Prismforce Privacy Statement

PRISMFORCE Inc has defined and established an organization level privacy statement to demonstrate our commitment towards a user's right to privacy.

A reference to “PRISMFORCE,” “we,” “us” or the “Company” is a reference to www.prismforce.com and its relevant affiliate involved in the collection, use, sharing, or other processing of Personal Data.

1. Responsible PRISMFORCE Entity

PRISMFORCE INC is the controller/processor of your Personal Data as described in this Privacy Statement, unless specified otherwise.

This Privacy Statement does not apply to the extent we process Personal Data in the role of a processor or service provider on behalf of our customers, including where we offer to our customers various products and services through which our customers (or their affiliates):

  • Create their own websites and applications running on our platforms.
  • Sell or offer their own products and services.
  • Send electronic communications to others.
  • Or otherwise collect, use, share or process Personal Data via our products and services.

We are not responsible for the privacy or data security practices of our customers, which may differ from those explained in this Privacy Statement.

For detailed privacy information related to a PRISMFORCE customer or a customer affiliate who uses the PRISMFORCE products and services as the controller, please contact our customer directly.

For the Privacy information where we process Personal Data in the role of processor or service provider on behalf of our customers, Privacy policy as part of the contract is applicable.

2. Processing activities covered

This Privacy Statement applies to the processing of Personal Data collected by us when you:

  • Visit our websites that display or link to this Privacy Statement
  • Visit our branded social media page
  • Visit our physical office
  • Receive communications from us, including emails, phone calls, texts or fax
  • Use our products and services as an authorized user (for example, as an employee of one of our customers who provided you with access to our services) where we act as a controller of your Personal data
  • Register for, attend or take part in our events, webinars, or contests

Our websites and services may contain links to other websites, applications, and services maintained by third parties. The information practices of other services, or of social media platforms that host our branded social media pages, are governed by their privacy statements, which you should review to better understand their privacy practices.

Processing of Personal Data is required for receiving certain products or services.

2.1 Processing Activities of Prismforce as a Processor for SaaS Customer

Prismforce shall treat Personal Data as Confidential Information and shall Process Personal Data on behalf of and only in accordance with Customer’s documented instructions and applicable Data Protection Laws and Regulations for the following purposes:

(i) Processing in accordance with the Agreement;

(ii) Processing initiated by Users in their use of the Services; and

(iii) Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement.

2.2 Details of the Processing

The subject-matter of Processing of Personal Data by Prismforce is the performance of the Services pursuant to the Agreement. The duration of the Processing, the nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects Processed under the agreement shall be specified in the DPA. Prismforce shall keep appropriate documentation on the processing activities carried out on behalf of the data controller.

Data Protection Officer: Prismforce has appointed a data protection officer who may be reached at dpo@prismforce.ai

3. What Personal Data do we collect?

3.1 Personal Data we collect directly from you

The Personal Data we collect directly from you may include identifiers, professional or employment-related information, financial account information, commercial information, visual information, and internet activity information. We collect such information in the following situations:

  • If you express an interest in obtaining additional information about our product & services - request customer support
  • Use our “Contact Us” or similar features
  • Register to use our websites
  • Sign up for an event, webinar or contest
  • Download certain content
  • We may require that you provide to us your contact information, such as your name, job title, company name, address, phone number, email address or username.
  • If you make purchases via our websites or register for an event or webinar, we may require that you provide to us your financial and billing information, such as billing name and address, credit card number or bank account information.
  • If you attend an event, we may, with your further consent, scan your attendee badge, which will provide to us your information, such as name, title, company name, address, country, phone number and email address
  • If you register for an online community that we host, we may ask you to provide a username, photo or other biographical information, such as your occupation, location, social media profiles, company name, areas of expertise and interests.
  • If you interact with our websites or emails, we automatically collect information about your device and your usage of our websites or emails (such as Internet Protocol (IP) addresses or other identifiers, which may qualify as Personal Data) using cookies, web beacons, or similar technologies.
  • If you use and interact with our services, we automatically collect information about your device and your usage of our services through log files and other technologies, some of which may qualify as personal data.
  • If you communicate with us via a phone call from us, we may record that call.
  • If you voluntarily submit certain information to our services, such as filling out a survey about your user experience, we collect the information you have provided as part of that request.
  • If you visit our offices, you may be required to register as a visitor and to provide your name, email address, phone number, company name and time and date of arrival.
  • Additionally, due to the COVID-19 pandemic, you may be required to provide information regarding your health status, including your temperature, COVID-19-related symptoms, exposure to COVID-19 positive individuals, and recent travel history.

If you provide us or our service providers with any Personal Data relating to other individuals, you represent that you have the authority to do so, and where required, have obtained the necessary consent, and acknowledge that it may be used in accordance with this Privacy Statement.

If you believe that your Personal Data has been provided to us in an incorrect manner, and want to exercise your rights relating to your Personal Data, please contact us by using the information in the “Contact Us” section.

3.2 Personal Data we collect directly from you

We may also collect information about you from other sources including third parties e.g. curated publicly available information. We may combine this information with aggregated personal Data provided by you. This helps us update, expand, and analyze our records, identify new customers, and create more tailored advertising to provide services that may be of interest to you.

The Personal Data we collect from other sources includes identifiers, professional or employment-related information, education information, commercial information, visual information, internet activity information, and inferences about preferences and behaviors.

In particular, we may collect such Personal Data from the following sources or equivalent:

  • Third party providers of business contact information, including mailing addresses, job titles, email addresses, phone numbers, IP addresses, social media profiles, LinkedIn URLs and custom profiles, for purposes of targeted advertising, delivering relevant email content, event promotion and profiling, determining eligibility and verifying contact information; and
  • Another individual at your organization who may provide us with your business contact information for the purposes of obtaining services; and
  • Platforms such as GitHub to manage code check-ins and pull requests.

4. What device and usage data do we process?

We use common information-gathering tools, such as tools for collecting usage data, cookies, web beacons, pixels, and similar technologies to automatically collect information that may contain Personal Data as you navigate our websites, our services, or interact with emails we have sent to you.

4.1 Device and usage data

We gather certain information automatically when individual users visit our websites. This information may include identifiers, commercial information, and internet activity information such as IP address (or proxy server information), device and application information, identification numbers and features, location, browser type, plug-ins, integrations, Internet service provider, mobile carrier, the pages and files viewed, searches, referring website, app or ad, operating system, system configuration information, advertising and language preferences, date and time stamps associated with your usage, and frequency of visits to the websites. This information is used to analyze overall trends, help us provide and improve our websites, offer a tailored experience for website users, and secure and maintain our websites.

In addition, we gather certain information automatically as part of your use of our cloud products and services. This information may include identifiers, commercial information, and internet activity information such as IP address (or proxy server), mobile device number, device and application identification numbers, location, browser type, Internet service provider or mobile carrier, the pages and files viewed, website and webpage interactions including searches and other actions you take, operating system and system configuration information and date and time stamps associated with your usage. This information is used to maintain the security of the services, to provide necessary functionality, to improve performance of the services, to assess and improve customer and user experience of the services, to review compliance with applicable usage terms, to identify future opportunities for development of the services, to assess capacity requirements, to identify customer opportunities, and for the security of PRISMFORCE generally.

Some of the device and usage data collected by the services, whether alone or in conjunction with other data, could be personally identifying to you. Please note that this device and usage data is primarily used to identify the uniqueness of each user logging on, apart from where it is strictly required to identify an individual for security purposes or as required as part of our provision of the services to our customers.

It is ensured that all of the above mentioned personal data shall be protected at all time by suitable controls as deemed appropriate by PRISMFORCE.

4.2 Cookies, web beacons and other tracking technologies on our website and in email communications

We may use technologies such as web beacons, pixels, tags, and JavaScript, alone or in conjunction with cookies, to gather information about the use of our websites and how people interact with our emails.

When you visit our websites, we, or an authorized third party, may place a cookie on your device that collects information, including Personal Data, about your online activities over time and across different sites.

Cookies allow us to track use, browsing preferences, and improve and customize your browsing experience.

We may use both session-based and persistent cookies on our websites. Session-based cookies exist only during a single session and disappear from your device when you close your browser or turn off the device. Persistent cookies remain on your device after you close your browser or turn your device off. To change your cookie settings and preferences for one of our websites, click the Cookie Preferences setting on your respective machine.

You can also control the use of cookies on your device, but choosing to disable cookies on your device may limit your ability to use some features on our websites and services.

The following describes how we use different categories of cookies and similar technologies and your options for managing the data collection settings of these technologies:

Required Cookies
Required cookies are necessary for basic website functionality. Some examples include session cookies needed to transmit the website, authentication cookies, and security cookies. If you have chosen to identify yourself to us, we may place on your browser a cookie that allows us to uniquely identify you when you are logged into the websites and to process your online transactions and requests.

Purpose: Because required cookies are essential to operate the websites, there is no option to opt out of these cookies.

Functional cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.

Functional cookies may also be used to improve how our websites function and to help us provide you with more relevant communications, including marketing communications. These cookies collect information about how our websites are used, including which pages are viewed most often.

We may use our own technology or third-party technology to track and analyze usage information to provide enhanced interactions and more relevant communications, and to track the performance of our advertisements.

For example, we may use Google Analytics, a web analytics service provided by Google, Inc.

Purpose: You can choose to opt out of functional cookies. You can also opt out from data collection by Google Analytics using a browser add-on and manage cookies through browser or Flash privacy settings.

Advertising cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and to direct marketing to them.

We sometimes use cookies delivered by us or by third parties to show you ads for our products that we think may interest you on devices you use and to track the performance of our advertisements.

Purpose: You can choose to opt out of targeting and advertising cookies by managing cookie settings and preferences in your browser.

4.3 Notices on behavioral advertising and opt-out for website visitors

As described above, we or one of our authorized partners may place or read cookies on your device when you visit our websites for the purpose of serving you targeted advertising.

4.4 Social Media Functionality

Our websites may use social media features, such as the Facebook “like” button, the “Tweet” button and other sharing widgets.

These features may allow you to post information about your activities on our website to outside platforms and social networks. They may also allow you to like or highlight information we have posted on our website or our branded social media pages.

Your interactions with Social Media Features are governed by the privacy policies of the companies providing them.

4.5 Telephony log information

If you use certain features of our services on a mobile device, we may also collect telephony log information like phone numbers, time and date of calls, duration of calls, SMS routing information and types of calls, as well as device event information and location information.

5. Purposes for which we process Personal Data and the legal basis for the same

We collect and process your Personal Data for the following purposes. Where required by law, we obtain your consent. Otherwise, we rely on another authorized legal basis, including performance of a contract or legitimate interest.

Purposes include:

  • Providing our websites and services
  • Promoting the security of our websites and services
  • Handling contact and user support requests
  • Managing contests or promotions
  • Managing payments
  • Developing and improving our websites and services
  • Assessing and improving user experience
  • Reviewing compliance with applicable usage terms
  • Assessing capacity requirements
  • Identifying customer opportunities
  • Registering office visitors
  • Recording phone calls
  • Displaying personalized advertisements and content
  • Sending marketing communications
  • Complying with legal obligations

If we need to collect and process Personal Data by law, or under a contract we have entered into with you, and you fail to provide the required Personal Data when requested, we may not be able to perform our contract with you.

6. Who do we share Personal Data with?

We may share your Personal Data as follows:

  • Service Providers
  • Affiliates
  • Event Sponsors
  • Contest and Promotion Sponsors
  • Third party networks and websites
  • Professional Advisers

We may also share anonymous or de-identified usage data with service providers for analysis and improvements, and may share such data publicly on an aggregate basis to show general usage trends.

7. International transfer of Personal Data

Your Personal Data may be collected, transferred to and stored by us in the US or by our affiliates and third-parties disclosed above, where such transfers are required for legitimate business reasons.

Prismforce uses the following sub-processors:

  • Prismforce Private Limited — Affiliate sub-processor / Support Services — India
  • Amazon Web Services — Production server and cloud hosting provider / Amazon S3 for data transfer — Mumbai, Hyderabad, Ohio, North Virginia, Ireland, Paris
  • Sentry — Application error tracking and monitoring — USA
  • Hotjar — Product Experience Insights and Analysis — Ireland
  • Mixpanel — Product analytics and privacy-safe session replay — United States / EEA
  • Freshworks — Support Ticketing Services — US, EEA, IND and AU
  • Google — Email Service Provider — Across all geographic data centers
  • Microsoft — AI Services Provider (Agent AI backend) — Primarily United States, with regional data centers depending on configuration

8. How long do we keep your Personal Data?

We may retain your Personal Data for a period of time consistent with the original purpose of collection or as long as required to fulfill our legal obligations.

We determine the appropriate retention period based on:

  • the amount, nature, and sensitivity of the Personal Data
  • the potential risk of harm from unauthorized use or disclosure
  • whether we can achieve the purposes of the processing through other means
  • applicable legal requirements

After expiry of the applicable retention periods, your Personal Data will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will implement appropriate measures to prevent any further use of such data.

Prismforce is governed by EU GDPR Data Retention and Data Erasure policies.

  • Retention period after contract termination: 30 days unless otherwise agreed
  • Retention period for inactive data processed as a data processor: 2 years unless otherwise agreed with the data controller

9. Your rights relating to your Personal Data

9.1 Your rights

Depending on applicable laws, your rights may include the right to:

  • Access your Personal Data held by us
  • Know more about how we processed your Personal Data
  • Rectify inaccurate Personal Data
  • Erase or delete your Personal Data
  • Restrict our processing of your Personal Data
  • Transfer your Personal Data to another controller
  • Object to processing of your Personal Data
  • Opt out of certain disclosures of your Personal Data to third parties
  • If you’re under the age of 16, opt in to certain disclosures of your Personal Data to third parties
  • Not be discriminated against for exercising your rights
  • Withdraw your consent at any time

The Agreement considers the following:

a. Privacy by Design and default
b. Achieving Security of Processing
c. Notification of breaches involving PII to a Supervisory authority within 72 hours
d. Notification of breaches involving PII to Customers and PII Principals within 72 hours
e. Prismforce shall inform the customer if in its opinion a processing instruction infringes applicable legislation or regulation
f. The organization does not use PII processed under a contract for the purposes of Marketing and Advertising
g. Coordinate with Clients for helping Audit the systems
h. The Data shall be deleted or de-identified after the processing is complete
i. Prismforce shall inform 24 hours in advance to clients in case of any legally binding requests for disclosure of PII

9.2 How to exercise your rights

To exercise your rights, please contact us using the information in the “Contact Us” section on our website.

We try to respond to all legitimate requests within one month unless otherwise required by law. If more information is needed to verify your identity or process your request, we will contact you.

Some registered users may update their settings, profiles, organization settings and event registrations by logging into their accounts.

To update billing information, discontinue your account or request return or deletion of your Personal Data and other information associated with your account, please contact us using the information in the “Contact Us” section.

9.3 Your rights relating to customer data

  • We may process Personal Data submitted by or for a customer as a processor on behalf of that customer.
  • We are not responsible for and have no control over the privacy and data security practices of our customers.
  • If your data has been submitted to us by or on behalf of a PRISMFORCE customer and you wish to exercise rights under applicable data protection laws, please inquire with them directly.
  • If you wish to make your request directly to us, please provide us the name of the PRISMFORCE customer who submitted your data.

We will refer your request to that customer and support them as needed in responding within a reasonable timeframe.

9.4 Your preferences for email and SMS marketing communications

If we process your Personal Data for sending marketing communications, you may manage your receipt of such communications by:

  • clicking the unsubscribe link in PRISMFORCE marketing emails
  • replying or texting “STOP” for PRISMFORCE SMS communications
  • turning off push notifications on PRISMFORCE apps
  • contacting us using the information in the “Contacting us” section

Please note that opting out of marketing communications does not opt you out of important business communications related to your current relationship with us.

10. How we secure your Personal Data

We take appropriate precautions including organizational, technical, and physical measures to help safeguard against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure of, or access to, the Personal Data we process or use.

This includes personal data used in:

  1. Our B2B product platforms
  2. Communication
  3. Emails
  4. Visuals
  5. Documents
  6. Contact forms
  7. Events
  8. Conferences
  9. Any other source as relevant

While we follow generally accepted standards to protect Personal Data, no method of storage or transmission is 100% secure.

You are solely responsible for protecting your password, limiting access to your devices and signing out of websites after your sessions. If you have any questions about the security of our websites, please connect with us formally with your query related to your personal data.

11. Changes to this Privacy Statement

We will update this Privacy Statement from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. If we do, we will update the “effective date” at the top.

If we make a material update, we may provide you with notice prior to the update taking effect, such as by posting a conspicuous notice on our website or by contacting you directly, or where required under applicable law and feasible, seek your consent to these changes.

We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing and sharing of your Personal Data.

12. Contacting Us

To exercise your rights regarding your Personal Data, or if you have questions regarding our Privacy practices, please reach out to us at:

privacy@prismforce.ai
support@prismforce.com

Reach out to Prismforce Data Protection Officer / Grievance Officer (Prismforce Privacy Team) at:

Ashwini Kumar Dixit
dpo@prismforce.ai
A-1004, 10th Floor, Kanakia Wall Street,
Andheri Kurla Road, Andheri East, Mumbai - 400093

We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you have the right to lodge a complaint with the competent supervisory authority.