This Data Processing Addendum (“DPA”) forms part of the Prism IO™ Terms of Use, or of the Master SaaS Subscription and Services Agreement where one is signed (either, the “Agreement”), between PopTech Studio LLC d.b.a. Prism IO™ (“Prism IO”) and the customer identified in the Agreement (“Customer”). It applies to the extent Prism IO processes Customer Personal Data on Customer’s behalf in providing the Services.
1. Definitions
- “Customer Personal Data” means personal data contained in Customer Content (as defined in the Agreement) that Prism IO processes on Customer’s behalf.
- “Data Protection Laws” means all laws applicable to the processing of Customer Personal Data, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and the CCPA as amended by the CPRA.
- “Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” have the meanings in the GDPR; “business”, “service provider”, “consumer”, “sell” and “share” have the meanings in the CCPA. “Controller” includes “business” and “processor” includes “service provider” and “contractor”.
- “Subprocessor” means a third party engaged by Prism IO to process Customer Personal Data.
- “SCCs” means the standard contractual clauses approved by European Commission Decision 2021/914, Module Two (controller to processor), and where relevant Module Three (processor to processor); “UK Addendum” means the UK International Data Transfer Addendum issued by the Information Commissioner.
2. Roles and scope
2.1 Customer is the controller of Customer Personal Data and Prism IO is its processor. Where Customer is itself a processor for its own clients (for example, an agency or studio), Customer warrants that it has its clients’ authorization to appoint Prism IO as a subprocessor, and Prism IO acts as processor to Customer.
2.2 This DPA does not apply to personal data for which Prism IO is the controller, namely account, billing, usage, security and marketing data about Customer’s users. The Prism IO™ Privacy Policy governs that data.
2.3 The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex I.
3. Prism IO’s obligations as processor
Prism IO will:
- (a) Instructions. Process Customer Personal Data only on Customer’s documented instructions, which consist of the Agreement, this DPA, Customer’s use and configuration of the Services, and any further written instructions Customer gives, unless required to do otherwise by law, in which case Prism IO will inform Customer before processing where the law permits. Prism IO will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
- (b) Confidentiality. Ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide, secure, support and legally operate the Services.
- (c) Security. Implement and maintain the technical and organizational measures described in Annex II, and not reduce their overall level of protection during the term.
- (d) Subprocessors. Engage Subprocessors only as set out in Section 5.
- (e) Data subject requests. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to data subject requests. If Prism IO receives a request directly from a data subject about Customer Personal Data, it will direct the data subject to Customer and will not respond substantively except as Customer instructs or the law requires. The Services provide export and deletion functions that Customer may use to fulfil requests itself.
- (f) Assistance. Taking into account the nature of the processing and the information available to it, assist Customer in meeting its obligations regarding security, breach notification, data protection impact assessments and prior consultation with supervisory authorities. Prism IO may charge reasonable fees for assistance that goes beyond what the Services and this DPA already provide and is not caused by Prism IO.
- (g) Deletion and return. At Customer’s choice, delete or return all Customer Personal Data on termination of the Services, and delete existing copies, as described in Section 7.
- (h) Information and audit. Make available the information necessary to demonstrate compliance with this DPA, as described in Section 8.
- (i) No sale or sharing. Not sell Customer Personal Data, not share it for cross-context behavioral advertising, not retain, use or disclose it for any purpose other than the business purposes specified in the Agreement or outside the direct business relationship with Customer, and not combine it with personal data received from other sources except as permitted for service providers under the CCPA. Prism IO certifies that it understands and will comply with these restrictions and will notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorized use.
- (j) No training. Not use Customer Personal Data to train or fine-tune generalized AI models, and engage AI model providers only under terms that prohibit them from doing so.
4. Customer’s obligations
Customer is responsible for the lawfulness of the Customer Personal Data it provides and its instructions, including having a lawful basis and giving any notices and obtaining any consents required to allow Prism IO to process it as the Agreement describes. Customer will not submit the restricted data categories listed in the Agreement’s acceptable use terms unless a signed Order permits it. Customer is responsible for configuring the Services, managing its users and credentials, and using the export and deletion functions appropriately.
5. Subprocessors
5.1 Customer gives Prism IO general authorization to engage the Subprocessors listed at prismio.ai/subprocessors/ as of the effective date of the Agreement.
5.2 Prism IO will give Customer at least 30 days’ notice before authorizing a new Subprocessor to process Customer Personal Data, by updating the Subprocessor List and by email to Customer’s account or notice address where Customer has subscribed to notifications.
5.3 Customer may object on reasonable data protection grounds within that notice period. The parties will discuss in good faith; if Prism IO cannot reasonably accommodate the objection, Customer may terminate the affected Services on written notice and receive a pro-rated refund of prepaid fees for the unused term, as its sole remedy.
5.4 Prism IO will impose on each Subprocessor data protection obligations that are no less protective than those in this DPA, by written contract, and remains liable to Customer for the performance of its Subprocessors’ obligations.
6. International transfers
6.1 Customer acknowledges that Prism IO processes Customer Personal Data in the United States and that Subprocessors process it in the locations shown in the Subprocessor List.
6.2 To the extent Customer Personal Data is subject to the GDPR and is transferred to a country without an adequacy decision, the parties agree that the SCCs (Module Two, or Module Three where Customer is a processor) are incorporated into this DPA, with Customer as data exporter and Prism IO as data importer, and completed as follows: Clause 7 (docking) applies; Clause 9(a) Option 2 (general authorization) with the notice period in Section 5.2; Clause 11 optional language does not apply; Clause 13 and Clause 17 governing law: Ireland; Clause 18 forum: the courts of Ireland; Annexes I, II and III of the SCCs are populated by Annexes I and II of this DPA and the Subprocessor List.
6.3 For UK data, the UK Addendum is incorporated, completed with the information in this DPA, and for Swiss data the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner.
6.4 Prism IO will rely on any Subprocessor’s certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where available, and otherwise on SCCs with that Subprocessor.
6.5 Where a transfer mechanism relied on is invalidated, the parties will cooperate in good faith to implement an alternative.
7. Return and deletion
7.1 During the term, Customer may export Customer Personal Data using the export functions of the Services in the formats they support (currently machine-readable JSON, Markdown and PDF for the Brand Identity System™, and a complete account export in JSON), and may delete it using the deletion functions.
7.2 On termination or expiry of the Services, Prism IO will, at Customer’s written election made within 30 days, return Customer Personal Data by making an export available, and in any event will delete Customer Personal Data from the live Services within 90 days and from backups within a further 30 days, except for data Prism IO must retain by law and de-identified audit records, which remain subject to this DPA for as long as they are retained.
7.3 On request, Prism IO will confirm deletion in writing.
8. Audit
8.1 Prism IO will make available to Customer, on request and no more than once in any 12-month period unless a supervisory authority requires otherwise or a personal data breach has occurred, the information reasonably necessary to demonstrate compliance with this DPA, which may include completed security questionnaires, summaries of penetration tests or third-party assessments when they exist, and this DPA’s Annex II.
8.2 Where that information is insufficient to demonstrate compliance under Data Protection Laws, Customer or an independent auditor bound by confidentiality may conduct an audit of Prism IO’s relevant processing, on at least 30 days’ written notice, during business hours, no more than once in any 12-month period, without unreasonably interfering with Prism IO’s operations, and at Customer’s expense unless the audit reveals a material breach. Prism IO does not have a SOC 2 or ISO 27001 report today and does not represent that one exists.
9. Personal data breach
Prism IO will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, by email to Customer’s account or notice address. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point, with further information provided as it becomes available. Prism IO will cooperate with Customer’s reasonable investigation and its notifications to authorities and data subjects. Notification is not an acknowledgment of fault.
10. Liability, precedence and term
10.1 Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except that nothing limits a party’s liability to data subjects under the SCCs.
10.2 In case of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Agreement for the subject matter it covers.
10.3 This DPA takes effect on the effective date of the Agreement and lasts for as long as Prism IO processes Customer Personal Data.
Annex I: Description of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Prism IO™ Services: modeling a Brand Identity System™ from Customer’s materials, serving it to Customer’s tools through the dashboard, API, SDK and MCP server, evaluating content against it, and producing Brand Audit reports |
| Duration | The term of the Agreement plus the deletion period in Section 7 |
| Nature and purpose | Storage, structuring, retrieval, analysis with deterministic rules and large language models, generation of structured outputs, transmission to Customer’s authorized tools, backup, support |
| Categories of data subjects | Customer’s personnel and leadership; Customer’s customers, prospects and audience members described in brand materials, testimonials, personas and research; other individuals named in Customer Content |
| Types of personal data | Names, titles, roles, contact details, quotations and testimonials, biographical and professional information, audience and persona descriptions, communications and content authored by individuals, and any other personal data Customer chooses to include. Special categories: not intended and prohibited by the Agreement unless a signed Order permits |
| Frequency | Continuous, as Customer uses the Services |
| Competent supervisory authority (SCCs Annex I.C) | Determined per Clause 13 of the SCCs: the supervisory authority of the EU member state in which the data exporter is established or, where it is not established in the EU, of the member state of its representative or of the data subjects concerned |
Annex II: Technical and organizational measures
Written from the deployed system on 2026-09-22. Prism IO will keep this Annex accurate and will not list a measure that is not implemented.
Access control and authentication – Customer users authenticate with email and password; passwords are stored only as salted bcrypt hashes. – Sign-in tokens are short-lived (24 hours) and can be revoked server-side; email verification and password reset links are single-use, hashed at rest and expire within 24 hours. – API and MCP credentials are issued per tenant, stored only as one-way hashes, and each credential resolves its tenant server-side; caller-supplied tenant identifiers are not trusted. – Access to content is deny-by-default and role-based; platform administration is a separately flagged privilege. – Authentication endpoints are rate-limited.
Tenant scope – Customer Content is stored and served under the customer’s tenant identifier. The Services do not use one customer’s content to produce another customer’s deliverables.
Encryption – All traffic to the website, dashboard, API and MCP server is encrypted in transit with TLS. – Connected third-party provider keys supplied by Customer are stored encrypted (symmetric authenticated encryption) and are masked in every response.
Logging and monitoring – Authentication, credential, administrative and governance events are logged with timestamp, actor, IP address and user agent to append-only audit tables. – Application errors are captured with secrets scrubbed before transmission. – Security telemetry records abuse and intrusion signals with redacted input only.
Infrastructure – The Services run on a virtual private server controlled by Prism IO, hosted in the United States; the database and application share the host and are not exposed to the public internet except through the application. – Host hardening and intrusion-prevention tooling are in place and periodically reviewed; secrets are held in an access-controlled store and rotated on a documented cadence. – Routine backups are taken and restore drills are performed periodically.
Personnel and organization – Access to production systems and Customer Content is limited to authorized personnel under confidentiality obligations, on a need-to-know basis. – Changes to production follow a documented review and sign-off process with evidence retained.
Data handling – Customer can export account and brand data in machine-readable form and delete the account, which removes Customer Content and de-identifies audit records, on demand. – Retention periods for security records, tokens and telemetry are documented in the Privacy Policy. – Customer Content is excluded from generalized AI model training, and AI providers are engaged under business API terms that prohibit training on API data.
Not represented – SOC 2, ISO 27001 or other third-party certification; HIPAA compliance; independent penetration testing; cyber liability insurance; multi-region redundancy.
Annex III: Subprocessors
The current list is published at prismio.ai/subprocessors/ and is incorporated by reference.
Prism IO™, Brand System Architect™, BrandOS™, Brand Identity Operating System™ and Brand Identity System™ are trademarks of PopTech Studio LLC. This document was last updated on September 22, 2026. Prior versions are available on request.
