Last updated: 1 May 2026.
This notice explains how PRAXIA.CH Ltd handles personal data during a paid engagement with a client organisation, typically an NHS Trust, NHS Foundation Trust, Integrated Care Board, or NHS provider collaborative.
It sits alongside our Privacy Policy. The Privacy Policy covers data we collect through this website. This notice covers data we process for you during work we are paid to do.
Read this together with your engagement contract and the Data Processing Agreement (DPA) we sign before any client data is shared. This notice is informational; the DPA is the legal instrument.
1. Who this notice applies to
This notice applies to client organisations that engage PRAXIA.CH Ltd to provide an AI Readiness Diagnostic, an Executive Design Control review, or any related governance, assurance, or advisory service.
Where we perform such work for an NHS organisation, that organisation is normally the Data Controller. PRAXIA.CH Ltd acts as the Data Processor under the DPA.
2. Data ownership and roles
| Role | Who | What it means |
|---|---|---|
| Data Controller | The client organisation | Decides what data is in scope, why it is processed, and how the outputs are used. Holds the relationship with data subjects. |
| Data Processor | PRAXIA.CH Ltd | Processes the data only on the Controller’s documented instructions, only for the purposes set out in the DPA, only for the duration of the engagement. |
| Sub-processors | Listed in section 6 | Process the data on our behalf, under flow-down obligations consistent with the head DPA. |
We do not process client engagement data for any purpose outside the engagement. We do not use it to train models. We do not benchmark across clients without explicit written consent. We do not use it to inform marketing.
3. The engagement working stack
We run engagements on Google Workspace (Gmail, Google Drive, Google Docs, Sheets, Slides, Meet, Chat, Calendar). We configure the available Google Workspace data-region controls so that covered engagement data is stored, and where supported processed, in Europe. Certain service, security, support, telemetry, account, or other data may be processed outside Europe under Google’s applicable contractual and international transfer safeguards.
| System | Provider | Purpose | Region |
|---|---|---|---|
| Mail, calendars, video meetings | Google LLC (Google Workspace) | Engagement correspondence and scheduling | Europe (data regions set to Europe) |
| Document and file storage | Google LLC (Google Drive, Docs, Sheets, Slides) | Working documents, engagement outputs, version history | Europe |
| Internal chat | Google LLC (Google Chat) | Internal team communication on the engagement | Europe |
Google LLC is established in the United States. Where data leaves the UK or EEA we rely on the relevant transfer mechanism: an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
If an engagement requires any tool outside this list (an AI provider, a survey tool, a transcription service), we name it in the engagement DPA before we use it. We do not silently add tools.
4. What data we process during an engagement
The data we process depends on the engagement, but it usually includes:
| Data | Why we process it |
|---|---|
| Names, work emails, and roles of the client team we work with | To run meetings, share drafts, and route correspondence. |
| Board minutes, papers, and committee documentation | To assess governance maturity and reporting structures. |
| AI strategy documents, risk registers, and policy drafts | To advise on AI readiness and design control. |
| Procurement, supplier, and DPIA documentation related to AI | To map AI exposure and assurance gaps. |
| Notes and observations made during interviews and workshops | To produce findings and recommendations. |
| Drafts of our reports, including the names of staff who contributed | To produce the engagement output. |
5. What is out of scope
Unless the engagement DPA specifically permits it, we will not collect, accept, or process:
- patient data, clinical records, or anything covered by the common law duty of confidentiality
- identifiable data about individual NHS staff members beyond their professional role and contact details
- safeguarding records or anything subject to specific NHS information governance regimes
- special category data under UK GDPR Article 9
If your engagement genuinely needs any of the above, tell us before signing the DPA so we can scope the controls properly. We will say no rather than carry data we cannot protect to the right standard.
6. Sub-processors
For engagement work the sub-processor list is short:
| Sub-processor | Purpose | Region |
|---|---|---|
| Google LLC (Google Workspace) | Mail, file storage, documents, chat, video, calendar | Europe (data regions set to Europe). Company established in the US. |
Where an engagement requires an additional sub-processor we name it in the DPA, with the lawful transfer mechanism, the location, and the purpose. The website processors named in our Privacy Policy do not receive engagement data.
7. Access, isolation, and security
Each engagement is held in its own Google Drive shared folder. Access is restricted to the named Praxia team for that engagement and the named client team. Internal Praxia team members are added on a need-to-access basis and are removed when their role ends.
We use Google Workspace administrative controls: enforced two-step verification, device management on the laptops we use for client work, restricted external sharing, and audit logging. We do not store engagement files on personal devices or personal accounts.
If we become aware of a personal data breach we will notify the Controller without undue delay and will provide the available information reasonably required to support the Controller’s assessment, containment, investigation, notification, and remediation obligations, including the Controller’s own consideration of notification to the ICO within the statutory 72-hour period under Article 33.
8. Retention and deletion
At the end of an engagement we hand over the engagement outputs and any working files the Controller asks us to retain.
We then keep a working archive of engagement materials for 12 months, in case the Controller wants to extend, refresh, or revisit the work. After 12 months, or earlier on written request, we delete the engagement folder and confirm deletion in writing.
Anonymised methodological learning (what worked, what did not, what to change in the next iteration of the Diagnostic) may be retained internally without identifying the client. Nothing client-identifying is retained beyond the 12 months without written consent.
9. Your rights and the DPA
The DPA between us sets out the formal mechanism for everything in this notice. Under that DPA, you have the right to audit our compliance with the DPA on reasonable notice, instruct deletion or return of data at any time, be notified of any sub-processor changes before they take effect, be told without undue delay of any personal data breach affecting your data, and receive the assistance you need to respond to data subject rights requests, DPIAs, and prior consultations with the ICO.
If you have not yet received a copy of our standard DPA, write to [dpo@praxia.ch] and we will send it.
10. Contact
For data protection enquiries about an active or proposed engagement: [dpo@praxia.ch].
For general privacy enquiries: [privacy@praxia.ch].
For commercial enquiries, use the contact form on this site.
If you wish to escalate, you may complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF