Praevexa MIS Technologies

Privacy Policy

This Privacy Policy explains how Praevexa MIS Technologies (OPC) Private Limited collects, uses, stores, shares, and protects personal information in connection with our websites, software products, Workforce Planner, professional services, business communications, and related offerings.

Effective Date: 6 August 2026 Last Updated: 25 September 2026 Website: www.praevexa.com
Scope. This Policy applies to Praevexa HRMS, CaseFlow, QualityFlow, Workforce Planner, MIS Reporting & Business Intelligence services, Website & Digital Presence services, custom business solutions, our public websites, product trials, sales and support interactions, and related Praevexa products and services.

1. Our Role and Scope

Praevexa MIS Technologies (OPC) Private Limited ("Praevexa", "we", "our", or "us") provides business software, online planning tools, reporting and business-intelligence services, website and digital-presence services, custom business solutions, and related support.

Depending on the context, Praevexa may determine why and how personal information is processed, or may process information on behalf of a customer organization under that customer's instructions. For example, a customer organization generally determines the purposes for which its employee, operational, case-management, or quality-management information is entered into Praevexa software. For website visitors, sales contacts, business prospects, account administrators, and direct customers, Praevexa may determine the purposes and means of processing.

This Privacy Policy is a notice describing our practices. It does not replace any customer-specific data processing agreement, statement of work, order form, or other written contract that may apply to a particular service.

2. Information We Collect

Depending on the product, service, or interaction, we may collect the following categories of information:

Organization and account information

  • Organization name, business contact details, subscription or trial information, billing details, user count, account status, and service configuration.
  • Name, business email address, employee or resource code, role, access type, authentication records, password-reset information, OTP records, and account activity.

HRMS information

  • Employee profile information, date of joining, reporting structure, shift information, roster, attendance, leave, reimbursement, documents, and other records entered by authorized customer users.

CaseFlow information

  • Departments, queues, worktypes, skillsets, routing rules, uploaded case data, assignments, priorities, outcomes, follow-up dates, handling-time information, activities, attendance context, audit records, and reports.

QualityFlow information

  • Production sample data, analyst or processor references, sampling criteria, checklist configuration and responses, quality scores, outcomes, severity, error categories and types, comments, acknowledgements, disputes, manager decisions, and related reports.

Workforce Planner information

  • Planning inputs may include forecast and actual volumes, working days, backlog, AHT or CPH, shrinkage, occupancy, attrition, hiring, training and ramp assumptions, automation assumptions, financial-planning inputs, and scenario information.
  • Workforce Planner planning inputs are designed to remain in the user's browser and are not intended to be stored on Praevexa servers. Information separately submitted for activation, trial registration, login, support, or communication may be collected by Praevexa.

MIS Reporting, Business Intelligence, website and digital-presence service information

  • Source files or data extracts, KPI definitions, report specifications, dashboard requirements, business rules, reporting calendars, report outputs, analyst instructions, project requirements, website content, brand assets, domain or hosting information, approved credentials where required for a project, and related communications.

Business prospect and professional contact information

  • Business name, website, country or city, business type, publicly available business contact details, professional name, job title, business email address, source of the information, information about a business's website or digital presence, communication history, marketing preferences, and opt-out status.

Website, enquiry, billing and support information

  • Name, company name, email address, phone number, request type, message, enquiry details, support history, quotation or invoice details, payment status, and information submitted through forms or communications.
  • We do not intentionally store full payment-card details ourselves when payment is handled by an independent payment provider.

Technical and analytics information

  • IP address, browser and device information, login session information, system logs, usage events, error logs, security events, referral source, approximate location, page views, and interaction information collected through our systems or analytics tools.

3. How We Collect Information

We may collect information:

  • Directly from you when you register, use a product, activate a tool, request a trial, contact us, submit a form, make a purchase, or communicate with us.
  • From customer organizations and their authorized administrators or users when they configure or use Praevexa products and services.
  • From files, records, systems, APIs, or information supplied by customers for an agreed project or service.
  • Automatically through website, application, server, security, and analytics technologies.
  • From publicly available business websites, public corporate registers, professional or business directories, professional networking sources, referrals, and other lawful business information sources for relevant business-to-business outreach.
  • From service providers involved in payments, hosting, email delivery, analytics, security, support, or other functions where applicable.

Where applicable law requires us to provide privacy information because we obtained personal information from another source, we aim to provide the required information within the applicable period and, where relevant, at or before our first direct communication.

4. How We Use Information

We may use information to:

  • Create, administer, authenticate, secure, and support organization and user accounts.
  • Provide HRMS, CaseFlow, QualityFlow, Workforce Planner, MIS Reporting & BI, Website & Digital Presence, and other agreed products or services.
  • Configure workflows, permissions, reporting, notifications, trials, subscriptions, pilots, implementations, and support.
  • Respond to enquiries, demonstrations, sales requests, product questions, support requests, quotations, and service discussions.
  • Process billing, payments, renewals, account status, and related commercial administration.
  • Maintain audit trails, logs, fraud-prevention measures, security controls, and incident records.
  • Understand website and product usage, troubleshoot issues, improve usability, measure marketing effectiveness, and develop services.
  • Identify businesses that may reasonably benefit from Praevexa products or services and conduct relevant business-to-business sales and marketing outreach where permitted by applicable law.
  • Personalize business communications based on publicly available information about an organization's operations, website, digital presence, or likely business requirements.
  • Manage marketing preferences, objections, unsubscribe requests, and suppression or do-not-contact records.
  • Comply with legal, regulatory, tax, security, contractual, and dispute-resolution obligations.
  • Establish, exercise, or defend legal rights and protect Praevexa, customers, users, and others from misuse or security threats.

5. Legal Bases and Customer Instructions

The legal basis or justification for processing depends on the service, the information, the relationship, and the law that applies. Where required by applicable law, we may rely on:

  • Contractual necessity — where processing is needed to provide a product or service, administer an account, fulfil a request, or perform an agreement.
  • Consent — where valid consent is required or is the appropriate basis, including certain optional marketing communications or technologies.
  • Legitimate interests — where permitted, for activities such as securing systems, preventing misuse, improving services, managing business relationships, and conducting proportionate business-to-business marketing that does not override an individual's rights and interests.
  • Legal obligations — where processing is required for tax, accounting, regulatory, court, law-enforcement, or other legal requirements.
  • Customer instructions — where Praevexa processes personal information on behalf of a customer organization for the customer's business purposes.

Business-to-business marketing

Where permitted by applicable law, Praevexa may use professional contact information for relevant business-to-business outreach based on legitimate business interests. We consider the nature and source of the information, the relevance of the proposed communication, the recipient's professional role, the likely impact on the individual, and available opt-out mechanisms before relying on such interests.

Where applicable law requires consent for a particular type of recipient, communication, or channel, we will rely on consent or another legally permitted basis before sending that communication.

Customer-provided employee and operational information

Customer organizations are responsible for ensuring that they have the necessary authority, notices, permissions, consents, contracts, or other lawful basis required to provide employee, customer, operational, quality, case, reporting, or other information to Praevexa. Where Praevexa acts on a customer's instructions, the customer remains responsible for determining the lawful purpose for which that information is processed.

6. Direct Marketing and Communications

We may send service-related, transactional, security, support, billing, trial, or account communications where necessary for the relevant relationship. These communications are different from optional promotional marketing.

Where permitted by applicable law, Praevexa may contact businesses or professional contacts about products or services that are reasonably relevant to their business role or organization. We may use publicly available business information to identify and personalize such outreach.

You may object to or opt out of direct marketing at any time by using the unsubscribe method provided in the message, replying with an unsubscribe request, or contacting us at contact@praevexa.com.

When a person or business asks not to receive further marketing, we may retain the minimum information necessary on a suppression or do-not-contact list so that we can continue to respect that preference.

We do not treat the mere public availability of a mobile number as permission to send promotional WhatsApp messages. Promotional messaging through WhatsApp or similar channels will be used only where the necessary permission or other lawful basis exists for that channel and recipient.

7. Cookies and Analytics

Our websites and applications may use cookies, local storage, analytics scripts, or similar technologies for security, authentication, preferences, website performance, product functionality, analytics, and marketing measurement.

We may use services such as Google Analytics or similar tools. Depending on configuration, these tools may receive information such as page visits, browser or device details, approximate location, referral source, and interaction information.

You can control or delete cookies through your browser settings. Disabling cookies or local storage may affect certain website or product functions. Our use of non-essential cookies and similar technologies is subject to applicable law, including any consent requirements that apply in the visitor's jurisdiction.

8. How We Share Information

Praevexa does not sell or rent customer, employee, or business-contact personal information as a data product. We may share information only where reasonably necessary, including:

  • With authorized users of the same customer organization according to configured roles and permissions.
  • With hosting, cloud, email, communications, analytics, security, payment, technical-support, and other service providers that support our operations.
  • With professional advisers, auditors, insurers, or contractors where reasonably necessary and subject to appropriate obligations.
  • With customer-approved parties for implementation, migration, support, integrations, reporting, website projects, or custom-development work.
  • Where required by law, regulation, court order, lawful government request, or legal process.
  • Where reasonably necessary to investigate fraud, misuse, security incidents, or threats to rights, safety, systems, or property.
  • In connection with a lawful corporate restructuring, financing, investment, merger, acquisition, transfer, or sale, subject to applicable confidentiality and legal requirements.

Service providers are expected to process information only for the purposes for which they are engaged and subject to applicable contractual, confidentiality, security, and legal requirements.

9. International Processing and Transfers

Praevexa is based in India and may use service providers or infrastructure located in India or other countries. As a result, personal information may be processed or accessed outside the country in which it was originally collected.

Where applicable law places conditions on international transfers, we take reasonable steps to use an available lawful transfer mechanism or other appropriate safeguards required for the relevant transfer. The precise mechanism may depend on the customer's location, the service provider, the type of information, and the applicable contract.

10. Data Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, misuse, loss, disclosure, alteration, or destruction. Measures may include:

  • Authentication, password, OTP, and session controls.
  • Role-based access controls and authorization checks.
  • Secure file access through controlled application handlers where applicable.
  • Server-side validation and database security controls.
  • Audit trails, system logs, and security monitoring.
  • Hosting, backup, and infrastructure-level safeguards appropriate to the service.

No internet-based system, transmission method, or electronic storage environment can be guaranteed to be completely secure. Customers and users must also protect their credentials, devices, access rights, and exported information.

11. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing services, maintaining accounts, supporting customers, meeting legal or contractual obligations, resolving disputes, maintaining security or audit records, enforcing agreements, and protecting legal rights.

  • Customer and account data: retained according to the service relationship, account status, contractual requirements, legal obligations, backup cycles, and agreed deletion arrangements.
  • Business prospect data: periodically reviewed. Records for unresponsive prospects are generally reviewed after 12 months from the last meaningful outreach or interaction and may be deleted or anonymized unless there is a valid reason to retain them.
  • Suppression records: minimum identifying information may be retained for as long as reasonably necessary to ensure that marketing opt-out requests continue to be respected.
  • Security, billing, tax, contractual, and dispute records: may be retained for longer where required for legal, accounting, fraud-prevention, evidentiary, or enforcement purposes.

Customers may request account closure or deletion, subject to applicable law, contractual commitments, payment obligations, legitimate retention needs, backup cycles, and technical limitations.

12. Privacy Rights and Requests

Depending on applicable law and the context in which information is processed, individuals may have rights to request access, correction, updating, deletion or erasure, information about processing, withdrawal of consent, objection to certain processing, restriction, portability, grievance handling, or other rights.

Direct marketing objection: you may object to or opt out of our use of your personal information for direct marketing at any time. Once we receive a valid objection or unsubscribe request, we will stop using that information for direct marketing, subject to retaining limited suppression information as described above.

If Praevexa processes employee or operational information on behalf of your employer or another customer organization, please first contact that organization's administrator, employer, or privacy contact. Praevexa may assist the customer organization with a valid request where technically and contractually appropriate.

We may need to verify identity or authority before acting on a privacy request. Rights may be subject to lawful exemptions, retention requirements, or other limitations under applicable law.

13. Customer Responsibilities

Customer organizations are responsible for:

  • Providing accurate organization and user information.
  • Granting access only to authorized users and removing access when it is no longer required.
  • Maintaining appropriate internal access, device, credential, and exported-data controls.
  • Providing required employee, worker, customer, or other notices and obtaining any legally required permissions, consents, or other lawful basis.
  • Ensuring they have authority to provide data, files, content, credentials, and business information used in Praevexa software or professional services.
  • Using Praevexa products and services in compliance with employment, privacy, data-protection, communications, intellectual-property, and other applicable laws.

14. Children’s Data

Praevexa's public website, business software, planning tools, and professional services are intended for business and professional use and are not directed to children.

Customer organizations should not enter a child's personal information into Praevexa software unless they have a legitimate business need and all authority, notices, permissions, safeguards, and legal requirements applicable to that processing are in place.

15. Third-Party Links and Services

Our websites, applications, or communications may contain links to third-party websites, platforms, payment providers, tools, or services. Third parties operate under their own terms and privacy practices. Praevexa is not responsible for the content, security, or privacy practices of third-party services that we do not control.

16. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our products, services, business practices, technology, or legal requirements. The current version will be posted on this page with an updated "Last Updated" date.

Where required by applicable law or contract, we may provide additional notice of material changes.

17. Contact and Privacy Grievances

For privacy questions, direct-marketing objections, data requests, grievances, support, or complaints, contact:

Praevexa MIS Technologies (OPC) Private Limited
Privacy / Grievance Contact
Email: contact@praevexa.com
Phone / WhatsApp: +91-8097426080
Website: https://www.praevexa.com

If a specific customer agreement identifies another privacy contact, data-processing term, or request procedure, that customer-specific arrangement may also apply.