Data architecture and security

Nobody learns from Proxeno that your practice might sell, and no buyer sees which practice a record belongs to, until you choose to list. This page describes how the platform holds practice information so that promise stands. How we use your data lists what each form and tool collects; the privacy policy is the policy behind both pages.

How practice information is held today

Information about a practice reaches us three ways: the forms on this site, the two evaluation tools and the research that builds the market dataset.

The evaluation tools never receive a practice name. Your answers are stored against a random ID, and if you type a practice name into a tool it stays in your browser and appears only on your own report. Form submissions do carry your name and contact details, because you are asking us to contact you. They go to our CRM, where access rules and the small number of people who handle them keep what you tell us out of everything a buyer sees.

The market dataset is built from public and commercial sources and records who owns what. It holds no evaluation answers and nothing you tell us in confidence.

The identity store

The build under way separates a practice's identity from its record. The name, the address and anything that points to the practice move to a separate store. The main record holds the numbers and the traits but not the name. A code links the two, and the name is joined back only when the seller opts onto the sell list.

A cloakroom is the way to picture it. You hand in your coat and take a numbered ticket. The coat goes to the back room and the front desk holds only tickets, so nobody at the desk can tell whose coat is whose. The coat comes out only when you present yourself and ask for it, and the desk notes the time it was collected.

Once this is live, the separation stops depending on people following rules. The records buyers see hold no name at all.

The consent log

Every time a practice provides information, the platform records what it was told the information would be used for and what it agreed to. The log is append-only: entries are added and dated, never edited or removed. When a seller opts onto the sell list and the name is joined back to the record, that is one more dated entry.

A platform that holds confidential information about who might sell can be asked to prove it never used that information before the owner agreed. The identity store and this log are the answer: the working record carries no name to use, and the log dates the moment the name came back.

Where the data is stored

Form submissions go to Zoho CRM on Zoho's Australian data centre. Answers and scores from the two evaluation tools, and the criteria recorded on the buyer form, sit on AWS infrastructure in Australia. Proxeno builds on AWS in Australia, and the identity store and consent log will sit there too.

The chat assistant inside the readiness tool sends your message to an AI model on AWS Bedrock in the Sydney region. The model receives the question you are viewing, never your answers, and conversations are not stored.

What each tool collects

The detail, form by form and tool by tool, is on how we use your data. To ask about anything on this page, or to request deletion of anything you have sent us, email admin@proxeno.io.