Privacy Policy
What ProAxis collects, why we collect it, who we share it with, how long we keep it, and the control you have over all of it — including everything our Google Calendar integration touches.
Last updated: September 7, 2026
Read the Terms of ServiceOverview and Scope
This Privacy Policy explains what ProAxis.ai collects, why we collect it, who we share it with, and the choices you have. It covers proaxis.ai, the platform at app.proaxis.ai, our mobile applications, our APIs, and any white-labelled instance operated by a ProAxis partner (together, the “Service”).
Using the Service is also governed by our Terms of Service. Where this policy uses “personal information”, read it to include “personal data” under the GDPR and equivalent terms under other laws.
Two roles, and why the difference matters
ProAxis handles data in two distinct capacities, and your rights depend on which one applies:
- As a controller — for our own customers. When you register, run campaigns, buy credits or connect an integration, we decide how that information is used, and this policy governs it.
- As a processor — for consumer data that moves through the Service on behalf of a buyer, publisher or partner. They decide why that data is collected; we process it under their instructions and their own privacy policy. If you are a consumer who called or submitted a form and you want your data removed, contact the business you dealt with, or write to privacy@proaxis.ai and we will route your request to them.
Information We Collect
Information you give us
- Account and identity — name, business name, email address, phone number, password, role and account type
- Business profile — services offered, coverage areas, licences, hours, capacity and staffing
- Campaign configuration — bids, caps, routing rules, destination numbers and qualification criteria
- Billing — billing address, tax details, and the payment token returned by our payment processor. We never see or store full card numbers
- Support and correspondence — the messages, attachments and screenshots you send us
Information generated by using the Service
- Call records — caller and destination numbers, timestamps, duration, routing path, disposition and outcome
- Call recordings and transcripts — the audio of calls carried by the Service and the text derived from it
- Lead, appointment and action records — the fields a consumer submitted, and what happened to them afterwards
- Verification and analytics output — intent, sentiment, quality scoring and the AI Verdict attached to an opportunity
- Product usage — pages viewed, features used, actions taken, and the timing of each
- Device and log data — IP address, browser and device type, operating system, referring page and error logs
Information from other sources
- Connected accounts — data from services you choose to link, such as Google Calendar. See clause 06
- Publishers and traffic partners — the consumer information attached to an opportunity they send us
- Payment and fraud providers — the outcome of a payment or a risk check
- Public and licensed sources — business registry, licensing and market data used for Market Intelligence
Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to secure the platform, and analytics cookies to understand how the Service is used. We do not use third-party advertising cookies to track you across other websites. You can block cookies in your browser, though the platform will not work correctly without the necessary ones.
How We Use Information
| Purpose | What it covers | Legal basis (GDPR) |
|---|---|---|
| Providing the Service | Routing calls, leads, appointments and actions; running campaigns; scheduling; accounts and sub-accounts | Performance of a contract |
| Verification and quality | Scoring opportunities, detecting invalid events and reviewing credit requests | Legitimate interests — a marketplace only works if what is billed is real |
| Billing and payments | Deducting credits, taking payment, invoicing, payouts and revenue share | Performance of a contract; legal obligation |
| Support and communication | Answering questions, sending service notices and platform updates | Performance of a contract; legitimate interests |
| Security and fraud prevention | Authentication, abuse detection, audit logs and investigating misuse | Legitimate interests; legal obligation |
| Improving the Service | Aggregated and de-identified analysis of how features perform | Legitimate interests |
| Marketing | Product news and offers, which you can unsubscribe from at any time | Consent, or legitimate interests where permitted |
We do not use call recordings, calendar data or consumer records to serve you advertising, and we do not use them to develop or train generalized AI or machine learning models.
Call Recording and Transcription
Calls carried by the Service are recorded and transcribed so that routing, verification, analytics and credit reviews can work. Recordings are available to the account that owns the call and to ProAxis staff for support, security and dispute review.
Recording laws differ by jurisdiction, including one- and two-party consent rules. If you use the Service to take or make calls, you are responsible for giving any notice and obtaining any consent your jurisdiction requires, and for your own do-not-call and messaging compliance. Our obligations to you are set out in the Terms of Service.
Google Account Integrations and Limited Use
ProAxis offers an optional Google Calendar integration. It exists for one reason: when an appointment is booked through the Service, it should land on the calendar your team already uses, and the Service should not book over something that is already there.
Connecting a Google account is entirely optional, is started by you through Google’s own consent screen, and can be disconnected at any time. The rest of the Service works without it. If you never connect a Google account, ProAxis receives no Google user data at all.
What we request, and why
| Scope | Access it grants | Why we need it |
|---|---|---|
| https://www.googleapis.com/auth/calendar.readonly | Read events on the calendars you select | To get your existing events so the platform knows when you are already busy and offers only real availability. |
| https://www.googleapis.com/auth/calendar.events | Create and update events | To create an event when an appointment is booked, and to update or cancel that event if the appointment is rescheduled or cancelled. |
These are the narrowest scopes the feature can work with. We do not request access to Gmail, Drive, Contacts, Photos or any other Google service, and we do not use Google account data for any purpose beyond the two described above.
What we receive, and what we store
- From your Google profile — your email address and name, used only to show which account is connected
- From your calendars — the start time, end time and busy/free status of events on the calendars you select, used to calculate availability
- Event titles and descriptions are read only where needed to render an appointment we created; we do not index, mine or analyse the content of your personal events
- We store OAuth access and refresh tokens, encrypted at rest, plus the identifiers of the events ProAxis created, so we can update or cancel them later
How Google user data is handled
- Read event times on the calendars you explicitly connect, to calculate availability
- Create, update and cancel the appointment events ProAxis books for you
- Store the minimum needed to keep the integration working
- Encrypt data in transit (TLS) and at rest, and restrict internal access to what is operationally necessary
- Sell or rent Google user data
- Use Google user data for advertising, ad targeting or marketing profiles
- Transfer Google user data to third parties, except as needed to provide the feature, to comply with law, or with your explicit consent
- Let humans read your calendar data, except with your consent, for a security investigation, to comply with law, or where the data is aggregated and anonymized
- Use Google user data to develop, improve or train generalized AI or machine learning models
Retention, deletion and revoking access
- Google user data is kept only while your Google account is connected, and only for as long as it is needed to schedule and manage appointments.
- You can disconnect the integration at any time in your ProAxis account settings. Disconnecting deletes the stored access and refresh tokens and the cached availability data, and ends all further access.
- You can also revoke ProAxis’s access directly from your Google account at myaccount.google.com/permissions.
- To request deletion of the Google user data we hold, email privacy@proaxis.ai from the address on the account. We action verified requests within 30 days and confirm in writing when it is done.
- Revoking access does not remove events already on your calendar — those stay yours to keep or delete in Google Calendar.
Other third-party services
The Service also integrates with telephony, payment, CRM and messaging providers. Your use of any third-party service is governed by that provider’s own terms and privacy policy, and we are not responsible for how those providers operate.
Data Retention
We keep information for as long as it is needed for the purpose it was collected, and then delete or de-identify it. In practice:
| Category | How long we keep it | Why |
|---|---|---|
| Account and billing records | For the life of the account, then up to 7 years | Tax, accounting and audit obligations |
| Call recordings and transcripts | Up to 24 months, or a shorter period you configure | Dispute and credit review, quality and analytics |
| Lead, appointment and action records | For the life of the account, then up to 24 months | Attribution, billing disputes and reporting |
| Google Calendar tokens and availability data | Only while connected; deleted on disconnect | The integration cannot work without them |
| Product usage and device logs | Up to 13 months | Security, debugging and capacity planning |
| Support correspondence | Up to 3 years after the ticket closes | Continuity of support and dispute history |
Backups roll off on their own schedule, so deleted data may persist in encrypted backups for a short period after deletion from the live system.
Security
- Encryption in transit with TLS, and encryption at rest for stored data, recordings and OAuth tokens
- Role-based access control, with internal access limited to staff who need it for their work
- Audit logging of administrative and data-access actions
- Segregation between accounts, sub-accounts and white-labelled instances
- Vendor review before a service provider is given access to personal information
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as the law requires, without undue delay. To report a suspected vulnerability or incident, email privacy@proaxis.ai.
Your Rights and Choices
Depending on where you live, you may have some or all of the following rights over the personal information we hold as a controller:
- Access — a copy of the information we hold about you, and how it is used
- Correction — to fix information that is inaccurate or incomplete
- Deletion — to have information erased, subject to our legal retention obligations
- Portability — to receive your information in a portable format
- Restriction and objection — to limit or object to certain processing, including processing based on legitimate interests
- Withdraw consent — at any time, where processing relies on consent, without affecting what came before
- Opt out of sale or sharing — we do not sell or share personal information for advertising, so there is nothing to opt out of
- Non-discrimination — we will not treat you differently for exercising any of these rights
To exercise a right, email privacy@proaxis.ai from the address on your account. We will verify your identity before acting and respond within the period the law allows — 30 days in most cases, 45 under the CCPA/CPRA, and we will tell you if we need an extension. An authorized agent may act for you with written permission.
If you are in the EEA or the UK and are not satisfied with our response, you may complain to your local supervisory authority.
To stop marketing email, use the unsubscribe link in any message or write to us. Service and billing notices are not marketing and cannot be turned off while your account is open.
International Transfers
ProAxis operates from the United States, and our service providers may process information in other countries. Where personal information is transferred out of the EEA or the UK, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK Addendum, together with technical measures such as encryption. You can request details of the safeguards used by writing to privacy@proaxis.ai.
Children’s Privacy
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email privacy@proaxis.ai and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. The “last updated” date at the top of this page reflects the current version. Material changes — anything that meaningfully changes what we collect, why, or who we share it with — will be announced in the platform or by email before they take effect. Continuing to use the Service after that means you accept the revised policy.
Contact
Questions about this policy, the Google Calendar integration, a data access request, or a deletion request:
- Privacy and data requests
- Legal
- Support
- Sales