Privacy Policy
Last Updated: July 20, 2026
1. Who we are
Proxion, Inc. (“Proxion,” “we,” “us”) is a Delaware corporation headquartered at 601 West 57th Street, New York, NY 10019, United States. We build expert-graded evaluation and training data for frontier AI labs and finance AI companies.
Contact: privacy@proxion.ai · Security matters: security@proxion.ai
2. Our two roles - read this first
This policy describes how we handle personal information as a controller, that is, information about our website visitors, business contacts, client personnel, and the members of our expert and engineering networks.
It does not govern client data. When we perform services for a client, any personal information contained in the materials the client sends us is processed only on that client’s instructions, in our role as a processor / service provider / contractor. We do not decide the purposes of that processing. Our handling of it is governed by our Data Processing Addendum, not by this policy. If you are a data subject whose information appears in a client’s materials, please direct your request to that client; if you contact us, we will refer you to them.
3. Personal information we collect, and why
3.1 Website visitors (proxion.ai)
● What: IP address, approximate (city-level) location derived from IP, device and browser type, pages viewed, referring URL, and interactions with the site.
● Why: to operate, secure, and improve the site and measure basic site performance.
● Basis (GDPR/UK GDPR): legitimate interests (operating and securing our site).
3.2 Business contacts, prospective clients, and inquiries
● What: name, work email, phone, job title, employer, professional profile information, correspondence with us, and records of meetings and calls.
● Sources: you directly; our website forms; publicly available professional sources and business-contact databases (including Apollo.io).
● Why: to respond to inquiries, provide information about our services, conduct business-to-business outreach, manage our sales pipeline, and administer contracts.
● Basis: legitimate interests (business development and relationship management); consent where required by local law; performance of a contract.
● You can opt out of outreach at any time by using the unsubscribe link in any email or writing to privacy@proxion.ai.
3.3 Expert Network and Engineering Network members (contractors)
● What: name, contact details, professional credentials, employment and education history, biography, work-product and quality metrics, payment and tax information, and onboarding information. Government identification, background-screening information, and payment account details are generally submitted directly to Proxion’s service providers; Proxion receives verification status, screening results or reports where permitted, and payment-administration information needed to manage the engagement.
● Why: to qualify, onboard, verify, pay, and manage our contractors; to satisfy client diligence requirements; and to meet legal, tax, and anti-fraud obligations.
● Basis: performance of a contract; legal obligation; legitimate interests (fraud prevention, client assurance, quality management).
● Sharing with clients: we may share an expert’s name, credentials, and biography with a client where the client requests it and it is relevant to qualification, diligence, or project oversight, only with the expert’s authorization, and limited to what is necessary. We do not include contractor personal information in client deliverables unless the individual has expressly authorized it and the client has specifically requested it.
3.4 Client personnel and authorized users
● What: name, work email, job title, account identifiers, multi-factor-authentication status, access records, and usage logs. Proxion does not store plaintext passwords.
● Why: to provision access, deliver and support the services, secure our systems, and administer the client relationship.
● Basis: performance of a contract; legitimate interests (security and service delivery).
3.5 Meetings and calls
Where we use recording or AI note-taking tools on calls, we will disclose this at the start of the call and obtain consent where required by applicable law. Recordings and transcripts are used to produce meeting notes and are retained per Section 8.
4. Sensitive personal information
We and our service providers process a limited amount of information that may be classified as “sensitive personal information” under US state privacy laws and, in some cases, as special-category or similarly protected information under applicable law:
● Government identification information (contractors and Expert Network members): identity verification through Persona; Proxion generally receives verification status and limited metadata rather than retaining the identification document.
● Background-screening information (contractors, where permitted): suitability, fraud prevention, and client assurance through Checkr or another approved provider.
● Payment account information (contractors): payment administration through Deel; Proxion generally receives payment status and limited account metadata.
● Account and authentication information (contractors; client users): authentication, access control, fraud prevention, and security; Proxion does not store plaintext passwords.
We use this information only for the purposes above, including performing services, verifying identity, preventing fraud, administering payments, and ensuring security and integrity. We do not use sensitive personal information to infer characteristics about an individual or for advertising.
5. How we disclose personal information
We disclose personal information to:
● Service providers and processors that support our operations under written contracts restricting their use of information. Current categories include cloud infrastructure and productivity (Amazon Web Services, Google Workspace); CRM and outreach (HubSpot, Apollo.io, Instantly); identity and screening (Persona, Checkr); contractor onboarding and payments (Deel); banking (JPMorgan Chase); e-signature (PandaDoc); scheduling (Calendly, Motion); and endpoint security (Action1). Providers may change as our operations evolve.
● Clients, where an expert has authorized disclosure of their credentials or biography (§3.3).
● Professional advisors (lawyers, accountants, auditors, and insurers) under duties of confidentiality.
● Authorities, where required by law. Where a request concerns client data, we follow the government-access procedure in our DPA: we notify the client unless legally prohibited, challenge the request where there is a reasonable basis, and disclose only the minimum necessary.
● A successor in connection with a merger, acquisition, or sale of assets, subject to this policy.
6. We do not sell or share your personal information
Proxion has not sold personal information, and has not shared personal information for cross-context behavioral advertising, in the preceding twelve (12) months, and does not do so. We do not deploy advertising pixels (including LinkedIn or X pixels) on proxion.ai. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.
7. International transfers
Our production Client datasets and task artifacts are hosted in the United States in AWS US-East. Other personal information is primarily stored or processed in the United States. Some service providers may process information in other jurisdictions as permitted by their applicable data-processing terms and transfer safeguards.
Authorized Personnel located outside the United States may remotely access approved systems to perform contracted work only from countries approved for the applicable project. Where personal information subject to the EU GDPR, UK GDPR, or Swiss FADP is transferred internationally, we use the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss amendments where applicable, and supplementary technical and organizational measures. A copy of the relevant transfer terms is available on request at privacy@proxion.ai.
8. Retention
We keep personal information only as long as necessary for the purposes described above:
● Client data (processor role): deleted from primary systems within 30 days of termination or a valid deletion request; from encrypted backups within 90 days. See the DPA.
● Business contact / CRM records: for the duration of the relationship and for 3 years thereafter, or until you opt out.
● Contractor records: for the engagement and for 7 years thereafter (tax, legal, and audit requirements).
● Identity verification and screening records: verification status and screening records retained for up to 12 months after completion, unless a longer period is required by law, contract, or a documented dispute; service providers may retain source records under their own legal obligations.
● Website and security logs: 12 months.
● Encrypted backups: up to 90 days.
9. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption at rest and in transit; multi-factor authentication; role-based, least-privilege access; periodic access reviews; identity verification and role-appropriate background screening; approved managed systems with restrictions on local storage and unapproved external AI or LLM tools; endpoint vulnerability and patch management; encrypted backups; security and privacy training; and a documented incident response process. No system is perfectly secure, and we review and update safeguards as our services and risks evolve.
10. Your rights
10.1 If you are in the EEA, UK, or Switzerland
You have the right to access, rectify, erase, and restrict processing of your personal information; to data portability; to object to processing based on legitimate interests (including direct marketing, we will stop on request); and to withdraw consent where processing is based on consent. You may lodge a complaint with your local supervisory authority.
We do not intentionally offer goods or services directly to individuals in the EEA or UK or monitor their behavior. If our activities change so that appointment of an EU or UK representative is required, we will make the appointment and update this policy.
10.2 If you are a California, Colorado, Connecticut, Virginia, or other US state resident
Subject to the thresholds and exemptions in the applicable statute, you have the right to: know what personal information we collect, use, and disclose; access and obtain a copy; correct inaccuracies; delete; opt out of sale, sharing, and targeted advertising (we do none of these); limit the use of sensitive personal information (see §4); and not be discriminated against for exercising these rights. Where a state law provides an appeal right, you may appeal a denial by replying to our decision; we will respond within the statutory period and, if we deny the appeal, tell you how to contact your state Attorney General.
Where applicable, Proxion honors the rights described above. When we process personal information on behalf of a client, we act as that client’s service provider, processor, or contractor and assist the client with applicable requests under our Data Processing Addendum.
10.3 How to exercise your rights
Email privacy@proxion.ai. We will verify your identity in proportion to the sensitivity of the request and respond within the timeframes required by applicable law. You may use an authorized agent; we will require proof of authorization.
11. Cookies and analytics
We use strictly necessary cookies to operate and secure the site and may use limited, non-advertising analytics to understand aggregate traffic and site performance. We do not use advertising cookies or advertising pixels and do not engage in cross-context behavioral advertising. Where required by law, we will provide a cookie banner or settings tool before using non-essential cookies. You can also control cookies through your browser settings.
12. Children
Our services are business-to-business and are not directed at children. We do not knowingly collect personal information from anyone under 18.
13. Changes to this policy
We may update this policy. We will change the “Last updated” date and, for material changes, provide notice through the site or by email. Version history is maintained internally and available on request.
14. Contact
Proxion, Inc. · 601 West 57th Street, New York, NY 10019, United States
Privacy: privacy@proxion.ai · Security: security@proxion.ai · Legal: legal@proxion.ai