Praxis
  • Features
  • Pricing
  • How it works
  • Privacy
  • Terms
Start firm

Privacy Policy

Effective date: 10 September 2026

1. Who we are

Praxis ("we", "our", "us") operates a practice operating system for CS and CA firms. This privacy policy describes how we collect, use, store, and protect personal data when you use the Praxis platform at praxis.lyvenor.com, app.praxis.lyvenor.com, and client.praxis.lyvenor.com.

For privacy questions, contact the founder at the work email shared during signup.

2. What data we collect

We collect only the data needed to run the platform for your firm:

  • Firm account: Firm name, firm slug, owner name, work email, password (hashed, never stored plain).
  • Staff profiles: Names, work emails, and role assignments made by the firm owner.
  • Client records: Legal name, PAN, type, status — all entered by your firm's staff.
  • Work records: Tasks, filings, invoices, status changes, and comments entered by staff.
  • Access logs: Per-request trace ID, session ID, login IP address, and timestamp. Stored for security monitoring and troubleshooting only.

3. How we use data

  • To provide and maintain the platform: authentication, tenant isolation, backups.
  • To respond to support requests from the firm owner or assigned admins.
  • To invoice the firm directly (early access) and process payments when automated online checkout ships.
  • To detect, prevent, and investigate security incidents or abuse of the platform.

We do not sell or rent personal data. We do not use firm or client data to train any AI or machine-learning model.

4. Firm data isolation

Each firm's data is scoped to a single tenant identifier at the application layer. Staff of Firm A cannot see Firm B's clients, tasks, filings, or invoices. Cross-tenant access is tested in the backend test suite on every change.

5. Data retention

  • Firm data is retained for the lifetime of the firm's subscription plus 30 days after account closure.
  • Access logs and security records: retained for up to 12 months after the event.
  • Email verification tokens: expire 24 hours after issue.
  • On written request from the firm owner, we permanently delete firm data within 7 business days, subject to any legal hold.

6. Data storage & security

  • Application data is stored in a managed PostgreSQL database with TLS in transit and at-rest encryption provided by the host.
  • Passwords are hashed with a per-password salt using a modern memory-hard hash algorithm.
  • JWT access tokens expire after 8 hours. Refresh tokens are stored hashed and rotated on every use.
  • All platform traffic uses HTTPS (TLS 1.2+). HTTP is redirected to HTTPS.

No system is 100% secure. We disclose confirmed material breaches to the affected firm owner within 72 hours of discovery, consistent with applicable law.

7. Cookies & local storage

Praxis does not use third-party analytics cookies. Session state lives in browser memory via a JavaScript boot step and per-tab sessionStorage for trace IDs. There is no persistent session cookie — tabs closed fully lose session state.

8. Your rights

As a firm owner or staff user, you may request access to, correction of, or deletion of your personal data held by Praxis. Firm clients: direct your request to the firm that holds your record; each firm is its own data controller for client data it enters.

9. Children

Praxis is a business tool and is not intended for use by anyone under 18. We do not knowingly collect personal data from minors.

10. Changes to this policy

We may update this policy from time to time. Material changes are notified via in-app banner or email to the firm owner at least 14 days before they take effect.

Praxis
© 2026 Praxis. All rights reserved.
  • Home
  • Pricing
  • Privacy
  • Terms
  • Sign in