Praxis privacy policy
Last updated: 28 September 2026
Scope and roles
This policy covers the Praxis web application, its email intake and the single Praxis Bridge Chrome Web Store extension. The veterinary practice decides which patients and workflows use Praxis and is the data controller. Praxis acts as its processor and handles practice data only to provide, secure and support the requested service.
Data we handle
Depending on the workflow the service handles account and session identifiers, workspace and team information, patient and client-identifying details, consultation records, notes, transcripts, recordings, schedules, catalogues, billing items, PIMS tenant and record identifiers, and bounded security, delivery and error metadata.
For the Chrome extension, the enabled PIMS tab's origin, URL and supported page content are limited web browsing activity under the Chrome Web Store taxonomy. They are used only for the clinician-facing Enable, connect, read and approved-write workflow. Praxis does not build general browsing history, inspect unrelated tabs, sell browsing data or use it for advertising.
How data is used and shared
Data is used to provide the practice's clinical and operational workflows, verify the open PIMS record, carry out clinician-approved actions, recover ambiguous deliveries, maintain security and reliability, and meet legal obligations. It may be transmitted to the configured Praxis service, the practice's own PIMS, and the hosting, database, workflow and AI subprocessors selected for that deployment where necessary for the requested feature. Praxis does not sell personal or sensitive data, transfer it to data brokers, or use it for personalised, retargeted or interest-based advertising.
Chrome extension controls
The extension requests access only to a supported PIMS site that the clinician deliberately enables. Runtime authority remains bound to the exact clicked HTTPS origin and selected workspace. Removing the site permission or signing out disables page reads and writes and clears local connector authority. PIMS session cookies and vendor credentials remain on the vendor origin and are not sent to Praxis. To maintain the background relay, the extension may restore an inactive pinned tab on the exact enabled site; it does not navigate or reload your other tabs. Vendor sign-outs still require vendor sign-in.
Audio and sensitive clinical data
The Side Panel can delegate microphone access only to the first-party Praxis application and only after the user starts a consented recording. Clinical, health and client-identifying information is sensitive. User data is encrypted in transit using HTTPS or WSS. Access is limited by workspace membership and the practice's configured permissions.
Email intake
A practice can give Praxis a dedicated email address so that staff can forward, copy or blind-copy patient emails to it, and a colleague can connect their own Microsoft 365 or Gmail mailbox for the same purpose. Email intake is switched off until a practice administrator switches it on; while it is off the address refuses mail. Praxis receives mail for the address with its own mail server and accepts it only for a practice that has intake switched on.
A received email, its attachments and the forwarder's note are used to find the patient and client it concerns in the practice's records, to file it to that record and to raise a task for the right colleague. The email's text may be read by the AI provider configured for the deployment to classify it and propose a match; filing into the practice management system still waits for a person's approval unless an administrator has chosen otherwise. Mail from outside the practice that it has not allowed is held in quarantine rather than filed. Attachments are scanned for viruses and are encrypted at rest. When Praxis cannot be sure, it may send the forwarding colleague a short clarifying reply through the deployment's email provider.
From a connected mailbox, Praxis copies only messages from the practice's clients on file, its colleagues and senders it has allowed; everything else in the mailbox is not read. The colleague who connected the mailbox can switch this off at any time. Forwards set aside as not patient mail are kept so a mistake can be undone, and deleted after 30 days; filed emails are kept as part of the patient's record until the practice deletes them.
Storage, retention and deletion
Extension access credentials and transient clinical result envelopes are held in trusted browser session storage. A rotating refresh credential and its bounded recovery receipt are held in trusted persistent extension storage to retain pairing across browser restarts and Store updates, for up to 180 days from pairing. Content scripts cannot read these storage areas. Explicit sign-out removes the credentials; remote revocation ends the device session. Persistent extension storage contains no clinical payloads; it holds the selected workspace, enabled-site binding, signed selector configuration and bounded content-free delivery receipts, which are removed after settlement or during sign-out as applicable.
Server recording audio is retained for 30 days by default and may be configured from 1 to 365 days. Other clinical records are retained until the practice deletes them because record-retention periods are the controller's decision and vary by jurisdiction. A practice administrator can export or erase the workspace through Praxis. Backups and subprocessors follow the applicable service agreement and data-processing terms.
Your choices and rights
Clinicians can refuse or remove the optional PIMS-site grant, stop microphone capture, sign out, or ask their practice administrator to exercise access, correction, export or deletion rights. Patients and clients should contact their veterinary practice, which is the controller. Practices should use the privacy or support contact identified in their signed Praxis service agreement for processor requests, security issues or questions about this policy.
Changes
Material changes to extension data handling, permissions, hosts or purposes require an updated Chrome Web Store release and matching disclosures. The date above identifies this published policy revision.