← Back to Prexa

Legal

Privacy Policy

Effective Date: May 20, 2026

This Privacy Policy explains how Prexa Limited collects, uses, discloses and safeguards information when you visit our website, interact with us or engage our services.

1. Introduction

Prexa Limited is a specialised cybersecurity firm providing design risk analysis for agentic systems, including autonomous AI agents, LLM-driven workflows and automated decision architectures.

We are committed to protecting the privacy and personal data of our clients, website visitors and business partners.

This Privacy Policy explains how we collect, use, disclose and safeguard information when you engage our services, visit our website or interact with us.

2. Information We Collect

We only collect personal information that is necessary for our business operations.

Identity and contact data may include your name, job title, company name, email address and phone number.

Technical and system data may include IP address, browser type and metadata associated with agentic architecture configurations provided during risk assessments.

Usage data may include information about how you use our website, client portals, evaluation tools and related services.

3. How We Use Your Information

We use collected information to provide services, including design risk analysis, threat modelling and cybersecurity reporting tailored to agentic systems.

We use information to communicate with you, respond to inquiries, manage client relationships and provide technical or regulatory updates.

We use information to improve security, enhance diagnostic tools, analyse usage trends and support the secure deployment of our services.

4. Information Sharing and Disclosure

Prexa Limited does not sell, trade or rent your personal information.

We may share information with trusted third-party service providers who assist us in operating our website, conducting business or servicing you, subject to confidentiality obligations.

We may disclose information where required by law, regulation, legal process or to protect our legal rights, customers, systems or the security of our services.

5. Data Security

Given our specialisation in agentic system risks, we apply security controls designed to protect the confidentiality, integrity and availability of personal data.

We implement technical, physical and administrative measures, which may include encryption, access controls and vulnerability assessment processes.

No website, cloud service, software platform or method of transmission is completely secure. We cannot guarantee absolute security, but we take reasonable steps to protect personal data from unauthorised access, loss or alteration.

6. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain business records, comply with legal obligations, resolve disputes and enforce agreements.

Where data is no longer required, we will take reasonable steps to delete, anonymise or securely retain it in accordance with applicable law and internal retention requirements.

7. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete or restrict the processing of your personal data.

You may also have the right to object to certain processing, request data portability or withdraw consent where processing is based on consent.

To exercise your rights, please contact us using the details set out in this policy.

8. Cookies and Website Data

Our website may use basic cookies or similar technologies to operate, understand website usage and improve the visitor experience.

Where required by law, we will provide appropriate cookie notices or consent mechanisms.

You can usually control cookies through your browser settings, although disabling certain cookies may affect website functionality.

9. International Transfers

Where personal data is transferred outside the United Kingdom or European Economic Area, we will take reasonable steps to ensure appropriate safeguards are in place.

These safeguards may include standard contractual clauses, contractual protections, technical controls or other mechanisms recognised under applicable data protection laws.

10. Third-Party Services

Our website or services may link to or integrate with third-party websites, software providers, cloud services or business tools.

We are not responsible for the privacy practices of third parties. You should review the privacy policies of any third-party services you use.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in regulatory standards, our services, security practices or agentic risk evaluation methodologies.

The updated version will be indicated by the effective date at the top of this page.

Continued use of our website or services after an update means the revised Privacy Policy applies from the stated effective date.

12. Contact

For questions about this Privacy Policy or to exercise your privacy rights, please contact privacy@prexa.io.

This website version is based on Prexa Limited’s privacy policy draft. Before publication, it should be reviewed for consistency with Prexa’s current entity details, service providers, data processing arrangements and customer onboarding process.