doxa.co
  • Platform
    DOXA ReputationReview management, surveys, sentiment & analytics DoxaConnectAI lead generation & WhatsApp customer re-engagement DoxaPrimeRevenue-attributed reporting & lost lead recovery
  • Automotive
  • DMCCA Compliance
  • Resources
  • Insights
Log In Book a Demo ▶ Demo
Legal

Privacy Policy

How Pixxnow Limited, trading as DOXA, collects, uses, stores and protects personal data across the doxa.co website and the Doxa.co, DoxaConnect and DoxaPrime applications.

Effective date: 18 August 2026  ·  Last updated: 18 August 2026  ·  Version: 1.0

Data controller: Pixxnow Limited, trading as DOXA, a company registered in Ireland.

Company registration number (CRO): 571154  ·  VAT number: IE3401470EH

Registered office: The Cubes Offices, Beacon South Quarter, Sandyford, Dublin, Ireland

Contents

  1. Who we are
  2. Scope of this policy
  3. Controller and processor roles
  4. Personal data we collect
  5. Google user data and Limited Use
  6. WhatsApp and DoxaConnect
  7. Automated processing and AI
  8. Legal bases for processing
  9. Sharing and sub-processors
  10. International transfers
  11. Data retention
  12. Security
  13. Your rights
  14. Cookies and similar technologies
  15. Children
  16. Changes to this policy
  17. Contact us

1. Who we are

DOXA is a trading name of Pixxnow Limited, an Irish-registered company (CRO number 571154) with its registered office at The Cubes Offices, Beacon South Quarter, Sandyford, Dublin, Ireland, and a UK presence in Birmingham. We provide software to franchised automotive dealerships and dealer groups in Ireland and the United Kingdom.

Our platform comprises three applications:

  • Doxa.co (DOXA Reputation) — Google-first review and reputation management, customer feedback surveys and sentiment analytics for dealerships.
  • DoxaConnect — AI-assisted customer re-engagement over WhatsApp, identifying vehicle upgrade opportunities within a dealership's existing customer database.
  • DoxaPrime — AI-generated intelligence reporting that turns customer feedback and dealership activity into commercial insight.

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679), the Irish Data Protection Act 2018, and the UK GDPR and Data Protection Act 2018 where our processing relates to individuals in the United Kingdom.

2. Scope of this policy

This policy applies to:

  • Visitors to https://doxa.co and its subdomains.
  • Dealership staff who hold user accounts on any DOXA application.
  • Individuals whose personal data is processed by DOXA on behalf of a dealership customer — for example, a dealership's own customers who receive a feedback survey or a WhatsApp message.
  • Prospective customers, job applicants and business contacts who correspond with us.

3. Controller and processor roles

Our role under data protection law depends on the data in question, and the distinction matters for how you exercise your rights.

Category of dataOur roleExplanation
Website visitors, enquiries, marketing contacts, job applicantsControllerWe decide why and how this data is processed.
Dealership user accounts and platform administrationControllerWe manage account credentials, access and billing.
A dealership's customer records, feedback, reviews and messaging historyProcessorThe dealership is the controller. We process this data on their documented instructions under a data processing agreement.

Where we act as a processor, requests to access, correct or delete personal data should be directed to the dealership that holds the relationship with you. We will assist that dealership in responding. If you are unsure which dealership holds your data, contact us and we will help you identify it.

4. Personal data we collect

4.1 Data you give us directly

  • Contact and enquiry data — name, business email address, telephone number, job title, company name, and the content of your enquiry, submitted through our contact, demo request or careers forms.
  • Account data — name, business email address, role and authentication credentials for users of our applications.
  • Correspondence — emails, support tickets and other communications between you and DOXA.

4.2 Data we collect automatically

  • Technical data — IP address, browser type and version, operating system, device type, and referring page.
  • Usage data — pages viewed, features used, and actions taken within our applications.
  • Log data — application and security logs recording access events and errors.

4.3 Data we receive from dealership customers

When a dealership subscribes to DOXA, we receive customer records exported from their dealer management system. Depending on the products in use, these may include name, contact details, vehicle details, service and purchase history, and finance term dates. We process this data solely to deliver the contracted service.

4.4 Data we receive from third-party platforms

We receive data from Google and from Meta (WhatsApp) as described in sections 5 and 6.

5. Google user data and Limited Use

The Doxa.co application connects to Google Business Profile on behalf of a dealership so that reviews and location information can be managed from a single interface. This section explains exactly what we access and what we do with it.

5.1 What we access

  • Google account identity — the email address and basic profile of the user who authorises the connection, used to associate the connection with a DOXA account.
  • Google Business Profile location data — the business locations the authorising user manages, including name, address and profile details.
  • Reviews — customer reviews left on those locations, including star rating, review text, reviewer display name and timestamp.
  • Review replies — we post replies to reviews on the dealership's behalf, at the dealership's instruction.

5.2 What we do with it

  • Display reviews and location performance inside the DOXA dashboard.
  • Generate reporting, sentiment analysis and intelligence for the dealership that owns the locations.
  • Publish review responses that the dealership has drafted or approved.

Limited Use disclosure

Doxa.co's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we confirm that we do not:

  • Transfer or sell Google user data to third parties for advertising, marketing or any other purpose unrelated to delivering our service.
  • Use Google user data to serve advertisements of any kind.
  • Use Google user data to train generalised or third-party artificial intelligence or machine learning models.
  • Allow humans to read Google user data, except where the user has given explicit consent, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.

5.3 Revoking access

A dealership may disconnect its Google Business Profile from Doxa.co at any time from within the application settings, or by revoking access at https://myaccount.google.com/permissions. Once access is revoked we cease retrieving Google user data, and cached Google user data is deleted within 30 days.

6. WhatsApp and DoxaConnect

DoxaConnect sends messages to a dealership's customers using the WhatsApp Business Platform, operated by Meta Platforms Ireland Limited. Messages are sent on the instruction of the dealership, which is the controller of that customer relationship and is responsible for establishing a lawful basis for contacting its customers.

In line with Article 50(1) of the EU Artificial Intelligence Act, recipients are informed at the outset of a conversation that they are interacting with an automated system. Recipients may opt out of further messages at any time by replying to the message. Opt-outs are honoured immediately and recorded.

Message content and delivery metadata are also processed by Meta under its own terms. See the WhatsApp Privacy Policy.

7. Automated processing and artificial intelligence

DOXA uses artificial intelligence to analyse customer feedback, classify sentiment, detect potential service issues, summarise review content and score the likelihood that a customer is ready to upgrade a vehicle. These outputs are decision-support tools presented to dealership staff. They do not produce legal effects concerning any individual and are not used to make solely automated decisions of the kind described in Article 22 of the GDPR.

We do not use personal data processed on behalf of our dealership customers to train generalised artificial intelligence models.

8. Legal bases for processing

PurposeLegal basis
Providing and administering our applications to subscribing dealershipsPerformance of a contract — Article 6(1)(b)
Responding to enquiries and demo requestsLegitimate interests — responding to a request directed to us, Article 6(1)(f)
Service security, fraud prevention and audit loggingLegitimate interests — protecting our platform and our customers, Article 6(1)(f)
Marketing communications to business contactsConsent, or legitimate interests where permitted by the ePrivacy Regulations 2011
Meeting legal, tax and regulatory obligationsLegal obligation — Article 6(1)(c)
Recruitment and assessment of job applicantsSteps prior to entering a contract — Article 6(1)(b), and legitimate interests

Where we rely on legitimate interests, we have carried out a balancing assessment and are satisfied that our interests are not overridden by the rights and freedoms of the individuals concerned. You may request further detail on that assessment at any time.

9. Sharing and sub-processors

We do not sell personal data. We share it only with service providers who process it on our behalf under written contract, and with professional advisers, regulators or authorities where we are legally required to do so.

ProviderPurposeProcessing location
Google Cloud PlatformApplication hosting and database servicesEU region
Amazon Web ServicesWhatsApp Business API infrastructureEU region
SupabaseDatabase and authentication servicesEU region
Meta Platforms Ireland LimitedWhatsApp message deliveryIreland, with onward global processing under Meta's terms
Google LLCGoogle Business Profile integrationGlobal
NetlifyWebsite hosting and content deliveryGlobal CDN
FormspreeWebsite contact form submission handlingUnited States

An up-to-date list of sub-processors is available to subscribing customers on request. We give customers advance notice of any intended change to our sub-processors.

10. International transfers

Our core application infrastructure — Google Cloud Platform, Amazon Web Services and Supabase — is hosted in EU regions, so customer data processed through our applications remains within the European Economic Area in normal operation.

Some ancillary services are located outside the EEA. Where personal data is transferred outside the EEA, we rely on one of the following safeguards:

  • An adequacy decision of the European Commission in respect of the destination country, including the EU–US Data Privacy Framework where the recipient is certified.
  • The European Commission's Standard Contractual Clauses, supplemented by a transfer impact assessment and, where required, additional technical and organisational measures.
  • The UK International Data Transfer Addendum, for transfers subject to the UK GDPR.

Copies of the relevant safeguards are available on request using the contact details in section 17.

11. Data retention

We retain personal data only for as long as necessary for the purposes set out in this policy, and then delete or irreversibly anonymise it.

DataRetention period
Enquiry, demo request and prospect data24 months from last meaningful contact
Marketing contact dataUntil you opt out. A minimal suppression record is kept indefinitely so we do not contact you again
Dealership user account dataDuration of the subscription, then deleted within 30 days of account closure
Customer data processed on behalf of a dealershipDuration of the subscription, then deleted or returned within 30 days of termination, in accordance with the data processing agreement
Google user data cached in our systemsDeleted within 30 days of the Google Business Profile connection being revoked
WhatsApp conversation recordsDuration of the subscription; individual conversation records are purged 24 months after the last interaction
Accounting, invoicing and tax records6 years from the end of the relevant accounting period, as required by Irish tax law
Employment and payroll records6 years after employment ends
Unsuccessful job applications12 months from the conclusion of the recruitment process
Application and security access logs12 months
Web server and infrastructure logs12 months
Encrypted system backups35 days on a rolling cycle, after which they are overwritten

Where we are required to retain data to establish, exercise or defend a legal claim, we will retain it for as long as that requirement subsists.

12. Security

We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control, multi-factor authentication for administrative access, network segregation, audit logging, regular patching, and vetting of personnel with access to customer data. Our website enforces HTTPS and a strict set of security response headers.

We operate a documented process for assessing and reporting personal data breaches, and will notify the relevant supervisory authority and affected individuals where the applicable legal thresholds are met.

No system is completely secure. If you believe your account has been compromised, contact us immediately using the details in section 17.

13. Your rights

Subject to the conditions in applicable law, you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Rectify inaccurate or incomplete personal data.
  • Erase your personal data where there is no ongoing lawful reason for us to hold it.
  • Restrict processing in certain circumstances.
  • Object to processing carried out on the basis of legitimate interests, and to direct marketing at any time.
  • Data portability — receive data you provided to us in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us using the details in section 17. We will respond within one month, and will tell you if we need to extend that period. We do not charge a fee unless a request is manifestly unfounded or excessive.

If you are dissatisfied with how we have handled your personal data, you may lodge a complaint with the Irish Data Protection Commission at www.dataprotection.ie, or, if you are in the United Kingdom, with the Information Commissioner's Office at ico.org.uk. We would appreciate the opportunity to address your concerns first.

14. Cookies and similar technologies

This website does not use cookies. We set no cookies of any kind — no analytics cookies, no advertising cookies, no tracking or profiling cookies, and no third-party marketing pixels. There is therefore no cookie consent banner, because there is nothing to consent to.

For completeness, we should disclose two related technologies:

  • Browser session storage. Our product demonstration pages store a single value in your browser's session storage to remember that you have entered the demonstration access code. It contains no personal data, is deleted when you close the browser tab, and is strictly necessary to provide the feature you requested. It is therefore exempt from the consent requirement under Regulation 5(5) of the ePrivacy Regulations 2011.
  • Third-party resources. Our pages load typefaces from Google Fonts and, on the demonstration pages only, a document generation library from the Cloudflare CDN. These providers necessarily receive your IP address in order to serve the file. They do not set cookies through our site and we receive no analytics or identifying data back from them.

Where you sign in to a DOXA application, a strictly necessary session cookie may be set by that application to keep you logged in. It is essential to the service, contains no marketing or tracking data, and is cleared when you sign out.

15. Children

Our services are business-to-business tools and are not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.

16. Changes to this policy

We may update this policy from time to time to reflect changes in our services, technology or legal obligations. The effective date and version number at the top of this page show when it was last revised. Where changes are material, we will notify subscribing customers directly and, where required, seek fresh consent.

17. Contact us

For any question about this policy, or to exercise any of your rights, contact:

Pixxnow Limited, trading as DOXA
The Cubes Offices, Beacon South Quarter
Sandyford, Dublin, Ireland
CRO 571154 · VAT IE3401470EH

Email: support@doxa.co
Telephone: +353 1 908 1570

We have assessed our processing activities against Article 37 of the GDPR and concluded that we are not required to appoint a statutory Data Protection Officer. Privacy matters are handled by the company's directors, who can be reached at the address above.

doxa.co

AI-powered reputation management and customer intelligence for automotive retail. Headquartered in Dublin, with offices in Birmingham.

Cyber Essentials Plus GDPR Compliant

Platform

DOXA Reputation DoxaConnect DoxaPrime Automotive

Resources

Free Resources Insights & Blog DMCCA Compliance Contact

Company

About DOXA Careers Privacy Policy Log In sales@doxa.co
© 2026 Pixxnow Limited trading as DOXA. Registered in Ireland, CRO 571154. All rights reserved.
Dublin, Ireland • Birmingham, UK