Privacy Policy
Draft — under legal review ahead of public launch. UK GDPR applies.
Who we are
Prism AI (“we”) operates prismai.uk. We are the data controller for account data, and a processor for the business content and audience data you bring into your workspace.
What we hold
Account details (name, email, hashed password), the brand profile you confirm, media you upload or import, content drafts, connection tokens for services you link (stored encrypted with AES-256-GCM), performance data those services return, leads you capture, and product analytics events about how the service is used.
Why we hold it (lawful bases)
To deliver the service you contracted for (contract); to secure accounts, prevent abuse and improve the product (legitimate interests); and where you ask us to email people, on the basis you confirm you have the right to contact them (your obligation as controller of that list).
Where it lives
Your workspace data is stored on our servers in the EU (Hetzner, Germany). AI processing sends relevant content to model providers (Anthropic, Google) under their API terms — they don't train public models on it.
Who sees it
Your workspace is isolated: other customers can't read it, and your connected accounts are yours alone. Our engineers access data only to operate the service or investigate an issue you raise.
How long
For as long as your account is active. On deletion request we remove your workspace (account, media, drafts, leads, tokens) within 30 days, keeping only what invoicing and law require.
Your rights
Access, correction, export, deletion, restriction and objection — email us and we'll act within a month. You can complain to the ICO (ico.org.uk) if you think we've got it wrong.
Newsletter recipients
Emails sent through Prism carry a one-click unsubscribe that takes effect immediately. Unsubscribes are enforced automatically; we never email an unsubscribed contact again on your behalf.
Data requests: support@prismai.uk