPR applies (because an EEA-established customer accesses the Platform), the rights and procedures described in Section 12.2 (substituting your EEA Member State's supervisory authority for the UK ICO) apply, and our cross-border transfer mechanism is the EU SCCs as described in Section 11. We have not appointed a representative under EU GDPR Article 27 at this time; we will do so if our EEA customer base reaches a level where Article 27 applies.

12.5 How to exercise your rights and opt out

You can exercise any of the rights above, and control how we use your information, as follows:

  • Data-subject requests (access, correction, deletion, portability, restriction, objection): email privacy@proxo.ai with the subject line "Privacy – Data Subject Request," telling us which right you want to exercise. We may need to verify your identity (for example, by confirming the email address associated with your account). We will respond within the time required by the law that applies to you (typically 30–45 days; where the law allows an extension, we will tell you).

  • Marketing emails: use the "unsubscribe" link in any product-marketing email, or email privacy@proxo.ai. Transactional and security messages cannot be turned off while your account is active.

  • Cookies and web tracking: use the cookie banner on proxo.ai to accept or reject analytics and marketing cookies at any time (see Section 8). Essential cookies cannot be disabled.

  • "Do Not Sell or Share" and Global Privacy Control: we do not sell your personal data or share it for cross-context behavioral advertising, and we honor Global Privacy Control (GPC) browser signals as a valid opt-out where required (see Section 8.4).

  • Withdraw consent: where we rely on your consent, you may withdraw it at any time; this does not affect processing already carried out.

  • Appeal: if we decline your request, you may appeal by replying to our response or emailing privacy@proxo.ai with the subject line "Privacy – Appeal." Where your state law provides an appeal right, we will respond within the statutory timeframe and tell you how to contact your state attorney general if you remain unsatisfied.

  • Data a customer organization entered about you: for most Platform data, the customer organization that uses Proxo is the controller and Proxo acts as its processor. Contact that organization directly, or email us and we will route your request to it.

We will not discriminate against you for exercising any of these rights.

13. Security

We maintain administrative, technical, and physical safeguards to protect personal data, including:

  • TLS 1.2+ for all browser-to-server and server-to-subprocessor communications.

  • Strong, industry-standard application-layer encryption for sensitive fields (email addresses, names, phone numbers, postal addresses, bank-account numbers, routing numbers, OAuth tokens).

  • OAuth-only sign-in (no user-managed passwords) plus mandatory two-factor authentication — a TOTP authenticator code or a hardware security key — with hardware security keys (FIDO2 / WebAuthn) required for administrator accounts.

  • Role-based access controls; least-privilege access for Proxo personnel; cross-organization access by Proxo employees logged in an immutable audit trail.

  • Continuous error and security monitoring and operational-metrics monitoring via our third-party monitoring providers; anomaly detection; rate limiting.

  • SOC 2 program managed via a third-party compliance-automation platform (in progress).

We will notify you (via the customer organization's billing contact) without undue delay after we confirm a security incident affecting your personal data, and in any event within the time required by applicable law.

No system is perfectly secure. The transmission of information over the internet is not completely secure, and we cannot guarantee absolute security.

14. Marketing Communications

We send transactional emails (account-related notifications, billing notices, security alerts) to all customers; these cannot be disabled while you have an active account. We may also send product-marketing emails (product updates, newsletters, event invitations); you can unsubscribe from these at any time using the unsubscribe link in the email.

15. Social Media

When you interact with our content on third-party social-media platforms (LinkedIn, X / Twitter, YouTube, Facebook, Instagram), those platforms collect data about you in accordance with their own privacy policies. We may receive aggregated or limited identifying information from those platforms (e.g., when you message us or interact with an ad). For YouTube specifically, data collection and consent are governed by YouTube's Terms of Service and Google's Privacy Policy.

16. Children

The Platform is a business-to-business service. The Platform is not directed to children under the age of 18, and we do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal information from a child under 18, we will delete that information promptly. If you believe we have collected information from or about a child under 18, please contact us at privacy@proxo.ai.

17. Changes to This Privacy Policy

We may revise this Privacy Policy from time to time. The current version is always posted at https://proxo.ai/legal/privacy. Material revisions (revisions that materially expand the categories of personal data we collect, the purposes of processing, or the recipients of personal data, or that materially restrict your rights) will be notified to the customer organization's billing contact by email at least thirty (30) days before they take effect. A changelog of material revisions is posted at https://proxo.ai/legal/changelog#privacy.

18. Contact

Privacy questions and data-subject requests: privacy@proxo.ai (subject "Privacy").

Proxo Ltd, 103 South Church Street, PO Box 472, Grand Cayman KY1-1106, Cayman Islands.

End of Privacy Policy.