Privacy policy
Last updated: 4 October 2026
1. Data controller
The data controller is Securebit S.r.l., Viale Antonio Gramsci 17/B, 80122 Napoli (NA), Italy, VAT no. 07962871211. You can write to the controller at [email protected] or by certified email (PEC) at [email protected].
2. Scope
This policy covers the Praxenta Retail platform as a whole: the praxenta.com website, the app.praxenta.com back office used by merchants, the online shops published on *.shop.praxenta.com subdomains or on a merchant's own domain, and the connected channels (WhatsApp Business Platform, email, payments).
Praxenta Retail is a service for shops, so there are two roles:
- For the data of praxenta.com visitors and of merchants and their staff using the back office, Securebit S.r.l. is the data controller.
- For the data of a shop's customers (people who buy, write on WhatsApp or register in the online shop), the controller is the merchant and Securebit S.r.l. acts as a processor under Article 28 GDPR, on the basis of the data processing agreement attached to the terms of service. Securebit remains the controller only for what is needed to run and protect the platform (security, abuse prevention, invoicing of the platform fee, legal obligations).
3. Data we process
Visitors of praxenta.com
- Data entered in the "Request a demo" form: name, shop name, city, phone or WhatsApp number, email, product category and your message.
- Technical data needed to run and protect the website (IP address, user agent).
Merchants and staff (back-office users)
- Account data: email, name, password (stored only in hashed form), optional second authentication factor.
- Shop data: company name, VAT number, address, contacts, domain, settings, credentials of connected services (stored encrypted).
- Contract data: plan, fee, recorded fee payments, reminders, communications.
- Activity log of the back office and technical access logs.
Customers of the shops (processed on behalf of the merchant)
- Account and order data: name, email, phone, shipping and billing addresses, orders, carts, returns, preferences.
- WhatsApp conversations: phone number in international format, WhatsApp profile name, content of messages sent and received (text, images, documents, audio, location, button and list replies), delivery and read statuses, timestamps and technical metadata, and any replies generated by the assistant.
- Marketing consent, with its source and the date it was given or withdrawn.
- Attribution data (which conversation, campaign or channel an order came from).
4. WhatsApp Business Platform
WhatsApp messages are sent and received through the WhatsApp Business Platform (Cloud API) of Meta Platforms Ireland Limited. Message content, phone numbers and conversation metadata pass through Meta's systems and are stored, separately for each shop, in the platform database in the European Union. Each shop uses its own number and credentials; Praxenta's own number is used for the demo shop and for platform communications to merchants.
A shop can reply freely to a person for 24 hours after their last message; outside that window it can only send messages based on templates approved by Meta. Marketing messages are sent only to people who gave their consent and can be stopped at any time by replying to the message or writing to the shop. Meta's processing is described in its privacy policy.
5. AI assistant
If the merchant enables the assistant, the text of WhatsApp conversations and the catalogue and order information needed to answer are sent to OpenAI (OpenAI Ireland Ltd and OpenAI, L.L.C.) through its APIs to generate a proposed reply. Under the OpenAI API terms, data sent through the API is not used to train its models. Prices, availability and order statuses quoted by the assistant are checked against the shop's data before sending; when the assistant cannot answer, the conversation is handed to a person at the shop. No decision with legal effects is taken solely by automated means.
6. Payments
Payments in the online shops are handled by Stripe (Stripe Payments Europe, Ltd.) or PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A.) on each merchant's own accounts. Card details are entered directly on those providers' pages and are not stored by the platform, which only receives the outcome of the payment and a transaction reference. The platform fee owed by merchants is paid by bank transfer, outside the platform.
7. Providers and transfers
Besides Meta, OpenAI, Stripe and PayPal we use the following providers as processors or sub-processors: Supabase (database, authentication and file storage, data stored in the European Union), Vercel (application hosting and content delivery network), Cloudflare (DNS and traffic protection), Postmark (transactional email). Some of these providers are established or operate infrastructure outside the European Union: in those cases the transfer relies on the European Commission's standard contractual clauses or on an adequacy decision (for example the Data Privacy Framework for the United States). We do not sell or share data with third parties for marketing purposes.
8. Purposes and legal bases
- To provide the requested service: running the online shop, orders, conversations and the account (Article 6(1)(b) GDPR: performance of a contract or pre-contractual measures).
- To comply with legal obligations, in particular tax and accounting rules (Article 6(1)(c)).
- To send marketing communications by WhatsApp or email to the shops' customers (Article 6(1)(a): consent, which can be withdrawn at any time).
- To keep the platform secure, prevent abuse and improve the service with aggregated data (Article 6(1)(f): legitimate interest).
9. Retention
- Demo form data: for as long as needed to handle the request and, if you do not become a customer, for at most 24 months.
- Account and shop data: for the duration of the contract and 12 months after it ends, unless earlier deletion is requested.
- Orders and tax documents: 10 years, as required by law.
- WhatsApp conversations and messages: for the duration of the relationship with the shop and in any case no longer than 24 months after the last message, unless earlier deletion is requested.
- Technical and security logs: 12 months.
10. Your rights
You can request access to your data, rectification, erasure, restriction of processing, data portability and object to processing, and withdraw consent at any time. Write to [email protected] or by PEC to [email protected]. If you are a customer of a shop you can also contact the shop directly: we help it respond. You have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali, www.garanteprivacy.it). How to request deletion is explained on the data deletion page.
11. Cookies
The praxenta.com website uses technical cookies only, described in the cookie policy (Italian). The back office and the online shops use technical cookies needed for the session, login and cart; any tool that requires consent is disclosed by the banner of the individual shop.
12. Minors
The services are intended for businesses and adults. We do not knowingly collect data of children under 14; if you become aware of such a case, write to us and we will delete it.
13. Changes
We may update this policy when the services or the law change. The date at the top shows the latest version; material changes are communicated to merchants in the back office.