Privacy Policy
Last updated: 7th of August, 2026
This privacy policy applies to the following Prisma websites: prisma.io, console.prisma.io, cloud.prisma.io, cloudprojects.prisma.io, and graph.cool. It is issued by Prisma Data, Inc., which acts as the data controller for personal data described in this policy. Questions may be directed to dpo@prisma.io.
Prisma gathers data from website visitors and service users. Required contact details include name, company name, address, phone number, and email address. Billing information encompasses credit card details and employee count. Optional data covers company revenue and industry specifics.
Website navigational information includes browser type, IP address, and user actions on the site. Embeddable Prisma Studio automatically collects application usage patterns, performance metrics, and integration metadata.
Free Tier accounts provide metadata regarding usage volume and feature access for abuse monitoring and optimization. Users wanting Free Tier data deletion should contact support@prisma.io.
Free Tier telemetry captures API call frequency, schema size, project activities, and integration types — helping prevent abuse while maintaining service reliability.
Prisma does not intentionally collect sensitive personal data (such as health data, biometric data, or data revealing racial or ethnic origin).
Prisma utilizes customer data to deliver and support services. Contact forms enable outreach regarding service interest. Marketing efforts involve using provided information to discuss services and share company updates.
Credit card information is used exclusively for financial qualification and payment collection. Website navigational data helps operate and improve the site while enabling personalization.
Where the GDPR or UK GDPR applies, Prisma processes personal data on the following legal bases: performance of a contract (providing the services), legitimate interests (service improvement, security, and abuse prevention), consent (marketing communications and non-essential cookies), and compliance with legal obligations.
Embeddable Studio telemetry enhances functionality and stability. Free Tier users receive transactional communications — such as plan limit, security, and service change notices — that are part of core service functionality and cannot be opted out of. Marketing communications, including feature announcements, always include an opt-out.
Prisma uses automated systems to monitor usage trends for abuse detection. Prisma does not make decisions producing legal or similarly significant effects about individuals based solely on automated processing.
Information shared in forums, bulletin boards, or chat rooms may be collected and used by other visitors. Prisma is not responsible for voluntarily submitted personal data in public forums.
Customer testimonials and names require prior consent before publication.
Data may be shared with service providers, vendors, and partners to support services. Joint promotional partners may receive data when users express interest in co-offered products. Partners are bound by their own privacy policies.
Credit card processing involves third-party providers prohibited from storing or using billing information beyond payment processing.
Prisma may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
All third parties undergo vetting and must maintain privacy standards consistent with the Data Privacy Framework. Prisma complies with DPF notice and choice principles: you may opt out of the disclosure of your personal data to third parties, or its use for a purpose materially different from the purpose for which it was collected, by contacting dpo@prisma.io. Free Tier abuse detection employs automated systems monitoring usage trends.
Prisma transfers customer data globally while maintaining compliance with this privacy policy. Prisma Data, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Prisma Data, Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regard to the processing of personal data received from the European Union and, under the UK Extension, from the United Kingdom (and Gibraltar), and to the Swiss-U.S. DPF Principles with regard to personal data received from Switzerland. If there is any conflict between the terms in this privacy policy and the DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Prisma Data, Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
In compliance with the DPF Principles, Prisma commits to resolve complaints about our collection or use of your personal data. Individuals in the EU, UK, or Switzerland with inquiries or complaints should first contact dpo@prisma.io. For complaints that cannot be resolved directly, Prisma has committed to cooperate and comply with the advice of the panel established by the EU data protection authorities (DPAs), the UK Information Commissioner's Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC). This independent dispute resolution mechanism is available to you at no cost. Under certain conditions described in the DPF Principles, you may also invoke binding arbitration when other dispute resolution procedures have been exhausted.
Prisma remains responsible and liable under the DPF Principles if third-party agents processing personal data on its behalf do so in a manner inconsistent with the Principles, unless Prisma proves that it is not responsible for the event giving rise to the damage.
For human resources data transferred from the EU, UK, or Switzerland in the context of an employment relationship, Prisma commits to cooperate and comply with the advice of the EU data protection authorities, the UK ICO, and the Swiss FDPIC, and to grant the rights provided under the DPF Principles.
Partner organizations handling HR and personal data follow equivalent legal requirements. Team members may contact dpo@prisma.io with questions or to limit data use.
Customers manage marketing communications through unsubscribe links in emails or by requesting preference changes via hello@prisma.io. Transactional account emails cannot be opted out.
Free Tier users receive periodic plan usage and service change messages as part of core service functionality.
Account registration changes can be made by logging in at prisma.io. You may also request access to, correction, or deletion of your personal data by contacting dpo@prisma.io. Requests receive responses within 30 days, or any shorter period required by applicable law. Individuals covered by the DPF may access, correct, amend, or delete personal data we hold about them.
Where the GDPR or UK GDPR applies, you additionally have the right to data portability, the right to restrict or object to processing, the right to withdraw consent at any time without affecting prior processing, and the right to lodge a complaint with your data protection supervisory authority.
Residents of California and other U.S. states with comprehensive privacy laws have the right to know and access the personal information we collect, correct or delete it, receive it in a portable format, and opt out of targeted advertising and the sale or sharing of personal information. Prisma does not sell personal information for money; third-party advertising cookies described in Section 4 may constitute "sharing" under California law, and you may opt out via our cookie settings, the Global Privacy Control signal, or dpo@prisma.io. We will not discriminate against you for exercising your rights, and you may appeal a refused request by replying to our decision.
Prisma retains personal data only for as long as needed to fulfill the purposes described in this policy, including providing the services, complying with legal, tax, and accounting obligations, resolving disputes, and enforcing agreements. When personal data is no longer required, it is deleted or anonymized. Retention periods vary by data category and are available on request via dpo@prisma.io.
Prisma's websites and services are not directed at children, and Prisma does not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact dpo@prisma.io and we will delete it.
Prisma employs administrative, technical, and physical security safeguards for customer data protection.
Prisma reserves the right to modify this privacy policy at any time. Free Tier discontinuation may alter data retention practices, with reasonable notification and data export opportunities provided.
Embeddable Prisma Studio operates as client-side software without visibility into end-user environments. Users bear sole responsibility for ensuring compliance with applicable laws across healthcare, finance, government, and other regulated sectors.