From 9eafe8fc2561876548a897a03aa532d5471fd333 Mon Sep 17 00:00:00 2001 From: joshmerp Date: Fri, 7 Aug 2026 20:42:45 +0200 Subject: [PATCH] chore(site): update privacy policy for DPF renewal and privacy-law coverage MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit DPF (Notice Principle) fixes: - Correct onward-transfer liability statement (Prisma remains liable unless not responsible for the event giving rise to the damage) - Link to dataprivacyframework.gov and name certified entity (Prisma Data, Inc. — verify against DPF List entry) - Name the independent recourse mechanism (EU DPA panel / ICO / FDPIC), state it is free of charge, and surface binding arbitration - General FTC jurisdiction statement (previously buried in HR section) - Disclose lawful requests by public authorities (national security / law enforcement) - Explicit DPF access/correction/deletion rights and opt-out choice Broader legal updates: - New "Your Privacy Rights" section: GDPR/UK GDPR rights incl. portability, restriction, objection, supervisory-authority complaint; US state rights incl. targeted-advertising/sharing opt-out, non-discrimination, and appeal; Global Privacy Control honored - New Data Retention and Children's Privacy sections - Cookie consent + GPC language in navigational-information section - Restrict "no opt-out" claim to transactional messages; marketing (incl. feature announcements) is opt-out-able - Automated-processing clarification; controller identity in §1 - Bump privacyLastUpdated to August 7, 2026 Needs legal review before merge. Co-Authored-By: Claude Fable 5 --- apps/site/src/data/privacy.tsx | 163 +++++++++++++++++++++++++++------ 1 file changed, 133 insertions(+), 30 deletions(-) diff --git a/apps/site/src/data/privacy.tsx b/apps/site/src/data/privacy.tsx index 249046e13e..004fd06e65 100644 --- a/apps/site/src/data/privacy.tsx +++ b/apps/site/src/data/privacy.tsx @@ -1,6 +1,6 @@ import type { ReactNode } from "react"; -export const privacyLastUpdated = "July 10, 2025"; +export const privacyLastUpdated = "7th of August, 2026"; type PrivacySection = { title: string; @@ -13,7 +13,9 @@ export const privacySections: PrivacySection[] = [ content: (

This privacy policy applies to the following Prisma websites: prisma.io, console.prisma.io, - cloud.prisma.io, cloudprojects.prisma.io, optimize.prisma.io, and graph.cool. + cloud.prisma.io, cloudprojects.prisma.io, and graph.cool. It is issued + by Prisma Data, Inc., which acts as the data controller for personal data described in this + policy. Questions may be directed to dpo@prisma.io.

), }, @@ -41,6 +43,10 @@ export const privacySections: PrivacySection[] = [ Free Tier telemetry captures API call frequency, schema size, project activities, and integration types — helping prevent abuse while maintaining service reliability.

+

+ Prisma does not intentionally collect sensitive personal data (such as health data, + biometric data, or data revealing racial or ethnic origin). +

), }, @@ -58,16 +64,28 @@ export const privacySections: PrivacySection[] = [ collection. Website navigational data helps operate and improve the site while enabling personalization.

+

+ Where the GDPR or UK GDPR applies, Prisma processes personal data on the following legal + bases: performance of a contract (providing the services), legitimate interests (service + improvement, security, and abuse prevention), consent (marketing communications and + non-essential cookies), and compliance with legal obligations. +

Embeddable Studio telemetry enhances functionality and stability. Free Tier users receive - transactional communications about plan limitations and feature announcements without - opt-out options. + transactional communications — such as plan limit, security, and service change notices — + that are part of core service functionality and cannot be opted out of. Marketing + communications, including feature announcements, always include an opt-out. +

+

+ Prisma uses automated systems to monitor usage trends for abuse detection. Prisma does not + make decisions producing legal or similarly significant effects about individuals based + solely on automated processing.

), }, { - title: "4. Website Navigational Information", + title: "4. Cookies and Website Navigational Information", content: ( <>

@@ -84,6 +102,12 @@ export const privacySections: PrivacySection[] = [ IP addresses track geographic data from visitors. Third-party ad networks collect navigational information to deliver targeted advertisements based on browsing history.

+

+ Where required by law, non-essential cookies are set only with your consent, and you can + change your cookie preferences at any time through our cookie settings. You can opt out of + targeted advertising as described in Section 10, and Prisma honors opt-out preference + signals such as Global Privacy Control (GPC) as required by applicable law. +

), }, @@ -111,49 +135,83 @@ export const privacySections: PrivacySection[] = [

Credit card processing involves third-party providers prohibited from storing or using - billing information beyond payment processing. Prisma reserves disclosure rights when - legally required. + billing information beyond payment processing. +

+

+ Prisma may be required to disclose personal data in response to lawful requests by public + authorities, including to meet national security or law enforcement requirements.

All third parties undergo vetting and must maintain privacy standards consistent with the - Data Privacy Framework. Prisma complies with DPF notice and choice principles; individuals - may limit data use by contacting dpo@prisma.io. Free - Tier abuse detection employs automated systems monitoring usage trends. + Data Privacy Framework. Prisma complies with DPF notice and choice principles: you may opt + out of the disclosure of your personal data to third parties, or its use for a purpose + materially different from the purpose for which it was collected, by contacting{" "} + dpo@prisma.io. Free Tier abuse detection employs + automated systems monitoring usage trends.

), }, { - title: "7. International Transfer of Information Collected", + title: "7. International Transfers and the Data Privacy Framework", content: ( <>

- Prisma transfers customer data globally while maintaining Privacy Statement compliance. - The company certifies adherence to EU-U.S. DPF, the UK Extension, and Swiss-U.S. DPF - principles regarding personal data from those regions. + Prisma transfers customer data globally while maintaining compliance with this privacy + policy. Prisma Data, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), + the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. + DPF) as set forth by the U.S. Department of Commerce. Prisma Data, Inc. has certified to + the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regard + to the processing of personal data received from the European Union and, under the UK + Extension, from the United Kingdom (and Gibraltar), and to the Swiss-U.S. DPF Principles + with regard to personal data received from Switzerland. If there is any conflict between + the terms in this privacy policy and the DPF Principles, the Principles shall govern. To + learn more about the Data Privacy Framework program, and to view our certification, please + visit{" "} + + https://www.dataprivacyframework.gov/ + + . +

+

+ Prisma Data, Inc. is subject to the investigatory and enforcement powers of the U.S. + Federal Trade Commission (FTC).

- Disputes resolve through relevant authorities and data protection authorities. The company - commits to cooperating with EU DPAs, UK ICO, and Swiss FDPIC regarding unresolved - complaints at no cost. + In compliance with the DPF Principles, Prisma commits to resolve complaints about our + collection or use of your personal data. Individuals in the EU, UK, or Switzerland with + inquiries or complaints should first contact{" "} + dpo@prisma.io. For complaints that cannot be resolved + directly, Prisma has committed to cooperate and comply with the advice of the panel + established by the EU data protection authorities (DPAs), the UK Information + Commissioner's Office (ICO), and the Swiss Federal Data Protection and Information + Commissioner (FDPIC). This independent dispute resolution mechanism is available to you at + no cost. Under certain conditions described in the DPF Principles, you may also invoke + binding arbitration when other dispute resolution procedures have been exhausted. +

+

+ Prisma remains responsible and liable under the DPF Principles if third-party agents + processing personal data on its behalf do so in a manner inconsistent with the Principles, + unless Prisma proves that it is not responsible for the event giving rise to the damage.

), }, { - title: "8. Human Resource Data and Personal Data", + title: "8. Human Resource Data", content: ( <>

- Prisma cooperates with EU data protection authorities, UK ICO, and Swiss FDPIC regarding - unresolved HR data complaints. The FTC investigates DPF compliance. + For human resources data transferred from the EU, UK, or Switzerland in the context of an + employment relationship, Prisma commits to cooperate and comply with the advice of the EU + data protection authorities, the UK ICO, and the Swiss FDPIC, and to grant the rights + provided under the DPF Principles.

Partner organizations handling HR and personal data follow equivalent legal requirements. - Third-party liability limitations apply unless legally mandated. Users may contact{" "} - dpo@prisma.io with questions or to limit data use. + Team members may contact dpo@prisma.io with questions + or to limit data use.

-

Binding arbitration is available under DPF Principles conditions.

), }, @@ -174,17 +232,62 @@ export const privacySections: PrivacySection[] = [ ), }, { - title: "10. Correcting and Updating Your Information", + title: "10. Your Privacy Rights", + content: ( + <> +

+ Account registration changes can be made by logging in at{" "} + prisma.io. You may also request access to, + correction, or deletion of your personal data by contacting{" "} + dpo@prisma.io. Requests receive responses within 30 + days, or any shorter period required by applicable law. Individuals covered by the DPF may + access, correct, amend, or delete personal data we hold about them. +

+

+ Where the GDPR or UK GDPR applies, you additionally have the right to data portability, + the right to restrict or object to processing, the right to withdraw consent at any time + without affecting prior processing, and the right to lodge a complaint with your data + protection supervisory authority. +

+

+ Residents of California and other U.S. states with comprehensive privacy laws have the + right to know and access the personal information we collect, correct or delete it, + receive it in a portable format, and opt out of targeted advertising and the sale or + sharing of personal information. Prisma does not sell personal information for money; + third-party advertising cookies described in Section 4 may constitute "sharing" under + California law, and you may opt out via our cookie settings, the Global Privacy Control + signal, or dpo@prisma.io. We will not discriminate + against you for exercising your rights, and you may appeal a refused request by replying + to our decision. +

+ + ), + }, + { + title: "11. Data Retention", + content: ( +

+ Prisma retains personal data only for as long as needed to fulfill the purposes described in + this policy, including providing the services, complying with legal, tax, and accounting + obligations, resolving disputes, and enforcing agreements. When personal data is no longer + required, it is deleted or anonymized. Retention periods vary by data category and are + available on request via dpo@prisma.io. +

+ ), + }, + { + title: "12. Children's Privacy", content: (

- Account registration changes can be made by logging in at{" "} - prisma.io. Information access, modification, or - deletion requests receive responses within 30 days. + Prisma's websites and services are not directed at children, and Prisma does not + knowingly collect personal data from children under 16. If you believe a child has provided + us personal data, contact dpo@prisma.io and we will + delete it.

), }, { - title: "11. Security", + title: "13. Security", content: (

Prisma employs administrative, technical, and physical security safeguards for customer data @@ -193,7 +296,7 @@ export const privacySections: PrivacySection[] = [ ), }, { - title: "12. Changes to this Privacy Statement", + title: "14. Changes to this Privacy Statement", content: (

Prisma reserves the right to modify this privacy policy at any time. Free Tier @@ -203,7 +306,7 @@ export const privacySections: PrivacySection[] = [ ), }, { - title: "13. Regulatory and Compliance Notice", + title: "15. Regulatory and Compliance Notice", content: (

Embeddable Prisma Studio operates as client-side software without visibility into end-user