Effective as of 2/7/2026
This Privacy Policy explains how Prism AI, Inc. ("Prism AI," "we," "us," or "our") collects, uses, discloses, and safeguards information in connection with the Bigspin website, dashboard, APIs, research studies and data-collection activities, interactive AI experiences, and related services that reference or link to this Policy (collectively, the "Services"). We recognize privacy is an ongoing responsibility and will update this Policy as our practices evolve.
For most customers, access to and use of the Services is governed by a separate written agreement between Prism AI and your organization (e.g., a Master Subscription Agreement and/or Order Form, and where applicable a Data Processing Addendum, together the "Enterprise Agreement"). If there is any conflict between this Privacy Policy and an Enterprise Agreement, the Enterprise Agreement governs with respect to the Services provided to that organization. This Privacy Policy applies to visitors of our public website, to account-level information we process to operate the Services, and to individuals who participate in research studies or data-collection activities conducted by or on behalf of Prism AI.
Regulated data: Unless expressly agreed in writing, the Services are not designed for protected health information (HIPAA), payment card data (PCI DSS), or similarly regulated data categories. If your use cases involve such data, you must have an Enterprise Agreement that expressly permits it and sets applicable controls.
We may collect the following types of Personal Data:
Note that we may collect certain of the Personal Data above in our capacity as a processor to our customers, who are the controllers. Such data is governed by the applicable Enterprise Agreement and/or Data Processing Addendum between us and our customers. We do not use Customer Data to train foundation models. Any exceptions require explicit written consent documented in your Enterprise Agreement.
We use Personal Data for the following purposes:
For avoidance of doubt, we do not use data we receive from customers pursuant to an enterprise agreement unless we have been expressly permitted to do so by contract.
GDPR legal bases: contract performance (Art. 6(1)(b)) for account/Services operations; legitimate interests (Art. 6(1)(f)) for security, service improvement, basic analytics, research, and publications; consent (Art. 6(1)(a)) for optional marketing or non-essential cookies; and legal obligations (Art. 6(1)(c)) where applicable.
We use cookies and similar technologies to operate the website/Services, remember preferences, authenticate users, analyze usage, and improve performance. You can manage cookies via your browser settings. Blocking essential cookies may impair functionality. Where required, we will obtain consent for non-essential cookies. See our Cookies notice (if published) for details.
We share Personal Data with third-party vendors to support delivery of the Services (e.g., cloud hosting, data storage, authentication, analytics, email/service communications, and—if enabled by you—LLM providers). We conduct vendor diligence and maintain contractual obligations requiring appropriate confidentiality, security, and data protection.
Categories of subprocessors include: cloud infrastructure (e.g., AWS), managed databases (e.g., Supabase), authentication providers (e.g., Clerk), analytics/telemetry, email delivery and customer support tools, and optional LLM or model providers (e.g., OpenAI, Anthropic, Together AI).
We may disclose information if required by law, to protect rights and safety, to enforce our agreements, or in connection with a corporate transaction (e.g., merger, acquisition, financing). We may publish de-identified, anonymized or aggregated insights that do not identify any individual or customer organization.
Research Data sharing. In addition to the sharing described above, Research Data may be disclosed as follows:
Prism AI is headquartered in the United States. If you access the Services from outside the U.S., we may transfer and process information in the U.S. and other countries that may not provide the same level of data protection as your jurisdiction. In some instances, your Personal Data may be transferred to Prism AI in the U.S. pursuant to the EU/UK Standard Contractual Clauses and additional measures as needed.
We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy or disclosed to you upon collection, to comply with legal obligations, resolve disputes, and enforce agreements.
Depending on your location, you may have rights under applicable laws (e.g., GDPR, UK GDPR, CCPA/CPRA) including the right to request access, correction, deletion, portability, restriction or objection to certain processing, and to withdraw consent where processing is based on consent. You also may have the right to opt out of certain uses or disclosures (e.g., targeted advertising) where applicable.
If your account is provisioned by your employer, please direct requests to your organization's administrator where appropriate. Otherwise, you (or your authorized agent) can submit a request by emailing privacy@bigspin.ai. We will verify and respond in accordance with applicable law. You also have the right to lodge a complaint with a supervisory authority.
The Services are not directed to individuals under the age of 18, and we do not knowingly collect Personal Data from children.
We may update this Policy from time to time. The "Effective" date at the top indicates when the current version took effect. Material changes will be communicated as required by law or by reasonable notice through the Services.
Questions about this Policy, our privacy practices, or requests to obtain a copy of our DPA or security reports (under NDA) can be sent to:
Prism AI, Inc.
Privacy Team
United States
privacy@bigspin.ai
This Privacy Policy may be updated periodically. Last updated: 2/7/2026
