How Pixxnow Limited, trading as DOXA, collects, uses, stores and protects personal data across the doxa.co website and the Doxa.co, DoxaConnect and DoxaPrime applications.
DOXA is a trading name of Pixxnow Limited, an Irish-registered company (CRO number 571154) with its registered office at The Cubes Offices, Beacon South Quarter, Sandyford, Dublin, Ireland, and a UK presence in Birmingham. We provide software to franchised automotive dealerships and dealer groups in Ireland and the United Kingdom.
Our platform comprises three applications:
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679), the Irish Data Protection Act 2018, and the UK GDPR and Data Protection Act 2018 where our processing relates to individuals in the United Kingdom.
This policy applies to:
Our role under data protection law depends on the data in question, and the distinction matters for how you exercise your rights.
| Category of data | Our role | Explanation |
|---|---|---|
| Website visitors, enquiries, marketing contacts, job applicants | Controller | We decide why and how this data is processed. |
| Dealership user accounts and platform administration | Controller | We manage account credentials, access and billing. |
| A dealership's customer records, feedback, reviews and messaging history | Processor | The dealership is the controller. We process this data on their documented instructions under a data processing agreement. |
Where we act as a processor, requests to access, correct or delete personal data should be directed to the dealership that holds the relationship with you. We will assist that dealership in responding. If you are unsure which dealership holds your data, contact us and we will help you identify it.
When a dealership subscribes to DOXA, we receive customer records exported from their dealer management system. Depending on the products in use, these may include name, contact details, vehicle details, service and purchase history, and finance term dates. We process this data solely to deliver the contracted service.
We receive data from Google and from Meta (WhatsApp) as described in sections 5 and 6.
The Doxa.co application connects to Google Business Profile on behalf of a dealership so that reviews and location information can be managed from a single interface. This section explains exactly what we access and what we do with it.
Doxa.co's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we confirm that we do not:
A dealership may disconnect its Google Business Profile from Doxa.co at any time from within the application settings, or by revoking access at https://myaccount.google.com/permissions. Once access is revoked we cease retrieving Google user data, and cached Google user data is deleted within 30 days.
DoxaConnect sends messages to a dealership's customers using the WhatsApp Business Platform, operated by Meta Platforms Ireland Limited. Messages are sent on the instruction of the dealership, which is the controller of that customer relationship and is responsible for establishing a lawful basis for contacting its customers.
In line with Article 50(1) of the EU Artificial Intelligence Act, recipients are informed at the outset of a conversation that they are interacting with an automated system. Recipients may opt out of further messages at any time by replying to the message. Opt-outs are honoured immediately and recorded.
Message content and delivery metadata are also processed by Meta under its own terms. See the WhatsApp Privacy Policy.
DOXA uses artificial intelligence to analyse customer feedback, classify sentiment, detect potential service issues, summarise review content and score the likelihood that a customer is ready to upgrade a vehicle. These outputs are decision-support tools presented to dealership staff. They do not produce legal effects concerning any individual and are not used to make solely automated decisions of the kind described in Article 22 of the GDPR.
We do not use personal data processed on behalf of our dealership customers to train generalised artificial intelligence models.
| Purpose | Legal basis |
|---|---|
| Providing and administering our applications to subscribing dealerships | Performance of a contract — Article 6(1)(b) |
| Responding to enquiries and demo requests | Legitimate interests — responding to a request directed to us, Article 6(1)(f) |
| Service security, fraud prevention and audit logging | Legitimate interests — protecting our platform and our customers, Article 6(1)(f) |
| Marketing communications to business contacts | Consent, or legitimate interests where permitted by the ePrivacy Regulations 2011 |
| Meeting legal, tax and regulatory obligations | Legal obligation — Article 6(1)(c) |
| Recruitment and assessment of job applicants | Steps prior to entering a contract — Article 6(1)(b), and legitimate interests |
Where we rely on legitimate interests, we have carried out a balancing assessment and are satisfied that our interests are not overridden by the rights and freedoms of the individuals concerned. You may request further detail on that assessment at any time.
We do not sell personal data. We share it only with service providers who process it on our behalf under written contract, and with professional advisers, regulators or authorities where we are legally required to do so.
| Provider | Purpose | Processing location |
|---|---|---|
| Google Cloud Platform | Application hosting and database services | EU region |
| Amazon Web Services | WhatsApp Business API infrastructure | EU region |
| Supabase | Database and authentication services | EU region |
| Meta Platforms Ireland Limited | WhatsApp message delivery | Ireland, with onward global processing under Meta's terms |
| Google LLC | Google Business Profile integration | Global |
| Netlify | Website hosting and content delivery | Global CDN |
| Formspree | Website contact form submission handling | United States |
An up-to-date list of sub-processors is available to subscribing customers on request. We give customers advance notice of any intended change to our sub-processors.
Our core application infrastructure — Google Cloud Platform, Amazon Web Services and Supabase — is hosted in EU regions, so customer data processed through our applications remains within the European Economic Area in normal operation.
Some ancillary services are located outside the EEA. Where personal data is transferred outside the EEA, we rely on one of the following safeguards:
Copies of the relevant safeguards are available on request using the contact details in section 17.
We retain personal data only for as long as necessary for the purposes set out in this policy, and then delete or irreversibly anonymise it.
| Data | Retention period |
|---|---|
| Enquiry, demo request and prospect data | 24 months from last meaningful contact |
| Marketing contact data | Until you opt out. A minimal suppression record is kept indefinitely so we do not contact you again |
| Dealership user account data | Duration of the subscription, then deleted within 30 days of account closure |
| Customer data processed on behalf of a dealership | Duration of the subscription, then deleted or returned within 30 days of termination, in accordance with the data processing agreement |
| Google user data cached in our systems | Deleted within 30 days of the Google Business Profile connection being revoked |
| WhatsApp conversation records | Duration of the subscription; individual conversation records are purged 24 months after the last interaction |
| Accounting, invoicing and tax records | 6 years from the end of the relevant accounting period, as required by Irish tax law |
| Employment and payroll records | 6 years after employment ends |
| Unsuccessful job applications | 12 months from the conclusion of the recruitment process |
| Application and security access logs | 12 months |
| Web server and infrastructure logs | 12 months |
| Encrypted system backups | 35 days on a rolling cycle, after which they are overwritten |
Where we are required to retain data to establish, exercise or defend a legal claim, we will retain it for as long as that requirement subsists.
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control, multi-factor authentication for administrative access, network segregation, audit logging, regular patching, and vetting of personnel with access to customer data. Our website enforces HTTPS and a strict set of security response headers.
We operate a documented process for assessing and reporting personal data breaches, and will notify the relevant supervisory authority and affected individuals where the applicable legal thresholds are met.
No system is completely secure. If you believe your account has been compromised, contact us immediately using the details in section 17.
Subject to the conditions in applicable law, you have the right to:
To exercise any of these rights, contact us using the details in section 17. We will respond within one month, and will tell you if we need to extend that period. We do not charge a fee unless a request is manifestly unfounded or excessive.
If you are dissatisfied with how we have handled your personal data, you may lodge a complaint with the Irish Data Protection Commission at www.dataprotection.ie, or, if you are in the United Kingdom, with the Information Commissioner's Office at ico.org.uk. We would appreciate the opportunity to address your concerns first.
This website does not use cookies. We set no cookies of any kind — no analytics cookies, no advertising cookies, no tracking or profiling cookies, and no third-party marketing pixels. There is therefore no cookie consent banner, because there is nothing to consent to.
For completeness, we should disclose two related technologies:
Where you sign in to a DOXA application, a strictly necessary session cookie may be set by that application to keep you logged in. It is essential to the service, contains no marketing or tracking data, and is cleared when you sign out.
Our services are business-to-business tools and are not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy from time to time to reflect changes in our services, technology or legal obligations. The effective date and version number at the top of this page show when it was last revised. Where changes are material, we will notify subscribing customers directly and, where required, seek fresh consent.
For any question about this policy, or to exercise any of your rights, contact:
Pixxnow Limited, trading as DOXA
The Cubes Offices, Beacon South Quarter
Sandyford, Dublin, Ireland
CRO 571154 · VAT IE3401470EH
Email: support@doxa.co
Telephone: +353 1 908 1570
We have assessed our processing activities against Article 37 of the GDPR and concluded that we are not required to appoint a statutory Data Protection Officer. Privacy matters are handled by the company's directors, who can be reached at the address above.