Legal
GDPR Compliance Statement
Effective Date: May 20, 2026
This statement explains how Prexa Limited approaches GDPR compliance when handling personal data in connection with corporate clients, partners, website visitors and agentic design risk analysis.
1. Relationship and Scope
Prexa Limited operates primarily as a Data Controller for the personal data of our corporate clients, partners and website visitors.
When performing design risk analysis on autonomous and agentic systems, Prexa may act as a Data Processor regarding any technical system logs or training metadata submitted to us for safety evaluation.
Prexa is committed to complying with the EU General Data Protection Regulation and the UK General Data Protection Regulation where applicable.
2. Legal Basis for Processing
Performance of a Contract: We may process personal data to execute services, reviews, diagnostics and risk assessments requested by our clients.
Legitimate Interests: We may process personal data to secure our infrastructure, prevent fraudulent interactions, maintain business operations and refine our cybersecurity analytics framework.
Legal Obligation: We may process personal data where necessary to comply with statutory records, audit tasks, security disclosure requirements or other legal obligations.
3. GDPR Data Protection Principles
Lawfulness, Fairness and Transparency: Personal data is processed in accordance with stated parameters and applicable legal requirements.
Purpose Limitation: Data collected for risk verification is not repurposed for unrelated marketing, profiling or incompatible purposes.
Data Minimisation: We request only the minimum system logs, identifiers and related information necessary to map security posture, agentic architecture risk and relevant system vulnerabilities.
Accuracy: We take reasonable steps to ensure that personal data processed in connection with our services is accurate and kept up to date where necessary.
Storage Limitation: We retain personal data only for as long as required for service delivery, contractual obligations, legal requirements or legitimate business purposes.
Integrity and Confidentiality: We apply appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse or alteration.
4. Data Retention
Prexa stores personal data only for as long as required to complete contract engagements, provide requested services, maintain business records, comply with legal obligations or resolve disputes.
Where personal data is no longer required, we will take reasonable steps to delete, anonymise or securely retain it in accordance with applicable law and internal retention processes.
5. International Transfers
Where data is transferred outside the European Economic Area or the United Kingdom, Prexa uses appropriate safeguards designed to ensure that personal data receives an equivalent level of protection.
These safeguards may include Standard Contractual Clauses, contractual commitments, technical controls or other mechanisms recognised under applicable data protection law.
6. Your Rights as a Data Subject
EU and UK residents may have specific legal rights regarding their personal data.
Right of Access: You may request a copy of personal data we hold about you.
Right to Rectification: You may ask us to correct inaccurate or incomplete personal data.
Right to Erasure: You may request that we delete your personal data where processing is no longer required or where another valid legal basis applies.
Right to Restriction: You may ask us to restrict processing in certain circumstances.
Right to Data Portability: You may request your personal data in a structured, commonly used and machine-readable format where applicable.
Right to Object: You may object to certain types of processing, including processing based on legitimate interests, where applicable.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time.
7. Processor Activities
Where Prexa acts as a Data Processor on behalf of a customer, we process personal data only in accordance with the customer’s documented instructions and applicable data protection obligations.
Processor activities may relate to technical system logs, metadata, architecture documents, risk assessment materials or other information submitted to Prexa for design risk analysis.
Where required, Prexa and the customer will enter into a Data Processing Agreement or equivalent contractual arrangement covering processor obligations.
8. Security Measures
Prexa applies technical and organisational measures designed to protect personal data in connection with agentic design audits and related services.
These measures may include access controls, encryption, secure system configuration, vulnerability management, internal confidentiality obligations and appropriate review processes.
No system can be guaranteed to be absolutely secure, but Prexa takes reasonable steps to reduce the risk of unauthorised access, accidental loss or unlawful processing.
9. Complaints
You have the right to lodge a complaint with your local Data Protection Authority if you believe your personal data has been processed in breach of applicable data protection law.
We encourage you to contact us first so that we can try to resolve any concern directly.
10. Contact and Inquiries
For requests related to your GDPR rights, or if you wish to make an inquiry regarding how your information is handled within our agentic design audits, please contact dpo@prexa.io.
This website version is based on Prexa Limited’s GDPR Compliance Statement draft. Before publication, it should be reviewed against Prexa’s current processing activities, service providers, data hosting arrangements and customer contracts.