1. Data Controller
In accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and the Luxembourg Act of 1 August 2018 on data protection, the data controller is:
Gideon Abutu (Manager)
PRAIX S.à r.l.
RCS Luxembourg: B311282
2 Rue Jean Engling, 1466 Dommeldange, Luxembourg
Email: legal@praixagent.com
Phone: +352 661 313 519
2. What We Collect
We collect and process the following data as part of providing our services:
Account data:
• Name, surname, email address, phone number, company details.
Usage data:
• IP address, browser type, operating system, pages visited, access timestamps.
Voice & call data (processed on your behalf):
• Where you use our platform as a business customer, the voice recordings and transcripts produced by your AI agents are processed by us strictly on your behalf, as your data processor, under our Data Processing Agreement — not for our own purposes.
Telephony data:
• Phone numbers used, call duration, call metadata.
Billing data:
• Payment information handled directly by our payment processor. We never store full card numbers.
3. Why We Process It, and On What Basis
Your data is processed for the following purposes:
• To provide the Service (performance of our contract with you): running your account, your agents, and your calls.
• To keep things running well (our legitimate interest): security, fraud prevention, product improvement, analytics.
• Because the law requires it (legal obligation): Luxembourg and European accounting, tax, and regulatory obligations.
• Because you said yes (consent): marketing communications, and any optional cookies you accept.
4. Our Partners
To provide the Service, we partner with a number of external software providers — for things like voice processing, telephony, and payments. You can see the current list of our partners any time by downloading it below.
Some of these partners process data in real time outside the European Economic Area, including in the United States. Where that happens, it is covered by the EU-US Data Privacy Framework, Standard Contractual Clauses, or an equivalent EU-recognized transfer mechanism. Call recordings and transcripts are stored on our servers in France.
5. How Long We Keep It
Your personal data is retained for the following periods:
• Account data: while your account is open, then deleted within 30 days after it is closed or you ask us to delete it, except for what the law requires us to keep.
• Call recordings & transcripts: while your account is open, then deleted within 30 days after it is closed, unless the law requires otherwise.
• Billing data: 10 years from the transaction, in accordance with Luxembourg accounting obligations.
• Cookies: Maximum 13 months.
6. Your Rights
Under the GDPR (Articles 15 to 22), you can ask us to:
• Show you what data we hold on you (access).
• Fix it if it's wrong (rectification).
• Delete it (erasure), subject to what we're legally required to keep.
• Hand it over in a portable, machine-readable format (portability).
• Stop certain processing (objection / restriction).
Email legal@praixagent.com and we'll respond within 30 days. If you're not satisfied with our answer, you can lodge a complaint with the Luxembourg Data Protection Authority (CNPD): www.cnpd.public.lu
7. Cookies
We use essential cookies to keep the site working (authentication, session security) — these don't require consent, as they rely on our legitimate interest. Analytics and preference cookies only run if you opt in (consent), and you can withdraw that consent at any time. Cookies are kept for a maximum of 13 months.
8. AI Voice Agents & Your Calls
If a PraixAgent-powered voice agent handled your call, your voice was processed to generate the agent's responses in real time. We do not use this processing to make any automated decision that has a legal or similarly significant effect on you, within the meaning of Article 22 of the GDPR.
We do not use voice recordings to identify you by your voice (biometric identification) or to infer sensitive characteristics about you, such as your emotions.
The business whose agent you spoke with is responsible for telling you that you're speaking with an AI system and for any recording notice — if you have questions about a specific call, please contact that business directly.
9. Keeping Your Data Safe
We implement appropriate technical and organizational measures to protect your personal data, in accordance with Article 32 of the GDPR:
• Encryption in transit (TLS 1.2 or higher); stored credentials and backups are encrypted with AES-256.
• Servers in a certified data centre in Paris, France, with two-factor authentication on server administration.
• Role-based access control and least-privilege principles.
• Logging and monitoring of access and errors.
No method of electronic transmission or storage is completely secure. In the event of a personal data breach, we will notify the CNPD and, where required, the people concerned, in accordance with Articles 33 and 34 of the GDPR. For data we process on behalf of our business customers, we notify them without undue delay and within 72 hours of becoming aware of the breach.