← All legal documents

Legal

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the Praxsys Terms of Service and governs processing of personal data on a customer’s behalf. It applies from the effective date, subject to the parties’ service agreement.

Effective

1. Parties, roles, and instructions

Praxsys is operated by Maher Khamiss, the service provider and processor under this DPA. “We,” “us,” and “our” refer to the operator. The customer and the operator are the parties to this DPA.

The customer is the person or organization using Praxsys under the service agreement and determining the purposes of processing customer personal data. If the customer acts as a processor, it must have authority from its controller to give instructions and engage us as a subprocessor.

Customer personal data is processed only on documented instructions, including the service agreement, this DPA, and authorized use of the service, unless applicable law requires otherwise. We will inform the customer of a legal processing requirement unless prohibited by law, and of an instruction we believe infringes applicable data-protection law.

This DPA covers customer-controlled content. Account administration, website inquiries, and other processing for which we determine the purposes are addressed in the Privacy Policy. Legal and data-protection notices may be sent to maher@praxsys.io.

2. Processing details

The processing covered by this DPA consists of:

  • Subject and purpose: providing Praxsys for organizing client work and enabling authorized collaboration.
  • Operations: receiving, hosting, storing, organizing, retrieving, displaying, transmitting, restricting, and deleting customer personal data as required for the service and customer instructions.
  • Duration: the service relationship and the period necessary to return or delete data under this DPA, subject to required legal retention.
  • People: customer personnel, collaborators, clients, business contacts, and other people whose information the customer is authorized to provide.
  • Data categories: identifiers, contact details, memberships, and personal information in projects, tasks, Packages, documents, files, requests, approvals, and related communications.
  • Sensitive data: do not provide data requiring specialized regulatory safeguards unless those requirements and suitable safeguards have been separately agreed in writing.

3. Confidentiality and security

We will limit access to customer personal data to authorized persons who need it to provide or support the service and who are subject to appropriate confidentiality duties. We will maintain technical and organizational measures appropriate to the nature of the processing and its risks.

Praxsys uses authenticated access, Space memberships and permissions, and database access controls to restrict customer information. Security measures must also address provider and administrative access, secure transmission, recovery, and handling of security incidents. Customers remain responsible for their users, endpoint security, permissions, and lawful configuration of their Spaces.

Customers may request information about relevant security measures at maher@praxsys.io. No particular certification, hosting country, or service-level guarantee is created by this DPA.

4. Subprocessors and international transfers

The customer gives general authorization to use the subprocessors identified on the provider page for the services described there. We will require appropriate written data-protection obligations from subprocessors and remain responsible for the processing obligations we delegate.

We will inform affected customers of intended additions or replacements before those providers begin processing their customer personal data, allowing a reasonable opportunity to raise a data-protection objection. Contact maher@praxsys.io to object. We will work to resolve a justified objection; if no suitable arrangement is available, the parties may end the affected processing rather than require the customer to accept it.

Restricted international transfers will be made only under a mechanism permitted by applicable law. Where standard contractual clauses or other transfer documents are required, they must be put in place for the relevant transfer. This DPA does not represent that unspecified transfer clauses have already been executed.

5. Individual requests and security incidents

Taking account of the processing and information available, we will assist the customer with rights requests, security obligations, data-protection impact assessments, and regulatory consultations required by applicable law. We will refer requests concerning customer-controlled data to the customer unless a different response is legally required.

We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data, provide available information about its nature, likely effects, and response, and provide further information as it becomes available. Customers must keep their service contact details current and remain responsible for notices they are required to give to individuals or authorities.

6. Return and deletion

When the relevant processing ends, we will, at the customer’s choice, return or delete customer personal data and delete existing copies unless law requires retention. Contact maher@praxsys.io to arrange an authorized request and a practical return or deletion process. The request must respect the rights and instructions of the customer controlling any shared Space.

Copies retained in restricted backups remain protected until deleted or overwritten through the applicable backup lifecycle and must not be used for ordinary service activity. Legally retained information remains protected and limited to the purpose requiring retention. We will explain applicable exceptions and provide confirmation of action on request.

7. Compliance information and contract order

We will make available information reasonably needed to demonstrate compliance with this DPA and permit audits or inspections required by applicable data-protection law. Arrangements must protect security, confidentiality, and other customers’ data without preventing legally required oversight.

For customer personal-data processing, this DPA takes priority over conflicting provisions of the general service terms. Mandatory law and applicable mandatory transfer terms take priority over conflicting provisions of this DPA. A separately signed data-processing agreement controls where it expressly replaces or supplements this DPA.

← All legal documents