Legal
Privacy Policy
How we collect, use and safeguard personal and business information across PACX.
Effective 4 September 2025
We at PACX.AI are committed to protecting your privacy. This policy explains how we collect, use and safeguard personal and business information when you use our platform and related services. By accessing or using PACX.AI, you agree to the practices described below.
01Introduction
We value transparency and trust. This policy describes what information we collect, how we use it, and the rights you have over your data.
02Scope of this policy
This policy applies to all PACX.AI products and services, including:
- Lumos, our AI analytics agent
- Condor, our AI predictive agent
- Our website, chat interfaces, APIs and connected applications
It covers data collection, processing and protection across these modules.
03Data we collect
Information you provide
- Account information. Name, email address, organization and login credentials.
- Uploaded data (Condor only). Files, datasets or inputs you provide for predictive modeling and analysis.
- Project and chat inputs. Questions, prompts and configurations used in analytics or AI interactions.
- Billing and payment information. Subscription or purchase details processed securely through approved third-party payment providers.
Information collected automatically
- Usage logs. Activity records, timestamps and interaction data used to maintain and improve performance.
- Device and connection data. IP address, browser and operating system information used for compatibility and security.
- Cookies and analytics. We use cookies and similar technologies for authentication, analytics and session continuity.
04How we use your data
We use personal and analytical data to:
- Provide, operate and improve PACX.AI features.
- Execute queries and analytics on your connected data sources (Lumos).
- Train, evaluate and forecast models for predictive insights (Condor).
- Communicate product updates, support messages or marketing offers, with opt-out available.
- Detect, prevent and respond to security or fraud incidents.
- Comply with legal or regulatory obligations.
We do not sell or rent your data to any third party.
05Data handling models
Lumos, our AI analytics agent
- Operates under a bring your own source model.
- Queries your connected databases or cloud sources directly.
- Where you connect a live database or cloud source, we query it directly and do not copy the underlying data. Where you connect a store, marketplace or advertising account, we keep a synchronized copy of that account's records so your history remains available after the platform stops serving it.
- Disconnecting a source erases the data we hold for it.
- Temporary query metadata held in active sessions is discarded automatically after completion.
Condor, our AI predictive agent
- Requires access to data you upload or share for model training and evaluation.
- Such data is stored and processed securely for the duration of the project.
- You may delete datasets and models at any time, which permanently removes them after standard retention and backup cycles.
06Data retention
- We retain data only as long as necessary to deliver services or meet legal obligations.
- Condor data is removed upon user deletion or project completion.
- Session and log data are anonymized or deleted once operationally unnecessary.
07Personal data sharing
We may share limited information only when necessary:
- Service providers. For hosting, analytics, communication and payment processing.
- Legal compliance. To respond to lawful requests or protect rights and safety.
- Business transitions. In the event of merger, acquisition or restructuring, with equivalent data-protection safeguards.
08Data security
Everything is encrypted, end to end, using industry-standard protocols. We apply enterprise-grade security practices throughout the platform:
- Encryption in transit. All traffic between you, our platform and any connected service travels over TLS. Plaintext connections are refused.
- Encryption at rest. Stored data is encrypted with AES-256 on managed cloud infrastructure.
- Envelope-encrypted credentials. Every credential you entrust to us, including API keys and access tokens, is encrypted with a dedicated managed key before it is written. Credentials are never stored in plaintext, never written to logs and never returned by any interface.
- Network isolation. Databases and internal services run inside a private network with no public endpoints, reachable only through authenticated, audited channels.
- Workspace isolation. Every workspace's data is logically separated and access-scoped, so one customer's data is never served to another.
- Least-privilege access. Access is granted by role, on a need-to-know basis, and reviewed. Connections to your external accounts are read-only wherever the provider supports it.
- Monitoring and hardening. Continuous monitoring, dependency and vulnerability management, and internal audit mechanisms across environments.
While we take every precaution, no system is completely immune from risk. Users should maintain strong passwords and safeguard their credentials.
09Your rights
You may:
- Access, update or delete your personal data.
- Restrict or object to specific processing activities.
- Request data export or portability.
- Withdraw consent for communications at any time.
All such requests can be made via security@pacx.ai.
10Third party integrations
PACX.AI may connect with third-party services such as data sources, analytics tools and communication platforms. Their own privacy policies govern how they process data. We encourage reviewing those policies before linking accounts.
11Cybersecurity and CERT-In compliance
We follow formal procedures for detecting, managing and reporting cybersecurity incidents in accordance with the Indian Computer Emergency Response Team (CERT-In) directives.
- Timely notification. Any qualifying incident is reported to CERT-In within six hours of detection.
- Official channels. Reports are sent to incident@cert-in.org.in or 1800-11-4949 using the Annexure-I format from the 28 April 2022 circular.
- Internal escalation. Incidents are logged, verified and resolved under our internal response framework.
- Recordkeeping. All incident documentation and corrective actions are securely maintained for audit and compliance.
12Changes to this policy
We may update this policy periodically. Significant updates will be communicated by email or in-app notifications, and the effective date will be revised.
Contact
For privacy or security concerns, contact: