Privacy Policy

Last updated: April 22, 2025

Introduction

Welcome to the privacy policy of Prism AI and Prism Replay (by Prism Technologies Inc.). This policy applies to all our products and services, including our website (www.prismreplay.com), our applications, and our Google OAuth application (Project ID: orbital-amulet-457322-b5). This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it.

Owner and Data Controller

Prism Technologies Inc. - 2261 Market Street STE 86585, San Francisco, CA, 94114

Owner contact email: founders@prismai.sh

Types of Data collected

Among the types of Personal Data that Prism AI and Prism Replay collects, by itself or through third parties, there are:

  • Email address
  • Usage Data
  • Trackers
  • Number of Users
  • Session statistics
  • Device information
  • First name
  • Last name
  • Google account information (when using our Google OAuth application, Project ID: orbital-amulet-457322-b5)
  • Authentication data

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection. Personal Data may be freely provided by the User, or, in case of Usage Data, collected automatically when using Prism AI or Prism Replay. Unless specified otherwise, all Data requested by Prism AI and Prism Replay is mandatory and failure to provide this Data may make it impossible for us to provide our services.

Users who are uncertain about which Personal Data is mandatory are welcome to contact the Owner. Any use of Cookies – or of other tracking tools — by Prism AI, Prism Replay or by the owners of third-party services used by our applications serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy.

Mode and place of processing the Data

Methods of processing

The Owner takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the Data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of Prism AI and Prism Replay (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Owner. The updated list of these parties may be requested from the Owner at any time.

Place

The Data is processed at the Owner's operating offices and in any other places where the parties involved in the processing are located. Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.

Retention time

Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users' consent.

The purposes of processing

The Data concerning the User is collected to allow the Owner to provide its Service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following:

  • Contacting the User
  • Analytics
  • Heat mapping and session recording
  • Tag management
  • Displaying content from external platforms
  • Handling payments
  • Hosting and backend infrastructure

Detailed information on the processing of Personal Data

Google OAuth Application

Our Google OAuth application (Project ID: orbital-amulet-457322-b5) collects and processes user data in accordance with Google's API Services User Data Policy. When you authenticate with our application using your Google account, we may access and store certain information from your Google account to provide our services.

We only request access to the data that is necessary for the functionality of our application. This data is not sold to third parties and is only used for the purposes stated in this privacy policy.

You can revoke our application's access to your Google account at any time through your Google account settings.

Analytics

The services contained in this section enable the Owner to monitor and analyze web traffic and can be used to keep track of User behavior.

Google Analytics 4

Company: Google LLC

Place of processing: United States

Personal Data processed: number of Users and related data

Contacting the User

Contact form

Personal Data processed: email address and other contact information

Mailing list or newsletter

Personal Data processed: email address and user information

Displaying content from external platforms

This type of service allows you to view content hosted on external platforms directly from the pages of Prism Replay and interact with them. This type of service might still collect web traffic data for the pages where the service is installed, even when Users do not use it.

Google Maps widget

Company: Google LLC

Place of processing: United States

Personal Data processed: Trackers and usage data

Google Fonts

Company: Google LLC

Place of processing: United States

Personal Data processed: Trackers and usage data

Handling payments

Unless otherwise specified, Prism Replay processes any payments by credit card, bank transfer or other means via external payment service providers. In general and unless where otherwise stated, Users are requested to provide their payment details and personal information directly to such payment service providers. Prism Replay isn't involved in the collection and processing of such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.

Stripe

Company: Stripe, Inc.

Place of processing: United States

Personal Data processed: email address and payment information

Heat mapping and session recording

Heat mapping services are used to display the areas of Prism Replay that Users interact with most frequently. This shows where the points of interest are. These services make it possible to monitor and analyze web traffic and keep track of User behavior. Some of these services may record sessions and make them available for later visual playback.

PostHog session replay

Company: PostHog, Inc.

Place of processing: United States

Personal Data processed: device information and session data

Hosting and backend infrastructure

This type of service has the purpose of hosting Data and files that enable Prism Replay to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of Prism Replay.

Vercel

Company: Vercel Inc.

Place of processing: United States

Personal Data processed: Usage Data and system information

Tag management

This type of service helps the Owner to manage the tags or scripts needed on Prism Replay in a centralized fashion. This results in the Users' Data flowing through these services, potentially resulting in the retention of this Data.

Google Tag Manager

Company: Google LLC

Place of processing: United States

Personal Data processed: Trackers and usage data

Cookie Policy

Prism AI, Prism Replay, and our Google OAuth application (Project ID: orbital-amulet-457322-b5) use Trackers. To learn more, Users may consult the Cookie Policy.

Further Information for Users in the European Union

Legal basis of processing

The Owner may process Personal Data relating to Users if one of the following applies:

  • Users have given their consent for one or more specific purposes.
  • Provision of Data is necessary for the performance of an agreement with the User and/or for any pre-contractual obligations thereof;
  • Processing is necessary for compliance with a legal obligation to which the Owner is subject;
  • Processing is related to a task that is carried out in the public interest or in the exercise of official authority vested in the Owner;
  • Processing is necessary for the purposes of the legitimate interests pursued by the Owner or by a third party.

The rights of Users based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights regarding their Data processed by the Owner. In particular, Users have the right to do the following, to the extent permitted by law:

  • Withdraw their consent at any time.
  • Object to processing of their Data.
  • Access their Data.
  • Verify and seek rectification.
  • Restrict the processing of their Data.
  • Have their Personal Data deleted or otherwise removed.
  • Receive their Data and have it transferred to another controller.
  • Lodge a complaint.

How to exercise these rights

Any requests to exercise User rights can be directed to the Owner through the contact details provided in this document. Such requests are free of charge and will be answered by the Owner as early as possible and always within one month, providing Users with the information required by law. Any rectification or erasure of Personal Data or restriction of processing will be communicated by the Owner to each recipient, if any, to whom the Personal Data has been disclosed unless this proves impossible or involves disproportionate effort. At the Users' request, the Owner will inform them about those recipients.

Further information for Users in the United States

This part of the document integrates with and supplements the information contained in the rest of the privacy policy and is provided by the business running Prism Replay and, if the case may be, its parent, subsidiaries and affiliates (for the purposes of this section referred to collectively as "we", "us", "our").

The information contained in this section applies to all Users who are residents in the United States.

Your privacy rights under US state laws

You may exercise certain rights regarding your Personal Information. In particular, to the extent permitted by applicable law, you have:

  • The right to access Personal Information: the right to know.
  • The right to correct inaccurate Personal Information.
  • The right to request the deletion of your Personal Information.
  • The right to obtain a copy of your Personal Information.
  • The right to opt out from the Sale of your Personal Information.
  • The right to non-discrimination.

How to exercise your privacy rights under US state laws

To exercise the rights described above, you need to submit your request to us by contacting us via the contact details provided in this document.

For us to respond to your request, we must know who you are. We will not respond to any request if we are unable to verify your identity and therefore confirm the Personal Information in our possession relates to you. You are not required to create an account with us to submit your request.

Additional information about Data collection and processing

Legal action

The User's Personal Data may be used for legal purposes by the Owner in Court or in the stages leading to possible legal action arising from improper use of Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), or related Services. The User declares to be aware that the Owner may be required to reveal personal data upon request of public authorities.

System logs and maintenance

For operation and maintenance purposes, Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), and any third-party services may collect files that record interaction with our services (System logs) or use other Personal Data (such as the IP Address) for this purpose.

Changes to this privacy policy

The Owner reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), and/or - as far as technically and legally feasible - sending a notice to Users via any contact information available to the Owner. It is strongly recommended to check this page often, referring to the date of the last modification listed at the bottom.

Should the changes affect processing activities performed on the basis of the User's consent, the Owner shall collect new consent from the User, where required.

Definitions and legal references

Personal Data (or Data) / Personal Information (or Information)

Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.

Sensitive Personal Information

Sensitive Personal Information means any Personal Information that is not publicly available and reveals information considered sensitive according to the applicable privacy law.

Usage Data

Information collected automatically through Prism AI, Prism Replay, our Google OAuth application (Project ID: orbital-amulet-457322-b5), or third-party services employed in our applications, which can include: the IP addresses or domain names of the computers utilized by the Users who use our services, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer, the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit, and other parameters about the device operating system and/or the User's IT environment.

User

The individual using Prism AI, Prism Replay, or our Google OAuth application (Project ID: orbital-amulet-457322-b5) who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor (or Processor)

The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, as described in this privacy policy.

Data Controller (or Owner)

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of Prism AI, Prism Replay, and our Google OAuth application (Project ID: orbital-amulet-457322-b5). The Data Controller, unless otherwise specified, is the Owner of Prism AI and Prism Replay services.

How can we help?

What you can do

Your data

  • Ask us to know and access the information we hold on you
  • Ask us to correct information we hold on you
  • Ask us to be forgotten (delete the information we hold on you)
  • Ask to port your data to another service

In case of issues

While we strive to create a positive user experience, we understand that issues may occasionally arise between us and our users. If this is the case, please feel free to contact us at founders@prismai.sh.

© copyright Prism 2024. All rights reserved.

Prism