Last updated 2026-07-23
Prismatic is a media-monitoring service operated from Romania. This policy explains what we process, why, and what you can ask us to do about it. It covers two different groups: the people who hold accounts with us, and the people who appear in the media we monitor.
Prismatic (dataprism.cloud) is operated from Romania. Our infrastructure runs in the European Union (AWS eu-central-1).
For any privacy question or request, contact privacy@dataprism.cloud.
You also have the right to complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro).
We process the account details you give us and the settings you choose:
Your email address, display name and role, held in AWS Cognito.
Your monitored keywords, keyword refinements, monitored social accounts, favourite stations and interface language.
Your email-digest and notification preferences, including web-push subscriptions if you enable them.
We use this to provide the service, to send the reports you have opted into, and to keep the service secure. Every digest email carries a one-click unsubscribe.
We set exactly one cookie: a first-party session cookie that keeps you signed in. It is strictly necessary for the service to work.
We use no advertising cookies, no third-party trackers and no cross-site analytics.
We record basic feature-usage events (for example, that a page was opened) so we can see which parts of the product are used. These are tied to your account id, contain no free text and no personal data, and are deleted automatically after a fixed period.
Errors are reported to Sentry with personal information disabled.
This is the core of what the service does, so we describe it plainly.
We collect material that has already been published: articles from Romanian news outlets, broadcasts from national television and radio stations, posts from public social accounts our clients monitor, and newsletters. From broadcasts we produce transcripts.
From that material we derive analysis, including the names of people mentioned or speaking, how often they appear, on which outlets, and the sentiment of the coverage. Our clients can search this and see, for a given name, the mentions from a given day with the time, the outlet and an extract.
We do not buy personal data, and we do not collect anything that is not already publicly published by the source.
Pending legal review
We rely on our legitimate interest in operating a media-monitoring service, and our clients' legitimate interest in knowing what is published about them, balanced against the rights of the people concerned. The material we process has already been published by its source.
Because we obtain this material from publishers rather than from the individuals themselves, we are not always able to notify each person individually, given the volume involved.
Pending legal review
Published news coverage can contain sensitive information — for example political affiliation, or reporting on health. We do not seek out such information, and we do not build categories based on it. It reaches us only where a publisher has already published it.
Account data is kept for as long as you have an account.
Usage events are deleted automatically after a fixed retention period.
Monitored media — articles, transcripts and the analysis derived from them — is currently retained indefinitely, because the value of monitoring is the historical record. We are reviewing whether to set a maximum retention period, and will state it here when we do.
Pending legal review
We do not sell personal data and we do not share it for advertising.
We use service providers to run the product: cloud hosting, email delivery, search infrastructure, error monitoring, speech-to-text for broadcasts, language models for analysis, and data-collection services for social platforms.
Some of these providers are outside the European Economic Area. Where that is the case we rely on the transfer safeguards permitted by law. We keep an internal register of these providers and will publish a current list here.
Whether or not you hold an account, you can ask us to confirm what we hold about you, to correct it, to delete it, or to object to our processing of it.
Write to privacy@dataprism.cloud. We will respond within the time limits set by the GDPR.
If you are unhappy with our response you can complain to ANSPDCP.
Parts of our output — summaries, briefings and thematic analysis — are produced by language models. They can be wrong, and the interface says so where they appear. We do not make automated decisions that produce legal effects about anyone.