Legal
Privacy Policy
How ProDex Labs collects, uses, shares, and protects personal information across our website, the platform, and Dexter — including data from accounts you connect to Dexter.
Last updated October 1, 2026 · Version 2.2 · Effective October 1, 2026
1. Introduction
ProDex Labs, Inc. ("ProDex Labs", "ProDex", "we", "our", or "us") is committed to protecting the privacy of the individuals and organizations that interact with our products and services. This Privacy Policy (the "Policy") explains how we collect, use, share, and protect personal information when you access or use our website at prodexlabs.com, the ProDex AI-Native Discrete Event Simulation Studio platform, Dexter (the AI assistant within the platform), related APIs, SDKs, and connectors, and any other product, content, or service we provide (collectively, the "Services").
This Policy applies to personal information that we collect from prospective customers, customer employees and end users authorized to access the Services on behalf of a customer organization, website visitors, applicants, and partners. It does not apply to the manufacturing operational data and tenant business records that customer organizations process through the Services on behalf of their own users — for that data, the customer is the controller and ProDex Labs acts as a processor under our Data Processing Addendum (the "DPA"). For Services-customer data, please refer to the agreement between your organization and ProDex Labs.
If you connect an account from another service to Dexter, Section 7 describes the information we access and how we use, store, and share it. Section 7 controls over other provisions of this Policy for connected-account information. Section 7.6 contains additional requirements for information received from Google APIs ("Google User Data").
2. Information We Collect
We collect information in four categories: information you provide directly, information collected automatically when you use the Services, information we receive from third parties, and information you authorize us to access from connected accounts.
2.1 Information You Provide
- Account information: name, business email address, role/title, employer, phone number, and authentication identifiers when you create or are provisioned an account on the Services.
- Customer-administrator information: contact details for the named billing, technical, and security points of contact at customer organizations.
- Communications and support: information you submit when you contact us by email, in-product chat, support tickets, or response to a sales inquiry, including the contents of those messages.
- Marketing and event registrations: information you provide when you sign up for newsletters, attend a webinar or trade show, or download gated content.
- Recruiting: information submitted when you apply for a position with us, including résumé, work history, and references.
2.2 Information Collected Automatically
- Usage information: pages and features accessed, actions performed within the Services (e.g., model created, simulation run, analysis viewed, connector enabled), timestamps, browser type and language, device identifiers, operating system, and approximate location derived from IP address.
- Log and security telemetry: server logs, error reports, audit-log entries, and authentication events used to operate, secure, and troubleshoot the Services.
- Cookies and similar technologies: as described in Section 10.
2.3 Information from Third Parties
- Identity providers: when you authenticate via Single Sign-On (Google Workspace, Microsoft Entra, or other SSO/SAML/OIDC providers configured by your employer), we receive the basic profile information your employer authorizes (typically name, email, and group membership).
- Customers: in some cases your employer may provide us with your contact information so we can provision your account.
- Service providers and integrations: data passed to us by integrations you configure (for example, analytics platforms or productivity tools) is processed in accordance with the integration scope you authorize. For connected accounts used by Dexter, the more specific rules in Section 7 apply.
2.4 Information from Connected Accounts
If you choose to connect an account to Dexter, we receive information from that service under the read-only permissions you authorize. Depending on the connector, this may include email and attachments, calendar events, documents, spreadsheets, messages, records, and associated metadata. Available connectors and requested permissions are identified in the Connectors screen. Section 7 governs this information.
2.5 Manufacturing Operational and Tenant Business Data
The Services are designed for customer organizations to upload and process their own manufacturing operational data — including bills of materials, routings, inventory positions, work orders, supplier records, and IoT telemetry — together with models, plans, schedules, and analyses derived from that data. ProDex Labs handles this category of data exclusively as a processor on behalf of the customer organization, in accordance with the customer's DPA. We do not use this data to advertise to anyone, to train shared AI models, or for any purpose outside the contracted Services.
3. How We Use Information
We use the information described above for the following purposes:
- Providing, operating, securing, and improving the Services, including authentication, access control, monitoring, incident response, and reliability engineering.
- Processing transactions and managing customer accounts, including billing, renewals, and contract administration.
- Communicating with you about the Services — for example, service announcements, security notices, scheduled maintenance, contractual updates, and responses to your inquiries.
- Providing customer support, training, and onboarding.
- Conducting product research and improving features (using aggregated and de-identified information where feasible).
- Detecting, investigating, and preventing fraud, abuse, security incidents, and violations of our Acceptable Use Policy.
- Marketing communications about ProDex Labs products and services, only where you have opted in or where permitted by applicable law (you can opt out at any time).
- Complying with applicable laws and regulations, including U.S. federal and state law, the laws of the jurisdictions in which our customers operate, and U.S. export-control regimes including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR) where applicable.
Connected-account information is used only for the narrower purposes described in Section 7, and never for marketing, advertising, or training generative models.
4. Legal Bases for Processing EU/UK/Swiss data subjects
Where the European Union General Data Protection Regulation, the UK GDPR, or the Swiss Federal Act on Data Protection applies to our processing of your personal information, we rely on the following legal bases:
- Contract: to perform our agreement with you or your employer (for example, providing the Services and managing your account).
- Legitimate interests: to operate, secure, and improve the Services, defend against legal claims, and engage in proportionate marketing to business contacts. Our legitimate interests do not override your rights and freedoms.
- Consent: where you have provided consent, including for certain marketing communications, optional cookies, and connecting an account to Dexter. You can withdraw consent at any time. Stopping a connection and deleting information already retrieved are separate actions, as explained in Section 7.7.
- Legal obligation: where we are required to process your information to comply with applicable law.
5. Information Sharing and Disclosure
ProDex Labs does not sell personal information. We share personal information only in the limited circumstances described below:
- Service providers and subprocessors: we share information with vendors who perform services on our behalf and are contractually bound to confidentiality, security, and use limitations consistent with this Policy and our DPA. Section 9 identifies our subprocessors and which may receive connected-account content.
- Customer organizations: if you use the Services as an employee, contractor, or end user of a customer organization, we may share information about your use of the Services with that organization, such as audit logs, license counts, and account activity. For connected accounts, administrator reporting is limited to connection status and related audit events; connecting an account does not itself give your organization’s administrators access to the contents of that account through ProDex.
- Legal compliance and protection of rights: we may disclose information in response to a lawful request from a government authority, to comply with applicable law, to enforce our agreements (including the Acceptable Use Policy), or to protect the rights, property, or safety of ProDex Labs, our customers, or others. Where permitted, we will notify the customer first and only produce the minimum information necessary.
- Business transactions: in the event of a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred to a successor entity, subject to this Policy. Transfers of Google User Data are subject to Section 7.6, including explicit prior user consent where required by the Google API Services User Data Policy.
- With your consent or at your direction: we share information with third parties when you instruct us to do so (for example, by configuring an integration).
6. AI and Machine Learning Processing
The Services include Dexter, an AI-powered assistant that helps users author, refine, and analyze simulation models, schedules, and plans in conversation with the platform. Dexter uses large language models provided by Anthropic, PBC under their commercial terms, with supporting tracing provided by LangChain, Inc. (LangSmith).
- Customer-organization prompts and outputs sent to the underlying LLM provider, including connected-account content in a Dexter conversation, are not used by ProDex or the LLM provider to train shared models. We do not use connected-account content to train generative models.
- LangSmith traces and Sentry error reports may contain retrieved connected-account content. These services support debugging, quality evaluation, and operation of the Services, subject to the restrictions in Section 7. Access to the ProDex LangSmith organization requires an administrator to add the person. This access control does not override the restrictions on human access to Google User Data in Section 7.6.
- Dexter stores conversation state so it can maintain context across a conversation and resume interrupted tasks. Retrieved content may remain in conversation state, traces, provider systems, and backups. Sections 7.4 and 11 describe retention and deletion.
- Any additional processing restrictions agreed in a customer contract or DPA apply to the relevant customer data. Connecting an account does not authorize submission of information prohibited by those agreements.
7. Connected Accounts
7.1 Optional individual connections
Some ProDex features let you connect an account from another service so Dexter can retrieve information when you ask. Connections are optional and off by default. Each connection is authorized by the individual user; an administrator cannot connect an account on your behalf. Available services are shown in the Connectors screen.
7.2 Information and permissions
The Connectors screen describes the service, the information accessed, and the permissions requested before you authorize a connection. Where a provider uses its own consent screen, permissions are also presented there. Depending on the connector, retrieved information may include email headers, bodies and attachments; calendar event details and attendees; documents and spreadsheets; messages; records; and associated metadata. Basic account identifiers help identify the connected account.
Our current connectors request read-only permissions. ProDex does not send, create, modify, move, or delete content in a connected account. Dexter retrieves information only in response to your requests. We do not bulk-copy, index, or continuously synchronize connected-account contents, or access them when you are not using ProDex.
7.3 How information is used
We use retrieved information to answer your requests and maintain the associated conversation context. For example, Dexter may locate and summarize relevant messages, extract facts into a plan or simulation, or review calendar information. Content may also appear in operational traces and error reports used to operate, troubleshoot, and evaluate the Services, subject to the additional Google restrictions in Section 7.6.
We do not sell connected-account information, use it for advertising, or use it to train generative models. We do not use it to build profiles unrelated to the features you request.
7.4 Storage and deletion
Retrieved content may be stored in Dexter conversations and other application data, model-provider systems, operational traces, error reports, and backups. Connection credentials are stored separately with restricted access and are not included in content sent to model providers, tracing services, or error-monitoring services.
Disabling or disconnecting a connection stops further access through that connection but retains stored credentials and previously retrieved content. Revoking access through the connected service removes our stored credentials for that connection; previously retrieved content remains.
You can delete a conversation or other data containing retrieved content from ProDex. Deleting a ProDex user removes that user’s associated credentials and content from active application storage. These actions do not automatically remove separate copies in traces, third-party provider systems, or backups. Section 11 describes the applicable retention arrangements.
7.5 Recipients
Retrieved content may be processed by Anthropic to generate responses, LangSmith for operational tracing and evaluation, Sentry for error monitoring, and our cloud infrastructure providers for storage, hosting, and backups. Their identities and processing regions are listed in Section 9. These services do not receive connected-account content for advertising or their own independent purposes. Connection credentials are not sent to Anthropic, LangSmith, or Sentry as part of this processing.
Other disclosures for legal compliance, security, business transactions, or at your direction are described in Section 5. Processing and disclosure of Google User Data remain subject to Section 7.6.
7.6 Google User Data and Limited Use
ProDex Labs’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
These requirements apply to covered Google User Data and information derived from it. Human access is restricted to the circumstances permitted by that policy. Ordinary access to an operational tool does not itself authorize a person to read Google User Data. Permitted circumstances include affirmative user agreement to view specified data, necessary security or legal access, and qualifying aggregated internal use. Transfers, including in a business transaction, must satisfy the policy’s conditions and applicable consent requirements.
7.7 Your controls
Disable or disconnect in ProDex: stop access through a connection. Stored credentials and previously retrieved content remain.
Revoke with the provider: revoke ProDex’s authorization through the connected service’s account settings. Our stored credentials are removed; previously retrieved content remains.
Delete content or your user account: delete a conversation or other data containing retrieved content in ProDex, or arrange removal of your user account. The distinction between active storage and retained copies is explained in Sections 7.4 and 11.
Contact us: email privacy@prodexlabs.com to request access to or deletion of information. If you use ProDex through an organization, you may also contact its administrator. We handle verified requests within the timeframes required by applicable law.
8. International Data Transfers
ProDex Labs is headquartered in the United States. The information we collect may be processed in the United States and in other countries where our service providers operate (currently primarily the United States and the European Union via Google Cloud and Microsoft Azure regions). Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the relevant authority, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms, as applicable.
9. Subprocessors
ProDex uses the following subprocessors to deliver the Services. We will provide reasonable advance notice, typically through customer notifications and an updated public list, before adding or replacing a subprocessor that materially changes processing activities. The final column identifies recipients of connected-account content under Section 7; it does not indicate that connection credentials are sent to model, tracing, or error-monitoring services. Services connected by users are identified separately in the Connectors screen.
| Subprocessor | Purpose | Processing Region | Connected content |
|---|---|---|---|
| Google LLC (Google Cloud Platform) | Primary cloud infrastructure: GKE, Cloud SQL, Cloud Storage, Memorystore, Secret Manager, Cloud KMS, logging & monitoring | United States (us-central1) | Yes (hosting and backups) |
| Microsoft Corporation (Microsoft Azure) | Secondary cloud infrastructure for Azure-resident customer environments | United States; per customer-tenant region | Yes (Azure tenants) |
| Google LLC (Google Workspace) | Corporate email, calendar, collaborative documents, identity provider | United States | No |
| Anthropic, PBC | Large language model inference for Dexter | United States | Yes |
| LangChain, Inc. (LangSmith) | LLM tracing and offline evaluation | United States | Yes |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States | Yes (error reports) |
| GitHub, Inc. | Source code hosting and CI/CD | United States | No |
| Slack Technologies (Salesforce) | Internal communications and incident-response coordination | United States | No |
| Linear | Engineering issue tracking | United States | No |
| Vanta, Inc. | Continuous compliance monitoring and evidence collection | United States | No |
10. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Services and to understand how they are used. Cookies are small text files that are stored on your device. We use:
- Strictly necessary cookies — required for authentication, session management, security, and load balancing. These cannot be disabled without preventing core functionality of the Services.
- Functional cookies — used to remember preferences such as language and time zone.
- Analytics cookies — used in aggregate and pseudonymized form to understand product usage and improve the Services. We do not use analytics for cross-site advertising.
You can control cookies through your browser settings. Most browsers allow you to refuse new cookies, delete existing cookies, or be notified when new cookies are set.
11. Data Retention
Retention depends on the type of information, the purpose for which it is processed, applicable contracts, and legal requirements. Deletion from active application storage does not automatically delete separate copies in traces, provider systems, or backups.
- Customer-tenant data is retained for the duration of the customer's subscription and deleted or returned in accordance with the customer's DPA.
- Connected-account credentials: disabling or disconnecting a connection retains stored credentials. Revocation through the connected service removes our stored credentials. Deleting a ProDex user removes the credentials associated with that user.
- Conversation content: retrieved information remains in active application storage until the relevant conversation or other data containing it is deleted, the user is deleted, or another applicable retention rule requires removal. Disabling, disconnecting, or revoking a connection does not itself delete content already retrieved.
- Account information is retained for the duration of the account plus the period required by law and for legitimate business purposes (typically 7 years for financial and audit records).
- Operational traces, error reports, and provider copies: these may retain retrieved content after its deletion from ProDex’s active application storage. Retention of this content follows each provider’s configured settings and our agreements with them. Verified deletion requests are handled as described in Section 13, subject to legal holds.
- Marketing data is retained until you opt out, after which we retain only the minimum necessary to honor the opt-out.
- Backups: deleting a chat or other application data does not automatically remove copies from backups. Backup copies are kept for disaster recovery under restricted access and may persist after information is deleted from active application storage.
12. Security
We take reasonable and appropriate technical, organizational, and physical measures to protect personal information from loss, misuse, unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 on managed cloud services).
- Role-based access control with multi-factor authentication enforced for production access.
- Encrypted storage of connection credentials with restricted access.
- Continuous logging, monitoring, and alerting on the production environment.
No method of transmission over the Internet or method of electronic storage is 100% secure. While we use commercially reasonable means to protect personal information, we cannot guarantee its absolute security.
13. Your Choices and Rights
Depending on where you reside and the nature of our relationship with you, you may have rights with respect to your personal information, including the rights to:
- Access — request a copy of the personal information we hold about you.
- Rectify — correct inaccurate or incomplete personal information.
- Delete — request deletion of personal information, subject to certain exceptions (such as legal-hold and ongoing contractual obligations).
- Restrict or object — restrict or object to certain processing, including processing based on our legitimate interests.
- Portability — receive a copy of your personal information in a structured, commonly used, machine-readable format.
- Withdraw consent: withdraw consent where processing is based on consent. You can stop connected-account access and request deletion as described in Section 7.7. Stopping access does not itself remove content already retrieved.
- Opt out of marketing — opt out of marketing communications by following the unsubscribe link in any email or by contacting us.
- Lodge a complaint — California residents may exercise rights under the California Consumer Privacy Act (CCPA/CPRA), and EU/UK/Swiss residents may lodge a complaint with their supervisory authority.
If you are a user of the Services through a customer organization, please direct rights requests to your employer first; we will work with the customer to fulfill verified requests. To submit a request directly, contact privacy@prodexlabs.com. We will respond within the timeframes required by applicable law.
14. Children’s Privacy
The Services are intended for business and professional use. They are not directed to and are not intended for use by individuals under the age of 18, and we do not knowingly collect personal information from individuals under 18. If we become aware that we have collected personal information from an individual under 18, we will take steps to delete that information.
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will provide notice through the Services, by email to the customer-administrator contact, or by other reasonable means before the changes take effect. The Last Updated date at the top of this Policy reflects the most recent revision. Prior versions are archived and made available on request to privacy@prodexlabs.com.
16. Contact Us
If you have questions or concerns about this Policy or our privacy practices, please contact us:
Email: privacy@prodexlabs.com
Mail: ProDex Labs, Inc., New York, New York, United States. Attn: Information Security Officer
17. Relationship to Other Agreements
This Policy should be read together with our Terms of Service, Acceptable Use Policy, and, for customer organizations, the Master Subscription Agreement and Data Processing Addendum. Where this Policy conflicts with the DPA concerning processing of customer-tenant data on a customer’s behalf, the DPA controls. For Google User Data, Section 7.6 controls to the extent required by the Google API Services User Data Policy. Nothing in this Policy expands the categories of data a customer is permitted to submit under its agreements.