Privacy notice.
Praxa builds AI operators that execute administrative work inside US health systems. That means two very different kinds of information sit near each other: ordinary business data about people who visit this website or talk to us, and protected health information that belongs to a health system and that we only ever touch under that health system's instruction. This notice is about the first kind. The second kind is governed by a signed agreement, not by a web page.
Two kinds of data, deliberately kept apart.
This notice is intended to cover two things, and only two things: the Praxa AI website at praxaai.ai, and the corporate relationship — the information we hold about prospective and current customer contacts, design partners, candidates, vendors, investors and anyone else who deals with the company directly.
It is not intended to govern protected health information. When a Praxa operator reads a referral packet or files an appeal, it is acting on a health system's records, inside that health system's systems, on that health system's instruction. In that work Praxa is a service provider to a covered entity, not the owner of the record — so the rules that apply come from the signed agreement with that customer, not from this page.
Track A
Website and business-contact data
Information about you as a site visitor, a business contact, or a candidate. Praxa decides what is collected, why, and for how long.
This is the data this notice is about.
Governed byThis notice, once counsel has finalised it
Track B
Protected health information
Patient information that a health system holds and that Praxa processes on its behalf, only for the workflows that customer has asked us to run.
Praxa does not decide what happens to it. The covered entity does.
Governed byThe Business Associate Agreement and any data processing terms signed with that customer [PLACEHOLDER — confirm with counsel: exact names of the operative agreements]
If you are a patient
Praxa has no direct relationship with the patients whose records its operators touch, and cannot answer requests about an individual record on its own initiative. Requests about your health information should go to the health system, clinic or insurer that holds it. They will direct us if action is required on our side.
What this website collects, and why.
Information you give us
This site has no account system and no forms that store data on our side. The way to reach us is email. If you write to us — to request a demo, to ask about a workflow, or to apply for a role — we hold what you send: your name, the address you wrote from, your organisation and title if you mention them, and the content of the message and any attachment.
We use it to reply, to evaluate whether there is a fit, and to keep a record of the conversation. [PLACEHOLDER — confirm with counsel: the full list of stated purposes, and whether any of them require a separate legal basis or consent]
Information collected automatically
Serving a page necessarily involves a request log. A request to this site can record your IP address, the approximate time, the page requested, the referring page, and your browser's user-agent string. That is how the site gets delivered and how abuse and outages get diagnosed; it is not used to build a profile of you.
Retention of those logs: [PLACEHOLDER — confirm with counsel: log retention period, who holds the logs, and whether that period is stated publicly or on request]
Candidate information
If you apply for a role, we hold your application materials and our notes on the process. Candidate data is handled separately from customer and marketing contacts. Retention of unsuccessful applications: [PLACEHOLDER — confirm with counsel: candidate data retention, and whether consent is required to keep an application on file]
Service providers
Running a website and a company means other companies process some of this data on our behalf — hosting, email, and the ordinary back-office tools any company uses. We are not naming them on this page yet, because a list that is wrong or out of date is worse than no list.
[PLACEHOLDER — confirm with counsel: whether a subprocessor list is published here, provided on request, or attached to the customer agreement — and who owns keeping it current]
Legal framework
Praxa is a US company serving US health systems, so the primary frame is US federal and state privacy law. Which specific state statutes apply, and whether any non-US regime is engaged by visitors from outside the United States, is a question for counsel rather than for a designer.
[PLACEHOLDER — confirm with counsel: applicable state privacy statutes, whether GDPR or UK GDPR is engaged, and the legal bases or business purposes to state for each processing activity]
What this website does not collect.
Saying what a site does not do is usually more useful than the list of what it does. The following is the intent for this website, and each line should be re-verified against the shipped build before launch.
- No protected health information. Nothing on this site is designed to receive PHI, and PHI should never be sent to us through this website or by ordinary email. If you need to share patient information, that happens inside an agreed, secured channel under a signed agreement — not here.
- No patient, clinical, claims or eligibility data. This site holds no records of care, no coding data, no remittances and no payer data.
- No payment card details. There is nothing to buy on this site and no payment form on it.
- No third-party advertising or analytics scripts. The build ships one external resource — the web font stylesheet described in section 05 — and its content security policy blocks third-party scripts outright.
- No advertising cookies and no cross-site tracking. As built, this site sets no cookies at all and writes nothing to your browser's storage. Dismissing the banner at the top of the page lasts until you reload it, because nothing is saved.
- No sale of personal information. Intent: Praxa does not sell personal information collected through this site and does not share it for cross-context behavioural advertising. [PLACEHOLDER — confirm with counsel: the exact statutory wording required, and whether a "Do Not Sell or Share My Personal Information" link must appear in the footer]
PHI is our customer's data. We act under instruction.
A Praxa operator does its work inside a customer's environment, on the customer's records, for the workflows that customer has asked us to run. In that arrangement the health system is the covered entity and the owner of the record; Praxa is its service provider. We do not acquire PHI for our own purposes, and we do not decide what may be done with it.
The terms that actually matter for that work are in the signed agreement, not on this page. A Business Associate Agreement is the document that sets permitted and required uses, the safeguards we are obliged to maintain, what happens on termination, and what we owe the customer if something goes wrong.
What the signed agreement governs, not this page
- Permitted uses and disclosures. Scoped to the workflows in the order form, and no wider.
- Minimum necessary. Which fields an operator may read for a given workflow, and how that is enforced technically.
- Safeguards. The administrative, physical and technical controls we are contractually obliged to maintain.
- Incident and breach notification. What we must report, to whom, and how quickly. [PLACEHOLDER — confirm with counsel: notification timelines exactly as they appear in the executed BAA. Do not state a number that is not in the agreement.]
- Subcontractors. Whether a subcontractor may touch PHI at all, and the flow-down obligations if one does. [PLACEHOLDER — confirm with counsel: current position on subcontractor access to PHI]
- Return and destruction. What happens to data at the end of the relationship. [PLACEHOLDER — confirm with counsel: return or destruction obligations and any retention required by law]
- Individual rights. How we support the covered entity in answering a request for access, amendment, restriction, or an accounting of disclosures.
Individual requests about PHI
Praxa cannot act unilaterally on an individual's PHI. If you are a patient, a request for access, correction or an accounting goes to the organisation that holds your record; if that organisation asks us to assist, we assist under the terms of our agreement with them. If you are a customer and you need our help answering such a request, your usual Praxa contact is the fastest route.
Model training
Whether, and on what terms, customer data may ever be used to improve a model is one of the most consequential questions a company in this position can answer, and it is not one to answer casually in a footer. Intent: nothing is used beyond the scope the customer has agreed in writing.
[PLACEHOLDER — confirm with counsel and engineering: the exact position on training, fine-tuning, evaluation, de-identification and aggregate reporting, and where that position is stated contractually]
Cookies, fonts and analytics.
Cookies
As built, this site sets no cookies. There is no consent banner because, as shipped, there is nothing to consent to. If that changes — if analytics, a chat widget, or a marketing tag is ever added — this section and the site's consent mechanism have to change at the same time, and that is a launch gate rather than an afterthought.
Web fonts
The one third-party resource this site loads is its typefaces, served from Google's font hosts. Requesting a font file necessarily discloses your IP address and user-agent to that host, which is a transfer of personal data even though nothing is stored on our side.
[PLACEHOLDER — confirm with counsel: whether third-party font hosting requires disclosure or consent for the visitor populations this site serves, and whether the fonts should instead be self-hosted to remove the transfer entirely]
Analytics
There is no analytics product on this site today. If one is adopted, the intent is to choose something that can run without cross-site identifiers, and to say plainly here what it collects.
[PLACEHOLDER — confirm with counsel: analytics vendor, what it collects, retention, and the disclosure and opt-out mechanism required]
Do Not Track and global privacy signals
[PLACEHOLDER — confirm with counsel: whether the Global Privacy Control signal must be honoured, and the statement required about Do Not Track]
Your rights and choices.
Depending on where you live, you may have rights over the information described in section 02 — typically the right to know what is held, to get a copy, to have it corrected, to have it deleted, to opt out of certain uses, and to appeal a refusal. Which of those you have, and what we are required to do about them, depends on the law that applies to you.
This draft does not state a response window, because a company should not promise a timeline it has not built the process to meet.
To be specified before publication
- The exhaustive list of rights, per applicable statute. [PLACEHOLDER — confirm with counsel]
- How a request is submitted, and the identity-verification step. [PLACEHOLDER — confirm with counsel]
- The acknowledgement and response windows, and any permitted extension. [PLACEHOLDER — confirm with counsel]
- The appeal route if a request is refused, and the regulator a complaint may be taken to. [PLACEHOLDER — confirm with counsel]
- Whether an authorised agent may submit a request on your behalf, and what proof is required. [PLACEHOLDER — confirm with counsel]
- Whether an EU or UK representative, or a data protection officer, must be appointed and named. [PLACEHOLDER — confirm with counsel. No name or address is stated in this draft because none has been confirmed.]
Rights over health information
Rights over PHI are exercised with the covered entity that holds the record, as described in section 04. They do not run through this page.
How we protect information.
Security is described where it belongs — on the security page, alongside how operators are isolated, what gets logged, and how a customer reviews what an operator did. This page makes no certification or audit claim, because a privacy notice is the wrong place to make one and because a claim like that has to be backed by a current report.
No system is perfectly secure. What a company can reasonably commit to is a stated control environment, evidence that it is in place, and honest disclosure when something goes wrong — and those commitments live in the customer agreement and the security documentation, not here.
[PLACEHOLDER — confirm with counsel: the security statement appropriate for a privacy notice, and whether any breach-notification duty to non-customer individuals must be described]
Changes, and how to reach us.
Changes to this notice
When this document is finalised it will carry a real date at the top, and a material change should be visible rather than silent. How a change is communicated — a revision history on this page, a notice to customers, or both — is a decision to make once, and keep to.
[PLACEHOLDER — confirm with counsel: change-notification method, whether a version history is published, and the effective-date convention]
Contact
Until a dedicated privacy mailbox exists, the general company address is the honest route. Do not send protected health information or other sensitive personal data by email.
[PLACEHOLDER — confirm with counsel: the privacy contact mailbox to publish, the legal entity name and postal address, and whether a regulator complaint route must be listed]
Reminder
This document is a draft pending legal review and is not in force. It creates no rights and no obligations. If you need to know how Praxa handles information in a live engagement, ask for the current signed agreement.