1. Overview
This Privacy Policy describes how Pixora Technologies (“Pixora”, “we”, “us” or “our”) handles personal information when you visit pixoratechnologies.com, email us, request a proposal, or engage us for website development, AI automation, SaaS and CRM development, 3D design, UI/UX design or graphic illustration services.
We are a design and technology studio, not an advertising company. We do not sell personal information, we do not build advertising profiles, and we do not share your data with data brokers. The data we hold exists so we can answer your enquiry, deliver the work you hired us for, and meet our legal and accounting obligations.
By using our website or engaging our services, you agree to the practices described here. If you do not agree, please do not use the site — and feel free to email us with your concerns before deciding.
2. Information we collect
2.1 Information you give us directly
Our contact form opens your own email client and sends a message to us. That message contains only what you typed into it, which typically includes:
- Your name and email address
- Your company or organisation name
- The service you are interested in, your budget range and preferred timeline
- Any project details, requirements or files you choose to describe or attach
Because the form is a mailto link, nothing you type is transmitted to, stored on, or processed by this website. The information reaches us only when you press send in your own email application, and only in the form of an ordinary email.
2.2 Information collected during an engagement
Once a project begins we may receive additional information necessary to do the work: billing and company details, contact details for your team members, brand assets, access credentials to systems we are asked to integrate with, and content or documents you provide for the build.
2.3 Information collected automatically
Like most websites, our hosting infrastructure records standard technical information when a page is served: IP address, browser and device type, referring page, pages viewed and timestamps. This is used for security, abuse prevention and aggregate traffic understanding — not to identify you personally.
2.4 Information we deliberately do not collect
- Payment card numbers — payments are processed by our bank or by third-party processors, never by us
- Special-category data (health, biometrics, religious or political views) unless a project specifically requires it and a separate agreement is in place
- Data from anyone we know to be under 16 years old
3. How we use your information
We use personal information only for the purposes below, and only for as long as those purposes apply:
- Responding to enquiries — answering your questions and preparing proposals, scopes and quotes
- Delivering services — designing, building, deploying and supporting the work you engaged us for
- Project communication — progress updates, staging links, review requests and handover materials
- Billing and accounting — issuing invoices, recording payments and meeting tax obligations
- Improving our work — understanding in aggregate which services and pages are useful
- Legal compliance — responding to lawful requests and enforcing our agreements
Where the law requires a lawful basis, ours is one of: performance of a contract with you, our legitimate interest in running and improving a professional services business, your consent (which you may withdraw at any time), or compliance with a legal obligation.
We will never sell, rent or trade your personal information, add you to a marketing list you did not ask to join, or use your project data to train publicly available AI models.
4. Client and project data
During a project we frequently act as a data processor on your behalf — for example, when we build a CRM containing your customers' records, or migrate a database into a new platform. In those cases:
- You remain the data controller and decide the purpose of processing
- We process that data only on your documented instructions and only to complete the agreed work
- We access production data only where genuinely necessary, preferring anonymised or seeded test data
- We can sign a Data Processing Agreement (DPA) before the engagement begins — just ask
- On project completion we return or securely delete the data at your direction
Credentials you share with us are stored in an encrypted password manager, limited to the team members who need them, and revoked or rotated at handover. We ask that you issue us scoped, revocable access rather than sharing primary account passwords.
5. AI services and your data
Our AI Automation service involves sending data through language models and related APIs. We take a conservative position on this:
- We use enterprise API endpoints with model training explicitly disabled
- API usage is billed to your own provider account wherever possible, so you retain visibility and control
- Sensitive fields are redacted or tokenised before leaving your environment where the workflow allows
- For regulated or highly sensitive workloads we can deploy open models on infrastructure you control, so no data leaves your perimeter
- We document what data each automation touches, so you always know the flow
6. Cookies and analytics
This website uses only what is strictly necessary to function. We store your light/dark theme preference in your browser's local storage so the site remembers how you like to read it — that preference never leaves your device and is not linked to you.
Where a client project or a future version of this site includes analytics, it will be privacy-respecting and disclosed here first. We do not run third-party advertising trackers, retargeting pixels or social media beacons.
7. Sharing and service providers
We share personal information only in these limited circumstances:
- Service providers — hosting, email, cloud storage, version control, project management and accounting platforms that we need to operate. Each is bound by contract to protect the data and use it only for the service they provide to us.
- Your own instructions — where you ask us to integrate with or transfer data to a third party
- Professional advisers — accountants and lawyers, under a duty of confidentiality
- Legal requirement — where we are compelled by valid legal process, in which case we will notify you unless legally prohibited
- Business transfer — if Pixora is acquired or merged, subject to the same protections described here
8. How long we keep information
- Enquiries that do not become projects — up to 24 months, then deleted
- Active project data — for the duration of the engagement
- Project archives and source files — 12 months after handover, so we can support you, unless you ask us to delete them sooner
- Invoices and financial records — as long as tax and accounting law requires
- Server logs — typically 30 to 90 days
You can ask us to delete your information at any time, subject to any records we are legally obliged to keep.
9. Security
We apply the same standards to our own systems that we build into client work:
- Encryption in transit (TLS) and at rest for stored project data
- Multi-factor authentication on every business-critical account
- Role-based access on a least-privilege basis, reviewed when team members change roles
- Encrypted credential management, with rotation at project handover
- Regular dependency and vulnerability patching
- Confidentiality obligations for every team member and subcontractor
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and any relevant supervisory authority without undue delay, and tell you what happened and what we are doing about it.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Request deletion of your information
- Restrict or object to certain processing
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these, email info@pixoratechnologies.com with “Privacy request” in the subject line. We respond within 30 days and will never charge you for a reasonable request.
11. International transfers
We work with clients and service providers across multiple countries, so your information may be processed outside your own jurisdiction. Where that happens we rely on appropriate safeguards — such as standard contractual clauses or an adequacy decision — to ensure your information keeps an equivalent level of protection.
12. Children's privacy
Our services are intended for businesses and professionals. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it promptly.
13. Changes to this policy
We may update this policy as our services or the law change. The “last updated” date at the top always reflects the current version. Material changes affecting active clients will be communicated by email rather than left to be discovered.
14. Contact us
Questions, requests or concerns about privacy at Pixora Technologies can go directly to info@pixoratechnologies.com. A real person on the team reads it, and you will hear back within one business day.
See also our Terms & Conditions, which govern the commercial side of working with us.