Privacy Policy

Graxis Technologies LLC ("Graxis," "we," "us," or "our") respects your privacy and is committed to protecting personal information handled through our websites, services, communications, and technology platforms.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our website, communicate with us, purchase or use our services, or otherwise interact with Graxis.

It also describes Graxis's role when we process information on behalf of business clients using our AI-powered customer engagement, communications, CRM, automation, and related technology services ("Services").

1. Scope of This Privacy Policy

This Privacy Policy applies to personal information collected through:

  • Graxis websites and online forms;

  • demo and consultation requests;

  • telephone calls and AI-assisted voice interactions;

  • SMS and other messaging communications;

  • email communications;

  • customer service interactions;

  • Graxis-managed CRM and automation systems;

  • AI-powered customer engagement systems;

  • business relationships with clients and prospective clients; and

  • other Graxis-operated services that reference this Privacy Policy.

This Privacy Policy does not govern the independent privacy practices of third-party websites, platforms, or services that Graxis does not control.

2. Our Role When Processing Information

Depending on the circumstances, Graxis may process personal information in different capacities.

2.1 Information Collected for Graxis

When you interact directly with Graxis—for example, by visiting our website, requesting a demonstration, contacting us, or becoming a Graxis client—we may collect and process information for our own legitimate business purposes as described in this Privacy Policy.

2.2 Information Processed on Behalf of Clients

Graxis also provides technology and automation services to other businesses.

When Graxis processes personal information on behalf of a Client in connection with the Services, Graxis generally acts as a service provider, processor, or business associate, as applicable, and processes such information according to the Client's instructions, applicable agreements, and applicable law.

The Client generally determines the purposes for which such information is collected and used and is responsible for providing applicable privacy notices, establishing an appropriate legal basis for processing, obtaining required consents, and responding to applicable privacy requests.

Individuals with questions regarding information collected by a Graxis Client should generally contact that business directly.

3. Information We Collect

Depending on how you interact with Graxis or our Services, we may collect the following categories of information.

3.1 Contact Information

This may include:

  • name;

  • email address;

  • telephone number;

  • company name;

  • job title;

  • mailing address; and

  • other contact information you provide.

3.2 Business Information

For Clients and prospective Clients, we may collect information concerning:

  • business operations;

  • services;

  • locations;

  • employees and authorized users;

  • scheduling and availability;

  • business policies;

  • pricing;

  • frequently asked questions;

  • customer engagement processes;

  • CRM configuration;

  • automation requirements; and

  • other information necessary to configure or provide the Services.

3.3 Customer and Lead Information

When providing Services on behalf of a Client, our systems may process information concerning that Client's customers, prospects, leads, patients, or other contacts.

Depending on the implementation, this information may include:

  • names;

  • telephone numbers;

  • email addresses;

  • appointment information;

  • communications;

  • customer inquiries;

  • conversation history;

  • service requests;

  • lead information;

  • CRM records;

  • form submissions; and

  • other information supplied by the Client or its customers.

3.4 Communications

We may collect and process communications made through systems operated or managed by Graxis, including:

  • SMS messages;

  • emails;

  • website chat conversations;

  • AI chat conversations;

  • telephone call information;

  • AI voice interactions;

  • customer service communications; and

  • communications submitted through online forms.

Depending on the applicable configuration, calls may be recorded, transcribed, summarized, or analyzed using automated or artificial intelligence technologies.

Graxis and its Clients are responsible for configuring appropriate notices and consent mechanisms according to their respective obligations under applicable law. Clients are responsible for informing Graxis of jurisdictions or circumstances requiring specific recording or consent configurations.

3.5 Account and Technical Information

We and our technology providers may automatically collect certain technical information, such as:

  • IP address;

  • browser type;

  • device information;

  • operating system;

  • referring website;

  • pages visited;

  • date and time of access;

  • session information;

  • system logs;

  • cookies; and

  • similar technologies.

3.6 Payment Information

If you purchase Services, payment information may be processed by third-party payment processors.

Graxis generally does not directly store complete payment-card information when payments are processed through an external payment provider.

3.7 Sources of Information

We may obtain personal information from the following sources:

  • automatically through websites, applications, communications systems, cookies, logs, and similar technologies.

  • from publicly available or lawfully obtained business sources, where permitted by applicable law; and

  • from third-party integrations, service providers, business partners, and technology platforms used in connection with the Services;

  • from a Client’s customers, prospects, leads, users, or other contacts when they interact with systems operated or managed through the Services;

  • from our Clients when they provide or make information available to Graxis in connection with the Services;

  • directly from you when you provide information to Graxis, communicate with us, request a demonstration, purchase Services, or otherwise interact with us;

4. Sensitive Information

Unless specifically requested through a system designed and approved for such information, users should not submit Social Security numbers, financial account credentials, medical information, government identification numbers, passwords, or other highly sensitive personal information through Graxis's general website forms, chat systems, or demonstration environments.

Clients operating in regulated industries or intending to process sensitive or regulated information through the Services must notify Graxis before such information is submitted so that appropriate contractual and technical requirements can be evaluated.

Where applicable law classifies information as sensitive personal information or sensitive data, Graxis will process such information only as authorized by the individual, as reasonably necessary to provide the Services, or as otherwise permitted or required by applicable law.

5. How We Use Information

Graxis may use personal information to:

  • provide and operate the Services;

  • respond to inquiries;

  • schedule demonstrations, consultations, or appointments;

  • establish and manage Client accounts;

  • configure AI agents and automation systems;

  • provide customer support;

  • process transactions and billing;

  • send administrative and service-related communications;

  • facilitate communications requested by our Clients;

  • operate CRM systems and workflows;

  • troubleshoot technical issues;

  • monitor system performance;

  • maintain security;

  • prevent fraud, misuse, or unauthorized access;

  • comply with legal and regulatory requirements;

  • enforce our agreements;

  • improve our Services;

  • develop new functionality;

  • maintain business records; and

  • perform other purposes disclosed when information is collected.

Where required by applicable law, Graxis will rely on an appropriate legal basis for processing personal information.

6. Artificial Intelligence

Graxis uses artificial intelligence and automated technologies as part of its Services.

Depending on the implementation, AI systems may process information to:

  • respond to customer inquiries;

  • answer questions;

  • conduct or assist with telephone conversations;

  • schedule appointments;

  • classify communications;

  • summarize conversations;

  • route requests;

  • update CRM records;

  • generate suggested responses;

  • perform automated follow-up;

  • assist with customer service; and

  • support other business workflows.

Information submitted to AI-powered features may be transmitted to third-party technology providers used to provide those features.

Graxis takes reasonable steps to configure AI systems and third-party providers consistent with applicable contractual, privacy, security, and regulatory requirements.

AI-generated output may not always be accurate. Users should not rely upon AI systems for emergency services or independent medical, legal, financial, or other professional advice unless expressly designed, authorized, and appropriately supervised for such use.

6.1 AI Data Use and Model Training

Graxis does not independently use Client customer data, communications, or Confidential Information to train general-purpose artificial intelligence models for unrelated purposes.

Third-party AI providers may process information according to the configuration, contractual terms, and data-use policies applicable to the services Graxis utilizes.

Where Client data is subject to contractual or regulatory restrictions, Graxis will configure applicable AI services consistent with those requirements where supported.

7. SMS and Mobile Communications

When you provide your telephone number and consent to receive SMS communications from Graxis, we may use your number to send communications consistent with the consent you provided.

Message frequency may vary. Message and data rates may apply.

You may opt out of SMS communications by replying STOP or using another opt-out method identified in the applicable communication.

You may request assistance by replying HELP where supported.

Consent to receive marketing SMS communications is not a condition of purchasing Graxis Services unless otherwise permitted by applicable law.

7.1 Mobile Information

Mobile information collected for SMS communications will not be sold or rented to third parties for their own marketing purposes.

Graxis does not share mobile opt-in information or consent with third parties for those third parties' independent marketing or promotional purposes.

We may share information with service providers and telecommunications providers as necessary to deliver messages, operate our communications systems, prevent fraud or abuse, and comply with applicable law.

8. Email Communications

Graxis may send administrative, transactional, service-related, and, where permitted, marketing email communications.

Marketing communications will provide an appropriate method for unsubscribing where required by applicable law.

Certain administrative or transactional communications necessary to maintain an account or provide contracted Services may continue even after a user unsubscribes from marketing communications.

9. Cookies and Similar Technologies

Graxis and its service providers may use cookies and similar technologies to:

  • operate our website;

  • remember preferences;

  • maintain sessions;

  • understand website usage;

  • improve website functionality;

  • detect security threats; and

  • measure the effectiveness of marketing activities.

Depending on the technologies implemented on our website and applicable law, users may have choices regarding non-essential cookies through browser settings or a cookie-consent mechanism.

10. How We Share Information

Graxis does not sell personal information for monetary consideration. Certain privacy laws define “sale,” “sharing,” or “targeted advertising” more broadly and may treat some disclosures involving advertising or analytics technologies as a sale, sharing, or targeted advertising even when no money is exchanged. To the extent Graxis engages in activity subject to such definitions, Graxis will provide applicable notices and opt-out rights as required by law.

We may disclose personal information in the following circumstances.

10.1 Service Providers

We may provide information to companies that perform services on our behalf, including providers of:

  • cloud hosting;

  • CRM technology;

  • artificial intelligence;

  • telecommunications;

  • SMS delivery;

  • email delivery;

  • payment processing;

  • analytics;

  • cybersecurity;

  • data storage;

  • customer support; and

  • other infrastructure necessary to provide the Services.

These providers may access information only as reasonably necessary to perform services for Graxis or our Clients, subject to applicable contractual and legal requirements.

10.2 Client-Directed Processing

When Graxis provides Services on behalf of a business Client, information may be processed, disclosed, transferred, or otherwise handled according to that Client's instructions and configuration, subject to applicable law and contractual requirements.

10.3 Legal Requirements

Graxis may disclose information when reasonably necessary to:

  • comply with applicable law;

  • respond to lawful subpoenas, court orders, or governmental requests;

  • enforce our agreements;

  • investigate suspected fraud or unlawful activity;

  • protect the rights, safety, systems, or property of Graxis, our Clients, or others; or

  • establish or defend legal claims.

10.4 Business Transactions

Information may be transferred in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction.

Any recipient will remain subject to applicable privacy obligations concerning transferred personal information.

11. Third-Party Platforms

Graxis relies on third-party technology providers to operate portions of the Services.

Third-party providers acting on Graxis’s behalf may process information only as reasonably necessary to provide the applicable services, subject to contractual, legal, and security requirements. Where a third-party service is independently selected, connected, or directed by a Client or user, that provider’s own terms, privacy policy, and data-processing terms may also apply.

Graxis takes reasonable steps to select and configure providers appropriate for the applicable Services but cannot guarantee the security, availability, or practices of independent third-party systems outside Graxis's control.

12. Healthcare and Protected Health Information

Graxis may provide configurations designed to support Clients subject to the Health Insurance Portability and Accountability Act ("HIPAA").

A Service described as "HIPAA-capable," "HIPAA-configurable," or similar does not mean that every Graxis implementation is automatically HIPAA compliant.

Healthcare Clients must notify Graxis before using the Services to create, receive, maintain, or transmit protected health information ("PHI").

Where Graxis acts as a business associate and a Business Associate Agreement ("BAA") is legally required, the applicable BAA must be executed before PHI is processed through the applicable Graxis Services.

PHI subject to an applicable BAA will be handled according to the terms of that BAA and applicable law.

Graxis will not knowingly permit PHI to be processed through a Service or third-party provider that has not been approved by Graxis for the applicable HIPAA deployment.

Clients remain responsible for ensuring that their use of the Services complies with their own obligations under HIPAA and other applicable healthcare privacy laws.

13. Data Security

Graxis uses commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, or destruction.

Such measures may include, as appropriate:

  • access controls;

  • authentication mechanisms;

  • encryption provided by applicable platforms;

  • account security controls;

  • logging and monitoring;

  • restricted administrative access; and

  • security practices implemented by our technology providers.

However, no internet-connected system, software platform, telecommunications network, or data-storage system can guarantee absolute security.

Users and Clients are responsible for protecting their account credentials and notifying Graxis promptly of suspected unauthorized access.

14. Data Retention

Graxis retains personal information for as long as reasonably necessary to:

  • provide the Services;

  • maintain the applicable business relationship;

  • fulfill the purposes described in this Privacy Policy;

  • satisfy contractual obligations;

  • comply with legal requirements;

  • resolve disputes;

  • maintain appropriate business records; and

  • enforce agreements.

Retention periods may vary depending on the type of information and the systems involved.

Following termination of a Client relationship, Graxis may delete or render inaccessible Client data maintained within Graxis-controlled systems in accordance with the applicable Service Agreement and Terms and Conditions.

Information stored by third-party platforms may also be subject to those providers' retention requirements.

15. Children's Privacy

Graxis Services are intended for businesses and adults and are not directed toward children under thirteen (13).

Graxis does not knowingly collect personal information directly from children under thirteen through its general website or marketing Services.

If we learn that personal information from a child was collected directly by Graxis in violation of applicable law, we will take reasonable steps to delete it.

This section does not prevent Graxis from processing information on behalf of a Client where such processing is lawful and appropriately governed by the Client's instructions and applicable agreements.

16. Privacy Rights

Depending on where you reside and applicable law, you may have certain rights regarding your personal information, which may include rights to:

  • request access to personal information;

  • request correction of inaccurate information;

  • request deletion of certain information;

  • obtain information concerning certain disclosures or processing activities;

  • opt out of certain marketing communications; or

  • exercise other rights provided by applicable privacy law.

Not all rights apply in all circumstances, and certain information may be exempt from a request.

Graxis may take reasonable steps to verify your identity before fulfilling a privacy request.

Graxis will not discriminate against an individual for exercising a privacy right provided by applicable law.

If Graxis processes information solely on behalf of one of our Clients, we may direct your request to that Client or assist the Client in responding as required by applicable law.

Privacy requests concerning information controlled directly by Graxis may be submitted using the contact information provided at the end of this Privacy Policy.

17. U.S. State Privacy Rights

If Graxis processes the relevant information solely on behalf of a Client, Graxis may direct the request to that Client or assist the Client as required by applicable law.

If Graxis denies a request and applicable law provides a right to appeal, you may submit an appeal using the same privacy contact information and identify the request you are appealing.

To exercise an applicable state privacy right concerning information controlled directly by Graxis, contact us using the information in Section 22. Graxis may take reasonable steps to verify your identity, authority, or residency before fulfilling a request. Authorized agents may be required to provide evidence of authorization, and Graxis may separately verify the request with the individual where permitted by law.

Graxis does not engage in profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning individuals unless disclosed and implemented in accordance with applicable law.

  • exercise privacy rights without unlawful discrimination or retaliation.

  • appeal certain decisions Graxis makes concerning a privacy request; and

  • designate an authorized agent to submit certain requests on your behalf;

  • limit or withdraw consent to certain processing of sensitive personal information where provided by law;

  • opt out of certain sales, sharing, targeted advertising, or qualifying profiling activities;

  • obtain a portable copy of certain personal information;

  • request deletion of certain personal information;

  • request correction of inaccurate personal information;

  • request access to or confirmation of personal information Graxis processes;

Where applicable, such rights may include the right to:

Residents of certain U.S. states may have additional rights regarding their personal information under applicable state privacy laws. These rights vary by jurisdiction and may be subject to exceptions, limitations, eligibility requirements, and business applicability thresholds.

18. International Users

Graxis primarily provides Services within the United States.

If personal information is submitted to Graxis from outside the United States, the information may be processed or stored in the United States or other locations where Graxis or its service providers operate.

Users outside the United States are responsible for determining whether use of the Services is appropriate under laws applicable to them, and Graxis may implement additional contractual or technical requirements where necessary.

19. Links to Other Websites

Our website or Services may contain links to third-party websites.

Graxis is not responsible for the privacy practices, security, content, or policies of websites that we do not control.

Users should review the privacy policies of third-party websites before providing personal information.

20. Changes to This Privacy Policy

Graxis may update this Privacy Policy from time to time to reflect changes in our Services, technologies, business practices, legal requirements, regulatory requirements, or other legitimate business needs.

Material changes may be communicated through our website, email, the Services, or another reasonable method where appropriate or required by applicable law.

Unless otherwise stated, changes become effective when the updated Privacy Policy is published or at another time specified by Graxis, subject to applicable law.

The version of this Privacy Policy published on our website represents Graxis's then-current privacy practices.

We encourage users to review this Privacy Policy periodically.

Graxis will maintain appropriate internal records of material revisions to this Privacy Policy.

21. Relationship to Graxis Terms and Other Agreements

Use of Graxis Services is also subject to the applicable Graxis Terms and Conditions, Service Agreement, and any other agreements entered into between Graxis and the applicable Client.

Where Graxis processes regulated information under a separate Data Processing Agreement, Business Associate Agreement, or similar agreement, that agreement will control with respect to matters specifically governed by it.

22. Contact Us

Questions, privacy requests, or concerns regarding this Privacy Policy or Graxis's privacy practices may be directed to:

[email protected]

For privacy-related requests, please include sufficient information for Graxis to reasonably identify and respond to your request.

For contractual or legal notices unrelated to privacy matters, contact:

[email protected]

© 2026 | Graxis Technologies LLC | All Rights Reserved

Terms & Conditions | Privacy Policy