Do you sign a data processing agreement?
Yes, always, and before any data is touched. Praxis provides a standard Article 28 DPA covering processing scope, duration, sub-processors, security measures and deletion at end of engagement. If your organisation has its own DPA template, that one is used instead — reviewing yours is part of the engagement, not an extra.
Where is our data hosted?
In the EU. Hetzner (Germany or Finland) by default, OVHcloud (France or Poland) where a client prefers that jurisdiction. Where Praxis builds infrastructure in your own accounts, the hosting is whatever you choose — and the EU-only recommendation still stands.
Is any data processed outside the EU?
Not by Praxis. There are no US-based Praxis sub-processors, so engaging Praxis adds no reliance on the EU–US Data Privacy Framework or on standard contractual clauses. Where your organisation already runs on Google Workspace or Microsoft 365, that transfer relationship is yours and predates the engagement: Praxis works inside your tenancy under your existing terms rather than introducing a new provider. If you want that exposure reduced, migrating is work Praxis does — planned, staged and costed in advance — but it is your decision and not a condition of anything.
You work inside our Google Workspace. What does that make you?
A processor acting on your documented instructions, exactly as the DPA describes. Access is scoped to the systems the work needs — a named shared drive, a specific project, a service account rather than a human login where a script is doing the work — and it is reviewed and revoked like any other. Nothing is copied out to Praxis infrastructure unless the work requires it and the DPA names it.
Do you put our data into AI tools?
Only what has been named in writing beforehand: the system, the folder, the categories of data and the model provider. Special-category data — membership, canvassing, donation and anything else revealing political opinion — is out of scope by default. Where AI is part of an engagement, it gets a scoped service account against named resources rather than a workspace-wide OAuth grant, and the AI-usage policy that comes out of the work is a document you can hand to a funder.
How do you handle members’ political opinions under GDPR Article 9?
By naming the Article 9(2) condition that applies before processing starts — most often 9(2)(d) for a political organisation processing its own members’ data, sometimes explicit consent. It is written into the DPA and the records of processing, so you can answer a regulator, a funder or a member with one sentence.
What happens to our data when the engagement ends?
Working copies are deleted and access is revoked at handover. Anything Praxis holds beyond that point exists only because a retainer specifies it. The systems themselves stay with you: your accounts, your repository, your hosting.
Can we audit or review your setup?
Yes. Ask for the DPA, the sub-processor list and the security measures annex at any point in the sales conversation — before signing anything. Nothing on this page is held back until a contract exists.
Does this website track visitors?
No. It sets no cookies, loads no third-party scripts, runs no analytics and makes no requests to any other domain — fonts included. There is nothing to consent to, which is why there is no consent banner. The same standard applies to what Praxis builds for clients.