SECTION 01
Company Legal Notice
Draft · last touched
Identity of the publisher
This website at atraxia.org is published by Atraxia.
General enquiries: support@atraxia.org. Responsible for content: Dr. Karim El Khaldi and Abdallah Diab.
About Atraxia
Atraxia is the parent company behind a growing portfolio of ventures and businesses, including in the health and wellness sector. Its first venture is Centium. References on this site to “we”, “us” and “Atraxia” mean Atraxia together with its subsidiaries and portfolio companies, unless a specific entity is named.
No professional or medical advice
Some of Atraxia’s portfolio companies, including Centium, operate in the health and wellness sector. Nothing on this website is medical, clinical, diagnostic, legal, tax or investment advice, and nothing here creates a practitioner-patient or adviser-client relationship. Always consult a qualified professional about your own circumstances.
Accuracy and availability
This site describes ventures at different stages of development, including some not yet released. Forward-looking statements about products, timing or capability are current intentions only and are not commitments. We may change, suspend or withdraw any part of the site at any time.
Third-party links
Links to third-party sites are provided for convenience. We do not control and are not responsible for their content, products or privacy practices.
Limitation of liability
To the fullest extent permitted by the laws of Lebanon, Atraxia excludes liability for loss arising from use of, or reliance on, this website. Nothing in this notice limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.
Governing law
This notice and any dispute arising from it are governed by the laws of Lebanon, subject to the exclusive jurisdiction of the courts of Lebanon.
Accessibility
We aim to meet WCAG 2.2 Level AA across our sites and products. This site has not yet undergone a formal, independent accessibility audit, so we cannot currently confirm full conformance. Based on an initial internal review, we are not aware of major barriers, though a few areas need attention before we can make that claim with confidence, including confirming colour contrast throughout, verifying full keyboard navigability, and reviewing labelling on interactive elements such as cookie preference controls. We will update this statement once a formal audit has been completed.
If you encounter a barrier using this site, email support@atraxia.org with the page and the assistive technology you use, and we will respond within 5 business days and offer the information in an alternative format.
SECTION 02
Group Privacy Policy
Draft · last touched
This policy explains how Atraxia and its portfolio companies handle personal data across our websites and applications. Where a portfolio company publishes its own product privacy notice, that notice governs that product and this policy covers the group layer.
Controller
The controller is Atraxia. Privacy contact: support@atraxia.org. We have not appointed a Data Protection Officer or an EU/UK representative at this time.
What we collect
- Contact data you send us: name, email address and message content when you email us or complete a form.
- Technical data: IP address, device and browser type, and pages viewed, collected through server logs and, where you consent, analytics.
- Product data: account and usage data generated in a portfolio product, described in that product’s own notice.
Health data. Some portfolio products may process health or wellness information, which is a special category of personal data. Where that applies, the relevant product notice sets out the specific condition relied upon (typically explicit consent) and the additional safeguards. This currently applies to Centium, which processes health and wellness data on the basis of explicit consent, with additional safeguards described in Centium’s own privacy notice.
We do not knowingly collect data from children under 16.
Why we use it, and our lawful basis
- To answer enquiries and provide requested information (performance of a contract, or legitimate interests).
- To operate, secure and improve our sites and products (legitimate interests).
- To measure how our sites are used (consent, via the cookie banner).
- To meet legal, accounting and regulatory obligations (legal obligation).
We do not sell personal data, and we do not use it for automated decision-making with legal or similarly significant effects.
Retention
We retain personal data for as long as your account is active. Where you request deletion, we remove your data within 30 days of that request, except where we are required to retain certain information to comply with a legal obligation.
Sharing
We share personal data with service providers acting on our instructions, including hosting, email delivery, analytics and support tooling, each under a written data processing agreement; with professional advisers; with other group companies where necessary for the purposes above; and with authorities where legally required.
Our current sub-processors are:
| PROVIDER | PURPOSE | CATEGORY |
| Supabase | Database hosting, and usage analytics | Hosting / Analytics |
| Cloudflare | Website hosting / CDN, and usage analytics | Hosting / Analytics |
| LiveKit Cloud | Voice and video calling infrastructure | Hosting / Infrastructure |
| GitHub Pages | Website hosting | Hosting |
| Google Workspace | Email delivery and customer support | Email delivery / Support |
We review this list periodically and update it when we add or remove a provider.
International transfers
Atraxia is based in Lebanon, where personal data is regulated under Law No. 81/2018 on the Protection of Personal Data. Where we process personal data of individuals located in the EU or UK, the GDPR and UK GDPR may also apply to us regardless of our location.
Personal data leaves Lebanon when it is processed by our service providers. Our database is hosted with Supabase in Mumbai, India (ap-south-1); voice and video calling is provided by LiveKit Cloud, which by default routes realtime media through the server cluster nearest each participant rather than a single fixed region; our website and CDN are served through Cloudflare’s global network; and email and support are handled through Google Workspace, which stores data across Google’s global infrastructure.
Where personal data is transferred to a country without an EU/UK adequacy decision (including India and the United States), we rely on Standard Contractual Clauses together with a transfer risk assessment, or the data subject’s explicit consent where applicable.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to our processing of your personal data, and to withdraw consent at any time. Under CCPA/CPRA, California residents may also request disclosure of categories collected, request deletion or correction, opt out of any “sale” or “sharing” (we do neither), and are entitled not to be discriminated against for exercising these rights.
To exercise a right, email support@atraxia.org. We respond within one month (GDPR) or 45 days (CCPA), and will tell you if we need longer. You may also complain to a supervisory authority. Lebanon does not currently have an independent data protection regulator; Law No. 81/2018 provides for enforcement through the competent Lebanese courts instead. If you are located in the EU or UK, you may lodge a complaint with the data protection authority in your own country of residence.
Changes
We will post material changes here and, where required, notify you directly.
SECTION 03
Cookie Policy and Cookie Preferences
Draft · last touched
This site does not currently set any cookies. There is no tracking, analytics, or session cookie in use on atraxia.org today.
If that changes in future (for example, if we add analytics or a functional cookie-based preference store), we will update this section before doing so, and cookie consent controls will be added at that time.
SECTION 04
Security and Responsible Disclosure
Draft · last touched
We welcome reports from security researchers. If you believe you have found a vulnerability in an Atraxia site or product, please tell us before telling anyone else.
How to report
Email support@atraxia.org with the subject line “Security report”. Include the affected asset, the steps to reproduce, the impact you believe it has, and any proof-of-concept. A dedicated security@atraxia.org address and PGP key are planned; support@atraxia.org is the working contact until that is set up. /.well-known/security.txt will be published once the dedicated address exists.
Our commitments
- We acknowledge reports within 2 business days.
- We give an initial assessment within 5 business days and keep you updated until resolution.
- We will not pursue legal action against researchers who follow this policy in good faith.
- We credit reporters who wish to be named once a fix has shipped.
Scope and rules
In scope: atraxia.org, centium.atraxia.org, and their public APIs, specifically the Supabase-backed API (authentication, database REST/Realtime, and storage endpoints) that Centium’s web and mobile apps use, and any publicly reachable Edge Function endpoints.
Not currently in public scope: Admin-Centium, which is a private, staff-only panel not exposed to the public internet. Reports involving it require separate authorisation.
Please do not access, modify or exfiltrate data belonging to anyone else; do not degrade our services (no denial-of-service, no volumetric or automated scanning that affects availability); do not use social engineering or physical attacks against our people or premises; and do not disclose publicly until we have confirmed a fix or 90 days have passed.
Out of scope: findings from automated scanners without demonstrated impact, missing best-practice headers with no exploitable consequence, rate-limiting on non-sensitive endpoints, and reports requiring a compromised device or a heavily outdated browser.
Rewards
No bounty is currently offered. We credit researchers publicly (with consent) as described above.
How we protect data
We use TLS encryption for all data in transit. Our database enforces row-level security policies scoping every query to the authenticated user, verified through real bypass-attempt testing rather than code review alone. Administrative actions require authenticated staff access and are logged to an audit trail. In September 2026, we identified and remediated a legacy client-side storage issue in which application data had persisted under the wrong domain following an earlier infrastructure migration; no server-side data was affected, and affected browsers are cleared automatically on their next visit. We do not currently hold third-party security certifications ourselves; our infrastructure providers maintain their own (for example, our database provider is SOC 2 Type II and ISO 27001 certified).
SECTION 05
Intellectual Property Policy
Draft · last touched
Ownership
All content on this site (text, design, layout, graphics, logos, icons, imagery, code and software) is owned by Atraxia or its licensors and is protected by copyright, trade mark and other intellectual property laws. The Atraxia name and mark, and the Centium name and mark, are trade marks of Atraxia.
What you may do
You may view this site and print or download extracts for your own personal, non-commercial reference, provided you keep all proprietary notices intact.
What you may not do
Without our prior written permission you may not reproduce, republish, adapt, frame, or commercially exploit any part of the site; use our marks in a way likely to cause confusion or imply endorsement; scrape or systematically extract content, including for training machine-learning models; or remove or obscure any proprietary notice.
Press and brand use
Journalists and partners may use our name and logo to refer to Atraxia factually, without alteration to colour, proportion or composition. For brand assets or approval, contact support@atraxia.org and we will send over the relevant materials.
Third-party and open-source materials
Our products are built using open-source frameworks and third-party services, including React, Vite, TypeScript, and Tailwind CSS across our web applications, alongside infrastructure and platform services from Supabase, Cloudflare, LiveKit, and Google. We use these under their respective open-source licences and commercial terms of service. We do not yet maintain a formal, itemised attribution and licence file; one will be published here as our stack matures.
Reporting infringement
If you believe material on our site infringes your rights, email support@atraxia.org with: identification of the protected work; the location of the material; your contact details; a statement of good-faith belief that the use is unauthorised; a statement that your notice is accurate; and your signature. We will investigate and remove or disable infringing material where appropriate, and we will forward the notice to the person who posted it, who may submit a counter-notice.
Unsolicited ideas
We do not accept unsolicited product ideas, proposals or materials. Anything you send us outside a signed agreement is treated as non-confidential, and we are free to use it without obligation to you.
SECTION 06
Careers Privacy Notice
Draft · last touched
This notice explains how Atraxia handles personal data about candidates. It sits alongside the Group Privacy Policy; where the two differ for recruitment, this notice applies.
What we collect
- Details you give us: CV, cover letter, contact details, work history, education, portfolio or code samples, and right-to-work information.
- Information generated during the process: interview notes, exercise submissions and assessment scores.
- Information from third parties: references you nominate, and public professional profiles. As a small team, background and reference checks are currently carried out directly by our co-founders as part of the interview process, rather than by a dedicated HR function or third-party screening provider.
Please do not send us health information or other special category data unless we ask for it to arrange an adjustment.
Why, and our lawful basis
We use this data to assess your suitability, communicate with you, arrange interviews, make and document a hiring decision, and meet legal obligations. Our basis is our legitimate interest in recruiting for our roles and, at offer stage, steps taken to enter into a contract with you. Where we ask to keep your details for future roles, we rely on your consent, which you can withdraw at any time.
Automated decision-making
We do not use automated tools to reject applications without human review. Every application is reviewed strictly by a human. No automated scoring, AI screening or ranking tool is used in our hiring process.
Who sees it
Access is limited to the hiring team and the people involved in that decision. We are not currently affiliated with any applicant tracking system, recruitment agency, or third-party IT/recruitment service provider, though this may change in future as we grow.
Retention
If your application is unsuccessful we keep your data for 12 months so we can consider you for other roles and evidence our decision, then delete it. If you join us, relevant records transfer to your employment file under the separate employee privacy notice.
Your rights
You have the same rights described in the Group Privacy Policy, including access, correction and deletion. Asking us to delete your data during a live process will normally mean we cannot continue considering your application. Contact support@atraxia.org.
Adjustments
If you need an adjustment at any stage, tell us. We use that information only to make the adjustment.
SECTION 07
Vendor / Supplier Privacy Notice
Draft · last touched
This notice is for people we deal with at our suppliers, vendors, contractors and professional advisers, and for sole traders who contract with us directly. It explains what we do with your personal data. It is not a data processing agreement; that sits in the contract.
What we collect
- Business contact details: name, job title, employer, work email, work phone.
- Relationship records: correspondence, meeting notes, contracts, statements of work and service records.
- Onboarding and compliance data: due diligence, sanctions and anti-bribery screening, insurance and, for sole traders, identity and right-to-work evidence.
- Payment data: invoices, bank details and payment history.
Why, and our lawful basis
To evaluate and onboard suppliers, manage the contract, process payments, keep accounting and tax records, and manage risk and security. Our basis is performance of a contract (or steps towards one), compliance with legal obligations, and our legitimate interest in managing our supply chain and protecting our business.
Sharing
With our finance, accounting, legal and IT providers; with banks and payment processors; with group companies where relevant to the engagement; and with authorities where required.
Retention
We keep contract and financial records for 10 years after the engagement ends, consistent with recordkeeping obligations under Lebanese commercial law, and contact records for 2 years after our last interaction.
If you process personal data for us
Where a supplier processes personal data on our behalf, we require a written agreement with confidentiality, security, sub-processor, assistance, breach-notification and deletion obligations, and appropriate transfer safeguards. Suppliers must notify us of a suspected personal data breach without undue delay and no later than 72 hours.
Your rights
The rights in the Group Privacy Policy apply. Contact support@atraxia.org.