Scope.
This Policy applies to Praevexa HRMS, CaseFlow, QualityFlow, Workforce Planner,
MIS Reporting & Business Intelligence services, Website & Digital Presence services,
custom business solutions, our public websites, product trials, sales and support interactions,
and related Praevexa products and services.
1. Our Role and Scope
Praevexa MIS Technologies (OPC) Private Limited ("Praevexa", "we", "our", or "us")
provides business software, online planning tools, reporting and business-intelligence
services, website and digital-presence services, custom business solutions, and related
support.
Depending on the context, Praevexa may determine why and how personal information is
processed, or may process information on behalf of a customer organization under that
customer's instructions. For example, a customer organization generally determines the
purposes for which its employee, operational, case-management, or quality-management
information is entered into Praevexa software. For website visitors, sales contacts,
business prospects, account administrators, and direct customers, Praevexa may determine
the purposes and means of processing.
This Privacy Policy is a notice describing our practices. It does not replace any
customer-specific data processing agreement, statement of work, order form, or other
written contract that may apply to a particular service.
2. Information We Collect
Depending on the product, service, or interaction, we may collect the following categories of information:
Organization and account information
- Organization name, business contact details, subscription or trial information, billing details, user count, account status, and service configuration.
- Name, business email address, employee or resource code, role, access type, authentication records, password-reset information, OTP records, and account activity.
HRMS information
- Employee profile information, date of joining, reporting structure, shift information, roster, attendance, leave, reimbursement, documents, and other records entered by authorized customer users.
CaseFlow information
- Departments, queues, worktypes, skillsets, routing rules, uploaded case data, assignments, priorities, outcomes, follow-up dates, handling-time information, activities, attendance context, audit records, and reports.
QualityFlow information
- Production sample data, analyst or processor references, sampling criteria, checklist configuration and responses, quality scores, outcomes, severity, error categories and types, comments, acknowledgements, disputes, manager decisions, and related reports.
Workforce Planner information
- Planning inputs may include forecast and actual volumes, working days, backlog, AHT or CPH, shrinkage, occupancy, attrition, hiring, training and ramp assumptions, automation assumptions, financial-planning inputs, and scenario information.
- Workforce Planner planning inputs are designed to remain in the user's browser and are not intended to be stored on Praevexa servers. Information separately submitted for activation, trial registration, login, support, or communication may be collected by Praevexa.
MIS Reporting, Business Intelligence, website and digital-presence service information
- Source files or data extracts, KPI definitions, report specifications, dashboard requirements, business rules, reporting calendars, report outputs, analyst instructions, project requirements, website content, brand assets, domain or hosting information, approved credentials where required for a project, and related communications.
Business prospect and professional contact information
- Business name, website, country or city, business type, publicly available business contact details, professional name, job title, business email address, source of the information, information about a business's website or digital presence, communication history, marketing preferences, and opt-out status.
Website, enquiry, billing and support information
- Name, company name, email address, phone number, request type, message, enquiry details, support history, quotation or invoice details, payment status, and information submitted through forms or communications.
- We do not intentionally store full payment-card details ourselves when payment is handled by an independent payment provider.
Technical and analytics information
- IP address, browser and device information, login session information, system logs, usage events, error logs, security events, referral source, approximate location, page views, and interaction information collected through our systems or analytics tools.
3. How We Collect Information
We may collect information:
- Directly from you when you register, use a product, activate a tool, request a trial, contact us, submit a form, make a purchase, or communicate with us.
- From customer organizations and their authorized administrators or users when they configure or use Praevexa products and services.
- From files, records, systems, APIs, or information supplied by customers for an agreed project or service.
- Automatically through website, application, server, security, and analytics technologies.
- From publicly available business websites, public corporate registers, professional or business directories, professional networking sources, referrals, and other lawful business information sources for relevant business-to-business outreach.
- From service providers involved in payments, hosting, email delivery, analytics, security, support, or other functions where applicable.
Where applicable law requires us to provide privacy information because we obtained
personal information from another source, we aim to provide the required information
within the applicable period and, where relevant, at or before our first direct
communication.
4. How We Use Information
We may use information to:
- Create, administer, authenticate, secure, and support organization and user accounts.
- Provide HRMS, CaseFlow, QualityFlow, Workforce Planner, MIS Reporting & BI, Website & Digital Presence, and other agreed products or services.
- Configure workflows, permissions, reporting, notifications, trials, subscriptions, pilots, implementations, and support.
- Respond to enquiries, demonstrations, sales requests, product questions, support requests, quotations, and service discussions.
- Process billing, payments, renewals, account status, and related commercial administration.
- Maintain audit trails, logs, fraud-prevention measures, security controls, and incident records.
- Understand website and product usage, troubleshoot issues, improve usability, measure marketing effectiveness, and develop services.
- Identify businesses that may reasonably benefit from Praevexa products or services and conduct relevant business-to-business sales and marketing outreach where permitted by applicable law.
- Personalize business communications based on publicly available information about an organization's operations, website, digital presence, or likely business requirements.
- Manage marketing preferences, objections, unsubscribe requests, and suppression or do-not-contact records.
- Comply with legal, regulatory, tax, security, contractual, and dispute-resolution obligations.
- Establish, exercise, or defend legal rights and protect Praevexa, customers, users, and others from misuse or security threats.
5. Legal Bases and Customer Instructions
The legal basis or justification for processing depends on the service, the information,
the relationship, and the law that applies. Where required by applicable law, we may rely on:
- Contractual necessity — where processing is needed to provide a product or service, administer an account, fulfil a request, or perform an agreement.
- Consent — where valid consent is required or is the appropriate basis, including certain optional marketing communications or technologies.
- Legitimate interests — where permitted, for activities such as securing systems, preventing misuse, improving services, managing business relationships, and conducting proportionate business-to-business marketing that does not override an individual's rights and interests.
- Legal obligations — where processing is required for tax, accounting, regulatory, court, law-enforcement, or other legal requirements.
- Customer instructions — where Praevexa processes personal information on behalf of a customer organization for the customer's business purposes.
Business-to-business marketing
Where permitted by applicable law, Praevexa may use professional contact information for
relevant business-to-business outreach based on legitimate business interests. We consider
the nature and source of the information, the relevance of the proposed communication, the
recipient's professional role, the likely impact on the individual, and available opt-out
mechanisms before relying on such interests.
Where applicable law requires consent for a particular type of recipient, communication,
or channel, we will rely on consent or another legally permitted basis before sending that
communication.
Customer-provided employee and operational information
Customer organizations are responsible for ensuring that they have the necessary authority,
notices, permissions, consents, contracts, or other lawful basis required to provide
employee, customer, operational, quality, case, reporting, or other information to
Praevexa. Where Praevexa acts on a customer's instructions, the customer remains responsible
for determining the lawful purpose for which that information is processed.
6. Direct Marketing and Communications
We may send service-related, transactional, security, support, billing, trial, or account
communications where necessary for the relevant relationship. These communications are
different from optional promotional marketing.
Where permitted by applicable law, Praevexa may contact businesses or professional contacts
about products or services that are reasonably relevant to their business role or
organization. We may use publicly available business information to identify and personalize
such outreach.
You may object to or opt out of direct marketing at any time by using the unsubscribe method
provided in the message, replying with an unsubscribe request, or contacting us at
contact@praevexa.com.
When a person or business asks not to receive further marketing, we may retain the minimum
information necessary on a suppression or do-not-contact list so that we can continue to
respect that preference.
We do not treat the mere public availability of a mobile number as permission to send
promotional WhatsApp messages. Promotional messaging through WhatsApp or similar channels
will be used only where the necessary permission or other lawful basis exists for that
channel and recipient.
7. Cookies and Analytics
Our websites and applications may use cookies, local storage, analytics scripts, or similar
technologies for security, authentication, preferences, website performance, product
functionality, analytics, and marketing measurement.
We may use services such as Google Analytics or similar tools. Depending on configuration,
these tools may receive information such as page visits, browser or device details,
approximate location, referral source, and interaction information.
You can control or delete cookies through your browser settings. Disabling cookies or local
storage may affect certain website or product functions. Our use of non-essential cookies and
similar technologies is subject to applicable law, including any consent requirements that
apply in the visitor's jurisdiction.
8. How We Share Information
Praevexa does not sell or rent customer, employee, or business-contact personal information
as a data product. We may share information only where reasonably necessary, including:
- With authorized users of the same customer organization according to configured roles and permissions.
- With hosting, cloud, email, communications, analytics, security, payment, technical-support, and other service providers that support our operations.
- With professional advisers, auditors, insurers, or contractors where reasonably necessary and subject to appropriate obligations.
- With customer-approved parties for implementation, migration, support, integrations, reporting, website projects, or custom-development work.
- Where required by law, regulation, court order, lawful government request, or legal process.
- Where reasonably necessary to investigate fraud, misuse, security incidents, or threats to rights, safety, systems, or property.
- In connection with a lawful corporate restructuring, financing, investment, merger, acquisition, transfer, or sale, subject to applicable confidentiality and legal requirements.
Service providers are expected to process information only for the purposes for which they
are engaged and subject to applicable contractual, confidentiality, security, and legal
requirements.
9. International Processing and Transfers
Praevexa is based in India and may use service providers or infrastructure located in India
or other countries. As a result, personal information may be processed or accessed outside
the country in which it was originally collected.
Where applicable law places conditions on international transfers, we take reasonable steps
to use an available lawful transfer mechanism or other appropriate safeguards required for
the relevant transfer. The precise mechanism may depend on the customer's location, the
service provider, the type of information, and the applicable contract.
10. Data Security
We use reasonable technical and organizational measures designed to protect information
against unauthorized access, misuse, loss, disclosure, alteration, or destruction.
Measures may include:
- Authentication, password, OTP, and session controls.
- Role-based access controls and authorization checks.
- Secure file access through controlled application handlers where applicable.
- Server-side validation and database security controls.
- Audit trails, system logs, and security monitoring.
- Hosting, backup, and infrastructure-level safeguards appropriate to the service.
No internet-based system, transmission method, or electronic storage environment can be
guaranteed to be completely secure. Customers and users must also protect their credentials,
devices, access rights, and exported information.
11. Data Retention
We retain information only for as long as reasonably necessary for the purposes described
in this Policy, including providing services, maintaining accounts, supporting customers,
meeting legal or contractual obligations, resolving disputes, maintaining security or audit
records, enforcing agreements, and protecting legal rights.
- Customer and account data: retained according to the service relationship, account status, contractual requirements, legal obligations, backup cycles, and agreed deletion arrangements.
- Business prospect data: periodically reviewed. Records for unresponsive prospects are generally reviewed after 12 months from the last meaningful outreach or interaction and may be deleted or anonymized unless there is a valid reason to retain them.
- Suppression records: minimum identifying information may be retained for as long as reasonably necessary to ensure that marketing opt-out requests continue to be respected.
- Security, billing, tax, contractual, and dispute records: may be retained for longer where required for legal, accounting, fraud-prevention, evidentiary, or enforcement purposes.
Customers may request account closure or deletion, subject to applicable law, contractual
commitments, payment obligations, legitimate retention needs, backup cycles, and technical
limitations.
12. Privacy Rights and Requests
Depending on applicable law and the context in which information is processed, individuals
may have rights to request access, correction, updating, deletion or erasure, information
about processing, withdrawal of consent, objection to certain processing, restriction,
portability, grievance handling, or other rights.
Direct marketing objection: you may object to or opt out of our use of your
personal information for direct marketing at any time. Once we receive a valid objection or
unsubscribe request, we will stop using that information for direct marketing, subject to
retaining limited suppression information as described above.
If Praevexa processes employee or operational information on behalf of your employer or
another customer organization, please first contact that organization's administrator,
employer, or privacy contact. Praevexa may assist the customer organization with a valid
request where technically and contractually appropriate.
We may need to verify identity or authority before acting on a privacy request. Rights may
be subject to lawful exemptions, retention requirements, or other limitations under
applicable law.
13. Customer Responsibilities
Customer organizations are responsible for:
- Providing accurate organization and user information.
- Granting access only to authorized users and removing access when it is no longer required.
- Maintaining appropriate internal access, device, credential, and exported-data controls.
- Providing required employee, worker, customer, or other notices and obtaining any legally required permissions, consents, or other lawful basis.
- Ensuring they have authority to provide data, files, content, credentials, and business information used in Praevexa software or professional services.
- Using Praevexa products and services in compliance with employment, privacy, data-protection, communications, intellectual-property, and other applicable laws.
14. Children’s Data
Praevexa's public website, business software, planning tools, and professional services are
intended for business and professional use and are not directed to children.
Customer organizations should not enter a child's personal information into Praevexa
software unless they have a legitimate business need and all authority, notices,
permissions, safeguards, and legal requirements applicable to that processing are in place.
15. Third-Party Links and Services
Our websites, applications, or communications may contain links to third-party websites,
platforms, payment providers, tools, or services. Third parties operate under their own
terms and privacy practices. Praevexa is not responsible for the content, security, or
privacy practices of third-party services that we do not control.
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our products, services, business
practices, technology, or legal requirements. The current version will be posted on this
page with an updated "Last Updated" date.
Where required by applicable law or contract, we may provide additional notice of material
changes.