Privacy Statement

Last updated: 2026-08-26

Who we are

The data controller for this platform is Prism. You can contact us at privacy@prism.ai.

What data we collect

When you use Prism we may collect the following personal data:

  • Name (as provided by the engagement facilitator)
  • Email address
  • Persona / role within the organization
  • Survey responses
  • IP address and basic request metadata (collected automatically)

Cookies

Names are shown in their production form. Three of them — __Secure-authjs.session-token, __Host-authjs.csrf-token and __Secure-authjs.callback-url — are stored by your browser with a __Secure- or __Host- prefix on the secure (HTTPS) site, and appear as authjs.session-token, authjs.csrf-token and authjs.callback-url on a local non-HTTPS development build. Every other cookie name below is the same in both cases.

Essential cookies are set without asking for your consent — the platform cannot function without them. Each entry below states when it is set. The functional and privacy cookies listed alongside them are not subject to consent either: a theme choice, a Global Privacy Control signal and a consent decision can only be honored by storing them. Only the performance-monitoring cookies at the end of the list are optional.

  • __Secure-authjs.session-token: Essential. Manages your admin session. Set when you sign in. HttpOnly, Secure, SameSite=Lax. Expires 4 hours after you sign in, whether or not you are active.
  • csrf-token: Essential. Cross-site request forgery protection for form submissions. Set on any page request that does not already carry it, and left alone after that. Readable by our own page scripts, which must send it back with each submission, so it is deliberately not HttpOnly. Secure, SameSite=Strict, 1 day.
  • __Host-authjs.csrf-token: Essential. Cross-site request forgery protection on the sign-in routes themselves. Set when you first reach one of those routes. HttpOnly, Secure, SameSite=Lax. No expiry is set, so your browser discards it when you close it.
  • __Secure-authjs.callback-url: Essential. Remembers the address to return you to as you move through a sign-in, sign-out or callback step. Set on requests to our authentication routes whenever the return address resolved for that request differs from the one already stored. HttpOnly, Secure, SameSite=Lax. No expiry is set, so your browser discards it when you close it.
  • prism.ui.theme: Functional. Remembers whether you chose the light or dark theme. Set only when you pick a theme. Persistent, 1 year.
  • prism-gpc-opt-out: Privacy. Records that your browser sent a Global Privacy Control signal. Set on any request that carries the signal. Persistent, 1 year.
  • prism-cookie-consent: Privacy. Records your cookie consent preference. Set when you accept or decline optional cookies. Persistent, 1 year.
  • cwr_s / cwr_u: Optional. Performance monitoring (AWS CloudWatch RUM). Set only if you accept optional cookies and your browser is not sending a Global Privacy Control signal. Used to measure page performance and errors. No advertising or cross-site tracking.

We do not use advertising or cross-site tracking cookies. Optional performance-monitoring cookies (above) are set only with your consent, are never used for advertising, and their telemetry is sent only to a monitoring endpoint within your own region, or not collected at all if your region is not covered.

Legal basis

We process your data under the following legal bases:

  • Legitimate interest for conducting the maturity assessment on behalf of the engaging organization.
  • Legitimate interest for contributing anonymized, aggregated assessment data to industry benchmark databases. See "Benchmark Data" below for details.

Benchmark Data

When an engagement is configured for benchmark contribution, anonymized and aggregated maturity scores may be contributed to the Prism industry benchmark database. This data:

  • Contains no company names, respondent names, email addresses, or any personally identifiable information.
  • Consists solely of numerical maturity scores grouped by industry vertical, geographic region, and company size band.
  • Is aggregated across multiple organizations: a minimum of 3 organizations per segment (k-anonymity) is required before any benchmark comparison is produced.
  • Has all links to the contributing organization permanently severed after aggregation. Once aggregated, it is impossible to trace a benchmark score back to a specific organization.
  • Is used only to produce statistical industry comparisons (median and top-performer thresholds) in assessment reports.

The decision to contribute benchmark data is made at the engagement level by the facilitating organization, not by individual survey respondents. If your organization does not wish to contribute benchmark data, please inform your account representative.

Data retention

Personal data is retained for a default period of 60 months from the date of collection. Organizations may request a shorter retention period. After the retention period expires, data is automatically purged or anonymized.

Audit logs are retained for 36 months (3 years) and are automatically purged via partition-based cleanup.

Benchmark data is retained indefinitely as it is fully anonymized and contains no personal data.

Your rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:

  • Access: request a copy of the data we hold about you.
  • Rectification: ask us to correct inaccurate data.
  • Erasure: ask us to delete your data (hard delete or anonymization).
  • Portability: receive your data in a structured, machine-readable format.
  • Object: object to our processing of your data.
  • Restrict processing: ask us to limit how we use your data.

To exercise any of these rights, please submit a request through our rights request form.

Global Privacy Control

We honor the Global Privacy Control (GPC) signal. When your browser sends a GPC signal, we automatically suppress all optional cookies.

Contact

If you have questions about this privacy statement or our data practices, contact us at privacy@prism.ai.

Submit a rights request