Privacy and Data Protection Policy
Version: 1.0
Effective Date: April 12, 2026
Owner: Dr. Jeffrey Bullock, CEO
Review Cycle: Annual
1. Purpose
This policy governs how PRISM collects, processes, stores, and protects personal and business information from clients, prospects, and users of PRISM services and applications.
2. Data We Collect
2.1 Client Data
- Contact information (name, email, phone, company)
- Session transcripts (with client knowledge and consent)
- Business information shared during consulting sessions
- Financial transaction data (invoices, payments)
- Deliverables and work product
2.2 Financial Data (Plaid Integration)
- PRISM connects its own business bank accounts via Plaid for internal revenue tracking
- No client bank accounts are connected without explicit written authorization
- Transaction data pulled via Plaid is stored in access-controlled systems on PRISM infrastructure
- Plaid credentials and tokens are encrypted and stored separately from application code
2.3 Website and Application Data
- Standard web analytics (page views, referral sources)
- Form submissions (name, email, inquiry details)
- No cookies are used for tracking beyond essential functionality
3. How We Use Data
- Client consulting: Delivering AI strategy, coaching, and implementation services
- Internal operations: Revenue tracking, session scheduling, deliverable management
- Communication: Session recaps, follow-ups, newsletters (with consent)
- Quality assurance: Reviewing session transcripts to improve coaching effectiveness
4. Data Sharing
PRISM does not sell, rent, or trade personal or business information.
Data is shared only with:
- Service providers who process data on our behalf (Google Workspace, Stripe, Plaid) under their respective privacy policies
- Team members (employees, contractors) on a need-to-know basis for service delivery
- Legal requirements if compelled by law, regulation, or legal process
5. Data Storage and Security
- Client data is stored in Google Drive, iCloud, and PRISM production infrastructure
- All storage locations use encryption in transit (TLS) and access controls
- Production infrastructure is hosted on Hostinger VPS with SSH key authentication
- Backups are maintained weekly
6. Data Retention
- Active clients: Data retained for duration of engagement plus 12 months
- Prospects: Contact data retained for 24 months after last interaction, then deleted
- Financial records: Retained per IRS requirements (7 years)
- Session transcripts: Retained for 24 months after engagement ends
7. Client Rights
Clients may request:
- A summary of what data PRISM holds about them
- Correction of inaccurate information
- Deletion of their data (subject to legal retention requirements)
- A copy of their data in a portable format
Requests should be directed to [email protected] and will be fulfilled within 30 days.
8. Third-Party Services
PRISM uses the following third-party services that process data:
| Service | Purpose | Data Processed |
|---|---|---|
| Google Workspace | Email, Drive, Calendar | Client communications, documents, scheduling |
| Stripe | Payment processing | Payment card and transaction data |
| Plaid | Bank account connectivity | PRISM business bank transactions |
| Calendly | Scheduling | Client name, email, meeting details |
| Zoom | Video conferencing | Session recordings (with notice) |
| Cloudflare | DNS, CDN, security | Web traffic routing |
| Hostinger | Infrastructure hosting | Application data, client portals |
9. Breach Notification
In the event of a data breach affecting client personal or business information, PRISM will:
- Notify affected individuals within 72 hours of confirmation
- Describe what data was affected and what steps PRISM is taking
- Provide guidance on protective measures clients should take
- Report to relevant authorities as required by law
Approved by:
Dr. Jeffrey Bullock, CEO
PRISM AI Consultants LLC
Date: April 12, 2026